SHOW:
|
|
- or go back to the newest paste.
| 1 | This is the training I (Kiran Karnad) used to provide at the 3-day infosec training workshop when I was working at VCIPL | |
| 2 | ||
| 3 | Module 00 - Student Introduction | |
| 4 | Student Introduction | |
| 5 | Certification | |
| 6 | ECSA Track | |
| 7 | LPT Track | |
| 8 | What next after ECSA Training? | |
| 9 | Demo - Overview of Available Resources | |
| 10 | Lab Sessions | |
| 11 | Student Introduction Review | |
| 12 | Module 01 - The Need for Security Analysis | |
| 13 | The Need for Security Analysis | |
| 14 | What are we Concerned About? | |
| 15 | So What are you Trying to Protect? | |
| 16 | Why are Intrusions so Often Successful? | |
| 17 | What are the Greatest Challenges? | |
| 18 | Environmental Complexity | |
| 19 | New Technologies | |
| 20 | New Threats and Exploits | |
| 21 | Demo - Keep Updated with Research | |
| 22 | Limited Focus | |
| 23 | Limited Expertise | |
| 24 | Tool: Data Loss Cost Calculator | |
| 25 | Demo - Tech//404 Data Loss Calculator | |
| 26 | In Order to Ensure… | |
| 27 | Authentication | |
| 28 | Authorization | |
| 29 | Confidentiality | |
| 30 | Integrity | |
| 31 | Availability | |
| 32 | Non-Repudiation | |
| 33 | We Must be Diligent | |
| 34 | Threat Agents | |
| 35 | Assessment Questions | |
| 36 | How Much Security is Enough? | |
| 37 | Risk | |
| 38 | Simplifying Risk | |
| 39 | Risk Analysis | |
| 40 | Risk Assessment Answers Seven Questions: | |
| 41 | Steps of Risk Assessment | |
| 42 | Demo - Risk Assessment | |
| 43 | Demo - CIO-view Self-assessment | |
| 44 | Risk Assessment Values | |
| 45 | Demo - Quantitative Threat Analysis | |
| 46 | Information Security Awareness | |
| 47 | Security Policies | |
| 48 | Security Policy Basics | |
| 49 | Demo - Policy Templates | |
| 50 | Types of Policies | |
| 51 | Promiscuous Policy | |
| 52 | Permissive Policy | |
| 53 | Prudent Policy | |
| 54 | Paranoid Policy | |
| 55 | Acceptable-Use Policy | |
| 56 | User-Account Policy | |
| 57 | Remote-Access Policy | |
| 58 | Information-Protection Policy | |
| 59 | Firewall-Management Policy | |
| 60 | Special-Access Policy | |
| 61 | Network-Connection Policy | |
| 62 | Business-Partner Policy | |
| 63 | Data Classification Policies | |
| 64 | Intrusion Detection Policies | |
| 65 | Virus Prevention Policies | |
| 66 | Laptop Security Policy | |
| 67 | Personal Security Policy | |
| 68 | Cryptography Policy | |
| 69 | Fair and Accurate Credit Transactions Act of 2003 (FACTA) | |
| 70 | Other Important Policies | |
| 71 | Policy Statements | |
| 72 | Basic Document Set of Information Security Policies | |
| 73 | ISO 17799 | |
| 74 | Domains of ISO 17799 | |
| 75 | No Simple Solutions | |
| 76 | U.S. Legislation | |
| 77 | California SB 1386 | |
| 78 | Sarbanes-Oxley 2002 | |
| 79 | Gramm-Leach-Bliley Act (GLBA) | |
| 80 | Health Insurance Portability and Accountability Act (HIPAA) | |
| 81 | USA Patriot Act 2001 | |
| 82 | U.K. Legislation | |
| 83 | How Does This Law Affect a Security Officer? | |
| 84 | The Data Protection Act 1998 | |
| 85 | The Human Rights Act 1998 | |
| 86 | Interception of Communications | |
| 87 | The Freedom of Information Act 2000 | |
| 88 | The Audit Investigation and Community Enterprise Act 2005 | |
| 89 | Demo - Vmware Overview | |
| 90 | Demo - Opening an Existing XP VMware System | |
| 91 | Demo - Opening VM Appliance | |
| 92 | Demo - Installing a New VM System | |
| 93 | Demo - Booting XP from Backtrack ISO | |
| 94 | Module 1 Review | |
| 95 | Module 02 - Advanced Googling | |
| 96 | Advanced Googling | |
| 97 | Site Operator | |
| 98 | intitle:index.of | |
| 99 | Demo - Default Pages: tsweb | |
| 100 | error | warning | |
| 101 | Demo - Google as a Proxy | |
| 102 | login | logon | |
| 103 | username | userid | employee.ID | “your username is” | |
| 104 | password | passcode | “your password is” | |
| 105 | admin | administrator | |
| 106 | –ext:html –ext:htm –ext:shtml –ext:asp –ext:php | |
| 107 | inurl:temp | inurl:tmp | inurl:backup | inurl:bak | |
| 108 | Google Advanced Search Form | |
| 109 | Categorization of the Operators | |
| 110 | allinanchor: | |
| 111 | allintext: | |
| 112 | Demo - Google Locating Live Cams | |
| 113 | Locating Public Exploit Sites | |
| 114 | Locating Exploits via Common Code Strings | |
| 115 | Locating Vulnerable Targets | |
| 116 | Locating Targets via Demonstration Pages | |
| 117 | Demo - Google Hack HoneyPot | |
| 118 | Demo - Goolag and Wikto | |
| 119 | Demo - Wikto Results and Google Guide | |
| 120 | Module 2 Review | |
| 121 | Module 03 - TCP/IP Packet Analysis | |
| 122 | TCP/IP Packet Analysis | |
| 123 | TCP/IP Model | |
| 124 | Demo - TCP/IP Movie Recommendation | |
| 125 | Application Layer | |
| 126 | Transport Layer | |
| 127 | Internet Layer | |
| 128 | Network Access Layer | |
| 129 | Comparing OSI and TCP/IP | |
| 130 | Demo - Engage Packet Builder | |
| 131 | TCP | |
| 132 | TCP Header | |
| 133 | IP Header: Protocol Field | |
| 134 | UDP | |
| 135 | TCP and UDP Port Numbers | |
| 136 | Port Numbers | |
| 137 | Demo - Warriors of the Net | |
| 138 | IANA | |
| 139 | Source and Destination Port Numbers | |
| 140 | Demo - Techtionary.com Port Numbers | |
| 141 | What Makes Each Connection Unique? | |
| 142 | Structure of a Packet | |
| 143 | TCP Operation | |
| 144 | Three-Way Handshake | |
| 145 | Demo - Techtionary.com TCP Handshake | |
| 146 | Flow Control | |
| 147 | Windowing | |
| 148 | Windowing and Window Sizes | |
| 149 | Simple Windowing | |
| 150 | Acknowledgement | |
| 151 | Sliding Windows | |
| 152 | Sequencing Numbers | |
| 153 | Synchronization | |
| 154 | Positive Acknowledgment and Retransmission (PAR) | |
| 155 | What is Internet Protocol v6 (IPv6)? | |
| 156 | Why IPv6? | |
| 157 | IPv4/IPv6 Transition Mechanisms | |
| 158 | IPv6 Security Issues | |
| 159 | Security Flaws in IPv6 | |
| 160 | IPv6 Infrastructure Security | |
| 161 | Ipsec | |
| 162 | Firewalls and Packet Filtering | |
| 163 | Denial-of-Service (DoS) Attacks | |
| 164 | UDP Operation | |
| 165 | Internet Control Message Protocol (ICMP) | |
| 166 | ICMP Message Delivery | |
| 167 | Format of an ICMP Message | |
| 168 | Unreachable Networks | |
| 169 | Time Exceeded Message | |
| 170 | IP Parameter Problem | |
| 171 | ICMP Control Messages | |
| 172 | ICMP Redirects | |
| 173 | Clock Synchronization and Transit Time Estimation | |
| 174 | Information Requests and Reply Message Formats | |
| 175 | Address Masks | |
| 176 | Router Solicitation and Advertisement | |
| 177 | Module 3 Review | |
| 178 | Module 04 - Advanced Sniffing Techniques | |
| 179 | Advanced Sniffing Techniques | |
| 180 | Demo - Basic Sniffers | |
| 181 | Demo - Packet Capturing with Windows Packetyzer | |
| 182 | What is Wireshark? | |
| 183 | Wireshark: Filters | |
| 184 | Wireshark: Tshark | |
| 185 | Wireshark: Tcpdump | |
| 186 | Demo - Tcpdump | |
| 187 | Protocol Dissection | |
| 188 | Steps to Solve GNU/ Linux Server Network Connectivity Issues | |
| 189 | Using Wireshark for Network Troubleshooting | |
| 190 | Using Wireshark for System Administration | |
| 191 | ARP Problems | |
| 192 | Demo - Sniffers and ARP | |
| 193 | ICMP Echo Request/Reply Header Layout | |
| 194 | TCP Flags | |
| 195 | Scenario 1: SYN no SYN+ACK | |
| 196 | Scenario 2: SYN Immediate Response RST | |
| 197 | Scenario 3: SYN SYN+ACK ACK | |
| 198 | Tapping into the Network | |
| 199 | Using Wireshark for Security Administration | |
| 200 | Sniffer Detection | |
| 201 | Wireless Sniffing with Wireshark | |
| 202 | Frequency | |
| 203 | Using Channel Hopping | |
| 204 | Interference and Collisions | |
| 205 | Recommendations for Sniffing Wireless Traffic | |
| 206 | Analyzing Wireless Traffic | |
| 207 | IEEE 802.11 Header | |
| 208 | Filters | |
| 209 | Unencrypted Data Traffic | |
| 210 | Identifying Hidden SSIDs | |
| 211 | Identifying EAP Authentication Failures | |
| 212 | Identifying WEP | |
| 213 | Identifying IPsec/VPN | |
| 214 | Decrypting Traffic | |
| 215 | Scanning | |
| 216 | TCP Connect Scan | |
| 217 | SYN Scan | |
| 218 | XMAS Scan | |
| 219 | Null Scan | |
| 220 | Remote Access Trojans | |
| 221 | Wireshark DNP3 Dissector Infinite Loop Vulnerability | |
| 222 | Time Stamps | |
| 223 | Time Zones | |
| 224 | Packet Reassembling | |
| 225 | Checksums | |
| 226 | Module 4 Review | |
| 227 | Module 05 - Vulnerability Analysis with Nessus | |
| 228 | Vulnerability Analysis with Nessus | |
| 229 | Nessus | |
| 230 | Features of Nessus | |
| 231 | Nessus Assessment Process | |
| 232 | Demo - Nessus on Windows | |
| 233 | Demo - Nessus on Windows Cont'd and GFI LANguard Comparison | |
| 234 | False Positives | |
| 235 | Examples of False Positives | |
| 236 | Identifying False Positives | |
| 237 | Suspicious Signs | |
| 238 | Demo - Backtrack 4 Nessus Install | |
| 239 | Module 5 Review | |
| 240 | Module 06 - Advanced Wireless Testing | |
| 241 | Advanced Wireless Testing | |
| 242 | Wireless Concepts | |
| 243 | Demo - Techtionary Website | |
| 244 | 802.11 Types | |
| 245 | Core Issues with 802.11 | |
| 246 | What’s the Difference? | |
| 247 | Other Types of Wireless | |
| 248 | Spread Spectrum Background | |
| 249 | Channels | |
