Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
September 2010 Free Giveaway Sponsor - APT by Joe McCray
August 2010 Free Giveaway Winners - CareerAcademy.com
Maltego 3: First Look
July 2010 Free Giveaway Winner - SANS vLive
Review: SANS FOR610 Reverse Engineering Malware
Book Review: The Art of Assembly Language 2nd Ed
June 2010 Free Giveaway Winner - Black Hat USA
Interview: Lenny Zeltser of Savvis and SANS Institute
The Guide to Neuroscience for Social Engineers
May 2010 Free Giveaway Winners - eLearnSecurity
April 2010 Free Giveaway Winners - CBT Nuggets
Tutorial: SEH Based Exploits and the Development Process
Review: eLearnSecurity’s Penetration Testing Pro (PTP)
March 2010 Free Giveaway Winners - Offensive Security
Miracle on Thirty-Hack Street - Answers and Winners
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 30 guests and 2 members online
EH-Net News Feeds
Latest Additions
Book Recommendations
You are here:
Home
Ethical Hacking Discussions and Related Certifications
Network Pen Testing
CEH - Certified Ethical Hacker
CEH - Official Course Modules v4
CEH Study Group -- Module 22: Penetration Testing
EH-Net
September 09, 2010, 01:58:51 AM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
:
Advertise on EH-Net!!
- Reasonable Rates, Highly Targeted Audience.
Home
Help
Calendar
Login
Register
EH-Net
>
Ethical Hacking Discussions and Related Certifications
>
Network Pen Testing
>
CEH - Certified Ethical Hacker
>
CEH - Official Course Modules v4
(Moderators:
Dengar13
,
Oyle
) >
CEH Study Group -- Module 22: Penetration Testing
Pages: [
1
]
Go Down
« previous
next »
Print
Author
Topic: CEH Study Group -- Module 22: Penetration Testing (Read 7179 times)
0 Members and 1 Guest are viewing this topic.
Dengar13
Moderator
Sr. Member
Offline
Posts: 376
CEH Study Group -- Module 22: Penetration Testing
«
on:
May 21, 2006, 03:49:38 PM »
Penetration Testing
Need for a Methodology
Penetration Test vs. Vulnerability Test
Reliance on Checklists and Templates
Phases of Penetration Testing
Passive Reconnaissance
Best Practices
Results that can be expected
Indicative passive reconnaissance steps include (but are not limited to)
Introduction to Penetration Testing
Type of Penetration Testing Methodologies
Open Source Vs Proprietary Methodologies
Security Assessment Vs Security Auditing
Risk Analysis
Types of Penetration Testing
Types Ethical Hacking
Vulnerability Assessment Vs Penetration Testing
Do-it Yourself Testing
Firms Offering Penetration Testing Services
Penetration Testing Insurance
Explication of Terms of Engagement
Pen-Test Service Level Agreements
Offer of Compensation
Starting Point and Ending Points of Testing
Penetration Testing Locations
Black Box Testing
White Box Testing
Grey Box Testing
Manual Penetration Testing
Automated Penetration Testing
Selecting the Right Tools
Pen Test Using Appscan
HackerShield
Pen-Test Using Cerberus Internet Scanner
Pen-Test Using CyberCop Scanner
Pen-Test Using Foundscan
Pen-Test Using Nessus
Pen-Test Using NetRecon
Pen-Test Using Retina
Pen-Test Using SAINT
Pen-Test Using SecureNET
Pen-Test Using SecureScan
Pen-Test Using SATAN, SARA and Security Analyzer
Pen-Test Using STAT Analyzer
Pen-Test Using Twwscan
VigilEnt
WebInspect
Evaluating Different Types of Pen-Test Tools
Platform on Which Tools Will be Used
Asset Audit
Fault Tree and Attack Trees
GAP Analysis
Device Inventory
Perimeter Firewall Inventory
Web Server Inventory
Load Balancer Inventory
Local Area Network Inventory
Demilitarized Zone Firewall
Internal Switch Network Sniffer
Application Server Inventory
Database Server Inventory
Name Controller and Domain Name Server
Physical Security
ISP Routers
