Mastering Server-Side Request Forgery (SSRF) Vulnerabilities

所在平台: Udemy

课程主页: https://www.udemy.com/course/mastering-server-side-request-forgery-ssrf-vulnerabilities/

课程评论:没有评论

第一个写评论        关注课程

课程简介

课程名称:精通服务器端请求伪造(SSRF)漏洞 课程概述:服务器端请求伪造(SSRF)是一种漏洞,攻击者可以利用该漏洞强迫应用程序向非预期位置发起请求。SSRF攻击通常用于建立与内部服务的连接,这些服务通常受到组织基础设施中防火墙的保护。这可能导致敏感数据泄露、拒绝服务攻击,甚至在最严重的情况下,远程代码执行。根据OWASP前10大安全风险,SSRF被列为当前网页应用程序的第十大关键安全风险。因此,掌握识别和利用SSRF漏洞的能力已经成为一项基本的技能。 在这门课程中,我们深入探讨了SSRF漏洞的技术细节。课程内容包括从黑箱和白箱的角度检测这些漏洞的方法,以及利用这些漏洞的各种技术。此外,我们还提供了防范和缓解SSRF攻击的见解。课程超越了基础知识,结合了理论与实践经验!它包含七个难度各异的动手实验,指导学员手动利用漏洞,然后使用Python进行漏洞利用的脚本编写和自动化。 通过完成这门课程,学员不仅能够深入理解SSRF漏洞,还能在实际应用中识别和利用这些漏洞。我们设计的课程内容适合初学者,让人不会感到困惑。 无论你是渗透测试员、应用安全专家、漏洞赏金猎人、软件开发者、道德黑客,还是对网页应用安全感兴趣的人,这门课程都非常适合你!

课程评论(0条)

课程详情

Server-Side Request Forgery (SSRF) is a vulnerability that allows an attacker to coerce the application into making requests to unintended locations. SSRF attacks are typically used to establish connections with internal services, which are safeguarded by firewalls within an organization's infrastructure. This could result in sensitive data exposure, denial of service attacks, and in the most severe cases, remote code execution.SSRF is ranked as the 10th most critical security risk facing web applications today according to the OWASP Top 10 list. Therefore, mastering the ability to identify and exploit SSRF vulnerabilities has become an essential and foundational skill.In this course, we dive into the technical details behind SSRF vulnerabilities. We explore methods for detecting these vulnerabilities from both black-box and white-box perspectives, along with various techniques for exploiting them. Moreover, we provide insights into preventive and mitigative measures to safeguard against SSRF attacks.This course goes beyond the basics, offering a well-balanced blend of theoretical knowledge and practical experience! It contains seven hands-on lab exercises of varying complexity levels, guiding you through the process of manually exploiting the vulnerability and then scripting and automating your exploits using Python.By the end of this course, you'll not only have a solid understanding of SSRF vulnerabilities, but also the ability to identify and exploit these vulnerabilities in real-world applications. We've designed the course content to be beginner-friendly, so you'll never feel overwhelmed.Whether you are a penetration tester, an application security specialist, a bug bounty hunter, a software developer, an ethical hacker, or simply someone intrigued by web application security, this course is for you!

课程标签

0人关注该课程

主题相关的课程