| 250 | Access Point | |
| 251 | Service Set ID | |
| 252 | Demo - Linksys-AP Config SSID | |
| 253 | Default SSIDs | |
| 254 | Chipsets | |
| 255 | Wi-Fi Equipment | |
| 256 | Expedient Antennas | |
| 257 | Vulnerabilities to 802.1x and RADIUS | |
| 258 | Security - WEP | |
| 259 | Wired Equivalent Privacy (WEP) | |
| 260 | Exclusive OR | |
| 261 | Encryption Process | |
| 262 | Chipping Sequence | |
| 263 | WEP Issues | |
| 264 | WEP - Authentication Phase | |
| 265 | WEP - Shared Key Authentication | |
| 266 | WEP - Association Phase | |
| 267 | WEP Flaws | |
| 268 | WEP Attack | |
| 269 | Demo - Authentication Settings | |
| 270 | Demo - WEP Set-Up Security | |
| 271 | Demo - Cain and Abel WEP Cracking | |
| 272 | WPA Interim 802.11 Security | |
| 273 | WPA | |
| 274 | Demo - Cracking WPA with Cain and Abel | |
| 275 | WPA2 (Wi-Fi Protected Access 2) | |
| 276 | 802.1X Authentication and EAP | |
| 277 | EAP Types | |
| 278 | Cisco LEAP | |
| 279 | TKIP (Temporal Key Integrity Protocol) | |
| 280 | Wireless Networks Testing | |
| 281 | Wireless Communications Testing | |
| 282 | Report Recommendations | |
| 283 | Wireless Attack Countermeasures | |
| 284 | Demo - MAC-SSID Security | |
| 285 | Wireless Penetration Testing with Windows | |
| 286 | War Driving | |
| 287 | The Jargon – WarChalking | |
| 288 | Wireless: Tools of the Trade | |
| 289 | Demo - Kismet in Windows | |
| 290 | Demo - Tool: Kismet in Linux | |
| 291 | Demo - Vistumbler War Driving and GPS Map Plotting | |
| 292 | How Does NetStumbler Work? | |
| 293 | “Active” vs. “Passive” WLAN Detection | |
| 294 | Disabling the Beacon | |
| 295 | Running NetStumbler | |
| 296 | Demo - Tool: Netstumbler | |
| 297 | AirCrack-ng | |
| 298 | AirCrack-ng: How Does it Work? | |
| 299 | AirCrack-ng: FMS and Korek Attacks | |
| 300 | AirCrack-ng: Notes | |
| 301 | Demo - Hacking WEP Encryption | |
| 302 | Determining Network Topology: Network View | |
| 303 | WarDriving and Wireless Penetration Testing with OS X | |
| 304 | Using a GPS | |
| 305 | Deauthenticating Clients | |
| 306 | StumbVerter | |
| 307 | MITM Attack Design | |
| 308 | MITM Attack Variables | |
| 309 | Hardware for the Attack: Antennas, Amps, and WiFi Cards | |
| 310 | Choosing the Right Antenna | |
| 311 | Amplifying the Wireless Signal | |
| 312 | IP Forwarding and NAT using IPtables | |
| 313 | Demo - Jasager fon Router | |
| 314 | Module 6 Review | |
| 315 | Module 07 - Designing a DMZ | |
| 316 | Designing a DMZ | |
| 317 | Introduction | |
| 318 | DMZ Concepts | |
| 319 | DMZ Design Fundamentals | |
| 320 | Advanced Design Strategies | |
| 321 | Types of Firewall and DMZ Architectures | |
| 322 | "Inside vs. Outside" Architecture | |
| 323 | "Three-Homed Firewall" DMZ Architecture | |
| 324 | Weak Screened Subnet Architecture | |
| 325 | Strong Screened Subnet Architecture | |
| 326 | Designing a DMZ using IPtables | |
| 327 | Designing Windows DMZ | |
| 328 | Precautions for DMZ Setup | |
| 329 | Demo - Designing DMZs | |
| 330 | Advanced Implementation of a Solaris DMZ Server | |
| 331 | Solaris DMZ Servers in a Conceptual Highly Available Configuration | |
| 332 | Hardening Checklists for DMZ Servers and Solaris | |
| 333 | Placement of Wireless Equipment | |
| 334 | Access to DMZ and Authentication Considerations | |
| 335 | Wireless DMZ Components | |
| 336 | WLAN DMZ Security Best Practices | |
| 337 | Ethernet Interface Requirements and Configuration | |
| 338 | DMZ Router Security Best Practice | |
| 339 | Six Ways to Stop Data Leaks | |
| 340 | Module 7 Review | |
| 341 | Module 08 - Snort Analysis | |
| 342 | Snort Analysis | |
| 343 | Snort Overview | |
| 344 | Modes of Operation | |
| 345 | Features of Snort | |
| 346 | Configuring Snort | |
| 347 | Snort: Variables | |
| 348 | Snort: Pre-processors | |
| 349 | Snort: Output Plug-ins | |
| 350 | Snort: Rules | |
| 351 | How Snort Operates | |
| 352 | Initializing Snort | |
| 353 | Demo - Snort IDS Testing Scanning Tools | |
| 354 | Signal Handlers | |
| 355 | Parsing the Configuration File | |
| 356 | Decoding | |
| 357 | Possible Decoders | |
| 358 | Pre-processing | |
| 359 | Detection | |
| 360 | Content Matching | |
| 361 | The Stream4 Pre-processor | |
| 362 | Inline Functionality | |
| 363 | Writing Snort Rules | |
| 364 | Snort Rule Header | |
| 365 | Snort Rule Header: Actions | |
| 366 | Snort Rule Header: Other Fields | |
| 367 | IP Address Negation Rule | |
| 368 | IP Address Filters | |
| 369 | The direction Operator | |
| 370 | Rule Options | |
| 371 | Activate/Dynamic Rules | |
| 372 | Metadata Rule Options: msg | |
| 373 | The reference Keyword | |
| 374 | The sid/rev Keyword | |
| 375 | The classtype Keyword | |
| 376 | Payload Detection Rule Options: content | |
| 377 | Modifier Keywords | |
| 378 | The uricontent Keyword | |
| 379 | The fragoffset Keyword | |
| 380 | Writing Good Snort Rules | |
| 381 | Tool for Writing Snort Rules: IDS Policy Manager | |
| 382 | Honeynet Security Console Tool | |
| 383 | Key Features | |
| 384 | Module 8 Review | |
| 385 | Module 09 - Log Analysis | |
| 386 | Log Analysis | |
| 387 | Logs | |
| 388 | Events that Need to be Logged | |
| 389 | What to Look Out For in Logs | |
| 390 | Automated Log Analysis Approaches | |
| 391 | Log Shipping | |
| 392 | Syslog | |
| 393 | Setting up a Syslog | |
| 394 | System Error Logs | |
| 395 | Kiwi Syslog Daemon | |
| 396 | Configuring Kiwi Syslog to Log to a MS SQL Database | |
| 397 | Configuring a Cisco Router for Syslog | |
| 398 | Configuring a DLink Router for Syslog | |
| 399 | Gathering Log Files from an IIS Web Server | |
| 400 | Apache Web Server Log | |
| 401 | AWStats Log Analyzer | |
| 402 | Cisco Router Logs | |
| 403 | Analyzing Netgear Wireless Router Logs | |
| 404 | Wireless Traffic Analysis Using Wireshark | |
| 405 | Configuring Firewall Logs in Local Windows System | |
| 406 | Viewing Local Windows Firewall Log | |
| 407 | Viewing Windows Event Log | |
| 408 | Collecting & Monitoring UNIX Syslog | |
| 409 | iptables | |
| 410 | Log Prefixing with iptables | |
| 411 | Firewall Log Analysis with grep | |
| 412 | SQL Database Log | |
| 413 | Using SQL Server to Analyze Web Logs | |
| 414 | Analyzing Oracle Logs: The Oracle Metric Log File | |
| 415 | ApexSQL Log | |
| 416 | Analyzing Solaris System Logs | |
| 417 | Demo - Splunk | |
| 418 | Module 9 Review | |
| 419 | Module 10 - Advanced Exploits and Tools | |
| 420 | Advanced Exploits and Tools | |
| 421 | Common Vulnerabilities | |
| 422 | Buffer Overflows Revisited | |
| 423 | Smashing the Stack for Fun and Profit | |
| 424 | Smashing the Heap for Fun and Profit | |
| 425 | Format Strings for Chaos and Mayhem | |
| 426 | The Anatomy of an Exploit | |
| 427 | Demo - Fuzzing for Weaknesses | |
| 428 | Vulnerable Code | |
| 429 | Shellcode | |
| 430 | Shellcode Examples | |
| 431 | Shellcode (cont’d) | |
| 432 | Demo - Stack Function | |
| 433 | Delivery Code | |
| 434 | Delivery Code: Example | |
| 435 | Demo - Compiling Exploits from Source Code | |
| 436 | Linux Exploits versus Windows | |
| 437 | Windows versus Linux | |
| 438 | Tools of the Trade: Debuggers | |
| 439 | Tools of the Trade: GDB | |
| 440 | Tools of the Trade: Metasploit | |
| 441 | Demo - Metasploit Intro | |
| 442 | Demo - Metasploit 101 | |
| 443 | Demo - Metasploit Interactive | |
| 444 | Tools of the Trade: Canvas | |
| 445 | Lab | |
| 446 | Tools of the Trade: CORE Impact | |
| 447 | Ways to Use CORE Impact | |
| 448 | Microsoft Baseline Security Analyzer (MBSA) | |
| 449 | Network Security Analysis Tool (NSAT) | |
| 450 | Sunbelt Network Security Inspector (SNSI) | |
| 451 | Demo - Saint Exploit of Windows XP | |
| 452 | Demo - dcom101 Exploit Autoshovel of Shell | |
| 453 | Demo - dcom Exploit Netcat Shovel of Shell and Extracting Hashes | |
| 454 | Demo - Backtrack 4 Milw0rm Metasploit Updates | |
| 455 | Module 10 Review | |
| 456 | Module 11 - Penetration Testing Methodologies | |
| 457 | Penetration Testing Methodologies | |
| 458 | Demo - dradis Effective Information Sharing | |
| 459 | What is Penetration Testing? | |
| 460 | Why Penetration Testing? | |
| 461 | What Should be Tested? | |
| 462 | What Makes a Good Penetration Test? | |
| 463 | Common Penetration Testing Techniques | |
| 464 | Penetration Testing Process | |
| 465 | Scope of Penetration Testing | |
| 466 | Blue Teaming/Red Teaming | |
| 467 | Types of Penetration Testing | |
| 468 | Black-box Penetration Testing | |
| 469 | White-box Penetration Testing | |
| 470 | Announced Testing/ Unannounced Testing | |
| 471 | Grey-box Penetration Testing | |
| 472 | Strategies of Penetration Testing | |
| 473 | External Penetration Testing | |
| 474 | Internal Security Assessment | |
| 475 | Application Security Assessment | |
| 476 | Types of Application Security Assessment | |
| 477 | Network Security Assessment | |
| 478 | Wireless/Remote Access Assessment | |
| 479 | Telephony Security Assessment | |
| 480 | Social Engineering | |
| 481 | Penetration Testing Consultants | |
| 482 | Required Skills Sets | |
| 483 | Hiring a Penetration Tester | |
| 484 | Responsibilities of a Penetration Tester | |
| 485 | Profile of a Good Penetration Tester | |
