



<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Expanding Security</title>
	<atom:link href="http://www.expandingsecurity.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.expandingsecurity.com</link>
	<description>The best security training for information assurance</description>
	<lastBuildDate>Fri, 09 Jul 2010 18:37:48 +0000</lastBuildDate>
	
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>CEH Syllabus overview</title>
		<link>http://www.expandingsecurity.com/2010/06/ceh-syllabus-overview/</link>
		<comments>http://www.expandingsecurity.com/2010/06/ceh-syllabus-overview/#comments</comments>
		<pubDate>Sun, 27 Jun 2010 17:57:30 +0000</pubDate>
		<dc:creator>Helaine</dc:creator>
				<category><![CDATA[CISSP]]></category>

		<guid isPermaLink="false">http://www.expandingsecurity.com/?p=1201</guid>
		<description><![CDATA[So that you can see whole course in one shot here are all the links to the weeks:
0. Orientation

Footprinting &#38; Scanning
Enumeration &#38; System Hacking
Trojans and Backdoors &#38; Sniffers
DOS &#38; Social Engineering
Session Hijacking &#38; Web Servers
Web Applications &#38; Passwords
SQL injection &#38;  Wireless
Viruses &#38; Novell
Linux &#38; Evasion
Buffer Overflows &#38; Cryptology

You might want to look at these from [...]]]></description>
			<content:encoded><![CDATA[<p>So that you can see whole course in one shot here are all the links to the weeks:</p>
<p>0. <a href="http://www.expandingsecurity.com/2010/06/ceh-online-orientation/">Orientation</a></p>
<ol>
<li><a href="http://www.expandingsecurity.com/2010/06/syllabus-hacker-01/">Footprinting &amp; Scanning</a></li>
<li><a href="http://www.expandingsecurity.com/2010/06/syllabus-hacker-02/">Enumeration &amp; System Hacking</a></li>
<li><a href="http://www.expandingsecurity.com/2010/06/syllabus-hacker-03/">Trojans and Backdoors &amp; Sniffers</a></li>
<li><a href="http://www.expandingsecurity.com/2010/06/syllabus-hacker-04/">DOS &amp; Social Engineering</a></li>
<li><a href="http://www.expandingsecurity.com/2010/06/syllabus-hacker-05/">Session Hijacking &amp; Web Servers</a></li>
<li><a href="http://www.expandingsecurity.com/2010/06/syllabus-hacker-06/">Web Applications &amp; Passwords</a></li>
<li><a href="http://www.expandingsecurity.com/2010/06/syllabus-hacker-07/">SQL injection &amp;  Wireless</a></li>
<li><a href="http://www.expandingsecurity.com/2010/06/syllabus-hacker-08/">Viruses &amp; Novell</a></li>
<li><a href="http://www.expandingsecurity.com/2010/06/syllabus-hacker-09/">Linux &amp; Evasion</a></li>
<li><a href="http://www.expandingsecurity.com/2010/06/syllabus-hacker-10/">Buffer Overflows &amp; Cryptology</a></li>
</ol>
<p>You might want to look at these from the <a href="http://www.expandingsecurity.com/about/events/">calendar  stand point </a>to see the dates and times for class.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.expandingsecurity.com/2010/06/ceh-syllabus-overview/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Syllabus Hacker 09</title>
		<link>http://www.expandingsecurity.com/2010/06/syllabus-hacker-09/</link>
		<comments>http://www.expandingsecurity.com/2010/06/syllabus-hacker-09/#comments</comments>
		<pubDate>Sun, 27 Jun 2010 17:42:58 +0000</pubDate>
		<dc:creator>Helaine</dc:creator>
				<category><![CDATA[Certified Ethical Hacker]]></category>

		<guid isPermaLink="false">http://www.expandingsecurity.com/?p=1163</guid>
		<description><![CDATA[
Please note: You will not be able to get files from the server unless you are a paid student and have been issued an account. So some links on this page will not work if you are a guest.
