Showing posts with label EC-Council. Show all posts

Crypto Ransomware Found On EC-Council Website That Runs A Certified Hacker Program



A ransomware was found on the official website of EC-Council that runs Certified Ethical hacker program. After EC-Council did not reply to Fox-IT in the context of the malware injected in their site, Fox-IT decided to go public with this news, the excerpt of which can be read at the end of this blog post.

The website http://iclass.eccouncil.org/, the official website of EC-Council, a new Mexico-based professional organization that runs the Certified Ethical Hacker program, the nemesis of a malware was found this Monday.

Shortly after the malware was found, researchers from security firm Fox-ITnotified EC-Council officials found that one of their subdomains was under the influence of a schemer who had injected angler, a toolkit that provides powerful Web drive-by exploits.

                                 A redirect was embedded at the bottom of the page as seen in this screenshot
Angler toolkit first appeared in late 2013. Since then, it has significantly grown in popularity in the cyber underworld. Angler toolkit evades detection by changing the variations of the various components it uses (HTML, JavaScript, Flash, Silverlight, Java and more).

On Thursday, after receiving no reply from the EC-Council and still seeing that the website was infected, Fox-IT published a blog post showing that the company had failed to respond them.
                      The ransom note presented to instruct the victim on ways to recover files
Unlike other drive-by attacks, this one is very hard for the researchers to replicate. Moreover, this exploit only targets the visitors using Internet Explorer and only when they come to the site from search engines like Google, Bing, Yahoo etc. Even though these conditions are met, people from certain IP addresses from certain geographic locales are also spared.
Here is an excerpt from the Fox-IT team:
Through this embedding the client is redirected a couple of times to avoid/frustrate/stop manual analysis and some automated systems. Once the user has jumped through all the redirects he/she ends up on the Angler exploit kit landing page from which the browser, flash player plugin or Silverlight plugin will be exploited. The Angler exploit kit first starts the ‘Bedep’ loader on an exploited victim machine which will download the final payload. The way the redirect occurs on the EC-COUNCIL website is through PHP code on the web server which is injecting the redirect into the web page. A vulnerability in the EC-COUNCIL website is most likely exploited as it runs the very popular WordPress CMS which has been a target through vulnerable plug-ins for years.


Monday, March 28, 2016

Career Academy – EC-Council Certified Security Analyst / Licensed Penetration Tester + LAB DVD


Career Academy – EC-Council Certified Security Analyst / Licensed Penetration Tester + LAB DVD
Genre: Training | ISO | English | 15.59 GB


The ECSA/LPT training program is a highly interactive security course designed to teach Security Professionals the advanced uses of the available methodologies, tools and techniques required to perform comprehensive information security tests. Students will learn how to design, secure and test networks to protect your organization from the threats hackers and crackers pose. By teaching the LPT methodology and ground breaking techniques for security and penetration testing, this course will help you perform the intensive assessments required to effectively identify and mitigate risks to the security of your infrastructure.
As students learn to identify security problems, they also learn how to avoid and eliminate them, with the course providing complete coverage of analysis and network security-testing topics. This course will prepare you to pass exam 412-79 to achieve EC-Council Certified Security Analyst (ECSA) certification
Career Academy is an EC-Council endorsed training provider. We have invited the best security trainers in the industry to help us develop the ultimate training and certification program which includes everything you will need to fully prepare for and pass your certification exams. This officially endorsed product gives our students access to the exam by providing you with a Voucher Number. The EC-Council Voucher Number can be used at any Prometric center, this voucher number is required and mandatory for you to schedule and pay for your exam. Without this voucher number Prometric will not entertain any of your requests to schedule and take the exam.

Course outline:-

Module 00 – Student Introduction
Module 01 – The Need for Security Analysis
Module 02 – Advanced Googling
Module 03 – TCP/IP Packet Analysis
Module 04 – Advanced Sniffing
Module 05 – Vulnerability Analysis
Module 06 – Advanced Wireless
Module 07 – Designing a DMZ
Module 08 – Snort Analysis
Module 09 – Log Analysis
Module 10 – Advanced Exploits and Tools
Module 11 – Penetration Testing Methodologies
Module 12 – Customers and Legal Agreements
Module 13 – Rules of Engagement
Module 14 – Penetration Testing Planning and Scheduling
Module 15 – Customers and Legal Agreements
Module 16 – Information Gathering
Module 17 – Vulnerability Analysis
Module 18 – External Penetration Testing
Module 19 – Internal Network Penetration Testing
Module 20 – Router and Switches Penetration Testing
Module 21 – Firewall Penetration Testing
Module 22 – IDS Penetration Testing
Module 23 – Wireless Network Penetration Testing
Module 24 – Denial of Service Penetration Testing
Module 25 – Password Cracking Penetration Testing
Module 26 – Social Engineering Penetration Testing
Module 27 – Stolen Laptops, PDAs, and Cell Phones Penetration Testing
Module 28 – Application Penetration Testing
Module 29 – Physical Security Penetration Testing
Module 30 – Database Penetration Testing
Module 31 – VoIP Penetration Testing
Module 32 – VPN Penetration Testing
Module 33 – War Dialing
Module 34 – Virus and Trojan Detection
Module 35 – Log Management Penetration Testing
Module 36 – File Integrity Checking
Module 37 – Bluetooth and Hand Held Device Penetration Testing
Module 38 – Telecommunication and Broadband Communication Penetration Testing
Module 39 – Email Security Penetration Testing
Module 40 – Security Patches Penetration Testing
Module 41 – Data Leakage Penetration Testing
Module 42 – Penetration Testing Deliverables and Conclusion
Module 43 – Penetration Testing Report and Documentation Writing
Module 44 – Penetration Testing Report Analysis
Module 45 – Post Testing Actions
Module 46 – Ethics of a Licensed Penetration Tester
Module 47 – Standards and Compliance


Download Torrent:





Monday, March 28, 2011

CEH : Certified Ethical Hacker



Course Outline :

Module 01: Introduction to Ethical Hacking

Module 02: Footprinting and Reconnaissance

Module 03: Scanning Networks

Module 04: Enumeration

Module 05: System Hacking

Module 06: Trojans and Backdoors

Module 07: Viruses and Worms

Module 08: Sniffers

Module 09: Social Engineering

Module 10: Denial of Service

Module 11: Session Hijacking

Module 12: Hacking Webservers

Module 13: Hacking Web Applications

Module 14: SQL Injection

Module 15: Hacking Wireless Networks

Module 16: Evading IDS, Firewalls, and Honeypots

Module 17: Buffer Overflow

Module 18: Cryptography

Module 19: Penetration Testing


Download Here :

http://www.megaupload.com/?d=XW119AMI
Thursday, March 24, 2011

Pageviews

Followers

Powered by Blogger.

- Copyright © 2013 Selva Sharing -Selvasharing- Powered by Blogger - Designed by @ Access -