Loading Events

« All Events

Hacking for Developers, DevOps and Technologists

October 5 @ 9:00 am - 5:00 pm

Join us on October 5th, 2019 for a full day of happy hacking joy, learning by doing hands-on labs and attacking. A smile will spread across your face as you explore weaknesses in IT systems, applications and web apps, IoT devices, protocols and ICS/SCADA systems. If the ever-connected world gives you vulnerable targets, hack all the things. The OWASP Top Ten will be the focus over a variety of different types of vulnerabilities from a hacker perspective, moving beyond the white hat tester mentality.

Threat modeling Underground economies and markets where intellectual property and data are sold. Discussing the reality of the economic consequences of exploitable technology from terrorism to cyber warfare. Who knew software vulnerabilities could lead to some crazy nation on nation shi*t? You’ll learn how to find some serious issues and exploit that code so hard the original developer or vendor will feel it.

You’ll jump right in and learn with a customized Kali pen testing operating system. Using OWASP ZAP, BeEF, Metasploit, Nmap, Recon NG, Nessus, Nikto, Maltego, Shodan, Censys, alternative search engines, OSINT, SpiderFoot and metadata tools. Finding exploitable systems, scanning, sniffing for credentials, XSS reflected and stored attacks, attacking browsers via JavaScript, SQL injection, CSRF, data leaks, replay attacks, exploiting vulnerable operating systems, applications, websites, embedded systems and critical infrastructure ICS/SCADA.

You’ll also learn:
* How attackers cover their tracks and take advantage of insufficient logging and monitoring.
* How attackers discover then pivot from one weak system to another, burrowing deep into an organization to steal intellectual property, data or anything of juicy value.

Required Materials
Attendees must bring a curious mind and some technology. Caution, using a Windows 10 host operating system can sometimes be problematic due to various auto-protection mechanisms in place by Microsoft. Mac/Apple operating systems can be used as a host but try to use the VM Fusion 64-bit version.
* Laptop with administrative privileges and 8 GB of RAM with 100 GB hard disk free
* Installation of VM Ware Player or Fusion
* Network connection, RJ45 and can be a USB to RJ45
* API keys and accounts setup in advance for the course
* Bring your own hoodie

Required Text
* OWASP Version 4 Testing Guide PDF, OWASP (Free)
* Course Workbook (Provided) Print, Chris Kubecka
* Hack the World with OSINT (optional, for paid students provided)

Agenda
* Course & Attendee Intro
* Lab Machine Setup
* Hacker/ Pentester/Nation State Mentalities
* OWASP Top 10
* Recon – Intro to Methodology
* OSINT Tool Setup (OWASP ZAP, Metasploit, Nmap, SpiderFoot, Nikto, Maltego etc.)
* Recon – Hands-on Passive OSINT
* Recon – Hands-on Active OSINT
* OWASP #1 Injections
* OWASP #2 Broken Authentication
* OWASP #3 Sensitive Data Disclosure
* OWASP #4 Security Misconfiguration

You may also register at the following location – https://www.cover6solutions.com/shop/hacking-for-developers-devops-and-technologists-w-chris-kubecka-oct-4-2019/. Discounts are automatically applied for Cover6 Alumni.

Details

Date:
October 5
Time:
9:00 am - 5:00 pm
Event Category:
Website:
https://www.meetup.com/DCCyberWarriors/events/264162563/

Venue

1964 Gallows Rd
1964 Gallows Rd
Vienna, VA 22182 us
+ Google Map

Upcoming events

Cover6 Events

#DMV Meetups

Conferences

Hiring Events