Course Overview

Understanding the bare bones of Session, and how it can be broken to gain access to accounts. As an ethical hacker how to identify the design flaws that are being exploited and to be addressed them to secure the system and/or application. With multiple, users/systems interconnected the attack surface is huge and has a high-risk impact, it's important to secure the sessions to prevent unauthorized access. Hands-on training on each attack scenario, to identify the flaws and address them with preventive mechanisms. Look at the scenarios in a haxor way, and understand the most widely used attack patterns. Preview of Attacking and preventive mechanisms on Session management.

What You Will Learn

  • Hands-on demo on various attack scenarios to provide the knowledge as an ethical hacker
  • Various real work scenarios on bad implementations leading to different kinds of attack scenarios
  • Useful for all Security Professionals
  • as it gives a POV(Point of View) from both attack and defence standpoint.

Program Curriculum

  • Anatomy of Session
  • What is Session Hijacking
  • Types of Session Hijacking Techniques
  • Tools – Hands on
  • $7 Million Cybersecurity Scholarship by EC-Council
  • Chapter 1 Quiz

  • Introduction to HTTP
  • Types of HTTP Session
  • Introduction of Network Protocols – Part 1
  • Introduction of Network Protocols – Part 2
  • Chapter 2 Quiz

  • Cookies exploitation with XSS
  • Session Fixation
  • Session IDs manipulation with Brute Force Attack
  • Session Donation
  • MITB (Man in the Browser) - Malware
  • Chapter 3 Quiz

  • TCP Session – Predicting the sequence
  • UDP Session Hijacking
  • IP Spoofing
  • Telnet Session Hijacking
  • DNS Session Hijacking
  • ARP Spoofing
  • SSL Strip
  • Chapter 4 Quiz

  • Securing Web Applications Part 1
  • Securing Web Applications Part 2
  • Securing Network using Secure Protocols
  • Secure Architecture – Design Implementations
  • Course Conclusion - Summary
  • Chapter 5 Quiz
Load more modules

Instructor

Ashwin Iyer

Ashwin Iyer has over 8+ years of Security Experience with having completed his Masters in Cyber Security and currently leading a Red Team. Ashwin has vast and dynamic experience of having worked as a Web Developer to currently leading an Offensive security team. He has experience in both Offensive and Defensive Security and currently holds a number of security certifications like OSCP, SANS GSEC Certified, etc.

Join over 1 Million professionals from the most renowned Companies in the world!

certificate

Empower Your Learning with Our Flexible Plans

Invest in your future with our flexible subscription plans. Whether you're just starting out or looking to enhance your expertise, there's a plan tailored to meet your needs. Gain access to in-demand skills and courses for your continuous learning needs.

Monthly Plans
Annual Plans
Save 20% with our annual plans!

Pro

Ideal for continuous learning, offering extensive resources with 600+ courses and diverse Learning Paths to enhance your skills.

$ 499.00
Billed annually or $59.00 billed monthly

What is included

  • 700+ Premium Short Courses
  • 50+ Structured Learning Paths
  • Validation of Completion with all courses and learning paths
  • New Courses added every month
Early Access Offer

Pro +

Experience immersive learning with Practice Labs, CTF Challenges, and exclusive EC-Council certifications for comprehensive skill-building.

$ 599.00
Billed annually or $69.00 billed monthly

Everything in Pro and

  • 800+ Practice Lab exercises with guided instructions
  • 150+ CTF Challenges with detailed walkthroughs
  • New Practice Labs and Challenges added every month
  • 3 Official EC-Council Essentials Certifications¹ (retails at $897!)
    Exclusive Bonus with Annual Plans

¹This plan includes Digital Forensics Essentials (DFE), Ethical Hacking Essentials (EHE), and Network Defense Essentials (NDE) certifications. No other EC-Council certifications are included.

Related Courses

1 of 8