ipentest

3-day infosec training syllabus - VCIPL

Oct 16th, 2013
1,613
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
  1. This is the training I (Kiran Karnad) used to provide at the 3-day infosec training workshop when I was working at VCIPL
  2.  
  3. Module 00 - Student Introduction
  4. Student Introduction
  5. Certification
  6. ECSA Track
  7. LPT Track
  8. What next after ECSA Training?
  9. Demo - Overview of Available Resources
  10. Lab Sessions
  11. Student Introduction Review
  12. Module 01 - The Need for Security Analysis
  13. The Need for Security Analysis
  14. What are we Concerned About?
  15. So What are you Trying to Protect?
  16. Why are Intrusions so Often Successful?
  17. What are the Greatest Challenges?
  18. Environmental Complexity
  19. New Technologies
  20. New Threats and Exploits
  21. Demo - Keep Updated with Research
  22. Limited Focus
  23. Limited Expertise
  24. Tool: Data Loss Cost Calculator
  25. Demo - Tech//404 Data Loss Calculator
  26. In Order to Ensure…
  27. Authentication
  28. Authorization
  29. Confidentiality
  30. Integrity
  31. Availability
  32. Non-Repudiation
  33. We Must be Diligent
  34. Threat Agents
  35. Assessment Questions
  36. How Much Security is Enough?
  37. Risk
  38. Simplifying Risk
  39. Risk Analysis
  40. Risk Assessment Answers Seven Questions:
  41. Steps of Risk Assessment
  42. Demo - Risk Assessment
  43. Demo - CIO-view Self-assessment
  44. Risk Assessment Values
  45. Demo - Quantitative Threat Analysis
  46. Information Security Awareness
  47. Security Policies
  48. Security Policy Basics
  49. Demo - Policy Templates
  50. Types of Policies
  51. Promiscuous Policy
  52. Permissive Policy
  53. Prudent Policy
  54. Paranoid Policy
  55. Acceptable-Use Policy
  56. User-Account Policy
  57. Remote-Access Policy
  58. Information-Protection Policy
  59. Firewall-Management Policy
  60. Special-Access Policy
  61. Network-Connection Policy
  62. Business-Partner Policy
  63. Data Classification Policies
  64. Intrusion Detection Policies
  65. Virus Prevention Policies
  66. Laptop Security Policy
  67. Personal Security Policy
  68. Cryptography Policy
  69. Fair and Accurate Credit Transactions Act of 2003 (FACTA)
  70. Other Important Policies
  71. Policy Statements
  72. Basic Document Set of Information Security Policies
  73. ISO 17799
  74. Domains of ISO 17799
  75. No Simple Solutions
  76. U.S. Legislation
  77. California SB 1386
  78. Sarbanes-Oxley 2002
  79. Gramm-Leach-Bliley Act (GLBA)
  80. Health Insurance Portability and Accountability Act (HIPAA)
  81. USA Patriot Act 2001
  82. U.K. Legislation
  83. How Does This Law Affect a Security Officer?
  84. The Data Protection Act 1998
  85. The Human Rights Act 1998
  86. Interception of Communications
  87. The Freedom of Information Act 2000
  88. The Audit Investigation and Community Enterprise Act 2005
  89. Demo - Vmware Overview
  90. Demo - Opening an Existing XP VMware System
  91. Demo - Opening VM Appliance
  92. Demo - Installing a New VM System
  93. Demo - Booting XP from Backtrack ISO
  94. Module 1 Review
  95. Module 02 - Advanced Googling
  96. Advanced Googling
  97. Site Operator
  98. intitle:index.of
  99. Demo - Default Pages: tsweb
  100. error | warning
  101. Demo - Google as a Proxy
  102. login | logon
  103. username | userid | employee.ID | “your username is”
  104. password | passcode | “your password is”
  105. admin | administrator
  106. –ext:html –ext:htm –ext:shtml –ext:asp –ext:php
  107. inurl:temp | inurl:tmp | inurl:backup | inurl:bak
  108. Google Advanced Search Form
  109. Categorization of the Operators
  110. allinanchor:
  111. allintext:
