Sunday, November 6, 2016

Learn Ethical Hacking


Learn Ethical Hacking


10+ Hours to learn practical attacks to test the security of computer systems from scratch using Linux.

Course Description

Welcome to my comprehensive course on Ethical Hacking! In this course, you will start as a beginner with no previous knowledge about penetration testing or hacking. The first thing you will learn is some basic information about ethical hacking and the different fields in penetration testing.
This course is focused on the practical side of penetration testing without neglecting the theory behind each attack. Before jumping into penetration testing, you will first learn how to set up a lab and install needed software to practice penetration testing on your own machine. All the attacks explained in this course are launched against real devices in my lab.
The course is structured in a way that will take you through the basics of linux, computer systems, networks and how devices communicate with each other. We will start by talking about how we can exploit these systems to carry out a number of powerful attacks. This course will take you from a beginner to a more advanced level — by the time you finish, you will have knowledge about most penetration testing fields.
The course is divided into four main sections:
1. Network Penetration Testing – This section will teach you how to test the security of networks, both wired and wireless. First, you will learn how networks work, basic network terminology and how devices communicate with each other. Then it will branch into three sub sections:
·       Pre-connection: in this section, we still don’t know much about penetration testing — all we have is a computer with a wireless card. You will learn how gather information about the networks and computers around you and launch a number of attacks without a password, such as controlling the connections around you (ie: deny/allow any device from connecting to any network). You will also learn how to create a fake accesspoint, attract users to connect to it and capture any important information they enter.
·       Gaining Access: Now that you have gathered information about the networks around you and found your target, you will learn how to crack the key and gain access to your target network. In this section you will learn a number of methods to crack WEP/WPA/WPA2 encryption.
·       Post Connection: Now you have the key to your target network and you can connect to it. In this section you will learn a number of powerful attacks that can be launched against the network and connected clients. These attacks will allow you to gain access to any account accessed by any device connected to your network and read all the traffic used by these devices (images, videos, audio, passwords …etc).
2. Gaining Access – In this section you will learn two main approaches to gain full control over any computer system:
·       Server Side Attacks:  In this approach you will learn how to gain full access to computer systems without the need for user interaction. You will learn how to gather information about a target computer system such as its operating system, open ports, installed services and discover weaknesses and vulnerabilities. You will also learn how to exploit these weaknesses to gain full control over the target. Finally you will learn how to generate different types of reports for your discoveries.
·       Client Side Attacks – If the target system does not contain any weaknesses then the only way to gain access to it is by interacting with the user. In this approach you will learn how to launch a number of powerful attacks to fool the target user and get them to install a backdoor on their device. This is done by creating fake updates and serving them to the user or by backdoornig downloadedfiles on the fly. You will also learn how to gather information about the target person and use social engineering to deliver a backdoor to them as an image or any other file type.
3. Post Exploitation – In this section you will learn how to interact with the systems you compromised so far. You’ll learn how to access the file system (read/write/upload/execute)maintain your access, spy on the target and even use the target computer as a pivot to hack other computer systems.
4. Web Application Penetration Testing – In this section you will learn how websites work. Then you will learn how to gather information about your target website, such as website owner, server location, used technologies and much more. You will also learn how to discover and exploit a number of dangerous vulnerabilities such as SQL injections, XSS vulnerabilitiesetc.
At the end of each section you will learn how to detect, prevent and secure your system and yourself from these attacks.
All the attacks in this course are practical attacks that work against any computer device, ie: it does not matter if the device is a phone, tablet, laptop, etc. Each attack is explained in a simple way — first you will learn the theory behind each attack and then you will learn how to carry out the attack using Kali Linux.
NOTE: This course is created for educational purposes only and all the attacks are launched in my own lab or against devices that I have permission to test.

What are the requirements?

  • Basic IT Skills
  • External wireless card (for the wifi cracking section) – preferably one that supports injection such as Alfa cards

What am I going to get from this course?

