Workshop
10. Security Assessment and Audit
Trainer
Net Square (IN)
Date
28-29 August 2006
Duration
2 Days
Price
Rp. 11.000.000,-
Requirement
Participants are required to bring their own laptops
Overview
This class offers a technical perspective and exposure to various audit and assessment tools and products to match the best in the indstry, the primary objective being to equip participants with the skills necessary to independently conduct assessments and audits of system/networks.
This course is designed and developed with following objectives for security professionals.
Briefing about security issues and concerns
Understanding security requirements
Gaining knowledge of assessment and audit methods
Performing large scale network assessments
Footprinting, enumerating and attacking systems
Vulnerability and exploit understanding
Web, routers, firewall assessments
Database hacking
Reporting and best practices
top ^
Course Outline
Security Fundamentals and Priciples
Security industry landscape and trends
Security posture and evolution
Corporate security objectives
Treat framework and modeling
Attack vectors and their impact
Popular attack points and severities
Q & A
Assessment and Audit - approaches & methods
Assessment methodologies and basics
Goals and objectives of assessment
Role of tools and credibility
Areas of assessment and importance
Audit basic and objective
Compliance and standards
Q & A
Network Assessment - footprinting & asset identifications
Footprinting basics and objectives
Methodologies and approaches
Public domain queries
WHOIS - query all
ARIS lookup
DNS queries and zone transfers
Trace routing and mapping
Network reconnaissance
Windows footprinting
Reporting and builing targets
Lab
Discovery & Posture mapping
TCP fundamentals
Ping sweeps
Scanning networks (TCP & UDP)
OS identification and stack fingerprinting
Banner grabbing
Protocol identification
Network mapping
Reporting and mapping targets
Lab
Information Gathering & Enumeration - Windows
Windows security overview
Enumerating fundamentals
Security issues with enumeration
Windows enumeration - NetBIOS over TCP
DNS enumeration
SNMP querying
LDAP enumeration
Lab
Information Gathering & Enumeration - Linux/Unix
Linux/Unix security overview
Linux/Unix systems enumeration basics
NFS enumeration
RPC querying
snmpwalk and enumeration
Users and groups enumeration
SAMBA information gathering
finger, rwho, rusers
Lab
Attacks & Hacking
Password guessing
Password cracking
Password sniffing
Privilege escalation
Netcal shell introduction
Other attack vectors
Lab
Vulnerability Assessment & Exploitation
Vulnerability basics
Detecting vulnerabilities
Vulnerability scanning using Nessus and other tools
Crafting exploits
Exploit frameworks - Metasploit
Countermeasures and Security
Lab
Web Hacking
HTTP protocol basics
Web application components
Web server assessment
Web application profiling
Web application hacking
Defending web applications
Tools and methods
Lab
Hacking Network Devices
Network mapping and entry points
Router identification
Compromising routers
Firewall identification
Firewall banner grabbing
Firewall loop holes
Compromising ACLs
VPN and other devices
Lab
SQL Hacking
SQL identification
SQL banner grabbing
MS-SQL cracking
MS-SQL hacking
ORACLE cracking
Security issues with ORACLE
Tools and methods
Lab
top ^
About the tutor
Shreeraj Shah is founder and director of Net-Square. He has five years of experience in the field of security with a strong academic background. He has experience in system security architecture, system administration, network architecture, web application development, security consulting and has performed network penetration testing and application evaluation exercises for many significant companies in the IT arena. Shreeraj graduated from Marist College with a Masters in Computer Science, and has a strong research background in computer networking, application development, and object-oriented programming. He received his Bachelor’s degree in Engineering, Instrumentation and Control from Gujarat University, and an MBA from Nirma Institute of Management, India.
Shreeraj is the co-author of "Web Hacking: Attacks and Defense" published by Addison Wesley. He has published several advisories, tools, and white papers as researcher, and has presented at conferences including HackInTheBox, RSA, Blackhat, Bellua, CII, NASSCOM etc. You can find his blog at http://shreeraj.blogspot.com/.
For questions regarding event registration, please call +62-21-570-5800 (Ms. Astri). For general questions, please email bcs2006@bellua.com or send an empty message to bcs-announce-subscribe@bellua.com to receive future event information.
< back
top ^