Advanced Security In Windows 2000
Length: 32 hours (4 days)
Overview:
It is a theoretical-practical course where it will be deepened in the topic so that the assistants will know closely and apply the main existent security problems in Windows 2000. During the development of the course, not only will typical problems and solutions of the operative system be discussed, but it will be interacted with common applications, such as web development, databases, mail, dns, with the purpose of work deeply in all the aspects related with IT security, being aware of the problems and its solutions.
Who should take this class:
• Windows 2000 server administrators • IT officers using Windows 2000 within their networks. • Applications programmers that function on Windows platform • Technical and/or support staff for Windows environment
Prerequisites:
• Basic knowledge of windows (commands, file systems, users). • Knowledge of Windows applications (web, mail, sql, dns). • Networks and communications knowledge. • IT security basic course.
What will you learn:
• Basic and advanced security topics in Windows 2000 • Identification, enumeration and attack techniques that are commonly used by intruders to attack Windows 2000. • Protocol, ports and services vulnerabilities • Weaknesses associated to Windows 2000 default installations. • Privileged scales in Windows 2000. • Users, permissions and ACLs. • IIS, DNS, mail, web applications, LDAP etc. secure setup. • IPSec filters setup and its use as a Firewall complimentary tool. • Adequately identify and eliminate the post-exploitation tools used by the attackers when they are attacking a Windows 2000 server. • Setup and use of detection and monitoring tools.
About the Labs:
Each participant has assigned a desktop where as each topic is reviewed he/she could review its associated aspects.
Special labs have been designed for the following topics:
• Privileged scale in Windows 2000 • Local attacks in Windows 2000, attacks to the most common services. • Attack and securing of Internet Information Server. • Enumeration techniques in a Windows 2000 platform. • Secure setup of Windows 2000. • Commands and tools commonly used. • SQL Injection attacks, DNS spoofing, etc.
|