
Learn to use the Vega web vulnerability scanner to test web apps for SQL injection, cross-site scripting, and blind SQL injection, install on Windows, and generate actionable remediation insights.
Understand cross-site scripting, a client-side vulnerability that lets attackers inject malicious code to steal cookies, session tokens, and sensitive data. Learn stored (persisted) and reflected XSS types, and see demonstration.
The lecture explains how the BeEF framework injects malicious JavaScript and shows how a vegan extension can detect and block these actions on a test page.
Explore how cross-site request forgery tricks a logged-in user into performing actions. The lecture demonstrates changing a victim's password and discusses social engineering and forged requests.
Explore phishing attacks using social engineering to steal credentials through fake clone websites that harvest usernames and passwords, demonstrated with a credential harvester and website cloning.
The course will introduce the various methods, tools and techniques used by attackers. You will study web application flaws and their exploitation.
No special skills are required as the course covers everything from the very basics.
This course covers:
After completing this course, you will understand major web application flaws and how to exploit a number of dangerous vulnerabilities such as SQL injections, CSRF attacks, XSS vulnerabilities, Phishing, etc.