|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/web-application-penetration-testing-v31-bug-hunting/
课程评论:没有评论
课程名称:网页应用渗透测试与安全 概述:本课程提供高水平的实践训练,专注于网页应用渗透测试,涵盖了OWASP十大漏洞的攻击与防护。课程结合了进攻性黑客使用的最先进技术,通过剖析和保护网页应用的安全性来进行学习。课程内容从网页技术的基本术语(如HTTP cookies、CORS、同源策略等)开始,最终提供了多种资源。 第二模块专注于应用程序的安全脆弱性映射,使用各种工具和技巧,重点使用最先进的拦截代理工具“Burp Suite”。主要讨论严重的漏洞,如SQL注入、跨站脚本(XSS)、跨站请求伪造(CSRF)、XML外部实体(XXE)攻击、远程命令执行、识别负载均衡器、Metasploit针对网页应用的使用、高级钓鱼攻击等。 培训方法:每节课以寻找和猎捕漏洞为开端,关注开发者在开发网页应用时是如何制作与确保安全的。一旦掌握了开发阶段到安全的清晰路径,便进入应用程序商业逻辑的攻击策略。这是许多渗透测试人员失败的地方。课程强调的策略是“如果我需要六个小时砍倒一棵树,我会用四个小时来磨好我的斧头,剩下的两个小时来砍树。”本课程的内容依据我们的灰帽安全工作经验进行调整。 课程材料:提供离线PDF幻灯片,8小时以上的视频课件,自学模式的HTML/Flash,支持PC、平板电脑和智能手机访问,400多张PDF幻灯片。 课程大纲:无
This is highly practical and hands-on training for Web application penetration testing that covers the OWASP top 10 vulnerabilities to attack and secure. Combining the most advanced techniques used by offensive hackers to exploit and secure. [+] Course at a glance Starting with various terminologies of web technologies such as, HTTP cookies, CORS, Same-origin-policy etc and ends with multiple resources. Once you get sufficient insights of web technologies, the second module covers the, Mapping of application for insecurities, with various tools and tricks with heavy usage of most advanced intercepting proxy "Burp Suite". Mostly focused over serious vulnerabilities such as SQL Injection, Cross-site scripting, Cross-site request forgery, XML External Entity (XXE) attacks, Remote command Execution, Identifying load balancers, Metasploit for web applications, Advanced phishing attacks through XSS and more.. [+] Training Methodology Every lesson starts with Finding and hunting for vulnerability by taking the points how developers make and secure the web application at the time of development, once we have the clear path of working of development phase to security, then we hunt for application business logics to attack. This is where most penetration testers failed in their own game. "If i need to chop down a tree in six hours, i will use four hours to sharpen my axe and rest 2 hours to cut the tree" The same strategy has been covered in this course. we start with getting around of web applications by making analysis of application and watching the working behavior of the same. #This course has been adapted from our work experience at gray hat security. [+] Course materials Offline access to read PDF slides 8+ Hours of Videos lessonsSelf-paced HTML/FlashAccess from PC, TABLETS, SMARTPHONES.400+ PDF Slides