|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/owasp-security-for-developers-an-offensive-approach/
课程评论:没有评论
课程名称:攻击视角 - OWASP开发者安全课程 课程概述:您将通过对您的网络应用程序进行攻击来学习如何保护它,即通过渗透测试。该课程主要以理论为主,仅包含一些实验和演示。 课程目标: - 培养“超越常规”的思维方式 - 从攻击的角度看待安全 - 学习最佳安全实践及(常见与不常见)攻击方式 - 学会保护您的应用和基础设施 课程内容: 1. 网络渗透测试概述 2. OWASP十大网络漏洞 3. API十大漏洞 4. HTTP安全头 5. JSON Web Tokens 6. 技术措施与最佳实践 7. 密码学 网络渗透测试概述: - 核心问题 - Web技术基础 - 安全审计与漏洞评估与渗透测试的区别 - 信息收集 - 扫描与枚举 - 映射目标面 - 用户攻击(跨站脚本攻击) - 服务器攻击 - 身份验证攻击 - 数据存储攻击 API十大安全漏洞: - 公开可访问应用中发现的漏洞实例 OWASP十大网络漏洞具体内容: - A1: 注入 - A2: 破坏的身份验证及会话管理 - A3: 跨站脚本攻击(XSS) - A4: 不安全的直接对象引用 - A5: 安全配置错误 - A6: 敏感数据暴露 - A7: 缺失功能级访问控制 - A8: 跨站请求伪造(CSRF) - A9: 使用已知漏洞的组件 - A10: 未经验证的重定向和转发 - 2017年新增加内容 - 2021年新增漏洞 常见漏洞:XSS、SQL注入、CSRF、XXE、LFI HTTP安全头: - 理解HTTP安全令牌及其作用 - HSTS - 强制传输安全 - CSP - 内容安全政策 - CORS - X-Frame-Options - X-XSS-Protection - X-Content-Type-Options - Referrer-Policy - Cookie标志:HTTPOnly、Secure JSON Web Tokens: - 理解JWT结构 - JWT的应用时机 - JWT的优缺点 - JWT的最佳实践 技术措施与最佳实践: - 输入验证 - 编码 - 为数据库查询绑定参数 - 保护传输中的数据 - 哈希和盐化用户密码 - 加密静态数据 - 日志记录最佳实践 - 安全认证用户 - 保护用户会话 - 授权操作 密码学: - 密码学概念 - 算法 - 密码学与密码分析工具 - 密码学攻击 通过本课程,学员将能够从攻击者的视角深入理解网络安全,并掌握一系列保护和防御策略,提升应用程序的安全性。
You will learn to protect your web application by attacking it, by performing penetration testing on it. This course is rather theoretical with only some labs and demos.ObjectivesDevelop "Out-of-box" thinkingSee security from an offensive perspectiveLearn best security practices and (most and less) common attacksLearn to defend your applications and infrastructureTopicsOverview of Web Penetration TestingOWASP Top Ten Web VulnerabilitiesAPI Top Ten vulnerabilitiesHTTP Security HeadersJSON Web TokensTechnical measures and best practicesCryptographyOverview of Web Penetration TestingCore problemsWeb Technologies basicsSecurity Audit vs Vulnerability Assessment vs PentestInformation GatheringScanning and EnumerationMapping the target surfaceAttacking Users. Cross Site ScriptingAttacking the ServerAttacking AuthenticationAttacking Data StoresTop 10 API Security VulnerabilitiesAPI VulnerabilitiesExamples of vulnerabilities found in publicly accessible applicationsOWASP Top Ten Web VulnerabilitiesA1: InjectionA2 - Broken Authentication and Session ManagementA3 - Cross-Site Scripting (XSS)A4 - Insecure Direct Object ReferencesA5 - Security MisconfigurationA6 - Sensitive data ExposureA7 - Missing Function Level Access ControlA8 - Cross-Site Request Forgery (CSRF)A9 - Using Components with Known VulnerabilitiesA10 - Unvalidated Redirects and ForwardsNew Addition in OWASP TOP 10 - 2017A4 - XML External entities (XXE)A5 - Broken Access ControlA8 - Insecure DeserializationA10 - Insufficient Logging & MonitoringNew additions in 2021Common Vulnerabilities: XSS, SQL Injection, CSRF, XXE, LFIHTTP Security HeadersUnderstand HTTP Security Tokens and their roleHSTS - Strict-Transport-SecurityCSP - Content-Security-PolicyCORSX-Frame-OptionsX-XSS-ProtectionX-Content-Type-OptionsReferrer-PolicyCookie flags: HTTPOnly, SecureJSON Web TokensUnderstanding JSON WEB TOKENSToken StructureWhen can you use JWTIssuesWhat is JWT good for?Best Practices for JSON Web TokensTechnical measures and best practicesInput ValidationEncodingBind Parameters for Database QueriesProtect Data in TransitHash and Salt Your Users' PasswordsEncrypt Data at RestLogging - Best practicesAuthenticate Users SafelyProtect User SessionsAuthorize ActionsCryptographyCryptographic conceptsAlgorithmsCryptography and cryptanalysis toolsCryptography attacks