The steps below, the files, and links within, are numbered in order of what you will need to [...]]]></description>
			<content:encoded><![CDATA[<div>
<p>Please note: You will not be able to get files from the server unless you are a paid student and have been issued an account. So some links on this page will not work if you are a guest.</p>
<p>The steps below, the files, and links within, are numbered in order of what you will need to read and do. If this set of steps is unclear, please attend orientation for a walk-through.</p>
<p>00- Reading &#8211; The chapter in the book tracks to the class number. Two other source documents are here:</p>
<p><a href="http://www.expandingsecurity.com/wp-content/uploads/2010/06/osstmm.en_.2.2.pdf">OSSTMM</a> <a href="http://www.expandingsecurity.com/wp-content/uploads/2010/06/SP800-115.pdf">SP800-115</a></p>
<p>01-Mind map review for Note Cards, Terms and Process. For every term in the concepts section of the mindmap you should find a definition first from the book and second from your research. For every tool in the book you should make a notecard based upon Reconn Layer, Exploit Category, and Process.</p>
<p>02-Tool review</p>
<p>You must have the VMware structure in place to start labs. Every week and every class you will be assigned one tool to research, add to the database, and screen capture. Success of each student can be achieved on your own, but if we work together and meet our deadlines, we can see more tools in a shorter time than if we do it all on our own. Check in orientation for your tool assignment. Check the CEH forum for details. You should be able to discuss this tool&#8217;s function, place in the process, and comparison to other tools. The list of tools discussed this week:</p>
<p>18.  Linux Hacking</p>
<ol>
<li>Cheops</li>
<li>Hunt</li>
<li>Nessus</li>
<li>Linux Rootkit V4 (LR4)</li>
<li>Nina p.</li>
<li>SARA (Security Auditor&#8217;s Research Assistant)</li>
<li>Xcrack</li>
<li>John the Ripper</li>
<li>Nmap</li>
<li>HPing2</li>
<li>LSOF</li>
<li>Netcat</li>
<li>Sniffit</li>
</ol>
<p>19.  Evading IDS   Firewalls and Honeypots</p>
<div id="_mcePaste">
<ol>
<li>Tcpreplay</li>
<li>Libmet</li>
<li>Rootshell</li>
<li>IPsend</li>
<li>Sun Packet Shell (psh) Protocol Testing Tool</li>
<li>Net::RawIP</li>
<li>CyberCop Scanner&#8217;s CASL</li>
<li>AckCmd</li>
<li>007 Shell</li>
<li>ICMP Shell</li>
<li>ACK Tunneling</li>
<li>Fragrouter</li>
<li>SideStep</li>
<li>Anzen NIDSbench</li>
<li>ADMutate</li>
</ol>
</div>
<p>03-Reports</p>
<p>As a professional you will be required to report your findings to management in a meaningful, actionable way. For each tool you must know how it fits with your original plan, the outcomes from its use, and what should be done to protect the environment from its use in the future.</p>
<p>04-Recording links are listed for your review of presentations. These are updated one week after the new class.</p>
<p>Recording ##</p>
<p>Recording ##</p>
<p>You can find these links and the class schedule here:<a href="http://www.expandingsecurity.com/about/events/">http://www.expandingsecurity.com/about/events/</a></p>
<p>All content is copyright protected. Downloading or reviewing any material means you consent to the copyright restrictions placed on all works by the author. You are forbidden from using any of this material in the teaching of any class. You are only permitted to use this as a current student of Expanding Security. You are not permitted to copy or distribute these materials in any way.</p>
</div>
]]></content:encoded>
			<wfw:commentRss>http://www.expandingsecurity.com/2010/06/syllabus-hacker-09/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Syllabus Hacker 10</title>
		<link>http://www.expandingsecurity.com/2010/06/syllabus-hacker-10/</link>
		<comments>http://www.expandingsecurity.com/2010/06/syllabus-hacker-10/#comments</comments>
		<pubDate>Mon, 21 Jun 2010 15:01:46 +0000</pubDate>
		<dc:creator>Helaine</dc:creator>
				<category><![CDATA[Certified Ethical Hacker]]></category>

		<guid isPermaLink="false">http://www.expandingsecurity.com/?p=1164</guid>
		<description><![CDATA[
Please note: You will not be able to get files from the server unless you are a paid student and have been issued an account. So some links on this page will not work if you are a guest.
The steps below, the files, and links within, are numbered in order of what you will need to [...]]]></description>
			<content:encoded><![CDATA[<div>
<p>Please note: You will not be able to get files from the server unless you are a paid student and have been issued an account. So some links on this page will not work if you are a guest.</p>
<p>The steps below, the files, and links within, are numbered in order of what you will need to read and do. If this set of steps is unclear, please attend orientation for a walk-through.</p>
<p>00- Reading &#8211; The chapter in the book tracks to the class number. Two other source documents are here:</p>
<p><a href="http://www.expandingsecurity.com/wp-content/uploads/2010/06/osstmm.en_.2.2.pdf">OSSTMM</a> <a href="http://www.expandingsecurity.com/wp-content/uploads/2010/06/SP800-115.pdf">SP800-115</a></p>
<p>01-Mind map review for Note Cards, Terms and Process. For every term in the concepts section of the mindmap you should find a definition first from the book and second from your research. For every tool in the book you should make a notecard based upon Reconn Layer, Exploit Category, and Process.</p>
<p>02-Tool review</p>
<p>You must have the VMware structure in place to start labs. Every week and every class you will be assigned one tool to research, add to the database, and screen capture. Success of each student can be achieved on your own, but if we work together and meet our deadlines, we can see more tools in a shorter time than if we do it all on our own. Check in orientation for your tool assignment. Check the CEH forum for details. You should be able to discuss this tool&#8217;s function, place in the process, and comparison to other tools. The list of tools discussed this week:</p>
