課程目錄: Web Security with the OWASP Testing Framework培訓(xùn)
4401 人關(guān)注
(78637/99817)
課程大綱:

        Web Security with the OWASP Testing Framework培訓(xùn)

 

 

Introduction

Exploring the OWASP Testing Project

Principles of testing
Testing techniques
Deriving security test requirements
Security tests integrated in development and testing workflows
Security test data analysis and reporting
Working with the OWASP Testing Framework

Phase 1: Before development begins
Phase 2: During definition and design
Phase 3: During development
Phase 4: During deployment
Phase 5: Maintenance and operations
A typical lifecycle testing workflow
Penetration testing methodologies
Testing the Web Application Security

Introduction and objectives
Information gathering
Conduct search engine discovery and reconnaissance for information leakage
Fingerprint web server
Review webserver metafiles for information leakage
Enumerate applications on webserver
Review webpage content for information leakage
Identify application entry points
Map execution paths through application
Fingerprint web application framework
Fingerprint web application
Map application architecture
Configuration and deployment management testing
Test network/infrastructure configuration
Test application platform configuration
Test file extensions handling for sensitive information
Review old, backup, and unreferenced files for sensitive information
Enumerate infrastructure and application admin interfaces
Test HTTP methods
Test HTTP strict transport security
Test RIA cross domain policy
Test file permission
Test for subdomain takeover
Test cloud storage
Identity Management Testing

Test role definitions
Test user registration process
Test account provisioning process
Testing for account enumeration and guessable user account
Testing for weak or unenforced username policy
Authentication Testing

Testing for credentials transported over an encrypted channel
Testing for default credentials
Testing for weak lock out mechanism
Testing for bypassing authentication schema
Testing for vulnerable remember password
Testing for browser cache weakness
Testing for weak password policy
Testing for weak security question answer
Testing for weak password change or reset functionalities
Testing for weaker authentication in alternative channel
Authorization Testing

Testing directory traversal/file include
Testing for bypassing authorization schema
Testing for privilege escalation
Testing for insecure direct object references
Session Management Testing

Testing for session management schema
Testing for cookies attributes
Testing for session fixation
Testing for exposed session variables
Testing for cross site request forgery
Testing for logout functionality
Testing session timeout
Testing for session puzzling
Testing for session hijacking
Input Validation Testing

Testing for reflected cross site scripting
Testing for stored cross site scripting
Testing for HTTP verb tampering
Testing for HTTP parameter pollution
Testing for SQL injection
Testing for Oracle
Testing for MySQL
Testing for SQL server
Testing for PostgreSQL
Testing for MS Access
Testing for NoSQL injection
Testing for ORM injection
Testing for Client-side
Testing for LDAP injection
Testing for XML injection
Testing for SSI injection
Testing for XPath injection
Testing for IMAP/SMTP injection
Testing for code injection
Testing for local file inclusion
Testing for remote file inclusion
Testing for command injection
Testing for format string injection
Testing for incubated vulnerability
Testing for HTTP splitting/smuggling
Testing for HTTP incoming requests
Testing for host header injection
Testing for server-side template injection
Testing for server-side request forgery
Testing for Error Handling

Testing for improper error handling
Testing for stack traces
Testing for Weak Cryptography

Testing for weak Transport Layer Security
Testing for padding Oracle
Testing for sensitive information sent via unencrypted channels
Testing for weak encryption
Business Logic Testing

Introduction to business logic
Test business logic data validation
Test ability to forge requests
Test integrity checks
Test for process timing
Test number of times a function can be used limits
Testing for the circumvention of work flows
Test defenses against application misuse
Test upload of unexpected file types
Test upload of malicious files
Client-Side Testing

Testing for DOM-based cross site scripting
Testing for JavaScript execution
Testing for HTML injection
Testing for client-side URL redirect
Testing for CSS injection
Testing for client-side resource manipulation
Testing cross origin resource sharing
Testing for cross site flashing
Testing for clickjacking
Testing WebSockets
Testing web messaging
Testing browser storage
Testing for cross site script inclusion
API Testing

Testing GraphQL
Reporting

Introduction
Executive summary
Findings
Appendices

主站蜘蛛池模板: 狠狠做五月深爱婷婷天天综合| 狠狠色丁香婷婷综合尤物| 狠狠人妻久久久久久综合蜜桃| 丁香婷婷色五月激情综合深爱| 亚洲国产综合专区电影在线| 色综合久久久久无码专区| 欧美一区二区三区综合| 五月天激情综合网丁香婷婷| 久久综合亚洲欧美成人| 久久青青草原综合伊人| 91精品欧美综合在线观看| 伊人久久大香线蕉综合热线| 丁香婷婷色五月激情综合深爱| 精品综合久久久久久97超人| 日日狠狠久久偷偷色综合免费| 亚洲人成伊人成综合网久久久| 久久久久久久综合综合狠狠| 狠狠色丁香婷婷综合尤物| 日韩欧美亚洲综合久久影院Ds| 色爱无码AV综合区| 欧美日韩综合在线| 国产成+人+综合+亚洲欧美| 伊人色综合一区二区三区| 久久综合五月丁香久久激情| 亚洲欧美日韩综合在线观看不卡顿| 亚洲成A人V欧美综合天堂麻豆| 狠狠色丁香婷婷综合尤物| 亚洲国产天堂久久综合| 人人妻人人狠人人爽天天综合网| 亚洲香蕉网久久综合影视| 欧美日韩国产综合视频一区二区三区| 大香网伊人久久综合网2020| 亚洲日本国产综合高清| 国产精品亚洲综合久久| 色欲香天天综合网无码| 婷婷五月综合色视频| 国产精品综合久成人| 97久久婷婷五月综合色d啪蜜芽| 久久91精品久久91综合| 一本久久a久久精品综合夜夜| 色综合网天天综合色中文男男|