  • 150 detailed videos about ethical hacking & computer security
  • Know what is hacking, ethical hacking and diffirent types of hackers
  • Learn about the different fields of ethical hacking
  • Set up a lab environment to practice hacking
  • Install Kali Linux – a penetration testing operating system
  • Install windows & vulnerable operating systems as virtual machines for testing
  • Learn linux basics
  • Learn linux commands and how to interact with the terminal
  • Learn Network Penetration Testing
  • Network basics & how devices interact inside a network
  • A number of practical attacks that can be used without knowing the key to the target network
  • Control connections of clients around you without knowing the password.
  • Create a fake Wi-Fi network with internet connection & spy on clients
  • Gather detailed information about clients and networks like their OS, opened ports …etc.
  • Crack WEP/WPA/WPA2 encryptions using a number of methods.
  • ARP Spoofing/ARP Poisonning
  • Launch Various Man In The Middle attacks.
  • Gain access to any account accessed by any client in your network.
  • Sniff packets from clients and analyse them to extract important info such as: passwords, cookies, urls, videos, images ..etc.
  • Discover open ports, installed services and vulnerabilities on computer systems
  • Gain control over computer systems using server side attacks
  • Exploit buffer over flows and code execution vulnerabilities to gain control over systems
  • Gain control over computer systems using client side attacks
  • Gain control over computer systems using fake updates
  • Gain control over computer systems by backdooring downloads on the fly
  • Gain control over WordPress sites
  • Gain control over Joomla sites
  • Gain control over Linux/Windows servers
  • Gain control of Social Networks/Accounts
  • Gain control over Webcams/Cameras
  • Create undetectable backdoors
  • Backdoor normal programs
  • Backdoor any file type such as pictures, pdf’s …etc.
  • Gather information about people, such as emails, social media accounts, emails and friends
  • Use social engineering to gain full control over target systems
  • Send emails from ANY email account without knowing the password for that account
  • Read, write download, upload and execute files on compromised systems
  • Capture key strikes on a compromised system
  • Use a compromised computer as a pivot to gain access to other computers on the same network
  • Web Penetration Attacks: SQLi, XSS(Reflected), LFI, RFI, Brute Force, Blind SQL Injection, Bypass Login, XSS (Dom Based), Shell Upload, Cross-site Request Forgery, Symlinking, Defacing Webistes.

What is the target audience?

  • Anybody who is interested in learning ethical hacking / penetration testing
  • Anybody who wants to learn how hackers would attack their computer systems
  • Anybody who wants to learn how to secure their systems from hacker
  • This course is for anyone who wants to become an expert in security, privacy and anonymity. This volume covers the required foundation building blocks of that skillset.
  • For anyone who would love to gain a practical skillset in mitigating the risk from, malware, Trojans, hackers, tracker, cyber criminals and all online threats.
  • This course is for anyone who wants to keep their precious files, emails, accounts and personal information out of the hands of the bad guys.
  • For beginners and intermediate Internet users who are interested in security, safety and privacy.
  • For those who want privacy and anonymity online from hackers, corporations and governments.
  • This course is designed for personal and home Internet security, privacy and anonymity. Most of the topics apply in the same way to a business, but the course is delivered as if to an individual for personal Internet security, privacy and anonymity.
Student’s Exprerience:“I’m at home taking the online class but I feel like I’m there in the room. I don’t feel isolated at all. I just have access to my comforts while taking the class.

CASE STUDY:
  1. Footprinting
What Is Footprinting?
Why Is Footprinting Necessary?
Internet Footprinting
Step 1: Determine the Scope of your Activities
Step 2: Get Propher Authorozition
Step 3: Publicly Available Information
Step 4: WHOIS & DNS Enumeration
Step 5: DNS Interrogation
Step 6: Network Reconnaissance

2. Scanning

Determining If the System Is Alive

Determining Which Services Are Running or Listening

Scan Types

Identifying TCP and UDP Services Running

Windows-Based Port Scanners

Port Scanning Breakdown
3.  Enumeration
 Basic Banner Grabbing
 Enumerating Common Network Services
 Summary

SYSTEM HACKING
▼ 4.  Hacking Windows
Unauthenticated Attacks
Authentication Spoofi ng Attacks
Remote Unauthenticated Exploits
Authenticated Attacks
Privilege Escalation
Extracting and Cracking Passwords
Remote Control and Back Doors
Port Redirection
Covering Tracks
General Countermeasures to Authenticated Compromise
Windows Security Features
Windows Firewall
Automated Updates
Security Center
Security Policy and Group Policy
Bitlocker and the Encrypting File System (EFS)
Windows Resource Protection
Integrity Levels, UAC, and LoRIE
Data Execution Prevention (DEP)
Service Hardening
Compiler-based Enhancements
Coda: The Burden of Windows Security