Legitimate Network Traffic Threat
Unauthorized Network Traffic Threat
Unauthorized Running Process Threat
Loss of Confidential Information
Business Impact of Threat
Pre-testing Dependencies
Post-testing Dependencies
Failure Management
Test Documentation Processes
Penetration Testing Tools
Defect Tracking Tools
Configuration Management Tools
Disk Replication Tools
Pen-Test Project Scheduling Tools
Network Auditing Tools
DNS Zone Transfer Testing Tools
Trace Route Tools and Services
Network Sniffing Tools
Denial of Service Emulation Tools
Traditional Load Testing Tools
System Software Assessment Tools
Operating System Protection Tools
Fingerprinting Tools
Port Scanning Tools
Directory and File Access Control Tools
File Share Scanning Tools
Password Directories
Password Guessing Tools
Link Checking Tools
Web site Crawlers
Web-Testing based Scripting Tools
Buffer Overflow Protection Tools
Buffer Overflow Generation Tools
Input Data Validation Tools
File encryption Tools
Database Assessment Tools
Keyboard Logging and Screen Reordering Tools
System Event Logging and Reviewing Tools
Tripwire and Checksum Tools
Mobile-Code Scanning Tools
Centralized Security Monitoring Tools
Web Log Analysis Tools
Forensic Data and Collection Tools
Security Assessment Tools
Multiple OS Management Tools
SANS Institute TOP 20 Security Vulnerabilities
All Operating System Platforms
Default installs of operating systems and applications
Accounts with no passwords or weak passwords
Nonexistent or incomplete backups
Large number of open ports
Not filtering packets for correct incoming and outgoing addresses
Nonexistent or incomplete logging
Vulnerable Common Gateway Interface (CGI) programs
Windows-specific
Unicode vulnerability-Web server folder traversal
Internet server application programming interface (ISAPI) extension buffer overflows
IIS Remote Data Services (RDS) exploit
Network Basic Input Output System (NetBIOS), unprotected Windows networking shares
Information leakage via null session connections
Weak hashing in SAM (Security Accounts Manager)-LanManager hash
UNIX-specific
Buffer overflows in Remote Procedure Call (RPC) services
Sendmail vulnerabilities
Bind weaknesses
Remote system command (such as rcp, rlogin, and rsh) vulnerabilities
Line Printer Daemons (LPD) vulnerabilities
Sadmind and mountd exploits
Default Simple Network Management Protocol (SNMP) strings
Penetration Testing Deliverable Templates
Test Status Report Identifier
Test Variances
Test Comprehensive Assessment
Summary of Results (Incidents)
Test Evaluation
Names of Persons (Approval)
Template Test Incident Report
Template Test Log
Active Reconnaissance
Attack Phase
Activity: Perimeter Testing
Activity: Web Application Testing – I
Activity: Web Application Testing – II
Activity: Wireless Testing
Activity: Acquiring Target
Activity: Escalating Privileges
Activity: Execute, Implant & Retract
Post Attack Phase & Activities
Automated Penetration Testing Tool - CORE Impact
Logged
A+, Net+, MCP, CEH
MCSE: Security/Messaging
MCSA: Security/Messaging
Former U.S. Marine and damn proud of it!
Dengar13
Moderator
Sr. Member
Offline
Posts: 376
Re: CEH Study Group -- Module 22: Penetration Testing
«
Reply #1 on:
May 21, 2006, 03:53:04 PM »
Some of the tools listed on this module are commercial and you won't see but a few questions on the exam. How can you have a question about WebInspect when it costs 25k? This is the are where I have the most experience. There are many free tools but the reporting isn't fun, in fact it is mostly manual. The commercial ones offer very robust reporting and for some people who need this for their clients the time saved is invaluable.
