OWASP Top 10: A2 - Broken Authentication
OWASP
| Intermediate
- 16 videos | 1h 32m 15s
- Includes Assessment
- Earns a Badge
Hardening user and device authentication can go a long way in securing web applications. In this course, you'll start by learning the difference between authentication and authorization, where authorization follows successful authentication. You'll also learn how authentication and authorization are related to web application security. Next, you'll explore how to hash and encrypt user credentials and harden user accounts through Microsoft Group Policy. You'll then examine how to use freely available tools to crack user credentials in various ways, such as using the John the Ripper tool to pass Linux passwords and the Hydra tool to crack RDP passwords. Lastly, you'll learn how to enable user multi-factor authentication and conditional access policies, as well as how to mitigate weak authentication.
WHAT YOU WILL LEARN
-
Discover the key concepts covered in this courseDifferentiate between authentication and authorizationRecognize how weak authentication configurations can lead to system compromiseHash user credentialsEncrypt user credentialsUse wireshark to view plain text credential transmissionsHarden user authentication settings using microsoft group policyUse the hydra tool to crack web form user passwords
-
Use burp suite to crack web form user passwordCrack rdp passwords using hydraUse john the ripper to crack linux passwordsUse the social engineering toolkit (set) to steal user credentialsEnable multi-factor authentication for a microsoft azure cloud user accountConfigure a conditional access policy in microsoft azureRecognize how to mitigate broken authentication attacksSummarize the key concepts covered in this course
IN THIS COURSE
-
1m 42s
-
6m 47s
-
6m 2s
-
6m 44s
-
5m 29s
-
6m 20s
-
4m 52s
-
7m 58s
-
8m 35s
-
6m 18s
-
5m 52s
-
5m 26s
-
7m 52s
-
6m 10s
-
4m 57s
-
1m 11s
EARN A DIGITAL BADGE WHEN YOU COMPLETE THIS COURSE
Skillsoft is providing you the opportunity to earn a digital badge upon successful completion on some of our courses, which can be shared on any social network or business platform.
Digital badges are yours to keep, forever.