EC-Council Certified Security Analyst (ECSA)

Similar documents
EC-Council Certified Security Analyst / License Penetration Tester (ECSA/LPT) v4.0 Bootcamp

Course Title: Penetration Testing: Security Analysis

Networking: EC Council Network Security Administrator NSA

Overview of Network Security The need for network security Desirable security properties Common vulnerabilities Security policy designs

Securing Cisco Network Devices (SND)

General Network Security

CYBERTRON NETWORK SOLUTIONS

NETWORK SECURITY (W/LAB) Course Syllabus

Linux Network Security

EC-Council Certified Security Analyst (ECSA)

WiFi Security Assessments

CRYPTUS DIPLOMA IN IT SECURITY

Build Your Own Security Lab

WLAN Attacks. Wireless LAN Attacks and Protection Tools. (Section 3 contd.) Traffic Analysis. Passive Attacks. War Driving. War Driving contd.

CYBER ATTACKS EXPLAINED: PACKET CRAFTING

COURSE NAME: INFORMATION SECURITY INTERNSHIP PROGRAM

How To Classify A Dnet Attack

Overview. Securing TCP/IP. Introduction to TCP/IP (cont d) Introduction to TCP/IP

WIRELESS SECURITY. Information Security in Systems & Networks Public Development Program. Sanjay Goel University at Albany, SUNY Fall 2006

CS5008: Internet Computing

Certified Ethical Hacker Exam Version Comparison. Version Comparison

Certified Ethical Hacker (CEH)

Professional Penetration Testing Techniques and Vulnerability Assessment ...

National Cyber League Certified Ethical Hacker (CEH) TM Syllabus

Information Security. Training

CH ENSA EC-Council Network Security Administrator Detailed Course Outline

Hackers are here. Where are you?

Topics in Network Security

Venue. Dates. Certified Ethical Hacker (CEH) boot camp. Inovatec College. Nairobi Kenya (exact hotel name to be confirmed

20-CS X Network Security Spring, An Introduction To. Network Security. Week 1. January 7

Developing Network Security Strategies


EC-Council Network Security Administrator (ENSA) Duration: 5 Days Method: Instructor-Led

Wireless Networks. Welcome to Wireless

Architecture Overview

PwC. Outline. The case for wireless networking. Access points and network cards. Introduction: OSI layers and 802 structure

Exam Questions SY0-401

Course Content Summary ITN 261 Network Attacks, Computer Crime and Hacking (4 Credits)

Network Security and Firewall 1

Session Hijacking Exploiting TCP, UDP and HTTP Sessions

Presented By: Holes in the Fence. Agenda. IPCCTV Attack. DDos Attack. Why Network Security is Important

National Cyber League Certified Ethical Hacker (CEH) TM Syllabus

If you know the enemy and know yourself, you need not fear the result of a hundred battles.

Certified Ethical Hacker (CEH) Ethical Hacking & Counter Measures Course 9962; 5 Days, Instructor-Led

Introduction to Intrusion Detection and Snort p. 1 What is Intrusion Detection? p. 5 Some Definitions p. 6 Where IDS Should be Placed in Network

Guide to Network Defense and Countermeasures Third Edition. Chapter 2 TCP/IP

Security Awareness. Wireless Network Security

Securing Networks with PIX and ASA

FRONT RUNNER DIPLOMA PROGRAM INFORMATION SECURITY Detailed Course Curriculum Course Duration: 6 months

12/3/08. Security in Wireless LANs and Mobile Networks. Wireless Magnifies Exposure Vulnerability. Mobility Makes it Difficult to Establish Trust

Virtual private network. Network security protocols VPN VPN. Instead of a dedicated data link Packets securely sent over a shared network Internet VPN

Intrusion Detection System Based Network Using SNORT Signatures And WINPCAP

Computer Forensics Training - Digital Forensics and Electronic Discovery (Mile2)

Learn Ethical Hacking, Become a Pentester

Hackers are here. Where are you?

