Bypassing Content Security Policy in Modern Web Applications

Learn How Hackers Can Bypass the Most Powerful Defensive Technology in Modern Web Applications

4.85 (12 reviews)
Udemy
platform
English
language
Network & Security
category
instructor
Bypassing Content Security Policy in Modern Web Applications
91
students
1 hour
content
May 2023
last update
$59.99
regular price

What you will learn

Discover how hackers can bypass a CSP via ajax(dot)googleapis(dot)com

Explore how hackers can bypass a CSP via Flash file

Learn how hackers can bypass a CSP via polyglot file

Discover how hackers can bypass a CSP via AngularJS

Learn step by step how all these attacks work in practice (DEMOS)

Check if your Content Security Policy is vulnerable to these attacks

Become a successful penetration tester / ethical hacker

Learn from one of the top hackers at HackerOne

Why take this course?

Content Security Policy (CSP) is the most powerful defensive technology in modern web applications. For hackers, this is an obstacle that blocks their attacks. That’s why hackers are very interested in bypassing Content Security Policy and obviously you don’t want that to happen.

In this course, you’ll learn how your Content Security Policy can be bypassed by hackers. What’s more, you’ll learn how to check if your Content Security Policy is vulnerable to these attacks. First, I’ll show you how hackers can bypass a CSP via ajax(dot)googleapis(dot)com. Next, I’ll present how hackers can bypass a CSP via Flash file. After that, I’ll explain to you what a polyglot file is and how it can be used to bypass a CSP. Finally, I’ll present how hackers can bypass a CSP via AngularJS.
-----------------------------------------------

*** For every single attack presented in this course there is a DEMO ***  so that you can see step by step how these attacks work in practice. I hope this sounds good to you and I can’t wait to see you in the class.
-----------------------------------------------

  • Case #1:  Bypassing CSP via ajax(dot)googleapis(dot)com

  • Case #2: Bypassing CSP via Flash File

  • Case #3: Bypassing CSP via Polyglot File

  • Case #4: Bypassing CSP via AngularJS

Screenshots

Bypassing Content Security Policy in Modern Web Applications - Screenshot_01Bypassing Content Security Policy in Modern Web Applications - Screenshot_02Bypassing Content Security Policy in Modern Web Applications - Screenshot_03Bypassing Content Security Policy in Modern Web Applications - Screenshot_04

Reviews

Kyle
June 1, 2023
Great explanations of various levels of CSP protections and potential bypass mechanisms. Would be nice if the code examples were available to copy/paste for note-taking.

Charts

Price

Bypassing Content Security Policy in Modern Web Applications - Price chart

Rating

Bypassing Content Security Policy in Modern Web Applications - Ratings chart

Enrollment distribution

Bypassing Content Security Policy in Modern Web Applications - Distribution chart
5347914
udemy ID
5/26/2023
course created date
5/28/2023
course indexed date
Bot
course submited by