|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/pentesting-with-kali-linux/
课程评论:没有评论
课程名称:使用Kali Linux进行渗透测试 概述:安全管理一直是安全专业人士面临的挑战。渗透测试不仅仅涉及网络,还包括Web应用程序。通过本课程,您将熟悉进行漏洞评估的知名工具,帮助您选择合适的工具和方法。课程采用实践导向,模拟典型的渗透测试场景。您将通过设置环境,学习如何使用Metasploit和Kali Linux工具识别并解决Windows操作系统(版本7、8.1、10)中的缺陷和漏洞。此外,您还将学习如何代理流量并实施最著名的黑客技术:传递哈希攻击。最后,您将深入理解Metasploit框架,并学习如何在成功入侵目标机器后保持访问权限,及如何破解当今网络中常用的无线安全类型,包括WEP、WPA和WPA2。 课程内容概述: 本培训项目包括两门完整课程,旨在提供最全面的培训。 第一门课程《实用Windows渗透测试》为您提供实践知识。您将学习服务识别和网络扫描技术,并掌握各种利用和后利用技术,包括如何代理流量和实施传递哈希攻击。完成后,您将能够成功识别和解决Windows OS中的漏洞。 第二门课程《Web应用程序渗透测试》将帮助您熟悉常用的漏洞评估工具。深入理解Metasploit框架,学习如何在成功入侵后保持对目标机器的访问,并了解创建有效报告的重要性,以便提交给客户。在课程结束时,您将具备在实时场景下执行渗透测试的能力,并通过一个挑战总结所学知识。 第三门课程《无线渗透测试为道德黑客》显示了如何针对无线网络及其协议执行无线渗透攻击,帮助您从根本上构建强大安全体系。您将首先学习无线理论,然后了解如何破解当今网络使用的各种无线安全技术,包括WEP、WPA和WPA2。通过使用常见的开源工具,您将掌握无线渗透测试过程的关键组件,包括设置自己的无线渗透测试实验室、进行无线网络侦查、数据包嗅探和注入,以及客户攻击。完成此课程后,您将能够进行完整的网站和服务器漏洞测试,执行无线渗透测试,并深化理解加密破解技能和顶级渗透测试者及道德黑客使用的方法。 作者介绍: - Gergely Révay:目前在德国和美国的跨国公司从事渗透测试,自2011年以来一直从事该领域工作。他曾在多个行业进行渗透测试和安全评估。 - Tajinder Kalsi:拥有超过9年的信息技术经验,在印度全国范围内的120多所大学举办过相关讲座,并参与过多个VAPT项目。他还是ISO 27001:2013审计员,曾出版过有关Linux安全的书籍,并参与过多个渗透测试视频课程的制作。 - Jason Dion:担任自由大学及其他多所大学的兼职讲师,拥有多项信息技术专业认证,具备丰富的网络工程经验,是网络操作中心副主任和信息系统官。 通过本课程的学习,您将掌握渗透测试的各个关键环节,提升自己的安全专业技能。
Managing security has always been a challenge for any security professional. Penetration testing is not only about networks but also web applications. Begin your journey by familiarizing yourself with the well-known tools to perform a vulnerability assessment. There are many tools available on the market for detecting security loopholes and networking attacks. Selecting the right tools and methods might seem confusing, but this course is designed to help navigate through those choicesThis learning path follows a practical approach with typical penetration test scenario throughout. You will start by setting up the environment and learn to identify and tackle the flaws and vulnerabilities within the Windows OS (versions 7, 8.1, 10) using Metasploit and Kali Linux tools. Along with this, you will also learn to proxy traffic and implement the most famous hacking technique: the pass-the-hash attack. You will then take a deep dive into understanding the Metasploit Framework and learn how to maintain access on the target machine when successfully exploited. Finally, you will learn how to hack each type of wireless security commonly used in today's networks, including WEP, WPA, and WPA2.Contents and OverviewThis training program includes 2 complete courses, carefully chosen to give you the most comprehensive training possible.The first course, Practical Windows Penetration Testing is hands-on to guarantee that you gain practical knowledge. You will start by setting up the environment and learn service identification and network scanning techniques. You will master various exploitation and post exploitation techniques. You will also learn to proxy traffic and implement the most famous hacking technique: the pass-the-hash attack.By the end of this video tutorial, you will be able to successfully identify and tackle the flaws and vulnerabilities within the Windows OS (versions 7, 8.1, 10) using Metasploit and Kali Linux tools.The second course, Pentesting Web Applications will help you start your journey by familiarizing yourself with the well-known tools to perform a vulnerability assessment. Take a deep dive into understanding the Metasploit Framework and learn how to maintain access on the target machine, when successfully exploited. Documentation is always essential and so is creating an effective report for submission to the customer. You will learn what to include in reports. Finally, you will be all set to perform penetration testing in a real-time scenario and will try to crack a challenge, summing up everything you have learned so far and applied it in real-time.The third course, Wireless Penetration Testing for Ethical Hacker will demonstrate how to perform wireless penetration attacks against wireless networks and their protocols in order to build strong and robust security systems from the ground up using the most popular tools in the penetration testing community.You'll learn some basic wireless theory before learning how to hack each type of wireless security commonly used in today's networks, including WEP, WPA, and WPA2. Using commonly available open source toolsets, you'll understand the key components of the wireless penetration testing process, including setting up your own wireless penetration testing lab, conducting wireless network reconnaissance (WLAN discovery), packet sniffing and injection, and client attacks..By end of this course youll be able to perform a full website and server vulnerability test, perform wireless penetration testing with popular tools and explore wireless pentesting techniques, develop encryption-cracking skills and gain insights into methods used by top pentesters and ethical hackers.About the Authors: Gergely Révay, the instructor of this course, hacks stuff for fun and profit at Multinational Corporation in Germany and in the USA. He has worked as a penetration tester since 2011; before that, he was a quality assurance engineer in his home country, Hungary. As a consultant, he did penetration tests and security assessments in various industries, such as insurance, banking, telco, mobility, healthcare, industrial control systems, and even car production.Tajinder Kalsi, with more than 9 years of working experience in the field of IT, Tajinder has conducted Seminars in Engineering Colleges all across India, on topics such as Information Security and Android Application Development at more than 120 colleges and teaching 10,000+ students. Apart from training, he has also worked on VAPT projects for various clients. When talking about certifications, Tajinder is a certified ISO 27001:2013 Auditor. Prior to this course, Tajinder has authored Practical Linux Security Cookbook published by Packt Publishing. He has also reviewed the following books: Web Application Penetration Testing with Kali Linux and Mastering Kali Linux for Advanced Penetration Testing. He has also authored 2 Video courses with Packt - Getting Started with Pentensing and Finding and Exploiting Hidden Vulnerabilities. He is best described as dedicated, devoted, and determined and a person who strongly believes in making his dreams come true. He defines himself as a tireless worker, who loves to laugh and make others laugh. I am also very friendly and level-headed.Jason Dion, CISSP No. 349867, is an Adjunct Instructor at Liberty University's College of Engineering and Computational Science and Anne Arundel Community College's Department of Computing Technologies with multiple information technology professional certifications, including Certified Information Systems Security Professional (CISSP), Certified Ethical Hacker (CEH), Certified Network Defense Architect (CNDA), Digital Forensic Examiner (DFE), Digital Media Collector (DMC), Security+, Network+, A+, and Information Technology Infrastructure Library v3. With networking experience dating back to 1992, Jason has been a network engineer, Deputy Director of a Network Operations Center, and an Information Systems Officer for large organizations around the globe.