Pentesting Exploits Noted In Smartphones (Android Edition)

所在平台: Udemy

课程主页: https://www.udemy.com/course/pentesting-exploits-noted-in-smartphones-android-edition/

课程评论:没有评论

第一个写评论        关注课程

课程简介

课程名称:手机渗透测试漏洞研究(Android版) 课程概述:本课程专为希望拓展技能的Android渗透测试者而设计,特别是那些希望深入了解Android安全领域的高级部分的学员。课程涵盖的不仅仅是导出活动和密钥存储访问,而是深入探讨Android应用之间的通信复杂性。学员将直观了解恶意应用如何利用意图、内容提供者等组件的错误配置来攻击目标应用。通过使用为本课程特别创建的Axolotl测试应用,学员将实践构建自己的“攻击者”应用,旨在利用每一个已发现的漏洞。真实案例将帮助学员将理论知识与实际攻击联系起来。课程结束时,学员不仅能够提升现有的渗透测试技能,还将获得针对Android应用漏洞进行攻防的专业见解。 课程内容包括: 1. 意图机制:探索`getIntent()`,可浏览意图,NFC标签攻击和MIME类型劫持。 2. 未导出内容提供者:利用`grantUriPermissions`进行常规测试所忽视的滥用。 3. WebView漏洞:理解JavaScript桥接威胁、文件访问技巧和跨域政策缺陷。 4. 自定义权限:深入了解自定义权限结构并应用于攻击场景。 5. 加载自定义DEX文件:动态注入恶意代码到目标应用,以绕过安全机制。 如果你已经掌握Android渗透测试的基础知识,并想通过探索额外的漏洞和攻击面来突破极限,那么本课程是通往Android安全前沿的门户。

课程评论(0条)

课程详情

Are you an Android penetration tester looking to expand your skill set beyond the usual vulnerabilities and dive deep into the more advanced areas of Android security? This hands-on course is precisely for you.It's not just about examining exported activities and keystore access. This course delves into the intricacies of how Android applications communicate with each other. You'll see firsthand how a malicious application can exploit misconfigurations in Intents, Content Providers, and other components to compromise or abuse target apps.Using our Axolotl test application, created specifically for this course, you'll practice building your own "attacker" application designed to exploit each discovered vulnerability. Real-life examples will help you connect the dots between theoretical knowledge and practical attacks frequently encountered in the wild. By the end, you'll not only have honed your existing penetration testing expertise, but also gained the highly specialized insight needed to tackle loopholes in Android apps.What this course covers:Intent Mechanics: Explore `getIntent()`, Browsable Intents, NFC tag exploits, and MIME-type hijacking.Unexported Content Providers: Abuse `grantUriPermissions` in ways typical testing overlooks.WebView Vulnerabilities: Understand JavaScript Bridge threats, file access tricks, and Cross-Origin policy flaws.Custom Permissions: Delve into custom permission structures for exploitation scenarios.Loading Custom DEX Files: Dynamically inject malicious code into target apps to bypass security measures.If you already understand the foundations of Android penetration testing and want to push the limits by exploring additional vulnerabilities and attack surfaces, this course is your gateway to the cutting edge of Android security.

课程标签

0人关注该课程

主题相关的课程