  112. Demo - Google Locating Live Cams
  113. Locating Public Exploit Sites
  114. Locating Exploits via Common Code Strings
  115. Locating Vulnerable Targets
  116. Locating Targets via Demonstration Pages
  117. Demo - Google Hack HoneyPot
  118. Demo - Goolag and Wikto
  119. Demo - Wikto Results and Google Guide
  120. Module 2 Review
  121. Module 03 - TCP/IP Packet Analysis
  122. TCP/IP Packet Analysis
  123. TCP/IP Model
  124. Demo - TCP/IP Movie Recommendation
  125. Application Layer
  126. Transport Layer
  127. Internet Layer
  128. Network Access Layer
  129. Comparing OSI and TCP/IP
  130. Demo - Engage Packet Builder
  131. TCP
  132. TCP Header
  133. IP Header: Protocol Field
  134. UDP
  135. TCP and UDP Port Numbers
  136. Port Numbers
  137. Demo - Warriors of the Net
  138. IANA
  139. Source and Destination Port Numbers
  140. Demo - Techtionary.com Port Numbers
  141. What Makes Each Connection Unique?
  142. Structure of a Packet
  143. TCP Operation
  144. Three-Way Handshake
  145. Demo - Techtionary.com TCP Handshake
  146. Flow Control
  147. Windowing
  148. Windowing and Window Sizes
  149. Simple Windowing
  150. Acknowledgement
  151. Sliding Windows
  152. Sequencing Numbers
  153. Synchronization
  154. Positive Acknowledgment and Retransmission (PAR)
  155. What is Internet Protocol v6 (IPv6)?
  156. Why IPv6?
  157. IPv4/IPv6 Transition Mechanisms
  158. IPv6 Security Issues
  159. Security Flaws in IPv6
  160. IPv6 Infrastructure Security
  161. Ipsec
  162. Firewalls and Packet Filtering
  163. Denial-of-Service (DoS) Attacks
  164. UDP Operation
  165. Internet Control Message Protocol (ICMP)
  166. ICMP Message Delivery
  167. Format of an ICMP Message
  168. Unreachable Networks
  169. Time Exceeded Message
  170. IP Parameter Problem
  171. ICMP Control Messages
  172. ICMP Redirects
  173. Clock Synchronization and Transit Time Estimation
  174. Information Requests and Reply Message Formats
  175. Address Masks
  176. Router Solicitation and Advertisement
  177. Module 3 Review
  178. Module 04 - Advanced Sniffing Techniques
  179. Advanced Sniffing Techniques
  180. Demo - Basic Sniffers
  181. Demo - Packet Capturing with Windows Packetyzer
  182. What is Wireshark?
  183. Wireshark: Filters
  184. Wireshark: Tshark
  185. Wireshark: Tcpdump
  186. Demo - Tcpdump
  187. Protocol Dissection
  188. Steps to Solve GNU/ Linux Server Network Connectivity Issues
  189. Using Wireshark for Network Troubleshooting
  190. Using Wireshark for System Administration
  191. ARP Problems
  192. Demo - Sniffers and ARP
  193. ICMP Echo Request/Reply Header Layout
  194. TCP Flags
  195. Scenario 1: SYN no SYN+ACK
  196. Scenario 2: SYN Immediate Response RST
  197. Scenario 3: SYN SYN+ACK ACK
  198. Tapping into the Network
  199. Using Wireshark for Security Administration
  200. Sniffer Detection
  201. Wireless Sniffing with Wireshark
  202. Frequency
  203. Using Channel Hopping
  204. Interference and Collisions
  205. Recommendations for Sniffing Wireless Traffic
  206. Analyzing Wireless Traffic
  207. IEEE 802.11 Header
  208. Filters
  209. Unencrypted Data Traffic
  210. Identifying Hidden SSIDs
  211. Identifying EAP Authentication Failures
  212. Identifying WEP
  213. Identifying IPsec/VPN
  214. Decrypting Traffic
  215. Scanning
  216. TCP Connect Scan
  217. SYN Scan
  218. XMAS Scan
  219. Null Scan
  220. Remote Access Trojans
  221. Wireshark DNP3 Dissector Infinite Loop Vulnerability
  222. Time Stamps
  223. Time Zones
  224. Packet Reassembling
  225. Checksums
  226. Module 4 Review
  227. Module 05 - Vulnerability Analysis with Nessus
  228. Vulnerability Analysis with Nessus
  229. Nessus
  230. Features of Nessus
  231. Nessus Assessment Process
  232. Demo - Nessus on Windows
  233. Demo - Nessus on Windows Cont'd and GFI LANguard Comparison
  234. False Positives
  235. Examples of False Positives
  236. Identifying False Positives
  237. Suspicious Signs
  238. Demo - Backtrack 4 Nessus Install
  239. Module 5 Review
  240. Module 06 - Advanced Wireless Testing
  241. Advanced Wireless Testing
  242. Wireless Concepts
  243. Demo - Techtionary Website
  244. 802.11 Types
  245. Core Issues with 802.11
  246. What’s the Difference?
  247. Other Types of Wireless
  248. Spread Spectrum Background
  249. Channels
  250. Access Point
  251. Service Set ID
  252. Demo - Linksys-AP Config SSID
  253. Default SSIDs
  254. Chipsets
  255. Wi-Fi Equipment
  256. Expedient Antennas
  257. Vulnerabilities to 802.1x and RADIUS
  258. Security - WEP
  259. Wired Equivalent Privacy (WEP)
  260. Exclusive OR
  261. Encryption Process
  262. Chipping Sequence
  263. WEP Issues
  264. WEP - Authentication Phase
  265. WEP - Shared Key Authentication
  266. WEP - Association Phase
  267. WEP Flaws
  268. WEP Attack
  269. Demo - Authentication Settings
  270. Demo - WEP Set-Up Security
  271. Demo - Cain and Abel WEP Cracking
  272. WPA Interim 802.11 Security
  273. WPA
  274. Demo - Cracking WPA with Cain and Abel
  275. WPA2 (Wi-Fi Protected Access 2)
  276. 802.1X Authentication and EAP
  277. EAP Types
  278. Cisco LEAP
  279. TKIP (Temporal Key Integrity Protocol)
  280. Wireless Networks Testing
  281. Wireless Communications Testing
  282. Report Recommendations
  283. Wireless Attack Countermeasures
  284. Demo - MAC-SSID Security
  285. Wireless Penetration Testing with Windows
  286. War Driving
  287. The Jargon – WarChalking
  288. Wireless: Tools of the Trade
  289. Demo - Kismet in Windows
  290. Demo - Tool: Kismet in Linux
  291. Demo - Vistumbler War Driving and GPS Map Plotting
  292. How Does NetStumbler Work?
  293. “Active” vs. “Passive” WLAN Detection
  294. Disabling the Beacon
  295. Running NetStumbler
  296. Demo - Tool: Netstumbler
  297. AirCrack-ng
  298. AirCrack-ng: How Does it Work?
  299. AirCrack-ng: FMS and Korek Attacks
  300. AirCrack-ng: Notes
  301. Demo - Hacking WEP Encryption
  302. Determining Network Topology: Network View
  303. WarDriving and Wireless Penetration Testing with OS X
  304. Using a GPS
  305. Deauthenticating Clients
  306. StumbVerter
  307. MITM Attack Design
  308. MITM Attack Variables
  309. Hardware for the Attack: Antennas, Amps, and WiFi Cards
  310. Choosing the Right Antenna
  311. Amplifying the Wireless Signal
  312. IP Forwarding and NAT using IPtables
  313. Demo - Jasager fon Router
  314. Module 6 Review
  315. Module 07 - Designing a DMZ
  316. Designing a DMZ
  317. Introduction
  318. DMZ Concepts
  319. DMZ Design Fundamentals
  320. Advanced Design Strategies
  321. Types of Firewall and DMZ Architectures
  322. "Inside vs. Outside" Architecture
  323. "Three-Homed Firewall" DMZ Architecture
  324. Weak Screened Subnet Architecture
  325. Strong Screened Subnet Architecture
  326. Designing a DMZ using IPtables
  327. Designing Windows DMZ
  328. Precautions for DMZ Setup
  329. Demo - Designing DMZs
  330. Advanced Implementation of a Solaris DMZ Server
  331. Solaris DMZ Servers in a Conceptual Highly Available Configuration
  332. Hardening Checklists for DMZ Servers and Solaris
  333. Placement of Wireless Equipment
  334. Access to DMZ and Authentication Considerations
  335. Wireless DMZ Components
  336. WLAN DMZ Security Best Practices
  337. Ethernet Interface Requirements and Configuration
  338. DMZ Router Security Best Practice
  339. Six Ways to Stop Data Leaks
  340. Module 7 Review
  341. Module 08 - Snort Analysis
  342. Snort Analysis
  343. Snort Overview
  344. Modes of Operation
  345. Features of Snort
  346. Configuring Snort
  347. Snort: Variables
  348. Snort: Pre-processors
  349. Snort: Output Plug-ins
  350. Snort: Rules
  351. How Snort Operates
  352. Initializing Snort
  353. Demo - Snort IDS Testing Scanning Tools
  354. Signal Handlers
  355. Parsing the Configuration File
  356. Decoding
  357. Possible Decoders
  358. Pre-processing
  359. Detection
  360. Content Matching
  361. The Stream4 Pre-processor
  362. Inline Functionality
  363. Writing Snort Rules
  364. Snort Rule Header
  365. Snort Rule Header: Actions
  366. Snort Rule Header: Other Fields
  367. IP Address Negation Rule
  368. IP Address Filters
  369. The direction Operator
  370. Rule Options
  371. Activate/Dynamic Rules
  372. Metadata Rule Options: msg
  373. The reference Keyword
  374. The sid/rev Keyword
  375. The classtype Keyword
  376. Payload Detection Rule Options: content
  377. Modifier Keywords
  378. The uricontent Keyword
  379. The fragoffset Keyword
  380. Writing Good Snort Rules
  381. Tool for Writing Snort Rules: IDS Policy Manager
  382. Honeynet Security Console Tool
  383. Key Features
  384. Module 8 Review
  385. Module 09 - Log Analysis
  386. Log Analysis
  387. Logs
  388. Events that Need to be Logged
  389. What to Look Out For in Logs
  390. Automated Log Analysis Approaches
  391. Log Shipping
  392. Syslog
  393. Setting up a Syslog
  394. System Error Logs
  395. Kiwi Syslog Daemon
  396. Configuring Kiwi Syslog to Log to a MS SQL Database
  397. Configuring a Cisco Router for Syslog
  398. Configuring a DLink Router for Syslog
  399. Gathering Log Files from an IIS Web Server
  400. Apache Web Server Log
  401. AWStats Log Analyzer
  402. Cisco Router Logs
  403. Analyzing Netgear Wireless Router Logs
  404. Wireless Traffic Analysis Using Wireshark
  405. Configuring Firewall Logs in Local Windows System
  406. Viewing Local Windows Firewall Log
  407. Viewing Windows Event Log
  408. Collecting & Monitoring UNIX Syslog
  409. iptables
  410. Log Prefixing with iptables
