What to bring?
Just bring your laptop. All necessary equipment will be provided including wired/wireless network connection, tools and utilities.
Computer attackers continue the relentless march in improving their tools and techniques. The simple scanning of yesteryear has given way to powerful suites of bundled, automated scanning and exploitation tools. Straightforward backdoors have evolved into powerful kernel-mode RootKits, manipulating the very hearts of our systems. Covert channels exfiltrate sensitive information and hash collision attacks are rapidly advancing, with your systems in the cross hairs. In all of these trends, thorough reconnaissance and deep subterfuge dominate the attackers' game.
If we don't keep up with their latest methods, our overall defenses and incident response practices will grow rusty. To help fight back, this action-packed four-day course describes these latest attack trends and what you can do to thwart the bad guys.
This course is more detailed and hands-on oriented of our popular Cutting-edge Hacking Techniques course. It will provide you with up-to-date knowledge on the latest hackers techniques and protection technologies. In addition to detailed descriptions of how the attacks function, you'll get hands-on experience with the tools and their defenses.
Sample topics include:
- Advanced network reconnaissance including stealth scans and identification of services running on non-standard ports
- Enumerating information from Windows hosts
- Late-breaking Nmap features - hands-on
- Assessing and Penetrating Windows® & Unix® networks and hosts
- Linking Windows and Unix vulnerabilities for maximum impact
- New Metasploit modules, including the Meterpreter and SAM Juicer – hands-on
- Rolling together recon, scanning, and exploitation with BiDiBLAH
- New Google search techniques for finding vulnerable systems
- IPS Fingerprinting
- Virtual Machine Detection
- Recent application-mode, user-mode and kernel-mode RootKits for Windows® and UNIX®, including Hacker Defender and Nushu
- Compilation and test of malicious Linux® Kernel Modules
- Client-side Attacks
- Layer 2 attacks via STP, DTP, and CDP with Yersinia
- Monitoring switched networks using arp spoofing and other techniques
- The dangers and detection of covert channels are explored using ICMP, UDP, TCP and HTTP protocols
- SQL hacking methodologies
- Buffer Overflow - hands on!
- Securing Windows & Unix hosts
- Advanced UNIX® configuration techniques
- Techniques attackers use to steal a million credit cards, and how to stop them
Hands-on include:
- Evolution
- Nmap
- Xprobe
- Hping2
- Nessus
- Metasploit
- BiDiBLAH
- Ettercap
- Whireshark
- Tcpdump
- Snort
- and many more...!
What Do I Get?
You get more than just knowledge of the latest tricks and techniques. You take home the following stuff:
- Certificate of Completion
- A bootable BackTrack(tm) distribution - BackTrack is the Top rated Linux live distribution focused on penetration testing. The merging of two very popular distributions (Whax and Auditor Security Collection) has catapulted BackTrack to the #1 spot on the "Top 100 Network Security Tools" list - http://sectools.org.!
Who Should Take the Course?
If you are a web application developer, system or network administrator, security personnel, auditor, and/or consultant concerned with network and system security, then you should take this course. Trainers:
Faiz Ahmad Shuja, CISSP, GCIH, GSEC
Faiz is a security expert and seasoned entrepreneur. He brings a tremendous amount of designing, implementing, and managing secure infrastructure expertise. He has been involved in intrusion detection/prevention systems, firewalls, honeypots/honeynets, penetration testing, vulnerability analysis, incident handing, and forensics analysis. His specific research interests include enterprise security monitoring, data analysis and security auditing. He is currently the CEO of Rewterz, which offers security consulting and managed security services. Faiz was the Senior Information Security Consultant for Cyber Internet Services (Pvt.) Ltd, Pakistan's largest ISP. The focus of his position was on information security system management and network infrastructure protection. Faiz also designed their Information Security Management System (ISMS) based on BS7799 guidelines and standards. Faiz is the Founder of Pakistan Honeynet Project, a non-profit, all-volunteer organization dedicated to Honeynet research. Pakistan Honeynet Project's goal is to learn and raise awareness about the motives and tactics of the Black Hat community targeting Pakistan's networks. Its aim is to share and dissipate knowledge about the various tools and hacker practices in use on the Internet today. Faiz is also the President of PAKCON, a non-profit organization which organizes yearly cyber security conventions in Pakistan. PAKCON is the brainchild of a group of capable security professionals who have employed their genius and aptitude to provide an overall extensive and comprehensive experience of information security in the form of a wide-ranging convention on information security. Faiz holds a Bachelors degree in Computer Science from the University of Karachi, GIAC Security Essentials (GSEC), GIAC Certified Incident Handler (GCIH) and Certified Information System Security Professional (CISSP) certifications. Muhammad Omar Khan, CISSP
Omar has been involved in the field of information security for past four years. His core competencies include information security management and best practices, intrusion detection systems, firewalls, honeynets, vulnerability assessment and penetration testing. He also has extensive programming experience in C, C++, PHP and C#.
He is a solution-oriented security specialist with notable success directing a broad range of corporate IT initiatives while participating in planning, analysis and implementation of information security and other solutions in direct support of business objectives. Omar is currently the CTO of Rewterz, which offers security consulting and managed security services. Prior to joining Rewterz, he was System Security Engineer for Cyber Internet Services (Pvt.) Ltd, Pakistan's largest ISP. Omar holds a Bachelors degree in Computer Science from Sir Syed University of Engineering and Technology and Certified Information System Security Professional (CISSP) certification. He is also an active member of Pakistan Honeynet Project and PAKCON. Muhammad Ahmed Siddiqui, CISSP
Ahmed has been involved in the field of information security for past four years now and has extensive experience in penetration testing, application vulnerability assessment, exploit coding and vulnerability research. He also has broad programming experience in C, VB, ASP, ASP .NET, Java and HTML.
Ahmed is currently working as Chief Architect at Rewterz, which offers security consulting and managed security services. Ahmed is the lead developer of Rewterz's managed security services' platform, Spleen. Ahmed holds a Bachelors degree in Computer Science from Sir Syed University of Engineering and Technology and Certified Information System Security Professional (CISSP) certification. He is also an active member of Pakistan Honeynet Project and PAKCON. Course Length:
Two days. All course materials, lunch and two tea breaks will be provided. A Certificate of Completion will be offered.
|