Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
Jan 2009 Free Giveaway Sponsor - Black Hat DC
Scooby Doo and the Crypto Caper - Answers and Winners
Daemon - A Contest Revealed
Hacking: The Art of Exploitation 2nd Edition
Nov 2008 Free Giveaway - Winners
Dec 2008 Free Giveaway Sponsor - SANS
Santa Claus is Hacking to Town
Plug-N-Play Network Hacking
Nov 2008 Free Giveaway Sponsor - CWNP
Daemon - A Contest Begins Now
It Happened One Friday - Answers and Winners
Daemon - A Contest
Scooby Doo and the Crypto Caper
MS Blue Hat Hackers Headline Chicago Security Con
The Pen Testing Perfect Storm Webcast Series with Skoudis, Wright, Johnson
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 22 guests and 1 member online
EH-Net Donations
Enter Amount:
$
CAD
USD
GBP
AUD
JPY
EUR
Google Ads
EH-Net News Feeds
Latest Additions
Book Recommendations
You are here:
Home
Forum
Ethical Hacking Discussions and Related Certifications
Network Pen Testing
CEH - Certified Ethical Hacker
CEH - Official Course Modules v4
CEH Study Group -- Module 22: Penetration Testing
Ethical Hacker Community Forums
January 09, 2009, 07:08:40 PM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: ChicagoCon 2009 - May 4 - 9. Boot Camps & an Ethical Hacking Conf.
www.chicagocon.com
Home
Help
Calendar
Login
Register
Ethical Hacker Community Forums
>
Ethical Hacking Discussions and Related Certifications
>
Network Pen Testing
>
CEH - Certified Ethical Hacker
>
CEH - Official Course Modules v4
(Moderators:
Dengar13
,
Oyle
) >
CEH Study Group -- Module 22: Penetration Testing
Pages: [
1
]
Go Down
« previous
next »
Print
Author
Topic: CEH Study Group -- Module 22: Penetration Testing (Read 4970 times)
0 Members and 1 Guest are viewing this topic.
Dengar13
Moderator
Full Member
Offline
Posts: 224
CEH Study Group -- Module 22: Penetration Testing
«
on:
May 21, 2006, 03:49:38 PM »
Penetration Testing
Need for a Methodology
Penetration Test vs. Vulnerability Test
Reliance on Checklists and Templates
Phases of Penetration Testing
Passive Reconnaissance
Best Practices
Results that can be expected
Indicative passive reconnaissance steps include (but are not limited to)
Introduction to Penetration Testing
Type of Penetration Testing Methodologies
Open Source Vs Proprietary Methodologies
Security Assessment Vs Security Auditing
Risk Analysis
Types of Penetration Testing
Types Ethical Hacking
Vulnerability Assessment Vs Penetration Testing
Do-it Yourself Testing
Firms Offering Penetration Testing Services
Penetration Testing Insurance
Explication of Terms of Engagement
Pen-Test Service Level Agreements
Offer of Compensation
Starting Point and Ending Points of Testing
Penetration Testing Locations
Black Box Testing
White Box Testing
Grey Box Testing
Manual Penetration Testing
Automated Penetration Testing
Selecting the Right Tools
Pen Test Using Appscan
HackerShield
Pen-Test Using Cerberus Internet Scanner
Pen-Test Using CyberCop Scanner
Pen-Test Using Foundscan
Pen-Test Using Nessus
Pen-Test Using NetRecon
Pen-Test Using Retina
Pen-Test Using SAINT
Pen-Test Using SecureNET
Pen-Test Using SecureScan
Pen-Test Using SATAN, SARA and Security Analyzer
Pen-Test Using STAT Analyzer
Pen-Test Using Twwscan
VigilEnt
WebInspect
Evaluating Different Types of Pen-Test Tools
Platform on Which Tools Will be Used
Asset Audit
Fault Tree and Attack Trees
GAP Analysis
Device Inventory
Perimeter Firewall Inventory
Web Server Inventory
Load Balancer Inventory
Local Area Network Inventory
Demilitarized Zone Firewall
Internal Switch Network Sniffer
Application Server Inventory
Database Server Inventory
Name Controller and Domain Name Server
Physical Security
ISP Routers
Legitimate Network Traffic Threat
Unauthorized Network Traffic Threat
Unauthorized Running Process Threat
Loss of Confidential Information
Business Impact of Threat
