SlideShare a Scribd company logo
1 of 12
INT 245
Penetration testing
Lecture 0
Course details
• LTP – 2 0 2
• Text Books
THE HACKER PLAYBOOK 2: PRACTICAL GUIDE TO PENETRATION TESTING by
PETER KIM, CREATESPACE INDEPENDENT PUBLISHING PLATFORM
• References:
COMPTIA PENTEST+ STUDY GUIDE: EXAM PT0-002, 2ND EDITION by MIKE
CHAPPLE, DAVID SEIDL, WILEY
STAR COURSE
This course is considered as a Star course because it has direct
contribution to the placements of students. It focuses on necessary skills
required for various job profiles in a company.
Course Outcomes
• Through this course students should be able to:
CO1 ::understand rules of engagement for safely conducting the penetration
Testing exercise within an organization
CO2 ::identify various footprinting techniques to enumerate a target
CO3 :: enumerate a vulnerability scan strategy in-line with organizational in-
scope requirements
CO4 :: demonstrate web application and mobile device exploitation using
different attacks
CO5 :: determine techniques used to conduct system hacking and launch
exploit code for remote access of a target
CO6 :: : illustrate different testing deliverables out of penetration testing
reports and suggest post corrective actions
Program Outcomes as specific to the particular course
• PO-1:Engineering knowledge::Apply the knowledge of mathematics, science, engineering fundamentals, and an engineering
specialization to the solution of complex engineering problems.
• PO-2: Problem analysis::Identify, formulate, research literature, and analyze complex engineering problems reaching substantiated
conclusions using first principles of mathematics, natural sciences, and engineering sciences.
• PO-3:Design/development of solutions::Design solutions for complex engineering problems and design system components or
processes that meet the specified needs with appropriate consideration for the public health and safety, and the cultural, societal, and
environmental considerations.
• PO-4:Conduct investigations of complex problems::Use research-based knowledge and research methods including design of
experiments, analysis and interpretation of data, and synthesis of the information to provide valid conclusions.
• PO-5: Modern tool usage::Create, select, and apply appropriate techniques, resources, and modern engineering and IT tools
including prediction and modeling to complex engineering activities with an understanding of the limitations
• PO-8:Ethics::Apply ethical principles and commit to professional ethics and responsibilities and norms of the engineering practice.
• PO-9:Individual and team work::Function effectively as an individual, and as a member or leader in diverse teams, and in
multidisciplinary settings.
• PO-12: Life-long learning::Recognize the need for, and have the preparation and ability to engage in independent and life-long
learning in the broadest context of technological change.
• PO-13: Competitive Skills::Ability to compete in national and international technical events and building the competitive spirit
Revised Bloom’s Taxonomy
The course
contents
List of practicals
• Introduction to Nmap: Basic commands of Nmap, System scanning using nmap,
interpretation of gathered information using nmap
• Vulnerability Scanning: System vulnerability scanning, identification of
vulnerabilities
• Introduction to Metasploit: Introduction to the tool, basic commands for
searching, selection, parameter configurations and deployment of exploits
• System Exploitation: Exploitation of Windows XP system using known
vulnerabilities
• Spoofing: Exploiting systems using IP Spoofing and Mac Spoofing
• Cross Site Scripting (XSS): Introduction to cross site scripting, identification of
websites vulnerable to cross site scripting
• XSS vulnerabilities identification: Identification of XSS vulnerabilities in the
websites and the way they could be exploited
• XSS Exploitation: Exploitation of XSS vulnerabilities using javascript
• SQL Injection: Introduction to SQL injection, Automated SQL injection using
SQLmap
• Manual SQL Injection: Demonstration of manual SQL injection attacks
Relevant resources
• Microsoft Word - NetCat_Intro.doc (tue.nl)
• Metasploit Course | Cybrary
• Scanning and Enumeration with NMAP Course | Cybrary
• Web Application Penetration Testing Course by Cydefe | Cybrary
• https://s3-us-west-2.amazonaws.com/stationx-public-
download/nmap_cheet_sheet_0.6.pdf
• What is SQL Injection? Tutorial & Examples | Web Security Academy
(portswigger.net)
• https://davidbombal.com/wireshark-tutorial-installation-and-
password-sniffing/
• https://www.exploit-db.com/google-hacking-database
Course Assessment Model
• Marks break up
• Attendance 5%
• CA 25%
• MTE 20%
• ETE 50%
• Total 100%
Three Class test – One before MTE and Two after MTE
CA 1-MCQs based questions-30 marks objective type questions carrying 1 mark each with no
negative marking
CA 2- BYOD practical-Based on CompTIA Pentest+ certification (one Practical question, job-
evaluation -15 marks and viva -15 marks )
CA 3- BYOD practical-30 Marks practical test. (Generating integrated Penetration testing report
on information gathering phase[5marks],scanning phase[10marks], exploiting the target [10 marks] and
suggesting remediation steps [5marks])
Recommended MOOCs course
Course
Code
Name of
MOOCs/Certifications LINK CA BENEFIT
INT245 CompTIA Pentest+ https://www.comptia.org/certifications/pentest Full course exempted
INT245
Beingcert Certified
Pentest Professional
https://www.beingcert.com/Certification/certified-
pentest-professional
All CAs +MTE
exempted
INT245
C|PENT(Certified Penetration
testing Professional)
https://www.eccouncil.org/train-certify/certified-
penetration-testing-professional-cpent/ Full course exempted
INT245
Cyber Security and
Privacy https://onlinecourses.nptel.ac.in/noc23_cs127/preview One CA exempted
Career prospects of Penetration Tester
• Application Penetration Tester
• Cyber Security Penetration Tester
• Network Penetration Tester
• Remote Penetration Tester