  411. Firewall Log Analysis with grep
  412. SQL Database Log
  413. Using SQL Server to Analyze Web Logs
  414. Analyzing Oracle Logs: The Oracle Metric Log File
  415. ApexSQL Log
  416. Analyzing Solaris System Logs
  417. Demo - Splunk
  418. Module 9 Review
  419. Module 10 - Advanced Exploits and Tools
  420. Advanced Exploits and Tools
  421. Common Vulnerabilities
  422. Buffer Overflows Revisited
  423. Smashing the Stack for Fun and Profit
  424. Smashing the Heap for Fun and Profit
  425. Format Strings for Chaos and Mayhem
  426. The Anatomy of an Exploit
  427. Demo - Fuzzing for Weaknesses
  428. Vulnerable Code
  429. Shellcode
  430. Shellcode Examples
  431. Shellcode (cont’d)
  432. Demo - Stack Function
  433. Delivery Code
  434. Delivery Code: Example
  435. Demo - Compiling Exploits from Source Code
  436. Linux Exploits versus Windows
  437. Windows versus Linux
  438. Tools of the Trade: Debuggers
  439. Tools of the Trade: GDB
  440. Tools of the Trade: Metasploit
  441. Demo - Metasploit Intro
  442. Demo - Metasploit 101
  443. Demo - Metasploit Interactive
  444. Tools of the Trade: Canvas
  445. Lab
  446. Tools of the Trade: CORE Impact
  447. Ways to Use CORE Impact
  448. Microsoft Baseline Security Analyzer (MBSA)
  449. Network Security Analysis Tool (NSAT)
  450. Sunbelt Network Security Inspector (SNSI)
  451. Demo - Saint Exploit of Windows XP
  452. Demo - dcom101 Exploit Autoshovel of Shell
  453. Demo - dcom Exploit Netcat Shovel of Shell and Extracting Hashes
  454. Demo - Backtrack 4 Milw0rm Metasploit Updates
  455. Module 10 Review
  456. Module 11 - Penetration Testing Methodologies
  457. Penetration Testing Methodologies
  458. Demo - dradis Effective Information Sharing
  459. What is Penetration Testing?
  460. Why Penetration Testing?
  461. What Should be Tested?
  462. What Makes a Good Penetration Test?
  463. Common Penetration Testing Techniques
  464. Penetration Testing Process
  465. Scope of Penetration Testing
  466. Blue Teaming/Red Teaming
  467. Types of Penetration Testing
  468. Black-box Penetration Testing
  469. White-box Penetration Testing
  470. Announced Testing/ Unannounced Testing
  471. Grey-box Penetration Testing
  472. Strategies of Penetration Testing
  473. External Penetration Testing
  474. Internal Security Assessment
  475. Application Security Assessment
  476. Types of Application Security Assessment
  477. Network Security Assessment
  478. Wireless/Remote Access Assessment
  479. Telephony Security Assessment
  480. Social Engineering
  481. Penetration Testing Consultants
  482. Required Skills Sets
  483. Hiring a Penetration Tester
  484. Responsibilities of a Penetration Tester
  485. Profile of a Good Penetration Tester
  486. Why Should the Company Hire You?
  487. Companies’ Concerns
  488. Methodology
  489. Demo - NIST Methodology
  490. Demo - PenTest Templates and Methodologies
  491. Penetration Testing Roadmap
  492. Guidelines for Security Checking
  493. Operational Strategies for Security Testing
  494. Security Category of the Information System
  495. Identifying Benefits of Each Test Type
  496. Prioritizing the Systems for Testing
  497. ROI on Penetration Testing
  498. Determining Cost of Each Test Type
  499. Need for a Methodology
  500. Penetration Test vs. Vulnerability Test
  501. Reliance on Checklists and Templates
  502. Phases of Penetration Testing
  503. Pre-Attack Phase
  504. Best Practices
  505. Results that can be Expected
  506. Passive Reconnaissance
  507. Active Reconnaissance
  508. Attack Phase
  509. Activity: Perimeter Testing
  510. Activity: Web Application Testing - I
  511. Activity: Web Application Testing – II
  512. Activity: Wireless Testing
  513. Activity: Acquiring Target
  514. Activity: Escalating Privileges
  515. Activity: Execute, Implant, and Retract
  516. Post-Attack Phase and Activities
  517. Module 11 Review
  518. Module 12 - Customers and Legal Agreements
  519. Customers and Legal Agreements
  520. Why do Organizations Need Pen-Testing?
  521. Initial Stages in Penetration Testing
  522. Understand Customer Requirements
  523. Create a Checklist of Testing Requirements
  524. Penetration Testing ‘Rules of Behavior’
  525. Demo - ISSAF Customers and Legal
  526. Penetration Testing Risks
  527. Penetration Testing by Third Parties
  528. Precautions While Outsourcing Penetration Testing
  529. Legal Consequences
  530. Demo - Computer Crimes and Implications
  531. Get Out of Jail Free Card
  532. Permitted Items in Legal Agreement
  533. Confidentiality and NDA Agreements
  534. Non-Disclosure and Secrecy Agreements (NDA)
  535. The Contract
  536. Liability Issues
  537. Negligence Claim
  538. Plan for the Worst
  539. Drafting Contracts
  540. How Much to Charge?
  541. Module 12 Review
  542. Module 13 - Rules of Engagement
  543. Rules of Engagement
  544. Rules of Engagement (ROE)
  545. Demo - OSSTMM Model
  546. Scope of ROE
  547. Steps for Framing ROE
  548. Clauses in ROE
  549. Demo - ScreenHunter Desktop Capture Tool
  550. Module 13 Review
  551. Module 14 - Penetration Testing Planning and Scheduling
  552. Penetration Testing Planning and Scheduling
  553. Test Plan
  554. Purpose of Test Plan
  555. Building a Penetration Test Plan
  556. Demo - Overview OSSTMM
  557. IEEE STD. 829–1998 SECTION HEADINGS
  558. Test Plan Identifier
  559. Test Deliverables
  560. Penetration Testing Planning Phase
  561. Define the Scope
  562. Project Scope
  563. When to Retest?
  564. Responsibilities
  565. Skills and Knowledge Required
  566. Internal Employees
  567. Penetration Testing Teams
  568. Tiger Team
  569. Building Tiger Team
  570. Questions to Ask Before Hiring Consultants to the Tiger Team
  571. Meeting With the Client
  572. Kickoff Meeting
  573. Penetration Testing Project Plan
  574. Work Breakdown Structure or Task List
  575. Penetration Testing Schedule
  576. Penetration Testing Project Scheduling Tools
  577. Test Plan Checklist
  578. Penetration Testing Hardware/Software Requirements
  579. EC-Council’s Vampire Box
  580. Begin Penetration Testing
  581. Demo - Installing Backtrack 4 into VMWare Environment
  582. Module 14 Review
  583. Module 15 - Customers and Legal Agreements
  584. Pre-Penetration Testing Checklist
  585. Demo - Pentest Checklist
  586. Step 1: Gather Information about Client Organization’s History and Background
  587. Step 2: Visit the Client Organization Premises
  588. Step 3: List the Client Organization’s Penetration Testing Requirements
  589. Step 4: Obtain Penetration Testing Permission from the Company’s Stakeholders
  590. Step 5: Obtain Detailed Proposal of Test and Services that are Proposed to be carried out
  591. Step 6: Identify the Office Space/Location your Team would be Working in for this Project
  592. Step 7: Obtain Temporary Identity Cards from the Organization for the Team who is Involved in the Process
  593. Step 8: Identify who will be Leading the Penetration Testing Project (Chief Penetration Tester)
  594. Step 9: Request from the Client Organization the Previous Penetration Testing/Vulnerability Assessment Reports
  595. Step 10: Prepare Rules of Engagement that Lists the Company’s Core Competencies/ Limitations/ Timescales
  596. Step 11: Hire a Lawyer who Understands IT and can Handle your Penetration Testing Legal Documents
  597. Step 12: Prepare PT Legal Document and get Vetted with your Lawyer
  598. Step 13: Prepare Non Disclosure Agreement (NDA) and have the Client Sign them
  599. Step 14: Obtain (if possible) Liability Insurance from a Local Insurance Firm
  600. Step 15: Identify your Core Competencies/Limitations
  601. Step 16: Allocate a Budget for the Penetration Testing Project ( X amount of $ )
  602. Step 17: Prepare a Tiger Team
  603. Step 18: List the Security Tools that you will be using for the Penetration Testing Project
  604. Step 19: List the Hardware and Software Requirements for the Penetration Testing Project
  605. Step 20: Identify the Clients Security Compliance Requirements
  606. Step 21: List the Servers, Workstations, Desktops and Network Devices that need to be Tested
  607. Step 22: Identify the Type of Testing that would be carried out - Black Box or White Box Testing
  608. Step 23: Identify the Type of Testing that would be carried out - Announced/ Unannounced
  609. Step 24: Identify Local Equipment Required for Pen Test
  610. Step 25: Identify Local Manpower Required for Pen Test
  611. Step 26: List the Contact Details of Personnel from Client Organization who will be in Charge of the Pen Test
  612. Step 27: Obtain the Contact Details of the Key Personnel for Approaching in case of an Emergency
  613. Step 29: List the Tests that will not be carried out at the Client Network
  614. Step 30: Identify the Purpose of the Test you are carrying out at the Client Organization
  615. Step 31: Identify the Network Topology in which the Test would be carried out
  616. Step 32: Obtain Special Permission if Required from Local Law Enforcement Agency
  617. Step 33: List known Waivers/Exemptions
  618. Step 34: List the Contractual Constraints in the Penetration Testing Agreement
  619. Step 35: Identify the Reporting Timescales with the Client Organization
  620. Step 36: Identify the List of Penetration Testers Required for this Project
  621. Step 37: Negotiate per Day/per Hour Fee that you will be Charging for the Penetration Testing Project
  622. Step 38: Draft the Timeline for the Penetration Testing Project
