Course Outline. ◉ Module I: Introduction to Ethical Hacking. ◉ Module II: Footprinting. ◉ Module III: Scanning. ◉ Module IV: Enumeration. ◉ Module V: System. Certified Ethical Hacker (CEH) v Official Pages · CEH v9: Certified Ethical Hacker Version 9 Study Guide. Pages·· Certified e-Business Professional • 3. Certified e-Business Consultant • 4. E++ Certified Technical Consultant • 5. Certified Ethical Hacker Bl-Council BC- Council.

Ethical Hacking Module I Introduction to Ethical Hacking EC-Council Module Objective Understanding the importance of security Introducing ethical hacking and essential terminology for the module Understanding the different phases involved in an exploit by a hacker Overview of attacks and identification of exploit categories Comprehending ethical hacking Legal implications of hacking Hacking, law and punishment EC-Council Problem Definition — Why Security? Evolution of technology focused on ease of use Increasing complexity of computer infrastructure administration and management Decreasing skill level needed for exploits Direct impact of security breach on corporate asset base and goodwill Increased networked environment and network based applications EC-Council Can Hacking Be Ethical? A threat is a potential violation of security. Vulnerability — Existence of a weakness, design, or implementation error that can lead to an unexpected, undesirable event compromising the security of the system. Attack — An assault on system security that derives from an intelligent threat. An attack is any action that violates security.

Sometimes, hackers harden the system from other hackers as well to own the system by securing their exclusive access with Backdoors, RootKits, Trojans and Trojan horse Backdoors. EC-Council Phase 5 - Covering Tracks Covering Tracks refers to the activities undertaken by the hacker to extend his misuse of the system without being detected. Reasons include need for prolonged stay, continued use of resources, removing evidence of hacking, avoiding legal action etc.

Examples include Steganography, tunneling, altering log files etc. Hackers can remain undetected for long periods or use this phase to start a fresh reconnaissance to a related target system.

Ethical (ceh) v3.0 official certified course.pdf hacker

Comprises of hackers with a social or political agenda Aims at sending across a message through their hacking activity and gaining visibility for their cause and themselves.

It remains a fact however, that gaining unauthorized access is a crime, no matter what the intent. Reconnaissance and Covering Tracks phases If hired by any organization, an ethical hacker asks the organization what it is trying to protect, against whom and what resources it is willing to expend in order to gain protection. In-depth knowledge about target platforms such as windows, Unix, Linux. Knowledgeable about security areas and related issues — though not necessarily a security professional.

EC-Council How do they go about it? Any security evaluation involves three components: Preparation — In this phase, a formal contract is signed that contains a non-disclosure clause as well as a legal clause to protect the ethical hacker against any prosecution that he may attract during the conduct phase.

The contract also outlines infrastructure perimeter, evaluation activities, time schedules and resources available to him. Conduct — In this phase, the evaluation technical report is prepared based on testing potential vulnerabilities. Local network — This mode simulates an employee with legal access gaining unauthorized access over the local network. Stolen equipment — This mode simulates theft of a critical information resource such as a laptop owned by a strategist, taken by the client unaware of its owner and given to the ethical hacker.

Click here. Eligibility process source Applicants who do not attend training must prove 2 years of information security experience via the application form found here: An attack is any action that violates security. Exploit — A defined way to breach the security of an IT system through vulnerability.

V3.0 (ceh) course.pdf official ethical hacker certified

EC-Council Elements of Security Security is a state of well-being of information and infrastructures in which the possibility of successful yet undetected theft, tampering, and disruption of information and services is kept low or tolerable Any hacking event will affect any one or more of the essential security elements.

Could be future point of return when noted for ease of entry for an attack when more is known on a broad scale about the target.

EC-Council Phase 1 - Reconnaissance contd. Passive reconnaissance involves monitoring network data for patterns and clues.

Scanning can include use of dialers, port scanners, network mapping, sweeping, vulnerability scanners etc. The hacker exploits the system. The exploit can occur over a LAN, locally, Internet, offline, as a deception or theft. Examples include stack- based buffer overflows, denial of service, session hijacking, password filtering etc.

Certified Ethical Hacker (CEH) v3.0 Official Course.pdf

Influencing factors include architecture and configuration of target system, skill level of the perpetrator and initial level of access obtained. The hacker has exploited a vulnerability and can tamper and compromise the system.

Sometimes, hackers harden the system from other hackers as well to own the system by securing their exclusive access with Backdoors, RootKits, Trojans and Trojan horse Backdoors. EC-Council Phase 5 - Covering Tracks Covering Tracks refers to the activities undertaken by the hacker to extend his misuse of the system without being detected.