
The goal of this lecture is to give you an idea of what you'll be capable of by the end of the course. It's going to showcase 3 different professional hacking techniques that you will learn in this course to launch proper phishing campaigns, steal login information, bypass 2FA and MFA (two and multi factor authentication), hack web browsers, access their exact location, access system resources like the web cam, and finally gain full remote control over any computer that is connected to the internet, and all of this will be done from within the cloud.
This is the main course introduction lecture, it'll introduce you to the main sections and topics of the course that will teach you how to use the cloud for hacking and explain what you'll learn and how you'll learn it.
This is the first theory lecture of the course, before you start learning how to use the cloud for hacking you have to understand what is the cloud and how does it work? This lecture will answer all of this and a bit more.
Now that you understand what is the cloud, this lecture will highlight it's benefits for hackers.
This is the first practical section in this course, this introduction lecture will breakdown to you what you'll learn in this section.
This lecture will introduce you to the different cloud computing providers out there and teach you how to sign up with Amazon AWS.
This lecture will teach you how to install a hacking operating system (Kali Linux) on the cloud for free.
In this lecture you will learn how to securely communicate with cloud servers and remotely control them using SSH.
In this lecture you will learn how to interact with the linux terminal and run linux commands.
This lecture will introduce you to the phishing section of this course. This section will teach you how to replicate any website that exists on the internet and host it on your own server on the cloud.
This can be very useful in so many scenarios. So first of all, you're going to be able to host your own websites on your own servers. Then I'm going to teach you how to use this knowledge to steal the login information of any web page and hack the web browsers that load that page.
Then we'll take our phishing game to the next level as you learn how to bypass multi-factor or two factor authentication using EvilginX and the browser in-browser attack. You'll even be able to use this to hack WhatsApp accounts or any other account that has a web interface.
Of course, this is going to work against all devices mobile phones, computers, tablets.It doesn't really matter.And against all operating systems windows, Linux, Apple macOS, iOS or even Android.
As we do this,I'm going to teach you more concepts about the cloud. So I'm going to teach you how to transfer files between your local computer and your cloud server, how to manage the file system on your cloud server to download and upload and edit and rename and move files exactly the same way that you communicate or interact with files on your local computer.
You'll also learn what do we mean by DNS, how to register a domain name and link it to your cloud server.
Finally, I will teach you how to enable HTTPS on your website.As a result.This increases user trust, browser trust and search engine trust, increasing the chances of executing a successful attack.
Last but not least, you'll learn basic PHP programming. But don't worry about it. I don't expect you to know any programming and I'm going to take you through it step by step.
This lecture will teach you how to install a web server on your cloud computer and use it to host files or websites on the cloud.
This lecture will teach you how to replicate or clone any website that exists on the internet and host it on your own server on the cloud.
This lecture will teach you how to use SFTP to securely and remotely manage the file system of your cloud computer, upload or download files, edit permissions, etc.
This lecture will teach you PHP basics to store store the login information entered, allowing you to steal the login information to any account from any website.
In this lecture you'll learn how to modify the login page to store the login information and create a professional phishing login page.
This lecture will introduce you to DNS and teach you how to register your own domain name.
In this lecture you'll learn how to edit DNS records to link a domain name to your cloud server.
This lecture will introduce you to HTTPS and explain to you why it is essential.
This lecture will teach you how to enable HTTPS on your website. This increases user trust, browser trust and search engine trust, increasing the chances of executing a successful attack.
This lecture will introduce you to the first technique that you will learn in this course to bypass 2FA or MFA (2 Factor or Multi Factor) Authentication.
In the structure you will learn how to install the needed software to bypass two factor and multifactor authentication.
This lecture will teach you step-by-step how to bypass two factor or multi factor authentication using EvilGinx.
This introduction lecture would introduce you to this idea and explain how it will work.
This lecture will teach you how to remotely unsecured access the desktop of cloud computers.
The browser and browser attack is the second technique that you will learn in this course to bypass 2FA or MFA (two factor or multi factor) authentication. This lecture will introduce you to the idea of the browser and browser attack, breakdown the needed software and explain to you how the whole set up will work.