  623. Step 39: Draft a Quotation for the Services that you'll be Providing to the Client Organization
  624. Step 40: Identify how the Final Penetration Testing Report will be Delivered to the Client Organization
  625. Step 41: Identify the Reports to be Delivered After Pen Test
  626. Step 42: Identify the Information Security Administrator who will be helping you in the Penetration Testing
  627. Module 15 Review
  628. Module 16 - Information Gathering
  629. Information Gathering
  630. What is Information Gathering?
  631. Information Gathering Steps
  632. Step 1: Crawl the Website and Mirror the Pages on Your PC
  633. Demo - HTTrack Website Copier
  634. Step 2: Crawl the FTP Site and Mirror the Pages on Your PC
  635. Demo - Wget and Backtrack 4 Live CD
  636. Step 3: Look up Registered Information in the Whois Database
  637. Demo - CentralOps and Domains by Proxy
  638. Demo - Backtrack and Whois
  639. Step 4: List the Products Sold by the Company
  640. Demo - Firecat (Firefox Addons)
  641. Step 5: List the Contact Information, Email Addresses, and Telephone Numbers
  642. Step 6: List the Company’s Distributors
  643. Step 7: List the Company’s Partners
  644. Demo - Email Spider
  645. Step 8: Search the Internet, Newsgroups, Bulletin Boards, Negative Websites for Information about the Company
  646. Demo - Maltego
  647. Step 9: Search for Trade Association Directories
  648. Step 10: Search for Link Popularity of Company Website
  649. Demo - Alexa
  650. Step 11: Compare Price of Product or Service with the Competitor
  651. Step 12: Find the Geographical Location
  652. Demo - Shazou
  653. Use Google Map to Find Geographical Location
  654. Step 13: Search the Internet Archive Pages about the Company
  655. Demo - Archive.org
  656. Step 14: Search Similar or Parallel Domain Name Listings
  657. Demo - ServerSniff TLDs
  658. Step 15: Search Job Posting Sites about the Company
  659. Step 16: Browse Social Network Websites
  660. Demo - Social Networking
  661. Step 17: Write Down Key Employees
  662. Step 18: Investigate Key Persons – Searching in Google, Look up their Resumes and Cross Link Information
  663. Step 19: List Employee Company and Personal Email Address
  664. Step 20: Search for Web Pages Posting Patterns and Revision Numbers
  665. Demo - No Tech Hacking
  666. Step 21: Email the Employee Disguised as Customer Asking for Quotation
  667. Step 22: Visit the Company as Inquirer and Extract Privileged Information
  668. Step 23: Visit the Company Locality
  669. Step 24: Use Web Investigation Tools to Extract Sensitive Data Targeting the Company
  670. Step 25: Use Intelius and Conduct Background Check on Company Key Personnel
  671. Step 26: Search on eBay for Company’s Presence
  672. Step 27: Use the Domain Research Tool to Investigate the Company’s Domain
  673. Step 28: Use the EDGAR Database to Research Company Information
  674. Step 34: Use GHDB and Search for the Company Name
  675. Demo - Summary
  676. Demo - Vmware 64bit Error Fix
  677. Demo - SEAT
  678. Demo - Metagoofil Search
  679. Demo - CORE Impact Email Info Gathering
  680. Module 16 Review
  681. Module 17 - Vulnerability Analysis
  682. Vulnerability Analysis
  683. Why Assess?
  684. Vulnerability Classification
  685. What is Vulnerability Assessment?
  686. Demo - Vulnerability Research Resources
  687. Demo - Nessus 4 Windows Install and Wikto Scan Webgoat
  688. Types of Vulnerability Assessment
  689. Demo - Nessus 3 Webgoat Scan BT4
  690. Demo - Nessus 4 Webgoat Scan
  691. Demo - GFI LANguard
  692. How to Conduct a Vulnerability Assessment
  693. How to Obtain a High Quality Vulnerability Assessment
  694. Vulnerability Assessment Phases
  695. Pre-Assessment Phase
  696. Assessment Phase
  697. Post-Assessment Phase
  698. Vulnerability Analysis Stages
  699. Comparing Approaches to Vulnerability Assessment
  700. Characteristics of a Good Vulnerability Assessment Solution
  701. Vulnerability Assessment Considerations
  702. Vulnerability Assessment Reports
  703. Demo - Nessus 3 BT Exporting NBE Report
  704. Vulnerability Report Model
  705. Timeline
  706. Types of Vulnerability Assessment Tools
  707. Choosing a Vulnerability Assessment Tool
  708. Vulnerability Assessment Tools Best Practices
  709. Vulnerability Assessment Tools
  710. Demo - Retina Security Scanner
  711. Other Vulnerability Tools
  712. Report
  713. Vulnerability Assessment Reports
  714. Automated Scanning Server Reports
  715. Periodic Vulnerability Scanning Report
  716. Module 17 Review
  717. Module 18 - External Penetration Testing
  718. External Penetration Testing
  719. Penetration Testing Roadmap
  720. External Intrusion Test and Analysis
  721. How is it Done?
  722. Client Benefits
  723. External Penetration Testing
  724. Steps – Conduct External Penetration Testing
  725. Demo - CORE Impact Network Vulnerability Test
  726. Demo - Samaurai Live CD Intro
  727. Step 1: Inventory Company’s External Infrastructure
  728. Step 2: Create Topological Map of the Network
  729. Step 3: Identify the IP Address
  730. Step 4: Locate the Traffic Route that Goes to the Web Servers
  731. Step 5/6: Locate TCP/UDP Traffic Path to the Destination
  732. Step 7: Identify the Physical Location of the Target Servers
  733. Step 8: Examine the Use IPV6 at the Remote Location
  734. Step 9: Lookup Domain Registry for IP Information
  735. Step 10: Find IP Block Information about the Target
  736. Step 11: Locate the ISP Servicing the Client
  737. Step 12: List Open Ports
  738. Open Ports on Web Server
  739. Step 13: List Closed Ports
  740. Port Scanning Tools
  741. Step 14: List Suspicious Ports that are Half Open/Closed
  742. Step 15: Port Scan Every Port (65,536) on the Target’s Network
  743. Step 16: Use SYN Scan on the Target and See the Response
  744. Step 17: Use Connect Scan on the Target and See the Response
  745. Demo - N-stalker Results Webgoat
  746. Demo - Breaking Access Control Passwords with Xhydra
  747. Demo - Viewing Website with Telnet
  748. Demo - Input-injection Attack
  749. Demo - Fast-track Overview and Install
  750. Demo - Fast-track Exploits
  751. Demo - Fast-track Clientside Attacks
  752. Demo - Fast-track Mass Attack
  753. Module 18 Review
  754. Module 19 - Internal Network Penetration Testing
  755. Internal Network Penetration Testing
  756. Penetration Testing Roadmap
  757. Internal Testing
  758. Methods of Internal Testing
  759. Enumerate Other Machines
  760. Step 1: Map the Internal Network
  761. Demo - Spiceworks Inventory
  762. Step 2: Scan the Network for Live Hosts
  763. Demo - SNMP Enumerating with BT
  764. Demo - FireScope MIB Tool
  765. Step 3: Port Scan Individual Machines
  766. Step 4: Try to Gain Access Using Known Vulnerabilities
  767. Demo - SMB NAT Dictionary Attacks
  768. Demo - Injecting the Abel Service
  769. Demo - Nslookup DNS Zone Transfer
  770. Step 5: Attempt to Establish Null Sessions
  771. Demo - Enumerate Banners
  772. Demo - Null Session Multiple Tools
  773. Demo - Null Session Countermeasures
  774. Step 6: Enumerate Users
  775. Step 7: Sniff the Network Using Wireshark
  776. Step 8: Sniff Pop3/FTP/Telnet Passwords
  777. Step 9: Sniff Email Messages/VoIP Traffic
  778. Sniffer Tools
  779. Demo - ARP Poisoning with Cain
  780. Step 10: Attempt Replay Attacks
  781. Demo - SSL MITM
  782. Step 11: Attempt ARP Poisoning
  783. Step 11a: Attempt Mac Flooding
  784. Step 12: Conduct a Man-in-the Middle Attack
  785. Step 13: Attempt DNS Poisoning
  786. Demo - Cain DNS Spoof
  787. Step 14: Try a Login to a Console Machine
  788. Step 15: Boot the PC Using Alternate OS and Steal the SAM File
  789. Demo - Local Password Reset
  790. Demo - Backtrack Local XP Password Attack
  791. Copying Commands in Knoppix
  792. ERD Commander 2005
  793. Reset Administrator Password
  794. Step 16: Attempt to Plant a Software Keylogger to Steal Passwords
  795. Keyloggers and Spy Software
  796. Demo - Hardware Keystroke Loggers
  797. Step 17: Attempt to Plant a Hardware Keylogger to Steal Passwords
  798. Step 18: Attempt to Plant a Spyware on the Target Machine
  799. Step 19: Attempt to Plant a Trojan on the Target Machine
  800. Step 20: Attempt to Create a Backdoor Account on the Target Machine
  801. Demo - Secure Tunnels and Anonymizer Techniques
  802. Step 21: Attempt to Bypass Anti-virus Software Installed on the Target Machine
  803. Demo - Stealth Tools v2 to Hide Viruses and Malware
  804. Step 22: Attempt to Send Virus Using the Target Machine
  805. Step 23: Attempt to Plant Rootkits on the Target Machine
  806. Demo - Dreampakpl Rootkit
  807. Step 24: Hide Sensitive Data on Target Machines
  808. Demo - Alternate Data Streams
  809. Step 25: Hide Hacking Tools and Other Data in Target Machines
  810. Step 26: Use Various Steganography Techniques to Hide Files on Target Machine
  811. Demo - Steganography
  812. Step 27: Escalate User Privileges
  813. Demo - Privilege Escalation
  814. Step 28: Capture POP3 Traffic
  815. Step 29: Capture SMTP Traffic
  816. Step 32: Capture HTTP Traffic
  817. Step 33: Capture HTTPS Traffic (Even Though it cannot be Decoded)
  818. Step 34: Capture RDP Traffic
  819. Step 35: Capture VoIP Traffic
  820. Demo - Cain VoIP RDP Interception
  821. Steps 40 and 41
  822. Step 42: Attempt Session Hijacking on Telnet Traffic
  823. Steps 43 and 44
  824. Continue Testing
  825. CORE Impact - Automated Tool
  826. Metasploit - Tool
  827. Canvas – Automated Tool
  828. Vulnerability Scanning Tools
  829. Document Everything
  830. Module 19 Review
  831.  
  832.  
