Practical Bug Bounty - Web Application Security and Penetration Testing
Offered By: Cyber Mentor via YouTube
Course Description
Overview
Syllabus
- Intro
- Keeper Security Sponsorship
- Course Introduction
- Importance of Web App Security
- Web App Security Standards and Best Practices
- Bug Bounty Hunting vs Penetration Testing
- Phases of a Web App Pentest
- CryptoCat Introduction
- Understanding Scope, Ethics, Code of Conduct, etc.
- Common Scoping Mistakes
- Installing VMWare / VirtualBox
- Installing Linux
- Lab Installation
- Web Technologies
- HTTP & DNS
- Fingerprinting Web Technologies
- Directory Enumeration and Brute Forcing
- Subdomain Enumeration
- Burp Suite Overview
- Introduction to Authentication
- Brute-force Attacks
- Attacking MFA
- Authentication Challenge Walkthrough
- Intro to Authorization
- IDOR - Insecure Direct Object Reference
- Introduction to APIs
- Broken Access Control
- Testing with Autorize
- Introduction to LFI/RFI
- Local File Inclusion Attacks
- Remote File Inclusion Attacks
- File Inclusion Challenge Walkthrough
- Conclusion
Taught by
The Cyber Mentor
Related Courses
Network SecurityGeorgia Institute of Technology via Udacity Proactive Computer Security
University of Colorado System via Coursera Identifying, Monitoring, and Analyzing Risk and Incident Response and Recovery
(ISC)² via Coursera Hacker101
HackerOne via Independent CNIT 127: Exploit Development
CNIT - City College of San Francisco via Independent