This lecture will walk you through the first steps of setting up the cloud computer to be used in the browser in browser attack.
And this structure you will continue building and enhancing the cloud computer to be used for the browser in browser attack and you will learn how to install a malicious web browser on the cloud server.
In this lecture you will learn how to enhance the URL to access the cloud computer which is essential to launching and effective and successful browser in browser attack.
In this structure you will learn how to use the browser in browser attack to hack Gmail account and bypass two factor or multi-factor (2FA / MFA) authentication.
This lecture will teach you how to use the browser in browser attack to hack any web enabled service such as WhatsApp.
This lecture will teach you how to change the user agent of the browser on the cloud computer. This is essential to targeting mobile devices in the browser and browser attack.
In this lecture we will continue improving our malicious browser on the cloud in order to use it to target mobile devices.
This lecture will teach you how to install a virtual keyboard on the cloud server so that it can be used to launch browser in browser attacks against mobile devices.
In this structure we will use the set up created in the previous lectures to target a mobile device, steal their Gmail password and bypass 2FA / MFA (two factor / multi factor) authentication.
This lecture will teach you how to accept multiple connections to the cloud server at the same time. This allows you to target multiple devices at the same time.
This lecture will teach you how to create multiple sessions on your cloud server. This is also essential to target multiple devices at the same time.
This lecture will teach you how to launch the browser in browser attack against multiple devices; phones, computers, and steel login information from these devices and bypass to factor or multi-factor authentication.
This section will teach you how to hack the whole browser that loads our phishing pages or malicious websites.
To do this, you'll learn how to embed malicious or evil code into these websites, this code will allow us to hack the browser. It will allow us to execute any type of JavaScript on that browser. It will give us more information about the targets, such as their IP address, which we can use to get their location. It will also allow us to access the system resources, such as their webcam and their GPS coordinates, which will give us their exact location. We'll also be able to steal login information from their computer and potentially gain full remote access to their computer.
At the end, you'll learn little bit more PHP and JavaScript programming, and you're going to create your own custom malicious page that will allow you to access the camera and the exact location of the target.
Finally, at the end of this section, you'll learn some URL manipulation tricks that will make your websites or our phishing pages more believable and more trustworthy, ultimately increasing the chances of the target interacting with them.
This section will introduce you to the browser exploitation framework - BeEF - and teach you how to install it on your cloud server. You will need this in future lectures in order to hack web browsers.
This lecture will teach you how to embed malicious or evil code into any website, this code will allow us to hack the browser. It will allow us to execute any type of JavaScript on that browser. It will give us more information about the targets, such as their IP address, which we can use to get their location. It will also allow us to access the system resources, such as their webcam and their GPS coordinates, which will give us their exact location. We'll also be able to steal login information from their computer and potentially gain full remote access to their computer.
This lecture will teach you how to enable HTTP on malicious pages, increasing user trust, search engine trust, and web browser trust. Ultimately increasing the chances of executing a successful attack.
This lecture will teach you how to hack Windows and Apple Mac OS web browsers. You'll learn how to get more information about the targets, such as their IP address, which we can use to get their location. It will also allow us to access the system resources, such as their webcam and their GPS coordinates, which will give us their exact location. We'll also be able to steal login information from their computer and potentially gain full remote access to their computer.
In this lecture you'll learn little bit more PHP and JavaScript programming to access the camera and the exact location of anyone that loads your website.
In this lecture you'll learn how to store the the exact location of the targets that load your website.
In this lecture you'll learn URL manipulation tricks to make your websites or phishing pages more believable and more trustworthy, ultimately increasing the chances of the target interacting with them.
This section will teach you how to hack or gain full remote control over any computer that is connected to the internet, regardless of their location and regardless of the operating system that they are running, whether it's running windows, Linux, or Apple Mac OS.
What we mean by full remote control is the ability to fully and remotely control a target computer and access all of its resources from within the cloud, using what's known as C and C, or command and control servers.
So you'll be able to execute any system commands that you want, access their file system, read, upload or download files, access system resources such as the camera and the keyboard, and even launch ransomware attacks.
