|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/the-art-of-web-security-testing/
课程评论:没有评论
**课程名称:** Web 安全测试的艺术 **课程概述:** 本课程将通过实际演示,教授学员如何利用真实世界的渗透测试方法来识别和测试网站的安全漏洞。与传统的、侧重理论且需要配置虚拟机才能学习的道德黑客课程不同,本课程旨在通过一种更具探索性和挑战性的方式,让任何人都能轻松地按照自己的节奏学习。 课程将重点讲解网站的常见顶级漏洞,包括: * **注入漏洞 (Injection Flaw):** 深入探讨 SQL 注入,包括手动和自动化工具的应用。 * **身份验证漏洞 (Authentication Flaw):** 学习如何使用“Magic Strings”方法绕过身份验证。 * **文件包含漏洞 (File Inclusion Flaw):** 分析和测试本地文件包含 (LFI) 漏洞,并深入理解其工作原理。 * **业务逻辑漏洞 (Business Logic Bugs):** 重点讲解影响用户及其信息的 IDOR 漏洞。 * **Bash 漏洞 (Bash Vulnerability):** 演示 Linux Bash Shell 中著名的“Shellshock”漏洞及其对网站的影响。 本课程将提供比传统课程和书籍更生动有趣的学习体验,适合那些渴望学习真实网络安全知识的学习者。 **课程大纲:** 无
In this course, I will practically demonstrate that how you can identify and test the security bugs of a website using real world pentesting methodologies. Typically, ethical hacking is taught by installing virtual machines on your PC and focused on more theory. This style of learning stops your exploration as there are no challenges. So what's next ? I have designed this course in a very easy way that anyone can start learning at their own pace and ease.This course is Mainly focused on many well known top vulnerabilities of a website including ;Injection Flaw: We will discuss Sql Injection in detail which is a very common website flaw both manually or using automated toolsAuthntication Flaw: We will look at Authentication Bypassing flaw using Magic Strings methodFile Inclusion Flaw: We will test LFI bug and try to understand its logics in detailBusiness Logic Bugs: We will cover an IDOR Vulnerability which effects on website users and their informationBash Vulnerability: We will see a very famous Bug of a Linux bash shell "Shellshock" and see its impact on a website Taking this course is much more fun & exciting than learning all of these in a traditional boring way - like through formal IT courses and books. So if you have a serious level of spark in learning the real knowledge then you are landed on a right course...Happy Learning!!!