Hack Yourself First: How to go on the Cyber-Offense [2013, ENG]

seeders: 5
leechers: 1
Added 12 years ago by ruudsach in Other

Download Fast Safe Anonymous
movies, software, shows...

Files

Hack Yourself First: How to go on the Cyber-Offense [2013, ENG] (Size: 1.03 GB)
  01.Introduction
  01.About the course.srt 2.73 KB
  01.About the course.wmv 3.25 MB
  02.Why hack yourself first.srt 5.74 KB
  02.Why hack yourself first.wmv 7.17 MB
  03.Introducing a vulnerable website – Supercar Showdown.srt 6.81 KB
  03.Introducing a vulnerable website – Supercar Showdown.wmv 13.94 MB
  04.Using Chrome's developer tools.srt 7.32 KB
  04.Using Chrome's developer tools.wmv 12.69 MB
  05.Monitoring and composing requests with Fiddler.srt 6.33 KB
  05.Monitoring and composing requests with Fiddler.wmv 8.36 MB
  06.Modifying requests and responses in Fiddler.srt 4.41 KB
  06.Modifying requests and responses in Fiddler.wmv 8.75 MB
  02.Transport Layer Protection
  01.Introduction.srt 1.77 KB
  01.Introduction.wmv 2.27 MB
  02.The three objectives of transport layer protection.srt 3.86 KB
  02.The three objectives of transport layer protection.wmv 4.18 MB
  03.Understanding a man in the middle attack.srt 4.97 KB
  03.Understanding a man in the middle attack.wmv 6.29 MB
  04.Protecting sensitive data in transit.srt 7.68 KB
  04.Protecting sensitive data in transit.wmv 11.88 MB
  05.The risk of sending cookies over insecure connections.srt 16.42 KB
  05.The risk of sending cookies over insecure connections.wmv 26.91 MB
  06.How loading login forms over HTTP is risky.srt 24.45 KB
  06.How loading login forms over HTTP is risky.wmv 43.06 MB
  07.Exploiting mixed-mode content.srt 13.32 KB
  07.Exploiting mixed-mode content.wmv 20.54 MB
  08.The HSTS header.srt 8.93 KB
  08.The HSTS header.wmv 15.21 MB
  09.Summary.srt 3.95 KB
  09.Summary.wmv 4.56 MB
  03.Cross Site Scripting (XSS)
  01.Introduction.srt 2.19 KB
  01.Introduction.wmv 2.57 MB
  02.Understanding untrusted data and sanitisation.srt 9.62 KB
  02.Understanding untrusted data and sanitisation.wmv 9.79 MB
  03.Establishing input sanitisation practices.srt 6.27 KB
  03.Establishing input sanitisation practices.wmv 7.85 MB
  04.Understanding XSS and output encoding.srt 13.54 KB
  04.Understanding XSS and output encoding.wmv 15.08 MB
  05.Identifying the use of output encoding.srt 7.14 KB
  05.Identifying the use of output encoding.wmv 9.27 MB
  06.Delivering a payload via reflected XSS.srt 13.13 KB
  06.Delivering a payload via reflected XSS.wmv 14.78 MB
  07.Testing for the risk of persistent XSS.srt 10.38 KB
  07.Testing for the risk of persistent XSS.wmv 22.85 MB
  08.The X-XSS-Protection header.srt 8.72 KB
  08.The X-XSS-Protection header.wmv 16.54 MB
  09.Summary.srt 4.04 KB
  09.Summary.wmv 4.91 MB
  04.Cookies
  01.Introduction.srt 1.65 KB
  01.Introduction.wmv 1.75 MB
  02.Cookies 101.srt 9.47 KB
  02.Cookies 101.wmv 10.21 MB
  03.Understanding HttpOnly cookies.srt 6.88 KB
  03.Understanding HttpOnly cookies.wmv 19.31 MB
  04.Understanding secure cookies.srt 8.61 KB
  04.Understanding secure cookies.wmv 16.83 MB
  05.Restricting cookie access by path.srt 13.19 KB
  05.Restricting cookie access by path.wmv 23.11 MB
  06.Reducing risk with cookie expiration.srt 8.63 KB
  06.Reducing risk with cookie expiration.wmv 12.35 MB
  07.Using session cookies to further reduce risk.srt 5.69 KB
  07.Using session cookies to further reduce risk.wmv 8.86 MB
  08.Summary.srt 3.23 KB
  08.Summary.wmv 4.1 MB
  05.Internal Implementation Disclosure
  01.Introduction.srt 2.62 KB
  01.Introduction.wmv 2.98 MB
  02.How an attacker builds a website risk profile.srt 9.76 KB
  02.How an attacker builds a website risk profile.wmv 15.67 MB
  03.Server response header disclosure.srt 8.96 KB
  03.Server response header disclosure.wmv 11.68 MB
  04.Locating at-risk websites.srt 8.94 KB
  04.Locating at-risk websites.wmv 19.84 MB
  05.HTTP fingerprinting of servers.srt 11.87 KB
  05.HTTP fingerprinting of servers.wmv 14.07 MB
  06.Disclosure via robots.txt.srt 6.83 KB
  06.Disclosure via robots.txt.wmv 7.43 MB
