|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/xss-attack-most-widespread-hacking-technique/
课程评论:没有评论
课程名称:XSS跨站脚本攻击 - 黑客技术 概述:跨站脚本(XSS)是一种存在已有几十年的黑客技术,至今仍在不断演变。它被认为是最常见的漏洞之一,长期以来一直位于OWASP前十名之内。在本课程中,您将学习如何通过手动代码注入测试Web应用程序中的跨站脚本脆弱性,涵盖各种XSS攻击(如更改内容、会话劫持等),并同时使用多种XSS有效载荷。课程将介绍基本的跨站脚本类型,包括持久性XSS、反射XSS和基于DOM的XSS,并解释如何通过解决当前一些互联网巨头的XSS挑战。 完成本课程后,您将能够畅通无阻地理解如何通过输入验证和输出转义来修复Web应用程序中的跨站脚本漏洞。虽然一般的黑客教程对于理解道德黑客和网络安全工作具有一定的帮助,但在简历中加入“初学者黑客”一项并不实际。然而,如果您认真学习本课程并深入理解跨站脚本的内容,您将获得一项有价值的网络安全技能,这对未来作为渗透测试员、网络安全顾问甚至Web开发者的简历都能有所加分。 本课程不仅旨在传授您关于XSS的知识,也希望引导您采用某种思维方式,以达成更好的结果。鉴于您选择了这个主题,我相信您已有坚实的互联网技术、HTML、JavaScript及一些服务器端编程语言的基础。 免责声明:未经过他方许可和同意使用本课程展示的技术,将面临刑事起诉,并可能根据您所在国的法律制度面临监禁处罚。
Cross Site Scripting or XSS is a hacking technique that exists for few decades now and that keeps on developing. It is considered to be the most common vulnerability that has been in the OWASP top 10 for years.Only here on Udemy!You will learn how to test web application for Cross Site Scripting manually by preforming code injection from the start, as well as performing various XSS attacks through different XSS examples (changing content, session hijacking, etc) by using various XSS payloads at the same time.We will go through basic types of Cross Site Scripting such as Stored XSS, Reflected XSS, Dom-Based XSS and we'll explain how you can pass through all of the XSS challenges from one of the biggest Internet companies of today.After this course you should be able to without any problems comprehend how to fix Cross Site Scripting vulnerabilities by using input validation and output escaping everywhere on the web application where it's necessary.Even though I believe that general Hacking Tutorials that cover different topics are quite good to understand what is Ethical Hacking in general and what cyber security jobs are all about, putting "Hacking for beginners" in your resume is not really an option. But if you pass this hacking course with attention and get a good understanding of what is Cross Site Scripting, you'll have a valuable cyber security skill under your belt that will look good in every resume of the future pen-tester, cyber security consultant, and even a web developer.In this course my intention is not only to pass you the knowledge about XSS, but to direct you to adopt a certain mindset that will lead you to results.Since you've decided for this subject, I guess you have a solid knowledge of Internet Technologies, HTML, JavaScript and some server side programming language.Disclaimer: Usage of techniques shown in this course without permit and consent of the other side will subject to criminal prosecution with potential jail penalty depending on the legal system of your country.