| 486 | Why Should the Company Hire You? | |
| 487 | Companies’ Concerns | |
| 488 | Methodology | |
| 489 | Demo - NIST Methodology | |
| 490 | Demo - PenTest Templates and Methodologies | |
| 491 | Penetration Testing Roadmap | |
| 492 | Guidelines for Security Checking | |
| 493 | Operational Strategies for Security Testing | |
| 494 | Security Category of the Information System | |
| 495 | Identifying Benefits of Each Test Type | |
| 496 | Prioritizing the Systems for Testing | |
| 497 | ROI on Penetration Testing | |
| 498 | Determining Cost of Each Test Type | |
| 499 | Need for a Methodology | |
| 500 | Penetration Test vs. Vulnerability Test | |
| 501 | Reliance on Checklists and Templates | |
| 502 | Phases of Penetration Testing | |
| 503 | Pre-Attack Phase | |
| 504 | Best Practices | |
| 505 | Results that can be Expected | |
| 506 | Passive Reconnaissance | |
| 507 | Active Reconnaissance | |
| 508 | Attack Phase | |
| 509 | Activity: Perimeter Testing | |
| 510 | Activity: Web Application Testing - I | |
| 511 | Activity: Web Application Testing – II | |
| 512 | Activity: Wireless Testing | |
| 513 | Activity: Acquiring Target | |
| 514 | Activity: Escalating Privileges | |
| 515 | Activity: Execute, Implant, and Retract | |
| 516 | Post-Attack Phase and Activities | |
| 517 | Module 11 Review | |
| 518 | Module 12 - Customers and Legal Agreements | |
| 519 | Customers and Legal Agreements | |
| 520 | Why do Organizations Need Pen-Testing? | |
| 521 | Initial Stages in Penetration Testing | |
| 522 | Understand Customer Requirements | |
| 523 | Create a Checklist of Testing Requirements | |
| 524 | Penetration Testing ‘Rules of Behavior’ | |
| 525 | Demo - ISSAF Customers and Legal | |
| 526 | Penetration Testing Risks | |
| 527 | Penetration Testing by Third Parties | |
| 528 | Precautions While Outsourcing Penetration Testing | |
| 529 | Legal Consequences | |
| 530 | Demo - Computer Crimes and Implications | |
| 531 | Get Out of Jail Free Card | |
| 532 | Permitted Items in Legal Agreement | |
| 533 | Confidentiality and NDA Agreements | |
| 534 | Non-Disclosure and Secrecy Agreements (NDA) | |
| 535 | The Contract | |
| 536 | Liability Issues | |
| 537 | Negligence Claim | |
| 538 | Plan for the Worst | |
| 539 | Drafting Contracts | |
| 540 | How Much to Charge? | |
| 541 | Module 12 Review | |
| 542 | Module 13 - Rules of Engagement | |
| 543 | Rules of Engagement | |
| 544 | Rules of Engagement (ROE) | |
| 545 | Demo - OSSTMM Model | |
| 546 | Scope of ROE | |
| 547 | Steps for Framing ROE | |
| 548 | Clauses in ROE | |
| 549 | Demo - ScreenHunter Desktop Capture Tool | |
| 550 | Module 13 Review | |
| 551 | Module 14 - Penetration Testing Planning and Scheduling | |
| 552 | Penetration Testing Planning and Scheduling | |
| 553 | Test Plan | |
| 554 | Purpose of Test Plan | |
| 555 | Building a Penetration Test Plan | |
| 556 | Demo - Overview OSSTMM | |
| 557 | IEEE STD. 829–1998 SECTION HEADINGS | |
| 558 | Test Plan Identifier | |
| 559 | Test Deliverables | |
| 560 | Penetration Testing Planning Phase | |
| 561 | Define the Scope | |
| 562 | Project Scope | |
| 563 | When to Retest? | |
| 564 | Responsibilities | |
| 565 | Skills and Knowledge Required | |
| 566 | Internal Employees | |
| 567 | Penetration Testing Teams | |
| 568 | Tiger Team | |
| 569 | Building Tiger Team | |
| 570 | Questions to Ask Before Hiring Consultants to the Tiger Team | |
| 571 | Meeting With the Client | |
| 572 | Kickoff Meeting | |
| 573 | Penetration Testing Project Plan | |
| 574 | Work Breakdown Structure or Task List | |
| 575 | Penetration Testing Schedule | |
| 576 | Penetration Testing Project Scheduling Tools | |
| 577 | Test Plan Checklist | |
| 578 | Penetration Testing Hardware/Software Requirements | |
| 579 | EC-Council’s Vampire Box | |
| 580 | Begin Penetration Testing | |
| 581 | Demo - Installing Backtrack 4 into VMWare Environment | |
| 582 | Module 14 Review | |
| 583 | Module 15 - Customers and Legal Agreements | |
| 584 | Pre-Penetration Testing Checklist | |
| 585 | Demo - Pentest Checklist | |
| 586 | Step 1: Gather Information about Client Organization’s History and Background | |
| 587 | Step 2: Visit the Client Organization Premises | |
| 588 | Step 3: List the Client Organization’s Penetration Testing Requirements | |
| 589 | Step 4: Obtain Penetration Testing Permission from the Company’s Stakeholders | |
| 590 | Step 5: Obtain Detailed Proposal of Test and Services that are Proposed to be carried out | |
| 591 | Step 6: Identify the Office Space/Location your Team would be Working in for this Project | |
| 592 | Step 7: Obtain Temporary Identity Cards from the Organization for the Team who is Involved in the Process | |
| 593 | Step 8: Identify who will be Leading the Penetration Testing Project (Chief Penetration Tester) | |
| 594 | Step 9: Request from the Client Organization the Previous Penetration Testing/Vulnerability Assessment Reports | |
| 595 | Step 10: Prepare Rules of Engagement that Lists the Company’s Core Competencies/ Limitations/ Timescales | |
| 596 | Step 11: Hire a Lawyer who Understands IT and can Handle your Penetration Testing Legal Documents | |
| 597 | Step 12: Prepare PT Legal Document and get Vetted with your Lawyer | |
| 598 | Step 13: Prepare Non Disclosure Agreement (NDA) and have the Client Sign them | |
| 599 | Step 14: Obtain (if possible) Liability Insurance from a Local Insurance Firm | |
| 600 | Step 15: Identify your Core Competencies/Limitations | |
| 601 | Step 16: Allocate a Budget for the Penetration Testing Project ( X amount of $ ) | |
| 602 | Step 17: Prepare a Tiger Team | |
| 603 | Step 18: List the Security Tools that you will be using for the Penetration Testing Project | |
| 604 | Step 19: List the Hardware and Software Requirements for the Penetration Testing Project | |
| 605 | Step 20: Identify the Clients Security Compliance Requirements | |
| 606 | Step 21: List the Servers, Workstations, Desktops and Network Devices that need to be Tested | |
| 607 | Step 22: Identify the Type of Testing that would be carried out - Black Box or White Box Testing | |
| 608 | Step 23: Identify the Type of Testing that would be carried out - Announced/ Unannounced | |
| 609 | Step 24: Identify Local Equipment Required for Pen Test | |
| 610 | Step 25: Identify Local Manpower Required for Pen Test | |
| 611 | Step 26: List the Contact Details of Personnel from Client Organization who will be in Charge of the Pen Test | |
| 612 | Step 27: Obtain the Contact Details of the Key Personnel for Approaching in case of an Emergency | |
| 613 | Step 29: List the Tests that will not be carried out at the Client Network | |
| 614 | Step 30: Identify the Purpose of the Test you are carrying out at the Client Organization | |
| 615 | Step 31: Identify the Network Topology in which the Test would be carried out | |
| 616 | Step 32: Obtain Special Permission if Required from Local Law Enforcement Agency | |
| 617 | Step 33: List known Waivers/Exemptions | |
| 618 | Step 34: List the Contractual Constraints in the Penetration Testing Agreement | |
| 619 | Step 35: Identify the Reporting Timescales with the Client Organization | |
| 620 | Step 36: Identify the List of Penetration Testers Required for this Project | |
| 621 | Step 37: Negotiate per Day/per Hour Fee that you will be Charging for the Penetration Testing Project | |
| 622 | Step 38: Draft the Timeline for the Penetration Testing Project | |
| 623 | Step 39: Draft a Quotation for the Services that you'll be Providing to the Client Organization | |
| 624 | Step 40: Identify how the Final Penetration Testing Report will be Delivered to the Client Organization | |
| 625 | Step 41: Identify the Reports to be Delivered After Pen Test | |
| 626 | Step 42: Identify the Information Security Administrator who will be helping you in the Penetration Testing | |
| 627 | Module 15 Review | |
| 628 | Module 16 - Information Gathering | |
| 629 | Information Gathering | |
| 630 | What is Information Gathering? | |
| 631 | Information Gathering Steps | |
| 632 | Step 1: Crawl the Website and Mirror the Pages on Your PC | |
| 633 | Demo - HTTrack Website Copier | |
| 634 | Step 2: Crawl the FTP Site and Mirror the Pages on Your PC | |
| 635 | Demo - Wget and Backtrack 4 Live CD | |
| 636 | Step 3: Look up Registered Information in the Whois Database | |
| 637 | Demo - CentralOps and Domains by Proxy | |
| 638 | Demo - Backtrack and Whois | |
| 639 | Step 4: List the Products Sold by the Company | |
| 640 | Demo - Firecat (Firefox Addons) | |
| 641 | Step 5: List the Contact Information, Email Addresses, and Telephone Numbers | |
| 642 | Step 6: List the Company’s Distributors | |
| 643 | Step 7: List the Company’s Partners | |
| 644 | Demo - Email Spider | |
| 645 | Step 8: Search the Internet, Newsgroups, Bulletin Boards, Negative Websites for Information about the Company | |
| 646 | Demo - Maltego | |
| 647 | Step 9: Search for Trade Association Directories | |
| 648 | Step 10: Search for Link Popularity of Company Website | |
| 649 | Demo - Alexa | |
| 650 | Step 11: Compare Price of Product or Service with the Competitor | |
| 651 | Step 12: Find the Geographical Location | |
