Pen testing
course contents
Introduction
Hacking, “White hacking”, What is penetration testing?
Why use pen testing, black box vs. white box testing, equipment
and tools, security lifecycles, counter hacking, pen testing
reports, methodologies, legal issues.
Physical security and social engineering
Testing access controls, perimeter reviews, location reviews,
alarm response testing. Request testing, guided suggestions,
trust testing.
Reconnaissance (discovery)
Gaining contacts and addresses, DNS queries, NIC queries,
ICMP ping sweeping, system and server trails from the target
network, information leaks.
Scanning (enumeration)
Gaining OS info, platform info, open port info, application
info. Routes used, firewalking, Port scanning, stealth
port scanning, FIN scanning, Xmas tree scanning, Null scanning,
spoofed scanning.
Gaining access
Getting past passwords, password grinding, spoofed tokens,
replays, remaining anonymous.
Securing networks
“
Hurdles”, firewalls, DMZ, stopping port scans, IDS,
Honeypots, Router testing, firewall testing, IDS testing
Exploiting (testing) vulnerabilities
Buffer overflows, DoS attacks, simple exploits, brute force
methods, UNIX based, Windows based, specific application
vulnerabilities.
Maintaining access
Backdooring systems, preventing detection.
Information security
Document grinding, privacy.
Telecommunications testing
PBX testing, Voicemail testing, modem testing.
|