Udemy – Learn Bug Bounty Hunting & Web Security Testing From Scratch
About Course
Udemy Original Course Link
As mentioned you’ll learn much more than just how to discover security bugs in this course, but here’s a list of the main security bugs and vulnerabilities that will be covered in the course:
Information Disclosure.
IDOR (Insecure Direct Object Reference).
Broken Access Control .
Directory / Path Traversal.
Cookie Manipulation.
CSRF (Client-Side Request Forgery).
OAUTH 2.0.
Injection Vulnerabilities.
Command Injection.
Blind Command Injection.
HTML Injection.
XSS (Cross-Site Scripting).
Reflected, Stored & DOM Based XSS.
Bypassing Security Filters.
Bypassing CSP (Content Security Policy).
SQL Injection.
Blind SQLi.
Time-based Blind SQLi.
SSRRF (Server-Side Request Forgery).
Blind SSRF.
XXE (XML External Entity) Injection.
Topics:
Information gathering.
End point discovery.
HTTP Headers.
HTTP status codes.
HTTP methods.
Input parameters.
Cookies.
HTML basics for bug hunting.
Javascript basics for bug hunting.
XML basics for bug hunting.
Filtering methods.
Bypassing blacklists & whitelists.
Bug hunting and research.
Hidden paths discovery.
Code analyses .
You’ll use the following tools to achieve the above:
Ferox Buster .
WSL .
Dev tools.
Burp Suite:
Basics.
Burp Proxy.
Intruder (Simple & Cluster-bomb).
Repeater.
Collaborator.
Course Content
Udemy – Learn Bug Bounty Hunting & Web Security Testing From Scratch
- 12:00
- 58:16
03. Broken Access Control Vulnerabilities
43:2304. Path Directory Traversal Vulnerabilities
42:0105. CSRF – Cross-Site Request Forgery
09:1806. OAUTH 2.0 Vulnerabilities
39:5407. Injection Vulnerabilities
01:2208. OS Command Injection
30:1809. XSS – Cross Site Scripting
14:5510. DOM XSS Vulnerabilities
31:5711. XSS – Bypassing Security
34:0212. Bypassing Content Security Policy (CSP)
20:0213. SQL Injection Vulnerabilities
34:0614. Blind SQL Injections
31:3015. Time-Based Blind SQL Injection
28:1216. SSRF (Server-Side Request Forgery)
19:0817. SSRF – Advanced Exploitation
13:3918. SSRF – Bypassing Security
24:3619. Blind SSRF Vulnerabilities
26:0220. XXE (XML External Entity) Injection
19:3121. 2 Hour Live Bug Hunting !
01:41:1922. Participating in Bug Bounty Programs
25:1323. Bonus Section