View difference between Paste ID: iMfb6J9G and 4W8iryHb
SHOW: | | - or go back to the newest paste.
1
This is the training I (Kiran Karnad) used to provide at the 3-day infosec training workshop when I was working at VCIPL
2
 
3
Module 00 - Student Introduction
4
Student Introduction
5
Certification
6
ECSA Track
7
LPT Track
8
What next after ECSA Training?
9
Demo - Overview of Available Resources
10
Lab Sessions
11
Student Introduction Review
12
Module 01 - The Need for Security Analysis
13
The Need for Security Analysis
14
What are we Concerned About?
15
So What are you Trying to Protect?
16
Why are Intrusions so Often Successful?
17
What are the Greatest Challenges?
18
Environmental Complexity
19
New Technologies
20
New Threats and Exploits
21
Demo - Keep Updated with Research
22
Limited Focus
23
Limited Expertise
24
Tool: Data Loss Cost Calculator
25
Demo - Tech//404 Data Loss Calculator
26
In Order to Ensure…
27
Authentication
28
Authorization
29
Confidentiality
30
Integrity
31
Availability
32
Non-Repudiation
33
We Must be Diligent
34
Threat Agents
35
Assessment Questions
36
How Much Security is Enough?
37
Risk
38
Simplifying Risk
39
Risk Analysis
40
Risk Assessment Answers Seven Questions:
41
Steps of Risk Assessment
42
Demo - Risk Assessment
43
Demo - CIO-view Self-assessment
44
Risk Assessment Values
45
Demo - Quantitative Threat Analysis
46
Information Security Awareness
47
Security Policies
48
Security Policy Basics
49
Demo - Policy Templates
50
Types of Policies
51
Promiscuous Policy
52
Permissive Policy
53
Prudent Policy
54
Paranoid Policy
55
Acceptable-Use Policy
56
User-Account Policy
57
Remote-Access Policy
58
Information-Protection Policy
59
Firewall-Management Policy
60
Special-Access Policy
61
Network-Connection Policy
62
Business-Partner Policy
63
Data Classification Policies
64
Intrusion Detection Policies
65
Virus Prevention Policies
66
Laptop Security Policy
67
Personal Security Policy
68
Cryptography Policy
69
Fair and Accurate Credit Transactions Act of 2003 (FACTA)
70
Other Important Policies
71
Policy Statements
72
Basic Document Set of Information Security Policies
73
ISO 17799
74
Domains of ISO 17799
75
No Simple Solutions
76
U.S. Legislation
77
California SB 1386
78
Sarbanes-Oxley 2002
79
Gramm-Leach-Bliley Act (GLBA)
80
Health Insurance Portability and Accountability Act (HIPAA)
81
USA Patriot Act 2001
82
U.K. Legislation
83
How Does This Law Affect a Security Officer?
84
The Data Protection Act 1998
85
The Human Rights Act 1998
86
Interception of Communications
87
The Freedom of Information Act 2000
88
The Audit Investigation and Community Enterprise Act 2005
89
Demo - Vmware Overview
90
Demo - Opening an Existing XP VMware System
91
Demo - Opening VM Appliance
92
Demo - Installing a New VM System
93
Demo - Booting XP from Backtrack ISO
94
Module 1 Review
95
Module 02 - Advanced Googling
96
Advanced Googling
97
Site Operator
98
intitle:index.of
99
Demo - Default Pages: tsweb
100
error | warning
101
Demo - Google as a Proxy
102
login | logon
103
username | userid | employee.ID | “your username is”
104
password | passcode | “your password is”
105
admin | administrator
106
–ext:html –ext:htm –ext:shtml –ext:asp –ext:php
107
inurl:temp | inurl:tmp | inurl:backup | inurl:bak
108
Google Advanced Search Form
109
Categorization of the Operators
110
allinanchor:
111
allintext:
112
Demo - Google Locating Live Cams
113
Locating Public Exploit Sites
114
Locating Exploits via Common Code Strings
115
Locating Vulnerable Targets
116
Locating Targets via Demonstration Pages
117
Demo - Google Hack HoneyPot
118
Demo - Goolag and Wikto
119
Demo - Wikto Results and Google Guide
120
Module 2 Review
121
Module 03 - TCP/IP Packet Analysis
122
TCP/IP Packet Analysis
123
TCP/IP Model
124
Demo - TCP/IP Movie Recommendation
125
Application Layer
126
Transport Layer
127
Internet Layer
128
Network Access Layer
129
Comparing OSI and TCP/IP
130
Demo - Engage Packet Builder
131
TCP
132
TCP Header
133
IP Header: Protocol Field
134
UDP
135
TCP and UDP Port Numbers
136
Port Numbers
137
Demo - Warriors of the Net
138
IANA
139
Source and Destination Port Numbers
140
Demo - Techtionary.com Port Numbers
141
What Makes Each Connection Unique?
142
Structure of a Packet
143
TCP Operation
144
Three-Way Handshake
145
Demo - Techtionary.com TCP Handshake
146
Flow Control
147
Windowing
148
Windowing and Window Sizes
149
Simple Windowing
150
Acknowledgement
151
Sliding Windows
152
Sequencing Numbers
153
Synchronization
154
Positive Acknowledgment and Retransmission (PAR)
155
What is Internet Protocol v6 (IPv6)?
156
Why IPv6?
157
IPv4/IPv6 Transition Mechanisms
158
IPv6 Security Issues
159
Security Flaws in IPv6
160
IPv6 Infrastructure Security
161
Ipsec
162
Firewalls and Packet Filtering
163
Denial-of-Service (DoS) Attacks
164
UDP Operation
165
Internet Control Message Protocol (ICMP)
166
ICMP Message Delivery
167
Format of an ICMP Message
168
Unreachable Networks
169
Time Exceeded Message
170
IP Parameter Problem
171
ICMP Control Messages
172
ICMP Redirects
173
Clock Synchronization and Transit Time Estimation
174
Information Requests and Reply Message Formats
175
Address Masks
176
Router Solicitation and Advertisement
177
Module 3 Review
178
Module 04 - Advanced Sniffing Techniques
179
Advanced Sniffing Techniques
180
Demo - Basic Sniffers
181
Demo - Packet Capturing with Windows Packetyzer
182
What is Wireshark?
183
Wireshark: Filters
184
Wireshark: Tshark
185
Wireshark: Tcpdump
186
Demo - Tcpdump
187
Protocol Dissection
188
Steps to Solve GNU/ Linux Server Network Connectivity Issues
189
Using Wireshark for Network Troubleshooting
190
Using Wireshark for System Administration
191
ARP Problems
192
Demo - Sniffers and ARP
193
ICMP Echo Request/Reply Header Layout
194
TCP Flags
195
Scenario 1: SYN no SYN+ACK
196
Scenario 2: SYN Immediate Response RST
197
Scenario 3: SYN SYN+ACK ACK
198
Tapping into the Network
199
Using Wireshark for Security Administration
200
Sniffer Detection
201
Wireless Sniffing with Wireshark
202
Frequency
203
Using Channel Hopping
204
Interference and Collisions
205
Recommendations for Sniffing Wireless Traffic
206
Analyzing Wireless Traffic
207
IEEE 802.11 Header
208
Filters
209
Unencrypted Data Traffic
210
Identifying Hidden SSIDs
211
Identifying EAP Authentication Failures
212
Identifying WEP
213
Identifying IPsec/VPN
214
Decrypting Traffic
215
Scanning
216
TCP Connect Scan
217
SYN Scan
218
XMAS Scan
219
Null Scan
220
Remote Access Trojans
221
Wireshark DNP3 Dissector Infinite Loop Vulnerability
222
Time Stamps
223
Time Zones
224
Packet Reassembling
225
Checksums
226
Module 4 Review
227
Module 05 - Vulnerability Analysis with Nessus
228
Vulnerability Analysis with Nessus
229
Nessus
230
Features of Nessus
231
Nessus Assessment Process
232
Demo - Nessus on Windows
233
Demo - Nessus on Windows Cont'd and GFI LANguard Comparison
234
False Positives
235
Examples of False Positives
236
Identifying False Positives
237
Suspicious Signs
238
Demo - Backtrack 4 Nessus Install
239
Module 5 Review
240
Module 06 - Advanced Wireless Testing
241
Advanced Wireless Testing
242
Wireless Concepts
243
Demo - Techtionary Website
244
802.11 Types
245
Core Issues with 802.11
246
What’s the Difference?
