The most trusted source for computer security training, certification and research.



Security 553: Metasploit for Penetration Testers
SANS@Home SEC 553 - 200902
Webcast Classroom Training
Monday, February 23, 2009 - Wednesday, February 25, 2009

CLOSED
Course Fee: $495.00
OnDemand Fee: $99.00


Instructors: Paul Asadoorian & John Strand
Start Date:  Monday, February 23, 2009
End Date:  Wednesday, February 25, 2009
Meeting Times:  7:00 PM - 10:00 PM EST
Meeting Days
  • Monday, February 23
  • Wednesday, February 25
Where:
World Wide Web
Secure Site Requires Login ID & Password

Bios:
 Paul Asadoorian: Paul has over 5 years experience working in the information security field. His work experience covers both major corporations and academic institutions. He currently holds two SANS GIAC certifications in intrusion detection (GCIA, GIAC Certified Intrusion Analyst) and incident response (GCIH, GIAC Certified Incident Handler). Paul also sits on the GIAC advisory board, has spent one year as a GCIA authorized grader, and continues to stay involved in the SANS Institute, contributing monthly to the SANS Advisor Newsletter. His research can be found in the book Network Intrusion Detection, 3rd edition, the SANS Reading Room web site, and SecurityFocus. Paul has presented for numerous organizations and conferences, including MIT Security Camp, and ISACA (Information Systems Audit and Control Association). Paul graduated from Bryant College with a bachelor of science in Computer Information Systems and currently works full-time for a large University, owns and operates his own security consulting business and maintains a security blog/podcast (http://pauldotcom.com).


 John Strand: John Strand currently is the owner and senior security researcher with Black Hills Information Security, and a consultant with Argotek, Inc for TS/SCI programs. As a certified SANS instructor he teaches: 504 "Hacker Techniques, Exploits and Incident Handling," 517, "Cutting Edge Hacking Techniques," and 560 "Network Penetration Testing." He is a contributing author of Nagios 3 Enterprise Network Monitoring, and a regular contributor to SearchSecurity's "Ask the Expert" series on the latest information security threats. He also regularly posts videos demonstrating the latest computer attacks and defenses at vimeo.com/album/26207. He started the practice of computer security with Accenture Consulting in the areas of intrusion detection, incident response, and vulnerability assessment/penetration testing. John then moved on to Northrop Grumman specializing in DCID 6/3 PL3-PL5 (multi-level security solutions), security architectures, and program certification and accreditation. He has a master's degree from Denver University and is currently also a professor at Denver University. In his spare time he writes loud rock music and makes various futile attempts at fly-fishing.

Testing your network for new vulnerabilities before the bad guys do should be a top priority for any organization. Unfortunately, developing tools and code to test for vulnerabilities in existing commercial and in-house software can be a tiring process. The Metasploit Project™ was designed to help fulfill this need. Using various components of The Metasploit Project™, you can rapidly develop tools to not only test for, but verify software vulnerabilities that may lurk on your network.

Attendees will become familiar with the various components of the Metasploit Project™, how to use those components to test and verify their networks, methods for detecting Metasploit, and how to develop custom exploit modules. The course concludes with a hands-on section, where the knowledge learned can be tested against virtual machines.

This course is well suited for penetration testers and ethical hackers. In addition, systems administrators, incident responders, and systems auditors can benefit from this course by learning how to quickly and efficiently develop tools to test and verify software vulnerabilities.

Attendees are expected to have a basic understanding of software exploits and hacker techniques.

It is imperative that you get written permission from the proper authority in your organization before using these tools and techniques on your company's system as well as advise your network and computer operations teams of your testing.

Who Should Attend:

  • Network administrators
  • Systems administrators
  • Penetration testers
  • Auditors
  • Incident responders
Full Course Description >>