|
|
1-800-THE-TREE (1-800-843-8733)
|
|
|
 |
|
Ethical Hacking and Countermeasures: Hands-OnPreventing Network and System Breaches
Course: 537
Type: Hands-On Training
Duration: 4 Days
You Will Learn How To
- Deploy ethical hacking to expose weaknesses in your organization and select countermeasures
- Gather intelligence by employing reconnaissance, published data and scanning tools
- Probe and compromise your network using hacking tools to test and improve your security
- Discover how malicious hackers exploit weaknesses to "own" the network
- Protect against privilege escalation to prevent intrusions
- Evade antivirus software, firewalls and IDS
Course Benefits As network breaches become increasingly sophisticated, proactive defenses are essential to counter malicious attacks. In this course, you learn to discover weaknesses in your network using the same mindset and methods as hackers. You acquire the knowledge to systematically test and exploit internal and external defenses. You learn countermeasures and how to reduce risk to your enterprise.Who Should Attend Security consultants, Information Assurance auditors, firewall/IDS personnel, programmers, PCI security testers and others responsible for securing enterprise systems. Security knowledge at the level of Course 468, "System and Network Security Introduction," and strong TCP/IP experience is assumed.Hands-On Training Hands-on exercises model hacking methods and countermeasures, including:
- Preparing the hacker toolkit
- Executing advanced port scanning
- Linking vulnerabilities and exploits
- Determining the vulnerabilities of a network
- Performing injection attacks
- Predicting and hijacking Web sessions
- Poisoning DNS to lure clients
- Configuring and using the Metasploit Framework
- Defeating stateless firewalls, IDS and antivirus software
- Deploying rootkits
Course 537 Content
- Defining a penetration testing methodology
- Creating a security testing plan
- Adhering to PCI standards
- Assembling the hacking tools
- Locating useful and relevant information
- Scavenging published data
- Mining archive sites
- Identifying authentication methods
- Analyzing firewalls
- Harvesting e-mail information
- Interrogating network services
- Scanning from the inside out with HTML
- Researching databases
- Determining target configuration
- Evaluating Vulnerability Assessment tools
- Discovering exploit resources
- Attacking with Metasploit
- Discovering filtered ports
- Manipulating ports to gain access
- Connecting to blocked services
- Examining Windows protection modes
- Analyzing Linux/UNIX processes
- Injecting SQL and HTML code
- Hijacking Web sessions by prediction and fixation
- Bypassing authentication mechanisms
- Poisoning DNS
- Executing Cross-site scripting (XSS)
- Gaining control of browsers
- Harvesting client information
- Enumerating internal data
- Selecting reverse or bind shells
- Leveraging the Metasploit Meterpreter
- Deploying portable media attacks
- Routing through compromised clients
- Forwarding and redirecting ports
- Stealing password hashes
- Extracting infrastructure routing, DNS and NetBIOS data
- Controlling memory processes
- Utilizing the remote file system
- Obfuscating vectors and payloads
- Side-stepping perimeter defenses
- Falsifying file headers to inject malware
- Discovering the gaps in antivirus protection
- Hooking APIs and virtualizing malware
- Controlling memory and execution with Direct Kernel Object Manipulation (DKOM)
- Reporting results and creating an action plan
- Managing patches and configuration
- Recommending defensive countermeasures
- Staying current with tools, trends and technology
|
Related Courses
|
|
|
|
 |
|
|