247
Other Types of Wireless
248
Spread Spectrum Background
249
Channels
250
Access Point
251
Service Set ID
252
Demo - Linksys-AP Config SSID
253
Default SSIDs
254
Chipsets
255
Wi-Fi Equipment
256
Expedient Antennas
257
Vulnerabilities to 802.1x and RADIUS
258
Security - WEP
259
Wired Equivalent Privacy (WEP)
260
Exclusive OR
261
Encryption Process
262
Chipping Sequence
263
WEP Issues
264
WEP - Authentication Phase
265
WEP - Shared Key Authentication
266
WEP - Association Phase
267
WEP Flaws
268
WEP Attack
269
Demo - Authentication Settings
270
Demo - WEP Set-Up Security
271
Demo - Cain and Abel WEP Cracking
272
WPA Interim 802.11 Security
273
WPA
274
Demo - Cracking WPA with Cain and Abel
275
WPA2 (Wi-Fi Protected Access 2)
276
802.1X Authentication and EAP
277
EAP Types
278
Cisco LEAP
279
TKIP (Temporal Key Integrity Protocol)
280
Wireless Networks Testing
281
Wireless Communications Testing
282
Report Recommendations
283
Wireless Attack Countermeasures
284
Demo - MAC-SSID Security
285
Wireless Penetration Testing with Windows
286
War Driving
287
The Jargon – WarChalking
288
Wireless: Tools of the Trade
289
Demo - Kismet in Windows
290
Demo - Tool: Kismet in Linux
291
Demo - Vistumbler War Driving and GPS Map Plotting
292
How Does NetStumbler Work?
293
“Active” vs. “Passive” WLAN Detection
294
Disabling the Beacon
295
Running NetStumbler
296
Demo - Tool: Netstumbler
297
AirCrack-ng
298
AirCrack-ng: How Does it Work?
299
AirCrack-ng: FMS and Korek Attacks
300
AirCrack-ng: Notes
301
Demo - Hacking WEP Encryption
302
Determining Network Topology: Network View
303
WarDriving and Wireless Penetration Testing with OS X
304
Using a GPS
305
Deauthenticating Clients
306
StumbVerter
307
MITM Attack Design
308
MITM Attack Variables
309
Hardware for the Attack: Antennas, Amps, and WiFi Cards
310
Choosing the Right Antenna
311
Amplifying the Wireless Signal
312
IP Forwarding and NAT using IPtables
313
Demo - Jasager fon Router
314
Module 6 Review
315
Module 07 - Designing a DMZ
316
Designing a DMZ
317
Introduction
318
DMZ Concepts
319
DMZ Design Fundamentals
320
Advanced Design Strategies
321
Types of Firewall and DMZ Architectures
322
"Inside vs. Outside" Architecture
323
"Three-Homed Firewall" DMZ Architecture
324
Weak Screened Subnet Architecture
325
Strong Screened Subnet Architecture
326
Designing a DMZ using IPtables
327
Designing Windows DMZ
328
Precautions for DMZ Setup
329
Demo - Designing DMZs
330
Advanced Implementation of a Solaris DMZ Server
331
Solaris DMZ Servers in a Conceptual Highly Available Configuration
332
Hardening Checklists for DMZ Servers and Solaris
333
Placement of Wireless Equipment
334
Access to DMZ and Authentication Considerations
335
Wireless DMZ Components
336
WLAN DMZ Security Best Practices
337
Ethernet Interface Requirements and Configuration
338
DMZ Router Security Best Practice
339
Six Ways to Stop Data Leaks
340
Module 7 Review
341
Module 08 - Snort Analysis
342
Snort Analysis
343
Snort Overview
344
Modes of Operation
345
Features of Snort
346
Configuring Snort
347
Snort: Variables
348
Snort: Pre-processors
349
Snort: Output Plug-ins
350
Snort: Rules
351
How Snort Operates
352
Initializing Snort
353
Demo - Snort IDS Testing Scanning Tools
354
Signal Handlers
355
Parsing the Configuration File
356
Decoding
357
Possible Decoders
358
Pre-processing
359
Detection
360
Content Matching
361
The Stream4 Pre-processor
362
Inline Functionality
363
Writing Snort Rules
364
Snort Rule Header
365
Snort Rule Header: Actions
366
Snort Rule Header: Other Fields
367
IP Address Negation Rule
368
IP Address Filters
369
The direction Operator
370
Rule Options
371
Activate/Dynamic Rules
372
Metadata Rule Options: msg
373
The reference Keyword
374
The sid/rev Keyword
375
The classtype Keyword
376
Payload Detection Rule Options: content
377
Modifier Keywords
378
The uricontent Keyword
379
The fragoffset Keyword
380
Writing Good Snort Rules
381
Tool for Writing Snort Rules: IDS Policy Manager
382
Honeynet Security Console Tool
383
Key Features
384
Module 8 Review
385
Module 09 - Log Analysis
386
Log Analysis
387
Logs
388
Events that Need to be Logged
389
What to Look Out For in Logs
390
Automated Log Analysis Approaches
391
Log Shipping
392
Syslog
393
Setting up a Syslog
394
System Error Logs
395
Kiwi Syslog Daemon
396
Configuring Kiwi Syslog to Log to a MS SQL Database
397
Configuring a Cisco Router for Syslog
398
Configuring a DLink Router for Syslog
399
Gathering Log Files from an IIS Web Server
400
Apache Web Server Log
401
AWStats Log Analyzer
402
Cisco Router Logs
403
Analyzing Netgear Wireless Router Logs
404
Wireless Traffic Analysis Using Wireshark
405
Configuring Firewall Logs in Local Windows System
406
Viewing Local Windows Firewall Log
407
Viewing Windows Event Log
408
Collecting & Monitoring UNIX Syslog
409
iptables
410
Log Prefixing with iptables
411
Firewall Log Analysis with grep
412
SQL Database Log
413
Using SQL Server to Analyze Web Logs
414
Analyzing Oracle Logs: The Oracle Metric Log File
415
ApexSQL Log
416
Analyzing Solaris System Logs
417
Demo - Splunk
418
Module 9 Review
419
Module 10 - Advanced Exploits and Tools
420
Advanced Exploits and Tools
421
Common Vulnerabilities
422
Buffer Overflows Revisited
423
Smashing the Stack for Fun and Profit
424
Smashing the Heap for Fun and Profit
425
Format Strings for Chaos and Mayhem
426
The Anatomy of an Exploit
427
Demo - Fuzzing for Weaknesses
428
Vulnerable Code
429
Shellcode
430
Shellcode Examples
431
Shellcode (cont’d)
432
Demo - Stack Function
433
Delivery Code
434
Delivery Code: Example
435
Demo - Compiling Exploits from Source Code
436
Linux Exploits versus Windows
437
Windows versus Linux
438
Tools of the Trade: Debuggers
439
Tools of the Trade: GDB
440
Tools of the Trade: Metasploit
441
Demo - Metasploit Intro
442
Demo - Metasploit 101
443
Demo - Metasploit Interactive
444
Tools of the Trade: Canvas
445
Lab
446
Tools of the Trade: CORE Impact
447
Ways to Use CORE Impact
448
Microsoft Baseline Security Analyzer (MBSA)
449
Network Security Analysis Tool (NSAT)
450
Sunbelt Network Security Inspector (SNSI)
451
Demo - Saint Exploit of Windows XP
452
Demo - dcom101 Exploit Autoshovel of Shell
453
Demo - dcom Exploit Netcat Shovel of Shell and Extracting Hashes
454
Demo - Backtrack 4 Milw0rm Metasploit Updates
455
Module 10 Review
456
Module 11 - Penetration Testing Methodologies
457
Penetration Testing Methodologies
458
Demo - dradis Effective Information Sharing
459
What is Penetration Testing?
460
Why Penetration Testing?
461
What Should be Tested?
462
What Makes a Good Penetration Test?
463
Common Penetration Testing Techniques
464
Penetration Testing Process
465
Scope of Penetration Testing
466
Blue Teaming/Red Teaming
467
Types of Penetration Testing
468
Black-box Penetration Testing
469
White-box Penetration Testing
470
Announced Testing/ Unannounced Testing
471
Grey-box Penetration Testing
472
Strategies of Penetration Testing
473
External Penetration Testing
474
Internal Security Assessment
475
Application Security Assessment
476
Types of Application Security Assessment
477
Network Security Assessment
478
Wireless/Remote Access Assessment
479
Telephony Security Assessment
480
Social Engineering
481
Penetration Testing Consultants
482
Required Skills Sets
483
Hiring a Penetration Tester
484
Responsibilities of a Penetration Tester
485
Profile of a Good Penetration Tester
486
Why Should the Company Hire You?
