Udemy
  •  
  •  
  •  
  •  
  •  
  •  
  •  
  •  
  •  
  •  
  •  
  •  
  •  
Development
Web Development Data Science Mobile Development Programming Languages Game Development Database Design & Development Software Testing Software Engineering Software Development Tools No-Code Development
Business
Entrepreneurship Communication Management Sales Business Strategy Operations Project Management Business Law Business Analytics & Intelligence Human Resources Industry E-Commerce Media Real Estate Other Business
Finance & Accounting
Accounting & Bookkeeping Compliance Cryptocurrency & Blockchain Economics Finance Finance Cert & Exam Prep Financial Modeling & Analysis Investing & Trading Money Management Tools Taxes Other Finance & Accounting
IT & Software
IT Certifications Network & Security Hardware Operating Systems & Servers Other IT & Software
Office Productivity
Microsoft Apple Google SAP Oracle Other Office Productivity
Personal Development
Personal Transformation Personal Productivity Leadership Career Development Parenting & Relationships Happiness Esoteric Practices Religion & Spirituality Personal Brand Building Creativity Influence Self Esteem & Confidence Stress Management Memory & Study Skills Motivation Other Personal Development
Design
Web Design Graphic Design & Illustration Design Tools User Experience Design Game Design 3D & Animation Fashion Design Architectural Design Interior Design Other Design
Marketing
Digital Marketing Search Engine Optimization Social Media Marketing Branding Marketing Fundamentals Marketing Analytics & Automation Public Relations Paid Advertising Video & Mobile Marketing Content Marketing Growth Hacking Affiliate Marketing Product Marketing Other Marketing
Lifestyle
Arts & Crafts Beauty & Makeup Esoteric Practices Food & Beverage Gaming Home Improvement & Gardening Pet Care & Training Travel Other Lifestyle
Photography & Video
Digital Photography Photography Portrait Photography Photography Tools Commercial Photography Video Design Other Photography & Video
Health & Fitness
Fitness General Health Sports Nutrition & Diet Yoga Mental Health Martial Arts & Self Defense Safety & First Aid Dance Meditation Other Health & Fitness
Music
Instruments Music Production Music Fundamentals Vocal Music Techniques Music Software Other Music
Teaching & Academics
Engineering Humanities Math Science Online Education Social Science Language Learning Teacher Training Test Prep Other Teaching & Academics
Web Development JavaScript React Angular CSS Node.Js PHP HTML5 Vue JS
AWS Certification Microsoft Certification AWS Certified Solutions Architect - Associate AWS Certified Cloud Practitioner CompTIA A+ Amazon AWS Cisco CCNA Microsoft AZ-900 AWS Certified Developer - Associate
Microsoft Power BI SQL Tableau Data Modeling Business Analysis Business Intelligence MySQL Qlik Sense Blockchain
Unity Unreal Engine Game Development Fundamentals C# 3D Game Development C++ Unreal Engine Blueprints 2D Game Development Virtual Reality
Google Flutter Android Development iOS Development React Native Swift Dart (programming language) Mobile App Development Kotlin SwiftUI
Graphic Design Photoshop Adobe Illustrator Drawing Digital Painting Canva InDesign Character Design Procreate Digital Illustration App
Life Coach Training Neuro-Linguistic Programming Personal Development Personal Transformation Life Purpose Mindfulness Meditation Sound Therapy CBT Cognitive Behavioral Therapy
Entrepreneurship Fundamentals Business Fundamentals Freelancing Business Strategy Startup Business Plan Online Business Blogging Home Business
Digital Marketing Social Media Marketing Marketing Strategy Internet Marketing Google Analytics Copywriting Email Marketing YouTube Marketing Podcasting

IT & SoftwareNetwork & SecurityEthical Hacking

Introdução ao Host Header Injection

Web Hacking - Aprenda a explorar a classe de vulnerabilidade Host Header Injection
Rating: 4.9 out of 54.9 (22 ratings)
55 students
Created by Rafael Cintra Lopes
Last updated 7/2021
Portuguese
Portuguese [Auto]

What you'll learn

  • Explorar Vulnerabilidades nos Cabeçalhos das Aplicações Web

Requirements

  • Ter noções básicas de vulnerabilidades web
  • Conhecer a base da computação

Description

O que é Host Header Injection?

O Host Header Injection é uma classe geral de vulnerabilidade de segurança de aplicação web que ocorre quando os cabeçalhos do Hypertext Transfer Protocol (HTTP) são gerados dinamicamente com base na entrada do usuário.

Um servidor Web lida com o valor do cabeçalho do Host para despachar a solicitação ao domínio de destino. Um invasor pode manipular este cabeçalho de Host com alguns domínios falsos para roubar informações confidenciais.

Um invasor pode desviar manualmente o código para produzir a saída desejada, simplesmente editando o valor do cabeçalho do host. Muito provavelmente os servidores da web são configurados para passar o cabeçalho do host desconhecido para o primeiro host virtual na lista de hosts virtuais sem o reconhecimento adequado. Portanto, é possível enviar as solicitações HTTP com cabeçalhos de host arbitrários para o primeiro host virtual.

Em muitos casos, os desenvolvedores confiam no valor do cabeçalho do Host HTTP e o utilizam para gerar links, importar scripts e até gerar links de redefinição de senha. Esta é uma má ideia, porque o cabeçalho do Host HTTP pode ser controlado por um invasor.


Neste treinamento, você vai aprender a explorar a classe de vulnerabilidade Host Header Injection, podendo escalar para as vulnerabilidades, Open Redirect, Cross‑Site Scripting (XSS), Cross Domain Referer Leakage, Cache Poisoning e Cookie Bomb.

Who this course is for:

  • Entusiastas em Segurança da Informação
  • Profissionais da área de Segurança da Informação
  • Pentesters
  • Bug Bounty Hunters

Instructor

Rafael Cintra Lopes
Pentester e Bug Bounty Hunter
Rafael Cintra Lopes
  • 4.9 Instructor Rating
  • 22 Reviews
  • 55 Students
  • 1 Course

Com mais de 9 anos de experiência na área de tecnologia da informação, atuo como Pentester e Security Researcher na Value Box Cybersecurity, realizando testes de vulnerabilidades em grandes empresas nacionais e internacionais.

Gosto de produzir conteúdos sobre hacking e segurança da informação, sendo por meio de artigos, videos e treinamentos.

Top companies choose Udemy Business to build in-demand career skills.
NasdaqVolkswagenBoxNetAppEventbrite
  • Udemy Business
  • Teach on Udemy
  • Get the app
  • About us
  • Contact us
  • Careers
  • Blog
  • Help and Support
  • Affiliate
  • Investors
  • Impressum Kontakt
  • Terms
  • Privacy policy
  • Cookie settings
  • Sitemap
  • Accessibility statement
Udemy
© 2022 Udemy, Inc.