1-800-THE-TREE (1-800-843-8733)
 

Hands-On Vulnerability Assessment: Protecting Your Organization

Exposing Network Weaknesses

 
Course: 589     Type: Hands-On Training     Duration: 4 Days

Quick Enroll    

You Will Learn How To
  • Detect and respond to vulnerabilities that put your organization at risk using scanners
  • Employ real-world exploits and evaluate their effect on your systems
  • Configure vulnerability scanners
  • Analyze the results of vulnerability scans
  • Assess vulnerability alerts and advisories
  • Establish a strategy for vulnerability management

Course Benefits
Knowledge of vulnerability assessment and hacking techniques allows you to detect vulnerabilities before your networks are attacked. In this course, you learn to configure and use vulnerability scanners to detect weaknesses and prevent network exploitation. You acquire the knowledge to assess the risk to your enterprise from an array of vulnerabilities and to minimize your exposure to costly security breaches.

Who Should Attend
Security auditors, firewall/IDS personnel, PCI security testers, network managers and others involved in securing enterprise systems. Experience with network security at the level of Course 468, "System and Network Security Introduction," is assumed. A working knowledge of TCP/IP is also assumed.

Hands-On Training
Exercises provide you with practical experience assessing vulnerabilities and include:
  • Configuring scanners
  • Port scanning and enumeration
  • Scanning infrastructure, servers and desktops
  • Exploiting browsers, IDS, SQL and buffer overflows
  • Investigating and preventing spyware
  • Creating custom vulnerability tests
  • Performing a risk assessment
  • Interpreting scanning reports
  • Identifying false positives and negatives
  • Comparing scanner results

Course 589 Content
Fundamentals
Introduction
  • Defining vulnerability, exploit, threat and risk
  • Identifying the goals of assessments
  • Creating a vulnerability report
  • Conducting an initial scan
  • Common Vulnerabilities and Exposure (CVE) list
Scanning and exploits
  • Vulnerability detection methods
  • Types of scanners
  • Port scanning and OS fingerprinting
  • Enumerating targets to test information leakage
  • Types of exploits: worm, spyware, backdoor, rootkits, Denial of Service (DoS)
  • Deploying exploit frameworks
Analyzing Vulnerabilities and Exploits
Uncovering infrastructure vulnerabilities
  • Scanning the infrastructure
  • Uncovering switch weaknesses
  • Vulnerabilities in Ethereal and Wireshark
  • Network management tool attacks
Attacks against firewalls and IDS
  • Firewall weaknesses
  • Identifying the Snort IDS buffer overflow
  • Corrupting memory with format string errors
Exposing server vulnerabilities
  • Scanning servers: assessing vulnerabilities on your network
  • Canonicalization and privilege escalation
  • Catching input validation errors
  • Performing buffer overflow attacks
  • SQL injection
  • Cross-site scripting (XSS) and cookie theft
Revealing desktop vulnerabilities
  • Scanning for desktop vulnerabilities
  • Client buffer overflows
  • Silent downloading: spyware and adware
  • Attacking cross-application vulnerabilities
  • Identifying browser plug-in weaknesses
Configuring Scanners and Generating Reports
Implementing scanner operations and configuration
  • Choosing credentials, ports and dangerous tests
  • Identifying dependencies
  • Preventing false negatives
  • Creating custom vulnerability tests
  • Fixing Nessus scans
  • Handling false positives
Creating and interpreting reports
  • Filtering and customizing reports
  • Interpreting differential reports
  • Contrasting the results of different scanners
  • Producing a differential report
Assessing Risks in a Changing Environment
Researching alert information
  • Using the National Vulnerability Database (NVD) to find relevant vulnerability and patch information
  • Evaluating and investigating security alerts and advisories
  • Determining vulnerability severity
  • Employing the Common Vulnerability Scoring System (CVSS)
Identifying factors that affect risk
  • Evaluating the impact of a successful attack
  • Calculating vulnerability severity
  • Weighing important risk factors
  • Performing a risk assessment
Managing Vulnerabilities
The vulnerability management cycle
  • Applying a vulnerability process
  • Standardizing scanning with Open Vulnerability Assessment Language (OVAL)
  • Patch and configuration management
Vulnerability controversies
  • Rewards for vulnerability discovery
  • Bounties on hackers
  • Legal issues and disclosure

Related Courses
  
 
Request More Info

Salutation

First Name

Last Name

Company

Zip Code

Country
   Codes
Work Phone

Extension

E-mail

A representative will contact you to follow up your request.
Privacy Statement

Save Up to 40% per course on the Training Passport!

Hands-On Vulnerability Assessment: Protecting Your Organization
Upcoming Dates
Feb 3 - 6, 2009
 New York
Mar 17 - 20, 2009
 Washington, DC (Reston, VA)
Mar 31 - Apr 3, 2009
 Ottawa
Apr 28 - May 1, 2009
 Washington, DC (Rockville, MD)
Jul 21 - 24, 2009
 New York
Sep 29 - Oct 2, 2009
 Ottawa

Hands-On Vulnerability Assessment: Protecting Your Organization
Bring Learning Tree On-Site

Course Tuition
$ 2,790 Standard Tuition
Tuition with a Savings Plan
$ 1,800 10-Day Pass
$ 1,670 Training Passport
$ 1,700 Premium-Pass
$ 2,200 Voucher 10-Pack
$ 2,515 Alumni Gold Discount
$ 2,484 Government Discount
 

 

Hands-On Vulnerability Assessment: Protecting Your Organization
Hands-On Vulnerability Assessment: Protecting Your Organization
Course participants scanning networks for vulnerabilities.
The most recent 100 evaluations scored this course at:

  (3.81/4.00)


CPE 23 Credits 2 Hour(s) College Credit
Customer Service or Enroll: 1-800-843-8733