|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/secure-coding-dive-into-injections-with-java-spring-boot/
课程评论:没有评论
课程名称:Web安全:使用Java和Spring Boot的注入攻击 课程概述:此课程专为Java网页开发人员设计,旨在帮助学员编写安全代码,学习伦理黑客和网络应用安全。课程将集中讲解OWASP十大漏洞中排名靠前的注入攻击。注入攻击仍然是OWASP十大攻击中的前三名,了解如何防范注入攻击对开发安全网络应用至关重要。 课程将采用实践的方式,涵盖多种类型的注入攻击,包括SQL注入、NoSQL注入、LDAP注入、LOG注入和CSV注入。课程内容将围绕如何从头开发一个包含常见网页登录模块的脆弱应用,同时结合Java、Spring Boot和Spring Security等技术,进行伦理黑客示例和攻击演示,并通过多层防御原则实施多种解决方案来保护应用。 课程亮点包括: - 开发脆弱的网页应用,包含SQL和NoSQL等多种注入示例。 - 使用最新的Spring Boot及其他依赖包,并提供逐步讲解。 - 附有源代码下载,便于学员直接进行注入攻击演示。 - 探讨各种保护措施,包括使用白名单进行验证和清理、准备语句的参数化查询、安全输出转义以及一般编码实践。 课程结束时,学员将能理解不同类型的注入脆弱性,进行应用攻击,并学习多种技术保护应用免受注入攻击。此外,课程提供30天全额退款保证,降低学员学习的风险。 如果您希望获取更详细的课程进展信息,可以查看介绍视频和免费课程,随时欢迎在Q&A和消息区提问、讨论概念及实施细节。让我们一起开始这段学习之旅!
Are you a Java web developer and want to write secure code? Do you want to learn Ethical hacking and Web application security? With this hands-on injection attacks course you will start learning web security using one of the top vulnerabilities of OWASP Top 10 list. Injection attack is still listed in top 3 attacks in the OWASP Top 10 and it is important to prevent against injection attacks to develop secure web applications. Krzysztof Telka: "Nice examples, where the host is presenting step by step how to exploit the application and then how to prevent. Lot of nice tools, features to check and examine the web page in case of hackers attack. CSV/Log4J/SQL made big wow effect on my face. The atendeers they will not be dissapointed Great job Ali, Thank you!"You can always use the latest versions for spring boot, and other dependencies in this course. I will be constantly updating the dependency version in the last section's lectures. You may check that to see the required code and configuration changes for updated versions. Also if you would like to use subtitles during the course, you can turn on the captions on videos. I suggest using subtitles to make it easier to follow the lectures. As part of the blue and red security teams,I have a practical knowledge and I am here to help you learn the injection vulnerability in detailIn this course, you will focus on different type of injection attacks;SQL InjectionNoSQL injectionLDAP injectionLOG injectionCSV injectionEthical hacking and Web application security are the two important subjects of Cyber Security field and having practical knowledge about Injections will enable you to better understand the security concepts and make a quick start. In this course you will follow defense-in-depth principle and apply multiple solutions to each vulnerability to secure the web application in multiple layers. You will follow a hands-on approach. You will not only learn how to exploit an application using different kind of injection attacks, but also develop the vulnerable applications from scratch in which you will have a common web login module with Thymeleaf and Bootstrap for a basic front-end, with Spring security form login authentication & authorisation, and with separate applications for SQL, NoSQL and LDAP injections. The applications will be developed using Java, Spring boot and Spring Data along with the most used data sources, such as PostgreSQL for SQL Injection, MongoDB for NoSQL injection and OpenLDAP for LDAP injection. In each section there will be;Development of the vulnerable web application using Java, Spring boot and Spring securityHacking of the application with various attack payloads and with Ethical hacking examplesProtection steps and the implementations to prevent injection attacksAt the end of the course you will understand the different type of injection vulnerabilities, perform injection attacks against the vulnerable web applications you have developed, and learn how to protect your applications against the injection attacks using various techniques such as,Validation and sanitisation using white list approachParametrised queries with prepared statementsEscaping outputUsing secure trusted librariesError handling and loggingGeneral coding practicesIf you want to skip the development and only perform the hacking of applications, you can jump into the injection lectures and download the source code provided in the resources section of that lecture. The source codes are in lecture 20 (SQL Injection), lecture 38 (NoSQL Injection), lecture 51 ( LDAP Injection), lecture 60 (LOG Injection) and lecture 74 (CSV Injection). Be aware that you will still need to install PostgreSQL for SQL Injection, MongoDB for NoSQL injection and OpenLDAP docker container for LDAP injection. You can see how to install and configure these data sources in the beginning lectures of each injection section. Manoj Singh: "Talented instructor and great course!!! Just a small suggestion, If you could add a chapter about "Broken Access Control" topic that will be a great help."For more detailed information on the progress of this course, you can check the introductory video and free lessons, and if you decide to enroll in this course, you are always welcome to ask and discuss the concepts and implementation details on Q/A and messages sections. I will guide you from start to finish to help you successfully complete the course and gain as much knowledge and experience as possible from this course.Remember! There is a 30-day full money-back guarantee for this course! So you can safely press the 'Buy this course' button with zero risk and join this learning journey with me.