487
Companies’ Concerns
488
Methodology
489
Demo - NIST Methodology
490
Demo - PenTest Templates and Methodologies
491
Penetration Testing Roadmap
492
Guidelines for Security Checking
493
Operational Strategies for Security Testing
494
Security Category of the Information System
495
Identifying Benefits of Each Test Type
496
Prioritizing the Systems for Testing
497
ROI on Penetration Testing
498
Determining Cost of Each Test Type
499
Need for a Methodology
500
Penetration Test vs. Vulnerability Test
501
Reliance on Checklists and Templates
502
Phases of Penetration Testing
503
Pre-Attack Phase
504
Best Practices
505
Results that can be Expected
506
Passive Reconnaissance
507
Active Reconnaissance
508
Attack Phase
509
Activity: Perimeter Testing
510
Activity: Web Application Testing - I
511
Activity: Web Application Testing – II
512
Activity: Wireless Testing
513
Activity: Acquiring Target
514
Activity: Escalating Privileges
515
Activity: Execute, Implant, and Retract
516
Post-Attack Phase and Activities
517
Module 11 Review
518
Module 12 - Customers and Legal Agreements
519
Customers and Legal Agreements
520
Why do Organizations Need Pen-Testing?
521
Initial Stages in Penetration Testing
522
Understand Customer Requirements
523
Create a Checklist of Testing Requirements
524
Penetration Testing ‘Rules of Behavior’
525
Demo - ISSAF Customers and Legal
526
Penetration Testing Risks
527
Penetration Testing by Third Parties
528
Precautions While Outsourcing Penetration Testing
529
Legal Consequences
530
Demo - Computer Crimes and Implications
531
Get Out of Jail Free Card
532
Permitted Items in Legal Agreement
533
Confidentiality and NDA Agreements
534
Non-Disclosure and Secrecy Agreements (NDA)
535
The Contract
536
Liability Issues
537
Negligence Claim
538
Plan for the Worst
539
Drafting Contracts
540
How Much to Charge?
541
Module 12 Review
542
Module 13 - Rules of Engagement
543
Rules of Engagement
544
Rules of Engagement (ROE)
545
Demo - OSSTMM Model
546
Scope of ROE
547
Steps for Framing ROE
548
Clauses in ROE
549
Demo - ScreenHunter Desktop Capture Tool
550
Module 13 Review
551
Module 14 - Penetration Testing Planning and Scheduling
552
Penetration Testing Planning and Scheduling
553
Test Plan
554
Purpose of Test Plan
555
Building a Penetration Test Plan
556
Demo - Overview OSSTMM
557
IEEE STD. 829–1998 SECTION HEADINGS
558
Test Plan Identifier
559
Test Deliverables
560
Penetration Testing Planning Phase
561
Define the Scope
562
Project Scope
563
When to Retest?
564
Responsibilities
565
Skills and Knowledge Required
566
Internal Employees
567
Penetration Testing Teams
568
Tiger Team
569
Building Tiger Team
570
Questions to Ask Before Hiring Consultants to the Tiger Team
571
Meeting With the Client
572
Kickoff Meeting
573
Penetration Testing Project Plan
574
Work Breakdown Structure or Task List
575
Penetration Testing Schedule
576
Penetration Testing Project Scheduling Tools
577
Test Plan Checklist
578
Penetration Testing Hardware/Software Requirements
579
EC-Council’s Vampire Box
580
Begin Penetration Testing
581
Demo - Installing Backtrack 4 into VMWare Environment
582
Module 14 Review
583
Module 15 - Customers and Legal Agreements
584
Pre-Penetration Testing Checklist
585
Demo - Pentest Checklist
586
Step 1: Gather Information about Client Organization’s History and Background
587
Step 2: Visit the Client Organization Premises
588
Step 3: List the Client Organization’s Penetration Testing Requirements
589
Step 4: Obtain Penetration Testing Permission from the Company’s Stakeholders
590
Step 5: Obtain Detailed Proposal of Test and Services that are Proposed to be carried out
591
Step 6: Identify the Office Space/Location your Team would be Working in for this Project
592
Step 7: Obtain Temporary Identity Cards from the Organization for the Team who is Involved in the Process
593
Step 8: Identify who will be Leading the Penetration Testing Project (Chief Penetration Tester)
594
Step 9: Request from the Client Organization the Previous Penetration Testing/Vulnerability Assessment Reports
595
Step 10: Prepare Rules of Engagement that Lists the Company’s Core Competencies/ Limitations/ Timescales
596
Step 11: Hire a Lawyer who Understands IT and can Handle your Penetration Testing Legal Documents
597
Step 12: Prepare PT Legal Document and get Vetted with your Lawyer
598
Step 13: Prepare Non Disclosure Agreement (NDA) and have the Client Sign them
599
Step 14: Obtain (if possible) Liability Insurance from a Local Insurance Firm
600
Step 15: Identify your Core Competencies/Limitations
601
Step 16: Allocate a Budget for the Penetration Testing Project ( X amount of $ )
602
Step 17: Prepare a Tiger Team
603
Step 18: List the Security Tools that you will be using for the Penetration Testing Project
604
Step 19: List the Hardware and Software Requirements for the Penetration Testing Project
605
Step 20: Identify the Clients Security Compliance Requirements
606
Step 21: List the Servers, Workstations, Desktops and Network Devices that need to be Tested
607
Step 22: Identify the Type of Testing that would be carried out - Black Box or White Box Testing
608
Step 23: Identify the Type of Testing that would be carried out - Announced/ Unannounced
609
Step 24: Identify Local Equipment Required for Pen Test
610
Step 25: Identify Local Manpower Required for Pen Test
611
Step 26: List the Contact Details of Personnel from Client Organization who will be in Charge of the Pen Test
612
Step 27: Obtain the Contact Details of the Key Personnel for Approaching in case of an Emergency
613
Step 29: List the Tests that will not be carried out at the Client Network
614
Step 30: Identify the Purpose of the Test you are carrying out at the Client Organization
615
Step 31: Identify the Network Topology in which the Test would be carried out
616
Step 32: Obtain Special Permission if Required from Local Law Enforcement Agency
617
Step 33: List known Waivers/Exemptions
618
Step 34: List the Contractual Constraints in the Penetration Testing Agreement
619
Step 35: Identify the Reporting Timescales with the Client Organization
620
Step 36: Identify the List of Penetration Testers Required for this Project
621
Step 37: Negotiate per Day/per Hour Fee that you will be Charging for the Penetration Testing Project
622
Step 38: Draft the Timeline for the Penetration Testing Project
623
Step 39: Draft a Quotation for the Services that you'll be Providing to the Client Organization
624
Step 40: Identify how the Final Penetration Testing Report will be Delivered to the Client Organization
625
Step 41: Identify the Reports to be Delivered After Pen Test
626
Step 42: Identify the Information Security Administrator who will be helping you in the Penetration Testing
627
Module 15 Review
628
Module 16 - Information Gathering
629
Information Gathering
630
What is Information Gathering?
631
Information Gathering Steps
632
Step 1: Crawl the Website and Mirror the Pages on Your PC
633
Demo - HTTrack Website Copier
634
Step 2: Crawl the FTP Site and Mirror the Pages on Your PC
635
Demo - Wget and Backtrack 4 Live CD
636
Step 3: Look up Registered Information in the Whois Database
637
Demo - CentralOps and Domains by Proxy
638
Demo - Backtrack and Whois
639
Step 4: List the Products Sold by the Company
640
Demo - Firecat (Firefox Addons)
641
Step 5: List the Contact Information, Email Addresses, and Telephone Numbers
642
Step 6: List the Company’s Distributors
643
Step 7: List the Company’s Partners
644
Demo - Email Spider
645
Step 8: Search the Internet, Newsgroups, Bulletin Boards, Negative Websites for Information about the Company
646
Demo - Maltego
647
Step 9: Search for Trade Association Directories
648
Step 10: Search for Link Popularity of Company Website
649
Demo - Alexa
650
Step 11: Compare Price of Product or Service with the Competitor
651
Step 12: Find the Geographical Location
652
Demo - Shazou
653
Use Google Map to Find Geographical Location
654
Step 13: Search the Internet Archive Pages about the Company
655
Demo - Archive.org
656
Step 14: Search Similar or Parallel Domain Name Listings
657
Demo - ServerSniff TLDs
658
Step 15: Search Job Posting Sites about the Company
659
Step 16: Browse Social Network Websites
660
Demo - Social Networking
661
Step 17: Write Down Key Employees
662
Step 18: Investigate Key Persons – Searching in Google, Look up their Resumes and Cross Link Information
663
Step 19: List Employee Company and Personal Email Address
664
Step 20: Search for Web Pages Posting Patterns and Revision Numbers
665
Demo - No Tech Hacking
666
Step 21: Email the Employee Disguised as Customer Asking for Quotation
667
Step 22: Visit the Company as Inquirer and Extract Privileged Information
668
Step 23: Visit the Company Locality
669
Step 24: Use Web Investigation Tools to Extract Sensitive Data Targeting the Company
670
Step 25: Use Intelius and Conduct Background Check on Company Key Personnel
671
Step 26: Search on eBay for Company’s Presence
672
Step 27: Use the Domain Research Tool to Investigate the Company’s Domain
673
Step 28: Use the EDGAR Database to Research Company Information
674
Step 34: Use GHDB and Search for the Company Name
675
Demo - Summary
676
Demo - Vmware 64bit Error Fix
677
Demo - SEAT
678
Demo - Metagoofil Search
679
Demo - CORE Impact Email Info Gathering
680
Module 16 Review
681
Module 17 - Vulnerability Analysis
682
Vulnerability Analysis
683
Why Assess?
