|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/web-application-security-for-absolute-beginners-no-coding/
课程评论:没有评论
课程名称:绝对初学者的OWASP前10名网络应用安全 概述:本课程为您提供即时访问课程幻灯片、免费的扫描网站资源以及易于理解的教学视频。如果您在学习过程中遇到困难,可以随时向教员寻求帮助。在1.5小时内,您将能够解释网络应用安全,而无需编写代码。课程将OWASP 2013和2017的前10名威胁合并为一份常见的网络应用安全威胁清单,并更新了2021年OWASP新增的威胁。您将学习开放Web应用安全项目(OWASP)识别的最常见威胁,此课程将为您的网络安全职业生涯提供良好的开端。 课程内容包括: 1) 理解OWASP前10名威胁 2) 解释每个安全威胁的影响 3) 理解这些威胁如何被攻击者、渗透测试者或黑客执行 4) 解释如何减轻这些安全威胁 您将无需懂得编码便能掌握上述要点。正确实施后,可以减少勒索软件的影响。课程对威胁的解释是概念性的,因为威胁的实施可能因情况而异。因此,了解安全威胁、其影响及潜在解决方案,将为您提供减轻网络应用安全威胁影响的必要知识。 课程内容(内容将持续更新): - 注入 - 破坏身份认证与会话管理 - 跨站脚本(XSS) - 破坏访问控制 - 安全配置错误 - 敏感数据泄露 - 不足的攻击保护 - 跨站请求伪造 - 使用已知漏洞的组件 - 保护不足的API - XML外部实体(XXE) - 不安全的反序列化 - 不足的日志记录与监控 - 加密失败 - 不安全设计 - 软件与数据完整性失败 - 服务器端请求伪造 讲师承诺: 我是全职的首席信息安全官(CISO)和网络安全顾问,已有十年以上的教学与咨询经验。我会全程支持您。如果您有任何关于课程内容或相关主题的问题,可以直接联系我。 关于讲师: 我的名字是Soerin,曾为多个大型荷兰组织担任CISO,并教导超过90,000名在线学生和2,000名离线学生,收获了数百条5星好评。 课程提供30天无条件退款保证,确保您对购买的满意。如果您不满意,我将全额退款,无需询问任何原因。 现在就注册,跟我一起更好地理解网络应用安全,预防勒索软件的发生!期待在课程中见到您!
+ Get instant access to course slides!+ Get instant access to FREE resources to scan your website+ Easy to understand how-to videos!+ Access to instructor if you ever get stuck!Within 1,5 hour you will be able to explain web application security without having to code. For your convenience: I've combined the OWASP 2017 and OWASP 2013 top 10 list into a single list of 10 common web application security threats.I've updated the course with the latest threats added by OWASP in 2021.I will teach you the most common threats identified by the Open Web Application Security Project (OWASP). This course will jumpstart your cyber security career! Overview1) Understand the OWASP top 10, 2) Explain impact per security threat, 3) Understand these threats can be executed by attackers / pentesters / hackers 4) Explain how these security threats can be mitigated You will be able to understand the above-mentioned points without having to understand code. When implemented properly, it will decrease the impact of ransomware. How is that possible?The threats are explained conceptually, since the implementation of a threat may differ per situation. Therefore, having a general understanding of the security threats, its implications and potential solutions will provide you with the essential knowledge to mitigate the impact of these web application security threats. Hence, no security coding or security testing experience needed.Content (the course is updated continuously thus this list will grow!)InjectionBroken Authentication and Session ManagementCross-Site ScriptingBroken Access ControlSecurity MisconfigurationSensitive Data ExposureInsufficient Attack ProtectionCross-Site Request ForgeryUsing Components with Known VulnerabilitiesUnderprotected APIsXML External Entities (XXE)Insecure DeserialisationInsufficient logging and monitoringCryptographic FailuresInsecure Design Software and Data Integrity Failures Server-Side Request Forgery My Promise to YouI'm a full time CISO / cyber security consultant and online teacher. I'll be here for you every step of the way. If you have any questions about the course content or anything related to this topic, you can send me a direct message.What makes me qualified to teach you?My name is Soerin and I've been a cyber security consultant and teacher of cyber security for over a decade. I teach over 90,000 students online, 2.000 offline and have accumulated hundreds of 5-star reviews like these:"I really like this format of short videos followed by a couple of questions, it is certainly my favorite way to learn." Camilla from Brazil "Really great structure, I love the "What is it?" -> "what is the impact?" -> "prevention tactics" aspect of it because it allows for a much more easy to follow course." Jason from USA"Great resources and very time-efficient. No extra unnecessary stuff, just the main points!" Emma from UKBesides experience as a Chief Information Security Officer (CISO) at several large Dutch organisations I hold the following certifications: Togaf FoundationCertified Information Systems Auditor (CISA)ISO 27001 Lead AuditorISO 27001 Lead ImplementerLeading Scaled Agile FrameworkCertified Information Systems Security Professional (CISSP)Certified Information Privacy Professional (CIPP / Europe)Certified SCRUM MasterCertified Secure Software Lifecycle professional (CSSLP)Azure Fundamentals (AZ-900)PRINCE 2 foundationInternational Software Testing Qualifications Board (ISTQB)I have a 30-day 100% money back guarantee, so if you aren't happy with your purchase, I will refund your course - no questions asked!I can't wait to see you in the course!Keep learning about Cyber Security to prevent Ransomware from the perspective of a CISO!Enrol now, and I'll help you in your journey understanding Web Application Security better than ever before!Cheers,Soerin