<p>20.  Buffer Overflows</p>
<div id="_mcePaste">
<ul>
<li>METASPLOIT</li>
</ul>
</div>
<p>21.  Cryptography</p>
<ul>
<li>cryptool.exe</li>
</ul>
<p>03-Reports</p>
<p>As a professional you will be required to report your findings to management in a meaningful, actionable way. For each tool you must know how it fits with your original plan, the outcomes from its use, and what should be done to protect the environment from its use in the future.</p>
<p>04-Recording links are listed for your review of presentations. These are updated one week after the new class.</p>
<p>Recording ##</p>
<p>Recording ##</p>
<p>You can find these links and the class schedule here:<a href="http://www.expandingsecurity.com/about/events/">http://www.expandingsecurity.com/about/events/</a></p>
<p>All content is copyright protected. Downloading or reviewing any material means you consent to the copyright restrictions placed on all works by the author. You are forbidden from using any of this material in the teaching of any class. You are only permitted to use this as a current student of Expanding Security. You are not permitted to copy or distribute these materials in any way.</p>
</div>
]]></content:encoded>
			<wfw:commentRss>http://www.expandingsecurity.com/2010/06/syllabus-hacker-10/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Syllabus Hacker 08</title>
		<link>http://www.expandingsecurity.com/2010/06/syllabus-hacker-08/</link>
		<comments>http://www.expandingsecurity.com/2010/06/syllabus-hacker-08/#comments</comments>
		<pubDate>Mon, 21 Jun 2010 13:34:12 +0000</pubDate>
		<dc:creator>Helaine</dc:creator>
				<category><![CDATA[Certified Ethical Hacker]]></category>

		<guid isPermaLink="false">http://www.expandingsecurity.com/?p=1162</guid>
		<description><![CDATA[
Please note: You will not be able to get files from the server unless you are a paid student and have been issued an account. So some links on this page will not work if you are a guest.
The steps below, the files, and links within, are numbered in order of what you will need to [...]]]></description>
			<content:encoded><![CDATA[<div>
<p>Please note: You will not be able to get files from the server unless you are a paid student and have been issued an account. So some links on this page will not work if you are a guest.</p>
<p>The steps below, the files, and links within, are numbered in order of what you will need to read and do. If this set of steps is unclear, please attend orientation for a walk-through.</p>
<p>00- Reading &#8211; The chapter in the book tracks to the class number. Two other source documents are here:</p>
<p><a href="http://www.expandingsecurity.com/wp-content/uploads/2010/06/osstmm.en_.2.2.pdf">OSSTMM</a> <a href="http://www.expandingsecurity.com/wp-content/uploads/2010/06/SP800-115.pdf">SP800-115</a></p>
<p>01-Mind map review for Note Cards, Terms and Process. For every term in the concepts section of the mindmap you should find a definition first from the book and second from your research. For every tool in the book you should make a notecard based upon Reconn Layer, Exploit Category, and Process.</p>
<p>02-Tool review</p>
<p>You must have the VMware structure in place to start labs. Every week and every class you will be assigned one tool to research, add to the database, and screen capture. Success of each student can be achieved on your own, but if we work together and meet our deadlines, we can see more tools in a shorter time than if we do it all on our own. Check in orientation for your tool assignment. Check the CEH forum for details. You should be able to discuss this tool&#8217;s function, place in the process, and comparison to other tools. The list of tools discussed this week:</p>
<p>16.  Viruses</p>
<ol>
<li>Senna Spy</li>
</ol>
<p>17.  Novell Hacking</p>
<div id="_mcePaste">
<ol>
<li>SETPWD.NLM</li>
<li>Kock</li>
<li>userdump</li>
<li>HackingTool NWL</li>
<li>Getit</li>
<li>Burglar, SetPass</li>
<li>Chknull.exe</li>
<li>Novelffs</li>
<li>Spooflog</li>
<li>Gobbler</li>
<li>Pandora</li>
<li>NOVELBFH.EXE</li>
<li>NWPCRACK.EXE</li>
<li>Bindery.exe &amp; BinCrack.exe</li>
</ol>
</div>
<p>03-Reports</p>
<p>As a professional you will be required to report your findings to management in a meaningful, actionable way. For each tool you must know how it fits with your original plan, the outcomes from its use, and what should be done to protect the environment from its use in the future.</p>
<p>04-Recording links are listed for your review of presentations. These are updated one week after the new class.</p>
<p>Recording ##</p>
<p>Recording ##</p>
<p>You can find these links and the class schedule here:<a href="http://www.expandingsecurity.com/about/events/">http://www.expandingsecurity.com/about/events/</a></p>
<p>All content is copyright protected. Downloading or reviewing any material means you consent to the copyright restrictions placed on all works by the author. You are forbidden from using any of this material in the teaching of any class. You are only permitted to use this as a current student of Expanding Security. You are not permitted to copy or distribute these materials in any way.</p>
</div>
]]></content:encoded>
			<wfw:commentRss>http://www.expandingsecurity.com/2010/06/syllabus-hacker-08/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Syllabus Hacker 07</title>
		<link>http://www.expandingsecurity.com/2010/06/syllabus-hacker-07/</link>
		<comments>http://www.expandingsecurity.com/2010/06/syllabus-hacker-07/#comments</comments>
		<pubDate>Mon, 21 Jun 2010 13:33:04 +0000</pubDate>
		<dc:creator>Helaine</dc:creator>
				<category><![CDATA[Certified Ethical Hacker]]></category>

		<guid isPermaLink="false">http://www.expandingsecurity.com/?p=1161</guid>
		<description><![CDATA[
Please note: You will not be able to get files from the server unless you are a paid student and have been issued an account. So some links on this page will not work if you are a guest.