684
Vulnerability Classification
685
What is Vulnerability Assessment?
686
Demo - Vulnerability Research Resources
687
Demo - Nessus 4 Windows Install and Wikto Scan Webgoat
688
Types of Vulnerability Assessment
689
Demo - Nessus 3 Webgoat Scan BT4
690
Demo - Nessus 4 Webgoat Scan
691
Demo - GFI LANguard
692
How to Conduct a Vulnerability Assessment
693
How to Obtain a High Quality Vulnerability Assessment
694
Vulnerability Assessment Phases
695
Pre-Assessment Phase
696
Assessment Phase
697
Post-Assessment Phase
698
Vulnerability Analysis Stages
699
Comparing Approaches to Vulnerability Assessment
700
Characteristics of a Good Vulnerability Assessment Solution
701
Vulnerability Assessment Considerations
702
Vulnerability Assessment Reports
703
Demo - Nessus 3 BT Exporting NBE Report
704
Vulnerability Report Model
705
Timeline
706
Types of Vulnerability Assessment Tools
707
Choosing a Vulnerability Assessment Tool
708
Vulnerability Assessment Tools Best Practices
709
Vulnerability Assessment Tools
710
Demo - Retina Security Scanner
711
Other Vulnerability Tools
712
Report
713
Vulnerability Assessment Reports
714
Automated Scanning Server Reports
715
Periodic Vulnerability Scanning Report
716
Module 17 Review
717
Module 18 - External Penetration Testing
718
External Penetration Testing
719
Penetration Testing Roadmap
720
External Intrusion Test and Analysis
721
How is it Done?
722
Client Benefits
723
External Penetration Testing
724
Steps – Conduct External Penetration Testing
725
Demo - CORE Impact Network Vulnerability Test
726
Demo - Samaurai Live CD Intro
727
Step 1: Inventory Company’s External Infrastructure
728
Step 2: Create Topological Map of the Network
729
Step 3: Identify the IP Address
730
Step 4: Locate the Traffic Route that Goes to the Web Servers
731
Step 5/6: Locate TCP/UDP Traffic Path to the Destination
732
Step 7: Identify the Physical Location of the Target Servers
733
Step 8: Examine the Use IPV6 at the Remote Location
734
Step 9: Lookup Domain Registry for IP Information
735
Step 10: Find IP Block Information about the Target
736
Step 11: Locate the ISP Servicing the Client
737
Step 12: List Open Ports
738
Open Ports on Web Server
739
Step 13: List Closed Ports
740
Port Scanning Tools
741
Step 14: List Suspicious Ports that are Half Open/Closed
742
Step 15: Port Scan Every Port (65,536) on the Target’s Network
743
Step 16: Use SYN Scan on the Target and See the Response
744
Step 17: Use Connect Scan on the Target and See the Response
745
Demo - N-stalker Results Webgoat
746
Demo - Breaking Access Control Passwords with Xhydra
747
Demo - Viewing Website with Telnet
748
Demo - Input-injection Attack
749
Demo - Fast-track Overview and Install
750
Demo - Fast-track Exploits
751
Demo - Fast-track Clientside Attacks
752
Demo - Fast-track Mass Attack
753
Module 18 Review
754
Module 19 - Internal Network Penetration Testing
755
Internal Network Penetration Testing
756
Penetration Testing Roadmap
757
Internal Testing
758
Methods of Internal Testing
759
Enumerate Other Machines
760
Step 1: Map the Internal Network
761
Demo - Spiceworks Inventory
762
Step 2: Scan the Network for Live Hosts
763
Demo - SNMP Enumerating with BT
764
Demo - FireScope MIB Tool
765
Step 3: Port Scan Individual Machines
766
Step 4: Try to Gain Access Using Known Vulnerabilities
767
Demo - SMB NAT Dictionary Attacks
768
Demo - Injecting the Abel Service
769
Demo - Nslookup DNS Zone Transfer
770
Step 5: Attempt to Establish Null Sessions
771
Demo - Enumerate Banners
772
Demo - Null Session Multiple Tools
773
Demo - Null Session Countermeasures
774
Step 6: Enumerate Users
775
Step 7: Sniff the Network Using Wireshark
776
Step 8: Sniff Pop3/FTP/Telnet Passwords
777
Step 9: Sniff Email Messages/VoIP Traffic
778
Sniffer Tools
779
Demo - ARP Poisoning with Cain
780
Step 10: Attempt Replay Attacks
781
Demo - SSL MITM
782
Step 11: Attempt ARP Poisoning
783
Step 11a: Attempt Mac Flooding
784
Step 12: Conduct a Man-in-the Middle Attack
785
Step 13: Attempt DNS Poisoning
786
Demo - Cain DNS Spoof
787
Step 14: Try a Login to a Console Machine
788
Step 15: Boot the PC Using Alternate OS and Steal the SAM File
789
Demo - Local Password Reset
790
Demo - Backtrack Local XP Password Attack
791
Copying Commands in Knoppix
792
ERD Commander 2005
793
Reset Administrator Password
794
Step 16: Attempt to Plant a Software Keylogger to Steal Passwords
795
Keyloggers and Spy Software
796
Demo - Hardware Keystroke Loggers
797
Step 17: Attempt to Plant a Hardware Keylogger to Steal Passwords
798
Step 18: Attempt to Plant a Spyware on the Target Machine
799
Step 19: Attempt to Plant a Trojan on the Target Machine
800
Step 20: Attempt to Create a Backdoor Account on the Target Machine
801
Demo - Secure Tunnels and Anonymizer Techniques
802
Step 21: Attempt to Bypass Anti-virus Software Installed on the Target Machine
803
Demo - Stealth Tools v2 to Hide Viruses and Malware
804
Step 22: Attempt to Send Virus Using the Target Machine
805
Step 23: Attempt to Plant Rootkits on the Target Machine
806
Demo - Dreampakpl Rootkit
807
Step 24: Hide Sensitive Data on Target Machines
808
Demo - Alternate Data Streams
809
Step 25: Hide Hacking Tools and Other Data in Target Machines
810
Step 26: Use Various Steganography Techniques to Hide Files on Target Machine
811
Demo - Steganography
812
Step 27: Escalate User Privileges
813
Demo - Privilege Escalation
814
Step 28: Capture POP3 Traffic
815
Step 29: Capture SMTP Traffic
816
Step 32: Capture HTTP Traffic
817
Step 33: Capture HTTPS Traffic (Even Though it cannot be Decoded)
818
Step 34: Capture RDP Traffic
819
Step 35: Capture VoIP Traffic
820
Demo - Cain VoIP RDP Interception
821
Steps 40 and 41
822
Step 42: Attempt Session Hijacking on Telnet Traffic
823
Steps 43 and 44
824
Continue Testing
825
CORE Impact - Automated Tool
826
Metasploit - Tool
827
Canvas – Automated Tool
828
Vulnerability Scanning Tools
829
Document Everything
830
Module 19 Review
831
832
833
Module 20 - Router and Switches Penetration Testing
834
Router and Switches Penetration Testing
835
Demo - Cain and Abel Routing Protocols and ID Networks
836
Penetration Testing Roadmap
837
Router Testing Issues
838
Need for Router Testing
839
General Requirements
840
Technical Requirements
841
Try to Compromise the Router
842
Steps for Router Penetration Testing
843
Step 1: Identify the Router Hostname
844
Step 2: Port Scan the Router
845
Step 3: Identify the Router Operating System and its Version
846
Steps 4/5: Identify Protocols Running/Testing for Package Leakage at the Router
847
Step 6: Test for Router Misconfigurations
848
Step 7: Test for VTY/TTY Connections
849
The Process to Get Access to the Router
850
Step 8: Test for Router Running Modes
851
Privilege Mode Attacks
852
Step 9: Test for SNMP Capabilities
853
SNMP “Community String”
854
Step 10: Test for TFTP Connections
855
TFTP Testing
856
Step 11: Test if Finger is Running on the Router
857
Step 12: Test for CDP Protocol Running on the Router
858
How to Test CDP Protocol?
