|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/recon-for-bug-bounty-pentesting-ethicalhacking-by-shifa-rohit-hacktify/
课程评论:没有评论
课程名称:2025年道德黑客/渗透测试与漏洞悬赏侦查 课程概述: 欢迎参加“漏洞悬赏渗透测试与道德黑客侦查”课程。本课程将从侦查和漏洞猎捕的基础开始,逐步深入到高级利用技术。我们将学习Web及Web服务器的基本概念,以及它们在日常生活中的应用。此外,课程将涵盖DNS、URL、URN、URI的基本知识,为漏洞猎捕打下坚实基础,并进一步探讨目标扩展、内容发现、模糊测试、CMS识别、证书透明度、可视化侦查、GitHub侦查、自定义字典、思维导图、漏洞悬赏自动化及相关平台的实践操作。 课程内容包括渗透测试和漏洞悬赏所需的所有工具和技术,帮助更好地理解后台运作机制。我们将学习各种目标选择技术,进行主机子网扫描、主机发现、内容发现以及子域名枚举等。课程将教授如何寻找web漏洞(如XSS、SQL注入等),提高范围以便更好地进行可视化。同时,我们将探索如何使用Shodan查找关键漏洞,利用GitHub侦查寻找敏感信息,并掌握日常任务的自动化执行方法。 课程包括以下主题: - Web基础知识及其在日常生活中的重要性 - DNS的工作原理及相关类型 - 漏洞猎捕及侦查的重要性 - Shodan工具的应用,包括查询、主机枚举及图形用户界面 - 证书透明度及子域名枚举的实用技巧 - 利用多个渗透测试工具扩展范围 - 模糊测试的基本方法及其实际操作 - 内容发现的工具使用,如Dirsearch和Gobuster - CMS识别以及WAF检测技术 - 思维导图的应用以简化攻击过程 - 各大漏洞悬赏平台的入门指南 本课程提供24小时支持,如有疑问可随时在问答区提问,老师会尽快回复。需要注意的是,本课程仅用于教育目的,对没有负责任的披露政策的网站进行测试是不道德的且违反法律,作者对此不承担任何责任。
Welcome to Recon for Bug Bounty Pentesting and Ethical HackingThis course starts with the Basics of Recon and Bug Bounty Hunting Fundamentals to Advance ExploitationThis course starts with basics with Web and Web Server Works and how it can be used in our day to day life We will also learn about DNS URL vs URN vs URI and Recon for Bug Bounties to make our base stronger and then further move on to Target Expansion Content Discovery Fuzzing CMS Identification Certificate Transparency Visual Recon GitHub Recon Custom Wordlists Mind Maps Bug Bounty Automation Bug Bounty Platforms with practicalsThis course covers All the Tools and Techniques for Penetration Testing and Bug Bounties for a better understanding of what is happening behind the hoodThe course also includes an in depth approach towards any target and increases the scope for mass hunting and successWith this course we will learn Target Selection Techniques for Host Subnet Scans and Host Discovery Content Discovery Subdomain Enumeration Horizontal and Vertical CMS Identification Fuzzing the target for finding web vulnerabilities like XSS Open Redirect SSRF SQL Injection etc How to increase the scope and take screenshots for a large number of hosts for better visualization We will also learn How to use Shodan for Bug Bounties to find critical vulnerabilities in targets We will also see GitHub Recon to find sensitive information for targets like API keys from GitHub Repositories Next we will see How to perform Automation for daily day to day tasks and easier ways to run tools We will also see How to write Bug Bounty and Pentesting Reports We will also cover mind maps by other hackers for a better approach toward any target and also we will see a mind map created by us We will also see Bug Bounty Platforms and how to kick start our journey on themHere is a more detailed breakdown of the course contentIn all the sections we will start with the fundamental principle of How the scan works and How can we perform ExploitationIn Introduction We will cover What is Web What are Web Servers DNS and We will also learn about DNS and How DNS works and also How DNS is important in our day to day life We will also see the difference between URL URN and URI We will also see the complete breakdown of the URL to understand better We will also learn about Bug Bounty Hunting and Understand the Importance of Recon in Bug Bounty Hunting and PentestingBefore starting the journey We will see Top 10 rules for Bug Bounty Hunting and we will understand the psychology of the HackersIn Shodan for Bug Bounties we will start with the installation of Shodan and we will learn about Shodan Queries such as Info Count downloads and many more and will run them from our command line We will also learn Host Enumeration Parse dataset Search Queries and Scan commands using Shodan The section cannot be completed without learning about Shodan GUI which is very simple and easily understandable We will also see Shodan Images Exploits Report generation and a lot