Friday, December 9, 2011

Advanced Windows Exploitation


Advanced windows exploitation is a course designed to explore and discover the vulnerabilities in Windows and exploit them. This is an advanced hard core training program for computer practitioners requiring Cyber security course sound knowledge of computer fundamentals and operating system concepts.

Advanced Windows Exploitation (AWE) is an anti-exploitation tool developed by Microsoft to prevent the bugs occurring in the system. It is a Windows Vulnerability Exploitation System that prevents illegal hacking of the computer networks. AWE was authored by Jim Gorman and Matteo Memelli.

Advanced windows exploitation is a powerful tool in the hands of vulnerability researchers and penetration testers who Best penetration testing certification exploit software vulnerabilities to gain code execution.

Advanced windows exploitation courses are offered by several- learning portals. A survey of these portals and the courses offered will help us in making the right choice.

OFFENSIVE SECURITY’S AWE:

Offensive Security, the pioneer in Backtracking, offers this drill-down, hands-on course on advanced windows exploitation. This practical Osce exam course in a lab environment is a challenging one for computer practitioners and security enthusiasts.

AWE Course Topics:

The AWE course by Offensive Security includes topics such as
  • Egghunters- understanding vulnerability and controlling the execution flow using Egghunters
  • NX Bypassing Techniques- bypassing and defeating NX
  • DEP Bypassing- Return Oriented Programming Exploitation
  • Custom Shell Code creation- Positioning independent shell code
  • Venetian  Shell Code Encoding- attacking the ?Unicode problem
  • Kernel Exploitation- communicating with kernel drivers and understanding input=output (I/O) control codes
  • Function Pointer Overwrites – studying Kernel Memory Corruption and Bypassing Device Driver checks
  • Heap Spraying- Java script Heap Internals
  • Writing immunity Plug-ins

AWE Course Duration, Fees, and Requirements:

  • The AWE Course is a 4 day course
  • On enrollment, the course entails course material , Backtrack DVDs
  • Preconfigured VMWare Machines with Ctp certification program preset vulnerabilities are provided to the students for the duration of the course. The students have to exploit the vulnerabilities.
  • The AWE Course costs $3800- $4500 depending on the scheme.
  •  The student should have a VMWare server installed Backtrack with network and DVDROM support and 60 GB HD free. 

Other AWE Courses:

·         Hawk Network Defense offers a comprehensive AWE Course which teaches exploitation of Integer Overflows, Buffer Overflows and Underflows, Format String Vulnerabilities, Structure Exception Handle (SEH) et al.

·         Immunity Inc. offers AWE courses where heap and stack overflow and DEC-RPC network are thoroughly exploited in Windows. Immunity‘s cutting edge AWE products are SPIKE, CANVAS and BODYGUARD.

·         Onzra Inc. also offers AWE courses using advanced techniques IDE evasion.

No comments:

Post a Comment