More Related Content

Similar to Lect0INT245.pptx

SE LAB MANUAL (R16).pdf
SE LAB MANUAL (R16).pdfSE LAB MANUAL (R16).pdf
SE LAB MANUAL (R16).pdfSRPatel10
 
OOSE Unit 3 PPT.ppt
OOSE Unit 3 PPT.pptOOSE Unit 3 PPT.ppt
OOSE Unit 3 PPT.pptitadmin33
 
Assessment and recognition in technical massive open on-line courses with and...
Assessment and recognition in technical massive open on-line courses with and...Assessment and recognition in technical massive open on-line courses with and...
Assessment and recognition in technical massive open on-line courses with and...eMadrid network
 
Innovative Educational Technology and Educational Infrastructure at MIT
Innovative Educational Technologyand Educational Infrastructureat MITInnovative Educational Technologyand Educational Infrastructureat MIT
Innovative Educational Technology and Educational Infrastructure at MITBrandon Muramatsu
 
Regtech in Fintech + QuSandbox Demo
Regtech in Fintech + QuSandbox DemoRegtech in Fintech + QuSandbox Demo
Regtech in Fintech + QuSandbox DemoQuantUniversity
 
UCD and Technical Communication: The Inevitable Marriage
UCD and Technical Communication: The Inevitable MarriageUCD and Technical Communication: The Inevitable Marriage
UCD and Technical Communication: The Inevitable MarriageChris LaRoche
 
Consulting proposal labs
Consulting proposal labsConsulting proposal labs
Consulting proposal labsAnil Sharma
 
Oxford blockchain module_breakdown
Oxford blockchain module_breakdownOxford blockchain module_breakdown
Oxford blockchain module_breakdownTiranjan Bulankulame
 
Security Patterns: Research Direction, Metamodel, Application and Verification
Security Patterns: Research Direction, Metamodel, Application and VerificationSecurity Patterns: Research Direction, Metamodel, Application and Verification
Security Patterns: Research Direction, Metamodel, Application and VerificationHironori Washizaki
 
Practical model management in the age of Data science and ML
Practical model management in the age of Data science and MLPractical model management in the age of Data science and ML
Practical model management in the age of Data science and MLQuantUniversity
 
OOSE Unit 5 PPT.ppt
OOSE Unit 5 PPT.pptOOSE Unit 5 PPT.ppt
OOSE Unit 5 PPT.pptitadmin33
 
Oose unit 3 ppt
Oose unit 3 pptOose unit 3 ppt
Oose unit 3 pptDr VISU P
 
Oose unit 5 ppt
Oose unit 5 pptOose unit 5 ppt
Oose unit 5 pptDr VISU P
 

Similar to Lect0INT245.pptx (20)

