Это пробный урок. Оформите подписку, чтобы получить доступ ко всем материалам курса. Премиум

  1. Урок 1. 00:03:21
    Welcome to the course
  2. Урок 2. 00:01:15
    The OWASP Top 10 explained
  3. Урок 3. 00:02:38
    Claude Code and agentic AI
  4. Урок 4. 00:01:19
    Meet your instructor
  5. Урок 5. 00:04:26
    Installing your tools
  6. Урок 6. 00:01:49
    The presentation tools
  7. Урок 7. 00:01:21
    Getting the source code
  8. Урок 8. 00:01:43
    How we'll study each vulnerability
  9. Урок 9. 00:03:54
    Introducing broken access control
  10. Урок 10. 00:02:07
    IDOR- The scenario
  11. Урок 11. 00:01:45
    IDOR- Why it's dangerous
  12. Урок 12. 00:02:17
    IDOR- Vulnerable version
  13. Урок 13. 00:02:35
    IDOR- Secure version
  14. Урок 14. 00:01:05
    Path traversal- The scenario
  15. Урок 15. 00:01:23
    Path traversal- Why it's dangerous
  16. Урок 16. 00:02:50
    Path traversal- Vulnerable version
  17. Урок 17. 00:02:00
    Path traversal- Secure version
  18. Урок 18. 00:00:48
    Missing function-level auth- The scenario
  19. Урок 19. 00:00:55
    Missing function-level auth- Why it's dangerous
  20. Урок 20. 00:01:22
    Missing function-level auth- Vulnerable version
  21. Урок 21. 00:01:46
    Missing function-level auth- Secure version
  22. Урок 22. 00:02:12
    Introducing security misconfiguration
  23. Урок 23. 00:03:13
    Docker defaults- The scenario
  24. Урок 24. 00:01:32
    Docker defaults- Why it's dangerous
  25. Урок 25. 00:01:36
    Docker defaults- Vulnerable version
  26. Урок 26. 00:02:28
    Docker defaults- Secure version
  27. Урок 27. 00:01:31
    Debug mode in production- The scenario
  28. Урок 28. 00:01:32
    Debug mode in production- Why it's dangerous
  29. Урок 29. 00:01:10
    Debug mode in production- Vulnerable version
  30. Урок 30. 00:02:03
    Debug mode in production- Secure version
  31. Урок 31. 00:01:11
    Missing security headers- The scenario
  32. Урок 32. 00:01:29
    Missing security headers- Why it's dangerous
  33. Урок 33. 00:01:14
    Missing security headers- Vulnerable version
  34. Урок 34. 00:02:00
    Missing security headers- Secure version
  35. Урок 35. 00:02:03
    Introducing supply chain failures
  36. Урок 36. 00:01:16
    Unpinned dependencies- The scenario
  37. Урок 37. 00:01:36
    Unpinned dependencies- Why it's dangerous
  38. Урок 38. 00:00:37
    Unpinned dependencies- Vulnerable version
  39. Урок 39. 00:02:16
    Unpinned dependencies- Secure version
  40. Урок 40. 00:01:27
    Known vulnerabilities- The scenario
  41. Урок 41. 00:01:21
    Known vulnerabilities- Why it's dangerous
  42. Урок 42. 00:04:08
    Known vulnerabilities- Fixing vulnerable dependencies
  43. Урок 43. 00:02:01
    Introducing cryptographic failures
  44. Урок 44. 00:01:05
    Weak password hashing- The scenario
  45. Урок 45. 00:01:30
    Weak password hashing- Why it's dangerous
  46. Урок 46. 00:00:54
    Weak password hashing- Vulnerable version
  47. Урок 47. 00:01:34
    Weak password hashing- Secure version
  48. Урок 48. 00:01:09
    Hard-coded keys- The scenario
  49. Урок 49. 00:01:44
    Hard-coded keys- Why it's dangerous
  50. Урок 50. 00:00:41
    Hard-coded keys- Vulnerable version
  51. Урок 51. 00:02:26
    Hard-coded keys- Secure version
  52. Урок 52. 00:01:29
    SQL injection- The scenario
  53. Урок 53. 00:01:13
    SQL injection- Why it's dangerous
  54. Урок 54. 00:02:09
    SQL injection- Vulnerable version
  55. Урок 55. 00:00:47
    SQL injection- Secure version
  56. Урок 56. 00:01:25
    NoSQL injection too
  57. Урок 57. 00:01:39
    XSS- The scenario
  58. Урок 58. 00:01:40
    XSS- Why it's dangerous
  59. Урок 59. 00:00:48
    XSS- Vulnerable version
  60. Урок 60. 00:01:00
    XSS- Secure version
  61. Урок 61. 00:00:53
    XSS- Secure version (continued)
  62. Урок 62. 00:01:48
    Introducing insecure design
  63. Урок 63. 00:02:15
    No rate limiting- The scenario
  64. Урок 64. 00:01:41