  833. Module 20 - Router and Switches Penetration Testing
  834. Router and Switches Penetration Testing
  835. Demo - Cain and Abel Routing Protocols and ID Networks
  836. Penetration Testing Roadmap
  837. Router Testing Issues
  838. Need for Router Testing
  839. General Requirements
  840. Technical Requirements
  841. Try to Compromise the Router
  842. Steps for Router Penetration Testing
  843. Step 1: Identify the Router Hostname
  844. Step 2: Port Scan the Router
  845. Step 3: Identify the Router Operating System and its Version
  846. Steps 4/5: Identify Protocols Running/Testing for Package Leakage at the Router
  847. Step 6: Test for Router Misconfigurations
  848. Step 7: Test for VTY/TTY Connections
  849. The Process to Get Access to the Router
  850. Step 8: Test for Router Running Modes
  851. Privilege Mode Attacks
  852. Step 9: Test for SNMP Capabilities
  853. SNMP “Community String”
  854. Step 10: Test for TFTP Connections
  855. TFTP Testing
  856. Step 11: Test if Finger is Running on the Router
  857. Step 12: Test for CDP Protocol Running on the Router
  858. How to Test CDP Protocol?
  859. Step 13: Test for NTP Protocol
  860. Step 14: Test for Access to Router Console Port
  861. Step 15: Test for Loose and Strict Source Routing
  862. Steps 16 and 17: Test for IP Spoofing/IP Handling Bugs
  863. Step 18: Test ARP Attacks
  864. Step 19: Test for Routing Protocol Assessment
  865. Step 20: RIP Testing
  866. Step 21: Test for OSPF Protocol
  867. Step 22: Test BGP Protocol
  868. Step 23: Test for EIGRP Protocol
  869. Step 24: Test Router Denial of Service Attacks
  870. Step 25: Test Router’s HTTP Capabilities
  871. Step 26: Test Through HSRP Attack
  872. Router Testing Report
  873. Steps for Testing Switches
  874. Step 1: Testing Address Cache Size
  875. Step 2: Data Integrity and Error Checking Test
  876. Step 3: Testing for Back-to-Back Frame Capacity
  877. Step 4: Testing for Frame Loss
  878. Step 5: Testing for Latency
  879. Step 6: Testing for Throughput
  880. Step 7: Test for Frame Error Filtering
  881. Step 8: Fully Meshed Test
  882. Step 9: Stateless QoS Functional Test
  883. Step 10: Spanning Tree Network Convergence Performance Test
  884. Step 11: OSPF Performance Test
  885. Step 12: Test for VLAN Hopping
  886. Step 13: Test for MAC Table Flooding
  887. Step 14: Testing for ARP Attack
  888. Step 15: Check for VTP Attack
  889. Module 20 Review
  890. Module 21 - Firewall Penetration Testing
  891. Firewall Penetration Testing
  892. Penetration Testing Roadmap
  893. What is a Firewall?
  894. What Does a Firewall Do?
  895. Packet Filtering
  896. What Can't a Firewall Do?
  897. How Does a Firewall Work?
  898. Firewall Logging Functionality
  899. Firewall Policy
  900. Periodic Review of Information Security Policies
  901. Firewall Implementation
  902. Build a Firewall Ruleset
  903. Maintenance and Management of Firewall
  904. Types of Firewall
  905. Demo - Introduction to Vyatta
  906. Packet Filtering Firewall
  907. IP Packet Filtering Firewall
  908. Circuit Level Gateway
  909. Application Level Firewall
  910. Stateful Multilayer Inspection Firewall
  911. Multilayer Inspection Firewall
  912. Steps for Conducting Firewall Penetration Testing
  913. Step 1: Locate the Firewall
  914. Step 2: Traceroute to Identify the Network Range
  915. Step 3: Port Scan the Firewall
  916. Step 4: Grab the Banner
  917. Step 5: Create Custom Packets and Look for Firewall Responses
  918. Step 6: Test Access Control Enumeration
  919. Step 7: Test to Identify Firewall Architecture
  920. Step 8: Testing Firewall Policy
  921. Step 9: Test Firewall Using Firewalking Tool
  922. Step 10: Test for Port Redirection
  923. Firewall Identification
  924. Step 11: Testing the Firewall from Both Sides
  925. Step 12: Overt Firewall Test from Outside
  926. Step 13: Test Covert Channels
  927. Step 14: Covert Firewall Test from Outside
  928. Step 15: Test HTTP Tunneling
  929. Step 16: Test Firewall Specific Vulnerabilities
  930. Demo - Vyatta
  931. Demo - CORE Impact Targeting Vyatta
  932. Document Everything
  933. Module 21 Review
  934. Module 22 - IDS Penetration Testing
  935. IDS Penetration Testing
  936. Penetration Testing Roadmap
  937. What is an IDS?
  938. Demo - IDS Blink and Ossec.net
  939. Network IDS
  940. Host-based IDS
  941. Demo - Blink Personal IPS IDS
  942. Application-based IDS
  943. Multi-Layer Intrusion Detection Systems
  944. Multi-Layer Intrusion Detection System Benefits
  945. Wireless Intrusion Detection Systems (WIDS)
  946. IDS Testing Tool - Evasion Gateway
  947. Common Techniques Used to Evade IDS Systems
  948. IDS Penetration Testing Steps
  949. Steps 1/2: Test for Resource Exhaustion/ IDS by Sending ARP Flood
  950. Steps 3/4: Test the IDS by MAC Spoofing/ IP Spoofing
  951. Steps 5/6: Test by Sending a Packet to the Broadcast Address/Inconsistent Packets
  952. Steps 7/8: Test IP Packet Fragmentation/Duplicate Fragments
  953. Steps 9/10: Test for Overlapping Fragments/Ping of Death
  954. Steps 11/12: Test for Odd Sized Packets/TTL Evasion
  955. Steps 13/14: Test by Sending a Packet to Port 0/UDP Checksum
  956. Steps 15/16: Test for TCP Retransmissions/ TCP Flag Manipulation
  957. The TCP Header looks like this:
  958. Step 17: Test TCP Flags
  959. Steps 18/19: Test the IDS by Sending SYN Floods/ Sequence Number Prediction
  960. Step 20: Test for Backscatter
  961. Steps 21/22: Test the IDS with ICMP Packets/ IDS Using Covert Channels
  962. Step 23: Test Using TCPReplay
  963. Step 24: Test Using TCPOpera
  964. Step 26: Test the IDS Using URL Encoding
  965. Step 27: Test the IDS Using Double Slashes
  966. Step 28: Test the IDS for Reverse Traversal
  967. Step 29: Test for Self Reference Directories
  968. Step 31: Test for IDS Parameter Hiding
  969. Step 32: Test for HTTP-Misformatting
  970. Step 33: Test for Long URLs
  971. Step 34: Test for DoS/Win Directory Syntax
  972. Step 35: Test for Null Method Processing
  973. Step 36: Test for Case Sensitivity
  974. Step 37: Test Session Splicing
  975. Module 22 Review
  976. Module 23 - Wireless Network Penetration Testing
  977. Wireless Network Penetration Testing
  978. Penetration Testing Roadmap
  979. Wireless Security Threats
  980. Wireless Assessment
  981. Attempt Wireless Monitoring
  982. Wireless Vulnerability Testing
  983. Wireless Penetration Testing Steps
  984. Demo - inSSIDer
  985. Demo - Wi-Spy Spectrum Analyzer
  986. Demo - Tips Resources
  987. Module 23 Review
  988. Module 24 - Denial of Service Penetration Testing
  989. Denial of Service Penetration Testing
  990. How Does a Denial of Service Attack Work?
  991. Distributed Denial of Service Attack
  992. Warning
  993. How to Conduct Denial of Service Attack Penetration Testing?
  994. Demo - Ping of Death and Nemesy
  995. Module 24 Review
  996. Module 25 - Password Cracking Penetration Testing
  997. Password Cracking Penetration Testing
  998. Passwords
  999. Common Password Vulnerabilities
  1000. Password Cracking Techniques
  1001. Types of Password Cracking Attacks
  1002. Demo - Cain and Abel Dictionary Attack
  1003. Demo - Cracking your Local XP 64-bit Password with Ophcrack
  1004. Demo - Cracking the Hash Imported into Cain and Abel
  1005. Demo - Rainbow Table Cracking
  1006. Steps in Password Cracking Penetration Testing
  1007. Step 5: Attempt to Guess Passwords
  1008. Demo - Removing a PDF Password
  1009. Module 25 Review
  1010. Module 26 - Social Engineering Penetration Testing
  1011. Social Engineering Penetration Testing
  1012. What is Social Engineering?
  1013. Requirements of Social Engineering
  1014. Steps in Conducting Social Engineering Penetration Test
  1015. Before you Start
  1016. Dress Like a Businessman
  1017. Step 1: Attempt Social Engineering Techniques Using Phone
  1018. Step 2: Attempt Social Engineering by Vishing
  1019. Step 3: Attempt Social Engineering by Telephone
  1020. Step 4: Attempt Social Engineering Using Email
  1021. Demo - Hotmail Social Engineering
  1022. Step 10: Attempt Social Engineering by Desktop Information
  1023. Step 12: Attempt Social Engineering Using Websites
  1024. Module 26 Review
  1025. Module 27 - Stolen Laptops, PDAs, and Cell Phones Penetration Testing
  1026. Stolen Laptops, PDAs, and Cell Phones Penetration Testing