| 652 | Demo - Shazou | |
| 653 | Use Google Map to Find Geographical Location | |
| 654 | Step 13: Search the Internet Archive Pages about the Company | |
| 655 | Demo - Archive.org | |
| 656 | Step 14: Search Similar or Parallel Domain Name Listings | |
| 657 | Demo - ServerSniff TLDs | |
| 658 | Step 15: Search Job Posting Sites about the Company | |
| 659 | Step 16: Browse Social Network Websites | |
| 660 | Demo - Social Networking | |
| 661 | Step 17: Write Down Key Employees | |
| 662 | Step 18: Investigate Key Persons – Searching in Google, Look up their Resumes and Cross Link Information | |
| 663 | Step 19: List Employee Company and Personal Email Address | |
| 664 | Step 20: Search for Web Pages Posting Patterns and Revision Numbers | |
| 665 | Demo - No Tech Hacking | |
| 666 | Step 21: Email the Employee Disguised as Customer Asking for Quotation | |
| 667 | Step 22: Visit the Company as Inquirer and Extract Privileged Information | |
| 668 | Step 23: Visit the Company Locality | |
| 669 | Step 24: Use Web Investigation Tools to Extract Sensitive Data Targeting the Company | |
| 670 | Step 25: Use Intelius and Conduct Background Check on Company Key Personnel | |
| 671 | Step 26: Search on eBay for Company’s Presence | |
| 672 | Step 27: Use the Domain Research Tool to Investigate the Company’s Domain | |
| 673 | Step 28: Use the EDGAR Database to Research Company Information | |
| 674 | Step 34: Use GHDB and Search for the Company Name | |
| 675 | Demo - Summary | |
| 676 | Demo - Vmware 64bit Error Fix | |
| 677 | Demo - SEAT | |
| 678 | Demo - Metagoofil Search | |
| 679 | Demo - CORE Impact Email Info Gathering | |
| 680 | Module 16 Review | |
| 681 | Module 17 - Vulnerability Analysis | |
| 682 | Vulnerability Analysis | |
| 683 | Why Assess? | |
| 684 | Vulnerability Classification | |
| 685 | What is Vulnerability Assessment? | |
| 686 | Demo - Vulnerability Research Resources | |
| 687 | Demo - Nessus 4 Windows Install and Wikto Scan Webgoat | |
| 688 | Types of Vulnerability Assessment | |
| 689 | Demo - Nessus 3 Webgoat Scan BT4 | |
| 690 | Demo - Nessus 4 Webgoat Scan | |
| 691 | Demo - GFI LANguard | |
| 692 | How to Conduct a Vulnerability Assessment | |
| 693 | How to Obtain a High Quality Vulnerability Assessment | |
| 694 | Vulnerability Assessment Phases | |
| 695 | Pre-Assessment Phase | |
| 696 | Assessment Phase | |
| 697 | Post-Assessment Phase | |
| 698 | Vulnerability Analysis Stages | |
| 699 | Comparing Approaches to Vulnerability Assessment | |
| 700 | Characteristics of a Good Vulnerability Assessment Solution | |
| 701 | Vulnerability Assessment Considerations | |
| 702 | Vulnerability Assessment Reports | |
| 703 | Demo - Nessus 3 BT Exporting NBE Report | |
| 704 | Vulnerability Report Model | |
| 705 | Timeline | |
| 706 | Types of Vulnerability Assessment Tools | |
| 707 | Choosing a Vulnerability Assessment Tool | |
| 708 | Vulnerability Assessment Tools Best Practices | |
| 709 | Vulnerability Assessment Tools | |
| 710 | Demo - Retina Security Scanner | |
| 711 | Other Vulnerability Tools | |
| 712 | Report | |
| 713 | Vulnerability Assessment Reports | |
| 714 | Automated Scanning Server Reports | |
| 715 | Periodic Vulnerability Scanning Report | |
| 716 | Module 17 Review | |
| 717 | Module 18 - External Penetration Testing | |
| 718 | External Penetration Testing | |
| 719 | Penetration Testing Roadmap | |
| 720 | External Intrusion Test and Analysis | |
| 721 | How is it Done? | |
| 722 | Client Benefits | |
| 723 | External Penetration Testing | |
| 724 | Steps – Conduct External Penetration Testing | |
| 725 | Demo - CORE Impact Network Vulnerability Test | |
| 726 | Demo - Samaurai Live CD Intro | |
| 727 | Step 1: Inventory Company’s External Infrastructure | |
| 728 | Step 2: Create Topological Map of the Network | |
| 729 | Step 3: Identify the IP Address | |
| 730 | Step 4: Locate the Traffic Route that Goes to the Web Servers | |
| 731 | Step 5/6: Locate TCP/UDP Traffic Path to the Destination | |
| 732 | Step 7: Identify the Physical Location of the Target Servers | |
| 733 | Step 8: Examine the Use IPV6 at the Remote Location | |
| 734 | Step 9: Lookup Domain Registry for IP Information | |
| 735 | Step 10: Find IP Block Information about the Target | |
| 736 | Step 11: Locate the ISP Servicing the Client | |
| 737 | Step 12: List Open Ports | |
| 738 | Open Ports on Web Server | |
| 739 | Step 13: List Closed Ports | |
| 740 | Port Scanning Tools | |
| 741 | Step 14: List Suspicious Ports that are Half Open/Closed | |
| 742 | Step 15: Port Scan Every Port (65,536) on the Target’s Network | |
| 743 | Step 16: Use SYN Scan on the Target and See the Response | |
| 744 | Step 17: Use Connect Scan on the Target and See the Response | |
| 745 | Demo - N-stalker Results Webgoat | |
| 746 | Demo - Breaking Access Control Passwords with Xhydra | |
| 747 | Demo - Viewing Website with Telnet | |
| 748 | Demo - Input-injection Attack | |
| 749 | Demo - Fast-track Overview and Install | |
| 750 | Demo - Fast-track Exploits | |
| 751 | Demo - Fast-track Clientside Attacks | |
| 752 | Demo - Fast-track Mass Attack | |
| 753 | Module 18 Review | |
| 754 | Module 19 - Internal Network Penetration Testing | |
| 755 | Internal Network Penetration Testing | |
| 756 | Penetration Testing Roadmap | |
| 757 | Internal Testing | |
| 758 | Methods of Internal Testing | |
| 759 | Enumerate Other Machines | |
| 760 | Step 1: Map the Internal Network | |
| 761 | Demo - Spiceworks Inventory | |
| 762 | Step 2: Scan the Network for Live Hosts | |
| 763 | Demo - SNMP Enumerating with BT | |
| 764 | Demo - FireScope MIB Tool | |
| 765 | Step 3: Port Scan Individual Machines | |
| 766 | Step 4: Try to Gain Access Using Known Vulnerabilities | |
| 767 | Demo - SMB NAT Dictionary Attacks | |
| 768 | Demo - Injecting the Abel Service | |
| 769 | Demo - Nslookup DNS Zone Transfer | |
| 770 | Step 5: Attempt to Establish Null Sessions | |
| 771 | Demo - Enumerate Banners | |
| 772 | Demo - Null Session Multiple Tools | |
| 773 | Demo - Null Session Countermeasures | |
| 774 | Step 6: Enumerate Users | |
| 775 | Step 7: Sniff the Network Using Wireshark | |
| 776 | Step 8: Sniff Pop3/FTP/Telnet Passwords | |
| 777 | Step 9: Sniff Email Messages/VoIP Traffic | |
| 778 | Sniffer Tools | |
| 779 | Demo - ARP Poisoning with Cain | |
| 780 | Step 10: Attempt Replay Attacks | |
| 781 | Demo - SSL MITM | |
| 782 | Step 11: Attempt ARP Poisoning | |
| 783 | Step 11a: Attempt Mac Flooding | |
| 784 | Step 12: Conduct a Man-in-the Middle Attack | |
| 785 | Step 13: Attempt DNS Poisoning | |
| 786 | Demo - Cain DNS Spoof | |
| 787 | Step 14: Try a Login to a Console Machine | |
| 788 | Step 15: Boot the PC Using Alternate OS and Steal the SAM File | |
| 789 | Demo - Local Password Reset | |
| 790 | Demo - Backtrack Local XP Password Attack | |
| 791 | Copying Commands in Knoppix | |
| 792 | ERD Commander 2005 | |
| 793 | Reset Administrator Password | |
| 794 | Step 16: Attempt to Plant a Software Keylogger to Steal Passwords | |
| 795 | Keyloggers and Spy Software | |
| 796 | Demo - Hardware Keystroke Loggers | |
| 797 | Step 17: Attempt to Plant a Hardware Keylogger to Steal Passwords | |
| 798 | Step 18: Attempt to Plant a Spyware on the Target Machine | |
| 799 | Step 19: Attempt to Plant a Trojan on the Target Machine | |
| 800 | Step 20: Attempt to Create a Backdoor Account on the Target Machine | |
| 801 | Demo - Secure Tunnels and Anonymizer Techniques | |
| 802 | Step 21: Attempt to Bypass Anti-virus Software Installed on the Target Machine | |
| 803 | Demo - Stealth Tools v2 to Hide Viruses and Malware | |
| 804 | Step 22: Attempt to Send Virus Using the Target Machine | |
| 805 | Step 23: Attempt to Plant Rootkits on the Target Machine | |
| 806 | Demo - Dreampakpl Rootkit | |
| 807 | Step 24: Hide Sensitive Data on Target Machines | |
| 808 | Demo - Alternate Data Streams | |
| 809 | Step 25: Hide Hacking Tools and Other Data in Target Machines | |
| 810 | Step 26: Use Various Steganography Techniques to Hide Files on Target Machine | |
| 811 | Demo - Steganography | |
| 812 | Step 27: Escalate User Privileges | |
| 813 | Demo - Privilege Escalation | |
| 814 | Step 28: Capture POP3 Traffic | |
| 815 | Step 29: Capture SMTP Traffic | |
| 816 | Step 32: Capture HTTP Traffic | |
| 817 | Step 33: Capture HTTPS Traffic (Even Though it cannot be Decoded) | |
| 818 | Step 34: Capture RDP Traffic | |
| 819 | Step 35: Capture VoIP Traffic | |
| 820 | Demo - Cain VoIP RDP Interception | |
| 821 | Steps 40 and 41 | |
| 822 | Step 42: Attempt Session Hijacking on Telnet Traffic | |
| 823 | Steps 43 and 44 | |
| 824 | Continue Testing | |
| 825 | CORE Impact - Automated Tool | |
| 826 | Metasploit - Tool | |
| 827 | Canvas – Automated Tool | |
| 828 | Vulnerability Scanning Tools | |
| 829 | Document Everything | |
| 830 | Module 19 Review | |
| 831 | ||
| 832 | ||
| 833 | Module 20 - Router and Switches Penetration Testing | |
| 834 | Router and Switches Penetration Testing | |
| 835 | Demo - Cain and Abel Routing Protocols and ID Networks | |
| 836 | Penetration Testing Roadmap | |
| 837 | Router Testing Issues | |
| 838 | Need for Router Testing | |
