Slogan
: Our Aim & Mission as a Organization to Promote Information Technology Education into Women's
; Teach , Train & Employee them in various Schools , Govt. Colleges
, Banks & Different Industries.
Student Shelter In Computers , EC-Council Academic Partner
EC-Council Academic Partner Lahore
Pakistan Offer’s Low Cost Certification & Coaching / Training for Students &
Professionals
Certified Ethical Hacker CEH Course Outline
ØModule 01: Introduction to Ethical Hacking
ØModule 02: Footprinting and Reconnaissance
ØModule 03: Scanning Networks
ØModule 04: Enumeration
ØModule 05: System Hacking
ØModule 06: Trojans and Backdoors
ØModule 07: Viruses and Worms
ØModule 08: Sniffers
ØModule 09: Social Engineering
ØModule 10: Denial of Service
ØModule 11: Session Hijacking
ØModule 12: Hijacking Webservers
ØModule 13: Hacking Web Applications
ØModule 14: SQL Injection
ØModule 15: Hacking Wireless Networks
ØModule 16: Evading IDS, Firewalls, and Honeypots
ØModule 17: Buffer Overflow
ØModule 18: Cryptography
ØModule 19: Penetration Testing
Student
Shelter In Computers ® EC-Council Academic Partner
Abbas Shahid Baqir (Director)
H. No 18 Sardar St College road New Samanabad Lahore Pakistan
Cell: 0300-4738405, E-mail :
stscomps@yahoo.com Web:
http://www.stscomps.com
This class will immerse the students into an interactive environment where they
will be shown how to scan, test, hack and secure their own systems. The lab
intensive environment gives each student in-depth knowledge and practical
experience with the current essential security systems. Students will begin by
understanding how perimeter defenses work and then be lead into scanning and
attacking their own networks, no real network is harmed. Students then learn how
intruders escalate privileges and what steps can be taken to secure a system.
Students will also learn about Intrusion Detection, Policy Creation, Social
Engineering, DDoS Attacks, Buffer Overflows and Virus Creation. When a student
leaves this intensive 5 day class they will have hands on understanding and
experience in Ethical Hacking. This course prepares you for EC-Council Certified
Ethical Hacker exam 312-50
Who Should Attend
This course will significantly benefit security officers, auditors, security
professionals, site administrators, and anyone who is concerned about the
integrity of the network infrastructure. Certification
The Certified Ethical Hacker exam 312-50 may be taken on the last day of the
training (optional). Students need to pass the online Prometric exam to receive
CEH certification.
Legal Agreement
Ethical Hacking and Countermeasures course mission is to educate, introduce and
demonstrate hacking tools for penetration testing purposes only. Prior to
attending this course, you will be asked to sign an agreement stating that you
will not use the newly acquired skills for illegal or malicious attacks and you
will not use such tools in an attempt to compromise any computer system, and to
indemnify EC-Council with respect to the use or misuse of these tools,
regardless of intent.
Not anyone can be a student — the Accredited
Training Centers (ATC) will make sure the applicants work for legitimate
companies.
Course Outline Version
7
CEHv7 Curriculum consists of instructor-led training and self-study. The
Instructor will provide the details of self-study modules to the students
beginning of the class.
Module 01: Introduction to Ethical Hacking
Internet Crime Current Report: IC3
Data Breach Investigations Report
Types of Data Stolen From the Organizations
Essential Terminologies
Elements of Information Security
Authenticity and Non-Repudiation
The Security, Functionality, and Usability
Triangle
Security Challenges
Effects of Hacking
Effects of Hacking on Business
Who is a Hacker?
Hacker Classes
Hacktivism
What Does a Hacker Do?
Phase 1 - Reconnaissance
Reconnaissance Types
Phase 2 - Scanning
Phase 3 – Gaining Access
Phase 4 – Maintaining Access
Phase 5 – Covering Tracks
Types of Attacks on a System
Operating System Attacks
Application-Level Attacks
Shrink Wrap Code Attacks
Misconfiguration Attacks
Why Ethical Hacking is Necessary?
Defense in Depth
Scope and Limitations of Ethical Hacking
What Do Ethical Hackers Do?
Skills of an Ethical Hacker
Vulnerability Research
Vulnerability Research Websites
What is Penetration Testing?
Why Penetration Testing?
Penetration Testing Methodology
Module 02: Footprinting and Reconnaissance
Footprinting Terminologies
What is Footprinting?