  07.The risks in HTML source.srt 5.95 KB
  07.The risks in HTML source.wmv 7.54 MB
  08.Internal error message leakage.srt 14.07 KB
  08.Internal error message leakage.wmv 17.98 MB
  09.Lack of access controls on diagnostic data.srt 14.14 KB
  09.Lack of access controls on diagnostic data.wmv 19.92 MB
  10.Summary.srt 5.08 KB
  10.Summary.wmv 6.21 MB
  06.Parameter Tampering
  01.Introduction.srt 2.83 KB
  01.Introduction.wmv 3.21 MB
  02.Identifying untrusted data in HTTP request parameters.srt 14.36 KB
  02.Identifying untrusted data in HTTP request parameters.wmv 17.95 MB
  03.Capturing requests and manipulating parameters.srt 12.52 KB
  03.Capturing requests and manipulating parameters.wmv 19.94 MB
  04.Manipulating application logic via parameters.srt 9.42 KB
  04.Manipulating application logic via parameters.wmv 14.69 MB
  05.Testing for missing server side validation.srt 20.62 KB
  05.Testing for missing server side validation.wmv 31.58 MB
  06.Understanding model binding.srt 4.86 KB
  06.Understanding model binding.wmv 5.03 MB
  07.Executing a mass assignment attack.srt 11.72 KB
  07.Executing a mass assignment attack.wmv 16.3 MB
  08.HTTP verb tampering.srt 13.97 KB
  08.HTTP verb tampering.wmv 20.47 MB
  09.Fuzz testing.srt 19.72 KB
  09.Fuzz testing.wmv 28.12 MB
  10.Summary.srt 6.89 KB
  10.Summary.wmv 8.15 MB
  07.SQL Injection
  01.Outline.srt 2.71 KB
  01.Outline.wmv 2.91 MB
  02.Understanding SQL injection.srt 13.06 KB
  02.Understanding SQL injection.wmv 14.2 MB
  03.Testing for injection risks.srt 10.69 KB
  03.Testing for injection risks.wmv 13.95 MB
  04.Discovering database structure via injection.srt 17.58 KB
  04.Discovering database structure via injection.wmv 22.83 MB
  05.Harvesting data via injection.srt 5.8 KB
  05.Harvesting data via injection.wmv 8.25 MB
  06.Automating attacks with Havij.srt 9.62 KB
  06.Automating attacks with Havij.wmv 12.97 MB
  07.Blind SQL injection.srt 21.48 KB
  07.Blind SQL injection.wmv 26.47 MB
  08.Secure app patterns.srt 11.33 KB
  08.Secure app patterns.wmv 13.15 MB
  09.Summary.srt 7.52 KB
  09.Summary.wmv 8.62 MB
  08.Cross Site Attacks
  01.Introduction.srt 1.92 KB
  01.Introduction.wmv 2.24 MB
  02.Understanding cross site attacks.srt 6.29 KB
  02.Understanding cross site attacks.wmv 7.73 MB
  03.Testing for a cross site request forgery risk.srt 10.58 KB
  03.Testing for a cross site request forgery risk.wmv 14.22 MB
  04.The role of anti-forgery tokens.srt 16.16 KB
  04.The role of anti-forgery tokens.wmv 21.68 MB
  05.Testing cross site request forgery against APIs.srt 15.18 KB
  05.Testing cross site request forgery against APIs.wmv 26.01 MB
  06.Mounting a clickjacking attack.srt 20.03 KB
  06.Mounting a clickjacking attack.wmv 29.53 MB
  07.Summary.srt 4.87 KB
  07.Summary.wmv 5.67 MB
  09.Account Management
  01.Introduction.srt 3.24 KB
  01.Introduction.wmv 3.6 MB
  02.Understanding password strength and attack vectors.srt 15.56 KB
  02.Understanding password strength and attack vectors.wmv 21.5 MB
  03.Limiting characters in passwords.srt 7.98 KB
  03.Limiting characters in passwords.wmv 9.13 MB
  04.Emailing credentials on account creation.srt 2.89 KB
  04.Emailing credentials on account creation.wmv 3.76 MB
  05.Account enumeration.srt 10.74 KB
  05.Account enumeration.wmv 12.19 MB
  06.Denial of service via password reset.srt 3.38 KB
  06.Denial of service via password reset.wmv 3.52 MB
  07.Correctly securing the reset processes.srt 4.58 KB
  07.Correctly securing the reset processes.wmv 5.19 MB
  08.Establishing insecure password storage.srt 11.26 KB
  08.Establishing insecure password storage.wmv 16.65 MB
  09.Testing for risks in the 'remember me' feature.srt 7.44 KB
  09.Testing for risks in the 'remember me' feature.wmv 13.36 MB
  10.Re-authenticating before key actions.srt 5.73 KB
  10.Re-authenticating before key actions.wmv 6.17 MB
  11.Testing for authentication brute force.srt 10.91 KB
  11.Testing for authentication brute force.wmv 13.01 MB
  12.Summary.srt 6.58 KB
  12.Summary.wmv 7.91 MB
  hack-yourself-first.zip 33.96 MB

