Curso DAST con Burp: práctica real +20 vulnerabilidades
About this course
Aprende DAST con Burp Suite analizando un código real en un entorno propio y totalmente funcional. Descubrirás más de 20 vulnerabilidades aplicando una metodología práctica y guiada, usando payloads efectivos, checklists personalizadas y plugins creados desde cero.Paso a paso, entenderás cómo detectar, confirmar y corregir fallos reales de seguridad, desde inyecciones hasta problemas de autenticación, cabeceras y otros tipos de vulnerabilidades.InyeccionesSQL Injection — localizarás, explotarás de forma controlada y corregirás inyecciones SQL en el código real.SSTI (Server-Side Template Injection) — detectarás plantillas vulnerables, probarás payloads en laboratorio y arreglarás el template.XSS (reflejado/persistente/DOM) — aprenderás a identificar tipos de XSS, reproducir casos seguros y sanitizar entradas.HTML Injection — verás cómo entradas no filtradas afectan la UI y cómo prevenirlo.Command Injection — detectarás llamadas al sistema inseguras, probarás payloads en entorno controlado y corregirás el código.Open Redirect — localizarás redirecciones no validadas y aplicarás validaciones/whitelists.CSRF — entenderás la teoría, crearás pruebas y aplicarás tokens/mitigaciones.Autenticación / AutorizaciónTeoría — comprenderás los conceptos clave de autenticación y autorización.IDOR (Insecure Direct Object Reference) — identificarás y explotarás accesos no autorizados entre usuarios y aplicarás correcciones en el código.JWT — analizarás tokens JWT: validación, firma, expiración y ataques comunes; aprenderás a detectarlos y miti
65/100
CourseAsk score
- What the provider tells you
- 45/45
- Who stands behind it
- 8/35
- How complete the listing is
- 12/20
Scores how much the provider publishes and who stands behind it — not how well it is taught.
What you'll learn
- detect SQL Injection vulnerabilities
- exploit and remediate SSTI
- identify and mitigate different types of XSS
- understand authentication and authorization concepts
- analyze and secure JWT tokens
Course objectives
- develop practical skills in web application security testing
- understand and apply security methodologies
- learn to use Burp Suite effectively
Price shown by Udemy — confirm on their site.
Enroll on UdemyYou'll be redirected to Udemy to complete enrollment.
- Listed & compared by CourseAsk
- English · 0
Coursera