DE PPT.pptx
DE PPT.pptxDE PPT.pptx
DE PPT.pptx
 
Se syllabus
Se syllabusSe syllabus
Se syllabus
 
SE LAB MANUAL (R16).pdf
SE LAB MANUAL (R16).pdfSE LAB MANUAL (R16).pdf
SE LAB MANUAL (R16).pdf
 
OOSE Unit 3 PPT.ppt
OOSE Unit 3 PPT.pptOOSE Unit 3 PPT.ppt
OOSE Unit 3 PPT.ppt
 
Data-X-v3.1
Data-X-v3.1Data-X-v3.1
Data-X-v3.1
 
Assessment and recognition in technical massive open on-line courses with and...
Assessment and recognition in technical massive open on-line courses with and...Assessment and recognition in technical massive open on-line courses with and...
Assessment and recognition in technical massive open on-line courses with and...
 
Innovative Educational Technology and Educational Infrastructure at MIT
Innovative Educational Technologyand Educational Infrastructureat MITInnovative Educational Technologyand Educational Infrastructureat MIT
Innovative Educational Technology and Educational Infrastructure at MIT
 
Itec410 lec01
Itec410 lec01Itec410 lec01
Itec410 lec01
 
Regtech in Fintech + QuSandbox Demo
Regtech in Fintech + QuSandbox DemoRegtech in Fintech + QuSandbox Demo
Regtech in Fintech + QuSandbox Demo
 
UCD and Technical Communication: The Inevitable Marriage
UCD and Technical Communication: The Inevitable MarriageUCD and Technical Communication: The Inevitable Marriage
UCD and Technical Communication: The Inevitable Marriage
 
Rachel Resume
Rachel ResumeRachel Resume
Rachel Resume
 
Consulting proposal labs
Consulting proposal labsConsulting proposal labs
Consulting proposal labs
 
sud new resume
sud new resumesud new resume
sud new resume
 
Oxford blockchain module_breakdown
Oxford blockchain module_breakdownOxford blockchain module_breakdown
Oxford blockchain module_breakdown
 
Security Patterns: Research Direction, Metamodel, Application and Verification
Security Patterns: Research Direction, Metamodel, Application and VerificationSecurity Patterns: Research Direction, Metamodel, Application and Verification
Security Patterns: Research Direction, Metamodel, Application and Verification
 
Practical model management in the age of Data science and ML
Practical model management in the age of Data science and MLPractical model management in the age of Data science and ML
Practical model management in the age of Data science and ML
 
OOSE Unit 5 PPT.ppt
OOSE Unit 5 PPT.pptOOSE Unit 5 PPT.ppt
OOSE Unit 5 PPT.ppt
 
Oose unit 3 ppt
Oose unit 3 pptOose unit 3 ppt
Oose unit 3 ppt
 
Career Portfolio
Career PortfolioCareer Portfolio
Career Portfolio
 
Oose unit 5 ppt
Oose unit 5 pptOose unit 5 ppt
Oose unit 5 ppt
 

Recently uploaded

Best investment platform in india-Falcon Invoice Discounting
Best investment platform in india-Falcon Invoice DiscountingBest investment platform in india-Falcon Invoice Discounting
Best investment platform in india-Falcon Invoice DiscountingFalcon Invoice Discounting
 
Editing progress 20th march.docxxxxxxxxx
Editing progress 20th march.docxxxxxxxxxEditing progress 20th march.docxxxxxxxxx
Editing progress 20th march.docxxxxxxxxxMollyBrown86
 
Dubai Call Girls O525547&19 Calls Girls In Dubai (L0w+Charger)
Dubai Call Girls O525547&19 Calls Girls In Dubai (L0w+Charger)Dubai Call Girls O525547&19 Calls Girls In Dubai (L0w+Charger)
Dubai Call Girls O525547&19 Calls Girls In Dubai (L0w+Charger)kojalkojal131
 
💚😋 jamshedpur Escort Service Call Girls, 9352852248 ₹5000 To 25K With AC💚😋
💚😋 jamshedpur Escort Service Call Girls, 9352852248 ₹5000 To 25K With AC💚😋💚😋 jamshedpur Escort Service Call Girls, 9352852248 ₹5000 To 25K With AC💚😋
💚😋 jamshedpur Escort Service Call Girls, 9352852248 ₹5000 To 25K With AC💚😋nirzagarg
 