Description


Обучающие видео » Компьютерные видеоуроки и обучающие интерактивные DVD » Программирование (видеоуроки)

Hack Yourself First: How to go on the Cyber-Offense

Год выпуска: 2013
Производитель: Pluralsight
Сайт производителя: http://pluralsight.com/training/Courses/TableOfContents/hack-yourself-first
Автор: Troy hunt
Продолжительность: 9h 25m
Тип раздаваемого материала: Видеоклипы
Язык: Английский
Описание:
"Взломай себя первым" - курс для тех, кто хочет находить уязвимости своих сайтов прежде, чем найдут другие.

"Hack Yourself First" is all about developers building up cyber-offense skills and proactively seeking out security vulnerabilities in their own websites before an attacker does.

The prevalence of online attacks against websites has accelerated quickly in recent years and the same risks continue to be readily exploited.
However, these are very often easily identified directly within the browser; it's just a matter of understanding the vulnerable patterns to look for.
This course comes at security from the view of the attacker in that their entry point is typically the browser.
They have a website they want to probe for security risks – this is how they go about it.
This approach is more reflective of the real online threat than reviewing source code is and it empowers developers to begin immediately assessing their applications even when they're running in a live environment without access to the source.
After all, that's what online attackers are doing.
[spoiler="Содержание"]
FileName Size Length Bit rate Data rate Resolution Frame Rate Parent Folder
01.About the course 3.24 MB 0:02:09 ‎128kbps 331.00 1024x768 ‎15 frames/second 01.Introduction
02.Why hack yourself first 7.16 MB 0:04:36 ‎128kbps 230.00 1024x768 ‎15 frames/second 01.Introduction
03.Introducing a vulnerable website – Supercar Showdown 13.9 MB 0:05:12 ‎128kbps 2561.00 1024x768 ‎15 frames/second 01.Introduction
04.Using Chrome's developer tools 12.6 MB 0:05:36 ‎128kbps 2688.00 1024x768 ‎15 frames/second 01.Introduction
05.Monitoring and composing requests with Fiddler 8.36 MB 0:04:55 ‎128kbps 2167.00 1024x768 ‎15 frames/second 01.Introduction
06.Modifying requests and responses in Fiddler 8.74 MB 0:03:26 ‎128kbps 1663.00 1024x768 ‎15 frames/second 01.Introduction
01.Introduction 2.26 MB 0:01:30 ‎128kbps 245.00 1024x768 ‎15 frames/second 02.Transport Layer Protection
02.The three objectives of transport layer protection 4.18 MB 0:02:59 ‎128kbps 914.00 1024x768 ‎15 frames/second 02.Transport Layer Protection
03.Understanding a man in the middle attack 6.29 MB 0:03:53 ‎128kbps 1548.00 1024x768 ‎15 frames/second 02.Transport Layer Protection
04.Protecting sensitive data in transit 11.8 MB 0:06:23 ‎128kbps 2381.00 1024x768 ‎15 frames/second 02.Transport Layer Protection