EC Council Security Analyst (ECSA)

Firewalls. Chapter 3

1. LAB SNIFFING LAB ID: 10

Introduction on Low level Network tools

Securing end devices

Hands-on Network Traffic Analysis Cyber Defense Boot Camp

information security and its Describe what drives the need for information security.

Post-Class Quiz: Telecommunication & Network Security Domain

Internet Firewall CSIS Internet Firewall. Spring 2012 CSIS net13 1. Firewalls. Stateless Packet Filtering

Intrusion Detection and Prevention: Network and IDS Configuration and Monitoring using Snort

Certified Wireless Security Professional (CWSP) Course Overview

HONEYD (OPEN SOURCE HONEYPOT SOFTWARE)

Network Security Administrator

Wireless Threats To Corporate Security A Presentation for ISACA UK Northern Chapter

Network Attacks and Defenses

WHITE PAPER. FortiGate DoS Protection Block Malicious Traffic Before It Affects Critical Applications and Systems

Some Tools for Computer Security Incident Response Team (CSIRT)

7 Network Security. 7.1 Introduction 7.2 Improving the Security 7.3 Internet Security Framework. 7.5 Absolute Security?

Security of IPv6 and DNSSEC for penetration testers

SY system so that an unauthorized individual can take over an authorized session, or to disrupt service to authorized users.

Detailed Description about course module wise:

BASIC ANALYSIS OF TCP/IP NETWORKS

APNIC elearning: Network Security Fundamentals. 20 March :30 pm Brisbane Time (GMT+10)

Cryptography and network security

Table of Contents. Cisco Wi Fi Protected Access 2 (WPA 2) Configuration Example

Ethical Hacking and Information Security. Foundation of Information Security. Detailed Module. Duration. Lecture with Hands On Session: 90 Hours

Demystifying Penetration Testing for the Enterprise. Presented by Pravesh Gaonjur

- Basic Router Security -

When a student leaves this intensive 5 day class they will have hands on understanding and experience in Ethical Hacking.

a) Encryption is enabled on the access point. b) The conference room network is on a separate virtual local area network (VLAN)

Lab VI Capturing and monitoring the network traffic

Network Security. Tampere Seminar 23rd October Overview Switch Security Firewalls Conclusion

The following chart provides the breakdown of exam as to the weight of each section of the exam.

ITEC441- IS Security. Chapter 15 Performing a Penetration Test

Information Technology Career Cluster Introduction to Cybersecurity Course Number:

Lecture Objectives. Lecture 8 Mobile Networks: Security in Wireless LANs and Mobile Networks. Agenda. References

Firewalls, Tunnels, and Network Intrusion Detection. Firewalls

Overview. Summary of Key Findings. Tech Note PCI Wireless Guideline

Chapter 1 Network Security

Hacking. Aims. Naming, Acronyms, etc. Sources

Interconnecting Cisco Networking Devices, Part 1 (ICND1) v3.0

AIRDEFENSE SOLUTIONS PROTECT YOUR WIRELESS NETWORK AND YOUR CRITICAL DATA SECURITY AND COMPLIANCE

Network Access Security. Lesson 10

INFORMATION SECURITY TRAINING CATALOG (2015)

Transcription:

Page 1 Certified Security Analyst (ECSA)

