• Log In
  • Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • HomePage
  • Instructor
  • Syllabus
  • Schedule
    • First Half of the Semester
      • Week 1: Course Introduction
      • Week 2: Meterpreter, Avoiding Detection, Client Side Attacks, and Auxiliary Modules
      • Week 3: Social Engineering Toolkit, SQL Injection, Karmetasploit, Building Modules in Metasploit, and Creating Exploits
      • Week 4: Porting Exploits, Scripting, and Simulating Penetration Testing
      • Week 5: Independent Study – Perform Metasploit Attack and Create Presentation
      • Week 6: Ettercap
      • Week 7: Introduction to OWASP’s WebGoat application
    • Second Half of the Semester
      • Week 8: Independent Study
      • Week 9: Introduction to Wireless Security
      • Week 10: Wireless Recon, WEP, and WPA2
      • Week 11: WPA2 Enterprise, Wireless beyond WiFi
      • Week 12: Jack the Ripper, Cain and Able, Delivery of Sample Operating Systems
      • Week 13: Independent Study – Analyze provided Operating System Samples and Create Assessment Report
      • Week 14: Deliver Assessment to Operating System Class either in person or via teleconferenc
  • Assignments
    • Analysis Reports
    • Group Project Report and Presentation
  • Webex
  • Harvard Coursepack
  • Gradebook

MIS 5212-Advanced Penetration Testing

MIS 5212 - Section 001 - Wade Mackey

Fox School of Business

Week 12

Microsoft Issues Emergency Patch For Critical Flaw In Windows Containers

May 4, 2018 by Younes Khantouri Leave a Comment

Just a few days prior to its monthly patch release, Microsoft released an emergency patch for a critical vulnerability in the Windows Host Compute Service Shim (hcsshim) library that could allow remote attackers to run malicious code on Windows computers.

Windows Host Compute Service Shim (hcsshim) is an open source library that helps “Docker for Windows” execute Windows Server containers using a low-level container management API in Hyper-V.

Discovered by Swiss developer and security researcher Michael Hanselmann, the critical vulnerability (tracked as CVE-2018-8115) is the result of the failure of the hcsshim library to properly validate input when importing a Docker container image

https://thehackernews.com/2018/05/windows-docker-containers.html

 

 

Card Data Stolen From 5 Million Saks and Lord & Taylor Customers

April 14, 2018 by Elizabeth V Calise 1 Comment

Cybercriminals have obtained more than five million credit & debit card numbers from customers of Saks Fifth Avenue and Lord & Taylor. The data was stolen using software that was implanted into the cash register systems at the stores. The investigation continues, but its e-commerce platform appears to not have been affected by the breach. However, the company has not stated how may customer accounts or stores were affected by the attack. This theft is one of the largest known breaches of a retailer and demonstrates how hard it is to secure credit-card transaction systems.

It was found that a group of Russian-speaking hackers known as Fin7 or JokerStash posted online that it had obtained a cache of five million stolen card numbers. Fin7 did not state where the numbers had been obtained. It is unclear how the malware was installed in the stores checkout systems, but it was stated that it was most likely from phishing emails.

Click here for the link.

U.S. Sees Wave of New Cyber Attacks on Energy Infrastructure

April 11, 2018 by Donald Hoxhaj Leave a Comment

https://oilprice.com/Geopolitics/International/US-Sees-Wave-Of-New-Cyber-Attacks-On-Energy-Infrastructure.html

United States has recently seen cyber-attacks on 7 natural gas pipeline operators. The attackers targeted 3rd party communications system Latitude Technologies. The result was that several services broke down. It’s still unclear whether any customer data was stolen in these attacks. Additionally, 4 pipeline providers namely Oneok, Boardwalk Pipeline Partners, Energy Transfer Partners and Eastern Shore Natural Gas confirmed that even they were attacked. This is a double-edged sword because energy industry continues to grow and increasingly become more and more dependent on automation and internet. The industry is particularly vulnerable to these attacks because of the invaluable amounts of customer information, profiles of customers, energy strategies, and business data.

Cybersecurity experts say that these hackers could potentially cause spills, fires, and service disruptions all from the comfort of their own home.

FireEye sees repeat cyber-attacks rising in Indian companies

April 11, 2018 by Donald Hoxhaj Leave a Comment

https://economictimes.indiatimes.com/tech/ites/fireeye-sees-repeat-cyber-attacks-rising-in-indian-companies/articleshow/63623311.cms

One of the reports published by FireEye says that many Indian companies are subjected to cyber-attacks and are quite repetitive. Out of all the industries, Education and Telecommunication industries have been the most common targets. Seems like over 49% of the customers in India and the APAC region have been victims of cyber-attacks in a year. Tim Wellsmore, director for threat intelligence-APAC at FireEye briefs that India is in a difficult position. Organisations are increasingly being re-targeted and there is a certain lack of skill shortage making governments and organisations ill-equipped to handle sophisticated attacks.

Week 11 and 12 Presentations

April 5, 2018 by Wade Mackey 3 Comments

Advanced Penetration Testing -Week-11 Advanced Penetration Testing -Week-12

Primary Sidebar

Weekly Discussions

  • Uncategorized (10)
  • Week 01 (18)
  • Week 02 (9)
  • Week 03 (13)
  • Week 04 (17)
  • Week 05 (12)
  • Week 06 (16)
  • Week 07 (2)
  • Week 08 (8)
  • Week 09 (5)
  • Week 10 (10)
  • Week 11 (5)
  • Week 12 (5)
  • Week 13 (2)
  • Week 14 (7)

Copyright © 2025 · Magazine Pro Theme on Genesis Framework · WordPress · Log in