05.The risk of sending cookies over insecure connections 26.9 MB 0:12:56 ‎128kbps 2750.00 1024x768 ‎15 frames/second 02.Transport Layer Protection
06.How loading login forms over HTTP is risky 43.0 MB 0:19:29 ‎128kbps 3640.00 1024x768 ‎15 frames/second 02.Transport Layer Protection
07.Exploiting mixed-mode content 20.5 MB 0:10:39 ‎128kbps 439.00 1024x768 ‎15 frames/second 02.Transport Layer Protection
08.The HSTS header 15.2 MB 0:07:11 ‎128kbps 2580.00 1024x768 ‎15 frames/second 02.Transport Layer Protection
09.Summary 4.56 MB 0:03:05 ‎128kbps 1357.00 1024x768 ‎15 frames/second 02.Transport Layer Protection
01.Introduction 2.57 MB 0:01:45 ‎128kbps 1496.00 1024x768 ‎15 frames/second 03.Cross Site Scripting (XSS)
02.Understanding untrusted data and sanitisation 9.78 MB 0:06:53 ‎128kbps 1927.00 1024x768 ‎15 frames/second 03.Cross Site Scripting (XSS)
03.Establishing input sanitisation practices 7.84 MB 0:04:39 ‎128kbps 2522.00 1024x768 ‎15 frames/second 03.Cross Site Scripting (XSS)
04.Understanding XSS and output encoding 15.0 MB 0:10:44 ‎128kbps 1880.00 1024x768 ‎15 frames/second 03.Cross Site Scripting (XSS)
05.Identifying the use of output encoding 9.26 MB 0:05:00 ‎128kbps 3179.00 1024x768 ‎15 frames/second 03.Cross Site Scripting (XSS)
06.Delivering a payload via reflected XSS 14.7 MB 0:09:51 ‎128kbps 2036.00 1024x768 ‎15 frames/second 03.Cross Site Scripting (XSS)
07.Testing for the risk of persistent XSS 22.8 MB 0:08:13 ‎128kbps 2654.00 1024x768 ‎15 frames/second 03.Cross Site Scripting (XSS)
08.The X-XSS-Protection header 16.5 MB 0:06:58 ‎128kbps 2681.00 1024x768 ‎15 frames/second 03.Cross Site Scripting (XSS)
09.Summary 4.90 MB 0:03:16 ‎128kbps 1526.00 1024x768 ‎15 frames/second 03.Cross Site Scripting (XSS)
01.Introduction 1.75 MB 0:01:19 ‎128kbps 1160.00 1024x768 ‎15 frames/second 04.Cookies
02.Cookies 101 10.2 MB 0:07:05 ‎128kbps 2200.00 1024x768 ‎15 frames/second 04.Cookies
03.Understanding HttpOnly cookies 19.3 MB 0:05:34 ‎128kbps 3321.00 1024x768 ‎15 frames/second 04.Cookies
04.Understanding secure cookies 16.8 MB 0:06:55 ‎128kbps 3614.00 1024x768 ‎15 frames/second 04.Cookies
05.Restricting cookie access by path 23.1 MB 0:10:18 ‎128kbps 1139.00 1024x768 ‎15 frames/second 04.Cookies
06.Reducing risk with cookie expiration 12.3 MB 0:06:44 ‎128kbps 3026.00 1024x768 ‎15 frames/second 04.Cookies
07.Using session cookies to further reduce risk 8.86 MB 0:04:39 ‎128kbps 2795.00 1024x768 ‎15 frames/second 04.Cookies
08.Summary 4.09 MB 0:02:39 ‎128kbps 1730.00 1024x768 ‎15 frames/second 04.Cookies
01.Introduction 2.97 MB 0:02:02 ‎128kbps 1584.00 1024x768 ‎15 frames/second 05.Internal Implementation Disclosure
02.How an attacker builds a website risk profile 15.6 MB 0:07:21 ‎128kbps 5777.00 1024x768 ‎15 frames/second 05.Internal Implementation Disclosure