  1027. Penetration Testing Roadmap
  1028. Stolen Laptop Testing
  1029. Laptop Theft
  1030. Demo - Darik's Boot and Nuke
  1031. Penetration Testing Steps
  1032. Step 1: Identify Sensitive Data in the Devices
  1033. Look for Personal Information in the Stolen Laptop
  1034. Step 2: Look for Passwords
  1035. Step 3: Look for Company Infrastructure or Finance Documents
  1036. Step 4: Extract the Address Book and Phone Numbers
  1037. Step 5: Extract Schedules and Appointments
  1038. Step 6: Extract Applications Installed on these Devices
  1039. Step 7: Extract Email Messages from these Devices
  1040. Step 8: Gain Access to Server Resources by Using Information you Extracted
  1041. Step 9: Attempt Social Engineering with the Extracted Information
  1042. Check for BIOS Password
  1043. Look into the Encrypted File
  1044. Check Cookies in Web Browsers
  1045. Install Software
  1046. Attempt to Enable Wireless
  1047. Module 27 Review
  1048. Module 28 - Application Penetration Testing
  1049. Application Penetration Testing
  1050. Application Testing
  1051. What is a Defect?
  1052. Defects vs. Failures
  1053. Defect Ratio
  1054. Requirements and Design Testing
  1055. Web Applications Penetration Testing
  1056. What is a Web Application?
  1057. Demo - Webgoat Hands-on Web Testing
  1058. Demo - Foundstone Overview Hacme Bank Weak Apps
  1059. Web Application Penetration Testing Steps
  1060. Step 1: Fingerprinting the Web Application Environment
  1061. Step 2: Investigate the Output from HEAD and OPTIONS Http Requests
  1062. Step 3: Investigate the Format and Wording of 404/Other Error Pages
  1063. Step 4: Test for Recognized File Types/Extensions/Directories
  1064. Step 5: Examine Source of Available Pages
  1065. Step 6: Manipulate Inputs in Order to Elicit a scripting Error
  1066. Step 7: Test Inner Working of a Web Application
  1067. Step 8: Test Database Connectivity
  1068. Step 9: Test the Application Code
  1069. Random Numbers vs. Unique Numbers
  1070. Step 10: Testing the Use of GET and POST in Web Application
  1071. Step 11: Test for Parameter-Tampering Attacks on Website
  1072. Step 12: Test for URL Manipulation
  1073. Step 13: Test for Cross Site scripting
  1074. Step 14: Test for Hidden Fields
  1075. Step 15: Test Cookie Attacks
  1076. Step 16: Test for Buffer Overflows
  1077. Step 17: Test for Bad Data
  1078. Step 18: Test Client-Side scripting
  1079. Step 19: Test for Known Vulnerabilities
  1080. Step 20: Test for Race Conditions
  1081. Step 21: Test with User Protection via Browser Settings
  1082. Step 22: Test for Command Execution Vulnerability
  1083. Step 23: Test for SQL Injection Attacks
  1084. Step 24: Test for Blind SQL Injection
  1085. Step 25: Test for Session Fixation Attack
  1086. Step 26: Test for Session Hijacking
  1087. Step 27: Test for XPath Injection Attack
  1088. Step 28: Test for Server Side Include Injection Attack
  1089. Step 29: Test for Logic Flaws
  1090. Step 30: Test for Binary Attacks
  1091. Step 31: Test for XML Structural
  1092. Step 32: Test for XML Content-level
  1093. Step 33: Test for WS HTTP GET Parameters/REST Attacks
  1094. Step 34: Test for Malicious SOAP Attachments
  1095. Step 35: Test for WS Replay
  1096. Testing Tools
  1097. KSES/ Mieliekoek.pl
  1098. Webgoat
  1099. AppScan
  1100. URL Scan
  1101. Demo - Hacme Bank Scan using N-Stalker
  1102. Demo - Hacme Bank Scan Core Web Testing
  1103. Module 28 Review
  1104. Module 29 - Physical Security Penetration Testing
  1105. Physical Security Penetration Testing
  1106. Physical Attacks
  1107. Steps in Conducting Physical Security Penetration Testing
  1108. Demo - Bump Key Animation
  1109. Step 1: Map the Possible Entrances
  1110. Step 2: Map the Physical Perimeter
  1111. Step 3: Penetrate Locks Used on the Gates, Doors, and Closets
  1112. Step 4: Observing From a Distance
  1113. Step 5: Penetrate Server Rooms, Cabling, and Wires
  1114. Step 6: Attempt Lock Picking Techniques
  1115. Step 7: Fire Detection Systems
  1116. Step 8: Air Conditioning Systems
  1117. Step 9: Electromagnetic Interception
  1118. Check for the Following
  1119. Step 10: Test if the Company has a Physical Security Policy
  1120. Step 11: Physical Assets
  1121. Step 12: Risk Test
  1122. Step 13: Test if any Valuable Paper Document is Kept at the Facility
  1123. Step 14: Check how these Documents are Protected
  1124. Step 15: Employee Access
  1125. Step 16: Test for Radio Frequency ID (RFID)
  1126. Step 17: Physical Access to Facilities
  1127. Step 18: Documented Process
  1128. Step 19: Test People in the Facility
  1129. Step 20: Who is Authorized?
  1130. Step 21: Test Fire Doors
  1131. Step 22: Check for Active Network Jacks in Meeting Rooms
  1132. Step 23: Check for Active Network Jacks in Company Lobby
  1133. Step 24: Check for Sensitive Information Lying around Meeting Rooms
  1134. Step 25: Check for Receptionist/Guard Leaving Lobby
  1135. Step 26: Check for Accessible Printers at the Lobby – Print Test Page
  1136. Step 27: Obtain Phone/Personnel Listing from the Lobby Receptionist
  1137. Step 28: Listen to Employee Conversation in Communal Areas/Cafeteria
  1138. Step 29: Can you Enter the Ceiling Space and Enter Secure Rooms
  1139. Step 30: Check Windows/Doors for Visible Alarm Senses
  1140. Step 31: Check Visible Areas for Sensitive Information
  1141. Step 32: Try to Shoulder Surf Users Logging on
  1142. Step 33: Try to Videotape Users Logging on
  1143. Steps 34 and 35
  1144. Step 36: Intercept and Analyze Guard Communication
  1145. Step 37: Attempt Piggybacking on Guarded Doors
  1146. Step 38: Attempt to Use Fake ID to Gain Access
  1147. Step 39: Test “ After Office Hours” Entry Methods
  1148. Step 40: Identify all Unguarded Entry Points
  1149. Step 43: Attempt to Bypass Sensors Configured on Doors and Windows
  1150. Step 44: Attempt Dumpster Diving Outside the Company Trash Area
  1151. Step 45: Use Binoculars from Outside the Building and See if you can View What is Going On Inside
  1152. Step 46: Use Active High Frequency Voice Sensors to Hear Private Conversation among Company Staff
  1153. Step 47: Dress as a FedEx/UPS Employee and Try to Gain Access to the Building
  1154. Document Everything
  1155. Module 29 Review
  1156. Module 30 - Database Penetration Testing
  1157. Database Penetration Testing
  1158. List of Steps
  1159. Demo - NTOSpider
  1160. Step 1: Scan for Default Ports Used by the Database
  1161. Step 2: Scan for Non-Default Ports Used by the Database
  1162. Step 3: Identify the Instance Names Used by the Database
  1163. Step 4: Identify the Version Numbers Used by the Database
  1164. Step 5: Attempt to Brute-Force Password Hashes from the Database
  1165. Step 6: Sniff Database Related Traffic on the Local Wire
  1166. Step 7: Microsoft SQL Server Testing
  1167. Step 7.1: Test for Direct Access Interrogation
  1168. Step 7.2: Scan for Microsoft SQL Server Ports ( TCP/UDP 1433)
  1169. Step 7.3: Test for SQL Server Resolution Service (SSRS)
  1170. Step 7.4: Test for Buffer Overflow in pwdencrypt() Function
  1171. Step 7.5: Test for Heap/Stack Buffer Overflow in SSRS
  1172. Step 7.6: Test for Buffer Overflows in Extended Stored Procedures
  1173. Step 7.7: Test for Service Account Registry Key
  1174. Step 7.8: Test the Stored Procedure to Run Web Tasks
  1175. Step 7.9: Exploit SQL Injection Attack
  1176. Step 7.10: Blind SQL Injection
  1177. Demo - SQL Injection with Lee Lawson
  1178. Step 7.11: Google Hacks
  1179. Step 7.12: Attempt Direct-exploit Attacks
  1180. Step 7.13: Try to Retrieve Server Account List
  1181. Step 7.14: Using OSQL Test for Default/Common Passwords
  1182. Step 7.15: Try to Retrieve Sysxlogins Table
  1183. Try to Retrieve Sysxlogins Table Views
  1184. SQL Server System Tables
  1185. Step 7.16: Brute-force SA Account
  1186. Step 8: Oracle Server Testing
  1187. Port Scanning Basic Techniques
  1188. Step 8.2: Check the Status of TNS Listener Running at Oracle Server
  1189. Listener Modes
  1190. Step 8.3: Try to Login Using Default Account Passwords
  1191. Step 8.4: Try to Enumerate SIDs
  1192. Step 8.5: Use SQL Plus to Enumerate System Tables
  1193. SQL PLUS: Screenshot
  1194. Step 9: MySQL Server Database Testing
  1195. Step 9.2: Extract the Version of Database being Used
