Burp Suite for E-commerce API and Web Security: WASP Top 10
Master Burp Suite to secure e-commerce APIs and web applications against OWASP Top 10 vulnerabilities.
...
Share
Burp Suite Configuration and E-commerce Environment Setup
Unit 1: Burp Suite Initial Setup
Burp Suite Overview
Installation & Launch
Proxy Settings
Browser Configuration
SSL Certificate Setup
Unit 2: E-commerce Environment Setup
E-commerce Platform
Docker Setup
Network Configuration
User Account Creation
Environment Validation
Injection Flaws and Broken Authentication
Unit 1: SQL Injection Vulnerabilities
SQL Injection Overview
SQLi with Burp Suite
Exploiting SQLi
SQLi Prevention
SQLi Real World
Unit 2: OS and LDAP Injection
OS Injection Overview
LDAP Injection Overview
OS Injection with Burp
LDAP Injection with Burp
Injection Prevention
Unit 3: Broken Authentication
Auth: The Basics
Weak Passwords
Session Management
Auth Prevention
Real World Auth
Sensitive Data Exposure and XXE Attacks
Unit 1: Understanding Sensitive Data Exposure
What is Sensitive Data?
Common Storage Mistakes
Insecure Data Transfer
Data Exposure in APIs
Burp: Passive Scanning
Unit 2: Preventing Sensitive Data Exposure
Encryption Best Practices
Access Control
Data Masking
Secure API Design
Monitoring and Logging
Unit 3: XML External Entity (XXE) Attacks
What is an XXE Attack?
Identifying XXE
Exploiting XXE
XXE: Blind Attacks
Preventing XXE Attacks
Broken Access Control and Security Misconfiguration
Unit 1: Understanding Broken Access Control
Access Control Defined
Bypassing ACLs
IDOR: The Silent Killer
Parameter Tampering
Burp for Access Control
Unit 2: Security Misconfiguration Deep Dive
What is Misconfiguration?
Default Credentials
Unnecessary Services
Header Hardening
Burp for Misconfiguration
XSS, Insecure Deserialization, and Component Vulnerabilities
Unit 1: Cross-Site Scripting (XSS) Deep Dive
XSS: An Introduction
Reflected XSS
Stored XSS
DOM-Based XSS
XSS Mitigation
Unit 2: Insecure Deserialization
Intro to Deserialization
Detecting Vulnerabilities
Exploiting Deserialization
Preventing Attacks
Secure Configuration
Unit 3: Components with Known Vulnerabilities
Component Vulnerabilities
Identifying Components
Dependency Check
Updating Components
Vulnerability Monitoring
Insufficient Logging & Monitoring
Unit 1: Understanding Insufficient Logging & Monitoring
The Importance of Logs
What to Log?
Where to Store Logs?
Monitoring Essentials
Log Retention Policies
Unit 2: Burp Suite for Logging Analysis
Burp's Role in Logging
Finding Missing Logs
Analyzing Log Content
Testing Error Handling
Reporting Findings
Unit 3: Mitigating Insufficient Logging & Monitoring
Enhance Logging Practices
Improve Monitoring
Incident Response
Automation
Regular Audits