The Ultimate Web Application Bug Bounty Hunting Course

所在平台: Udemy

课程主页: https://www.udemy.com/course/the-ultimate-web-application-bug-bounty-hunting-course/

课程评论:没有评论

第一个写评论        关注课程

课程简介

课程名称:终极网络应用漏洞赏金猎人课程 课程概述:欢迎来到终极网络应用漏洞赏金猎人课程。这门课程的讲师是马丁·弗尔克(Martin Voelk),他是一位拥有25年网络安全经验的专家。马丁持有包括CISSP、OSCP、OSWP、Portswigger BSCP、CCIE、PCI ISA和PCIP等多个高端认证。他在一家大型科技公司担任顾问,同时参与漏洞赏金项目,发现了成千上万的重大和高危漏洞。在本课程中,马丁通过逐步的方法指导学生如何发现网络漏洞。理论课程结合相关的免费实践Burp实验室,以巩固知识。马丁不仅仅是输入有效负载,还详细解释每一步如何找到漏洞以及为何可以以特定方式利用它们。视频内容易于理解和跟随,适合任何希望成为专业网络应用漏洞赏金猎人的人。 课程大纲: 1. 跨站脚本(XSS) - 理论与实验 2. 跨站请求伪造(CSRF) - 理论与实验 3. 开放重定向 - 理论与实验 4. 绕过访问控制 - 理论与实验 5. 服务器端请求伪造(SSRF) - 理论与实验 6. SQL注入 - 理论与实验 7. 操作系统命令注入 - 理论与实验 8. 不安全的直接对象引用(IDOR) - 理论与实验 9. XML外部实体(XXE)注入 - 理论与实验 10. API测试 - 理论与实验 11. 文件上传漏洞 - 理论与实验 12. JavaScript分析 - 理论与实验 13. 跨源资源共享(CORS) - 理论与实验 14. 商业逻辑漏洞 - 理论与实验 15. 注册缺陷 16. 登录缺陷 17. 密码重置缺陷 18. 更新账户缺陷 19. 开发工具缺陷 20. 核心应用分析 21. 支付功能缺陷 22. 高级功能缺陷 23. 目录遍历 - 理论与实验 24. 查找大多数漏洞的方法论 25. Portswigger神秘实验室(在没有提示的应用程序上寻找漏洞) 备注与免责声明: Portswigger实验室是Portswigger提供的公共免费服务,任何人均可使用以提升技能。您只需注册一个免费账户。我会在合理的时间内回应问题。学习网络应用渗透测试/漏洞赏金猎人是一项漫长的过程,因此如果您没有立即找到漏洞,请不要感到沮丧。尽量利用Google,阅读Hacker One报告,并深入研究每个功能。本课程仅用于教育目的,所提供的信息不得用于恶意利用,仅可在您有权限攻击的目标上使用。

课程评论(0条)

课程详情

Welcome to the ultimate Web Application Bug Bounty Hunting course.Your instructor is Martin Voelk. He is a Cyber Security veteran with 25 years of experience. Martin holds some of the highest certification incl. CISSP, OSCP, OSWP, Portswigger BSCP, CCIE, PCI ISA and PCIP. He works as a consultant for a big tech company and engages in Bug Bounty programs where he found thousands of critical and high vulnerabilities.In this course Martin walks students through a step-by-step methodology on how to uncover web vulnerabilities. The theoretical lecture is complimented with the relevant free practical Burp labs to reinforce the knowledge. Martin is not just inserting the payload but explains each step on finding the vulnerability and why it can be exploited in a certain way. The videos are easy to follow along and replicate. This training is highly recommended for anyone who wants to become a professional Web Application Bug Bounty Hunter.Course outline:1. Cross-site scripting (XSS) - Theory and Labs2. Cross-site request forgery (CSRF) - Theory and Labs3. Open Redirect - Theory and Labs4. Bypassing Access Control - Theory and Labs5. Server-side request forgery (SSRF) - Theory and Labs6. SQL injection - Theory and Labs7. OS command injection - Theory and Labs8. Insecure Direct Object References (IDOR) - Theory and Labs9. XML external entity (XXE) injection - Theory and Labs10. API Testing - Theory and Labs11. File upload vulnerabilities - Theory and Labs12. Java Script analysis - Theory and Labs13. Cross-origin resource sharing (CORS) - Theory and Labs14. Business logic vulnerabilities - Theory and Labs15. Registration flaws16. Login flaws17. Password reset flaws18. Updating account flaws19. Developer tool flaws20. Analysis of core application21. Payment feature flaws22. Premium feature flaws23. Directory Traversal - Theory and Labs24. Methodology to find most bugs25. Portswigger Mystery Labs (finding bugs on applications without hints)Notes & DisclaimerPortswigger labs are a public and a free service from Portswigger for anyone to use to sharpen their skills. All you need is to sign up for a free account. I will to respond to questions in a reasonable time frame. Learning Web Application Pen Testing / Bug Bounty Hunting is a lengthy process, so please don't feel frustrated if you don't find a bug right away. Try to use Google, read Hacker One reports and research each feature in-depth. This course is for educational purposes only. This information is not to be used for malicious exploitation and must only be used on targets you have permission to attack.

课程标签

0人关注该课程

主题相关的课程