859
Step 13: Test for NTP Protocol
860
Step 14: Test for Access to Router Console Port
861
Step 15: Test for Loose and Strict Source Routing
862
Steps 16 and 17: Test for IP Spoofing/IP Handling Bugs
863
Step 18: Test ARP Attacks
864
Step 19: Test for Routing Protocol Assessment
865
Step 20: RIP Testing
866
Step 21: Test for OSPF Protocol
867
Step 22: Test BGP Protocol
868
Step 23: Test for EIGRP Protocol
869
Step 24: Test Router Denial of Service Attacks
870
Step 25: Test Router’s HTTP Capabilities
871
Step 26: Test Through HSRP Attack
872
Router Testing Report
873
Steps for Testing Switches
874
Step 1: Testing Address Cache Size
875
Step 2: Data Integrity and Error Checking Test
876
Step 3: Testing for Back-to-Back Frame Capacity
877
Step 4: Testing for Frame Loss
878
Step 5: Testing for Latency
879
Step 6: Testing for Throughput
880
Step 7: Test for Frame Error Filtering
881
Step 8: Fully Meshed Test
882
Step 9: Stateless QoS Functional Test
883
Step 10: Spanning Tree Network Convergence Performance Test
884
Step 11: OSPF Performance Test
885
Step 12: Test for VLAN Hopping
886
Step 13: Test for MAC Table Flooding
887
Step 14: Testing for ARP Attack
888
Step 15: Check for VTP Attack
889
Module 20 Review
890
Module 21 - Firewall Penetration Testing
891
Firewall Penetration Testing
892
Penetration Testing Roadmap
893
What is a Firewall?
894
What Does a Firewall Do?
895
Packet Filtering
896
What Can't a Firewall Do?
897
How Does a Firewall Work?
898
Firewall Logging Functionality
899
Firewall Policy
900
Periodic Review of Information Security Policies
901
Firewall Implementation
902
Build a Firewall Ruleset
903
Maintenance and Management of Firewall
904
Types of Firewall
905
Demo - Introduction to Vyatta
906
Packet Filtering Firewall
907
IP Packet Filtering Firewall
908
Circuit Level Gateway
909
Application Level Firewall
910
Stateful Multilayer Inspection Firewall
911
Multilayer Inspection Firewall
912
Steps for Conducting Firewall Penetration Testing
913
Step 1: Locate the Firewall
914
Step 2: Traceroute to Identify the Network Range
915
Step 3: Port Scan the Firewall
916
Step 4: Grab the Banner
917
Step 5: Create Custom Packets and Look for Firewall Responses
918
Step 6: Test Access Control Enumeration
919
Step 7: Test to Identify Firewall Architecture
920
Step 8: Testing Firewall Policy
921
Step 9: Test Firewall Using Firewalking Tool
922
Step 10: Test for Port Redirection
923
Firewall Identification
924
Step 11: Testing the Firewall from Both Sides
925
Step 12: Overt Firewall Test from Outside
926
Step 13: Test Covert Channels
927
Step 14: Covert Firewall Test from Outside
928
Step 15: Test HTTP Tunneling
929
Step 16: Test Firewall Specific Vulnerabilities
930
Demo - Vyatta
931
Demo - CORE Impact Targeting Vyatta
932
Document Everything
933
Module 21 Review
934
Module 22 - IDS Penetration Testing
935
IDS Penetration Testing
936
Penetration Testing Roadmap
937
What is an IDS?
938
Demo - IDS Blink and Ossec.net
939
Network IDS
940
Host-based IDS
941
Demo - Blink Personal IPS IDS
942
Application-based IDS
943
Multi-Layer Intrusion Detection Systems
944
Multi-Layer Intrusion Detection System Benefits
945
Wireless Intrusion Detection Systems (WIDS)
946
IDS Testing Tool - Evasion Gateway
947
Common Techniques Used to Evade IDS Systems
948
IDS Penetration Testing Steps
949
Steps 1/2: Test for Resource Exhaustion/ IDS by Sending ARP Flood
950
Steps 3/4: Test the IDS by MAC Spoofing/ IP Spoofing
951
Steps 5/6: Test by Sending a Packet to the Broadcast Address/Inconsistent Packets
952
Steps 7/8: Test IP Packet Fragmentation/Duplicate Fragments
953
Steps 9/10: Test for Overlapping Fragments/Ping of Death
954
Steps 11/12: Test for Odd Sized Packets/TTL Evasion
955
Steps 13/14: Test by Sending a Packet to Port 0/UDP Checksum
956
Steps 15/16: Test for TCP Retransmissions/ TCP Flag Manipulation
957
The TCP Header looks like this:
958
Step 17: Test TCP Flags
959
Steps 18/19: Test the IDS by Sending SYN Floods/ Sequence Number Prediction
960
Step 20: Test for Backscatter
961
Steps 21/22: Test the IDS with ICMP Packets/ IDS Using Covert Channels
962
Step 23: Test Using TCPReplay
963
Step 24: Test Using TCPOpera
964
Step 26: Test the IDS Using URL Encoding
965
Step 27: Test the IDS Using Double Slashes
966
Step 28: Test the IDS for Reverse Traversal
967
Step 29: Test for Self Reference Directories
968
Step 31: Test for IDS Parameter Hiding
969
Step 32: Test for HTTP-Misformatting
970
Step 33: Test for Long URLs
971
Step 34: Test for DoS/Win Directory Syntax
972
Step 35: Test for Null Method Processing
973
Step 36: Test for Case Sensitivity
974
Step 37: Test Session Splicing
975
Module 22 Review
976
Module 23 - Wireless Network Penetration Testing
977
Wireless Network Penetration Testing
978
Penetration Testing Roadmap
979
Wireless Security Threats
980
Wireless Assessment
981
Attempt Wireless Monitoring
982
Wireless Vulnerability Testing
983
Wireless Penetration Testing Steps
984
Demo - inSSIDer
985
Demo - Wi-Spy Spectrum Analyzer
986
Demo - Tips Resources
987
Module 23 Review
988
Module 24 - Denial of Service Penetration Testing
989
Denial of Service Penetration Testing
990
How Does a Denial of Service Attack Work?
991
Distributed Denial of Service Attack
992
Warning
993
How to Conduct Denial of Service Attack Penetration Testing?
994
Demo - Ping of Death and Nemesy
995
Module 24 Review
996
Module 25 - Password Cracking Penetration Testing
997
Password Cracking Penetration Testing
998
Passwords
999
Common Password Vulnerabilities
1000
Password Cracking Techniques
1001
Types of Password Cracking Attacks
1002
Demo - Cain and Abel Dictionary Attack
1003
Demo - Cracking your Local XP 64-bit Password with Ophcrack
1004
Demo - Cracking the Hash Imported into Cain and Abel
1005
Demo - Rainbow Table Cracking
1006
Steps in Password Cracking Penetration Testing
1007
Step 5: Attempt to Guess Passwords
1008
Demo - Removing a PDF Password
1009
Module 25 Review
1010
Module 26 - Social Engineering Penetration Testing
1011
Social Engineering Penetration Testing
1012
What is Social Engineering?
1013
Requirements of Social Engineering
1014
Steps in Conducting Social Engineering Penetration Test
1015
Before you Start
1016
Dress Like a Businessman
1017
Step 1: Attempt Social Engineering Techniques Using Phone
1018
Step 2: Attempt Social Engineering by Vishing
1019
Step 3: Attempt Social Engineering by Telephone
1020
Step 4: Attempt Social Engineering Using Email
1021
Demo - Hotmail Social Engineering
1022
Step 10: Attempt Social Engineering by Desktop Information
1023
Step 12: Attempt Social Engineering Using Websites
1024
Module 26 Review
1025
Module 27 - Stolen Laptops, PDAs, and Cell Phones Penetration Testing
1026
Stolen Laptops, PDAs, and Cell Phones Penetration Testing
1027
Penetration Testing Roadmap
1028
Stolen Laptop Testing
1029
Laptop Theft
1030
Demo - Darik's Boot and Nuke
1031
Penetration Testing Steps
1032
Step 1: Identify Sensitive Data in the Devices
1033
Look for Personal Information in the Stolen Laptop
1034
Step 2: Look for Passwords
1035
Step 3: Look for Company Infrastructure or Finance Documents
1036
Step 4: Extract the Address Book and Phone Numbers
1037
Step 5: Extract Schedules and Appointments
1038
Step 6: Extract Applications Installed on these Devices
1039
Step 7: Extract Email Messages from these Devices
1040
Step 8: Gain Access to Server Resources by Using Information you Extracted
1041
Step 9: Attempt Social Engineering with the Extracted Information
1042
Check for BIOS Password
1043
Look into the Encrypted File
1044
Check Cookies in Web Browsers
1045
Install Software
1046
Attempt to Enable Wireless
1047
Module 27 Review
1048
Module 28 - Application Penetration Testing
1049
Application Penetration Testing
1050
Application Testing
1051
What is a Defect?
