OffSec - WEB200
WEB-200: Foundational Web Application Assessments with Kali Linux(線上課程及認證考試方案)
WEB-200: Foundational Web Application Assessments with Kali Linux
- 時數:0小時
- 費用:NT$ 57,570
- 點數:不適用企業點數
選擇查詢分區開課時間
地點 | 班號 | 日期 | 時間 | 預約 |
---|
目前查無開課時段
詳細開課時間請洽詢業務
新竹、台中、高雄如有上課需求,請參考台北開課日期,洽當地服務人員依需求加開遠距開課日期
教材
課程目標
Learn the foundations of web application assessments with Foundational Web Application Assessments with Kali Linux (WEB-200). Learners who complete the course and pass the exam will earn the OffSec Web Assessor (OSWA) certification and will demonstrate their ability to leverage web exploitation techniques on modern applications. This course teaches learners how to discover and exploit common web vulnerabilities and how to exfiltrate sensitive data from target web applications. Learners that complete the course will obtain a wide variety of skill sets and competencies for web app assessments.
線上課程方案介紹 (恆逸金銀卡會員另有優惠)
● Course & Cert Exam Bundle:NT57,570/一次性(含90天Lab與1次考試)
● Learn One: NT90,490/一年(含365天Lab與2次考試)
● Learn Unlimited:NT200,000/(含365天Lab與無限次考試)
適合對象
- Job roles like: Web Penetration Testers, Pentesters, Web Application Developers, Application Security Analysts, Application Security Architects, and SOC Analysts and other blue team members
- Anyone interested in expanding their understanding of Web Application Attacks, and/or Infra Pentesters looking to broaden their skill sets and Web App expertise
預備知識
- WEB-100: Web Application Basics
- WEB-100: Linux Basics 1 & 2
- WEB-100: Networking Basics
課程內容
- Introduction to WEB200
- Tools
- Cross-Site Scripting Introduction and Discovery
- Cross-Site Scripting Exploitation and Case Study
- Cross-Origin Attacks
- Introduction to SQL
- SQL Injection
- Directory Traversal Attacks
- XML External Entities
- Server-side Template Injection - Discovery and Exploitation
- Command Injection
- Server-side Request Forgery
- Insecure Direct Object Referencing
- Assembling the Pieces: Web Application Assessment Breakdown
學會技能
- Enumerate web applications and four common database management systems
- Manually discover and exploit common web application vulnerabilities
- Go beyond alert() and actually exploit other users with cross-site scripting
- Exploit six different templating engines, often leading to RCE
備註事項
報名請上OffSec全系列線上課程平台
推薦課程
相關連結
台北恆逸教育訓練中心
- 02-25149191
- 02-25149292
- 台北市松山區復興北路99號14樓
新竹恆逸教育訓練中心
- 03-5723322
- 03-5745738
- 新竹市光復路二段295號3樓之2
台中恆逸教育訓練中心
- 04-23297722
- 04-23102000
- 台中市西區臺灣大道二段309號2樓
高雄恆逸教育訓練中心
- 07-5361199
- 07-5361698
- 高雄市苓雅區新光路38號4樓之1