The steps below, the files, and links within, are numbered in order of what you will need to [...]]]></description>
			<content:encoded><![CDATA[<div>
<p>Please note: You will not be able to get files from the server unless you are a paid student and have been issued an account. So some links on this page will not work if you are a guest.</p>
<p>The steps below, the files, and links within, are numbered in order of what you will need to read and do. If this set of steps is unclear, please attend orientation for a walk-through.</p>
<p>00- Reading &#8211; The chapter in the book tracks to the class number. Two other source documents are here:</p>
<p><a href="http://www.expandingsecurity.com/wp-content/uploads/2010/06/osstmm.en_.2.2.pdf">OSSTMM</a> <a href="http://www.expandingsecurity.com/wp-content/uploads/2010/06/SP800-115.pdf">SP800-115</a></p>
<p>01-Mind map review for Note Cards, Terms and Process. For every term in the concepts section of the mindmap you should find a definition first from the book and second from your research. For every tool in the book you should make a notecard based upon Reconn Layer, Exploit Category, and Process.</p>
<p>02-Tool review</p>
<p>You must have the VMware structure in place to start labs. Every week and every class you will be assigned one tool to research, add to the database, and screen capture. Success of each student can be achieved on your own, but if we work together and meet our deadlines, we can see more tools in a shorter time than if we do it all on our own. Check in orientation for your tool assignment. Check the CEH forum for details. You should be able to discuss this tool&#8217;s function, place in the process, and comparison to other tools. The list of tools discussed this week:</p>
<p>14.  SQL Injection</p>
<div id="_mcePaste">
<ol>
<li>sqlmap</li>
<li>SQLCict</li>
<li>SQLExec</li>
<li>sqlbf</li>
<li>SQLSmack</li>
<li>SQL2.exe</li>
</ol>
</div>
<p>15.  Hacking Wireless Networks</p>
<ol>
<li>Airsnort</li>
<li>Kismet</li>
<li>WEPCrack</li>
<li>MAC Sniffing &amp; AP Spoofing</li>
<li>NetStumbler</li>
<li>AiroPeek</li>
</ol>
<p>03-Reports</p>
<p>As a professional you will be required to report your findings to management in a meaningful, actionable way. For each tool you must know how it fits with your original plan, the outcomes from its use, and what should be done to protect the environment from its use in the future.</p>
<p>04-Recording links are listed for your review of presentations. These are updated one week after the new class.</p>
<p>Recording ##</p>
<p>Recording ##</p>
<p>You can find these links and the class schedule here:<a href="http://www.expandingsecurity.com/about/events/">http://www.expandingsecurity.com/about/events/</a></p>
<p>All content is copyright protected. Downloading or reviewing any material means you consent to the copyright restrictions placed on all works by the author. You are forbidden from using any of this material in the teaching of any class. You are only permitted to use this as a current student of Expanding Security. You are not permitted to copy or distribute these materials in any way.</p>
</div>
]]></content:encoded>
			<wfw:commentRss>http://www.expandingsecurity.com/2010/06/syllabus-hacker-07/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Syllabus Hacker 06</title>
		<link>http://www.expandingsecurity.com/2010/06/syllabus-hacker-06/</link>
		<comments>http://www.expandingsecurity.com/2010/06/syllabus-hacker-06/#comments</comments>
		<pubDate>Sun, 20 Jun 2010 21:03:20 +0000</pubDate>
		<dc:creator>Helaine</dc:creator>
				<category><![CDATA[Certified Ethical Hacker]]></category>

		<guid isPermaLink="false">http://www.expandingsecurity.com/?p=1160</guid>
		<description><![CDATA[
Please note: You will not be able to get files from the server unless you are a paid student and have been issued an account. So some links on this page will not work if you are a guest.