1052
Defects vs. Failures
1053
Defect Ratio
1054
Requirements and Design Testing
1055
Web Applications Penetration Testing
1056
What is a Web Application?
1057
Demo - Webgoat Hands-on Web Testing
1058
Demo - Foundstone Overview Hacme Bank Weak Apps
1059
Web Application Penetration Testing Steps
1060
Step 1: Fingerprinting the Web Application Environment
1061
Step 2: Investigate the Output from HEAD and OPTIONS Http Requests
1062
Step 3: Investigate the Format and Wording of 404/Other Error Pages
1063
Step 4: Test for Recognized File Types/Extensions/Directories
1064
Step 5: Examine Source of Available Pages
1065
Step 6: Manipulate Inputs in Order to Elicit a scripting Error
1066
Step 7: Test Inner Working of a Web Application
1067
Step 8: Test Database Connectivity
1068
Step 9: Test the Application Code
1069
Random Numbers vs. Unique Numbers
1070
Step 10: Testing the Use of GET and POST in Web Application
1071
Step 11: Test for Parameter-Tampering Attacks on Website
1072
Step 12: Test for URL Manipulation
1073
Step 13: Test for Cross Site scripting
1074
Step 14: Test for Hidden Fields
1075
Step 15: Test Cookie Attacks
1076
Step 16: Test for Buffer Overflows
1077
Step 17: Test for Bad Data
1078
Step 18: Test Client-Side scripting
1079
Step 19: Test for Known Vulnerabilities
1080
Step 20: Test for Race Conditions
1081
Step 21: Test with User Protection via Browser Settings
1082
Step 22: Test for Command Execution Vulnerability
1083
Step 23: Test for SQL Injection Attacks
1084
Step 24: Test for Blind SQL Injection
1085
Step 25: Test for Session Fixation Attack
1086
Step 26: Test for Session Hijacking
1087
Step 27: Test for XPath Injection Attack
1088
Step 28: Test for Server Side Include Injection Attack
1089
Step 29: Test for Logic Flaws
1090
Step 30: Test for Binary Attacks
1091
Step 31: Test for XML Structural
1092
Step 32: Test for XML Content-level
1093
Step 33: Test for WS HTTP GET Parameters/REST Attacks
1094
Step 34: Test for Malicious SOAP Attachments
1095
Step 35: Test for WS Replay
1096
Testing Tools
1097
KSES/ Mieliekoek.pl
1098
Webgoat
1099
AppScan
1100
URL Scan
1101
Demo - Hacme Bank Scan using N-Stalker
1102
Demo - Hacme Bank Scan Core Web Testing
1103
Module 28 Review
1104
Module 29 - Physical Security Penetration Testing
1105
Physical Security Penetration Testing
1106
Physical Attacks
1107
Steps in Conducting Physical Security Penetration Testing
1108
Demo - Bump Key Animation
1109
Step 1: Map the Possible Entrances
1110
Step 2: Map the Physical Perimeter
1111
Step 3: Penetrate Locks Used on the Gates, Doors, and Closets
1112
Step 4: Observing From a Distance
1113
Step 5: Penetrate Server Rooms, Cabling, and Wires
1114
Step 6: Attempt Lock Picking Techniques
1115
Step 7: Fire Detection Systems
1116
Step 8: Air Conditioning Systems
1117
Step 9: Electromagnetic Interception
1118
Check for the Following
1119
Step 10: Test if the Company has a Physical Security Policy
1120
Step 11: Physical Assets
1121
Step 12: Risk Test
1122
Step 13: Test if any Valuable Paper Document is Kept at the Facility
1123
Step 14: Check how these Documents are Protected
1124
Step 15: Employee Access
1125
Step 16: Test for Radio Frequency ID (RFID)
1126
Step 17: Physical Access to Facilities
1127
Step 18: Documented Process
1128
Step 19: Test People in the Facility
1129
Step 20: Who is Authorized?
1130
Step 21: Test Fire Doors
1131
Step 22: Check for Active Network Jacks in Meeting Rooms
1132
Step 23: Check for Active Network Jacks in Company Lobby
1133
Step 24: Check for Sensitive Information Lying around Meeting Rooms
1134
Step 25: Check for Receptionist/Guard Leaving Lobby
1135
Step 26: Check for Accessible Printers at the Lobby – Print Test Page
1136
Step 27: Obtain Phone/Personnel Listing from the Lobby Receptionist
1137
Step 28: Listen to Employee Conversation in Communal Areas/Cafeteria
1138
Step 29: Can you Enter the Ceiling Space and Enter Secure Rooms
1139
Step 30: Check Windows/Doors for Visible Alarm Senses
1140
Step 31: Check Visible Areas for Sensitive Information
1141
Step 32: Try to Shoulder Surf Users Logging on
1142
Step 33: Try to Videotape Users Logging on
1143
Steps 34 and 35
1144
Step 36: Intercept and Analyze Guard Communication
1145
Step 37: Attempt Piggybacking on Guarded Doors
1146
Step 38: Attempt to Use Fake ID to Gain Access
1147
Step 39: Test “ After Office Hours” Entry Methods
1148
Step 40: Identify all Unguarded Entry Points
1149
Step 43: Attempt to Bypass Sensors Configured on Doors and Windows
1150
Step 44: Attempt Dumpster Diving Outside the Company Trash Area
1151
Step 45: Use Binoculars from Outside the Building and See if you can View What is Going On Inside
1152
Step 46: Use Active High Frequency Voice Sensors to Hear Private Conversation among Company Staff
1153
Step 47: Dress as a FedEx/UPS Employee and Try to Gain Access to the Building
1154
Document Everything
1155
Module 29 Review
1156
Module 30 - Database Penetration Testing
1157
Database Penetration Testing
1158
List of Steps
1159
Demo - NTOSpider
1160
Step 1: Scan for Default Ports Used by the Database
1161
Step 2: Scan for Non-Default Ports Used by the Database
1162
Step 3: Identify the Instance Names Used by the Database
1163
Step 4: Identify the Version Numbers Used by the Database
1164
Step 5: Attempt to Brute-Force Password Hashes from the Database
1165
Step 6: Sniff Database Related Traffic on the Local Wire
1166
Step 7: Microsoft SQL Server Testing
1167
Step 7.1: Test for Direct Access Interrogation
1168
Step 7.2: Scan for Microsoft SQL Server Ports ( TCP/UDP 1433)
1169
Step 7.3: Test for SQL Server Resolution Service (SSRS)
1170
Step 7.4: Test for Buffer Overflow in pwdencrypt() Function
1171
Step 7.5: Test for Heap/Stack Buffer Overflow in SSRS
1172
Step 7.6: Test for Buffer Overflows in Extended Stored Procedures
1173
Step 7.7: Test for Service Account Registry Key
1174
Step 7.8: Test the Stored Procedure to Run Web Tasks
1175
Step 7.9: Exploit SQL Injection Attack
1176
Step 7.10: Blind SQL Injection
1177
Demo - SQL Injection with Lee Lawson
1178
Step 7.11: Google Hacks
1179
Step 7.12: Attempt Direct-exploit Attacks
1180
Step 7.13: Try to Retrieve Server Account List
1181
Step 7.14: Using OSQL Test for Default/Common Passwords
1182
Step 7.15: Try to Retrieve Sysxlogins Table
1183
Try to Retrieve Sysxlogins Table Views
1184
SQL Server System Tables
1185
Step 7.16: Brute-force SA Account
1186
Step 8: Oracle Server Testing
1187
Port Scanning Basic Techniques
1188
Step 8.2: Check the Status of TNS Listener Running at Oracle Server
1189
Listener Modes
1190
Step 8.3: Try to Login Using Default Account Passwords
1191
Step 8.4: Try to Enumerate SIDs
1192
Step 8.5: Use SQL Plus to Enumerate System Tables
1193
SQL PLUS: Screenshot
1194
Step 9: MySQL Server Database Testing
1195
Step 9.2: Extract the Version of Database being Used
1196
Step 9.3: Try to Login Using Default/Common Passwords
1197
Step 9.4: Brute-force Accounts Using Dictionary Attack
1198
Dictionary Attack Tools
1199
Dictionary Attack Tool: SQLdict
1200
Step 9.5: Extract System and User Tables from the Database
1201
Demo - CORE Impact Webgoat Information Gathering
1202
Demo - CORE Impact Webgoat SQL Numeric Injection
1203
Demo - Hacme Bank Testing with Wikto
1204
Module 30 Review
1205
Module 31 - VoIP Penetration Testing
1206
VoIP Penetration Testing
1207
Penetration Testing Roadmap
1208
Vulnerability Assessment
1209
VoIP Risks and Vulnerabilities
1210
VoIP Security Threat
1211