Logged
A+, Net+, MCP, CEH
MCSE: Security/Messaging
MCSA: Security/Messaging
Former U.S. Marine and damn proud of it!
Dengar13
Moderator
Sr. Member
Offline
Posts: 376
Re: CEH Study Group -- Module 22: Penetration Testing
«
Reply #2 on:
May 24, 2006, 09:47:48 AM »
What are your favorite tools to use people???
Logged
A+, Net+, MCP, CEH
MCSE: Security/Messaging
MCSA: Security/Messaging
Former U.S. Marine and damn proud of it!
Oyle
Moderator
Sr. Member
Offline
Posts: 264
"Man. Nature. Technology".
Re: CEH Study Group -- Module 22: Penetration Testing
«
Reply #3 on:
May 24, 2006, 07:47:49 PM »
I really like the SuperScan program from (I think) Foundstone that came on the CD I got from doing the CEH class, but it's really old, and along with Nmap, it really gives me hassle when I try to install it on my Inspiron XP Pro notebook. It refuses to run, don't know why.
I try to install the newest version of the Windows version of Nmap on my Inspriron, and after it Installs, I try to run it and it puts up a command window, what looks like the Nmap man page whizzes by, and then the command windows shuts. the Nmap GUI never runs. Don't know why.
Logged
MCP, MCP+I, MCSA, MCSE(NT4/W2K), CCNA, CCA, NWCCC, VH-PIRTS, CEH
--------------------
"hackers are like jedi, crackers are like the sith: do not fall prey to the dark side".
From 1337 h4x0r h4ndb00k: "the ten laws of geek", law x
-Tapeworm
don
Editor-In-Chief
Administrator
Hero Member
Offline
Posts: 3294
Editor-In-Chief
Re: CEH Study Group -- Module 22: Penetration Testing
«
Reply #4 on:
May 24, 2006, 08:36:36 PM »
Works fine on my XP system. Did you let the Nmap installation create the desktop icon or did you create it yourself? If need be, we can compare settings of the shortcut.
Don
Logged
CISSP, MCSE, CEH, Security+ SME
Negrita
Sr. Member
Offline
Posts: 289
Re: CEH Study Group -- Module 22: Penetration Testing
«
Reply #5 on:
May 25, 2006, 03:57:32 AM »
Firstly, you should read through the
Windows Install Guide
. This helped me get around the same problem that you have.
Secondly, Microsoft
purpously broke
Nmap with XP SP2. Fyodor made
a workaround
, which should work with any version later than 3.55. If you have XP SP2 and a version of Nmap earlier than 3.55 then it's time to update.
«
Last Edit: May 25, 2006, 03:59:17 AM by Negrita
»
Logged
CEH, CCSA NG/AI, NNCSS, MCP, MCSA 2003
There are 10 kinds of people, those that understand binary, and those that don't.
Oyle
Moderator
Sr. Member
Offline
Posts: 264
"Man. Nature. Technology".
Re: CEH Study Group -- Module 22: Penetration Testing
«
Reply #6 on:
May 25, 2006, 08:20:16 AM »
Oooooo, that's a big help. Explains a lot. I don't have time to play with it right now, but I should be able to later on tonight. I'll let ya know.
Thanks a lot!!!
(my favorite smiley. really says a lot).
Logged
MCP, MCP+I, MCSA, MCSE(NT4/W2K), CCNA, CCA, NWCCC, VH-PIRTS, CEH
--------------------
"hackers are like jedi, crackers are like the sith: do not fall prey to the dark side".
From 1337 h4x0r h4ndb00k: "the ten laws of geek", law x
-Tapeworm
Pages: [
1
]
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Special Events
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> News Items and General Discussion About EH-Net
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Cyber Warfare
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
=====> CEH - Official Course Modules v4
=====> CEH - Official Course Modules v5
=====> CEH - Official Course Modules v6
===> CPTS - Certified Pen Testing Specialist
=====> CPTS - Official Course Modules v5
===> CPTE - Certified Pen Testing Expert
=====> CPTE - Official Course Modules v1
===> ECSA - EC-Council Certified Security Analyst
=====> ECSA - Official Course Modules v1.2
=====> ECSA / LPT - Official Course Modules v3
===> OSCP - Offensive Security Certified Professional
===> GPEN - GIAC Certified Penetration Tester
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
=====> CHFI - Official Course Modules v2
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Hardware
=> Malware
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Gates
=> Haddix
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Support EH-Net
Help Support EH-Net with Our Amazon Store
Try CBT Nuggets Free!
