|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/tryhackmeweb-fundamentalshacking-web-applicationsarabic/
课程评论:没有评论
课程名称:THM: Bug Bounty (阿拉伯语) 课程概述: 本课程旨在教授学员如何攻击 Web 应用程序。要成功攻击和利用 Web 应用程序,首先需要理解其工作原理。 课程内容分为四个主要部分: 1. **Web 基础知识 (Web Fundamentals)**:提供所有必需的先备知识,帮助学员理解 Web 应用程序的运作方式。 2. **安全工具 (Security Tools)**:重点学习如何使用行业标准的工具与目标进行交互。 3. **漏洞 (Vulnerabilities)**:涵盖当前 Web 应用程序中存在的各种漏洞,深入探讨其根本原因,并提供实际的利用体验。 4. **熟能生巧 (Practise Makes Perfect)**:帮助学员巩固和应用前几个部分所学知识。 完成本课程后,学员将能够: * 理解 Web 应用程序的工作原理。 * 在攻击 Web 应用程序时运用行业标准工具。 * 解释并利用常见的 Web 漏洞。 * 将所学知识应用于其他目标,例如面试或专业的 Web 应用程序安全评估。 此外,学员还将学习: * DNS 的工作原理及其在访问互联网服务中的作用。 * 如何使用 HTTP 协议从 Web 服务器请求内容。 * 仅使用浏览器开发者工具手动审查 Web 应用程序的安全问题(不依赖任何工具或脚本)。 * 发现 Web 服务器上隐藏或私有内容的不同方法,这些方法可能导致新的漏洞。
The aim of this course is to teach you how to attack web applications. To successfully attack and exploit web applications, you need to understand how they work. The first section (Web Fundamentals) will give you all the pre-requisite knowledge on this.The second section (Security Tools) focuses on learning how to use Industry Standard tooling to interact with your targets.The third section (Vulnerabilities) covers various vulnerabilities found in web applications today. This section will go over root causes of these vulnerabilities and give you hands on experience on exploiting them.The final section (Practise Makes Perfect) will help you apply what you've learnt in previous sections.After completing this course, you should be able to:understand how web applications workutilise industry standard tooling when attacking web applicationsexplain and exploit common web vulnerabilitiesapply this knowledge to other targets (be it within an interview or a professional web applications security assessment)Learn how DNS works and how it helps you access internet services.Learn about how you request content from a web server using the HTTP protocolManually review a web application for security issues using only your browsers developer tools. Hacking with just your browser, no tools or scripts.Learn the various ways of discovering hidden or private content on a webserver that could lead to new vulnerabilities.