Page 2 Introduction Certified Security Analyst (ECSA) complements the Certified Ethical Hacker (CEH) certification by exploring the analytical phase of ethical hacking. While CEH exposes the learner to hacking tools and technologies, ECSA takes it a step further by exploring how to analyze the outcome from these tools and technologies. Through groundbreaking penetration testing methods and techniques, ECSA class helps students perform the intensive assessments required to effectively identify and mitigate risks to the security of the infrastructure. This makes ECSA a relevant milestone towards achieving s Licensed penetration Tester, which also ingrains the learner in the business aspect of penetration testing. The Licensed Penetration Tester standardizes the knowledge base for penetration testing professionals by incorporating the best practices followed by experienced experts in the field. The objective of Certified Security Analyst is to add value to experienced security professionals by helping them analyze the outcomes of their tests. ECSA leads the learner into the advanced stages of ethical hacking. Advanced Penetration Testing and Security Analysis The ECSA/LPT training program is a highly interactive 5-day security class designed to teach Security Professionals the advanced uses of the available methodologies, tools and techniques required to perform comprehensive information security tests. Students will learn how to design, secure and test networks to protect your organization from the threats hackers and crackers pose. By teaching the LPT methodology and ground breaking techniques for security and penetration testing, this class will help you perform the intensive assessments required to effectively identify and mitigate risks to the security of your infrastructure. As students learn to identify security problems, they also learn how to avoid and eliminate them, with the class providing complete coverage of analysis and network security-testing topics.

Requirements Pass exam 412-79 to achieve Certified Security Analyst (ECSA) certification. Benefits ECSA is for experienced hands in the industry and is backed by a curriculum designed by the best in the field. Greater industry acceptance as seasoned security professional. Learn to analyze the outcomes from using security tools and security testing techniques. Requirement for the LPT certification.certification Page 3 Exam Students will be prepared for s ECSA exam 412-79 on the last day of the class. This certification is also pre-requisite to s Licensed Penetration Tester Program. Frequently Asked Questions 1. How does ECSA deliver value to a security professional like me? ECSA teaches you to interpret and analyze outcomes you come across during routine and exceptional security testing. It helps you analyze the symptoms and pin point the causes of those symptoms which reflect the security posture of the network. 2. Why should I take ECSA when I am already certified as a security professional? Most security certifications highlight the management aspects or the technical aspects alone. ECSA helps you bridge the gap to a certain extent by helping you detect the causes of security lapses and what implications it might carry for the management. This leads you to a step closer to becoming a licensed penetration tester, where you become a complete penetration testing professional. 3. How does ECSA deliver value to the enterprise s security team? Having an ECSA on your enterprise security team will enhance value to the team as you would have a professional aboard who is exposed to advanced security testing and proficient to make studied analysis of the situation. 4. How is ECSA different from CEH? CEH exposes the learner to various hacking tools and techniques, while ECSA exposes the learner to the analysis and interpretation of results obtained from using those tools and techniques. 5. I have over three years experience in the industry. Should I opt for ECSA instead of CEH? ECSA is not a replacement for CEH. CEH provides the learner with the foundation ground over which you can fortify your skills using knowledge gained from ECSA

6. How long is the training? The ECSA and LPT training are combined into a single ECSA/LPT Certification Boot camp class. The duration of this boot camp is 5 days. You will be prepared for ECSA and LPT certification at the end of this class. 7. What is the cost of the exam? The ECSA exam costs USD 300.00 Page 4 Course Description ECSA/LPT is a security class like no other! Providing real world hands on experience, it is the only indepth Advanced Hacking and Penetration Testing class available that covers testing in all modern infrastructures, operating systems and application environments. s Certified Security Analyst/LPT program is a highly interactive 5-day security class designed to teach Security Professionals the advanced uses of the LPT methodologies, tools and techniques required to perform comprehensive information security tests. Students will learn how to design, secure and test networks to protect your organization from the threats hackers and crackers pose. By teaching the tools and ground breaking techniques for security and penetration testing, this class will help you perform the intensive assessments required to effectively identify and mitigate risks to the security of your infrastructure. As students learn to identify security problems, they also learn how to avoid and eliminate them, with the class providing complete coverage of analysis and network security-testing topics. Who Should Attend Network server administrators, Firewall Administrators, Security Testers, System Administrators and Risk Assessment professionals. Duration: 5 days (9:00 5:00) Certification

