|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/the-ultimate-bac-and-idor-guide-for-ethical-hacking/
课程评论:没有评论
这是一门名为“终极 BAC 和 IDOR 指南,助力道德黑客”的 Coursera 课程。 **课程概述:** 本课程旨在深入探讨“修复的访问控制”(Broken Access Control, BAC)和“不安全的直接对象引用”(Insecure Direct Object Reference, IDOR)这两个概念。课程将提供一系列工具、方法论、技巧和窍门,帮助学习者提升在 BAC 方面的技能。 **讲师介绍:** 讲师 Wesley 拥有一家渗透测试公司,他在多年的实践中形成了自己独特的工作方式,尤其擅长跨站脚本(XSS)攻击,并对 BAC 和 IDOR 产生了浓厚的兴趣。他拥有丰富的教学经验,希望通过本课程将自己的知识传授给学习者,帮助他们快速成长,避免自己曾经历的弯路。 **课程面向对象:** * 初级黑客,希望学习新的漏洞利用类型。 * 中级黑客,希望深入研究 BAC 和 IDOR,并将其自动化或半自动化地寻找。 **为何学习 BAC?** BAC 是 OWASP Top 10 - 2021 中最常见的漏洞类型。它看似易于利用,但实际上背后存在更深层次的复杂性。讲师在漏洞赏金(bug bounty)实践中发现,BAC 漏洞极为普遍,他希望通过教授大家如何使用不同工具来发现和利用这类漏洞,从而降低其普遍性。
First of all, we have to start by explaining to you what is in this course. You might have heard of the terms Broken Access Control (BAC) and Insecure Direct Object Reference (IDOR) before, but do you really understand what it is all about? In this course, we are going to go through a list of tools, methodologies, tips, and tricks that will help you level up your BAC game.Who am I? My name is Wesley, I own a pen testing company and throughout the years I have had to design my own way of working. This has led me to my favorite issue type XSS but it also came with a surprising exploit type I turned out to adore! I am of course talking about BAC and IDOR. With several years of teaching experience, I wanted to build a course to pass my knowledge on to you and to help you grow without having to go through the same growing pains I experienced. Who is this course for? If you are a beginner hacker who is looking to add a new exploit type to their repertoire or even a medior hacker who wants to further explore BAC and IDOR to the point of automation/semi-automating the search for the noble exploit type of BAC. Why BAC?Why BAC? Because it's the most common exploit type of the OWASP top 10 - 2021 of course! This deceptively difficult exploit pulls you in with its allure of easy exploitation but you will soon realize there is much more than just the surface-level exploits you have to take into account. In my bug bounty journey, I have seen how incredibly common this exploit type is and I hope to bring down its prevalence by teaching you how to find and exploit this bug with different tools.