27/02/2013
Wings2i comes back with Professional Pe*******on Testing Training & Workshop!
Bangalore, 9th & 10th March, 2013
If anybody wish to nominate for this workshop contact 9900059762 or email [email protected]
Overview
The goal of the “Professional Pe*******on Testing” course is to help your organization take preventive measures against malicious attacks by attacking the system itself; all the while staying within legal limits. This philosophy stems from the proven practice of trying to catch a thief, by thinking like a thief.
To ensure that organizations have adequately protected their information assets, they must adopt the approach of “defense in depth”. In other words, they must pe*****te their networks and assess the security posture for vulnerabilities and exposure.
This Program prepares individuals in the specific network, systems and security discipline to sit for several certifications such as CEH, ECSA and CPT etc from a vendor-neutral perspective. These certifications will fortify the application knowledge of security officers, auditors, security professionals, site administrators, and anyone who is concerned about the integrity of the network infrastructure.
The goal of our two-day Instructor-Led Training modules is to equip information security professionals with the knowledge to identify and correct weak points that make information systems vulnerable to attack.
Key Topics Covered
Module 1.
Terms, Definitions, Methodologies (2 Hours)
• Information Security –101
• CIA Triad
• Threat, Vulnerability and Risk
• Terms and Definitions
• Ethical Hacking?
• Vulnerability Assessment?
• Pe*******on Testing?
• Risk Assessment?
• Security Audits?
• Types of Pe*******on Testing
• Black Box vs. White Box
• External vs. Internal
• Building your Red Team
• Pe*******on Testing Methodologies & Frameworks
• Legal Issues
• Security News Bytes – Recent high profile breaches
Module 2.
Network Pe*******on Testing (4 hours)
• Reconnaissance
• Google hacking
• OSINT
• Public search
• Scanning
• Port Scanning
• O.S finger printing
• Service detection
• Vulnerability identification
• Mastering NMAP
• Vulnerability Assessment with Nessus
• Protocol Analysis
• Detailed Protocol Analysis with Wireshark
• Exploitation
• Advanced exploitation with Metasploit
• Post exploitation techniques
• Social Engineering
• Attacking highly secured environment
• Case Studies
Module 3.
Wireless Pe*******on Testing (2 hours)
• Wireless Basics
• Wireless Standards – The 802.11 Family
• Wireless Sniffing – Tools &Techniques
• Understanding WEP
• Attacking WEP
• Understanding WPA/WPA2
• Attacking WPA/WPA2
• Challenges of Wireless exploitation
• War driving
Module 4.
Web Application Pe*******on Testing (3 hours)
• Intro to Web Application Security
• Web Application Architecture
• Web 1.0 vs Web 2.0
• Evolution of Web Application and security issues
• OWASP Top 10 –Vulnerabilities & Exploitation
o A1: Injection
o A2: Cross-Site Scripting (XSS)
o A3: Broken Authentication and Session Management
o A4: Insecure Direct Object References
o A5: Cross-Site Request Forgery (CSRF)
o A6: Security Mis-configuration
o A7: Insecure Cryptographic Storage
o A8: Failure to Restrict URL Access
o A9: Insufficient Transport Layer Protection
o A10: Un-validated Redirects and Forwards
• Exploitation techniques and tools
• Web2.0 Attacks
• Web Application Pe*******on Testing using OWASP Testing Guide
• Case Studies
Module 5.
Preparing the Report (1 hour)
• Preparing a Pe*******on Testing Report
• Report Templates
• Eliminating false positives
• Categorizing Risk and Vulnerabilities
• Solutions & References
• Conclusion
What You’ll Learn?
• Various Methodologies such as OSSTMM, OWASP and ISSAF etc
• Concepts of Security Testing
• Network, Wireless and Web Application Hacking
• Conducting Black/White/Gray Box Testing
• Conducting Internal and External pe*******on testing
• Real life case studies
What you’ll get?
• Updated list of tools & softwares
• Vulnerable machines and applications for further practice
• Pe*******on testing report templates
• Resources for further research and study
Workshop Details:
• Duration: 2 days (6 hours / day)
• Instructor-led, Classroom Training & Workshop
• Short Lectures, Discussions and Exercises
• Case studies
Certification details:
• Workshop participation certificates will be provided to each participant
Prerequisites
Knowledge on TCP/IP, OS Concepts and Web technologies.
Audience
IT Security Consultants, System Engineers, System Administrators, Application Developers and Network Administrators
Pricing: 12500 + 12.36% service tax
About the trainer:
Gokul C Gopinath is an Information Security Professional having more than 4 years of experience in information security, VA/PT, web application assessments etc. Provided services in both government and private sectors and has conducted numerous consulting projects in the area of Information Security. He has conducted several technical workshops and trainings for his clients including government organizations. He is one of the initiator of OWASP Mantra project, executive member of ISRA (Information Security Research Association), organizing member of international hacking conference c0c0n, team member of Matriux, he is also a team member of WarDriving Kerala project.