OWASP Top 10: A03:2021-Injection
OWASP
| Intermediate
- 11 videos | 1h 6m
- Includes Assessment
- Earns a Badge
Many web applications accept input from either external data sources or app users. In this course, learn about the types of injection attacks and how malicious users submit malicious code or commands to a web app for execution by the web server stack. Next, practice testing a web app for injection vulnerabilities using the OWASP ZAP tool, setting low security for a vulnerable web app tool, and executing injection attacks against a web app. Finally, discover how to mitigate injection attacks using input validation and input sanitization. Upon completion, you'll be able to identify and mitigate web app injection attacks.
WHAT YOU WILL LEARN
-
Discover the key concepts covered in this courseRecognize types of injection attacksOutline how to mitigate injection attacks using fuzzing, input validation, and sanitizationTest a web app for injection vulnerabilities using the owasp zed attack proxy (zap) toolExecute a sql injection attack against a web application using freely available toolsExecute a command injection attack against a web application using freely available tools
-
Identify how java and javascript are used in web applicationsRecognize how cross-site scripting (xss) attacks occurRun a cross-site scripting (xss) attack through web page formsRun a cross-site scripting (xss) attack to hijack a client web browserSummarize the key concepts covered in this course
IN THIS COURSE
-
1m 4s
-
6m 54s
-
6m 56s
-
7m 1s
-
6m 29s
-
6m 59s
-
6m 24s
-
6m 24s
-
7m 51s
-
8m 58s
-
1m 1s
EARN A DIGITAL BADGE WHEN YOU COMPLETE THIS COURSE
Skillsoft is providing you the opportunity to earn a digital badge upon successful completion on some of our courses, which can be shared on any social network or business platform.
Digital badges are yours to keep, forever.