|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/pentesting-and-security-testing-with-owasp-zap-mastery-course/
课程评论:没有评论
课程名称:使用 OWASP ZAP 的渗透测试:精通课程 课程概述:欢迎参加《使用 OWASP ZAP 的渗透测试》课程!该课程旨在教授您如何测试 web 应用程序,进行自动化测试、手动测试和模糊测试,执行漏洞猎杀以及使用 ZAP 完整评估网站的安全性。课程强调易用性,具备识别许多其他工具未能发现的关键安全漏洞的能力,是每个渗透测试员、黑客和开发者必备的工具。ZAP 能与多种黑客和渗透测试工具(如 SQLmap、nmap、Burp suite、Nikto 等)集成,还支持与 Burp 的结合使用以获得更大的灵活性。 ZAP 的一些特色功能包括: - 快速启动和“指点拍摄” - 可拦截代理 - 自动化与手动测试相兼容 - ZAP HUD 模式 - 主动与被动扫描 - 针对不同用例的攻击模式 - 易于集成到 CI/CD 流程 - 支持多种脚本语言 课程材料包括离线 PDF 幻灯片、超过 8 小时的视频课程,且可在 PC、平板和智能手机上自主学习。 ZAP 针对 web 应用程序和 web 服务器测试的漏洞包括但不限于: - 路径遍历 - 远程文件包含 - 代码泄露 - 跨站脚本(XSS) - SQL 注入 - 目录浏览 - 缓冲区溢出 - 会话固定攻击 - 多种高级注入技术 这个课程将为您提供全面的渗透测试技能,使您能够识别和利用潜在的安全漏洞,确保 web 应用程序的安全性。
[+] Course at a glanceWelcome, to this course, "PenTesting with OWASP ZAP" a fine grained course that enables you to test web application, automated testing, manual testing, fuzzing web applications, perform bug hunting and complete web assessment using ZAP. focused over ease of use and with special abilities to take down the web applications that most of the tool will leave you with unnoticed and or, un touched critical vulnerabilities in web applications but then the ZAP comes to rescue and do the rest what other tools can not find."This course is completely focused over pen testing web applications with ZAP"The ZAP, is a fine grained tool that every penetration testers, hacker, developers must have in their arsenal and hence required a solid understanding and through training to perform security testing from its core. ZAP can work with and integrate with many tools in the hacking, penetration testing segment such as: SQLmap, nmap, Burp suite, Nikto and every tool inside kali linux. Invoking with burp gives much flexibility to combine the power of ZAP and burp suite at the same time and in complete order.[+] Some special features of the ZAPQuick start using "point and shoot"Intercepting proxy with liked browserProxying through zap then scanningManual testing with automated testingZAP HUD mode, to test apps and attack in a single pageAttack modes for different use cases.Active scanning with passive scanningRequester for Manual testingPlug-n-hack supportCan be easily integrated into CI/CDPowerful REST based APITraditional AJAX spiderSupport for the wide range of scripting languagesSmart card supportPort scanningParameter analysisInvoking and using other apps I.e: Burp suiteSession managementAnti-CSRF token handlingDynamic SSL certificates supportAnd much more...[+] Course materialsOffline access to read PDF slides8+ Hours of Videos lessonsSelf-paced HTML/FlashAccess from PC, TABLETS, SMARTPHONES.PDF Slide[+] Below are the Vulnerabilities that ZAP security tests against a web application & web server to hunt for loopholes Path Traversal, Remote File Inclusion, Source Code Disclosure - /WEB-INF folder, Server Side Include, Cross Site Scripting (Reflected) Cross Site Scripting (Persistent) - Prime, Cross Site Scripting (Persistent) - Spider, Cross Site Scripting (Persistent), SQL Injection Server Side Code Injection, Remote OS Command Injection, Directory Browsing, External Redirect, Buffer Overflow Medium Format String Error, CRLF Injection Medium, Parameter Tampering, Script Active Scan Rules, Remote Code Execution - Shell Shock Anti CSRF Tokens Scanner, Heartbleed OpenSSL Vulnerability, Cross-Domain Misconfiguration, Source Code Disclosure - CVE-2012-1823Remote Code Execution - CVE-2012-1823, Session Fixation, SQL Injection - MySQL, SQL Injection - Hypersonic SQL, SQL Injection - Oracle SQL Injection - PostgreSQL, Advanced SQL Injection, XPath Injection, XML External Entity Attack, Generic Padding Oracle Expression Language Injection, Source Code Disclosure - SVN, Backup File Disclosure, Integer Overflow Error, Insecure HTTP Method HTTP Parameter Pollution scanner, Possible Username Enumeration, Source Code Disclosure - Git, Source Code Disclosure - File Inclusion Httpoxy - Proxy Header Misuse, LDAP Injection, SQL Injection - SQLite, Cross Site Scripting (DOM Based), SQL Injection - MsSQL Example Active Scanner: Denial of Service, An example active scan rule which loads data from a file, Cloud Metadata Potentially Exposed Relative Path Confusion, Apache Range Header DoS, User Agent Fuzzer, HTTP Only Site, Proxy Disclosure, ELMAH Information Leak Trace.axd Information,.htaccess Information,.env Information Leak, XSLT Injection. _________________________________________________________________________________________________________________________________________________