Course Outline v3 ECSA/LPT Certification Bootcamp Module 1: The Need for Security Analysis What Are We Concerned About? So What Are You Trying To Protect? Why Are Intrusions So Often Successful? What Are The Greatest Challenges? Environmental Complexity New Technologies New Threats, New Exploits Limited Focus Limited Expertise Authentication Authorization Confidentiality Integrity Availability Nonrepudiation We Must Be Diligento:p> Threat Agents Assessment Questions How Much Security is Enough? Risk Simplifying Risk Risk Analysis Risk Assessment Answers Seven Questions Steps of Risk Assessment Risk Assessment Values Information Security Awareness Security policies Types of Policies Promiscuous Policy Permissive Policy Page 5

Page 6 Prudent Policy Paranoid Policy Acceptable-Use Policy User-Account Policy Remote-Access Policy Information-Protection Policy Firewall-Management Policy Special-Access Policy Network-Connection Policy Business-Partner Policy Other Important Policies Policy Statements Basic Document Set of Information Security Policies ISO 17799 Domains of ISO 17799 No Simple Solutions U.S. Legislation California SB 1386 Sarbanes-Oxley 2002 Gramm-Leach-Bliley Act (GLBA) Health Insurance Portability and Accountability Act (HIPAA) USA Patriot Act 2001 U.K. Legislation How Does This Law Affect a Security Officer? The Data Protection Act 1998 The Human Rights Act 1998 Interception of Communications The Freedom of Information Act 2000 The Audit Investigation and Community Enterprise Act 2005 Module 2: Advanced Googling Site Operator intitle:index.of error warning login logon username userid employee.id your username is password passcode your password is

admin administrator admin login ext:html ext:htm ext:shtml ext:asp ext:php inurl:temp inurl:tmp inurl:backup inurl:bak intranet help.desk Locating Public Exploit Sites Locating Exploits Via Common Code Strings Searching for Exploit Code with Nonstandard Extensions Locating Source Code with Common Strings Locating Vulnerable Targets Locating Targets Via Demonstration Pages Powered by Tags Are Common Query Fodder for Finding Web Applications Locating Targets Via Source Code Vulnerable Web Application Examples Locating Targets Via CGI Scanning A Single CGI Scan-Style Query Directory Listings Finding IIS 5.0 Servers Web Server Software Error Messages IIS HTTP/1.1 Error Page Titles Object Not Found Error Message Used to Find IIS 5.0 Apache Web Server Apache 2.0 Error Pages Application Software Error Messages ASP Dumps Provide Dangerous Details Many Errors Reveal Pathnames and Filenames CGI Environment Listings Reveal Lots of Information Default Pages A Typical Apache Default Web Page Locating Default Installations of IIS 4.0 on Windows NT 4.0/OP Default Pages Query for Web Server Outlook Web Access Default Portal Searching for Passwords Windows Registry Entries Can Reveal Passwords Usernames, Cleartext Passwords, and Hostnames! Page 7

Page 8 Module III: TCP/IP Packet Analysis TCP/IP Model Application Layer Transport Layer Internet Layer Network Access Layer Comparing OSI and TCP/IP Addressing IPv4 Addresses IP Classes of Addresses Reserved IP Addresses Private Addresses Subnetting IPv4 and IPv6 Transport Layer Flow Control Three-Way Handshake TCP/IP Protocols TCP Header IP Header IP Header: Protocol Field UDP TCP and UDP Port Numbers Port Numbers TCP Operation Synchronization or 3-way Handshake Denial of Service (DoS) Attacks DoS Syn Flooding Attack Windowing Acknowledgement Windowing and Window Sizes Simple Windowing Sliding Windows Sequencing Numbers Positive Acknowledgment and Retransmission (PAR) UDP Operation Port Numbers Positioning between Transport and Application Layer (TCP and UDP)