VVIP Pune Call Girls Parvati Gaon WhatSapp Number 8005736733 With Elite Staff...
VVIP Pune Call Girls Parvati Gaon WhatSapp Number 8005736733 With Elite Staff...VVIP Pune Call Girls Parvati Gaon WhatSapp Number 8005736733 With Elite Staff...
VVIP Pune Call Girls Parvati Gaon WhatSapp Number 8005736733 With Elite Staff...SUHANI PANDEY
 
Western Copper and Gold - May 2024 Presentation
Western Copper and Gold - May 2024 PresentationWestern Copper and Gold - May 2024 Presentation
Western Copper and Gold - May 2024 PresentationPaul West-Sells
 
Diligence Checklist for Early Stage Startups
Diligence Checklist for Early Stage StartupsDiligence Checklist for Early Stage Startups
Diligence Checklist for Early Stage StartupsTILDEN
 
VIP Call Girls Kheda 7001035870 Whatsapp Number, 24/07 Booking
VIP Call Girls Kheda 7001035870 Whatsapp Number, 24/07 BookingVIP Call Girls Kheda 7001035870 Whatsapp Number, 24/07 Booking
VIP Call Girls Kheda 7001035870 Whatsapp Number, 24/07 Bookingdharasingh5698
 
Ambala Escorts Service ☎️ 6378878445 ( Sakshi Sinha ) High Profile Call Girls...
Ambala Escorts Service ☎️ 6378878445 ( Sakshi Sinha ) High Profile Call Girls...Ambala Escorts Service ☎️ 6378878445 ( Sakshi Sinha ) High Profile Call Girls...
Ambala Escorts Service ☎️ 6378878445 ( Sakshi Sinha ) High Profile Call Girls...mriyagarg453
 
Indapur - Virgin Call Girls Pune | Whatsapp No 8005736733 VIP Escorts Service...
Indapur - Virgin Call Girls Pune | Whatsapp No 8005736733 VIP Escorts Service...Indapur - Virgin Call Girls Pune | Whatsapp No 8005736733 VIP Escorts Service...
Indapur - Virgin Call Girls Pune | Whatsapp No 8005736733 VIP Escorts Service...SUHANI PANDEY
 
Terna - 1Q 2024 Consolidated Results Presentation
Terna - 1Q 2024 Consolidated Results PresentationTerna - 1Q 2024 Consolidated Results Presentation
Terna - 1Q 2024 Consolidated Results PresentationTerna SpA
 
VVIP Pune Call Girls Sopan Baug WhatSapp Number 8005736733 With Elite Staff A...
VVIP Pune Call Girls Sopan Baug WhatSapp Number 8005736733 With Elite Staff A...VVIP Pune Call Girls Sopan Baug WhatSapp Number 8005736733 With Elite Staff A...
VVIP Pune Call Girls Sopan Baug WhatSapp Number 8005736733 With Elite Staff A...SUHANI PANDEY
 
VVIP Pune Call Girls Handewadi WhatSapp Number 8005736733 With Elite Staff An...
VVIP Pune Call Girls Handewadi WhatSapp Number 8005736733 With Elite Staff An...VVIP Pune Call Girls Handewadi WhatSapp Number 8005736733 With Elite Staff An...
VVIP Pune Call Girls Handewadi WhatSapp Number 8005736733 With Elite Staff An...SUHANI PANDEY
 
VIP Call Girls Junagadh 7001035870 Whatsapp Number, 24/07 Booking
VIP Call Girls Junagadh 7001035870 Whatsapp Number, 24/07 BookingVIP Call Girls Junagadh 7001035870 Whatsapp Number, 24/07 Booking
VIP Call Girls Junagadh 7001035870 Whatsapp Number, 24/07 Bookingdharasingh5698
 
Nicola Mining Inc. Corporate Presentation May 2024
Nicola Mining Inc. Corporate Presentation May 2024Nicola Mining Inc. Corporate Presentation May 2024
Nicola Mining Inc. Corporate Presentation May 2024nicola_mining
 
Dattawadi ( Call Girls ) Pune 6297143586 Hot Model With Sexy Bhabi Ready Fo...
Dattawadi ( Call Girls ) Pune  6297143586  Hot Model With Sexy Bhabi Ready Fo...Dattawadi ( Call Girls ) Pune  6297143586  Hot Model With Sexy Bhabi Ready Fo...
Dattawadi ( Call Girls ) Pune 6297143586 Hot Model With Sexy Bhabi Ready Fo...tanu pandey
 
