Learn Bug Bounty Hunting & Web Security Testing From Scratch
Год выпуска: 1/2025
Производитель: Udemy
Сайт производителя:
https://www.udemy.com/course/learn-bug-bounty-hunting-web-security-testing-from-scratch/
Автор: Zaid Sabih, z Security
Продолжительность: 11h 3m 52s
Тип раздаваемого материала: Видеоурок
Язык: Английский
Субтитры: Английский
Описание:
Learn how to discover bugs / vulnerabilities like experts | OWASP top 10 + more | No prior knowledge required
What you'll learn
- 95+ videos to teach you bug hunting & security testing from scratch.
- 80+ hands-on real-life examples - from simple to advanced.
- Discover the most common web application bugs and vulnerabilities.
- Discover bugs from the OWASP top 10 most common security threats.
- Bypass filters & security on all of the covered bugs & vulnerabilities.
- 2 Hour LIVE bug hunt / pentest on a real web application at the end of the course.
- My approach to bug hunting and web application penetration testing.
- The bug hunter / hacker mentality.
Requirements
- Basic IT Skills
- No prior knowledge required in bug hunting, hacking or programming.
- Computer with a minimum of 4GB ram/memory.
- Operating System: Windows / Apple Mac OS / Linux.
Description
Welcome to my comprehensive course on Bug Bounty Hunting & Web Security Testing course. This course assumes you have
NO prior knowledge, it starts with you from scratch and takes you
step-by-step to an advanced level, able to discover a large number of bugs or vulnerabilities (including the
OWASP top 10) in any web application regardless of the technologies used in it or the cloud servers that it runs on.
This course is highly
practical but doesn't neglect the theory, we'll start with basics to teach you how websites work, the technologies used and how these technologies work together to produce these nice and functional platforms that we use everyday. Then we'll start hacking and bug hunting straight away. You'll
learn everything by example, by discovering security bugs and vulnerabilities, no boring dry lectures.
The course is divided into a number of sections, each aims to teach you a common security bug or vulnerability from the OWASP top 10 most common security threats. Each section takes you through a number of
hands-on examples to teach you the cause of the security bug or vulnerability and how to discover it in a number of scenarios, from
simple to advanced. You'll also learn
advanced techniques to bypass filters and security measures. As we do this I will also introduce you to different hacking and security concepts, tools and techniques. Everything will be taught through examples and hands-on practicals, there will be no useless or boring lectures!
At the end of the course I will take you through a
two hour pentest or bug hunt to show you how to combine the knowledge that you acquired and employ it in a real-life scenario to discover bugs and vulnerabilities in a real website! I will show you how I approach a target, analyse it, and take it apart to discover bugs and vulnerabilities in features that most would think are secure!
As mentioned you'll learn much more than just how to discover security bugs in this course.
Here's a list of the main security bugs and vulnerabilities that will be covered in the course:
- Information Disclosure.
- IDOR (Insecure Direct Object Reference).
- Broken Access Control .
- Directory / Path Traversal.
- Cookie Manipulation.
- CSRF (Client-Side Request Forgery).
- OAUTH 2.0.
- Injection Vulnerabilities.
- Command Injection.
- Blind Command Injection.
- HTML Injection.
- XSS (Cross-Site Scripting).
- Reflected, Stored & DOM Based XSS.
- Bypassing Security Filters.
- Bypassing CSP (Content Security Policy).
- SQL Injection.
- Blind SQLi.
- Time-based Blind SQLi.
- SSRRF (Server-Side Request Forgery).
- Blind SSRF.
- XXE (XML External Entity) Injection.
Topics:
- Information gathering.
- End point discovery.
- HTTP Headers.
- HTTP status codes.
- HTTP methods.
- Input parameters.
- Cookies.
- HTML basics for bug hunting.
- Javascript basics for bug hunting.
- XML basics for bug hunting.
- Filtering methods.
- Bypassing blacklists & whitelists.
- Bug hunting and research.
- Hidden paths discovery.
- Code analyses .
You'll use the following tools to achieve the above:
- Ferox Buster .
- WSL .
- Dev tools.
- Burp Suite:
- Basics.