| 839 | General Requirements | |
| 840 | Technical Requirements | |
| 841 | Try to Compromise the Router | |
| 842 | Steps for Router Penetration Testing | |
| 843 | Step 1: Identify the Router Hostname | |
| 844 | Step 2: Port Scan the Router | |
| 845 | Step 3: Identify the Router Operating System and its Version | |
| 846 | Steps 4/5: Identify Protocols Running/Testing for Package Leakage at the Router | |
| 847 | Step 6: Test for Router Misconfigurations | |
| 848 | Step 7: Test for VTY/TTY Connections | |
| 849 | The Process to Get Access to the Router | |
| 850 | Step 8: Test for Router Running Modes | |
| 851 | Privilege Mode Attacks | |
| 852 | Step 9: Test for SNMP Capabilities | |
| 853 | SNMP “Community String” | |
| 854 | Step 10: Test for TFTP Connections | |
| 855 | TFTP Testing | |
| 856 | Step 11: Test if Finger is Running on the Router | |
| 857 | Step 12: Test for CDP Protocol Running on the Router | |
| 858 | How to Test CDP Protocol? | |
| 859 | Step 13: Test for NTP Protocol | |
| 860 | Step 14: Test for Access to Router Console Port | |
| 861 | Step 15: Test for Loose and Strict Source Routing | |
| 862 | Steps 16 and 17: Test for IP Spoofing/IP Handling Bugs | |
| 863 | Step 18: Test ARP Attacks | |
| 864 | Step 19: Test for Routing Protocol Assessment | |
| 865 | Step 20: RIP Testing | |
| 866 | Step 21: Test for OSPF Protocol | |
| 867 | Step 22: Test BGP Protocol | |
| 868 | Step 23: Test for EIGRP Protocol | |
| 869 | Step 24: Test Router Denial of Service Attacks | |
| 870 | Step 25: Test Router’s HTTP Capabilities | |
| 871 | Step 26: Test Through HSRP Attack | |
| 872 | Router Testing Report | |
| 873 | Steps for Testing Switches | |
| 874 | Step 1: Testing Address Cache Size | |
| 875 | Step 2: Data Integrity and Error Checking Test | |
| 876 | Step 3: Testing for Back-to-Back Frame Capacity | |
| 877 | Step 4: Testing for Frame Loss | |
| 878 | Step 5: Testing for Latency | |
| 879 | Step 6: Testing for Throughput | |
| 880 | Step 7: Test for Frame Error Filtering | |
| 881 | Step 8: Fully Meshed Test | |
| 882 | Step 9: Stateless QoS Functional Test | |
| 883 | Step 10: Spanning Tree Network Convergence Performance Test | |
| 884 | Step 11: OSPF Performance Test | |
| 885 | Step 12: Test for VLAN Hopping | |
| 886 | Step 13: Test for MAC Table Flooding | |
| 887 | Step 14: Testing for ARP Attack | |
| 888 | Step 15: Check for VTP Attack | |
| 889 | Module 20 Review | |
| 890 | Module 21 - Firewall Penetration Testing | |
| 891 | Firewall Penetration Testing | |
| 892 | Penetration Testing Roadmap | |
| 893 | What is a Firewall? | |
| 894 | What Does a Firewall Do? | |
| 895 | Packet Filtering | |
| 896 | What Can't a Firewall Do? | |
| 897 | How Does a Firewall Work? | |
| 898 | Firewall Logging Functionality | |
| 899 | Firewall Policy | |
| 900 | Periodic Review of Information Security Policies | |
| 901 | Firewall Implementation | |
| 902 | Build a Firewall Ruleset | |
| 903 | Maintenance and Management of Firewall | |
| 904 | Types of Firewall | |
| 905 | Demo - Introduction to Vyatta | |
| 906 | Packet Filtering Firewall | |
| 907 | IP Packet Filtering Firewall | |
| 908 | Circuit Level Gateway | |
| 909 | Application Level Firewall | |
| 910 | Stateful Multilayer Inspection Firewall | |
| 911 | Multilayer Inspection Firewall | |
| 912 | Steps for Conducting Firewall Penetration Testing | |
| 913 | Step 1: Locate the Firewall | |
| 914 | Step 2: Traceroute to Identify the Network Range | |
| 915 | Step 3: Port Scan the Firewall | |
| 916 | Step 4: Grab the Banner | |
| 917 | Step 5: Create Custom Packets and Look for Firewall Responses | |
| 918 | Step 6: Test Access Control Enumeration | |
| 919 | Step 7: Test to Identify Firewall Architecture | |
| 920 | Step 8: Testing Firewall Policy | |
| 921 | Step 9: Test Firewall Using Firewalking Tool | |
| 922 | Step 10: Test for Port Redirection | |
| 923 | Firewall Identification | |
| 924 | Step 11: Testing the Firewall from Both Sides | |
| 925 | Step 12: Overt Firewall Test from Outside | |
| 926 | Step 13: Test Covert Channels | |
| 927 | Step 14: Covert Firewall Test from Outside | |
| 928 | Step 15: Test HTTP Tunneling | |
| 929 | Step 16: Test Firewall Specific Vulnerabilities | |
| 930 | Demo - Vyatta | |
| 931 | Demo - CORE Impact Targeting Vyatta | |
| 932 | Document Everything | |
| 933 | Module 21 Review | |
| 934 | Module 22 - IDS Penetration Testing | |
| 935 | IDS Penetration Testing | |
| 936 | Penetration Testing Roadmap | |
| 937 | What is an IDS? | |
| 938 | Demo - IDS Blink and Ossec.net | |
| 939 | Network IDS | |
| 940 | Host-based IDS | |
| 941 | Demo - Blink Personal IPS IDS | |
| 942 | Application-based IDS | |
| 943 | Multi-Layer Intrusion Detection Systems | |
| 944 | Multi-Layer Intrusion Detection System Benefits | |
| 945 | Wireless Intrusion Detection Systems (WIDS) | |
| 946 | IDS Testing Tool - Evasion Gateway | |
| 947 | Common Techniques Used to Evade IDS Systems | |
| 948 | IDS Penetration Testing Steps | |
| 949 | Steps 1/2: Test for Resource Exhaustion/ IDS by Sending ARP Flood | |
| 950 | Steps 3/4: Test the IDS by MAC Spoofing/ IP Spoofing | |
| 951 | Steps 5/6: Test by Sending a Packet to the Broadcast Address/Inconsistent Packets | |
| 952 | Steps 7/8: Test IP Packet Fragmentation/Duplicate Fragments | |
| 953 | Steps 9/10: Test for Overlapping Fragments/Ping of Death | |
| 954 | Steps 11/12: Test for Odd Sized Packets/TTL Evasion | |
| 955 | Steps 13/14: Test by Sending a Packet to Port 0/UDP Checksum | |
| 956 | Steps 15/16: Test for TCP Retransmissions/ TCP Flag Manipulation | |
| 957 | The TCP Header looks like this: | |
| 958 | Step 17: Test TCP Flags | |
| 959 | Steps 18/19: Test the IDS by Sending SYN Floods/ Sequence Number Prediction | |
| 960 | Step 20: Test for Backscatter | |
| 961 | Steps 21/22: Test the IDS with ICMP Packets/ IDS Using Covert Channels | |
| 962 | Step 23: Test Using TCPReplay | |
| 963 | Step 24: Test Using TCPOpera | |
| 964 | Step 26: Test the IDS Using URL Encoding | |
| 965 | Step 27: Test the IDS Using Double Slashes | |
| 966 | Step 28: Test the IDS for Reverse Traversal | |
| 967 | Step 29: Test for Self Reference Directories | |
| 968 | Step 31: Test for IDS Parameter Hiding | |
| 969 | Step 32: Test for HTTP-Misformatting | |
| 970 | Step 33: Test for Long URLs | |
| 971 | Step 34: Test for DoS/Win Directory Syntax | |
| 972 | Step 35: Test for Null Method Processing | |
| 973 | Step 36: Test for Case Sensitivity | |
| 974 | Step 37: Test Session Splicing | |
| 975 | Module 22 Review | |
| 976 | Module 23 - Wireless Network Penetration Testing | |
| 977 | Wireless Network Penetration Testing | |
| 978 | Penetration Testing Roadmap | |
| 979 | Wireless Security Threats | |
| 980 | Wireless Assessment | |
| 981 | Attempt Wireless Monitoring | |
| 982 | Wireless Vulnerability Testing | |
| 983 | Wireless Penetration Testing Steps | |
| 984 | Demo - inSSIDer | |
| 985 | Demo - Wi-Spy Spectrum Analyzer | |
| 986 | Demo - Tips Resources | |
| 987 | Module 23 Review | |
| 988 | Module 24 - Denial of Service Penetration Testing | |
| 989 | Denial of Service Penetration Testing | |
| 990 | How Does a Denial of Service Attack Work? | |
| 991 | Distributed Denial of Service Attack | |
| 992 | Warning | |
| 993 | How to Conduct Denial of Service Attack Penetration Testing? | |
| 994 | Demo - Ping of Death and Nemesy | |
| 995 | Module 24 Review | |
| 996 | Module 25 - Password Cracking Penetration Testing | |
| 997 | Password Cracking Penetration Testing | |
| 998 | Passwords | |
| 999 | Common Password Vulnerabilities | |
| 1000 | Password Cracking Techniques | |
| 1001 | Types of Password Cracking Attacks | |
| 1002 | Demo - Cain and Abel Dictionary Attack | |
| 1003 | Demo - Cracking your Local XP 64-bit Password with Ophcrack | |
| 1004 | Demo - Cracking the Hash Imported into Cain and Abel | |
| 1005 | Demo - Rainbow Table Cracking | |
| 1006 | Steps in Password Cracking Penetration Testing | |
| 1007 | Step 5: Attempt to Guess Passwords | |
| 1008 | Demo - Removing a PDF Password | |
| 1009 | Module 25 Review | |
| 1010 | Module 26 - Social Engineering Penetration Testing | |
| 1011 | Social Engineering Penetration Testing | |
| 1012 | What is Social Engineering? | |
| 1013 | Requirements of Social Engineering | |
| 1014 | Steps in Conducting Social Engineering Penetration Test | |
| 1015 | Before you Start | |
| 1016 | Dress Like a Businessman | |
| 1017 | Step 1: Attempt Social Engineering Techniques Using Phone | |
| 1018 | Step 2: Attempt Social Engineering by Vishing | |
| 1019 | Step 3: Attempt Social Engineering by Telephone | |
| 1020 | Step 4: Attempt Social Engineering Using Email | |
| 1021 | Demo - Hotmail Social Engineering | |
| 1022 | Step 10: Attempt Social Engineering by Desktop Information | |
| 1023 | Step 12: Attempt Social Engineering Using Websites | |
| 1024 | Module 26 Review | |
| 1025 | Module 27 - Stolen Laptops, PDAs, and Cell Phones Penetration Testing | |
| 1026 | Stolen Laptops, PDAs, and Cell Phones Penetration Testing | |
| 1027 | Penetration Testing Roadmap | |
| 1028 | Stolen Laptop Testing | |
| 1029 | Laptop Theft | |
| 1030 | Demo - Darik's Boot and Nuke | |