Recent Forum Topics
Security
: Looing for app pen testing and VOIP pen testing courses
(3) by
dynamik
Incident Response
: SIEM and incident response
(10) by
pseud0
Other
: What do you think it takes to be a Pen Test Ninja?
(20) by
sil
Network Pen Testing
: Masters Degree
(5) by
ziggy_567
Calendar Of Events
: Ekoparty 6°
(0) by
don
Career Central
: CISA certification, now what?
(1) by
partek
News Items and General Discussion About EH-Net
: [Article]-August 2010 Free Giveaway Winners - CareerAcademy.com
(12) by
pizza1337
Calendar Of Events
: ToorCon 12
(0) by
don
Calendar Of Events
: RSA Conference Japan 2010
(1) by
don
Security
: Learn Security Online
(10) by
impelse
Tutorials
: Metasploit Auxiliary Module: SHODAN Enumerator
(0) by
Manu Zacharia (-M-)
News from the Outside World
: Snoop Dogg, Ethical Hacker?
(4) by
recursivenickname
Programming
: Reverse engineering = epeen?
(14) by
dynamik
General Certification
: OWASP AppSec USA 2010 web application security conference
(0) by
crossover
Network Pen Testing
: Future of pen testing
(1) by
T_Bone
Physical Security
: Learning lock picking
(9) by
shaqazoolu
Cyber Warfare
: Please guys, I really need your help
(9) by
shaqazoolu
Network Pen Testing
: Penetration Tool list
(4) by
dynamik
Other
: Solaris 8 - from bin to root
(9) by
dynamik
Physical Security
: No Tech Hacking
(1) by
sil
Tutorials
: Post your Cheat Sheets
(9) by
sachitre
News Items and General Discussion About EH-Net
: [Article]-September 2010 Free Giveaway Sponsor - APT by Joe McCray
(5) by
awesec
Web Applications
: crossdomain.xml file
(0) by
T_Bone
Network Pen Testing
: CREST Information
(2) by
T_Bone
Links to cool sites.
: Security Solutions Contest - By Symantec - Be King For a Week!
(0) by
Manu Zacharia (-M-)
Tutorials
: Re: How to...
(3) by
evereter
Links to cool sites.
: LM, NTLM, & MD5 Online password Cracker "Plan-text.info"
(8) by
don
Wireless
: Does Mobile Security Deserve New Board?
(3) by
dynamik
Tools
: hacking tools: pc keylogger, mac keylogger, mobile keylogger
(4) by
evereter
Tools
: Python Keylogger
(1) by
evereter
Calendar Of Events
: BSidesKC 2010
(1) by
TheParanoidDroid
Security
: Advice for next certifications wanted
(16) by
don
Calendar Of Events
: BSidesOttawa 2010
(1) by
H1t M0nk3y
News from the Outside World
: Hackers accidentally give Microsoft their code
(3) by
MaXe
Calendar Of Events
: BSidesDelaware 2010
(1) by
Ketchup
Calendar Of Events
: Black Hat Abu Dhabi 2010
(0) by
don
Calendar Of Events
: BSidesDFW 2010
(0) by
don
Calendar Of Events
: BSidesAtlanta 2010
(0) by
don
Calendar Of Events
: t2'10 Infosec Conference
(0) by
don
General Certification
: A+ and Net+
(11) by
mallaigh
Vote For EH-Net
progenic.com
technorati fave
Privacy Notice
for TDCC & All Properties
© 2010 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.