AMG Quarterly Investor Presentation May 2024
AMG Quarterly Investor Presentation May 2024AMG Quarterly Investor Presentation May 2024
AMG Quarterly Investor Presentation May 2024gstubel
 
Teekay Tankers Q1-24 Earnings Presentation
Teekay Tankers Q1-24 Earnings PresentationTeekay Tankers Q1-24 Earnings Presentation
Teekay Tankers Q1-24 Earnings PresentationTeekay Tankers Ltd
 

Recently uploaded (20)

(INDIRA) Call Girl Kashmir Call Now 8617697112 Kashmir Escorts 24x7
(INDIRA) Call Girl Kashmir Call Now 8617697112 Kashmir Escorts 24x7(INDIRA) Call Girl Kashmir Call Now 8617697112 Kashmir Escorts 24x7
(INDIRA) Call Girl Kashmir Call Now 8617697112 Kashmir Escorts 24x7
 
Best investment platform in india-Falcon Invoice Discounting
Best investment platform in india-Falcon Invoice DiscountingBest investment platform in india-Falcon Invoice Discounting
Best investment platform in india-Falcon Invoice Discounting
 
Editing progress 20th march.docxxxxxxxxx
Editing progress 20th march.docxxxxxxxxxEditing progress 20th march.docxxxxxxxxx
Editing progress 20th march.docxxxxxxxxx
 
Dubai Call Girls O525547&19 Calls Girls In Dubai (L0w+Charger)
Dubai Call Girls O525547&19 Calls Girls In Dubai (L0w+Charger)Dubai Call Girls O525547&19 Calls Girls In Dubai (L0w+Charger)
Dubai Call Girls O525547&19 Calls Girls In Dubai (L0w+Charger)
 
💚😋 jamshedpur Escort Service Call Girls, 9352852248 ₹5000 To 25K With AC💚😋
💚😋 jamshedpur Escort Service Call Girls, 9352852248 ₹5000 To 25K With AC💚😋💚😋 jamshedpur Escort Service Call Girls, 9352852248 ₹5000 To 25K With AC💚😋
💚😋 jamshedpur Escort Service Call Girls, 9352852248 ₹5000 To 25K With AC💚😋
 
VVIP Pune Call Girls Parvati Gaon WhatSapp Number 8005736733 With Elite Staff...
VVIP Pune Call Girls Parvati Gaon WhatSapp Number 8005736733 With Elite Staff...VVIP Pune Call Girls Parvati Gaon WhatSapp Number 8005736733 With Elite Staff...
VVIP Pune Call Girls Parvati Gaon WhatSapp Number 8005736733 With Elite Staff...
 
Western Copper and Gold - May 2024 Presentation
Western Copper and Gold - May 2024 PresentationWestern Copper and Gold - May 2024 Presentation
Western Copper and Gold - May 2024 Presentation
 
Diligence Checklist for Early Stage Startups
Diligence Checklist for Early Stage StartupsDiligence Checklist for Early Stage Startups
Diligence Checklist for Early Stage Startups
 
VIP Call Girls Kheda 7001035870 Whatsapp Number, 24/07 Booking
VIP Call Girls Kheda 7001035870 Whatsapp Number, 24/07 BookingVIP Call Girls Kheda 7001035870 Whatsapp Number, 24/07 Booking
VIP Call Girls Kheda 7001035870 Whatsapp Number, 24/07 Booking
 
Ambala Escorts Service ☎️ 6378878445 ( Sakshi Sinha ) High Profile Call Girls...
Ambala Escorts Service ☎️ 6378878445 ( Sakshi Sinha ) High Profile Call Girls...Ambala Escorts Service ☎️ 6378878445 ( Sakshi Sinha ) High Profile Call Girls...
Ambala Escorts Service ☎️ 6378878445 ( Sakshi Sinha ) High Profile Call Girls...
 
Indapur - Virgin Call Girls Pune | Whatsapp No 8005736733 VIP Escorts Service...
Indapur - Virgin Call Girls Pune | Whatsapp No 8005736733 VIP Escorts Service...Indapur - Virgin Call Girls Pune | Whatsapp No 8005736733 VIP Escorts Service...
Indapur - Virgin Call Girls Pune | Whatsapp No 8005736733 VIP Escorts Service...
 
