|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/thick-client-pentest-modern-approaches-2024complete-guide/
课程评论:没有评论
课程名称:厚客户端渗透测试:现代方法 2024(完整指南) 课程概述: Namaste!! 这门课程旨在与社区分享厚客户端渗透测试的知识,并不单纯是教学。我们将从理解厚客户端的概念开始,逐步深入到厚客户端渗透测试的各个方面,包括如何截获和分析其安全性。 在课程中,网络安全专业人员(通常称为道德黑客或渗透测试者)将模拟现实世界的攻击,以识别应用程序中的漏洞、弱点和潜在的安全风险。渗透测试过程通常结合手动测试和专业工具的使用,分析应用程序的代码、通信协议、数据处理机制及其他组件。 课程内容将涵盖以下工具的演示: - Echo Mirage - Javasnoop - jadx - MITM-Relay - Sysinternal-suite/strings64.exe - Wireshark - Dnspy/Dot Peek/VB decompiler/ILspy - Fiddler - JD-GUI - Nmap - Sysinternal-suite Meterpreter - Winhex - Impulsive DLL/Auditor/DLL SPY - Process hacker - HxD hex editor - Snoop - WinSpy++/Windows detective - Uispy - Regshot - 以及更多 这些安全工具各自功能不同,使我们能够采用现代的方法和各种技术,识别厚客户端应用中的弱点。通过综合使用这些工具,我们可以进行全面的安全评估,并应用先进的方法确保对应用程序安全态势的彻底检查。
Namaste!!I have prepared the course to share my knowledge with my community. My intention is not to teach but to share the knowledge of Thick Client pen-testing. We will start by understanding what a Thick Client is and then progress towards mastering Thick Client pen-testing, including how to intercept and analyze its security. Thick client pen-testing, cybersecurity professionals, often known as ethical hackers or penetration testers, simulate real-world attacks to identify vulnerabilities, weaknesses, and potential security risks in the application. The process typically involves a combination of manual testing and the use of specialized tools to analyze the application's code, communication protocols, data handling mechanisms, and other components.While we cover the Thick Client Pentest, we will see the demo on the below tools.Echo MirageJavasnoopJadxMITM-RelaySysinternal-suite/strings64.exeWiresharkDnspy/ Dot Peek/ VB decompiler/ ILspyFiddlerJD-GUINmapSysinternal-suite Meterpreter WinhexImplusive DLL/ Auditor/ DLL SPYProcess hackerHxD hex editorSnoopWinSpy++/Windows detective UispyRegshot Many more.The listed security tools function differently, allowing us to adopt a modern approach and utilize various techniques to identify weaknesses within thick client applications. Through their combined usage, we can perform comprehensive assessments and apply advanced methodologies to ensure a thorough examination of the application's security posture.