Unveiling Oauth for Bug Bounty Hunting

所在平台: Udemy

课程主页: https://www.udemy.com/course/unveiling-oauth-for-bug-bounty-hunting/

课程评论:没有评论

第一个写评论        关注课程

课程简介

课程名称:揭示OAuth在漏洞赏金狩猎中的应用 课程概述:OAuth是当今网络应用渗透测试、API安全测试和安卓安全测试中最重要的话题之一。它在几乎所有应用中被广泛使用,常见的漏洞如账户接管通常与OAuth配置错误相关。如果你不清楚如何进行OAuth测试,那么这门课程非常适合你。你将学习与OAuth相关的不同攻击类型及其相应的配置错误,以及如何将OAuth与其他漏洞进行链式利用。课程中通过PortSwigger实验室演示了OAuth配置错误,并讨论了来自漏洞赏金计划的实时发现。你也可以在自己的程序中找出类似的问题。 课程内容包括: - 什么是OAuth? - OAuth的类型 - OAuth的工作原理 - OAuth配置错误 - 在实验室和实际案例中展示账户接管的演示 - 使用Postman分析开发者文档中的OAuth流程 - 分析如何绕过一些限制,并与其他漏洞联动 - 理解从各种报告和文章中收集的商业逻辑配置错误 课程强调,教程仅用于教育目的,请勿在现实世界中滥用。

课程评论(0条)

课程详情

OAuth is one the most important topics nowadays if you study web applications penetration testing or API security testing or android security testing then OAuth is one of the most common topics, it is popularly used in almost every application, and vulnerabilities like account takeover are found in oauth misconfigurations, if you don't know how to go for oauth testing then this course is for you, you will be able to learn different types of attacks possible with oauth with respective misconfiguration and will learn how chaining can be done in oauth with other vulnerabilities, I have demonstrated the oauth misconfiguration using portswigger labs and also discussed the live finding from a bug bounty programme, you can also find similar issues on your programme as wellThis is a short course, in this course, you will be going to learn =>What is Oauth?Types of Oauth?How does Oauth work?What are oauth misconfigurations?Demonstrations of account takeovers on lab and live casesAnalysing oauth flow from developers docs using PostmanAnalysing how to bypass some of the restrictions and chaining oauth with other vulnerabilitiesUnderstanding more business logic misconfiguration collected from various reports and articles.Use the tutorials for education purposes only don't misuse them in the real worldThanks

课程标签

0人关注该课程

主题相关的课程