YoVDO

Practical Bug Bounty - Web Application Security and Penetration Testing

Offered By: Cyber Mentor via YouTube

Tags

Bug Bounty Courses Penetration Testing Courses Burp Suite Courses Web Application Security Courses Subdomain Enumeration Courses

Course Description

Overview

Save Big on Coursera Plus. 7,000+ courses at $160 off. Limited Time Only!
Dive into a comprehensive 4-hour 46-minute video course on practical bug bounty hunting. Learn essential web application security concepts, including authentication attacks, authorization vulnerabilities, and file inclusion exploits. Explore the differences between bug bounty hunting and penetration testing, understand scoping and ethics, and gain hands-on experience with tools like Burp Suite. Master techniques for fingerprinting web technologies, directory enumeration, and subdomain discovery. Complete practical challenges and walkthroughs to reinforce your skills in identifying and exploiting common web vulnerabilities.

Syllabus

- Intro
- Keeper Security Sponsorship
- Course Introduction
- Importance of Web App Security
- Web App Security Standards and Best Practices
- Bug Bounty Hunting vs Penetration Testing
- Phases of a Web App Pentest
- CryptoCat Introduction
- Understanding Scope, Ethics, Code of Conduct, etc.
- Common Scoping Mistakes
- Installing VMWare / VirtualBox
- Installing Linux
- Lab Installation
- Web Technologies
- HTTP & DNS
- Fingerprinting Web Technologies
- Directory Enumeration and Brute Forcing
- Subdomain Enumeration
- Burp Suite Overview
- Introduction to Authentication
- Brute-force Attacks
- Attacking MFA
- Authentication Challenge Walkthrough
- Intro to Authorization
- IDOR - Insecure Direct Object Reference
- Introduction to APIs
- Broken Access Control
- Testing with Autorize
- Introduction to LFI/RFI
- Local File Inclusion Attacks
- Remote File Inclusion Attacks
- File Inclusion Challenge Walkthrough
- Conclusion


Taught by

The Cyber Mentor

Related Courses

Introduction to OWASP Top 10 Security Risks
A Cloud Guru
AWS SimuLearn: Cyber Security Threats
Amazon Web Services via AWS Skill Builder
AWS SimuLearn: Edge Protection
Amazon Web Services via AWS Skill Builder
Cloud Security Scanner: Qwik Start
Google via Google Cloud Skills Boost
OWASP Top 10: Broken Access Control
Codecademy