Ethical Hacking Course
The Esqo 5-day in-depth Ethical Hacking course will give a thorough grounding in current hacking techniques used to penetrate computer systems and how to defend against them.
Trainers
Our trainers not only know their own course material they are themselves veteran penetration testing professionals. During the course they will draw on their real world experience in the field to illustrate and educate.
Audience
Network, system engineers, consultants and management will all benefit from the course. System designers and software developers will also benefit as the course will give them added security awareness vital when designing and building systems.
The course is instructed using a combination of class lectures and practical sessions. During the five day course the students will break into some of the following systems
|
| |
Microsoft Windows NT and 2000/XP
Sun Solaris
RedHat Linux
Cisco
FreeBSD |
|
Each topic covered during the lectures will be put into practive during the practical sessions when each student will use the tools and techniques learnt in class on the lab machines.
|
| Day 1 |
Introduction
Information Gathering and Enumeration
Network Sniffing
Windows Exploits
|
|
After the first day students will be familiar with network port scanning techniques including idle scanning and advanced fingerprinting techniques. Students will exploit an OS level vulnerability in Windows, a client side issue in Internet Explorer and create a reverse shell payload for a JPEG vulnerability
|
| Day 2 |
Windows Domains
Windows Tools
Buffer Overflows
Exploit Writing Exercise |
|
After the second day students will have a thorough grounding in common exploit types and the underlying mechanisms. The Buffer Overflow module is supported by a lab exercise in which students will write an exploit.
|
| Day 3 |
Wireless Hacking
Cisco Hacking
Database Hacking
E-Mail Hacking
Web Browser Hacking |
|
After the third day students will, amongst other things be able to identify and penetrate vulnerable Oracle servers. Students will also get the chance to exploit the E-Mail and Web Browsing clients on their own lab machines.
|
| Day 4 |
Web Servers
Web Application Hacking |
|
After the fourth day students will have a firm understanding of web hacking techniques from the perspective of the Web Server and Web Applications. These modules also give a firm grounding in HTTP and its workings including sub topics like authentication. Featured vulnerabilities will include WebDAV, SSL PCT and Apache and OpenSSL issues.
The Web Application module covers SSL proxies used to test applications protected by SSL and web interceptor software like Achilles and WebScarab. The module takes an in-depth look at web application issues module including sessions and hijacking. SQL injection, XSS and session hijacking is illustrated in step-by-step demonstrations and exercises.
|
| Day 5 |
Unix Hacking |
|
The final day will introduce the Unix system, its architecture, weaknesses and attacks on the Unix file system and network services.
Each student will receive a CD-ROM containing all the tools that were used during the labs. The students will also be presented with course documentation and a certificate of attendance. Both Windows-based and Unix-based attack tools will be used. |