- Burp Proxy.
- Intruder (Simple & Cluster-bomb).
- Repeater.
- Collaborator.
With this course you'll get 24/7 support, so if you have any questions you can post them in the Q&A section and we'll respond to you within 15 hours.
Checkout the curriculum and the course teaser for more info!
Who this course is for:
- Anybody looking to become a bug bounty hunter.
- Anybody interested in web application hacking / penetration testing.
- Anybody interested in learning how to secure websites & web applications from hackers.
- Web developers so they can create secure web application & secure their existing ones.
- Web admins so they can secure their websites.
Формат видео: MP4
Видео: avc, 1280x720, 16:9, 30.000 к/с, 3000 кб/с
Аудио: aac lc, 48.0 кгц, 128 кб/с, 2 аудио
Изменения/Changes
Version 2023/10 compared to 2022/10 has increased the number of 1 lesson and the duration of 7 minutes. English subtitles have also been added to the course.
The 2025/1 version has not changed in terms of the number of lessons and duration compared to 2023/10, but it has been updated after 2 years.
MediaInfo
General
Complete name : D:\2_1\Udemy - Learn Bug Bounty Hunting & Web Security Testing From Scratch (1.2025)\07. Injection Vulnerabilities\1. Introduction to Injection Vulnerabilities.mp4
Format : MPEG-4
Format profile : Base Media
Codec ID : isom (isom/iso2/avc1/mp41)
File size : 29.9 MiB
Duration : 1 min 21 s
Overall bit rate : 3 089 kb/s
Frame rate : 30.000 FPS
Writing application : Lavf58.12.100
Video
ID : 1
Format : AVC
Format/Info : Advanced Video Codec
Format profile : Main@L3.1
Format settings : CABAC / 4 Ref Frames
Format settings, CABAC : Yes
Format settings, Reference frames : 4 frames
Codec ID : avc1
Codec ID/Info : Advanced Video Coding
Duration : 1 min 21 s
Bit rate : 3 000 kb/s
Width : 1 280 pixels
Height : 720 pixels
Display aspect ratio : 16:9
Frame rate mode : Constant
Frame rate : 30.000 FPS
Color space : YUV
Chroma subsampling : 4:2:0
Bit depth : 8 bits
Scan type : Progressive
Bits/(Pixel*Frame) : 0.109
Stream size : 28.6 MiB (96%)
Writing library : x264 core 148
Encoding settings : cabac=1 / ref=3 / deblock=1:0:0 / analyse=0x1:0x111 / me=umh / subme=6 / psy=1 / psy_rd=1.00:0.00 / mixed_ref=1 / me_range=16 / chroma_me=1 / trellis=1 / 8x8dct=0 / cqm=0 / deadzone=21,11 / fast_pskip=1 / chroma_qp_offset=-2 / threads=22 / lookahead_threads=3 / sliced_threads=0 / nr=0 / decimate=1 / interlaced=0 / bluray_compat=0 / constrained_intra=0 / bframes=3 / b_pyramid=2 / b_adapt=1 / b_bias=0 / direct=1 / weightb=1 / open_gop=0 / weightp=2 / keyint=60 / keyint_min=6 / scenecut=0 / intra_refresh=0 / rc_lookahead=60 / rc=cbr / mbtree=1 / bitrate=3000 / ratetol=1.0 / qcomp=0.60 / qpmin=0 / qpmax=69 / qpstep=4 / vbv_maxrate=3000 / vbv_bufsize=6000 / nal_hrd=none / filler=0 / ip_ratio=1.40 / aq=1:1.00
Codec configuration box : avcC
Audio
ID : 2
Format : AAC LC
Format/Info : Advanced Audio Codec Low Complexity
Codec ID : mp4a-40-2
Duration : 1 min 21 s
Duration_LastFrame : -1 ms
Bit rate mode : Constant
Bit rate : 128 kb/s
Channel(s) : 2 channels
Channel layout : L R
Sampling rate : 48.0 kHz
Frame rate : 46.875 FPS (1024 SPF)
Compression mode : Lossy
Stream size : 1.24 MiB (4%)
Default : Yes
Alternate group : 1