OWASP Top 10: Comprehensive Web Application Security

所在平台: Udemy

课程主页: https://www.udemy.com/course/the-utlimate-guide-to-web-hacking-owasp-top-techniques/

课程评论:没有评论

第一个写评论        关注课程

课程简介

**课程名称:** OWASP Top 10:全面的 Web 应用程序安全 **课程概述:** 本课程将深入探讨 Web 应用程序最常见的十大攻击(OWASP Top 10)。您将学习这些漏洞是如何被利用的,并通过实践操作,掌握识别、利用和防御这些攻击的技巧。 **主要学习内容:** * **揭示 OWASP Top 10 攻击:** 详细了解每种攻击的原理、攻击手法及相关技巧。 * **实践操作:** 利用 **DVWA (Damn Vulnerable Web Application)** 和 **OWASP BWA (Broken Web Applications)** 等靶场,在真实环境中演练攻击过程,深入理解攻击的幕后机制。 * **信息收集:** 学习如何收集目标域信息,并寻找潜在的攻击目标。 * **渗透工具:** 熟悉 **Kali Linux** 发行版中常用的渗透测试工具,了解不同级别黑客使用的工具。 * **脚本编写:** 编写简单的脚本,为更高级的渗透测试和自定义工具开发打下基础。 * **常见攻击类型:** 重点学习 **SQL 注入、命令注入、跨站脚本 (XSS)、跨站请求伪造 (CSRF)、路径遍历、文件包含** 等多种攻击方式。 **重要声明:** 本课程仅用于教育目的。学员需自行承担使用课程技术和方法的风险。在未经授权的情况下,严禁将所学技术应用于非自有资产。作者不对任何非法使用行为承担任何法律责任。 **建议:** 如果您喜欢本课程,请给予好评并推荐给您的朋友和同事。

课程评论(0条)

课程详情

Welcome to "Ultimate Guide to Web Application Security OWASP Top Attacks"In this course, we will explore together the most common attacks against web applications, referred to as OWASP TOP 10, and learn how to exploit these vulnerabilities so that you have a solid background in order to protect your assets. You will:- Discover OWASP Top attacks and how they are performed and the tricks and techniques related to them.- Do extensive exercises on DVWA (Damn Vulnerable Web Application) and OWASP BWA (Broken Web Applications) to see in actual practice how to attack live systems and what goes on behind the scenes.- Learn to get information about a target domain and search for potential victims.- See the tools most used by hackers of all levels grouped in one place; the Kali Linux distribution.- Code some of your own scripts to get you started with advanced penetration where you will need to forge you own tools.Some of the attacks you'll see are: SQL Injection, Command Injection, Cross-site Scripting, Cross-sitr Request Forgery, Path Traversal, File Inclusion, etc.DISCLAIMER: This course is for educational purposes only. Use at your own risk. You must have an explicit authorization to use these techniques and similar ones on assets not owned by you. The author holds no legal responsibility whatsoever for any unlawful usage leveraging the techniques and methods described in this course.If you like the course, please give a rating and recommend to your friends and colleagues.

课程标签

0人关注该课程

主题相关的课程