Pre-testing Dependencies
Post-testing Dependencies
Failure Management
Test Documentation Processes
Penetration Testing Tools
Defect Tracking Tools
Configuration Management Tools
Disk Replication Tools
Pen-Test Project Scheduling Tools
Network Auditing Tools
DNS Zone Transfer Testing Tools
Trace Route Tools and Services
Network Sniffing Tools
Denial of Service Emulation Tools
Traditional Load Testing Tools
System Software Assessment Tools
Operating System Protection Tools
Fingerprinting Tools
Port Scanning Tools
Directory and File Access Control Tools
File Share Scanning Tools
Password Directories
Password Guessing Tools
Link Checking Tools
Web site Crawlers
Web-Testing based Scripting Tools
Buffer Overflow Protection Tools
Buffer Overflow Generation Tools
Input Data Validation Tools
File encryption Tools
Database Assessment Tools
Keyboard Logging and Screen Reordering Tools
System Event Logging and Reviewing Tools
Tripwire and Checksum Tools
Mobile-Code Scanning Tools
Centralized Security Monitoring Tools
Web Log Analysis Tools
Forensic Data and Collection Tools
Security Assessment Tools
Multiple OS Management Tools
SANS Institute TOP 20 Security Vulnerabilities
All Operating System Platforms
Default installs of operating systems and applications
Accounts with no passwords or weak passwords
Nonexistent or incomplete backups
Large number of open ports
Not filtering packets for correct incoming and outgoing addresses
Nonexistent or incomplete logging
Vulnerable Common Gateway Interface (CGI) programs
Windows-specific
Unicode vulnerability-Web server folder traversal
Internet server application programming interface (ISAPI) extension buffer overflows
IIS Remote Data Services (RDS) exploit
Network Basic Input Output System (NetBIOS), unprotected Windows networking shares
Information leakage via null session connections
Weak hashing in SAM (Security Accounts Manager)-LanManager hash
UNIX-specific
Buffer overflows in Remote Procedure Call (RPC) services
Sendmail vulnerabilities
Bind weaknesses
Remote system command (such as rcp, rlogin, and rsh) vulnerabilities
Line Printer Daemons (LPD) vulnerabilities
Sadmind and mountd exploits
Default Simple Network Management Protocol (SNMP) strings
Penetration Testing Deliverable Templates
Test Status Report Identifier
Test Variances
Test Comprehensive Assessment
Summary of Results (Incidents)
Test Evaluation
Names of Persons (Approval)
Template Test Incident Report
Template Test Log
Active Reconnaissance
Attack Phase
Activity: Perimeter Testing
Activity: Web Application Testing – I
Activity: Web Application Testing – II
Activity: Wireless Testing
Activity: Acquiring Target
Activity: Escalating Privileges
Activity: Execute, Implant & Retract
Post Attack Phase & Activities
Automated Penetration Testing Tool - CORE Impact
Logged
A+, Net+, MCP, CEH
MCSE: Security/Messaging
MCSA: Security/Messaging
Former U.S. Marine and damn proud of it!
Dengar13
Moderator
Full Member
Offline
Posts: 224
Re: CEH Study Group -- Module 22: Penetration Testing
«
Reply #1 on:
May 21, 2006, 03:53:04 PM »
Some of the tools listed on this module are commercial and you won't see but a few questions on the exam. How can you have a question about WebInspect when it costs 25k? This is the are where I have the most experience. There are many free tools but the reporting isn't fun, in fact it is mostly manual. The commercial ones offer very robust reporting and for some people who need this for their clients the time saved is invaluable.
Logged
A+, Net+, MCP, CEH
MCSE: Security/Messaging
MCSA: Security/Messaging
Former U.S. Marine and damn proud of it!
Dengar13
Moderator
Full Member
Offline
Posts: 224
Re: CEH Study Group -- Module 22: Penetration Testing
«
Reply #2 on:
May 24, 2006, 09:47:48 AM »
What are your favorite tools to use people???
