Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

Coursera

Ethical Hacking, Pentesting & Bug Bounty Hunting v2

Packt via Coursera

Overview

Google, IBM & Meta Certificates – 40% Off
One plan covers every Professional Certificate on Coursera.
Unlock All Certificates
This course features Coursera Coach! A smarter way to learn with interactive, real-time conversations that help you test your knowledge, challenge assumptions, and deepen your understanding as you progress through the course. In this comprehensive course, you will learn how to identify and exploit subdomain takeovers, HTML injection vulnerabilities, and clickjacking attacks, with hands-on labs to develop your ethical hacking skills. You will be guided through real-world exploitation techniques, including AWS, Tumblr, and Shopify subdomain takeovers, using tools like Burp Suite, Subjack, and Subfinder. By diving into practical demonstrations and case studies, you’ll gain invaluable experience in conducting security assessments. The course walks you through a variety of advanced hacking topics, starting with the basics of subdomain takeovers and moving on to more complex concepts such as SQL Injection, SSRF, and Remote Code Execution (RCE). The course also includes multiple lab setups for practical experience. Whether you're a beginner looking to start your ethical hacking journey or an intermediate learner wanting to enhance your skills, this course will help you build expertise in penetration testing and web security. No prior experience is required, although basic knowledge of web technologies is beneficial. By the end of the course, you will be able to exploit subdomain takeovers, conduct SQL injections, bypass clickjacking protections, and perform live exploitation techniques.

Syllabus

  • Introduction
    • In this module, we will introduce the course structure and goals, covering essential disclaimers and updates. Additionally, you will set up the Burp Suite Proxy environment to prepare for the hands-on labs throughout the course. This foundational setup ensures that you are equipped for the practical aspects of the course.
  • Future Updates
    • In this module, we will explore potential future updates that will be incorporated into the course. You will be introduced to upcoming tools and resources that will enhance your learning experience, ensuring the course remains current and comprehensive.
  • Setting up Environment
    • In this module, we will guide you through setting up Burp Suite Proxy and the required environment for conducting penetration testing labs. This section is crucial for familiarizing yourself with the tools and processes needed for future practical exercises.
  • Subdomain Takeovers
    • In this module, we will dive deep into subdomain takeovers, teaching you how to identify and enumerate subdomains for testing. You will also gain hands-on experience using tools like Sublister and Subjack to exploit vulnerabilities and take over subdomains.
  • HTML Injection
    • In this module, we will cover HTML injection, explaining how it works and how attackers exploit it. Through a series of practical exercises and live demos, you will learn to identify and mitigate HTML injection vulnerabilities.
  • Click Jacking
    • In this module, we will focus on clickjacking, teaching you how attackers use this technique to trick users into clicking on malicious content. You will practice exploiting clickjacking vulnerabilities through various hands-on exercises and demonstrations.
  • File Inclusion Exploitation
    • In this module, we will explore file inclusion vulnerabilities, specifically LFI and RFI. You will practice exploiting these vulnerabilities in a lab setup and learn how to escalate LFI to RCE for deeper exploitation.
  • Broken Link Hijacking
    • In this module, we will cover Broken Link Hijacking (BLH), teaching you how to identify and exploit this vulnerability in real-world scenarios. You'll practice using different tools to automate and exploit BLH for penetration testing.
  • SQL Injection
    • In this module, we will dive into SQL Injection (SQLi), one of the most common web application vulnerabilities. You will learn how to exploit SQLi on various database tables and use tools like SQLMap for automating attacks.
  • SSRF
    • In this module, we will teach you the concept of SSRF and how it can be exploited to target both internal and external systems. You will practice exploiting SSRF vulnerabilities and bypassing security filters for successful attacks.
  • Remote Code Execution
    • In this module, we will explore Remote Code Execution (RCE) vulnerabilities, explaining how attackers exploit them. You will practice executing RCE attacks in a controlled environment and understand the severity of these vulnerabilities.
  • How to start with Bug Bounty Platforms and Reporting
    • In this module, we will introduce you to bug bounty platforms, guiding you on how to get started with platforms like BugCrowd and HackerOne. You'll learn how to submit vulnerability reports and understand the processes involved in ethical hacking and bug bounty hunting.

Taught by

Packt - Course Instructors

Reviews

Start your review of Ethical Hacking, Pentesting & Bug Bounty Hunting v2

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.