Port Numbers http://www.iana.org/assignments/port-numbers What Makes Each Connection Unique? Internet Control Message Protocol (ICMP) Error Reporting and Error Correction ICMP Message Delivery Format of an ICMP Message Unreachable Networks Destination Unreachable Message ICMP Echo (Request) and Echo Reply Detecting Excessively Long Routes IP Parameter Problem ICMP Control Messages ICMP Redirects Clock Synchronization and Transit Time Estimation Information Requests and Reply Message Formats Address Masks Router Solicitation and Advertisement Page 9 Module 4: Advanced Sniffing Techniques What is Wireshark? Wireshark: Filters IP Display Filters Example Wireshark: Tshark Wireshark: Editcap Wireshark: Mergecap Wireshark: Text2pcap Using Wireshark for Network Troubleshooting Network Troubleshooting Methodology Using Wireshark for System Administration ARP Problems ICMP Echo Request/Reply Header Layout TCP Flags TCP SYN Packet Flags Bit Field Capture Filter Examples Scenario 1: SYN no SYN+ACK

Page 10 Scenario 2: SYN Immediate Response RST Scenario 3: SYN SYN+ACK ACK Using Wireshark for Security Administration Detecting Internet Relay Chat Activity Wireshark as a Detector for Proprietary Information Transmission Sniffer Detection Wireless Sniffing with Wireshark AirPcap Using Channel Hopping Interference and Collisions Recommendations for Sniffing Wireless Analyzing Wireless Traffic IEEE 802.11 Header IEEE 802.11 Header Fields Filters Filtering on Source MAC Address and BSSID Filtering on BSSID Filter on SSID Wireless Frame Types Filters Unencrypted Data Traffic Identifying Hidden SSIDs Revealed SSID Identifying EAP Authentication Failures Identifying the EAP Type Identifying Key Negotiation Properties EAP Identity Disclosure Identifying WEP Identifying TKIP and CCMP Identifying IPSec/VPN Decrypting Traffic Scanning TCP Connect Scan SYN Scan XMAS Scan Null Scan Remote Access Trojans NetBus Analysis

Trojan Analysis Example NetBus Analysis Module 5: Vulnerability Analysis with Nessus Nessus Features of Nessus Nessus Assessment Process Nessus: Scanning Nessus: Enumeration Nessus: Vulnerability Detection Configuring Nessus Updating Nessus Plug-Ins Using the Nessus Client Starting a Nessus Scan Generating Reports Data Gathering Host Identification Port Scan SYN scan Timing Port Scanning Rules of Thumb Plug-in Selection Dangerous plugins Scanning Rules of Thumb Report Generation Reports: Result Identifying False Positives Suspicious Signs False Positives Examples of False Positives Writing Nessus Plugins Writing a Plugin Installing and Running the Plugin Nessus Report with output from our plugin Security Center http://www.tenablesecurity.com Page 11

Page 12 Module 6: Advanced Wireless Testing Wireless Concepts Wireless Concepts 802.11 Types Core Issues with 802.11 What s the Difference? Other Types of Wireless Spread Spectrum Background Channels Access Point Service Set ID Default SSIDs Chipsets Wi-Fi Equipment Expedient Antennas Vulnerabilities to 802.1x and RADIUS Wired Equivalent Privacy Security - WEP Wired Equivalent Privacy Exclusive OR Encryption Process Chipping Sequence WEP Issues WEP - Authentication Phase WEP - Shared Key Authentication WEP - Association Phase WEP Flaws WEP Attack WEP: Solutions WEP Solution 802.11i Wireless Security Technologies WPA Interim 802.11 Security WPA 802.1X Authentication and EAP EAP Types Cisco LEAP TKIP (Temporal Key Integrity Protocol)

Wireless Networks Testing Wireless Communications Testing Report Recommendations Wireless Attack Countermeasures Wireless Penetration Testing with Windows Attacks And Tools War Driving The Jargon WarChalking WarPumpkin Wireless: Tools of the Trade Mapping with Kismet WarDriving with NetStumbler How NetStumbler Works? Active versus Passive WLAN Detection Disabling the Beacon Running NetStumbler Captured Data Using NetStumbler Filtering by Channels Airsnort WEPCrack Monkey-Jack How Monkey-Jack Works Before Monkey-Jack After Monkey-Jack AirCrack-ng How Does It Work? FMS and Korek Attacks Crack WEP Available Options Usage Examples Cracking WPA/WPA2 Passphrases Notes Determining Network Topology: Network View WarDriving and Wireless Penetration Testing with OS X What is the Difference between Active and Passive Sniffing? Using a GPS Attacking WEP Encryption with KisMAC Page 13