Terna - 1Q 2024 Consolidated Results Presentation
Terna - 1Q 2024 Consolidated Results PresentationTerna - 1Q 2024 Consolidated Results Presentation
Terna - 1Q 2024 Consolidated Results Presentation
 
Call Girls in Panjabi Bagh, Delhi 💯 Call Us 🔝9953056974 🔝 Escort Service
Call Girls in Panjabi Bagh, Delhi 💯 Call Us 🔝9953056974 🔝 Escort ServiceCall Girls in Panjabi Bagh, Delhi 💯 Call Us 🔝9953056974 🔝 Escort Service
Call Girls in Panjabi Bagh, Delhi 💯 Call Us 🔝9953056974 🔝 Escort Service
 
VVIP Pune Call Girls Sopan Baug WhatSapp Number 8005736733 With Elite Staff A...
VVIP Pune Call Girls Sopan Baug WhatSapp Number 8005736733 With Elite Staff A...VVIP Pune Call Girls Sopan Baug WhatSapp Number 8005736733 With Elite Staff A...
VVIP Pune Call Girls Sopan Baug WhatSapp Number 8005736733 With Elite Staff A...
 
VVIP Pune Call Girls Handewadi WhatSapp Number 8005736733 With Elite Staff An...
VVIP Pune Call Girls Handewadi WhatSapp Number 8005736733 With Elite Staff An...VVIP Pune Call Girls Handewadi WhatSapp Number 8005736733 With Elite Staff An...
VVIP Pune Call Girls Handewadi WhatSapp Number 8005736733 With Elite Staff An...
 
VIP Call Girls Junagadh 7001035870 Whatsapp Number, 24/07 Booking
VIP Call Girls Junagadh 7001035870 Whatsapp Number, 24/07 BookingVIP Call Girls Junagadh 7001035870 Whatsapp Number, 24/07 Booking
VIP Call Girls Junagadh 7001035870 Whatsapp Number, 24/07 Booking
 
Nicola Mining Inc. Corporate Presentation May 2024
Nicola Mining Inc. Corporate Presentation May 2024Nicola Mining Inc. Corporate Presentation May 2024
Nicola Mining Inc. Corporate Presentation May 2024
 
Dattawadi ( Call Girls ) Pune 6297143586 Hot Model With Sexy Bhabi Ready Fo...
Dattawadi ( Call Girls ) Pune  6297143586  Hot Model With Sexy Bhabi Ready Fo...Dattawadi ( Call Girls ) Pune  6297143586  Hot Model With Sexy Bhabi Ready Fo...
Dattawadi ( Call Girls ) Pune 6297143586 Hot Model With Sexy Bhabi Ready Fo...
 
AMG Quarterly Investor Presentation May 2024
AMG Quarterly Investor Presentation May 2024AMG Quarterly Investor Presentation May 2024
AMG Quarterly Investor Presentation May 2024
 
Teekay Tankers Q1-24 Earnings Presentation
Teekay Tankers Q1-24 Earnings PresentationTeekay Tankers Q1-24 Earnings Presentation
Teekay Tankers Q1-24 Earnings Presentation
 

