Learn now how to build your $120 000/year career as Ethical Hacker!
A job that can be done from home, coffee shop or remote island!
In order to protect yourself from hackers, you must think as one.
This training is based on a practical approach of day-by-day situations and it contain labs based on real environments.
The course objective is to help you learn to master the (ethical) hacking techniques and methodology that are used in penetration systems. The course is designed for IT passionate, network and system engineers, security officers.
Below are the main topics, both theoretical and practical, of this course:
In this video are presented most why web application security is so important and how they developed over the years
You will familiarise yourself with web technologies. It is important to have a good foundation before going forward.
You will be guided trough the step required to install required tools and services in order to create a testing lab.
Understand the process and the need of mapping a web application.
Learn how to use burp in order to brute-force usernames and password within your testing environment.
A demo showing how to discover a web application resources.
A demo showing how to discover a web application resources, including the one that are not linked within the website.
A good overview of how authentication and session management works.
Perform a man-in-the middle attack and capture authentication details of the computer in the same LAN. Test it in the lab environment.
Intercept and analyze HTTPS (encrypted) traffic.
Understand access control data stores and learn what client side attacks implies.
Perform an SQL injection attack to get data from the database.
Perform SQLi using an automate tool and get remote shell trough an SQLi vulnerability.
Present problems related to file upload and show how an attacker can get control over the server trough a file upload correlated with a remote file inclusion.
Understand the Cross Site Scripting and how it affects users.
A real example of how users are affected of XSS.
Understand the difference between Reflected and Stored XSS trough examples.
See the whole Penetration Testing process summarised, from the beginning to the end.
Senior Information Security Consultant
I work in the Internet security team, focused on ethical hacking - deliberately and purposefully challenging the IT security assumptions, strategies, and methods of protecting vital assets and information by emulating an adversary. Act as an effective participant in multidisciplinary security project team. -Scan and exploit for a wide variety of data center infrastructure and application vulnerabilities, following defined rules of engagement and attack scenarios (ethical hacking). Make recommendations on security weaknesses and report on activities and findings. - Perform Internet penetration testing (black box / white box testing) and code reviews (manual and automated) - Security lab fixed and virtual assets design for different LAN / WAN architectures - Use testing tools as NetBIOS scanning, network pinging and testing, packet crafting and analyzing, port scanning for vulnerability assessment - Perform analysis and testing to verify the strengths and weaknesses of - Web Applications and Web Services (SML, SOAP, WSDL, UDDI, etc.) - Perform analysis and testing to verify the strengths and weaknesses of a variety of operating systems, network devices, web applications, and security architectures - Assist with the development of remediation services for identified findings - Customize, operate, audit, and maintain security related tools and applications
- Trainer for Web Application Hacking and Network Infrastructure Hacking - Training students for CCNA and CCNA Security Certification - Training NDG Linux Basics - Legal Main Contact - Curriculum Leader
- CREST CRT (Registered Penetration Tester)
- ISO 270001 Lead Auditor
- ECSA (EC-Council Certified Professional)
- CEH (Certified Ethical Hacker)
- CEI (Certified EC-Council Instructor)
- VMWare vSphere Install, Configure, Manage
- CCNA and CCNA Security
- CCNP Routing and CCNP Switching
- Advanced Linux&InfoSEC
- Microsoft Certified Technology Specialist (MCTS/MCP 70-642): Microsoft Windows Server 2008 Network Infrastructure, etc.