Page 14 Deauthenticating Clients Attacking WPA with KisMAC Brute-force Attacks Against 40-bit WEP Wordlist Attacks Mapping WarDrives with StumbVerter MITM Attack basics MITM Attack Design MITM Attack Variables Hardware for the Attack Antennas, Amps, WiFi Cards Wireless Network Cards Choosing the Right Antenna Amplifying the Wireless Signal Identify and Compromise the Target Access Point Compromising the Target Crack the WEP key Aircrack-ng Cracked the WEP Key The MITM Attack Laptop Configuration IP Forwarding and NAT Using Iptables Installing Iptables and IP Forwarding Establishing the NAT Rules Dnsmasq Configuring Dnsmasq Apache Web Servers Virtual Directories Clone the Target Access Point and Begin the Attack Start the Wireless Interface Deauthenticate Clients Connected to the Target Access Point Wait for the Client to Associate to Your Access Point Spoof the Application Modify the Page Example Page Login/php page Redirect Web Traffic Using Dnsmasq Module 7: Designing a DMZ Introduction DMZ Concepts

Multitiered Firewall With a DMZ Flow DMZ Design Fundamentals Advanced Design Strategies Designing Windows DMZ Designing Windows DMZ Precautions for DMZ Setup Security Analysis for the DMZ Designing Sun Solaris DMZ Placement of Servers Advanced Implementation of a Solaris DMZ Server Solaris DMZ Servers in a Conceptual Highly Available Configuration Private and Public Network Firewall Ruleset DMA Server Firewall Ruleset Solaris DMZ System Design Disk Layout and Considerations Designing Wireless DMZ Placement of Wireless Equipment Access to DMZ and Authentication Considerations Wireless DMZ Components Wireless DMZ Using RADIUS to Authenticate Users WLAN DMZ Security Best-Practices DMZ Router Security Best-Practice DMZ Switch Security Best-Practice Six Ways to Stop Data Leaks Reconnex Page 15 Module 8: Snort Analysis Snort Overview Modes of Operation Features of Snort Configuring Snort Variables Preprocessors Output Plugins Rules Working of Snort Initializing Snort

Page 16 Signal Handlers Parsing the Configuration File Decoding Possible Decoders Preprocessing Detection Content Matching Content-Matching Functions The Stream4 Preprocessor Inline Functionality Writing Snort Rules Snort Rule Header Snort Rule Header: Actions Snort Rule Header: Other Fields IP Address Negation Rule IP Address Filters Port Numbers Direction Operator Rule Options Activate/Dynamic Rules Meta-Data Rule Options: msg Reference Keyword sid/rev Keyword Classtype Keyword Payload Detection Rule Options: content Modifier Keywords Offset/depth Keyword Uricontent keyword fragoffset keyword ttl keyword id keyword flags keyword itype keyword : icmp id Writing Good Snort Rules Sample Rule to Catch Metasploit Buffer Overflow Exploit Tool for writing Snort rules: IDS Policy Manager Subscribe to Snort Rules

Honeynet Security Console Tool Key Features Module 9: Log Analysis Introduction to Logs Types of Logs Events that Need to be Logged What to Look Out For in Logs W3C Extended Log File Format Automated Log Analysis Approaches Log Shipping Analyzing Syslog Syslog Setting up a Syslog Syslog: Enabling Message Logging Main Display Window Configuring Kiwi Syslog to Log to a MS SQL Database Configuring Ethereal to Capture Syslog Messages Sending Log Files via email Configuring Cisco Router for Syslog Configuring DLink Router for Syslog Configuring Cisco PIX for Syslog Configuring an Intertex / Ingate/ PowerBit/ SurfinBird ADSL router Configuring a LinkSys wireless VPN Router Configuring a Netgear ADSL Firewall Router Analyzing Web Server Logs Apache Web Server Log AWStats Configuring AWStats for IIS Log Processing in AWStats Analyzing Router Logs Router Logs Analyzing Wireless Network Devices Logs Wireless Traffic Log Analyzing Windows Logs Configuring Firewall Logs in Local Windows System Viewing Local Windows Firewall Log Page 17