Lect0INT245.pptx

  • 2. Course details • LTP – 2 0 2 • Text Books THE HACKER PLAYBOOK 2: PRACTICAL GUIDE TO PENETRATION TESTING by PETER KIM, CREATESPACE INDEPENDENT PUBLISHING PLATFORM • References: COMPTIA PENTEST+ STUDY GUIDE: EXAM PT0-002, 2ND EDITION by MIKE CHAPPLE, DAVID SEIDL, WILEY
  • 3. STAR COURSE This course is considered as a Star course because it has direct contribution to the placements of students. It focuses on necessary skills required for various job profiles in a company.
  • 4. Course Outcomes • Through this course students should be able to: CO1 ::understand rules of engagement for safely conducting the penetration Testing exercise within an organization CO2 ::identify various footprinting techniques to enumerate a target CO3 :: enumerate a vulnerability scan strategy in-line with organizational in- scope requirements CO4 :: demonstrate web application and mobile device exploitation using different attacks CO5 :: determine techniques used to conduct system hacking and launch exploit code for remote access of a target CO6 :: : illustrate different testing deliverables out of penetration testing reports and suggest post corrective actions
  • 5. Program Outcomes as specific to the particular course • PO-1:Engineering knowledge::Apply the knowledge of mathematics, science, engineering fundamentals, and an engineering specialization to the solution of complex engineering problems. • PO-2: Problem analysis::Identify, formulate, research literature, and analyze complex engineering problems reaching substantiated conclusions using first principles of mathematics, natural sciences, and engineering sciences. • PO-3:Design/development of solutions::Design solutions for complex engineering problems and design system components or processes that meet the specified needs with appropriate consideration for the public health and safety, and the cultural, societal, and environmental considerations. • PO-4:Conduct investigations of complex problems::Use research-based knowledge and research methods including design of experiments, analysis and interpretation of data, and synthesis of the information to provide valid conclusions. • PO-5: Modern tool usage::Create, select, and apply appropriate techniques, resources, and modern engineering and IT tools including prediction and modeling to complex engineering activities with an understanding of the limitations • PO-8:Ethics::Apply ethical principles and commit to professional ethics and responsibilities and norms of the engineering practice. • PO-9:Individual and team work::Function effectively as an individual, and as a member or leader in diverse teams, and in multidisciplinary settings. • PO-12: Life-long learning::Recognize the need for, and have the preparation and ability to engage in independent and life-long learning in the broadest context of technological change. • PO-13: Competitive Skills::Ability to compete in national and international technical events and building the competitive spirit
  • 8. List of practicals • Introduction to Nmap: Basic commands of Nmap, System scanning using nmap, interpretation of gathered information using nmap • Vulnerability Scanning: System vulnerability scanning, identification of vulnerabilities • Introduction to Metasploit: Introduction to the tool, basic commands for searching, selection, parameter configurations and deployment of exploits • System Exploitation: Exploitation of Windows XP system using known vulnerabilities • Spoofing: Exploiting systems using IP Spoofing and Mac Spoofing • Cross Site Scripting (XSS): Introduction to cross site scripting, identification of websites vulnerable to cross site scripting • XSS vulnerabilities identification: Identification of XSS vulnerabilities in the websites and the way they could be exploited • XSS Exploitation: Exploitation of XSS vulnerabilities using javascript • SQL Injection: Introduction to SQL injection, Automated SQL injection using SQLmap • Manual SQL Injection: Demonstration of manual SQL injection attacks
  • 9. Relevant resources • Microsoft Word - NetCat_Intro.doc (tue.nl) • Metasploit Course | Cybrary • Scanning and Enumeration with NMAP Course | Cybrary • Web Application Penetration Testing Course by Cydefe | Cybrary • https://s3-us-west-2.amazonaws.com/stationx-public- download/nmap_cheet_sheet_0.6.pdf • What is SQL Injection? Tutorial & Examples | Web Security Academy (portswigger.net) • https://davidbombal.com/wireshark-tutorial-installation-and- password-sniffing/ • https://www.exploit-db.com/google-hacking-database
  • 10. Course Assessment Model • Marks break up • Attendance 5% • CA 25% • MTE 20% • ETE 50% • Total 100% Three Class test – One before MTE and Two after MTE CA 1-MCQs based questions-30 marks objective type questions carrying 1 mark each with no negative marking CA 2- BYOD practical-Based on CompTIA Pentest+ certification (one Practical question, job- evaluation -15 marks and viva -15 marks ) CA 3- BYOD practical-30 Marks practical test. (Generating integrated Penetration testing report on information gathering phase[5marks],scanning phase[10marks], exploiting the target [10 marks] and suggesting remediation steps [5marks])
  • 11. Recommended MOOCs course Course Code Name of MOOCs/Certifications LINK CA BENEFIT INT245 CompTIA Pentest+ https://www.comptia.org/certifications/pentest Full course exempted INT245 Beingcert Certified Pentest Professional https://www.beingcert.com/Certification/certified- pentest-professional All CAs +MTE exempted INT245 C|PENT(Certified Penetration testing Professional) https://www.eccouncil.org/train-certify/certified- penetration-testing-professional-cpent/ Full course exempted INT245 Cyber Security and Privacy https://onlinecourses.nptel.ac.in/noc23_cs127/preview One CA exempted
  • 12. Career prospects of Penetration Tester • Application Penetration Tester • Cyber Security Penetration Tester • Network Penetration Tester • Remote Penetration Tester