
The first goal is to identify the main security properties and understand how they are organised and work.
Overview of the attacks types that exist and Internet Security glossary review.
Security services and mechanisms are key to keep data secure, get to know what are the best options and methods according a given digital scenario.
Learn about common security terms and updated reports.
Vulnerability - Weakness that may allow attackers to gain access to the system or info.
Attack - A malicious activity that attempts to violate the security properties of the system .
Intrusion - An attack that successfully exploited a vulnerability.
Overview of the most common terms regarding malware
Learn about Security Properties, the CIA triad and the three kinds of attack surfaces.
Risk assessment, assessing what the risks are.
Security plan, identifies and organizes the security activities for a computing system
and also about threat modeling and legal aspects of IT applications
Apply the previously learned theory to a real live situation
Final review and conclusion of a risk management report
Introduction to cryptography and differences between good and bad security solutions.
Since the onset of civilisation cryptography has played a significant role to keep our data private, find out how and why.
Learn the cryptographic principles such as:
Kerckhoffs’ principle
Mathematics
Randomness
Bits of key strength
Find out what kind of attacks can be performed on cryptographic algorithms.
We'll use the theory to see how the tools work.
Safe browsing from the browser to the mac address on a virtual environment
Please install the following software for this chapter:
VirtualBox, Nmap, Netcat, Metasploit
It's all great and Open Source software.
Use Nmap and Netcat tools to find out more about a remote system
Using the discovered information we can know exploit the vulnerable services
Locally benchmark security to understand how the machine can be secured.
Best practices to easily secure a machine that should be applied everywhere.
A scouting procedure shares a lot of similarities with the preliminary steps for a pentesting session, despite the obvious differences, especially in terms of the objective.
- We must plan before executing
- Gather as much intelligence as possible from out of-band sources
- Try to be invisible.
It is recommended for you to use a separate network interface for pentesting tasks.
(That’s why we are using Kali linux on a VM)
The quieter you become the more you can listen.
Run an ARP-scan under the radar
We'll write a simple formulary that retrieves the user text and save it on the database.
However this data is not sanitized and Cross Site Scripting (XSS) attacks are quite easy to execute.
Jquery CDN link: http://ajax.googleapis.com/ajax/libs/jquery/1.11.1/jquery.min.js
Internet is a great technology however it became a major requirement rather than an asset as it used to be. Some time has passed were we only used the Internet to check some information or news, today even our coffee grinder is connected to the Internet with IoT now this whole spread is putting almost every device on the Internet however the major issue is that we are deploying not only online devices but potential zombies that can be used by third parties to perform a Denial of Service attack.
Learn how this type of attack operates and what DoS,
DDos and DrDOS stand for.
CentOS virtualboxes: https://www.osboxes.org/centos/
More DoS iptable rules: https://www.thegeekstuff.com/2011/06/iptables-rules-examples/?utm_source=feedburner
Get to know FreeNAS and how it can make your life easier with backups, virtual machines, media center, etc...
Get your private server running with FreeNAS
Run TimeMachine on your FreeNAS server to backup your MacOS data without the need of expensive hardware.
Grab your CentOS VM image here: https://www.osboxes.org/centos/
Password: osboxes.org
This curse sums up more than 10 years working on IT and the content of a master degree in information technologies security.
The topics are:
CIA triad, types of attacks and security mechanisms
Security concepts and methodologies (Terminology, Security properties and case study of a Risk Management plan)
Cryptography (Introduction, Historical background, principles and how to stay anonymous on the Internet)
Security benchmark (Black-box and white-box approach to exploit and secure a system)
Formulary hacks (Code a vulnerable form, exploit and secure it)
Security in email (PGP) and web servers (X.509)
Network firewall with Snort integration
Remote security analysis and assessment
Build a dedicated virtual server (Backup your data, including Time Machine, run your Virtual Machines among other perks)
Extra chapters about web server sandboxes and the Wannacry ransomware, will be updated as I see fit our you demand.
Even if you are already a system administrator or a newbie you are most likely to find something new, as I did previously to start this.
If you have any question or doubt just send me a message.
All questions and feedback will have a response within 24 hours, sign up today and start learning now.
You will also learn how use most of Google's full capacities, use other search engines to fetch sensitive information and validate if credentials are compromised. Besides this you will learn how to setup a phishing attack website in order to get sensitive information by cloning websites such as Google's, Facebook, LinkedIn, etc and you will also learn how to setup a local fake WiFi access point to get users credentials, among other useful information.
Course contents updated on January 2025