Logged
A+, Net+, MCP, CEH
MCSE: Security/Messaging
MCSA: Security/Messaging
Former U.S. Marine and damn proud of it!
Oyle
Moderator
Sr. Member
Offline
Posts: 264
"Man. Nature. Technology".
Re: CEH Study Group -- Module 22: Penetration Testing
«
Reply #3 on:
May 24, 2006, 07:47:49 PM »
I really like the SuperScan program from (I think) Foundstone that came on the CD I got from doing the CEH class, but it's really old, and along with Nmap, it really gives me hassle when I try to install it on my Inspiron XP Pro notebook. It refuses to run, don't know why.
I try to install the newest version of the Windows version of Nmap on my Inspriron, and after it Installs, I try to run it and it puts up a command window, what looks like the Nmap man page whizzes by, and then the command windows shuts. the Nmap GUI never runs. Don't know why.
Logged
MCP, MCP+I, MCSA, MCSE(NT4/W2K), CCNA, CCA, NWCCC, VH-PIRTS, CEH
--------------------
"hackers are like jedi, crackers are like the sith: do not fall prey to the dark side".
From 1337 h4x0r h4ndb00k: "the ten laws of geek", law x
-Tapeworm
don
Editor-In-Chief
Administrator
Hero Member
Offline
Posts: 2442
Editor-In-Chief
Re: CEH Study Group -- Module 22: Penetration Testing
«
Reply #4 on:
May 24, 2006, 08:36:36 PM »
Works fine on my XP system. Did you let the Nmap installation create the desktop icon or did you create it yourself? If need be, we can compare settings of the shortcut.
Don
Logged
CISSP, MCSE, CEH, Security+ SME
Negrita
Sr. Member
Offline
Posts: 289
Re: CEH Study Group -- Module 22: Penetration Testing
«
Reply #5 on:
May 25, 2006, 03:57:32 AM »
Firstly, you should read through the
Windows Install Guide
. This helped me get around the same problem that you have.
Secondly, Microsoft
purpously broke
Nmap with XP SP2. Fyodor made
a workaround
, which should work with any version later than 3.55. If you have XP SP2 and a version of Nmap earlier than 3.55 then it's time to update.
«
Last Edit: May 25, 2006, 03:59:17 AM by Negrita
»
Logged
CEH, CCSA NG/AI, NNCSS, MCP, MCSA 2003
There are 10 kinds of people, those that understand binary, and those that don't.
Oyle
Moderator
Sr. Member
Offline
Posts: 264
"Man. Nature. Technology".
Re: CEH Study Group -- Module 22: Penetration Testing
«
Reply #6 on:
May 25, 2006, 08:20:16 AM »
Oooooo, that's a big help. Explains a lot. I don't have time to play with it right now, but I should be able to later on tonight. I'll let ya know.
Thanks a lot!!!
(my favorite smiley. really says a lot).
Logged
MCP, MCP+I, MCSA, MCSE(NT4/W2K), CCNA, CCA, NWCCC, VH-PIRTS, CEH
--------------------
"hackers are like jedi, crackers are like the sith: do not fall prey to the dark side".
From 1337 h4x0r h4ndb00k: "the ten laws of geek", law x
-Tapeworm
Pages: [
1
]
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Special Events
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009
=> News Items and General Discussion About EH-Net
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> Certification
===> The Charter Study Group - Pen Test
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
=====> CEH - Official Course Modules v4
=====> CEH - Official Course Modules v5
=====> CEH - Official Course Modules v6
===> CPTS - Certified Pen Testing Specialist
=====> CPTS - Official Course Modules v5
===> CPTE - Certified Pen Testing Expert
=====> CPTE - Official Course Modules v1
===> ECSA - EC-Council Certified Security Analyst
=====> ECSA - Official Course Modules v1.2
=====> ECSA / LPT - Official Course Modules v3
===> OSCP - Offensive Security Certified Professional
===> GPEN - GIAC Certified Penetration Tester
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
=====> CHFI - Official Course Modules v2
===> EnCE - EnCase® Certified Examiner
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Hardware
=> Malware
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Gates
=> Heffner
=> Hoffman
=> RichM
=> Murray
=> J. Peltier
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
Loading...
