강의

멘토링

로드맵

Inflearn brand logo image
BEST
Security & Network

/

Computer Security

Skill-Up! Webshell Obfuscation Techniques for Bypassing Webshell Detection Solutions

Basic understanding of web shells and web shell detection solutions, as well as attack methods and obfuscation techniques for bypassing them!

(4.8) 27 reviews

452 learners

  • crehacktive
Penetration Testing
Web Shell

Reviews from Early Learners

What you will learn!

  • Webshell Basic Concepts

  • How to create a web shell

  • How web shell works

  • Webshell detection solution concept

  • Background of the emergence of web shell detection solutions

  • Attack methodology in a web shell detection solution environment

  • Web shell obfuscation techniques

📖 A series of file upload vulnerability attacks, explained by a simulated hacking expert!

  • PART (1): Basics / Practical Attacks / Secure Coding
    This training covers the most crucial aspect of file upload vulnerability attacks, detailing the attack process with a completely different approach from previously known methods. You'll learn the fundamentals of attack, practical bypass techniques, case studies, various countermeasures, and secure coding. This essential training serves as the foundation for subsequent courses.
  • PART (2): Advanced Attack Techniques / In-Depth Practical Analysis
    This course teaches advanced attack techniques and Web Application Firewall bypass techniques not covered in PART (1), and analyzes technical techniques used in practical environments through hands-on practice.
  • SKILL-UP: Webshell Obfuscation Techniques Current Course
    In today's web environment, the use of web shell detection solutions is increasing, and accordingly, analysts must possess the skills to bypass them. Therefore, this training will be essential for practitioners.

📖 Webshell Obfuscation Techniques !? Why Learn Them?!

The frequency of hacking in today's web service environment continues to rise. Consequently, security solutions for web services are emerging and evolving, and one of these solutions is the " web shell detection solution ."

However, for the attacking diagnostician, security solutions are also a mountain to overcome!
For this reason , understanding and mastering web shell obfuscation techniques is a must!

📖 Web shell obfuscation techniques that can be applied immediately in practice!

You'll learn practical web shell obfuscation techniques, proven and applied in practice, to bypass web shell detection solutions! And because obfuscation techniques are applied after identifying detection points, bypassing them is simple and easy!

📖 From the principle of web shell operation
Practice creating your own web shell!

Understanding web shells is essential for bypassing web shell detection solutions, right?
We will cover the basic concepts, operating principles, and even hands-on practice of creating a "web shell."

📖 Anyone who wants to Skill-Up!
Grow through this course!

This training is suitable for both beginners and practitioners alike! Of course, we recommend taking the course with at least some understanding of file upload vulnerabilities.

This will be an opportunity to enjoy diagnosing the web shell detection solution environment that can be experienced during practical diagnosis!

💡 Related Courses

Analysis of File Upload Vulnerability Attack Techniques and Practical Cases
The ultimate web hacking master! A lecture on exploiting file upload vulnerabilities!

Recommended for
these people

Who is this course right for?

  • Job seekers who want to study practical skills

  • Practitioners diagnosing in practice

  • Security Solutions Developer

  • Practitioners who want to improve their skills

Hello
This is

25,880

Learners

1,361

Reviews

497

Answers

4.9

Rating

18

Courses

:: 국내 정보보안 솔루션 개발 기업 재직 ::
- 앱 위변조 방지 솔루션 : 미들웨어 담당 / 해킹 대회 운영진 / 국내 유명 해킹/방어 훈련장 제작

:: 국내 정보보안 전문 업체 재직 ::
- 블랙박스 모의해킹 / 시나리오 기반 모의해킹 / 웹 취약점 진단 / 모바일 취약점 진단 / 소스코드 취약점 진단 / APT 모의 훈련 / DDoS 모의훈련 / 인프라 진단 / 스마트 가전 진단
- 국내 대기업, 중소기업 다수 진단

:: 외부 교육 및 활동 ::
- 멀티캠퍼스, 국가 보안 기술 연구소(ETRI)
- 국내 정보보안 업체 : 재직자 대상 "웹 모의해킹 심화 교육" 진행중
- 해커팩토리 문제 제작

:: 취약점 발견 ::

1) Web Application Server 취약점
- TMAX JEUS : 원격 명령어 실행 취약점(Remote Command Execution Vulnerability)
- IBM WebSphere(CVE-2020-4163) : 원격 명령어 실행 취약점(Remote Command Execution Vulnerability)

2) CMS(Contents Management System) 취약점
- 네이버 스마트에디터 : 파일 업로드 취약점
- 그누보드 : SQL Injection , 파일 업로드 취약점(그누보드4, 그누보드5), XSS ...
- 킴스큐 : 파리미터 변조 취약점 , 파일 업로드 취약점

* 이메일 : crehacktive3@naver.com
* 블로그 : http://www.crehacktive.co.kr

Curriculum

All

42 lectures ∙ (3hr 30min)

Course Materials:

Lecture resources
Published: 
Last updated: 

Reviews

All

27 reviews

4.8

27 reviews

  • cjh0823님의 프로필 이미지
    cjh0823

    Reviews 6

    Average Rating 3.3

    5

    100% enrolled

    명강의 감사합니다.

    • 박정연님의 프로필 이미지
      박정연

      Reviews 1

      Average Rating 5.0

      5

      100% enrolled

      잘들었습니다 감사합니다!

      • leeseokmin님의 프로필 이미지
        leeseokmin

        Reviews 3

        Average Rating 5.0

        5

        100% enrolled

        좋은 강의라고 생각합니다. 다시 복습하고 좋은 내용은 암기할 수 있도록 하겠습니다.

        • 조상태님의 프로필 이미지
          조상태

          Reviews 1

          Average Rating 5.0

          5

          100% enrolled

          알기쉽고 다방면으로 내용을 담으셔서 도움이 되었습니다.

          • 석진우님의 프로필 이미지
            석진우

            Reviews 1

            Average Rating 5.0

            5

            100% enrolled

            웹쉘에 대한 기본적인 지식을 얻기 좋은 내용입니다

            $11.00

            crehacktive's other courses

            Check out other courses by the instructor!

            Similar courses

            Explore other courses in the same field!