03.Server response header disclosure 11.6 MB 0:07:01 ‎128kbps 2250.00 1024x768 ‎15 frames/second 05.Internal Implementation Disclosure
04.Locating at-risk websites 19.8 MB 0:06:53 ‎128kbps 8626.00 1024x768 ‎15 frames/second 05.Internal Implementation Disclosure
05.HTTP fingerprinting of servers 14.0 MB 0:09:25 ‎128kbps 1418.00 1024x768 ‎15 frames/second 05.Internal Implementation Disclosure
06.Disclosure via robots.txt 7.42 MB 0:05:32 ‎128kbps 1110.00 1024x768 ‎15 frames/second 05.Internal Implementation Disclosure
07.The risks in HTML source 7.53 MB 0:04:38 ‎128kbps 2241.00 1024x768 ‎15 frames/second 05.Internal Implementation Disclosure
08.Internal error message leakage 17.9 MB 0:11:02 ‎128kbps 3687.00 1024x768 ‎15 frames/second 05.Internal Implementation Disclosure
09.Lack of access controls on diagnostic data 19.9 MB 0:11:27 ‎128kbps 3907.00 1024x768 ‎15 frames/second 05.Internal Implementation Disclosure
10.Summary 6.20 MB 0:04:03 ‎128kbps 1565.00 1024x768 ‎15 frames/second 05.Internal Implementation Disclosure
01.Introduction 3.21 MB 0:02:16 ‎128kbps 1592.00 1024x768 ‎15 frames/second 06.Parameter Tampering
02.Identifying untrusted data in HTTP request parameters 17.9 MB 0:11:01 ‎128kbps 229.00 1024x768 ‎15 frames/second 06.Parameter Tampering
03.Capturing requests and manipulating parameters 19.9 MB 0:09:57 ‎128kbps 3188.00 1024x768 ‎15 frames/second 06.Parameter Tampering
04.Manipulating application logic via parameters 14.6 MB 0:07:34 ‎128kbps 2079.00 1024x768 ‎15 frames/second 06.Parameter Tampering
05.Testing for missing server side validation 31.5 MB 0:16:20 ‎128kbps 579.00 1024x768 ‎15 frames/second 06.Parameter Tampering
06.Understanding model binding 5.03 MB 0:03:46 ‎128kbps 712.00 1024x768 ‎15 frames/second 06.Parameter Tampering
07.Executing a mass assignment attack 16.2 MB 0:09:16 ‎128kbps 2565.00 1024x768 ‎15 frames/second 06.Parameter Tampering
08.HTTP verb tampering 20.4 MB 0:11:27 ‎128kbps 2806.00 1024x768 ‎15 frames/second 06.Parameter Tampering
09.Fuzz testing 28.1 MB 0:14:43 ‎128kbps 4834.00 1024x768 ‎15 frames/second 06.Parameter Tampering
10.Summary 8.14 MB 0:05:30 ‎128kbps 1434.00 1024x768 ‎15 frames/second 06.Parameter Tampering
01.Outline 2.90 MB 0:02:02 ‎128kbps 1215.00 1024x768 ‎15 frames/second 07.SQL Injection
02.Understanding SQL injection 14.1 MB 0:09:52 ‎128kbps 2179.00 1024x768 ‎15 frames/second 07.SQL Injection
03.Testing for injection risks 13.9 MB 0:07:53 ‎128kbps 3198.00 1024x768 ‎15 frames/second 07.SQL Injection
04.Discovering database structure via injection 22.8 MB 0:13:42 ‎128kbps 3297.00 1024x768 ‎15 frames/second 07.SQL Injection
05.Harvesting data via injection 8.24 MB 0:04:36 ‎128kbps 2908.00 1024x768 ‎15 frames/second 07.SQL Injection
06.Automating attacks with Havij 12.9 MB 0:07:24 ‎128kbps 3424.00 1024x768 ‎15 frames/second 07.SQL Injection