VoIP Penetration Testing Steps
1212
Demo - VoIP Overview Testing
1213
Step 1: Test for Eavesdropping
1214
Step 2: Test for Flooding and Logic Attacks
1215
Step 3: Test for Denial of Service (DoS) Attack
1216
Step 4: Test for Call Hijacking & Redirection Attack
1217
Step 5: Test for ICMP Ping Sweeps
1218
Step 6: Test for ARP Pings
1219
Step 7: Test for TCP Ping Scans
1220
Step 8: Test for SNMP Sweeps
1221
Step 9: Test for Port Scanning and Service Discovery
1222
Step 10: Test for Host/Device Identification
1223
Step 11: Test for Banner Grabbing
1224
Step 12: Test for SIP User/Extension Enumeration
1225
Step 13: Test for Automated OPTIONS Scanning with sipsak
1226
Step 14: Test for Automated REGISTER, INVITE, and OPTIONS Scanning with SIPSCAN against SIP Server
1227
Step 15: Test for Enumerating TFTP Servers
1228
Step 16: Test for SNMP Enumeration
1229
Step 17: Test for Sniffing TFTP Configuration File Transfers
1230
Step 18: Test for Number Harvesting and Call Pattern Tracking
1231
VoIP Security Tools
1232
AuthTool
1233
VoIPong
1234
Demo - VoIP Interception with Cain and Abel
1235
VoIPong: Screenshots
1236
Vomit
1237
PSIPDump
1238
Netdude
1239
Netdude: Features
1240
Oreka
1241
rtpBreak
1242
SNScan
1243
Smap
1244
Example: Locating Devices
1245
Example: Fingerprinting Devices
1246
Example: Learning Mode
1247
SIPScan
1248
Scanning SIP Phones
1249
SIPScan: Screenshot
1250
SIPcrack
1251
VoIPaudit
1252
Sipsak
1253
SIPp
1254
SipBomber
1255
Spitter
1256
VoIP Fuzzing Tools
1257
VoIP Signaling Manipulation Tools
1258
VoIP Media Manipulation Tools
1259
Module 31 Review
1260
Module 32 - VPN Penetration Testing
1261
VPN Penetration Testing
1262
Virtual Private Network (VPN)
1263
VPN Penetration Testing Steps
1264
Demo - VPN Testing
1265
Step 1.1 Scanning: 500 UDP IPSEC
1266
Step 1.2 Scanning: 1723 TCP PPTP
1267
Step 1.3 Scanning: 443 TCP/SSL
1268
Step 1.4 Scanning: nmap -sU -P0 -p 500
1269
Step 1.5 Scanning: Ipsecscan xxx.xxx.xxx.xxx-255
1270
Step 2: Fingerprinting
1271
Step 2.1: Get the IKE Handshake
1272
Step 2.2: UDP Backoff Fingerprinting
1273
Step 2.3: Vendor ID Fingerprinting
1274
Step 2.4: Check for IKE Aggressive Mode
1275
Step 3.1: PSK Crack: ikeprobe xxx.xxx.xxx.xxx-255
1276
Step 3.2 PSK Crack: Sniff for Responses with C&A or IKECrack
1277
Step 4: Test for Default User Accounts
1278
Step 4.1: Check for Unencrypted Username in a File or the Registry
1279
Check for Unencrypted Username in a File or the Registry: Screenshot
1280
Step 4.2: Test for Plain-Text Password
1281
Step 5: Test for SSL VPN
1282
Tool: IKE-scan
1283
IKE-scan: Screenshot
1284
Tool: IKEProbe
1285
Tool: VPNmonitor
1286
Tool: IKECrack
1287
Module 32 Review
1288
Module 33 - War Dialing
1289
War Dialing
1290
War Dialing Techniques
1291
Why Conduct a War Dialing Pentest?
1292
Pre-Requisites for War Dialing Penetration Testing
1293
Software Selection for War Dialing
1294
Guidelines for Configuring Different War Dialing Software
1295
Recommendations for Establishing an Effective War Dialing Process
1296
Interpreting War Dialing Results
1297
List of War Dialing Tools
1298
Demo - New War Dialing Tool: WarVOX
1299
PhoneSweep
1300
THC Scan
1301
ToneLoc
1302
ModemScan - www.wardial.net
1303
War Dialing Countermeasures SandTrap Tool
1304
Module 33 Review
1305
Module 34 - Virus and Trojan Detection
1306
Virus and Trojan Detection
1307
Steps for Detecting Trojans and Viruses
1308
Step 1: Use netstat -a to Detect Trojans Connections
1309
Step 2: Check Windows Task Manager
1310
Step 3: Check Whether Scanning Programs are Enabled
1311
Step 3.1: Perform Scanning for Suspicious Running Processes
1312
Step 3.2: Perform Scanning for Suspicious Registry Entries
1313
Step 3.3: Check for Suspicious Open Ports
1314
Step 3.4: Check Whether Suspicious Network Activities are Present
1315
Step 3.5: Use HijackThis to Scan for Spyware
1316
Step 4: Check Whether Anti-Virus and Anti-Trojan Programs are Working
1317
Step 5: Detection of a Boot-Sector Virus
1318
Spyware Detectors
1319
Demo - Beast Trojan
1320
Anti-Trojans
1321
Anti-Virus Software
1322
Module 34 Review
1323
Module 35 - Log Management Penetration Testing
1324
Log Management Penetration Testing
1325
Need for Log Management
1326
Challenges in Log Management
1327
Steps for Log Management Penetration Testing
1328
Step 1: Scan for Log Files
1329
Step 2: Try to Flood Syslog Servers with Bogus Log Data
1330
Step 3: Try Malicious Syslog Message Attack (Buffer Overflow)
1331
Step 4: Perform Man-in-the-Middle Attack
1332
Step 5: Check Whether the Logs are Encrypted
1333
Step 6: Check Whether Arbitrary Data Can be Injected Remotely into Microsoft ISA Server Log File
1334
Step 7: Perform DoS Attack Against Check Point FW-1 Syslog Daemon (Only for CheckPoint Firewall)
1335
Step 8: Send Syslog Messages Containing Escape Sequences to Syslog Daemon of Check Point FW-1 NG FP3
1336
Checklist For Secure Log Management
1337
Module 35 Review
1338
Module 36 - File Integrity Checking
1339
File Integrity Checking
1340
File Integrity
1341
Integrity Checking Techniques
1342
Demo - File Integrity Checkers
1343
Steps for Checking File Integrity
1344
Step 1: Check While you Unzip the File
1345
Step 2: Check for CRC Value Integrity Checking
1346
CRC Checking in Windows
1347
Step 3: Check for Hash Value Integrity Checking
1348
Step 3.1: Get the File and Previously Calculated Hash Value for the File
1349
Step 3.2: Generate a New Hash Value for the File
1350
Step 3.3: Match the Old and New Hash Values
1351
File Integrity Checking Tools
1352
Module 36 Review
1353
Module 37 - Bluetooth and Hand Held Device Penetration Testing
1354
Bluetooth and Hand Held Device Penetration Testing
1355
Jailbreaking an iPhone
1356
Steps for iPhone Penetration Testing
1357
Demo - Jailbreak
1358
Demo - iPod Custom Apps
1359
Step 1: Jailbreak the iPhone
1360
Jailbreaking Using PwnageTool or QuickPwn
1361
Jailbreaking Using QuickPwn
1362
Step-by-Step Guide to Jailbreak iPhone 3G and Preserve Baseband using PwnageTool
1363
Step 2: Unlock the iPhone
1364
Step 4: Hack iPhone using Metasploit
1365
Step 5: Check for Access Point with Same Name and Encryption Type
1366
Step 6: Check Whether Malformed Data Can be Sent to the Device
1367
Step 7: Check Whether Basic Memory Mapping Information Can be Extracted
1368
Vulnerabilities in BlackBerry
1369
Steps for Penetration Testing
1370
Step 1: Try Blackjacking on BlackBerry
1371
Step 2: Try to Attack by Sending Malformed TIFF Image Files
1372
PDA Attacks
1373
Steps for Penetration Testing 2
1374
Step 1: Check Whether Passwords can be Cracked
1375
Step 2: Try for ActiveSync Attacks
1376
Step 3: Check Whether the IR Port is Enabled
1377
Step 4: Check Whether Encrypted Data can be Decrypted
1378
Bluetooth: Introduction
1379
Different Attacks in Bluetooth Devices
1380
Steps for Penetration Testing in Bluetooth
1381
Step 1: Check Whether the PIN Can be Cracked
1382
Step 2: Try to Perform a Blueprinting Attack
1383
Step 3: Check Whether you are able to Extract the SDP Profiles
1384
Step 4: Try Pairing Code Attacks
1385
Step 5: Try a Man-in-the-Middle Attack
1386
Step 6: Try a BlueJacking Attack
1387
Step 7: Try a BTKeylogging Attack
1388
Step 8: Try Bluesmacking -The Ping of Death
1389
Step 9: Try a BlueSnarfing Attack
1390
Try a BlueSnarfing Attack
1391
Step 10: Try a BlueBug Attack
1392
Step 11: Try BlueSpam
1393
Module 37 Review
1394
Module 38 - Telecommunication and Broadband Communication Penetration Testing
1395
Telecommunication and Broadband Communication Penetration Testing
