|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/offensive-api-exploitation/
课程评论:没有评论
课程名称:攻击性API利用 课程概述:现代应用程序的构建依赖于API,攻击者对此非常熟悉。本课程旨在为安全专业人员、伦理黑客和漏洞赏金猎人提供攻击性技能,以利用真实世界中的API漏洞。无论是针对移动应用、网络服务还是第三方集成,学员将学习如何以攻击者的视角来审视API,识别测试人员常常忽视的缺陷。课程基于先前的培训(攻击性寻找漏洞方法和攻击性漏洞赏金猎人2.0),深入探讨OWASP API安全十大漏洞及其扩展内容。 学员将学习如何识别错误配置、身份验证破坏、授权缺陷、限流滥用、服务器端请求伪造(SSRF)等。课程采用实用的实践方式,从侦察和模糊测试到复杂漏洞链和撰写专业级报告,帮助学员在真实评估、红队测试和漏洞赏金项目中取得成功。此外,学员还将了解攻击者如何利用现代技术,如GraphQL、JWT、API网关和云连接API。 课程重点包括: - 攻击性利用OWASP API十大漏洞 - 真实世界API漏洞赏金案例研究及实践实验 - 工具使用:Burp Suite、Postman、FFUF、Kiterunner、curl及自定义脚本 - 实践侦察、模糊测试、端点枚举和PoC开发 - 学习如何像专业API渗透测试员一样思考、行动和报告。
Modern applications are built on APIs - and attackers know it. This advanced course is designed to equip security professionals, ethical hackers, and bug bounty hunters with the offensive skills needed to exploit real-world API vulnerabilities. Whether targeting mobile apps, web services, or third-party integrations, you'll learn how to approach APIs like an attacker and identify flaws that most testers miss.Built on the foundation of your previous training (Offensive Approach to Hunt Bugs and Offensive Bug Bounty Hunter 2.0), this course dives deep into the OWASP API Security Top 10 and beyond. You'll explore misconfigurations, broken authentication, authorization flaws, rate-limit abuse, SSRF, and more - all through a practical, hands-on approach.From reconnaissance and fuzzing to chaining complex vulnerabilities and writing professional-grade reports, this course gives you the skills needed to succeed in real-world assessments, red teaming, and bug bounty programs. You'll also gain insights into how attackers exploit modern technologies like GraphQL, JWT, API Gateways, and cloud-connected APIs. Key Highlights:Offensive exploitation of OWASP API Top 10 vulnerabilitiesReal-world API bug bounty case studies and practical labsTools: Burp Suite, Postman, FFUF, Kiterunner, curl, and custom scriptsHands-on recon, fuzzing, endpoint enumeration, and PoC developmentLearn how to think, act, and report like a professional API pentester