Objectives of Footprinting
Footprinting Threats
Finding a Company’s URL
Locate Internal URLs
Public and Restricted Websites
Search for Company’s Information
Tools to Extract Company’s Data
Footprinting Through Search Engines
Collect Location Information
Satellite Picture of a Residence
People Search
People Search Using http://pipl.com
People Search Online Services
People Search on Social Networking Services
Gather Information from Financial Services
Footprinting Through Job Sites
Monitoring Target Using Alerts
Competitive Intelligence Gathering
Competitive Intelligence-When Did this
Company Begin? How Did it Develop?
Competitive Intelligence-What are the
Company's Plans?
Competitive Intelligence-What Expert Opinion
Say About the Company?
Competitive Intelligence Tools
Competitive Intelligence Consulting
Companies
WHOIS Lookup
WHOIS Lookup Result Analysis
WHOIS Lookup Tools: SmartWhois
WHOIS Lookup Tools
WHOIS Lookup Online Tools
Extracting DNS Information
DNS Interrogation Tools
DNS Interrogation Online Tools
Locate the Network Range
Traceroute
Traceroute Analysis
Traceroute Tool: 3D Traceroute
Traceroute Tool: LoriotPro
Traceroute Tool: Path Analyzer Pro
Traceroute Tools
Mirroring Entire Website
Website Mirroring Tools
Mirroring Entire Website Tools
Extract Website Information from http://www.archive.org
Monitoring Web Updates Using Website Watcher
Tracking Email Communications
Email Tracking Tools
Footprint Using Google Hacking Techniques
What a Hacker Can Do With Google Hacking?
Google Advance Search Operators
Finding Resources using Google Advance
Operator
Google Hacking Tool: Google Hacking Database (GHDB)
Google Hacking Tools
Additional Footprinting Tools
Footprinting Countermeasures
Footprinting Pen Testing
Module 03: Scanning Networks
Network Scanning
Types of Scanning
Checking for Live Systems - ICMP Scanning
Ping Sweep
Ping Sweep Tools
Three-Way Handshake
TCP Communication Flags
Create Custom Packet using TCP Flags
Hping2 / Hping3
Hping Commands
Scanning Techniques
TCP Connect / Full Open Scan
Stealth Scan (Half-open Scan)
Xmas Scan
FIN Scan
NULL Scan
IDLE Scan
IDLE Scan: Step 1
IDLE Scan: Step 2.1 (Open Port)
IDLE Scan: Step 2.2 (Closed Port)
IDLE Scan: Step 3
ICMP Echo Scanning/List Scan
SYN/FIN Scanning Using IP Fragments
UDP Scanning
Inverse TCP Flag Scanning
ACK Flag Scanning
Scanning: IDS Evasion Techniques
IP Fragmentation Tools
Scanning Tool: Nmap
Scanning Tool: NetScan Tools Pro
Scanning Tools
Do Not Scan These IP Addresses (Unless you
want to get into trouble)
Scanning Countermeasures
War Dialing
Why War Dialing?
War Dialing Tools
War Dialing Countermeasures
War Dialing Countermeasures: SandTrap Tool
OS Fingerprinting
Active Banner Grabbing Using Telnet
Banner Grabbing Tool: ID Serve
GET REQUESTS
Banner Grabbing Tool: Netcraft
Banner Grabbing Tools
Banner Grabbing Countermeasures: Disabling or
Changing Banner
Hiding File Extensions
Hiding File Extensions from Webpages
Vulnerability Scanning
Vulnerability Scanning Tool: Nessus
Vulnerability Scanning Tool: SAINT
Vulnerability Scanning Tool: GFI LANGuard
Network Vulnerability Scanners
LANsurveyor
Network Mappers
Proxy Servers
Why Attackers Use Proxy Servers?
Use of Proxies for Attack
How Does MultiProxy Work?
Free Proxy Servers
Proxy Workbench
Proxifier Tool: Create Chain of Proxy Servers
SocksChain
TOR (The Onion Routing)
TOR Proxy Chaining Software
HTTP Tunneling Techniques
Why do I Need HTTP Tunneling?
Super Network Tunnel Tool
Httptunnel for Windows
Additional HTTP Tunneling Tools
SSH Tunneling
SSL Proxy Tool
How to Run SSL Proxy?
Proxy Tools
Anonymizers
Types of Anonymizers
Case: Bloggers Write Text Backwards to Bypass
Web Filters in China
Text Conversion to Avoid Filters
Censorship Circumvention Tool: Psiphon
How Psiphon Works?
How to Check if Your Website is Blocked in
China or Not?
