|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/securing-aspnet-web-applications/
课程评论:没有评论
**课程名称:** 网站安全:ASP.NET Web网络安全,OWASP Top 10+ **课程概述:** 本课程旨在提升开发者在代码安全方面的意识,应对日益严峻的网络安全数据泄露问题。课程内容涵盖OWASP Top 10安全漏洞,并结合软件工程实践,通过大量动手实验(包含详细指导和源代码)帮助学员构建更安全的应用。 **课程亮点:** * **权威性:** 微软内部开发者培训指定课程,讲师Chuck McCullough拥有20年以上的授课经验,学员遍布全球各大企业、政府机构和军队。 * **实用性:** 深入讲解OWASP Top 10常见安全漏洞,包括但不限于: * 注入类漏洞 (SQL注入, XPath注入, 命令注入等) * 认证失效 * XML外部实体注入 * 敏感数据泄露 * 安全配置错误 * 访问控制失效 (避免直接对象引用) * 跨站脚本攻击 (XSS) * 不安全的对象反序列化 * 使用存在已知漏洞的组件 * 日志记录和监控不足 * 其他常见问题 (CSRF, 输入验证等) * **全方位安全:** 不仅关注代码层面,还涵盖业务层面的安全加固。 * **实战导向:** 通过丰富的动手实验,教授学员如何构建“默认安全”的应用程序,遵循软件开发最佳实践,实现高性价比和强大的安全防护能力。 * **持续演进:** 课程内容紧跟当前技术发展和安全挑战,保持与时俱进。 **学习收获:** 学员将学习如何识别和防范常见的Web安全漏洞,掌握安全软件开发的原则和实践,从而有效提升ASP.NET Web应用程序的整体安全性。
Every day we hear news of yet another breach of some organization's data. Many of these result in huge costs to the organization, some have even gone out of business as a result. The Payment Card Industry (PCI) as well as many other international and local regulations require some level of security awareness for developers. This course was designed specifically to increase the awareness of security flaws in code.Why choose this course? Microsoft uses Chuck's courses to train their developers internally. Chuck's courses have been delivered to thousands of developers in-person, online and via Udemy, including major corporations, government agencies and military around the world.Students will learn the OWASP top 10 as well as software engineering practices that lead to a more secure development work product through many hands-on exercises complete with instruction and source code.Security in the software development lifecycleInjection Flaws - SQL Injection, XPath Injection, cmd Injection and moreBroken Authentication - learn to use Identity to avoid authentication flawsXML External EntitiesSensitive Data ExposureSecurity MisconfigurationBroken Access Control - prevent direct object referencesCross Site ScriptingInsecure object deserializationUsing components with known vulnerabilitiesInsufficient Logging and MonitoringOther issues - CSRF, ValidationSecuring the business tierSecure by defaultLearn to build applications that are secure by default. Following the best practices of software development not only provides great results in a cost efficient way, but also enhances the security posture of the application. Hands-on labs demonstrate these concepts.This course has been presented to thousands of developers over the last 2 decades with great success. Evolving the course to keep up with todays challenges and technologies is a primary goal for us. Join expert developer Chuck McCullough for this course on web security.