| 1031 | Penetration Testing Steps | |
| 1032 | Step 1: Identify Sensitive Data in the Devices | |
| 1033 | Look for Personal Information in the Stolen Laptop | |
| 1034 | Step 2: Look for Passwords | |
| 1035 | Step 3: Look for Company Infrastructure or Finance Documents | |
| 1036 | Step 4: Extract the Address Book and Phone Numbers | |
| 1037 | Step 5: Extract Schedules and Appointments | |
| 1038 | Step 6: Extract Applications Installed on these Devices | |
| 1039 | Step 7: Extract Email Messages from these Devices | |
| 1040 | Step 8: Gain Access to Server Resources by Using Information you Extracted | |
| 1041 | Step 9: Attempt Social Engineering with the Extracted Information | |
| 1042 | Check for BIOS Password | |
| 1043 | Look into the Encrypted File | |
| 1044 | Check Cookies in Web Browsers | |
| 1045 | Install Software | |
| 1046 | Attempt to Enable Wireless | |
| 1047 | Module 27 Review | |
| 1048 | Module 28 - Application Penetration Testing | |
| 1049 | Application Penetration Testing | |
| 1050 | Application Testing | |
| 1051 | What is a Defect? | |
| 1052 | Defects vs. Failures | |
| 1053 | Defect Ratio | |
| 1054 | Requirements and Design Testing | |
| 1055 | Web Applications Penetration Testing | |
| 1056 | What is a Web Application? | |
| 1057 | Demo - Webgoat Hands-on Web Testing | |
| 1058 | Demo - Foundstone Overview Hacme Bank Weak Apps | |
| 1059 | Web Application Penetration Testing Steps | |
| 1060 | Step 1: Fingerprinting the Web Application Environment | |
| 1061 | Step 2: Investigate the Output from HEAD and OPTIONS Http Requests | |
| 1062 | Step 3: Investigate the Format and Wording of 404/Other Error Pages | |
| 1063 | Step 4: Test for Recognized File Types/Extensions/Directories | |
| 1064 | Step 5: Examine Source of Available Pages | |
| 1065 | Step 6: Manipulate Inputs in Order to Elicit a scripting Error | |
| 1066 | Step 7: Test Inner Working of a Web Application | |
| 1067 | Step 8: Test Database Connectivity | |
| 1068 | Step 9: Test the Application Code | |
| 1069 | Random Numbers vs. Unique Numbers | |
| 1070 | Step 10: Testing the Use of GET and POST in Web Application | |
| 1071 | Step 11: Test for Parameter-Tampering Attacks on Website | |
| 1072 | Step 12: Test for URL Manipulation | |
| 1073 | Step 13: Test for Cross Site scripting | |
| 1074 | Step 14: Test for Hidden Fields | |
| 1075 | Step 15: Test Cookie Attacks | |
| 1076 | Step 16: Test for Buffer Overflows | |
| 1077 | Step 17: Test for Bad Data | |
| 1078 | Step 18: Test Client-Side scripting | |
| 1079 | Step 19: Test for Known Vulnerabilities | |
| 1080 | Step 20: Test for Race Conditions | |
| 1081 | Step 21: Test with User Protection via Browser Settings | |
| 1082 | Step 22: Test for Command Execution Vulnerability | |
| 1083 | Step 23: Test for SQL Injection Attacks | |
| 1084 | Step 24: Test for Blind SQL Injection | |
| 1085 | Step 25: Test for Session Fixation Attack | |
| 1086 | Step 26: Test for Session Hijacking | |
| 1087 | Step 27: Test for XPath Injection Attack | |
| 1088 | Step 28: Test for Server Side Include Injection Attack | |
| 1089 | Step 29: Test for Logic Flaws | |
| 1090 | Step 30: Test for Binary Attacks | |
| 1091 | Step 31: Test for XML Structural | |
| 1092 | Step 32: Test for XML Content-level | |
| 1093 | Step 33: Test for WS HTTP GET Parameters/REST Attacks | |
| 1094 | Step 34: Test for Malicious SOAP Attachments | |
| 1095 | Step 35: Test for WS Replay | |
| 1096 | Testing Tools | |
| 1097 | KSES/ Mieliekoek.pl | |
| 1098 | Webgoat | |
| 1099 | AppScan | |
| 1100 | URL Scan | |
| 1101 | Demo - Hacme Bank Scan using N-Stalker | |
| 1102 | Demo - Hacme Bank Scan Core Web Testing | |
| 1103 | Module 28 Review | |
| 1104 | Module 29 - Physical Security Penetration Testing | |
| 1105 | Physical Security Penetration Testing | |
| 1106 | Physical Attacks | |
| 1107 | Steps in Conducting Physical Security Penetration Testing | |
| 1108 | Demo - Bump Key Animation | |
| 1109 | Step 1: Map the Possible Entrances | |
| 1110 | Step 2: Map the Physical Perimeter | |
| 1111 | Step 3: Penetrate Locks Used on the Gates, Doors, and Closets | |
| 1112 | Step 4: Observing From a Distance | |
| 1113 | Step 5: Penetrate Server Rooms, Cabling, and Wires | |
| 1114 | Step 6: Attempt Lock Picking Techniques | |
| 1115 | Step 7: Fire Detection Systems | |
| 1116 | Step 8: Air Conditioning Systems | |
| 1117 | Step 9: Electromagnetic Interception | |
| 1118 | Check for the Following | |
| 1119 | Step 10: Test if the Company has a Physical Security Policy | |
| 1120 | Step 11: Physical Assets | |
| 1121 | Step 12: Risk Test | |
| 1122 | Step 13: Test if any Valuable Paper Document is Kept at the Facility | |
| 1123 | Step 14: Check how these Documents are Protected | |
| 1124 | Step 15: Employee Access | |
| 1125 | Step 16: Test for Radio Frequency ID (RFID) | |
| 1126 | Step 17: Physical Access to Facilities | |
| 1127 | Step 18: Documented Process | |
| 1128 | Step 19: Test People in the Facility | |
| 1129 | Step 20: Who is Authorized? | |
| 1130 | Step 21: Test Fire Doors | |
| 1131 | Step 22: Check for Active Network Jacks in Meeting Rooms | |
| 1132 | Step 23: Check for Active Network Jacks in Company Lobby | |
| 1133 | Step 24: Check for Sensitive Information Lying around Meeting Rooms | |
| 1134 | Step 25: Check for Receptionist/Guard Leaving Lobby | |
| 1135 | Step 26: Check for Accessible Printers at the Lobby – Print Test Page | |
| 1136 | Step 27: Obtain Phone/Personnel Listing from the Lobby Receptionist | |
| 1137 | Step 28: Listen to Employee Conversation in Communal Areas/Cafeteria | |
| 1138 | Step 29: Can you Enter the Ceiling Space and Enter Secure Rooms | |
| 1139 | Step 30: Check Windows/Doors for Visible Alarm Senses | |
| 1140 | Step 31: Check Visible Areas for Sensitive Information | |
| 1141 | Step 32: Try to Shoulder Surf Users Logging on | |
| 1142 | Step 33: Try to Videotape Users Logging on | |
| 1143 | Steps 34 and 35 | |
| 1144 | Step 36: Intercept and Analyze Guard Communication | |
| 1145 | Step 37: Attempt Piggybacking on Guarded Doors | |
| 1146 | Step 38: Attempt to Use Fake ID to Gain Access | |
| 1147 | Step 39: Test “ After Office Hours” Entry Methods | |
| 1148 | Step 40: Identify all Unguarded Entry Points | |
| 1149 | Step 43: Attempt to Bypass Sensors Configured on Doors and Windows | |
| 1150 | Step 44: Attempt Dumpster Diving Outside the Company Trash Area | |
| 1151 | Step 45: Use Binoculars from Outside the Building and See if you can View What is Going On Inside | |
| 1152 | Step 46: Use Active High Frequency Voice Sensors to Hear Private Conversation among Company Staff | |
| 1153 | Step 47: Dress as a FedEx/UPS Employee and Try to Gain Access to the Building | |
| 1154 | Document Everything | |
| 1155 | Module 29 Review | |
| 1156 | Module 30 - Database Penetration Testing | |
| 1157 | Database Penetration Testing | |
| 1158 | List of Steps | |
| 1159 | Demo - NTOSpider | |
| 1160 | Step 1: Scan for Default Ports Used by the Database | |
| 1161 | Step 2: Scan for Non-Default Ports Used by the Database | |
| 1162 | Step 3: Identify the Instance Names Used by the Database | |
| 1163 | Step 4: Identify the Version Numbers Used by the Database | |
| 1164 | Step 5: Attempt to Brute-Force Password Hashes from the Database | |
| 1165 | Step 6: Sniff Database Related Traffic on the Local Wire | |
| 1166 | Step 7: Microsoft SQL Server Testing | |
| 1167 | Step 7.1: Test for Direct Access Interrogation | |
| 1168 | Step 7.2: Scan for Microsoft SQL Server Ports ( TCP/UDP 1433) | |
| 1169 | Step 7.3: Test for SQL Server Resolution Service (SSRS) | |
| 1170 | Step 7.4: Test for Buffer Overflow in pwdencrypt() Function | |
| 1171 | Step 7.5: Test for Heap/Stack Buffer Overflow in SSRS | |
| 1172 | Step 7.6: Test for Buffer Overflows in Extended Stored Procedures | |
| 1173 | Step 7.7: Test for Service Account Registry Key | |
| 1174 | Step 7.8: Test the Stored Procedure to Run Web Tasks | |
| 1175 | Step 7.9: Exploit SQL Injection Attack | |
| 1176 | Step 7.10: Blind SQL Injection | |
| 1177 | Demo - SQL Injection with Lee Lawson | |
| 1178 | Step 7.11: Google Hacks | |
| 1179 | Step 7.12: Attempt Direct-exploit Attacks | |
| 1180 | Step 7.13: Try to Retrieve Server Account List | |
| 1181 | Step 7.14: Using OSQL Test for Default/Common Passwords | |
| 1182 | Step 7.15: Try to Retrieve Sysxlogins Table | |
| 1183 | Try to Retrieve Sysxlogins Table Views | |
| 1184 | SQL Server System Tables | |
| 1185 | Step 7.16: Brute-force SA Account | |
| 1186 | Step 8: Oracle Server Testing | |
| 1187 | Port Scanning Basic Techniques | |
| 1188 | Step 8.2: Check the Status of TNS Listener Running at Oracle Server | |
| 1189 | Listener Modes | |
| 1190 | Step 8.3: Try to Login Using Default Account Passwords | |
| 1191 | Step 8.4: Try to Enumerate SIDs | |
| 1192 | Step 8.5: Use SQL Plus to Enumerate System Tables | |
| 1193 | SQL PLUS: Screenshot | |
| 1194 | Step 9: MySQL Server Database Testing | |
| 1195 | Step 9.2: Extract the Version of Database being Used | |
| 1196 | Step 9.3: Try to Login Using Default/Common Passwords | |
| 1197 | Step 9.4: Brute-force Accounts Using Dictionary Attack | |
