|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/web-application-hacking-penetration-testing/
课程评论:没有评论
课程名称:网络应用程序黑客与渗透测试 课程概述:如果您正在寻找一个简洁明了的课程,涵盖网络应用程序中十大重要安全漏洞,那么您来对地方了!无论应用程序部署在云端、物理服务器还是虚拟机上,网络应用程序的漏洞都是存在的,这种安全风险不会因为云部署而消失。本课程侧重于实践学习和知识应用,包含了教程,教您如何在自己的机器上安装Xampp服务器和漏洞应用,以便您可以真正实践所学内容,而不仅仅是观看教程。许多课程主要关注如何利用物理服务器的漏洞,但随着云计算成为主流和物理服务器安全性的提升,学习这些技术可能不再那么有益。本课程涵盖以下OWASP十大网络应用程序安全风险:1. 注入(SQL注入、命令注入)2. 身份验证被破坏3. 敏感数据泄露4. XML外部实体(XXE)5. 访问控制破坏6. 安全配置错误7. 跨站脚本(XSS)8. 不安全的反序列化9. 使用已知漏洞的组件10. 不足的日志和监控。 本课程仅供教育目的。
If you are looking for a course that provides good coverage of the important top 10 security vulnerabilities in Web Applications in a short and concise way then you have come to the right place!! This course is relevant whether you are looking for application that are deployed on cloud or physical servers and VM's since the web application vulnerabilities don't magically disappear just because the application is deployed on the cloud.This course is focused on practical learning and applying your knowledge. To achieve that the course includes tutorial on how to install Xampp server and vulnerable applications on your machine so that you can practice what you are learning rather than just watch the tutorials.There are many courses which mainly focus on how to exploit the vulnerabilities of physical servers but with the cloud being the preferred way nowadays to deploy application and also with advances made in securing physical servers learning those techniques may not prove to be very advantageous. This course covers the below OWASP top 10 web application security risks - 1. Injection - SQL Injection, Command Injection2. Broken Authentication3. Sensitive Data Exposure 4. XML External Entities (XXE)5. Broken Access Control6. Security Misconfiguration7. Cross-Site Scripting (XSS)8. Insecure Deserialization9. Using Components with Known Vulnerabilities10. Insuffcient Logging and MonitoringThis course is for educational purposes only.