  1196. Step 9.3: Try to Login Using Default/Common Passwords
  1197. Step 9.4: Brute-force Accounts Using Dictionary Attack
  1198. Dictionary Attack Tools
  1199. Dictionary Attack Tool: SQLdict
  1200. Step 9.5: Extract System and User Tables from the Database
  1201. Demo - CORE Impact Webgoat Information Gathering
  1202. Demo - CORE Impact Webgoat SQL Numeric Injection
  1203. Demo - Hacme Bank Testing with Wikto
  1204. Module 30 Review
  1205. Module 31 - VoIP Penetration Testing
  1206. VoIP Penetration Testing
  1207. Penetration Testing Roadmap
  1208. Vulnerability Assessment
  1209. VoIP Risks and Vulnerabilities
  1210. VoIP Security Threat
  1211. VoIP Penetration Testing Steps
  1212. Demo - VoIP Overview Testing
  1213. Step 1: Test for Eavesdropping
  1214. Step 2: Test for Flooding and Logic Attacks
  1215. Step 3: Test for Denial of Service (DoS) Attack
  1216. Step 4: Test for Call Hijacking & Redirection Attack
  1217. Step 5: Test for ICMP Ping Sweeps
  1218. Step 6: Test for ARP Pings
  1219. Step 7: Test for TCP Ping Scans
  1220. Step 8: Test for SNMP Sweeps
  1221. Step 9: Test for Port Scanning and Service Discovery
  1222. Step 10: Test for Host/Device Identification
  1223. Step 11: Test for Banner Grabbing
  1224. Step 12: Test for SIP User/Extension Enumeration
  1225. Step 13: Test for Automated OPTIONS Scanning with sipsak
  1226. Step 14: Test for Automated REGISTER, INVITE, and OPTIONS Scanning with SIPSCAN against SIP Server
  1227. Step 15: Test for Enumerating TFTP Servers
  1228. Step 16: Test for SNMP Enumeration
  1229. Step 17: Test for Sniffing TFTP Configuration File Transfers
  1230. Step 18: Test for Number Harvesting and Call Pattern Tracking
  1231. VoIP Security Tools
  1232. AuthTool
  1233. VoIPong
  1234. Demo - VoIP Interception with Cain and Abel
  1235. VoIPong: Screenshots
  1236. Vomit
  1237. PSIPDump
  1238. Netdude
  1239. Netdude: Features
  1240. Oreka
  1241. rtpBreak
  1242. SNScan
  1243. Smap
  1244. Example: Locating Devices
  1245. Example: Fingerprinting Devices
  1246. Example: Learning Mode
  1247. SIPScan
  1248. Scanning SIP Phones
  1249. SIPScan: Screenshot
  1250. SIPcrack
  1251. VoIPaudit
  1252. Sipsak
  1253. SIPp
  1254. SipBomber
  1255. Spitter
  1256. VoIP Fuzzing Tools
  1257. VoIP Signaling Manipulation Tools
  1258. VoIP Media Manipulation Tools
  1259. Module 31 Review
  1260. Module 32 - VPN Penetration Testing
  1261. VPN Penetration Testing
  1262. Virtual Private Network (VPN)
  1263. VPN Penetration Testing Steps
  1264. Demo - VPN Testing
  1265. Step 1.1 Scanning: 500 UDP IPSEC
  1266. Step 1.2 Scanning: 1723 TCP PPTP
  1267. Step 1.3 Scanning: 443 TCP/SSL
  1268. Step 1.4 Scanning: nmap -sU -P0 -p 500
  1269. Step 1.5 Scanning: Ipsecscan xxx.xxx.xxx.xxx-255
  1270. Step 2: Fingerprinting
  1271. Step 2.1: Get the IKE Handshake
  1272. Step 2.2: UDP Backoff Fingerprinting
  1273. Step 2.3: Vendor ID Fingerprinting
  1274. Step 2.4: Check for IKE Aggressive Mode
  1275. Step 3.1: PSK Crack: ikeprobe xxx.xxx.xxx.xxx-255
  1276. Step 3.2 PSK Crack: Sniff for Responses with C&A or IKECrack
  1277. Step 4: Test for Default User Accounts
  1278. Step 4.1: Check for Unencrypted Username in a File or the Registry
  1279. Check for Unencrypted Username in a File or the Registry: Screenshot
  1280. Step 4.2: Test for Plain-Text Password
  1281. Step 5: Test for SSL VPN
  1282. Tool: IKE-scan
  1283. IKE-scan: Screenshot
  1284. Tool: IKEProbe
  1285. Tool: VPNmonitor
  1286. Tool: IKECrack
  1287. Module 32 Review
  1288. Module 33 - War Dialing
  1289. War Dialing
  1290. War Dialing Techniques
  1291. Why Conduct a War Dialing Pentest?
  1292. Pre-Requisites for War Dialing Penetration Testing
  1293. Software Selection for War Dialing
  1294. Guidelines for Configuring Different War Dialing Software
  1295. Recommendations for Establishing an Effective War Dialing Process
  1296. Interpreting War Dialing Results
  1297. List of War Dialing Tools
  1298. Demo - New War Dialing Tool: WarVOX
  1299. PhoneSweep
  1300. THC Scan
  1301. ToneLoc
  1302. ModemScan - www.wardial.net
  1303. War Dialing Countermeasures SandTrap Tool
  1304. Module 33 Review
  1305. Module 34 - Virus and Trojan Detection
  1306. Virus and Trojan Detection
  1307. Steps for Detecting Trojans and Viruses
  1308. Step 1: Use netstat -a to Detect Trojans Connections
  1309. Step 2: Check Windows Task Manager
  1310. Step 3: Check Whether Scanning Programs are Enabled
  1311. Step 3.1: Perform Scanning for Suspicious Running Processes
  1312. Step 3.2: Perform Scanning for Suspicious Registry Entries
  1313. Step 3.3: Check for Suspicious Open Ports
  1314. Step 3.4: Check Whether Suspicious Network Activities are Present
  1315. Step 3.5: Use HijackThis to Scan for Spyware
  1316. Step 4: Check Whether Anti-Virus and Anti-Trojan Programs are Working
  1317. Step 5: Detection of a Boot-Sector Virus
  1318. Spyware Detectors
  1319. Demo - Beast Trojan
  1320. Anti-Trojans
  1321. Anti-Virus Software
  1322. Module 34 Review
  1323. Module 35 - Log Management Penetration Testing
  1324. Log Management Penetration Testing
  1325. Need for Log Management
  1326. Challenges in Log Management
  1327. Steps for Log Management Penetration Testing
  1328. Step 1: Scan for Log Files
  1329. Step 2: Try to Flood Syslog Servers with Bogus Log Data
  1330. Step 3: Try Malicious Syslog Message Attack (Buffer Overflow)
  1331. Step 4: Perform Man-in-the-Middle Attack
  1332. Step 5: Check Whether the Logs are Encrypted
  1333. Step 6: Check Whether Arbitrary Data Can be Injected Remotely into Microsoft ISA Server Log File
  1334. Step 7: Perform DoS Attack Against Check Point FW-1 Syslog Daemon (Only for CheckPoint Firewall)
  1335. Step 8: Send Syslog Messages Containing Escape Sequences to Syslog Daemon of Check Point FW-1 NG FP3
  1336. Checklist For Secure Log Management
  1337. Module 35 Review
  1338. Module 36 - File Integrity Checking
  1339. File Integrity Checking
  1340. File Integrity
  1341. Integrity Checking Techniques
  1342. Demo - File Integrity Checkers
  1343. Steps for Checking File Integrity
  1344. Step 1: Check While you Unzip the File
  1345. Step 2: Check for CRC Value Integrity Checking
  1346. CRC Checking in Windows
  1347. Step 3: Check for Hash Value Integrity Checking
  1348. Step 3.1: Get the File and Previously Calculated Hash Value for the File
  1349. Step 3.2: Generate a New Hash Value for the File
  1350. Step 3.3: Match the Old and New Hash Values
  1351. File Integrity Checking Tools
  1352. Module 36 Review
  1353. Module 37 - Bluetooth and Hand Held Device Penetration Testing
  1354. Bluetooth and Hand Held Device Penetration Testing
  1355. Jailbreaking an iPhone
  1356. Steps for iPhone Penetration Testing
  1357. Demo - Jailbreak
  1358. Demo - iPod Custom Apps
  1359. Step 1: Jailbreak the iPhone
  1360. Jailbreaking Using PwnageTool or QuickPwn
  1361. Jailbreaking Using QuickPwn
  1362. Step-by-Step Guide to Jailbreak iPhone 3G and Preserve Baseband using PwnageTool
  1363. Step 2: Unlock the iPhone
  1364. Step 4: Hack iPhone using Metasploit
  1365. Step 5: Check for Access Point with Same Name and Encryption Type
  1366. Step 6: Check Whether Malformed Data Can be Sent to the Device
  1367. Step 7: Check Whether Basic Memory Mapping Information Can be Extracted
  1368. Vulnerabilities in BlackBerry
  1369. Steps for Penetration Testing
  1370. Step 1: Try Blackjacking on BlackBerry
  1371. Step 2: Try to Attack by Sending Malformed TIFF Image Files
  1372. PDA Attacks
  1373. Steps for Penetration Testing 2
  1374. Step 1: Check Whether Passwords can be Cracked
  1375. Step 2: Try for ActiveSync Attacks
  1376. Step 3: Check Whether the IR Port is Enabled
  1377. Step 4: Check Whether Encrypted Data can be Decrypted
  1378. Bluetooth: Introduction
  1379. Different Attacks in Bluetooth Devices
  1380. Steps for Penetration Testing in Bluetooth
  1381. Step 1: Check Whether the PIN Can be Cracked
  1382. Step 2: Try to Perform a Blueprinting Attack
  1383. Step 3: Check Whether you are able to Extract the SDP Profiles
  1384. Step 4: Try Pairing Code Attacks
  1385. Step 5: Try a Man-in-the-Middle Attack
  1386. Step 6: Try a BlueJacking Attack
  1387. Step 7: Try a BTKeylogging Attack
  1388. Step 8: Try Bluesmacking -The Ping of Death