moreIn the end we will see the summary and revision of the section to remember the important queries and key pointsWe will see live hunting with Shodan and understand the latest CVEs and perform exploits We will see Jenkins Exploitation Logs Jenkins Exploitation Credentials ADB under Shodan LIVE HuntingIn Certificate Transparency for Subdomain Enumeration we will learn about crt dot sh wildcards of crt dot sh and We will learn automation for crt dot sh to enumerate subdomains for a target We will also learn about Shodan Censys for Subdomain Enumeration We will learn about Google and Facebook Certificate Transparency We will also learn to find out Subdomains using DNS Dumpster and enumerate all the DNS records as well as save the hosts in an XLSX format We will also see the workflow for dnsdumpster to know about the whole target server from its DNS records like A CNAME MX TXT etcIn Scope Expansion we will learn about ASN Lookup Pentest tools VirusTotal We will also learn about some awesome tools like Sublister Subfinder Knockpy Asset Finder Amass Findomain Sublert Project Discovery Nmmapper and a lot more We will also understand how to use them effectively for expanding the scope to walk on a less traveled road and achieve success in bug bountiesIn DNS Enumeration for Bug Bounties we will learn and understand about DNS Dumpster DNS Goodies Altdns Massdns Vertical and Horizontal Correlation Viewdns info and enumerate the subdomains from the recursive DNSWe will start with Introduction to Fuzzing Its importance and Step by Step process We will see fuzzing practically on LAB and LIVE websites to understand better We will Learn Understand and Use tools like Wfuzz and FFUF and also see how we can perform recursive fuzzing on the target We will also perform HTTP Basic Auth Fuzz to crack the login of the dashboards and also do Login Authentication Cracking with the help of useful wordlistsWe will utilize some of the wordlists like SecLists FuzzDB Jhaddix All txt and will also see how to make our own custom wordlists for the targetsContent Discovery covers tools like Dirsearch Gobuster which will be helpful for finding out sensitive endpoints of the targets like db conf or env files which may contain the DB username and passwords Also sensitive information like periodic backups or source code and can also be identified which can lead to the compromise of the whole serverIn CMS Identification we will learn and understand about Wappalyzer Builtwith Netcraft WhatWeb Retire jsAs Banner Grabbing and identifying information about the target is the foremost step we will identify the underlying technologies which will enable us to narrow down the approach which will lead to successIn WAF Identification we will see WAF Detection with Nmap WAF Fingerprinting with Nmap WafW00f vs NmapWe will know if there are any firewalls running on the target and accordingly send our payloads to the targets and throttle our requests so we can evade them successfullyThe Mindmaps for Recon and Bug Bounty section will cover the approach and methodology towards the target for pentesting and bug bounty A strong and clear visual representation will help in performing the attack process with more clarity and will help in knowing the next stepsThe Bug Bounty Platforms section contains a Roadmap of How to start your Bug Bounty Journey on different Platforms like HackerOne Bugcrowd Integrity Synack It also covers how to Report Private RVDP ProgramsWith this course you get 24 7 support so if you have any questions you can post them in the Q and A section and we will respond to you as soon as possibleNotesThis course is created for educational purposes only and all the websites I have performed attacks on are ethically reported and fixedTesting any website that does not have a Responsible Disclosure Policy is unethical and against the law The author does not hold any responsibility