    No rate limiting- Why it's dangerous
  65. Урок 65. 00:00:56
    No rate limiting- Vulnerable version
  66. Урок 66. 00:02:40
    No rate limiting- Secure version
  67. Урок 67. 00:01:55
    Client-side only enforcement- The scenario
  68. Урок 68. 00:00:59
    Client-side only enforcement- Why it's dangerous
  69. Урок 69. 00:01:30
    Client-side only enforcement- Vulnerable version
  70. Урок 70. 00:01:57
    Introducing authentication failures
  71. Урок 71. 00:01:17
    Weak password policies- The scenario
  72. Урок 72. 00:00:54
    Weak password policies- Why it's dangerous
  73. Урок 73. 00:01:27
    Weak password policies- Vulnerable version
  74. Урок 74. 00:03:28
    Weak password policies- Secure version
  75. Урок 75. 00:01:18
    Insecure password reset- The scenario
  76. Урок 76. 00:01:18
    Insecure password reset- Why it's dangerous
  77. Урок 77. 00:01:55
    Insecure password reset- Vulnerable version
  78. Урок 78. 00:02:37
    Insecure password reset- Secure version
  79. Урок 79. 00:00:33
    Introducing integrity failures
  80. Урок 80. 00:02:05
    Mass assignment- The scenario
  81. Урок 81. 00:00:42
    Mass assignment- Why it's dangerous
  82. Урок 82. 00:01:14
    Mass assignment- Vulnerable version
  83. Урок 83. 00:00:52
    Mass assignment- Secure version
  84. Урок 84. 00:01:46
    Untrusted CDNs- The scenario
  85. Урок 85. 00:01:04
    Untrusted CDNs- Why it's dangerous
  86. Урок 86. 00:01:18
    Untrusted CDNs- Vulnerable version
  87. Урок 87. 00:03:39
    Untrusted CDNs- Secure version
  88. Урок 88. 00:00:36
    Introducing logging and alerting failures
  89. Урок 89. 00:01:18
    No auth logging- The scenario
  90. Урок 90. 00:01:00
    No auth logging- Why it's dangerous
  91. Урок 91. 00:01:40
    No auth logging- Vulnerable version
  92. Урок 92. 00:02:27
    No auth logging- Secure version
  93. Урок 93. 00:01:27
    No monitoring- The scenario
  94. Урок 94. 00:00:44
    No monitoring- Why it's dangerous
  95. Урок 95. 00:01:07
    No monitoring- Vulnerable version
  96. Урок 96. 00:02:19
    No monitoring- Secure version
  97. Урок 97. 00:00:47
    Introducing mishandling of exceptional conditions
  98. Урок 98. 00:01:50
    Verbose error messages- The scenario
  99. Урок 99. 00:00:59
    Verbose error messages- Why it's dangerous
  100. Урок 100. 00:01:07
    Verbose error messages- Vulnerable version
  101. Урок 101. 00:01:46
    Verbose error messages- Secure version
  102. Урок 102. 00:01:57
    Missing transactions- The scenario
  103. Урок 103. 00:00:31
    Missing transactions- Why it's dangerous
  104. Урок 104. 00:01:29
    Missing transactions- Vulnerable version
  105. Урок 105. 00:03:08
    Missing transactions- Secure version
  106. Урок 106. 00:02:14
    Why 13 markdown files matter
  107. Урок 107. 00:01:22
    Meet the security lead
  108. Урок 108. 00:05:25
    Core components of the security lead agent
  109. Урок 109. 00:05:19
    The security lead markdown file
  110. Урок 110. 00:05:42
    Choosing our target applications
  111. Урок 111. 00:02:33
    Setting up the projects
  112. Урок 112. 00:05:05
    Setting up Kibitzr
  113. Урок 113. 00:13:14
    Analyzing Kibitzr with our agent
  114. Урок 114. 00:13:30
    Reviewing the security report
  115. Урок 115. 00:08:10
    Fixing the SMTP TLS issue
  116. Урок 116. 00:15:16
    Fixing tier 1 issues 2, 3, and 4
  117. Урок 117. 00:05:43
    Analyzing Superset with our agent
  118. Урок 118. 00:02:40
    Analysis complete
  119. Урок 119. 00:11:25
    Reviewing the security report_2
  120. Урок 120. 00:02:51
    The hardening launch list
  121. Урок 121. 00:06:38
    Reviewing the logging overview
  122. Урок 122. 00:08:45
    Adding the guest JWT check feature
  123. Урок 123. 00:05:28
    Analyzing the Paperless-ngx Project
  124. Урок 124. 00:13:32
    Running a Security Review on Paperless-ngx
  125. Урок 125. 00:06:12
    Fixing the RCE from Unsafe Redis Pickle Deserialization
  126. Урок 126. 00:11:23
    Lightning Review