The steps below, the files, and links within, are numbered in order of what you will need to [...]]]></description>
			<content:encoded><![CDATA[<div>
<p>Please note: You will not be able to get files from the server unless you are a paid student and have been issued an account. So some links on this page will not work if you are a guest.</p>
<p>The steps below, the files, and links within, are numbered in order of what you will need to read and do. If this set of steps is unclear, please attend orientation for a walk-through.</p>
<p>00- Reading &#8211; The chapter in the book tracks to the class number. Two other source documents are here:</p>
<p><a href="http://www.expandingsecurity.com/wp-content/uploads/2010/06/osstmm.en_.2.2.pdf">OSSTMM</a> <a href="http://www.expandingsecurity.com/wp-content/uploads/2010/06/SP800-115.pdf">SP800-115</a></p>
<p>01-Mind map review for Note Cards, Terms and Process. For every term in the concepts section of the mindmap you should find a definition first from the book and second from your research. For every tool in the book you should make a notecard based upon Reconn Layer, Exploit Category, and Process.</p>
<p>02-Tool review</p>
<p>You must have the VMware structure in place to start labs. Every week and every class you will be assigned one tool to research, add to the database, and screen capture. Success of each student can be achieved on your own, but if we work together and meet our deadlines, we can see more tools in a shorter time than if we do it all on our own. Check in orientation for your tool assignment. Check the CEH forum for details. You should be able to discuss this tool&#8217;s function, place in the process, and comparison to other tools. The list of tools discussed this week:</p>
<p>12.  Web Application Vulnerabilities</p>
<div id="_mcePaste">
<ol>
<li>OWASP web goat</li>
<li>Instant Source</li>
<li>Wget</li>
<li>Lynx</li>
<li>Helpme2.</li>
<li>Black Widow</li>
<li>WindowBomb</li>
<li>WebSleuth</li>
<li>IEEN</li>
</ol>
</div>
<p>13.  Web Based  Password Cracking Techniques</p>
<ol>
<li>WinSSLMiM</li>
<li>Brutus</li>
<li>ObiWan</li>
<li>Munga Bunga</li>
<li>Dictionary Maker</li>
<li>PassList</li>
<li>ReadCookies.html</li>
<li>WebCracker</li>
<li>Revelation</li>
</ol>
<p>03-Reports</p>
<p>As a professional you will be required to report your findings to management in a meaningful, actionable way. For each tool you must know how it fits with your original plan, the outcomes from its use, and what should be done to protect the environment from its use in the future.</p>
<p>04-Recording links are listed for your review of presentations. These are updated one week after the new class.</p>
<p>Recording ##</p>
<p>Recording ##</p>
<p>You can find these links and the class schedule here:<a href="http://www.expandingsecurity.com/about/events/">http://www.expandingsecurity.com/about/events/</a></p>
<p>All content is copyright protected. Downloading or reviewing any material means you consent to the copyright restrictions placed on all works by the author. You are forbidden from using any of this material in the teaching of any class. You are only permitted to use this as a current student of Expanding Security. You are not permitted to copy or distribute these materials in any way.</p>
</div>
]]></content:encoded>
			<wfw:commentRss>http://www.expandingsecurity.com/2010/06/syllabus-hacker-06/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Syllabus Hacker 05</title>
		<link>http://www.expandingsecurity.com/2010/06/syllabus-hacker-05/</link>
		<comments>http://www.expandingsecurity.com/2010/06/syllabus-hacker-05/#comments</comments>
		<pubDate>Sun, 20 Jun 2010 01:23:36 +0000</pubDate>
		<dc:creator>Helaine</dc:creator>
				<category><![CDATA[Certified Ethical Hacker]]></category>

		<guid isPermaLink="false">http://www.expandingsecurity.com/?p=1159</guid>
		<description><![CDATA[
Please note: You will not be able to get files from the server unless you are a paid student and have been issued an account. So some links on this page will not work if you are a guest.
