|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/secure-programming-of-web-applications-developers-and-tpms/
课程评论:没有评论
课程名称:网页应用的安全编程 - 开发人员和技术项目经理(TPMs) 概述:本课程旨在帮助学员理解应用程序安全的重要性。每周都发生的对知名网页应用的成功攻击事件,凸显了学习“网页应用安全性”背景的必要性,尤其是针对定制或自开发应用的情况。在现如今,计算机系统已深深融入我们的工作和生活之中,企业在技术进步面前,维护IT安全变得愈发复杂和困难。大型企业会根据行业标准(如ISO 27001)建立复杂的安全流程,而这些流程往往需要专业的安全团队来实施。持续的质量保证、维护和调整也是IT安全流程的重要组成部分。无论是开发产品还是运营在线商店,IT安全都是一个至关重要的特点。安全事件不仅会损害企业形象,还可能导致法律或财务后果。 课程内容包括: - 常见漏洞概述 - 漏洞的原因与背景 - 安全编程一般原则 - 代码/命令注入概况 - (非)SQL代码注入 - 跨站请求伪造(CSRF) - 跨站脚本攻击(XSS) - 开放重定向 - 文件包含/目录遍历 - 点击劫持 - 会话劫持 - 信息泄露 - 身份验证漏洞攻击 - 拒绝服务攻击 - 中间件 - 第三方软件 总结与结论部分同样重要。课程所教授的原则是与编程语言和平台无关的,尽管课程将包含Java和PHP的实例。 授课教师Frank Hissen是一位计算机科学家和安全专家,拥有20年以上IT安全教学经验,为各类企业提供IT安全咨询和软件工程服务。
Understand Application Security: Numerous successful attacks on well-known web applications on a weekly basis should be reason enough to study the background of "Web Application Security" of custom-made or self-developed applications.Computer systems are ubiquitous and part of our working and private everyday life. For companies it is increasingly complex and difficult to keep up their IT security with the current technical progress. Large enterprises establish security processes which are created according to industry standards (e.g., ISO 27001). These processes are very complex and can only be implemented by teams of security experts. Constant quality assurance, maintenance and adaptation also belong to an IT security process.It does not matter if a company develops products or runs an online shop, IT security is a characteristic feature. Security incidents, which maybe even reach public uncontrolled, do not only damage the business image but may also lead to legal or financial consequences.IntroTypical Vulnerabilities OverviewCause & BackgroundSecure Programming in generalCode/Command Injection in general(No)SQL Code InjectionCross-Site Request Forgery (CSRF)Cross-Site Scripting (XSS)Open RedirectionFile Inclusion / Directory TraversalClickjackingSession-HijackingInformation DisclosureAttacks on Weaknesses of the AuthenticationDenial of ServiceMiddlewareThird-Party SoftwareSummary and ConclusionThe principles taught in this course are language and platform independent. However, the course will include examples for Java and PHP.Instructor Frank Hissen, Computer Scientist and Security Expert, teaches IT security for over 20 years and works for companies of all sizes as IT Security Consultant and Software Engineer.