The most trusted source for computer security training, certification and research.



select a course
Toronto, ON - October 6 - 8, 2008
Global Information Assurance Certification

SANS always provides the best training and trainers with a vast amount of knowledge.
-Mike Brennan, SSIC

SECURITY 517

Cutting-Edge Hacking Techniques

Monday, October 6, 2008 : 9am - 5pm
John Strand, SANS Certified Instructor
6 CPE Credits

Computer attackers continue their relentless march in improving their tools and techniques. The simple scanning of yesteryear has given way to powerful suites of bundled, automated scanning and exploitation tools. Straightforward backdoors have evolved into powerful kernel-mode RootKits, manipulating the very hearts of our systems. Covert channels exfiltrate sensitive information and hash collision attacks are rapidly advancing, with your systems in the cross hairs. In all of these trends, thorough reconnaissance and deep subterfuge dominate the attackers' game.

If we don't keep up with their latest methods, our overall defenses and incident response practices will grow rusty. To help fight back, this action-packed one-day course describes these latest attack trends and what you can do to thwart the bad guys. In addition to detailed descriptions of how the attacks function, you'll get hands-on experience with the tools and their defenses.

This fast-paced, intermediate-to-advanced course is ideal for students who have taken a multi-day hacking course in the past (offered by other training organizations or SANS' own 504 or 560 courses) and are looking to update their understanding and skills. Also, if you are preparing for that final push on your GCIH certification, this session can help you brush up and refresh your knowledge of computer attacks before taking the exam.

  • Who Should Attend This Course
    • Managers and professionals who have taken a multi-day hacking course seeking to update their understanding and skills
    • Professionals preparing for the GCIH or GPEN certification
  • Sampling of Topics
    • Metasploit modules, including the Meterpreter and Priv – hands on
    • New Google search techniques for finding vulnerable systems
    • Cross-Site Scripting attacks to steal sensitive information – hands on
    • IPS Fingerprinting
    • Virtual Machine Detection, the possibility of VM Escape and what it means to you – hands on
    • Recent user-mode and kernel-mode RootKits for Windows and UNIX, including Hacker Defender and Nushu
    • Hash collisions and their implications with Stripwire and Confoo – hands on
    • Late-breaking Nmap features – hands on
    • Techniques attackers use to steal a million credit cards and how to stop them

SANS delivers the best training I have seen in the industry.
-Brian Hughes, Idaho State University