▼ 5.  Hacking Unix
The Quest for Root
A Brief Review
Vulnerability Mapping
Remote Access vs. Local Access
Remote Access
Data-Driven Attacks
I Want My Shell
Common Types of Remote Attacks
Local Access
After Hacking Root
What Is a Sniffer?
How Sniffers Work
Popular Sniffers
Rootkit Recovery

▼ 6. Remote Connectivity and VoIP Hacking
Preparing to Dial Up
War-Dialing
Hardware
Legal Issues
Peripheral Costs
Software
Brute-Force Scripting—The Homegrown Way
A Final Note About Brute-Force Scripting
PBX Hacking
Voicemail Hacking
Virtual Private Network (VPN) Hacking
Basics of IPSec VPNs
Voice over IP Attacks
Attacking VoIP


▼ 7. Network Devices
Discovery
Detection
Autonomous System Lookup
Normal traceroute
Public Newsgroups
Service Detection
Network Vulnerability
OSI Layer 1
OSI Layer 2
OSI Layer 3
Misconfi gurations
Route Protocol Hacking
Management Protocol Hacking


▼ 8. Wireless Hacking
Wireless Footprinting
Equipment
War-Driving Software
Wireless Mapping
Wireless Scanning and Enumeration
Wireless Sniffers
Wireless Monitoring Tools
Identifying Wireless Network Defenses and Countermeasures
SSID
MAC Access Control
Gaining Access (Hacking 802.11)
SSID
MAC Access Control
WEP
Attacks Against the WEP Algorithm
Tools That Exploit WEP Weaknesses
LEAP
WPA
Attacks Against the WPA Algorithm
Additional Resources
▼ 9. Hacking Hardware
Physical Access: Getting in the Door
Hacking Devices
Default Confi gurations
Owned Out of the Box
Standard Passwords
Bluetooth
Reverse Engineering Hardware
Mapping the Device
Sniffi ng Bus Data
Firmware Reversing
JTAG

▼ 10. Hacking Code
Common Exploit Techniques
Buffer Overfl ows and Design Flaws
Input Validation Attacks
Common Countermeasures
People: Changing the Culture
Process: Security in the Development Lifecycle (SDL)

▼ 11. Web Hacking
Web Server Hacking
Sample Files
Source Code Disclosure
Canonicalization Attacks
Server Extensions
Buffer Overflows
Web Server Vulnerability Scanners
Web Application Hacking
Finding Vulnerable Web Apps with Google
Web Crawling
Web Application Assessment
Common Web Application Vulnerabilities


▼ 12. Hacking the Internet User
Internet Client Vulnerabilities
A Brief History of Internet Client Hacking
JavaScript and Active Scripting
Cookies
Cross-Site Scripting (XSS)
Cross-Frame/Domain Vulnerabilities
SSL Attacks
Payloads and Drop Points
E-Mail Hacking
Instant Messaging (IM)
Microsoft Internet Client Exploits and Countermeasures
General Microsoft Client-Side Countermeasures
Why Not Use Non-Microsoft Clients?
Socio-Technical Attacks: Phishing and Identity Theft
Phishing Techniques
Annoying and Deceptive Software: Spyware, Adware, and Spam
Common Insertion Techniques
Blocking, Detecting, and Cleaning Annoying and
Deceptive Software
Malware
Malware Variants and Common Techniques
Denial of Service(DoS) and Distributed Denial of Service (DDoS) Attacks
/******************************************  
 PAYMENT METHOD:
► Western Union (WU)
► PayPal
Contact Us: 
 WhatsApp Number: +387603178639
/***************************************
– Lessons are recorded to FULL HD resolution
– With lessons you will get pdf file with commands ( step by step), also my private hacking tools written in python and ruby and my real world hacking techniques.
– After payment is done, course will be automatically transferred to costumer.Also payment can be done in the two parts (after 7 days another part of payment).Lessons are from beginners to expert ethical hacker, so you don’t need
to worry about understanding course, and money back is guaranteed.
For more details about  Cyber Security &  Black Hat Ethical Hacking Course [Contact Us] image below:

Credits to: http://www.learnhack.info/

No comments:

Post a Comment