The steps below, the files, and links within, are numbered in order of what you will need to [...]]]></description>
			<content:encoded><![CDATA[<div>
<p>Please note: You will not be able to get files from the server unless you are a paid student and have been issued an account. So some links on this page will not work if you are a guest.</p>
<p>The steps below, the files, and links within, are numbered in order of what you will need to read and do. If this set of steps is unclear, please attend orientation for a walk-through.</p>
<p>00- Reading &#8211; The chapter in the book tracks to the class number. Two other source documents are here:</p>
<p><a href="http://www.expandingsecurity.com/wp-content/uploads/2010/06/osstmm.en_.2.2.pdf">OSSTMM</a> <a href="http://www.expandingsecurity.com/wp-content/uploads/2010/06/SP800-115.pdf">SP800-115</a></p>
<p>01-Mind map review for Note Cards, Terms and Process. For every term in the concepts section of the mindmap you should find a definition first from the book and second from your research. For every tool in the book you should make a notecard based upon Reconn Layer, Exploit Category, and Process.</p>
<p>02-Tool review</p>
<p>You must have the VMware structure in place to start labs. Every week and every class you will be assigned one tool to research, add to the database, and screen capture. Success of each student can be achieved on your own, but if we work together and meet our deadlines, we can see more tools in a shorter time than if we do it all on our own. Check in orientation for your tool assignment. Check the CEH forum for details. You should be able to discuss this tool&#8217;s function, place in the process, and comparison to other tools. The list of tools discussed this week:</p>
<p>10.  Session Hijacking</p>
<div id="_mcePaste">
<ol>
<li>Hunt</li>
<li>Juggernaut</li>
<li>TTY Watcher</li>
<li>IP watcher</li>
<li>T-Sight</li>
</ol>
</div>
<p>11.  Hacking Web Servers</p>
<ol>
<li> Unicodeuploader.pl</li>
<li> cmdasp.asp</li>
<li> iiscrack.dll</li>
<li> ispc.exe</li>
<li> CleanllSLog</li>
<li> IISHackexe</li>
<li> IISxploit.exe</li>
<li> execiis-win32.exe</li>
</ol>
<div></div>
<p>03-Reports</p>
<p>As a professional you will be required to report your findings to management in a meaningful, actionable way. For each tool you must know how it fits with your original plan, the outcomes from its use, and what should be done to protect the environment from its use in the future.</p>
<p>04-Recording links are listed for your review of presentations. These are updated one week after the new class.</p>
<p>Recording ##</p>
<p>Recording ##</p>
<p>You can find these links and the class schedule here:<a href="http://www.expandingsecurity.com/about/events/">http://www.expandingsecurity.com/about/events/</a></p>
<p>All content is copyright protected. Downloading or reviewing any material means you consent to the copyright restrictions placed on all works by the author. You are forbidden from using any of this material in the teaching of any class. You are only permitted to use this as a current student of Expanding Security. You are not permitted to copy or distribute these materials in any way.</p>
</div>
]]></content:encoded>
			<wfw:commentRss>http://www.expandingsecurity.com/2010/06/syllabus-hacker-05/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Syllabus Hacker 04</title>
		<link>http://www.expandingsecurity.com/2010/06/syllabus-hacker-04/</link>
		<comments>http://www.expandingsecurity.com/2010/06/syllabus-hacker-04/#comments</comments>
		<pubDate>Sat, 19 Jun 2010 22:47:48 +0000</pubDate>
		<dc:creator>Helaine</dc:creator>
				<category><![CDATA[Certified Ethical Hacker]]></category>

		<guid isPermaLink="false">http://www.expandingsecurity.com/?p=1158</guid>
		<description><![CDATA[
Please note: You will not be able to get files from the server unless you are a paid student and have been issued an account. So some links on this page will not work if you are a guest.
The steps below, the files, and links within, are numbered in order of what you will need to [...]]]></description>
			<content:encoded><![CDATA[<div>
<p>Please note: You will not be able to get files from the server unless you are a paid student and have been issued an account. So some links on this page will not work if you are a guest.</p>
<p>The steps below, the files, and links within, are numbered in order of what you will need to read and do. If this set of steps is unclear, please attend orientation for a walk-through.</p>
<p>00- Reading &#8211; The chapter in the book tracks to the class number. Two other source documents are here:</p>
<p><a href="http://www.expandingsecurity.com/wp-content/uploads/2010/06/osstmm.en_.2.2.pdf">OSSTMM</a> <a href="http://www.expandingsecurity.com/wp-content/uploads/2010/06/SP800-115.pdf">SP800-115</a></p>
<p>01-Mind map review for Note Cards, Terms and Process. For every term in the concepts section of the mindmap you should find a definition first from the book and second from your research. For every tool in the book you should make a notecard based upon Reconn Layer, Exploit Category, and Process.</p>
<p>02-Tool review</p>
<p>You must have the VMware structure in place to start labs. Every week and every class you will be assigned one tool to research, add to the database, and screen capture. Success of each student can be achieved on your own, but if we work together and meet our deadlines, we can see more tools in a shorter time than if we do it all on our own. Check in orientation for your tool assignment. Check the CEH forum for details. You should be able to discuss this tool&#8217;s function, place in the process, and comparison to other tools. The list of tools discussed this week:</p>
<p>8.  Denial of Service</p>
<div id="_mcePaste">
<ol>
<li>Smurf</li>
<li>Targa</li>
<li>Trinoo</li>
<li>Ping of Death</li>
<li>TFN</li>
<li>SSPing</li>
<li>TFN2K</li>
<li>Land Exploit</li>
<li>Stacheldraht</li>
<li>WinNuke</li>
<li>Jolt2</li>
<li>Bubonic.c</li>
</ol>
</div>
<p>9.  Social Engineering</p>
<ol>
<li>None!</li>
<li>Special Assignment</li>
</ol>
<p>03-Reports</p>
<p>As a professional you will be required to report your findings to management in a meaningful, actionable way. For each tool you must know how it fits with your original plan, the outcomes from its use, and what should be done to protect the environment from its use in the future.</p>
<p>04-Recording links are listed for your review of presentations. These are updated one week after the new class.</p>
<p>Recording ##</p>
<p>Recording ##</p>
<p>You can find these links and the class schedule here:<a href="http://www.expandingsecurity.com/about/events/">http://www.expandingsecurity.com/about/events/</a></p>
<p>All content is copyright protected. Downloading or reviewing any material means you consent to the copyright restrictions placed on all works by the author. You are forbidden from using any of this material in the teaching of any class. You are only permitted to use this as a current student of Expanding Security. You are not permitted to copy or distribute these materials in any way.</p>
</div>
]]></content:encoded>
			<wfw:commentRss>http://www.expandingsecurity.com/2010/06/syllabus-hacker-04/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Syllabus Hacker 03</title>
		<link>http://www.expandingsecurity.com/2010/06/syllabus-hacker-03/</link>
		<comments>http://www.expandingsecurity.com/2010/06/syllabus-hacker-03/#comments</comments>
		<pubDate>Sat, 19 Jun 2010 22:42:33 +0000</pubDate>
		<dc:creator>Helaine</dc:creator>
				<category><![CDATA[Certified Ethical Hacker]]></category>

		<guid isPermaLink="false">http://www.expandingsecurity.com/?p=1157</guid>
		<description><![CDATA[
Please note: You will not be able to get files from the server unless you are a paid student and have been issued an account. So some links on this page will not work if you are a guest.
