An advanced technical hands on course focusing on hacking and counter hacking. The course revolves around a series of exercises based on "hacking" into a network (pen testing the network) and then defending against the hacks.
Technical support staff, auditors and security
professionals.
Staff who are responsible for network
infrastructure integrity.
5 days
Hacking concepts, phases, types of attacks, “White hacking”, What is penetration testing? Why use pen testing, black box vs. white box testing, equipment and tools, security lifecycles, counter hacking, pen testing reports, methodologies, legal issues.
Testing access controls, perimeter reviews, location reviews, alarm response testing. Request testing, guided suggestions, trust testing. Social engineering concepts, techniques, counter measures, Identity theft, Impersonation on social media, Footprints through social engineering
Footprinting methodologies, concepts, threats and countermeasures, WHOIS footprinting, Gaining contacts and addresses, DNS queries, NIC queries, ICMP ping sweeping, system and server trails from the target network, information leaks, competitive intelligence. Scanning pen testing.
Getting past passwords, password grinding, spoofed tokens, replays, remaining anonymous.
Gaining OS info, platform info, open port info, application info. Routes used, proxies, firewalking, Port scanning, stealth port scanning, vulnerability scanning, FIN scanning, Xmas tree scanning, Null scanning, spoofed scanning, Scanning beyond IDS. Enumeration concepts, counter measures and enumeration pen testing.
Hacking webservers, web applications, Wireless networks and mobile platforms. Concepts, threats, methodology, hacking tools and countermeasures.
Detection, concepts, countermeasures, Pen testing Trojans, backdoors, sniffers and viruses. MAC attacks, DHCP attacks, ARP poisoning, DNS poisoning Anti-Trojan software, Malware analysis Sniffing tools.
Buffer overflows,, simple exploits, brute force methods, UNIX based, Windows based, specific application vulnerabilities.
Concepts, techniques, attack tools, Botnet, countermeasures, protection tools, DoS attack pen testing.
Types and testing, Blind SQL Injection, Injection tools, evasion and countermeasures.
“Hurdles”, firewalls, DMZ, stopping port scans, IDS, Honeypots, Router testing, firewall testing, IDS testing, Buffer Overflow.
PKI, Encryption algorithms, tools, Email and Disk Encryption.
Document grinding, privacy.
"Excellent presentation - very good course structure."
"Course was a real eye-opener to some of the barriers we encounter."
This structured course uses Instructor Led Training to provide the best possible learning experience. Small class sizes ensure students benefit from our engaging and interactive style of teaching with delegates encouraged to ask questions throughout the course. Quizzes follow each major section allowing checking of learning. Hands on sessions are used throughout to allow delegates to consolidate their new skills.