Ethical Hacking: Session Hijacking

Ethical Hacking: Session Hijacking

1h 14mIntermediate2021-01-07

Authors

Malcolm Shore

Malcolm Shore

Cybersecurity Expert, Former Director of GCSB

Course details

One of the most sophisticated forms of cyberattacks is session hijacking. Hackers take over network, web, or service sessions—the valid interactions of unsuspecting users—in order to gain unauthorized access to data and systems and attack an organization from the inside. The root failure is weaknesses in common protocols. To prevent these attacks, IT security professionals need to know which protocols are vulnerable and how to test their systems for exposure.

This course teaches you what session hijacking is, and how black-hat hackers use it to attack an organization. Learn how TCP, web, and wireless protocols work and how hackers exploit them. Find out how to use built-in Windows and Linux tools, as well as specialized third-party solutions such as Zed Attack Proxy (ZAP) and Cain, to detect and shore up vulnerabilities. Author and cybersecurity expert Malcolm Shore also discusses remote hijacking, which allows hackers to take control of drones or even vehicles.

Skills covered

Security TestingLinuxCert PrepCybersecurityOpen Source

Concepts

0. Introduction

  • 01 - Understanding session hijacking
  • 02 - What you should know before watching this course
  • 03 - Disclaimer

1. Network Session Hijacking

  • 04 - Understanding TCP sequence numbers
  • 05 - Hijacking a Telnet session
  • 06 - Real-world hijacks

2. Web Session Hijacking

  • 07 - Understanding web sessions
  • 08 - Understanding WebSockets
  • 09 - Banking on Zero
  • 10 - Hijacking sessions using man-in-the-browser
  • 11 - Intercepting sessions through man-in-the-middle
  • 12 - Stripping SSL to downgrade the session
  • 13 - Hijacking an HTTP session through cookies
  • 14 - Using Subterfuge to hijack sessions through ARP poisoning
  • 15 - Using Webscarab-NG as a web proxy

3. Additional Tools

  • 16 - Using Zed Attack Proxy (ZAP)
  • 17 - Using Cain

4. Service Hijacking

  • 18 - Hijacking SSH sessions
  • 19 - DNS hijacking
  • 20 - Cloud hijacking

5. Hijacking in the Physical World

  • 21 - Going physical - Hijacking cars and drones
  • 22 - Getting more physical with drones

Conclusion

  • 23 - Next steps
40,000 Toman