The steps below, the files, and links within, are numbered in order of what you will need to [...]]]></description>
			<content:encoded><![CDATA[<div>
<p>Please note: You will not be able to get files from the server unless you are a paid student and have been issued an account. So some links on this page will not work if you are a guest.</p>
<p>The steps below, the files, and links within, are numbered in order of what you will need to read and do. If this set of steps is unclear, please attend orientation for a walk-through.</p>
<p>00- Reading &#8211; The chapter in the book tracks to the class number. Two other source documents are here:</p>
<p><a href="http://www.expandingsecurity.com/wp-content/uploads/2010/06/osstmm.en_.2.2.pdf">OSSTMM</a> <a href="http://www.expandingsecurity.com/wp-content/uploads/2010/06/SP800-115.pdf">SP800-115</a></p>
<p>01-Mind map review for Note Cards, Terms and Process. For every term in the concepts section of the mindmap you should find a definition first from the book and second from your research. For every tool in the book you should make a notecard based upon Reconn Layer, Exploit Category, and Process.</p>
<p>02-Tool review</p>
<p>You must have the VMware structure in place to start labs. Every week and every class you will be assigned one tool to research, add to the database, and screen capture. Success of each student can be achieved on your own, but if we work together and meet our deadlines, we can see more tools in a shorter time than if we do it all on our own. Check in orientation for your tool assignment. Check the CEH forum for details. You should be able to discuss this tool&#8217;s function, place in the process, and comparison to other tools. The list of tools discussed this week:</p>
<p>6.  Trojans and Backdoors</p>
<div id="_mcePaste">
<ol>
<li>TCPView</li>
<li>Firekiller 2000</li>
<li>fPort</li>
<li>Inzider</li>
<li>Graffiti.exe</li>
<li>Hard disk Killer HDKP4.0</li>
</ol>
<ul>
<li>Trojan</li>
</ul>
<ol>
<li>Netcat</li>
<li>Whack-A-Mole</li>
<li>BoSniffer</li>
<li>QAZ</li>
<li>Tini</li>
<li>Donald Dick</li>
<li>SubSeven</li>
<li>Back Orifice 2000</li>
<li>Back Orifice Plug-ins</li>
<li>NetBus</li>
<li>Senna Spy</li>
<li>Beast</li>
</ol>
<ul>
<li>Communication</li>
</ul>
<ol>
<li>Reverse WWW Shell &#8211; Covert channels using HTTP</li>
<li>Loki</li>
</ol>
<ul>
<li>Programming tool</li>
</ul>
<ol>
<li>EliteWrap</li>
<li>IconPlus</li>
<li>Restorator</li>
</ol>
</div>
<p>7.  Sniffers</p>
<ol>
<li>Wireshark Ethereal</li>
<li>Macof, Mailsnarf, URLSnarf, Webspy</li>
<li>Snort</li>
<li>Ettercap</li>
<li>Windump</li>
<li>SMAC</li>
<li>Etherpeek</li>
<li>Mac Changer</li>
<li>Iris</li>
<li>NetIntercept</li>
<li>EtherFlood</li>
<li>dsniff</li>
<li>WinDNSSpoof</li>
</ol>
<div></div>
<p>03-Reports</p>
<p>As a professional you will be required to report your findings to management in a meaningful, actionable way. For each tool you must know how it fits with your original plan, the outcomes from its use, and what should be done to protect the environment from its use in the future.</p>
<p>04-Recording links are listed for your review of presentations. These are updated one week after the new class.</p>
<p>Recording ##</p>
<p>Recording ##</p>
<p>You can find these links and the class schedule here:<a href="http://www.expandingsecurity.com/about/events/">http://www.expandingsecurity.com/about/events/</a></p>
<p>All content is copyright protected. Downloading or reviewing any material means you consent to the copyright restrictions placed on all works by the author. You are forbidden from using any of this material in the teaching of any class. You are only permitted to use this as a current student of Expanding Security. You are not permitted to copy or distribute these materials in any way.</p>
</div>
]]></content:encoded>
			<wfw:commentRss>http://www.expandingsecurity.com/2010/06/syllabus-hacker-03/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Syllabus Hacker 02</title>
		<link>http://www.expandingsecurity.com/2010/06/syllabus-hacker-02/</link>
		<comments>http://www.expandingsecurity.com/2010/06/syllabus-hacker-02/#comments</comments>
		<pubDate>Sat, 19 Jun 2010 22:25:49 +0000</pubDate>
		<dc:creator>Helaine</dc:creator>
				<category><![CDATA[Certified Ethical Hacker]]></category>

		<guid isPermaLink="false">http://www.expandingsecurity.com/?p=1156</guid>
		<description><![CDATA[Please note: You will not be able to get files from the server unless you are a paid student and have been issued an account. So some links on this page will not work if you are a guest.
