|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/offensive-security-pathway-level-4-of-6/
课程评论:没有评论
Coursera 课程:进攻性安全路径 - 第 4 阶段 (共 6 阶段) 本课程是进攻性安全系列路线图的第四阶段,旨在大幅提升您的黑客技能。您将深入学习 Web 应用程序的高级漏洞,包括 SQL 注入、跨站请求伪造 (CSRF)、远程文件包含 (RFI) 和服务器端请求伪造 (SSRF),使您能够超越基础漏洞,有效利用 Web 应用。 课程还将重点讲解入侵后的利用技术,即获取系统访问权后如何收集敏感数据、通过键盘记录监控用户活动以及在已攻陷网络中维持持久性。 权限提升是进攻性安全中的关键环节,您将学习如何使用 WinPEAS 和 LinPEAS 等工具在 Windows 和 Linux 系统中实现权限升级。 此外,本课程的一大亮点是 Active Directory 的攻防技术。您将学习如何使用 Bloodhound、Kerberoasting 和 Pass-the-Hash 等技术来绘制和利用 AD 环境。同时,还将探索高级网络攻击,如中间人攻击 (MITM)、ARP 欺骗和 DNS 劫持。 本阶段课程为准备迎接进攻性安全中最具挑战性但也最有价值的实践做好准备。 **课程大纲:** * **Web 攻击:** 深入探究高级 Web 应用程序漏洞,包括 SQL 注入、CSRF、RFI 和 SSRF。 * **入侵后利用技术:** 学习在获取系统访问权后如何收集敏感信息、记录用户活动并建立持久性。 * **权限提升技术:** 掌握使用 WinPEAS 和 LinPEAS 等工具在 Windows 和 Linux 系统上提升权限的方法。 * **Active Directory 攻防:** 学习使用 Bloodhound、Kerberoasting、Pass-the-Hash 等技术以及利用配置错误来绘制和利用 AD 环境。 * **高级网络攻击:** 学习执行中间人攻击 (MITM)、ARP 欺骗和 DNS 劫持等高级网络攻击。 * **专项 Windows 渗透:** 专注于利用鲜为人知的攻击向量的高级 Windows 漏洞利用技术。 * **专项 Linux 渗透:** 学习利用特定的 Linux 发行版和高级配置以达到最大效果。
Level 4, Offensive Security Colonel (OSC), propels your hacking skills to an advanced level by diving deep into web application vulnerabilities, post-exploitation techniques, and privilege escalation on both Windows and Linux. This chapter covers sophisticated web attacks like SQL Injection, Cross-Site Request Forgery (CSRF), Remote File Inclusion (RFI), and Server-Side Request Forgery (SSRF), giving you the tools to exploit web applications beyond basic vulnerabilities.You'll gain an understanding of post-exploitation strategies-what to do after you've compromised a system. This includes gathering sensitive data, monitoring user activities through keylogging, and maintaining persistence in compromised networks. Privilege escalation is crucial in offensive security, and this course will teach you how to elevate privileges on Windows and Linux systems using tools like WinPEAS and LinPEAS.One of the highlights of this chapter is hacking Active Directory, a critical skill for those looking to specialize in network attacks. You'll learn to map and exploit AD environments using techniques like Bloodhound, Kerberoasting, and Pass-the-Hash. Additionally, you'll explore advanced network attacks, including MITM, ARP spoofing, and DNS poisoning.This level is designed for those ready to tackle the most complex and rewarding challenges in offensive security.SyllabusWeb Attacks: Deep dive into advanced web application vulnerabilities, including SQL Injection, Cross-Site Request Forgery (CSRF), Remote File Inclusion (RFI), and Server-Side Request Forgery (SSRF).Post-Exploitation Techniques: Understanding how to gather sensitive information, keylog user activities, and establish persistence after gaining access.Privilege Escalation Techniques: Learn how to escalate privileges on Windows and Linux systems using tools like WinPEAS and LinPEAS.Hacking Active Directory: Techniques to map and exploit AD environments, including Bloodhound, Kerberoasting, Pass-the-Hash, and abusing misconfigurations.Network Attacks (Advanced): Conducting advanced network attacks like Man-in-the-Middle (MITM), ARP spoofing, and DNS poisoning.Specialized Windows Hacking: Advanced Windows exploitation techniques focusing on lesser-known attack vectors.Specialized Linux Hacking: Exploiting specific Linux distributions and advanced configurations for maximum impact.