HOME > IT & Software > Cross Site Scripting (XSS) Attacks for Pentesters

Cross Site Scripting (XSS) Attacks for Pentesters

SynopsisCross Site Scripting (XSS Attacks for Pentesters, available...
Cross Site Scripting (XSS) Attacks for Pentesters  No.1

Cross Site Scripting (XSS) Attacks for Pentesters, available at $39.99, has an average rating of 3.65, with 16 lectures, based on 48 reviews, and has 281 subscribers.

You will learn about Learn about the most widely find Injection Attack, Cross Site Scripting (XSS). Explore in-depth about XSS and its less known derivatives like mXSS and RPO XSS Learn how to detect XSS in a Web Application Learn about real world red team XSS Exploitation. Learn how to break different contexts and execute code. This course is ideal for individuals who are Pentesters or Web Application Security Engineers or Web Application Developers or Security Engineers or Students or Anyone with Interest in Web Security It is particularly useful for Pentesters or Web Application Security Engineers or Web Application Developers or Security Engineers or Students or Anyone with Interest in Web Security.

Enroll now: Cross Site Scripting (XSS) Attacks for Pentesters

Summary

Title: Cross Site Scripting (XSS) Attacks for Pentesters

Price: $39.99

Average Rating: 3.65

Number of Lectures: 16

Number of Published Lectures: 16

Number of Curriculum Items: 16

Number of Published Curriculum Objects: 16

Original Price: ?6,500

Quality Status: approved

Status: Live

What You Will Learn

  • Learn about the most widely find Injection Attack, Cross Site Scripting (XSS).
  • Explore in-depth about XSS and its less known derivatives like mXSS and RPO XSS
  • Learn how to detect XSS in a Web Application
  • Learn about real world red team XSS Exploitation.
  • Learn how to break different contexts and execute code.
  • Who Should Attend

  • Pentesters
  • Web Application Security Engineers
  • Web Application Developers
  • Security Engineers
  • Students
  • Anyone with Interest in Web Security
  • Target Audiences

  • Pentesters
  • Web Application Security Engineers
  • Web Application Developers
  • Security Engineers
  • Students
  • Anyone with Interest in Web Security
  • Cross Site Scripting or XSS is still one of the most common injection vulnerability that exist in modern as well as legacy Web Applications. This course will teach XSS in-depth and even talk about the lesser known derivatives of XSS called Mutation XSS (mXSS) and Relative Path Overwrite XSS (RPO XSS). If you are interested in learning about the different types of XSS, different context in XSS, and about real world red team XSS Exploitation, then this course is for you and it does not take hours. Invest just 2 hours and master XSS in-depth.

    This course is completely hands-on and every concept is explained with a demo or exercise. This allow students to try out all the things that they have learned. This course explains XSS, its types, context and also discuss about exploiting XSS vulnerabilities in real world where you can perform offensive attacks ranging from Keylogging, Cookie Stealing, Phishing, Victim/Browser/Network Fingerprinting to much advanced attacks like reverse TCP shell, Driveby Attacks etc with OWASP Xenotix XSS Exploit Framework.

    OWASP Xenotix XSS Exploit Framework is an Advanced Cross Site Scripting Vulnerability Detection and Exploitation Framework written by the author of this course. Finally we will also discuss about XSS Protection where we discuss about Input Validation, Context Sensitive output escaping and the various security headers that help us to mitigate XSS. Also as a take away you will get The Ultimate XSS Protection Cheat sheet from OpenSecurity.

    The course will cover the following things.

  • What is XSS?
  • Why XSS?
  • Types of XSS
  • Reflected XSS or Non-Persistent XSS
  • Stored XSS or Persistent XSS
  • DOM XSS
  • mXSS or Mutation XSS
  • RPO or Relative Path Overwrite XSS
  • What are the Source of XSS?
  • Different Contexts in XSS
  • HTML Context
  • Attribute Context
  • URL Context
  • Style Context
  • Script Context
  • Attacks in Real World
  • Exploiting XSS with OWASP Xenotix XSS Exploit Framework
  • XSS Protection
  • Course Curriculum

    Chapter 1: Introduction

    Lecture 1: Introduction to Cross Site Scripting (XSS) Attacks for Pentesters

    Lecture 2: What, Why and Types of XSS

    Chapter 2: Types of XSS

    Lecture 1: Reflected XSS or Non-Persistent XSS

    Lecture 2: Stored XSS or Persistent XSS

    Lecture 3: DOM XSS

    Lecture 4: mXSS or Mutation XSS

    Lecture 5: RPO or Relative Path Overwrite XSS

    Chapter 3: Source of XSS

    Lecture 1: What are the different Sources of XSS?

    Chapter 4: Different Contexts in XSS

    Lecture 1: HTML Context

    Lecture 2: Attribute Context

    Lecture 3: URL Context

    Lecture 4: Style Context

    Lecture 5: Script Context

    Chapter 5: XSS Attacks in Realworld

    Lecture 1: Exploiting XSS with OWASP Xenotix XSS Exploit Framework

    Chapter 6: XSS Protection

    Lecture 1: XSS Protection

    Lecture 2: XSS Protection Cheatsheet

    Instructors

  • Cross Site Scripting (XSS) Attacks for Pentesters  No.2
    Ajin Abraham
    Security Researcher
  • Rating Distribution

  • 1 stars: 7 votes
  • 2 stars: 3 votes
  • 3 stars: 14 votes
  • 4 stars: 13 votes
  • 5 stars: 11 votes
  • Frequently Asked Questions

    How long do I have access to the course materials?

    You can view and review the lecture materials indefinitely, like an on-demand channel.

    Can I take my courses with me wherever I go?

    Definitely! If you have an internet connection, courses on Udemy are available on any device at any time. If you don’t have an internet connection, some instructors also let their students download course lectures. That’s up to the instructor though, so make sure you get on their good side!