Web Security: Common Vulnerabilities And Their Mitigation

所在平台: Udemy

课程主页: https://www.udemy.com/course/web-security-common-vulnerabilities-and-their-mitigation/

课程评论:没有评论

第一个写评论        关注课程

课程简介

课程名称:网络安全:常见漏洞及其缓解 课程概述:本课程旨在帮助您为网站“穿上盔甲”,保护自己免受最常见的威胁和漏洞。通过实例,理解常见安全攻击的工作原理及其缓解措施,学习安全实践以确保网站用户的安全。 课程内容: - 了解常见安全攻击如何运作,包括跨站脚本(XSS)、跨站请求伪造(XSRF)、会话劫持、直接对象引用等诸多攻击方式。 - 学习如何缓解这些风险,这是网络开发者的核心职责。通过示例,掌握防止脚本注入、使用安全令牌缓解XSRF风险、管理会话和Cookie、对输入进行清理和验证、通过哈希和加密安全管理凭证等技术。 - 探索需要遵循的安全实践,包括现代浏览器提供的保护措施和风险缓解策略,以及如何限制网站暴露的表面面积。 课程包含的主题: - 网络安全攻击:跨站脚本、会话劫持、凭证管理、跨站请求伪造、SQL注入、直接对象引用、社会工程学等。 - 风险缓解技术:使用内容安全策略头、用户输入验证与清理、安全令牌验证、沙盒iframe、安全会话和过期管理、密码恢复等。 - 网络安全基础知识:双因素认证、开放Web应用程序安全项目(OWASP)。 本课程适合希望提高网络应用安全性,了解最新安全攻击及防护措施的开发者及专业人士。

课程评论(0条)

课程详情

Coat your website with armor, protect yourself against the most common threats and vulnerabilities. Understand, with examples, how common security attacks work and how to mitigate them. Learn secure practices to keep your website users safe. Let's parse that. How do common security attacks work?: This course walks you through an entire range of web application security attacks, XSS, XSRF, Session Hijacking, Direct Object Reference and a whole lot more. How do we mitigate them?: Mitigating security risks is a web developer's core job. Learn by example how you can prevent script injection, use secure tokens to mitigate XSRF, manage sessions and cookies, sanitize and validate input, manage credentials safely using hashing and encryption etc. What secure practices to follow?: See what modern browsers have to offer for protection and risk mitigation, how you can limit the surface area you expose in your site. What's included in this course: Security attacks such as Cross Site Scripting, Session Hijacking, Credential Management, Cross Site Request Forgery, SQL Injection, Direct Object Reference, Social Engineering Risk mitigation using the Content Security Policy Header, user input validation and sanitization, secure token validation, sandboxed iframes, secure sessions and expiry, password recovery Web security basics: Two factor authentication, Open Web Application Security Project,

课程标签

0人关注该课程

主题相关的课程