Page 18 Viewing Windows Event Log AAnalyzing Linux Logs iptables Log Prefixing with iptables Firewall Log Analysis with grep Analyzing SQL Server Logs SQL Database Log ApexSQL Log Configuring ApexSQL Log Analyzing VPN Server Logs VPN Client Log Analyzing Firewall Logs Why Firewall Logs are Important Firewall Log Sample ManageEngine Firewall Analyzer Installing Firewall Analyzer Viewing Firewall Analyzer Reports Firewall Analyzer Log Reports Analyzing IDS Logs SnortALog IDS Log Sample Analyzing DHCP Logs DHCP Log NTP Configuration Time Synchronization and Logging NTP Overview NTP Client Configuration Configuring an NTP client using the Client Manager Configuring an NTP Server NTP: Setting Local Date and Time Log Analysis Tools All-Seeing Eye Tool: Event Log Tracker Network Sniffer Interface Test Tool Syslog Manager 2.0.1 Sawmill WALLWATCHER Log Alert Tools

Network Eagle Monitor Network Eagle Monitor: Features SQL Server Database Log Navigator What Log Navigator does? How Does Log Navigator Work? Snortsnarf Types of Snort Alarms ACID (Analysis Console for Intrusion Databases) Page 19 Module 10: Advanced Exploits and Tools Common Vulnerabilities Buffer Overflows Revisited Smashing the Stack for Fun and Profit Smashing the Heap for Fun and Profit Format Strings for Chaos and Mayhem The Anatomy of an Exploit Vulnerable code Shellcoding Shellcode Examples Delivery Code Delivery Code: Example Linux Exploits Versus Windows Windows Versus Linux Tools of the Trade: Debuggers Tools of the Trade: GDB Tools of the Trade: Metasploit Metasploit Frame work User-Interface Modes Metasploit: Environment Environment: Global Environment Environment: Temporary Environment Metasploit: Options Metasploit: Commands Metasploit: Launching the Exploit MetaSploit: Advanced Features Tools of the Trade: Canvas Tools of the Trade: CORE Impact

IMPACT Industrializes Penetration Testing Ways to Use CORE IMPACT Other IMPACT Benefits ANATOMY OF A REAL-WORLD ATTACK CLIENT SIDE EXPLOITS Impact Demo Lab Page 20 Module 11: Penetration Testing Methodologies Module 12: Customers and Legal Agreements Module 13: Penetration Testing Planning and Scheduling Module 14: Pre Penetration Testing Checklist Module 15: Information Gathering Module 16: Vulnerability Analysis Module 17: External Penetration Testing Module 18: Internal Network Penetration Testing Module 19: Router Penetration Testing Module 20: Firewall Penetration Testing Module 21: IDS Penetration Testing Module 22: Wireless Network Penetration Testing Module 23: Denial of Service Penetration Testing Module 24: Password Cracking Penetration Testing Module 25: Social Engineering Penetration Testing Module 26: Stolen Laptop Penetration Testing Module 27: Application Penetration Testing Module 28: Physical Security Penetration Testing Module 29: Database Penetration testing Module 30: VoIP Penetration Testing Module 31: VPN Penetration Testing Module 32: Penetration Testing Report Analysis Module 33: Penetration Testing Report and Documentation Writing Module 34: Penetration Testing Deliverables and Conclusion Module 35: Ethics of a Licensed Penetration Tester

Page 21 2007. All rights reserved. This document is for informational purposes only. MAKES NO WARRANTIES, EX- PRESS OR IMPLIED, IN THIS SUMMARY. logo is registered trademarks or trademarks of in the United States and/or other countries.