  1389. Step 9: Try a BlueSnarfing Attack
  1390. Try a BlueSnarfing Attack
  1391. Step 10: Try a BlueBug Attack
  1392. Step 11: Try BlueSpam
  1393. Module 37 Review
  1394. Module 38 - Telecommunication and Broadband Communication Penetration Testing
  1395. Telecommunication and Broadband Communication Penetration Testing
  1396. Broadband Communication
  1397. Risk in Broadband Communication
  1398. Steps for Broadband Communication Penetration Testing
  1399. Step 1: Check Whether the Firewall Device is Installed on Network
  1400. Step 1.1: Check Whether Personal and Hardware Firewalls are Installed
  1401. Step 1.2: Check Whether These Firewalls Prevent Intruders or Detect Any Rogue Software
  1402. Step 1.3: Check Whether the Logging is Enabled on the Firewall
  1403. Step 1.4: Check Whether the Firewall is in Stealth Mode
  1404. Step 2: Check Whether Web Browsers are Properly Configured
  1405. Step 2.1: Check Whether the Browser has Default Configuration
  1406. Step 2.2: Check for the Browser Plugins
  1407. Step 2.3: Check Whether Active Code is Enabled
  1408. Step 2.4: Check Whether the Browser Version is Updated
  1409. Step 2.5: Check Whether the Cookies are Enabled
  1410. Step 2.6: Check Whether the scripting Languages are Enabled
  1411. Step 3: Check for Operating System Configuration Options
  1412. Step 3.1: Check Whether Operating System and Application Software are Updated
  1413. Step 3.2: Check Whether the File and Printer Sharing Option is Enabled
  1414. Step 3.3: Check Whether the Anti-Virus Programs are Enabled
  1415. Step 3.4: Check the Configuration of Anti-Virus Program
  1416. Step 3.5: Check Whether Anti-Spyware is Enabled
  1417. Step 4: Check for Wireless and other Home Networking Technologies
  1418. Step 4.1: Check for VPN Policy Configurations
  1419. Step 4.2: Try for Wiretapping
  1420. Step 4.3: Try to Perform War Driving
  1421. Step 4.4: Check Whether the Wireless Base Station is at Default Configuration
  1422. Step 4.5: Check Whether WEP is Implemented
  1423. Step 4.6: Try to Crack the WEP Key
  1424. Step 4.7: Try to Crack the SSID Password
  1425. Step 4.8: Check Whether the Simple Network Management Protocol (SNMP) is Enabled
  1426. Guidelines for Securing Telecommuting and Home Networking Resources
  1427. Module 38 Review
  1428. Module 39 - Email Security Penetration Testing
  1429. Email Security Penetration Testing
  1430. Introduction to Email Security
  1431. Pre-Requisite For Email Penetration Testing
  1432. Demo - Hacking Email Accounts
  1433. Steps for Email Penetration Testing
  1434. Step 1: Try to Access Email ID and Password
  1435. Step 2: Check Whether Anti-Phishing Software is Enabled
  1436. Step 3: Check Whether Anti-Spamming Tools are Enabled
  1437. Step 4: Try to Perform Email Bombing
  1438. Step 5: Perform CLSID Extension Vulnerability Test
  1439. Step 6: Perform VBS Attachment Vulnerability Test
  1440. Step 7: Perform Double File Extension Vulnerability Test
  1441. Step 8: Perform Long Filename Vulnerability Test
  1442. Step 9: Perform ActiveX Vulnerability Test
  1443. Step 10: Perform Iframe Remote Vulnerability Test
  1444. Step 11: Perform MIME Header Vulnerability Test
  1445. Step 12: Perform Malformed File Extension Vulnerability Test
  1446. Step 13: Perform Access Exploit Vulnerability Test
  1447. Step 14: Perform Fragmented Message Vulnerability Test
  1448. Step 15: Perform Long Subject Attachment Checking Test
  1449. List of Anti-Phishing Tools
  1450. PhishTank SiteChecker
  1451. PhishTank SiteChecker: Screenshot
  1452. NetCraft
  1453. GFI MailEssentials
  1454. SpoofGuard
  1455. List of Anti-Spamming Tools
  1456. AEVITA Stop SPAM Email
  1457. SpamExperts Desktop
  1458. Spytech SpamAgent
  1459. Module 39 Review
  1460. Module 40 - Security Patches Penetration Testing
  1461. Security Patches Penetration Testing
  1462. Patch Management
  1463. Patch and Vulnerability Group (PVG)
  1464. Countermeasure Testing Steps
  1465. Step 1: Check If Organization has a PVG in Place
  1466. Step 2: Check Whether the Security Environment is Updated
  1467. Step 3: Check Whether Organization uses Automated Patch Management Tools
  1468. Step 4: Check the Last Date of Patching
  1469. Step 5: Check the Patches on Non-Production Systems
  1470. Step 6: Check the Vender Authentication Mechanism
  1471. Step 7: Check Whether Downloaded Patches Contain Viruses
  1472. Step 8: Check for Dependency of New Patches
  1473. Security Checklist for Patch Management
  1474. Patch Management Tools
  1475. Module 40 Review
  1476. Module 41 - Data Leakage Penetration Testing
  1477. Data Leakage Penetration Testing
  1478. Penetration Testing Roadmap
  1479. Data Leakage
  1480. Data Leakage Statistics
  1481. How Much Security?
  1482. How Data Can be Leaked
  1483. What to Protect
  1484. Steps for Data Leakage
  1485. Step 1: Check Physical Availability of USB Devices
  1486. Step 2: Check Whether USB Drive is Enabled
  1487. Step 3: Try to Enable USB
  1488. Step 4: Check Whether USB Asked for Password
  1489. Step 5: Check Whether Bluetooth is Enabled
  1490. Step 6: Check if the Firewire is Enabled
  1491. Step 7: Check if FTP Ports 21 and 22 are Enabled
  1492. Step 8: Check Whether any Memory Slot is Available and Enabled in Systems
  1493. Step 9: Check Whether Employees are Using Camera Devices within Restricted Areas
  1494. Step 10: Check Whether Systems have Any Camera Driver Installed
  1495. Step 11: Check Whether Anti-Spyware and Anti-Trojans are Enabled
  1496. Step 12: Check Whether Encrypted Data Can be Decrypted
  1497. Step 13: Check if the Internal Hardware Components are Locked
  1498. Step 14: Check Whether Size of Mail and Mail Attachments is Restricted
  1499. Data Privacy and Protection Acts
  1500. Data Protection Tools
  1501. Module 41 Review
  1502. Module 42 - Penetration Testing Deliverables and Conclusion
  1503. Penetration Testing Deliverables and Conclusion
  1504. Destroy the Report
  1505. Sign-Off Document
  1506. Module 42 Review
  1507. Module 43 - Penetration Testing Report and Documentation Writing
  1508. Penetration Testing Report and Documentation Writing
  1509. Penetration Testing Report
  1510. Documentation Writing
  1511. Table of Contents
  1512. Summary of Execution
  1513. Summary of Weaknesses
  1514. Scope of the Project
  1515. Result Analysis
  1516. Recommendations
  1517. Appendices
  1518. Test Reports on Network
  1519. Summary Recommendations
  1520. Exploited Vulnerabilities
  1521. Payment Card Industry (PCI) Report
  1522. Client-Side Test Reports
  1523. Client-Side Penetration Test Report
  1524. User Report
  1525. Test Reports on Web Applications
  1526. Web Application Testing Report
  1527. Detailed Findings
  1528. Detailed Results
  1529. Strategic and Tactical Directives
  1530. Writing the Final Report
  1531. Creating the Final Report
  1532. Report Format
  1533. Delivery
  1534. Report Retention
  1535. Module 43 Review
  1536. Module 44 - Penetration Testing Report Analysis
  1537. Penetration Testing Report Analysis
  1538. Report on Penetration Testing
  1539. Pen-Test Team Meeting
  1540. Research Analysis
  1541. Pen-Test Findings
  1542. Rating Findings
  1543. Demo - Practical Threat Analysis Tool
  1544. Example of Finding- I
  1545. Example of Finding- II
  1546. Analyze
  1547. Module 44 Review
  1548. Module 45 - Post Testing Actions
  1549. Post Testing Actions
  1550. Prioritize Recommendations
  1551. Develop Action Plan
  1552. Create Process for Minimizing Misconfiguration Chances
  1553. Updates and Patches
  1554. Capture Lessons Learned and Best Practices
  1555. Create Security Policies
  1556. Conduct Training
  1557. Take Social Engineering Class
  1558. Destroy the Pen-Test Report
  1559. Module 45 Review
  1560. Module 46 - Ethics of a Licensed Penetration Tester
  1561. Ethics of a Licensed Penetration Tester
  1562. What Makes a Licensed Penetration Tester?
  1563. Modus Operandi
  1564. Evolving as a Licensed Penetration Tester
  1565. Licensed Penetration Tester Dress Code
  1566. LPT Audited Logos
  1567. Example: LPT Audited Logos
  1568. Module 46 Review
  1569. Module 47 - Standards and Compliance
  1570. Customers and Legal Agreements
  1571. Module 47 Review
  1572. Course Closure
Advertisement
Add Comment
Please, Sign In to add comment