You'll be able to remotely do anything on that computer as if it's your own computer, and do all of that from within the cloud.
This lecture will introduce you to the idea of command and control or C2 servers, you'll learn what we mean by C2 servers, their pros and cons, and which C2 server is the best.
Welcome to my comprehensive course that will teach you how to use the cloud for hacking. With NO prior knowledge required, this course takes you from a beginner to an expert at launching advanced attacks from the cloud. Giving you the ability to hack online accounts, web browsers, bypass two or multi factor authentication, and gain full remote control over all operating systems (Windows, Linux and Apple Mac OS) from within the cloud. That's not all, you'll also be able to use the cloud knowledge you acquire in this course to host your own websites and your own cloud applications.
This course is highly practical but it won't neglect the theory. We'll start with basics of ethical hacking and cloud computing. Then we'll dive and start using the cloud for hacking straight away. You'll learn everything by example, by hacking online accounts, computers, and browsers, no boring dry lectures. By the end of the course you will have a strong foundation in cloud computing and ethical hacking.
To achieve this the course is divided into a number of sections, each aims to teach you a specific hacking technique! You'll first learn the cloud concepts related to this technique, then you'll learn how to use the cloud to hack computers, phones, browsers, online accounts and much more. As we do this I will also introduce you to different hacking concepts, tools and techniques. Everything will be taught through examples and hands-on practicals, there will be no useless or boring lectures!
All the techniques in this course are practical and work against real systems, you'll understand the whole mechanism of each technique first, then you'll learn how to use it to hack from the cloud. Therefore by the end of the course you'll be able to modify these techniques to launch more powerful attacks, and adopt them to suit different situations and different scenarios .
As mentioned this course will will teach you both ethical hacking and cloud computing at the same time, here are some of the topics that will be covered in the course:
Hacking topics:
Phishing basics + advanced.
Clone / replicate any website on the internet.
Bypass two or multi factor authentication (2FA / MFA).
Hacking online accounts such as Whatsapp accounts, email accounts, etc.
Hacking Windows, Apple Mac OS and Linux from the cloud.
Creating backdoors for Windows, Apple Mac OS and Linux.
Creating trojans for Windows, Apple Mac OS and Linux.
Hacking web browsers on all operating systems and devices.
Stealing credentials using fake prompts .
Stealing sensitive info from hacked computers.
Accessing system resources such as the keyboard and camera from the cloud.
Advanced malware delivery using specialised cloud services.
Cross-platform download page to serve the right malware based on the target's OS.
URL manipulation to include convincing words such as Facebook.
Generating convincing download links with safe extensions such as .pdf.
Launching ransomware attacks from the cloud.
Tracking any device from the cloud using a link.
Read, write download, upload and execute files on compromised systems.
Botnet basics and concepts.
Cloud topics:
Install & use Kali Linux from the cloud.
Cloning websites on the internet.
Install a GUI on cloud servers and access their desktop.
Hosting your own websites and cloud applications.
Enabling HTTPs.
Understand DNS and the different record types.
Use Amazon's cloud service AWS.
Configuring firewall rules.
Link a domain name to cloud servers.
SSH basics.
FTP and SFTP basics.
Apache2 basics.
Novnc.
Other topics:
PHP basics.
Javascript basics
AI Basics
Linux basics.
Linux commands.
How to use the Linux terminal.
Throughout the course you'll learn how to use use the following tools to achieve the above:
Kali Linux
AWS.
SSH.
Certbot
Evilginx.
Pwndrop.
Filezilla.
Openvnc.
Empire.
Starkiller
Distopia
Netcat.
BeEF.
Checkout the curriculum and the course teaser for more info!
With this course you'll get 24/7 support, so if you have any questions you can post them in the Q&A section and we'll respond to you within less than 15 hours.
Notes:
This course is created for educational purposes only and all the attacks are launched in my own lab or against devices that I have permission to test.
This course is totally a product of Zaid Sabih & zSecurity, no other organisation is associated with it or a certification exam. Although, you will receive a Course Completion Certification from Udemy, apart from that NO OTHER ORGANISATION IS INVOLVED.