The steps below, the files, and links within, are numbered in order of what you will need to [...]]]></description>
			<content:encoded><![CDATA[<p>Please note: You will not be able to get files from the server unless you are a paid student and have been issued an account. So some links on this page will not work if you are a guest.</p>
<p>The steps below, the files, and links within, are numbered in order of what you will need to read and do. If this set of steps is unclear, please attend orientation for a walk-through.</p>
<p>00- Reading &#8211; The chapter in the book tracks to the class number. Two other source documents are here:</p>
<p><a href="http://www.expandingsecurity.com/wp-content/uploads/2010/06/osstmm.en_.2.2.pdf">OSSTMM</a> <a href="http://www.expandingsecurity.com/wp-content/uploads/2010/06/SP800-115.pdf">SP800-115</a></p>
<p>01-Mind map review for Note Cards, Terms and Process. For every term in the concepts section of the mindmap you should find a definition first from the book and second from your research. For every tool in the book you should make a notecard based upon Reconn Layer, Exploit Category, and Process.</p>
<p>02-Tool review</p>
<p>You must have the VMware structure in place to start labs. Every week and every class you will be assigned one tool to research, add to the database, and screen capture. Success of each student can be achieved on your own, but if we work together and meet our deadlines, we can see more tools in a shorter time than if we do it all on our own. Check in orientation for your tool assignment. Check the CEH forum for details. You should be able to discuss this tool&#8217;s function, place in the process, and comparison to other tools. The list of tools discussed this week:</p>
<p>4.  Enumeration</p>
<ol>
<li>net view,  nbstat</li>
<li>Enum</li>
<li>DumpSec</li>
<li>NAT</li>
<li>GetAcct</li>
<li>SNMPutil</li>
<li>IP Network Browser</li>
<li>sid2user</li>
<li>user2sid</li>
<li>NBTscan</li>
</ol>
<p>5.  System Hacking</p>
<ol>
<li>IKS Software Keylogger</li>
<li>Legion</li>
<li>GetAdmin</li>
<li>WinZapper</li>
<li>hk.exe</li>
<li>Evidence Eliminator</li>
<li>makestrm.exe</li>
<li>ads_cat</li>
<li>eBlaster</li>
<li>RootKit</li>
<li>elsave.exe</li>
<li>SMBDie</li>
<li>NBTDeputy</li>
<li>dskprobe.exe</li>
<li>KerbCrack</li>
<li>LOphtcrack</li>
<li>SMB Grind</li>
<li>SMBRelay</li>
<li>John the Ripper</li>
<li>Spyware: Spector</li>
</ol>
<div><strong><br />
</strong></div>
<p>03-Reports</p>
<p>As a professional you will be required to report your findings to management in a meaningful, actionable way. For each tool you must know how it fits with your original plan, the outcomes from its use, and what should be done to protect the environment from its use in the future.</p>
<p>Sample RFP from <a href="http://www.expandingsecurity.com/wp-content/uploads/2010/06/foundstone_rfp_template.doc" target="_blank">foundstone</a>.</p>
<p>04-Recording links are listed for your review of presentations. These are updated one week after the new class.</p>
<p>Recording ##</p>
<p>Recording ##</p>
<p>You can find these links and the class schedule here:<a href="http://www.expandingsecurity.com/about/events/">http://www.expandingsecurity.com/about/events/</a></p>
<p>All content is copyright protected. Downloading or reviewing any material means you consent to the copyright restrictions placed on all works by the author. You are forbidden from using any of this material in the teaching of any class. You are only permitted to use this as a current student of Expanding Security. You are not permitted to copy or distribute these materials in any way.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.expandingsecurity.com/2010/06/syllabus-hacker-02/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