| 1198 | Dictionary Attack Tools | |
| 1199 | Dictionary Attack Tool: SQLdict | |
| 1200 | Step 9.5: Extract System and User Tables from the Database | |
| 1201 | Demo - CORE Impact Webgoat Information Gathering | |
| 1202 | Demo - CORE Impact Webgoat SQL Numeric Injection | |
| 1203 | Demo - Hacme Bank Testing with Wikto | |
| 1204 | Module 30 Review | |
| 1205 | Module 31 - VoIP Penetration Testing | |
| 1206 | VoIP Penetration Testing | |
| 1207 | Penetration Testing Roadmap | |
| 1208 | Vulnerability Assessment | |
| 1209 | VoIP Risks and Vulnerabilities | |
| 1210 | VoIP Security Threat | |
| 1211 | VoIP Penetration Testing Steps | |
| 1212 | Demo - VoIP Overview Testing | |
| 1213 | Step 1: Test for Eavesdropping | |
| 1214 | Step 2: Test for Flooding and Logic Attacks | |
| 1215 | Step 3: Test for Denial of Service (DoS) Attack | |
| 1216 | Step 4: Test for Call Hijacking & Redirection Attack | |
| 1217 | Step 5: Test for ICMP Ping Sweeps | |
| 1218 | Step 6: Test for ARP Pings | |
| 1219 | Step 7: Test for TCP Ping Scans | |
| 1220 | Step 8: Test for SNMP Sweeps | |
| 1221 | Step 9: Test for Port Scanning and Service Discovery | |
| 1222 | Step 10: Test for Host/Device Identification | |
| 1223 | Step 11: Test for Banner Grabbing | |
| 1224 | Step 12: Test for SIP User/Extension Enumeration | |
| 1225 | Step 13: Test for Automated OPTIONS Scanning with sipsak | |
| 1226 | Step 14: Test for Automated REGISTER, INVITE, and OPTIONS Scanning with SIPSCAN against SIP Server | |
| 1227 | Step 15: Test for Enumerating TFTP Servers | |
| 1228 | Step 16: Test for SNMP Enumeration | |
| 1229 | Step 17: Test for Sniffing TFTP Configuration File Transfers | |
| 1230 | Step 18: Test for Number Harvesting and Call Pattern Tracking | |
| 1231 | VoIP Security Tools | |
| 1232 | AuthTool | |
| 1233 | VoIPong | |
| 1234 | Demo - VoIP Interception with Cain and Abel | |
| 1235 | VoIPong: Screenshots | |
| 1236 | Vomit | |
| 1237 | PSIPDump | |
| 1238 | Netdude | |
| 1239 | Netdude: Features | |
| 1240 | Oreka | |
| 1241 | rtpBreak | |
| 1242 | SNScan | |
| 1243 | Smap | |
| 1244 | Example: Locating Devices | |
| 1245 | Example: Fingerprinting Devices | |
| 1246 | Example: Learning Mode | |
| 1247 | SIPScan | |
| 1248 | Scanning SIP Phones | |
| 1249 | SIPScan: Screenshot | |
| 1250 | SIPcrack | |
| 1251 | VoIPaudit | |
| 1252 | Sipsak | |
| 1253 | SIPp | |
| 1254 | SipBomber | |
| 1255 | Spitter | |
| 1256 | VoIP Fuzzing Tools | |
| 1257 | VoIP Signaling Manipulation Tools | |
| 1258 | VoIP Media Manipulation Tools | |
| 1259 | Module 31 Review | |
| 1260 | Module 32 - VPN Penetration Testing | |
| 1261 | VPN Penetration Testing | |
| 1262 | Virtual Private Network (VPN) | |
| 1263 | VPN Penetration Testing Steps | |
| 1264 | Demo - VPN Testing | |
| 1265 | Step 1.1 Scanning: 500 UDP IPSEC | |
| 1266 | Step 1.2 Scanning: 1723 TCP PPTP | |
| 1267 | Step 1.3 Scanning: 443 TCP/SSL | |
| 1268 | Step 1.4 Scanning: nmap -sU -P0 -p 500 | |
| 1269 | Step 1.5 Scanning: Ipsecscan xxx.xxx.xxx.xxx-255 | |
| 1270 | Step 2: Fingerprinting | |
| 1271 | Step 2.1: Get the IKE Handshake | |
| 1272 | Step 2.2: UDP Backoff Fingerprinting | |
| 1273 | Step 2.3: Vendor ID Fingerprinting | |
| 1274 | Step 2.4: Check for IKE Aggressive Mode | |
| 1275 | Step 3.1: PSK Crack: ikeprobe xxx.xxx.xxx.xxx-255 | |
| 1276 | Step 3.2 PSK Crack: Sniff for Responses with C&A or IKECrack | |
| 1277 | Step 4: Test for Default User Accounts | |
| 1278 | Step 4.1: Check for Unencrypted Username in a File or the Registry | |
| 1279 | Check for Unencrypted Username in a File or the Registry: Screenshot | |
| 1280 | Step 4.2: Test for Plain-Text Password | |
| 1281 | Step 5: Test for SSL VPN | |
| 1282 | Tool: IKE-scan | |
| 1283 | IKE-scan: Screenshot | |
| 1284 | Tool: IKEProbe | |
| 1285 | Tool: VPNmonitor | |
| 1286 | Tool: IKECrack | |
| 1287 | Module 32 Review | |
| 1288 | Module 33 - War Dialing | |
| 1289 | War Dialing | |
| 1290 | War Dialing Techniques | |
| 1291 | Why Conduct a War Dialing Pentest? | |
| 1292 | Pre-Requisites for War Dialing Penetration Testing | |
| 1293 | Software Selection for War Dialing | |
| 1294 | Guidelines for Configuring Different War Dialing Software | |
| 1295 | Recommendations for Establishing an Effective War Dialing Process | |
| 1296 | Interpreting War Dialing Results | |
| 1297 | List of War Dialing Tools | |
| 1298 | Demo - New War Dialing Tool: WarVOX | |
| 1299 | PhoneSweep | |
| 1300 | THC Scan | |
| 1301 | ToneLoc | |
| 1302 | ModemScan - www.wardial.net | |
| 1303 | War Dialing Countermeasures SandTrap Tool | |
| 1304 | Module 33 Review | |
| 1305 | Module 34 - Virus and Trojan Detection | |
| 1306 | Virus and Trojan Detection | |
| 1307 | Steps for Detecting Trojans and Viruses | |
| 1308 | Step 1: Use netstat -a to Detect Trojans Connections | |
| 1309 | Step 2: Check Windows Task Manager | |
| 1310 | Step 3: Check Whether Scanning Programs are Enabled | |
| 1311 | Step 3.1: Perform Scanning for Suspicious Running Processes | |
| 1312 | Step 3.2: Perform Scanning for Suspicious Registry Entries | |
| 1313 | Step 3.3: Check for Suspicious Open Ports | |
| 1314 | Step 3.4: Check Whether Suspicious Network Activities are Present | |
| 1315 | Step 3.5: Use HijackThis to Scan for Spyware | |
| 1316 | Step 4: Check Whether Anti-Virus and Anti-Trojan Programs are Working | |
| 1317 | Step 5: Detection of a Boot-Sector Virus | |
| 1318 | Spyware Detectors | |
| 1319 | Demo - Beast Trojan | |
| 1320 | Anti-Trojans | |
| 1321 | Anti-Virus Software | |
| 1322 | Module 34 Review | |
| 1323 | Module 35 - Log Management Penetration Testing | |
| 1324 | Log Management Penetration Testing | |
| 1325 | Need for Log Management | |
| 1326 | Challenges in Log Management | |
| 1327 | Steps for Log Management Penetration Testing | |
| 1328 | Step 1: Scan for Log Files | |
| 1329 | Step 2: Try to Flood Syslog Servers with Bogus Log Data | |
| 1330 | Step 3: Try Malicious Syslog Message Attack (Buffer Overflow) | |
| 1331 | Step 4: Perform Man-in-the-Middle Attack | |
| 1332 | Step 5: Check Whether the Logs are Encrypted | |
| 1333 | Step 6: Check Whether Arbitrary Data Can be Injected Remotely into Microsoft ISA Server Log File | |
| 1334 | Step 7: Perform DoS Attack Against Check Point FW-1 Syslog Daemon (Only for CheckPoint Firewall) | |
| 1335 | Step 8: Send Syslog Messages Containing Escape Sequences to Syslog Daemon of Check Point FW-1 NG FP3 | |
| 1336 | Checklist For Secure Log Management | |
| 1337 | Module 35 Review | |
| 1338 | Module 36 - File Integrity Checking | |
| 1339 | File Integrity Checking | |
| 1340 | File Integrity | |
| 1341 | Integrity Checking Techniques | |
| 1342 | Demo - File Integrity Checkers | |
| 1343 | Steps for Checking File Integrity | |
| 1344 | Step 1: Check While you Unzip the File | |
| 1345 | Step 2: Check for CRC Value Integrity Checking | |
| 1346 | CRC Checking in Windows | |
| 1347 | Step 3: Check for Hash Value Integrity Checking | |
| 1348 | Step 3.1: Get the File and Previously Calculated Hash Value for the File | |
| 1349 | Step 3.2: Generate a New Hash Value for the File | |
| 1350 | Step 3.3: Match the Old and New Hash Values | |
| 1351 | File Integrity Checking Tools | |
| 1352 | Module 36 Review | |
| 1353 | Module 37 - Bluetooth and Hand Held Device Penetration Testing | |
| 1354 | Bluetooth and Hand Held Device Penetration Testing | |
| 1355 | Jailbreaking an iPhone | |
| 1356 | Steps for iPhone Penetration Testing | |
| 1357 | Demo - Jailbreak | |
| 1358 | Demo - iPod Custom Apps | |
| 1359 | Step 1: Jailbreak the iPhone | |
| 1360 | Jailbreaking Using PwnageTool or QuickPwn | |
| 1361 | Jailbreaking Using QuickPwn | |
| 1362 | Step-by-Step Guide to Jailbreak iPhone 3G and Preserve Baseband using PwnageTool | |
| 1363 | Step 2: Unlock the iPhone | |
| 1364 | Step 4: Hack iPhone using Metasploit | |
| 1365 | Step 5: Check for Access Point with Same Name and Encryption Type | |
| 1366 | Step 6: Check Whether Malformed Data Can be Sent to the Device | |
| 1367 | Step 7: Check Whether Basic Memory Mapping Information Can be Extracted | |
| 1368 | Vulnerabilities in BlackBerry | |
| 1369 | Steps for Penetration Testing | |
| 1370 | Step 1: Try Blackjacking on BlackBerry | |
| 1371 | Step 2: Try to Attack by Sending Malformed TIFF Image Files | |
| 1372 | PDA Attacks | |
| 1373 | Steps for Penetration Testing 2 | |
| 1374 | Step 1: Check Whether Passwords can be Cracked | |
| 1375 | Step 2: Try for ActiveSync Attacks | |
| 1376 | Step 3: Check Whether the IR Port is Enabled | |
| 1377 | Step 4: Check Whether Encrypted Data can be Decrypted | |
| 1378 | Bluetooth: Introduction | |
| 1379 | Different Attacks in Bluetooth Devices | |
| 1380 | Steps for Penetration Testing in Bluetooth | |
| 1381 | Step 1: Check Whether the PIN Can be Cracked | |
| 1382 | Step 2: Try to Perform a Blueprinting Attack | |
| 1383 | Step 3: Check Whether you are able to Extract the SDP Profiles | |
| 1384 | Step 4: Try Pairing Code Attacks | |
| 1385 | Step 5: Try a Man-in-the-Middle Attack | |
| 1386 | Step 6: Try a BlueJacking Attack | |
| 1387 | Step 7: Try a BTKeylogging Attack | |
| 1388 | Step 8: Try Bluesmacking -The Ping of Death | |
