드림핵을 시작하기전에는 단순히 웹 개발 지식만 있는 상태였는데 web 보안 커리큘럼을 듣고서 시큐어 코딩 능력도 향상 시킬 수 있어서 좋았습니다.
Web Hacking Advanced - Server-Side
Learn advanced server-side web hacking techniques, and analyze/exploit vulnerabilities commonly found in real-world services. This Path is designed for those seeking to enhance their server-side security skills.
Web Hacking Advanced - Server-Side
Learn advanced server-side web hacking techniques, and analyze/exploit vulnerabilities commonly found in real-world services. This Path is designed for those seeking to enhance their server-side security skills.
0% Completed
Total 0 completed
Lecture
0 /20
Excluded
20
Wargame
0 /9
9
Quiz
0 /7
7
The Lab is a practice and is not included in the overall progress.
Why It's Worth Your Time
Behind the web services we use daily, web servers process data and deliver content to users. Security vulnerabilities on the server-side can lead to severe incidents like authentication bypass, data breaches, and system compromises. This Path dives deeper into real-world techniques such as Blind SQL Injection, NoSQL Injection, Command Injection, and file upload vulnerabilities. Through hands-on exercises beyond theory, you will build practical web hacking skills for real-world scenarios.
Topics Covered
- Blind SQL Injection: Error-based and Time-based techniques
- DBMS Fingerprinting techniques
- NoSQL Injection in MongoDB, CouchDB, and Redis
- WAF bypass and web security filter bypass
- Command Injection analysis in Windows and Linux environments
- File upload/download vulnerabilities and .htaccess exploitation
Recommended For
- Aspiring white-hat hackers, security consultants, and bug bounty hunters
- Those aiming to master server-side web hacking techniques
- CTF players targeting advanced server-side challenges
Prerequisite Knowledge
- Strong understanding of web hacking basics
- Basic Linux usage skills
- Basic knowledge of web application architecture
- Basic HTML knowledge
- Basic JavaScript knowledge
- Basic SQL knowledge
Unit Composition
- 1700 Coin700 CoinExplore advanced SQL Injection techniques and WAF (Web Application Firewall) bypass strategies.Blind SQL Injection Advanced[WHA-S] ExploitTech: Blind SQL Injection AdvancedError & Time based SQL Injection[WHA-S] ExploitTech: Error & Time based SQL Injection[Exercise] Blind SQL Injection Advanced[WHA-S] Exercise: Blind SQL Injection Advancedblind sql injection advanced[Self-practice] Error & Time based Injectionerror based sql injectionBypass WAF[WHA-S] ExploitTech: Bypass WAFLab: WAF BypassDBMS Misconfiguration[WHA-S] Exploit Tech: DBMS MisconfigurationQuiz: DBMS Misconfiguration[Exercise] Bypass WAF[WHA-S] Exercise: Bypass WAFsql injection bypass WAF[Self-practice] Bypass WAF Advancedsql injection bypass WAF Advanced
- 2
- 3500 Coin500 CoinLearn in depth about security vulnerabilities and attack techniques targeting various NoSQL databases.CouchDB[WHA-S] ExploitTech: CouchDBMSMongoDB[WHA-S] ExploitTech: MongoDB DBMSLab: MongoDB InjectionLab: MongoDB Blind InjectionQuiz: MongoDB DBMSRedis[WHA-S] ExploitTech: Redis DBMSLab: Redis[Exercise] CouchDB[WHA-S] Exercise: CouchDBNoSQL-CouchDB[Self-practice] RedisphpMyRedis
- 4Command Injection for Linux[WHA-S] ExploitTech: Command Injection for LinuxCommand Injection for Windows[WHA-S] Background: Command Injection for WindowsQuiz: Command Injection for WindowsCommand Injection Vulnerability Cases[WHA-S] ExploitTech: Command Injection Vulnerability casesLab: PHP escapeshellcmd Command Injection[Exercise] Command Injection Advanced[WHA-S] Exercise: Command Injection AdvancedCommand Injection Advanced
- 5Learn about file upload/download vulnerabilities across various environments and how to exploit them.File Vulnerabilities for Windows[WHA-S] Background: File Vulnerabilities for WindowsQuiz: File Vulnerabilities for WindowsFile Vulnerabilities for Linux[WHA-S] Background: File Vulnerabilities for LinuxQuiz: File Vulnerabilities for LinuxFile Vulnerability Cases[WHA-S] ExploitTech: File Vulnerability cases[Exercise] File Vulnerability Advanced[WHA-S] Exercise: File Vulnerability AdvancedFile Vulnerability Advanced for linux[Self-practice] Apache htaccessApache htaccess
Reviews
0% Completed
Total 0 completed
Lecture
0 /20
Excluded
20
Wargame
0 /9
9
Quiz
0 /7
7
The Lab is a practice and is not included in the overall progress.
