
Explore the bug bounty concept and how large payouts on websites incentivize discovering vulnerabilities, introducing key ideas for starting with bug bounty on websites.
Lab:
https://portswigger.net/web-security/information-disclosure/exploiting/lab-infoleak-via-backup-files
Lab:
https://portswigger.net/web-security/information-disclosure/exploiting/lab-infoleak-on-debug-page
Lab:
https://portswigger.net/web-security/information-disclosure/exploiting/lab-infoleak-in-version-control-history
Lab
https://portswigger.net/web-security/information-disclosure/exploiting/lab-infoleak-in-error-messages
Lab
https://portswigger.net/web-security/access-control/lab-user-role-controlled-by-request-parameter
Lab
https://portswigger.net/web-security/access-control/lab-insecure-direct-object-references
Lab
https://portswigger.net/web-security/access-control/lab-user-role-can-be-modified-in-user-profile
Lab
https://portswigger.net/web-security/file-path-traversal/lab-absolute-path-bypass
Labs
https://portswigger.net/web-security/file-path-traversal/lab-simple
https://portswigger.net/web-security/file-path-traversal/lab-validate-file-extension-null-byte-bypass
https://portswigger.net/web-security/file-path-traversal/lab-sequences-stripped-non-recursively
Explore file path traversal automation testing using payloads and the intruder tool in a lab, with yaml configuration and status code analysis.
Lab
https://portswigger.net/web-security/cross-site-scripting/reflected/lab-html-context-nothing-encoded
Lab
https://portswigger.net/web-security/cross-site-scripting/dom-based/lab-document-write-sink
The training course on Vulnerability Disclosure Programs offers participants a valuable opportunity to gain practical skills in identifying and responsibly enhancing the security of digital systems. Its objective is to equip attendees with the necessary knowledge and skills to discover vulnerabilities and leverage them securely and effectively.
Participants will learn how to identify and exploit common vulnerabilities, gaining proficiency in using specialized tools for detection and assessing their severity. They will also acquire techniques to analyze and evaluate weaknesses in applications and systems, enabling them to deliver detailed and accurate reports to companies and organizations.
Participants will also explore ethical considerations surrounding vulnerability disclosure, ensuring they approach security testing with integrity and accountability. This holistic approach not only enhances technical skills but also fosters a culture of responsible cybersecurity practices within organizations.
Key topics covered in the course include a comprehensive introduction to Vulnerability Disclosure Programs and their significance, advanced techniques and methodologies for vulnerability discovery, as well as exploitation strategies and assessment tools.
Upon completion, participants will be well-prepared to actively engage in Vulnerability Disclosure Programs, contributing effectively to enhancing the security of digital applications and systems. This course is ideal for software developers and information security professionals seeking practical and advanced skills in vulnerability discovery.