Practical Hacking II (HCKP2)
Cybersecurity, ICT Security
This hands-on course explores practical offensive and defensive techniques: map networks, identify targets, and find server and service weaknesses. Through live demos you will study network reconnaissance, vulnerability scanning, exploit development and privilege escalation.
Modules cover workstation compromises, hardening, web app testing, VoIP, mobile exploitation, ATM and car attacks, plus Darknet research. Labs combine live cases and tool reviews, focusing on web application flaws, mobile attack vectors, ATM compromise and darknet and OSINT.
THIS TRAINING COURSE WILL HELP YOU:
- Map networks and discover high-value targets
- Identify vulnerabilities and run practical exploits
- Perform privilege escalation and compromise systems
- Harden workstations, web apps, VoIP and ATMs
WHO SHOULD ATTEND?
- Security engineers and penetration testers
- System and network administrators
- Incident responders and SOC analysts
- IT staff responsible for system hardening
COURSE LOCATION AND AVAILABLE DATES
This public course is delivered online only, so you can attend remotely without travelling to a classroom. The same course can also be delivered in person as private training at your premises.
For technically demanding courses, prepared remote labs are provided, so you do not need to install anything locally.
Private training
Unlock your employees' potential. We can adapt every course in our portfolio to your objectives and participants.
Need training at your premises or want to tailor the content and duration? We will prepare the right solution, in Czech or English.
Request customised training
Course content:
Hide details
-
Network security
-
Kali Linux – introduction
-
Network reconnaissance
-
Port scanning
-
Identification of operating systems and services
-
Vulnerability identification and comparison of scanners
-
Exploitation – live hacker demonstration
-
Privilege escalation
-
Metasploitable2 and Metasploitable3
-
Vulnhub and HackTheBox
-
Practical demo of compromising several vulnerable servers
-
Linux – password storage and cracking
-
Linux – extracting plaintext passwords from memory
-
Red Teaming and Purple Teaming
-
Workstation hacking
-
Attacks via physical access
-
Privilege escalation methods
-
Attacks on system services
-
Startup Repair Attack
-
Sticky Keys Attack
-
FireWire Inception Attack
-
Cold Boot Attack
-
Workstation security
-
Role of antivirus
-
Encryption
-
System updates
-
Physical security
-
Web application security
-
OWASP Testing Guide methodology
-
OWASP Top 10
-
SQLi, XSS, CSRF, XXE, …
-
Live demonstrations of vulnerabilities
-
Tool comparisons
-
Lessons from web penetration tests
-
VoIP security
-
SIP caller number / name spoofing
-
SIP Denial of Service
-
Call eavesdropping
-
Vulnerabilities in endpoint VoIP phones
-
PBX compromise
-
Mobile phone security
-
Collecting user data on Android, iOS and Windows Mobile
-
Stored history and interesting files
-
SMS of Death
-
Call encryption
-
Attack vectors against communications
-
Physical security
-
Pattern vs PIN
-
Smudge Attack, Spearphone Attack
-
Bypassing biometric authentication
-
ATM security in practice
-
Hardware and software of ATMs used in the Czech Republic
-
Description of protections and vulnerable points
-
Examples of attack types
-
Money jackpotting
-
Skimming
-
Physical attacks
-
Experience from real ATM penetration tests
-
Car hacking
-
Attacks on central locking
-
Darknet ecosystem
-
Anonymizing networks, Deepnet and darknet, TOR structure
-
Hidden Services – including live demonstrations
-
Black markets: goods and services
-
Drugs, weapons, counterfeit money, passports, ...
-
Laundering Bitcoins
-
Attacks in TOR (de-anonymization of users, providers, Hidden Services)
-
Major TOR and Bitcoin scandals
-
NSA hacking tools
-
Analysis of the Shadow Brokers leak
-
Practical demos and descriptions of tools and exploits
-
EternalBlue, EternalRomance, EternalSynergy, EternalChampion
-
Fuzzbench, DoublePulsar, DanderSpritz
-
Social networks – Big Brother and anonymity
-
Overview of social networks with focus on Facebook
-
Collecting user data and building shadow profiles
-
Facebook Graph API Explorer
-
Potential abuse by attackers
-
Tracking by Google
-
Steganography
-
History
-
Modern uses with examples
-
Subliminal advertising
-
Microdotting – conspiracy or reality?
-
Demonstration from the NSA data leak case
-
Hiding a file inside another file
-
Alternate Data Streams in NTFS
-
DoS and DDoS attacks
-
Botnets and their evolution, trends
-
Link saturation attacks
-
Amplification attacks
-
Slow HTTP DoS
-
Hash collision DoS
-
XML Bomb
-
DDoS-as-a-service – demo of offerings
-
DDoS used for extortion
-
Prerequisites:
-
Familiarity with Windows and Linux and a basic understanding of TCP/IP network security.
-
Recommended previous course:
-
Hacking in Practice (HCKP1)
-
Schedule:
-
3 days (9:00-17:00)
-
Price per person:
-
799.60 € ( 967.52 € incl. 21% VAT)
Training and learning environment
What does the environment for in-person IT courses look like?We hold training courses in our own classrooms equipped with modern computer equipment for each participant and a large projection screen. Each workstation is fitted with a powerful computer for seamless practical exercises, and the environment supports a calm, friendly atmosphere during training.
Do I need to bring my own laptop to the classroom IT course?Our training rooms are fully equipped, so you do not need to bring your own laptop. A modern computer with all necessary hardware and software is ready for you at your workstation.
Will you receive an official certificate after completing an IT course?Yes, upon successful completion of the training course, you will receive an official ICT Pro certificate confirming your participation and acquired technical skills. You can use it to verify your qualifications or add it to your professional profile.
Where can you find our training center in Brno?The premises of the ICT Pro training center are located on the 1st floor of the COMGUARD building at Sochorova 38 in Brno. Positioned on the border of Žabovřesky and Komín, the location is easily accessible by both car and public transport.
Where can you find our training center in Prague?The premises of the ICT Pro training center are located on the 1st floor of the Opatov Park building at Líbalova 1, Prague 11 – Chodov. The location provides a comfortable environment for your education with convenient access.
What facilities and refreshments are available to you during training breaks?Our training centers feature a fully equipped kitchenette for a comfortable break during your courses. The facilities include a coffee machine, microwave, kettle, and a wide selection of drinks and snacks.
What beverage refreshments are available during your course?A beverage station with a coffee machine, teas, syrups, and water is at your disposal throughout the entire training session. You can enjoy a coffee or another drink of your choice anytime during breaks.
What light refreshments are provided for you during the courses?During course breaks, participants can enjoy light sweet snacks, pastries, and fruit syrups to mix their own drinks. Fresh water dispenser and plates are also available for your convenience.
Should I bring my own snacks to ICT Pro training?There is no need to. A wide selection of savory snacks, sweet biscuits, and snack bars is available for you during breaks. Boost your energy for all-day focus right inside the training center premises.
Can you spend training breaks in the fresh air?Yes, an outdoor terrace is available at our training center. During breaks between learning sessions, you can relax in the fresh air in a pleasant green environment.
Where can you relax during course breaks?Our training center features a spacious outdoor terrace with seating options. During breaks between learning sessions, you can step outside to relax and recharge in the fresh air.