Learn Step by Step Web Hacking and Penetration Testing

所在平台: Udemy

课程主页: https://www.udemy.com/course/web-application-ethical-hacking/

课程评论:没有评论

第一个写评论        关注课程

课程简介

课程名称:逐步学习网络黑客与渗透测试 课程概述:为了保护自己免受黑客攻击,您需要以黑客的思维方式进行思考。本课程采用基于实际案例的培训,包含针对真实环境的实验室。您将作为初学者开始,没有有关渗透测试或黑客的先前知识。课程重点放在渗透测试的实践方面,同时不忽视每种攻击背后的理论。在进入渗透测试之前,您将首先学习如何建立实验室并安装所需软件,以便在自己的机器上练习渗透测试。课程的目标是帮助您掌握在渗透系统中使用的(道德)黑客技术和方法。本课程适合热爱IT的人员、网络和系统工程师、安全官员等。了解网站的工作原理后,我们将讨论如何利用这些组件。课程将从初学者引导到更高级别,使您能够发起攻击并测试网站和网络应用的安全性,并且您还将能够帮助修复这些漏洞,保护网站安全。 主要内容包括: - 核心问题(原因,防御) - 网络技术(HTTP协议,网络功能,编码) - 映射(蜘蛛抓取与分析) - 认证攻击(技术,缺陷,修复,暴力破解) - 会话管理攻击(状态,令牌,缺陷) - 访问控制攻击(常见漏洞,攻击) - 数据存储攻击(SQL注入,绕过过滤器,权限提升) - 绕过客户端控制(浏览器拦截,HTML拦截,修复) - 服务器攻击(操作系统命令注入,路径遍历,邮件注入,文件上传) - 应用逻辑攻击 - 跨站脚本攻击(XSS) - 用户攻击(CSRF,点击劫持,HTML注入) - OWASP十大漏洞 - 网络攻击 实验室项目包括: - 蜘蛛抓取与网站分析 - 暴力破解 - 会话劫持(中间人攻击) - 获取Gmail或Facebook密码(通过SSLStrip) - SQL注入 - 文件上传与远程执行 - 跨站脚本攻击(存储型+反射型,Cookie盗窃,防止XSS) - CSRF(通过CSRF漏洞更改密码,防止CSRF) 注意:本课程仅用于教育目的,所有攻击均在隔离的实验室环境中进行。

课程评论(0条)

课程详情

In order to protect yourself from hackers, you must think as one.This training is based on a practical approach of day-by-day situations and it contain labs based on real environments. In this course, you will start as a beginner with no previous knowledge about penetration testing or hacking.This course is focused on the practical side of penetration testing without neglecting the theory behind each attack. Before jumping into penetration testing, you will first learn how to set up a lab and install needed software to practice penetration testing on your own machine. The course objective is to help you learn to master the (ethical) hacking techniques and methodology that are used in penetration systems. The course is designed for IT passionate, network and system engineers, security officers. Once you understand how websites work we will start talking about how can we exploit these components. This course will take you from a beginner to a more advanced level - so you will be able to launch attacks and test the security of websites and web applications, and furthermore you'll be able to help fixing these vulnerabilities and secure websites from them. Below are the main topics, both theoretical and practical, of this course:Core problems (Causes. Defences)Web Technologies (HTTP Protocol, Web Functionality, Encoding)Mapping (Spidering and Analysing)Attacking Authentication (Technologies, Flaws, Fixes, Brute Force)Attacking Session Management (State, Tokens, Flaws)Attacking Access Controls (Common Vulnerabilities, Attacks)Attacking Data Stores (SQL Injection, Bypassing Filters, Escalation)Bypassing Client-Side Controls (Browser Interception, HTML interception, Fixes)Attacking the server (OS command Injection, Path Traversal, Mail Injection, File Upload)Attacking Application LogicCross Site ScriptingAttacking Users (CSRF, ClickJacking, HTML Injection)OWASP Top Ten VulnerabilitiesNetwork AttacksLabs:Spidering, Website Analyser Brute-ForceSession Hijacking via Mann-in-The-MiddleGet Gmail or Facebook Passwords via SSLStripSQL InjectionUpload File and Remote ExecutionCross-Site Scripting (Stored + Reflected, Cookie Stealing, Preventing XSS)CSRF (Change password trough CSRF vuln., Preventing CSRF)NOTE: This course is created only for educational purposes and all the attacks are launched in an isolated lab environment.

课程标签

0人关注该课程

主题相关的课程