Sponsors
Polls
How many security events including conferences and training do you attend a year:
1 - 2
3 - 4
5 - 6
7+
None - But want to
None - Choose not to
Support EH-Net
Support EH-Net by
Buying all of your
Amazon items using
the search bar above.
Try CBT Nuggets Free!
Recent Forum Topics
Other
: Windows 7 Beta Available Tomorrow
(7) by
NickFnord
Wireless
: WEP cracking, how to ping router?
(2) by
duffman984
Oct 2008 - Scooby Doo and the Crypto Caper
: Skillz October 08 Winning Entry - Creative
(2) by
rforsythe
Book Reviews
: Need a book suggestion!
(5) by
unicityd
OSCP - Offensive Security Certified Professional
: Offensive Security Releases Sample Pen Testing Report
(2) by
Chan
Web Applications
: Determine URL from IP address
(3) by
scottr
Malware
: uninstall trend mciro officescan clients
(2) by
Hack_80
Other
: openSUSE 11.1 Released
(0) by
don
Other
: Insanity?
(5) by
jason
Other
: Fedora Hits the 10 Spot
(0) by
don
Other
: FreeBSD 7.1 Released
(0) by
don
OSCP - Offensive Security Certified Professional
: Next Up OSCP101 v2.0
(39) by
don
Tools
: Core Impact Essentials
(0) by
sgt_mjc
News from the Outside World
: Google branching out a little further...
(3) by
jason
Physical Security
: Magnetic stripe card spoofing
(5) by
jason
Gates
: Oracle version module for metasploit
(3) by
RoleReversal
Malware
: THe website is Evil but what to do??
(3) by
NickFnord
CEH - Certified Ethical Hacker
: Helow... help some tutorials...
(7) by
K3lV1n
CEH - Certified Ethical Hacker
: CEH is a scam
(20) by
K3lV1n
Mass Media
: Daniel Suarez Interview
(9) by
blackazarro
Malware
: Security Forecast for 2009
(5) by
jason
News from the Outside World
: Is this acceptable?
(9) by
jason
Wireless
: Wireless Pen Testing Cards
(6) by
jason
Oct 2008 - Scooby Doo and the Crypto Caper
: Skillz October 08 Winning Entry - Technical
(1) by
jason
Book Reviews
: [Article]-Mitnick - The Art Of Intrusion: Ch 1 - Hacking The Casinos For A Million Bu...
(5) by
jason
Links to cool sites.
: Free Computer Engineering Classes From Stanford
(3) by
jason
Oct 2008 - Scooby Doo and the Crypto Caper
: [Article]-Scooby Doo and the Crypto Caper - Answers and Winners
(2) by
jason
News Items and General Discussion About EH-Net
: [Article]-Jan 2009 Free Giveaway Sponsor - Black Hat DC
(1) by
jason
News Items and General Discussion About EH-Net
: EH-Net Milestone - 2 Articles Cross 1 Million Page Views
(3) by
BillV
Other
: What kind of lab, machines you have for your security testing?
(12) by
charlottebandit
Malware
: Network Virus Problem
(9) by
RoleReversal
Wireless
: WUSB600N good usb ?
(2) by
nap191
Other
: FBI code cracking challenge
(3) by
jimbob
Calendar Of Events
: RSA 2009
(0) by
don
Forensics
: Network Forensic tools/practice/techniques
(2) by
jimbob
Malware
: Autoplay when i try to open the drive.
(4) by
jimbob
CEH - Certified Ethical Hacker
: Any Practice Environment for learning tool for CEH?
(15) by
don
Wireless
: a petri-dish bridge
(2) by
don
CEH - Certified Ethical Hacker
: TFTP Tranfer time out
(5) by
jason
Tools
: tool to trace users
(8) by
pseud0
Vote For EH-Net
progenic.com
binarica.com
technorati fave
Privacy Notice
for TDCC & All Properties
© 2009 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.