• Log In
  • Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • HomePage
  • Instructor
  • Syllabus
  • Schedule
    • First Half of the Semester
      • Week 1: Course Introduction
      • Week 2: Meterpreter, Avoiding Detection, Client Side Attacks, and Auxiliary Modules
      • Week 3: Social Engineering Toolkit, SQL Injection, Karmetasploit, Building Modules in Metasploit, and Creating Exploits
      • Week 4: Porting Exploits, Scripting, and Simulating Penetration Testing
      • Week 5: Independent Study – Perform Metasploit Attack and Create Presentation
      • Week 6: Ettercap
      • Week 7: Introduction to OWASP’s WebGoat application
    • Second Half of the Semester
      • Week 8: Independent Study
      • Week 9: Introduction to Wireless Security
      • Week 10: Wireless Recon, WEP, and WPA2
      • Week 11: WPA2 Enterprise, Wireless beyond WiFi
      • Week 12: Jack the Ripper, Cain and Able, Delivery of Sample Operating Systems
      • Week 13: Independent Study – Analyze provided Operating System Samples and Create Assessment Report
      • Week 14: Deliver Assessment to Operating System Class either in person or via teleconferenc
  • Assignments
    • Analysis Reports
    • Group Project Report and Presentation
  • Webex
  • Harvard Coursepack
  • Gradebook

MIS 5212-Advanced Penetration Testing

MIS 5212 - Section 001 - Wade Mackey

Fox School of Business

BIlaal Williams

Cybercriminals Seized Control of Brazilian Bank for 5 Hours

April 5, 2017 by BIlaal Williams Leave a Comment

Cybercriminals for five hours one day took over the online operations of a major bank and intercepted all of its online banking, mobile, point-of-sale, ATM, and investment transactions in an attack that employed valid SSL digital certificates and Google Cloud to support the phony bank infrastructure. The attackers also obtained valid digital certificates for their poser bank’s servers via Let’s Encrypt, a legitimate HTTPS certificate provider, to dupe customers who, when they logged into their online accounts, were redirected to the phony systems.The bank didn’t deploy the two-factor authentication option offered by Registro.br, which left the financial institution vulnerable to an authentication-type attack as well as authentication-type flaws such as CSRF. This was a major bank heist, as this bank has $25 billion in assets, 5 million customers worldwide, and 500 branches in Brazil, Argentina, the US, and the Cayman Islands. According to the article many more banks are at risk; most banks in Latin America rely on a third-party DNS provider for their infrastructure, and at least half of the top 20 largest banks in the world use DNS providers for some or all of their DNS infrastructure.

Article

Exploiting “Vulnerable Server” for Windows 7

February 27, 2017 by BIlaal Williams 3 Comments

This is a tutorial I found which shows how to discover and test an exploit in Windows 7. The tutorial involves using a debugger to test an application that has been sent a buffer overflow and identify the spot in memory to place the shellcode. The tutorial doesn’t get too much into assembly and offers a pretty clear description when needed. There is also a tutorial to exploit Windows applications that have DEP using ROP (a topic that was touched on in Metasploit Unleashed in “Exploit Payloads-MSFrop”).

https://samsclass.info/127/proj/vuln-server.htm
https://samsclass.info/127/proj/rop.htm

Metasploit Project

February 22, 2017 by BIlaal Williams Leave a Comment

Metasploit PowerPoint

Executive Summary

Metasploit Valentines Day update

February 17, 2017 by BIlaal Williams Leave a Comment

This article is from the weekly blog post from Rapid 7. There’s a few interesting topics talked about, such as their suggestion for users to use post exploitation modules, a new exploit to exfiltrate data from Cisco Firepower Management console, a new stateless Android meterpreter module and a new module for hacking into cars remotely. This blog seems like a good way to stay updated on new modules and updates to the Metasploit framework and news in the offsec community.

https://community.rapid7.com/community/metasploit/blog/2017/02/09/metasploit-framework-valentines-update

Primary Sidebar

Weekly Discussions

  • Uncategorized (35)
  • Week 01 (2)
  • Week 02 (14)
  • Week 03 (13)
  • Week 04 (10)
  • Week 05 (7)
  • Week 06 (29)
  • Week 07 (8)
  • Week 08 (1)
  • Week 09 (6)
  • Week 10 (12)
  • Week 11 (7)
  • Week 12 (4)
  • Week 13 (6)
  • Week 14 (18)

Copyright © 2025 · Magazine Pro Theme on Genesis Framework · WordPress · Log in