07.Blind SQL injection 26.4 MB 0:17:01 ‎128kbps 504.00 1024x768 ‎15 frames/second 07.SQL Injection
08.Secure app patterns 13.1 MB 0:08:38 ‎128kbps 2574.00 1024x768 ‎15 frames/second 07.SQL Injection
09.Summary 8.61 MB 0:05:36 ‎128kbps 1689.00 1024x768 ‎15 frames/second 07.SQL Injection
01.Introduction 2.24 MB 0:01:36 ‎128kbps 1173.00 1024x768 ‎15 frames/second 08.Cross Site Attacks
02.Understanding cross site attacks 7.73 MB 0:05:00 ‎128kbps 159.00 1024x768 ‎15 frames/second 08.Cross Site Attacks
03.Testing for a cross site request forgery risk 14.2 MB 0:08:33 ‎128kbps 2313.00 1024x768 ‎15 frames/second 08.Cross Site Attacks
04.The role of anti-forgery tokens 21.6 MB 0:13:22 ‎128kbps 2470.00 1024x768 ‎15 frames/second 08.Cross Site Attacks
05.Testing cross site request forgery against APIs 26.0 MB 0:11:52 ‎128kbps 6108.00 1024x768 ‎15 frames/second 08.Cross Site Attacks
06.Mounting a clickjacking attack 29.5 MB 0:16:10 ‎128kbps 2386.00 1024x768 ‎15 frames/second 08.Cross Site Attacks
07.Summary 5.66 MB 0:03:47 ‎128kbps 1419.00 1024x768 ‎15 frames/second 08.Cross Site Attacks
01.Introduction 3.60 MB 0:02:25 ‎128kbps 1778.00 1024x768 ‎15 frames/second 09.Account Management
02.Understanding password strength and attack vectors 21.4 MB 0:12:00 ‎128kbps 783.00 1024x768 ‎15 frames/second 09.Account Management
03.Limiting characters in passwords 9.12 MB 0:06:21 ‎128kbps 1157.00 1024x768 ‎15 frames/second 09.Account Management
04.Emailing credentials on account creation 3.75 MB 0:02:13 ‎128kbps 2796.00 1024x768 ‎15 frames/second 09.Account Management
05.Account enumeration 12.1 MB 0:08:11 ‎128kbps 3025.00 1024x768 ‎15 frames/second 09.Account Management
06.Denial of service via password reset 3.51 MB 0:02:36 ‎128kbps 943.00 1024x768 ‎15 frames/second 09.Account Management
07.Correctly securing the reset processes 5.18 MB 0:03:36 ‎128kbps 2732.00 1024x768 ‎15 frames/second 09.Account Management
08.Establishing insecure password storage 16.6 MB 0:09:00 ‎128kbps 3345.00 1024x768 ‎15 frames/second 09.Account Management
09.Testing for risks in the 'remember me' feature 13.3 MB 0:05:49 ‎128kbps 5236.00 1024x768 ‎15 frames/second 09.Account Management
10.Re-authenticating before key actions 6.16 MB 0:04:28 ‎128kbps 1241.00 1024x768 ‎15 frames/second 09.Account Management
11.Testing for authentication brute force 13.0 MB 0:08:18 ‎128kbps 294.00 1024x768 ‎15 frames/second 09.Account Management
12.Summary 7.90 MB 0:05:08 ‎128kbps 1720.00 1024x768 ‎15 frames/second 09.Account Management
[/spoiler]
Файлы примеров: присутствуют
Формат видео: WMV
Видео: wmv3, 1024x768, 15fps, 159~8626 kbps
Аудио: wma2, 128kbps, 44.1kHz, Stereo
[spoiler="Скриншоты"]

[/spoiler]
Доп. информация: Exercise include slides, code files and Transcripts

Related Torrents

torrent name size uploader age seed leech
0