| 1389 | Step 9: Try a BlueSnarfing Attack | |
| 1390 | Try a BlueSnarfing Attack | |
| 1391 | Step 10: Try a BlueBug Attack | |
| 1392 | Step 11: Try BlueSpam | |
| 1393 | Module 37 Review | |
| 1394 | Module 38 - Telecommunication and Broadband Communication Penetration Testing | |
| 1395 | Telecommunication and Broadband Communication Penetration Testing | |
| 1396 | Broadband Communication | |
| 1397 | Risk in Broadband Communication | |
| 1398 | Steps for Broadband Communication Penetration Testing | |
| 1399 | Step 1: Check Whether the Firewall Device is Installed on Network | |
| 1400 | Step 1.1: Check Whether Personal and Hardware Firewalls are Installed | |
| 1401 | Step 1.2: Check Whether These Firewalls Prevent Intruders or Detect Any Rogue Software | |
| 1402 | Step 1.3: Check Whether the Logging is Enabled on the Firewall | |
| 1403 | Step 1.4: Check Whether the Firewall is in Stealth Mode | |
| 1404 | Step 2: Check Whether Web Browsers are Properly Configured | |
| 1405 | Step 2.1: Check Whether the Browser has Default Configuration | |
| 1406 | Step 2.2: Check for the Browser Plugins | |
| 1407 | Step 2.3: Check Whether Active Code is Enabled | |
| 1408 | Step 2.4: Check Whether the Browser Version is Updated | |
| 1409 | Step 2.5: Check Whether the Cookies are Enabled | |
| 1410 | Step 2.6: Check Whether the scripting Languages are Enabled | |
| 1411 | Step 3: Check for Operating System Configuration Options | |
| 1412 | Step 3.1: Check Whether Operating System and Application Software are Updated | |
| 1413 | Step 3.2: Check Whether the File and Printer Sharing Option is Enabled | |
| 1414 | Step 3.3: Check Whether the Anti-Virus Programs are Enabled | |
| 1415 | Step 3.4: Check the Configuration of Anti-Virus Program | |
| 1416 | Step 3.5: Check Whether Anti-Spyware is Enabled | |
| 1417 | Step 4: Check for Wireless and other Home Networking Technologies | |
| 1418 | Step 4.1: Check for VPN Policy Configurations | |
| 1419 | Step 4.2: Try for Wiretapping | |
| 1420 | Step 4.3: Try to Perform War Driving | |
| 1421 | Step 4.4: Check Whether the Wireless Base Station is at Default Configuration | |
| 1422 | Step 4.5: Check Whether WEP is Implemented | |
| 1423 | Step 4.6: Try to Crack the WEP Key | |
| 1424 | Step 4.7: Try to Crack the SSID Password | |
| 1425 | Step 4.8: Check Whether the Simple Network Management Protocol (SNMP) is Enabled | |
| 1426 | Guidelines for Securing Telecommuting and Home Networking Resources | |
| 1427 | Module 38 Review | |
| 1428 | Module 39 - Email Security Penetration Testing | |
| 1429 | Email Security Penetration Testing | |
| 1430 | Introduction to Email Security | |
| 1431 | Pre-Requisite For Email Penetration Testing | |
| 1432 | Demo - Hacking Email Accounts | |
| 1433 | Steps for Email Penetration Testing | |
| 1434 | Step 1: Try to Access Email ID and Password | |
| 1435 | Step 2: Check Whether Anti-Phishing Software is Enabled | |
| 1436 | Step 3: Check Whether Anti-Spamming Tools are Enabled | |
| 1437 | Step 4: Try to Perform Email Bombing | |
| 1438 | Step 5: Perform CLSID Extension Vulnerability Test | |
| 1439 | Step 6: Perform VBS Attachment Vulnerability Test | |
| 1440 | Step 7: Perform Double File Extension Vulnerability Test | |
| 1441 | Step 8: Perform Long Filename Vulnerability Test | |
| 1442 | Step 9: Perform ActiveX Vulnerability Test | |
| 1443 | Step 10: Perform Iframe Remote Vulnerability Test | |
| 1444 | Step 11: Perform MIME Header Vulnerability Test | |
| 1445 | Step 12: Perform Malformed File Extension Vulnerability Test | |
| 1446 | Step 13: Perform Access Exploit Vulnerability Test | |
| 1447 | Step 14: Perform Fragmented Message Vulnerability Test | |
| 1448 | Step 15: Perform Long Subject Attachment Checking Test | |
| 1449 | List of Anti-Phishing Tools | |
| 1450 | PhishTank SiteChecker | |
| 1451 | PhishTank SiteChecker: Screenshot | |
| 1452 | NetCraft | |
| 1453 | GFI MailEssentials | |
| 1454 | SpoofGuard | |
| 1455 | List of Anti-Spamming Tools | |
| 1456 | AEVITA Stop SPAM Email | |
| 1457 | SpamExperts Desktop | |
| 1458 | Spytech SpamAgent | |
| 1459 | Module 39 Review | |
| 1460 | Module 40 - Security Patches Penetration Testing | |
| 1461 | Security Patches Penetration Testing | |
| 1462 | Patch Management | |
| 1463 | Patch and Vulnerability Group (PVG) | |
| 1464 | Countermeasure Testing Steps | |
| 1465 | Step 1: Check If Organization has a PVG in Place | |
| 1466 | Step 2: Check Whether the Security Environment is Updated | |
| 1467 | Step 3: Check Whether Organization uses Automated Patch Management Tools | |
| 1468 | Step 4: Check the Last Date of Patching | |
| 1469 | Step 5: Check the Patches on Non-Production Systems | |
| 1470 | Step 6: Check the Vender Authentication Mechanism | |
| 1471 | Step 7: Check Whether Downloaded Patches Contain Viruses | |
| 1472 | Step 8: Check for Dependency of New Patches | |
| 1473 | Security Checklist for Patch Management | |
| 1474 | Patch Management Tools | |
| 1475 | Module 40 Review | |
| 1476 | Module 41 - Data Leakage Penetration Testing | |
| 1477 | Data Leakage Penetration Testing | |
| 1478 | Penetration Testing Roadmap | |
| 1479 | Data Leakage | |
| 1480 | Data Leakage Statistics | |
| 1481 | How Much Security? | |
| 1482 | How Data Can be Leaked | |
| 1483 | What to Protect | |
| 1484 | Steps for Data Leakage | |
| 1485 | Step 1: Check Physical Availability of USB Devices | |
| 1486 | Step 2: Check Whether USB Drive is Enabled | |
| 1487 | Step 3: Try to Enable USB | |
| 1488 | Step 4: Check Whether USB Asked for Password | |
| 1489 | Step 5: Check Whether Bluetooth is Enabled | |
| 1490 | Step 6: Check if the Firewire is Enabled | |
| 1491 | Step 7: Check if FTP Ports 21 and 22 are Enabled | |
| 1492 | Step 8: Check Whether any Memory Slot is Available and Enabled in Systems | |
| 1493 | Step 9: Check Whether Employees are Using Camera Devices within Restricted Areas | |
| 1494 | Step 10: Check Whether Systems have Any Camera Driver Installed | |
| 1495 | Step 11: Check Whether Anti-Spyware and Anti-Trojans are Enabled | |
| 1496 | Step 12: Check Whether Encrypted Data Can be Decrypted | |
| 1497 | Step 13: Check if the Internal Hardware Components are Locked | |
| 1498 | Step 14: Check Whether Size of Mail and Mail Attachments is Restricted | |
| 1499 | Data Privacy and Protection Acts | |
| 1500 | Data Protection Tools | |
| 1501 | Module 41 Review | |
| 1502 | Module 42 - Penetration Testing Deliverables and Conclusion | |
| 1503 | Penetration Testing Deliverables and Conclusion | |
| 1504 | Destroy the Report | |
| 1505 | Sign-Off Document | |
| 1506 | Module 42 Review | |
| 1507 | Module 43 - Penetration Testing Report and Documentation Writing | |
| 1508 | Penetration Testing Report and Documentation Writing | |
| 1509 | Penetration Testing Report | |
| 1510 | Documentation Writing | |
| 1511 | Table of Contents | |
| 1512 | Summary of Execution | |
| 1513 | Summary of Weaknesses | |
| 1514 | Scope of the Project | |
| 1515 | Result Analysis | |
| 1516 | Recommendations | |
| 1517 | Appendices | |
| 1518 | Test Reports on Network | |
| 1519 | Summary Recommendations | |
| 1520 | Exploited Vulnerabilities | |
| 1521 | Payment Card Industry (PCI) Report | |
| 1522 | Client-Side Test Reports | |
| 1523 | Client-Side Penetration Test Report | |
| 1524 | User Report | |
| 1525 | Test Reports on Web Applications | |
| 1526 | Web Application Testing Report | |
| 1527 | Detailed Findings | |
| 1528 | Detailed Results | |
| 1529 | Strategic and Tactical Directives | |
| 1530 | Writing the Final Report | |
| 1531 | Creating the Final Report | |
| 1532 | Report Format | |
| 1533 | Delivery | |
| 1534 | Report Retention | |
| 1535 | Module 43 Review | |
| 1536 | Module 44 - Penetration Testing Report Analysis | |
| 1537 | Penetration Testing Report Analysis | |
| 1538 | Report on Penetration Testing | |
| 1539 | Pen-Test Team Meeting | |
| 1540 | Research Analysis | |
| 1541 | Pen-Test Findings | |
| 1542 | Rating Findings | |
| 1543 | Demo - Practical Threat Analysis Tool | |
| 1544 | Example of Finding- I | |
| 1545 | Example of Finding- II | |
| 1546 | Analyze | |
| 1547 | Module 44 Review | |
| 1548 | Module 45 - Post Testing Actions | |
| 1549 | Post Testing Actions | |
| 1550 | Prioritize Recommendations | |
| 1551 | Develop Action Plan | |
| 1552 | Create Process for Minimizing Misconfiguration Chances | |
| 1553 | Updates and Patches | |
| 1554 | Capture Lessons Learned and Best Practices | |
| 1555 | Create Security Policies | |
| 1556 | Conduct Training | |
| 1557 | Take Social Engineering Class | |
| 1558 | Destroy the Pen-Test Report | |
| 1559 | Module 45 Review | |
| 1560 | Module 46 - Ethics of a Licensed Penetration Tester | |
| 1561 | Ethics of a Licensed Penetration Tester | |
| 1562 | What Makes a Licensed Penetration Tester? | |
| 1563 | Modus Operandi | |
| 1564 | Evolving as a Licensed Penetration Tester | |
| 1565 | Licensed Penetration Tester Dress Code | |
| 1566 | LPT Audited Logos | |
| 1567 | Example: LPT Audited Logos | |
| 1568 | Module 46 Review | |
| 1569 | Module 47 - Standards and Compliance | |
| 1570 | Customers and Legal Agreements | |
| 1571 | Module 47 Review | |
| 1572 | Course Closure |