1396
Broadband Communication
1397
Risk in Broadband Communication
1398
Steps for Broadband Communication Penetration Testing
1399
Step 1: Check Whether the Firewall Device is Installed on Network
1400
Step 1.1: Check Whether Personal and Hardware Firewalls are Installed
1401
Step 1.2: Check Whether These Firewalls Prevent Intruders or Detect Any Rogue Software
1402
Step 1.3: Check Whether the Logging is Enabled on the Firewall
1403
Step 1.4: Check Whether the Firewall is in Stealth Mode
1404
Step 2: Check Whether Web Browsers are Properly Configured
1405
Step 2.1: Check Whether the Browser has Default Configuration
1406
Step 2.2: Check for the Browser Plugins
1407
Step 2.3: Check Whether Active Code is Enabled
1408
Step 2.4: Check Whether the Browser Version is Updated
1409
Step 2.5: Check Whether the Cookies are Enabled
1410
Step 2.6: Check Whether the scripting Languages are Enabled
1411
Step 3: Check for Operating System Configuration Options
1412
Step 3.1: Check Whether Operating System and Application Software are Updated
1413
Step 3.2: Check Whether the File and Printer Sharing Option is Enabled
1414
Step 3.3: Check Whether the Anti-Virus Programs are Enabled
1415
Step 3.4: Check the Configuration of Anti-Virus Program
1416
Step 3.5: Check Whether Anti-Spyware is Enabled
1417
Step 4: Check for Wireless and other Home Networking Technologies
1418
Step 4.1: Check for VPN Policy Configurations
1419
Step 4.2: Try for Wiretapping
1420
Step 4.3: Try to Perform War Driving
1421
Step 4.4: Check Whether the Wireless Base Station is at Default Configuration
1422
Step 4.5: Check Whether WEP is Implemented
1423
Step 4.6: Try to Crack the WEP Key
1424
Step 4.7: Try to Crack the SSID Password
1425
Step 4.8: Check Whether the Simple Network Management Protocol (SNMP) is Enabled
1426
Guidelines for Securing Telecommuting and Home Networking Resources
1427
Module 38 Review
1428
Module 39 - Email Security Penetration Testing
1429
Email Security Penetration Testing
1430
Introduction to Email Security
1431
Pre-Requisite For Email Penetration Testing
1432
Demo - Hacking Email Accounts
1433
Steps for Email Penetration Testing
1434
Step 1: Try to Access Email ID and Password
1435
Step 2: Check Whether Anti-Phishing Software is Enabled
1436
Step 3: Check Whether Anti-Spamming Tools are Enabled
1437
Step 4: Try to Perform Email Bombing
1438
Step 5: Perform CLSID Extension Vulnerability Test
1439
Step 6: Perform VBS Attachment Vulnerability Test
1440
Step 7: Perform Double File Extension Vulnerability Test
1441
Step 8: Perform Long Filename Vulnerability Test
1442
Step 9: Perform ActiveX Vulnerability Test
1443
Step 10: Perform Iframe Remote Vulnerability Test
1444
Step 11: Perform MIME Header Vulnerability Test
1445
Step 12: Perform Malformed File Extension Vulnerability Test
1446
Step 13: Perform Access Exploit Vulnerability Test
1447
Step 14: Perform Fragmented Message Vulnerability Test
1448
Step 15: Perform Long Subject Attachment Checking Test
1449
List of Anti-Phishing Tools
1450
PhishTank SiteChecker
1451
PhishTank SiteChecker: Screenshot
1452
NetCraft
1453
GFI MailEssentials
1454
SpoofGuard
1455
List of Anti-Spamming Tools
1456
AEVITA Stop SPAM Email
1457
SpamExperts Desktop
1458
Spytech SpamAgent
1459
Module 39 Review
1460
Module 40 - Security Patches Penetration Testing
1461
Security Patches Penetration Testing
1462
Patch Management
1463
Patch and Vulnerability Group (PVG)
1464
Countermeasure Testing Steps
1465
Step 1: Check If Organization has a PVG in Place
1466
Step 2: Check Whether the Security Environment is Updated
1467
Step 3: Check Whether Organization uses Automated Patch Management Tools
1468
Step 4: Check the Last Date of Patching
1469
Step 5: Check the Patches on Non-Production Systems
1470
Step 6: Check the Vender Authentication Mechanism
1471
Step 7: Check Whether Downloaded Patches Contain Viruses
1472
Step 8: Check for Dependency of New Patches
1473
Security Checklist for Patch Management
1474
Patch Management Tools
1475
Module 40 Review
1476
Module 41 - Data Leakage Penetration Testing
1477
Data Leakage Penetration Testing
1478
Penetration Testing Roadmap
1479
Data Leakage
1480
Data Leakage Statistics
1481
How Much Security?
1482
How Data Can be Leaked
1483
What to Protect
1484
Steps for Data Leakage
1485
Step 1: Check Physical Availability of USB Devices
1486
Step 2: Check Whether USB Drive is Enabled
1487
Step 3: Try to Enable USB
1488
Step 4: Check Whether USB Asked for Password
1489
Step 5: Check Whether Bluetooth is Enabled
1490
Step 6: Check if the Firewire is Enabled
1491
Step 7: Check if FTP Ports 21 and 22 are Enabled
1492
Step 8: Check Whether any Memory Slot is Available and Enabled in Systems
1493
Step 9: Check Whether Employees are Using Camera Devices within Restricted Areas
1494
Step 10: Check Whether Systems have Any Camera Driver Installed
1495
Step 11: Check Whether Anti-Spyware and Anti-Trojans are Enabled
1496
Step 12: Check Whether Encrypted Data Can be Decrypted
1497
Step 13: Check if the Internal Hardware Components are Locked
1498
Step 14: Check Whether Size of Mail and Mail Attachments is Restricted
1499
Data Privacy and Protection Acts
1500
Data Protection Tools
1501
Module 41 Review
1502
Module 42 - Penetration Testing Deliverables and Conclusion
1503
Penetration Testing Deliverables and Conclusion
1504
Destroy the Report
1505
Sign-Off Document
1506
Module 42 Review
1507
Module 43 - Penetration Testing Report and Documentation Writing
1508
Penetration Testing Report and Documentation Writing
1509
Penetration Testing Report
1510
Documentation Writing
1511
Table of Contents
1512
Summary of Execution
1513
Summary of Weaknesses
1514
Scope of the Project
1515
Result Analysis
1516
Recommendations
1517
Appendices
1518
Test Reports on Network
1519
Summary Recommendations
1520
Exploited Vulnerabilities
1521
Payment Card Industry (PCI) Report
1522
Client-Side Test Reports
1523
Client-Side Penetration Test Report
1524
User Report
1525
Test Reports on Web Applications
1526
Web Application Testing Report
1527
Detailed Findings
1528
Detailed Results
1529
Strategic and Tactical Directives
1530
Writing the Final Report
1531
Creating the Final Report
1532
Report Format
1533
Delivery
1534
Report Retention
1535
Module 43 Review
1536
Module 44 - Penetration Testing Report Analysis
1537
Penetration Testing Report Analysis
1538
Report on Penetration Testing
1539
Pen-Test Team Meeting
1540
Research Analysis
1541
Pen-Test Findings
1542
Rating Findings
1543
Demo - Practical Threat Analysis Tool
1544
Example of Finding- I
1545
Example of Finding- II
1546
Analyze
1547
Module 44 Review
1548
Module 45 - Post Testing Actions
1549
Post Testing Actions
1550
Prioritize Recommendations
1551
Develop Action Plan
1552
Create Process for Minimizing Misconfiguration Chances
1553
Updates and Patches
1554
Capture Lessons Learned and Best Practices
1555
Create Security Policies
1556
Conduct Training
1557
Take Social Engineering Class
1558
Destroy the Pen-Test Report
1559
Module 45 Review
1560
Module 46 - Ethics of a Licensed Penetration Tester
1561
Ethics of a Licensed Penetration Tester
1562
What Makes a Licensed Penetration Tester?
1563
Modus Operandi
1564
Evolving as a Licensed Penetration Tester
1565
Licensed Penetration Tester Dress Code
1566
LPT Audited Logos
1567
Example: LPT Audited Logos
1568
Module 46 Review
1569
Module 47 - Standards and Compliance
1570
Customers and Legal Agreements
1571
Module 47 Review
1572
Course Closure