Web Application Pentest Assessment (WAPA) [Arabic]

所在平台: Udemy

课程主页: https://www.udemy.com/course/web-application-pentest-assessment-wapa-arabic/

课程评论:没有评论

第一个写评论        关注课程

课程简介

课程名称:网络应用渗透测试评估(WAPA) [阿拉伯语] 课程概述: 网络应用渗透测试评估(WAPA)是一个实践性强的课程,旨在教授学员如何发现、评估、利用和修复各种网络应用程序的漏洞。该课程专为初学者设计,适合对网络安全特别是网络应用渗透测试感兴趣的学习者。无论您是网络安全领域的从业者,还是IT专业人员、计算机科学学生、网络开发人员或技术爱好者,WAPA都能满足您的需求。课程以阿拉伯语授课,为具有基本Linux背景但无须具备网络开发背景的初学者量身定制。 课程内容: WAPA课程深入涵盖OWASP网络应用程序十大漏洞,并对每种漏洞提供不同的缓解建议。课程主要包括以下主题: - 虚拟化与Kali Linux - OSI模型层 - 网络基础设施 - 前端与后端的区别 - HTTP请求与响应 - 拦截技术(Burp Suite) - 同源策略(SOP) - Cookies与会话管理 - 内容管理系统(CMS) - OWASP框架 - 暴力破解与字典攻击 - 加密、解密、哈希、HMAC、编码、解码与数字签名 - SQL注入(基于错误和盲注) - XSS攻击(反射型、存储型和DOM型) - 命令注入 - 认证攻击 - 授权攻击 - 会话管理攻击 - JWT攻击 - 路径遍历攻击 - 本地文件包含(LFI) - 远程文件包含(RFI) - 不受限制的文件上传 - 渗透测试方法论 - CVSS v3评分系统 - 渗透测试报告撰写 课程结尾,学员将能够进行实际的网络渗透测试,并交付一份专业的渗透测试报告。

课程评论(0条)

课程详情

Web Application Pentest Assessment (WAPA) is a hands-on course that you will learn how to discover, assess, exploit and remediate a lot of web application vulnerabilities.WAPA is for beginner-levels only who is passionate about learning and digging more into cyber security specially in web application penetration testing track.WAPA is Arabic-spoken course carefully designed for beginners with fair Linux background and NO web development background needed.WAPA is not only for cybersecurity guys but also for IT professionals, computer science students, web developers and techy geeks.WAPA is hands-on course covers most of OWASP web application Top 10 vulnerabilities with different mitigation recommendations for each discovered vulnerabilities discussed through the course.WAPA covers the following topics:Virtualization Kali LinuxOSI layersWeb infrastructureFront-end vs. Back-endHTTP requests and responsesInterception (Burp Suite)SOPCookies & sessionsSession managementContent Management System (CMS)OWASPBrute-force and dictionary attacksEncryption, decryption, hashing, HMAC, encoding, decoding and digital signatureSQL injection (Error-based, blind-based)XSS attack (Reflected, Stored and DOM-based)Command injectionAuthentication attacksAuthorization attacksSession management attacksJWT attacksPath traversal attackLocal File Inclusion (LFI)Remote File Inclusion (RFI)Unrestricted file uploadPenetration testing methodologyCVSS v3 scoring systemPenetration testing reportingAt the end of the course you will be able to conduct real-world web penetration testing engagement and deliver a professional penetration testing report.

课程标签

0人关注该课程

主题相关的课程