Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

Using Snyk to Find & Fix Vulnerabilities

John Hammond via YouTube

Overview

Google, IBM & Meta Certificates – 40% Off
One Coursera Plus subscription covers most Professional Certificates on Coursera.
Unlock All Certificates
This introductory hands-on course demonstrates using Snyk to identify and patch vulnerabilities in application dependencies and Docker containers. It applies the workflow to the Goof vulnerable web application and the Hack The Box BlitzProp challenge, including directory traversal, prototype pollution, and remote code execution.

Syllabus

- BlitzProp HackTheBox Cyber Apocalypse CTF challenge Intro.
- What is snyk?.
- Snyk can be FREE!.
- Connecting Snyk to Github.
- Discovering Goof, the Vulnerable Web App.
- Deploying Goof.
- Interacting with Goof.
- Finding Directory Traversal/File Access.
- Snyk Vulnerability Database.
- Patching Vulnerabilities with Snyk.
- Pivoting back to the HackTheBox BlitzProp challenge.
- Finding Prototype Pollution and RCE with Snyk.
- Deploying the BlitzProp challenge with Docker.
- Exploiting the Prototype Pollution vulnerability.
- Using Snyk to Patch the Vulnerability.
- Validating the change with our exploit.
- Wrap Up & Thank You.

Taught by

John Hammond

Reviews

Start your review of Using Snyk to Find & Fix Vulnerabilities

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.