Pentesters Practical Approach for Bug Hunting and Bug Bounty

所在平台: Udemy

课程主页: https://www.udemy.com/course/pentesters-practical-approach-for-bug-hunting-and-bug-bounty/

课程评论:没有评论

第一个写评论        关注课程

课程简介

课程名称:渗透测试员的实用方法:漏洞狩猎与漏洞赏金 课程概述: 欢迎参加《渗透测试员的实用方法:漏洞狩猎与漏洞赏金》课程。要享受本课程,您需要保持积极的态度和学习的热情。在这个课程中,您将学习渗透测试员和漏洞猎人的实用技能。我们看到一些渗透测试员通过漏洞赏金平台每年赚取数百万美元。许多课程教授的工具和概念在实际应用中却很少使用。本课程将专注于能帮助您成为成功的安全研究员和漏洞猎人的工具、主题以及实践演示。课程内容极具实践性,涵盖所有基本主题。该课程是一个适合初学者的短期实用课程,涵盖各种主动攻击技术和渗透测试Web应用程序的战略方法。 学习成果: 完成本课程后,您将能够识别评估中经常会错过的各种漏洞。 课程模块: - 确定目标范围 - 理解应用程序商业逻辑 - 威胁映射 - 基于范围的侦查 - 手动渗透测试 - 应用特定攻击 - Juice Shop入门 - 深入了解Juice Shop的每个功能 - SSL/TLS枚举攻击 - 横幅利用 - 版本枚举 - 使用FTP提取敏感数据 - 页面源中的泄露信息查找 - 身份验证和授权缺陷 - XSS漏洞 - 注入攻击 - 客户端验证绕过攻击 - 参数污染攻击 - 强制数据推送攻击 - 基于会话的缺陷 - 寻找注入和IDOR漏洞 - 权限提升猎杀 - 利用文件上传功能 - 角色级检查绕过 - 商业逻辑绕过漏洞 - 破坏访问控制 - 支付网关绕过攻击 - 缺失的服务器端验证利用 注意:本课程仅用于教育目的。所有展示的攻击均在获得许可的情况下进行。请在获得许可的情况下才进行攻击。

课程评论(0条)

课程详情

Welcome to this course on Pentesters Practical Approach for Bug Hunting and Bug Bounty. To enjoy this course, you need a positive attitude and a desire to learn.In this course, you will learn the practical side of penetration testers and bug hunters. We have seen that how some of the pen-testers are earning millions in a year through bug bounty platforms. Too many courses teach students tools and concepts that are never used in the real world. In this course, we will focus only on tools, topics and practical live demonstration that will make you successful as a security researcher and bug hunter. The course is incredibly hands on and will cover all essential topics.This is a short-term beginner-friendly practical course that covers different types of offensive techniques and strategical approach to pentest the web application.Takeaways: After this course you will be able to find various types of vulnerabilities which you often miss during your assessment.Modules Introduced in this Course:Defining the target Scope Understanding Application Business Logic Threat Mapping Performing scope based recon Performing Manual Pentesting Performing Application Specific Attacks Introduction to Juice Shop Hitting hard Juice shopApplication navigation to each featureSSL/TLS Enumeration AttacksBanner ExploitsVersion EnumerationSensitive data fetching using FTP ExplorationLeaked Information lookup in Page SourceAuthentication Authorization FlawsXSS ExploitsInjection AttacksClient Side Validation Bypass AttacksParameter Pollution AttackForce Data Pushing AttackSession Based FlawsHunt For Injection and IDORPrivilege Escalation HuntExploit File Upload FeatureRole Level Checks BypassBusiness Logic Bypass ExploitBroken Access ControlPayment Gateway Bypass attacksMissing Server Side Validation ExploitNote: This course has been created for educational purposes only. All attacks shown were done so with given permission. Please do not attack a host unless you have permission to do so.

课程标签

0人关注该课程

主题相关的课程