웹 개발자와 정보보안 입문자가 꼭 알아야 할 웹 해킹 & 시큐어 코딩
크리핵티브
정보보안 입문자와 웹 개발자 분들을 위한 웹 해킹 입문 강의! 본 강의를 시작으로 웹 해킹을 재미있게 시작해보세요!
Basic
모의해킹, 인젝션
Basic understanding of web shells and web shell detection solutions, as well as attack methods and obfuscation techniques for bypassing them!
Webshell Basic Concepts
How to create a web shell
How web shell works
Webshell detection solution concept
Background of the emergence of web shell detection solutions
Attack methodology in a web shell detection solution environment
Web shell obfuscation techniques
The frequency of hacking in today's web service environment continues to rise. Consequently, security solutions for web services are emerging and evolving, and one of these solutions is the " web shell detection solution ."
However, for the attacking diagnostician, security solutions are also a mountain to overcome!
For this reason , understanding and mastering web shell obfuscation techniques is a must!
You'll learn practical web shell obfuscation techniques, proven and applied in practice, to bypass web shell detection solutions! And because obfuscation techniques are applied after identifying detection points, bypassing them is simple and easy!
Understanding web shells is essential for bypassing web shell detection solutions, right?
We will cover the basic concepts, operating principles, and even hands-on practice of creating a "web shell."
This training is suitable for both beginners and practitioners alike! Of course, we recommend taking the course with at least some understanding of file upload vulnerabilities.
This will be an opportunity to enjoy diagnosing the web shell detection solution environment that can be experienced during practical diagnosis!
Who is this course right for?
Job seekers who want to study practical skills
Practitioners diagnosing in practice
Security Solutions Developer
Practitioners who want to improve their skills
25,880
Learners
1,361
Reviews
497
Answers
4.9
Rating
18
Courses
:: 국내 정보보안 솔루션 개발 기업 재직 ::
- 앱 위변조 방지 솔루션 : 미들웨어 담당 / 해킹 대회 운영진 / 국내 유명 해킹/방어 훈련장 제작
:: 국내 정보보안 전문 업체 재직 ::
- 블랙박스 모의해킹 / 시나리오 기반 모의해킹 / 웹 취약점 진단 / 모바일 취약점 진단 / 소스코드 취약점 진단 / APT 모의 훈련 / DDoS 모의훈련 / 인프라 진단 / 스마트 가전 진단
- 국내 대기업, 중소기업 다수 진단
:: 외부 교육 및 활동 ::
- 멀티캠퍼스, 국가 보안 기술 연구소(ETRI)
- 국내 정보보안 업체 : 재직자 대상 "웹 모의해킹 심화 교육" 진행중
- 해커팩토리 문제 제작
:: 취약점 발견 ::
1) Web Application Server 취약점
- TMAX JEUS : 원격 명령어 실행 취약점(Remote Command Execution Vulnerability)
- IBM WebSphere(CVE-2020-4163) : 원격 명령어 실행 취약점(Remote Command Execution Vulnerability)
2) CMS(Contents Management System) 취약점
- 네이버 스마트에디터 : 파일 업로드 취약점
- 그누보드 : SQL Injection , 파일 업로드 취약점(그누보드4, 그누보드5), XSS ...
- 킴스큐 : 파리미터 변조 취약점 , 파일 업로드 취약점
* 이메일 : crehacktive3@naver.com
* 블로그 : http://www.crehacktive.co.kr
All
42 lectures ∙ (3hr 30min)
Course Materials:
All
27 reviews
4.8
27 reviews
Reviews 6
∙
Average Rating 3.3
Reviews 1
∙
Average Rating 5.0
Reviews 3
∙
Average Rating 5.0
Reviews 1
∙
Average Rating 5.0
Reviews 1
∙
Average Rating 5.0
$11.00
Check out other courses by the instructor!
Explore other courses in the same field!