G-Zapper
Anonymizer Tools
Spoofing IP Address
IP Spoofing Detection Techniques: Direct TTL
Probes
IP Spoofing Detection Techniques: IP
Identification Number
IP Spoofing Detection Techniques: TCP Flow
Control Method
Knowledge Required to Program Buffer Overflow
Exploits
Buffer Overflow Steps
Attacking a Real Program
Format String Problem
Overflow using Format String
Smashing the Stack
Once the Stack is Smashed...
Simple Uncontrolled Overflow
Simple Buffer Overflow in C
Code Analysis
Exploiting Semantic Comments in C
(Annotations)
How to Mutate a Buffer Overflow Exploit?
Identifying Buffer Overflows
How to Detect Buffer Overflows in a Program?
BOU (Buffer Overflow Utility)
Testing for Heap Overflow Conditions: heap.exe
Steps for Testing for Stack Overflow in
OllyDbg Debugger
Testing for Stack Overflow in OllyDbg
Debugger
Testing for Format String Conditions using IDA
Pro
BoF Detection Tools
Defense Against Buffer Overflows
Preventing BoF Attacks
Programming Countermeasures
Data Execution Prevention (DEP)
Enhanced Mitigation Experience Toolkit (EMET)
EMET System Configuration Settings
EMET Application Configuration Window
/GS http://microsoft.com
BoF Security Tools
BufferShield
Buffer Overflow Penetration Testing
Module 18: Cryptography
Cryptography
Types of Cryptography
Government Access to Keys (GAK)
Ciphers
Advanced Encryption Standard (AES)
Data Encryption Standard (DES)
RC4, RC5, RC6 Algorithms
The DSA and Related Signature Schemes
RSA (Rivest Shamir Adleman)
Example of RSA Algorithm
The RSA Signature Scheme
Message Digest (One-way Bash) Functions
Message Digest Function: MD5
Secure Hashing Algorithm (SHA)
What is SSH (Secure Shell)?
MD5 Hash Calculators: HashCalc, MD5 Calculator
and HashMyFiles
Cryptography Tool: Advanced Encryption Package
Cryptography Tools
Public Key Infrastructure (PKI)
Certification Authorities
Digital Signature
SSL (Secure Sockets Layer)
Transport Layer Security (TLS)
Disk Encryption
Disk Encryption Tool: TrueCrypt
Disk Encryption Tools
Cryptography Attacks
Code Breaking Methodologies
Brute-Force Attack
Meet-in-the-Middle Attack on Digital Signature
Schemes
Cryptanalysis Tool: CrypTool
Cryptanalysis Tools
Online MD5 Decryption Tool
Module 19: Penetration Testing
Introduction to Penetration Testing
Security Assessments
Vulnerability Assessment
Limitations of Vulnerability Assessment
Penetration Testing
Why Penetration Testing?
What Should be Tested?
What Makes a Good Penetration Test?
ROI on Penetration Testing
Testing Points
Testing Locations
Types of Penetration Testing
External Penetration Testing
Internal Security Assessment
Black-box Penetration Testing
Grey-box Penetration Testing
White-box Penetration Testing
Announced / Unannounced Testing
Automated Testing
Manual Testing
Common Penetration Testing Techniques
Using DNS Domain Name and IP Address
Information
Enumerating Information about Hosts on
Publicly-Available Networks
Phases of Penetration Testing
Pre-Attack Phase
Attack Phase
Activity: Perimeter Testing
Enumerating Devices
Activity: Acquiring Target
Activity: Escalating Privileges
Activity: Execute, Implant, and Retract
Post-Attack Phase and Activities
Penetration Testing Deliverable Templates
Penetration Testing Methodology
Application Security Assessment
Web Application Testing - I
Web Application Testing - II
Web Application Testing - III
Network Security Assessment
Wireless/Remote Access Assessment
Wireless Testing
Telephony Security Assessment
Social Engineering
Testing Network-Filtering Devices
Denial of Service Emulation
Outsourcing Penetration Testing Services
Terms of Engagement
Project Scope
Pentest Service Level Agreements
Penetration Testing Consultants
Evaluating Different Types of Pentest Tools
Application Security Assessment Tool
Webscarab
Network Security Assessment Tool
Angry IP scanner
GFI LANguard
Wireless/Remote Access Assessment Tool
Kismet
Telephony Security Assessment Tool
Omnipeek
Testing Network-Filtering Device Tool
Traffic IQ Professional
Designed &
Developed by Webmaster Abbas Shahid Baqir Webmaster Feedback: stscomps@yahoo.com All Rights
Reserved Copyright, 2010-2015 Student Shelter In Computers
®