Learn Social Engineering From Scratch
Welcome to my comprehensive course on Social Engineering! In this course, you will start as a beginner with no previous knowledge about penetration testing or hacking, we will start with the basics of social engineering, and by end of it you’ll be at an advanced level being able to hack into all major operating systems (windows, OS X and Linux), generate different types of trojans and deliver them using smart social engineering techniques.
This course is focused on the practical side of penetration testing without neglecting the theory . Before jumping into penetration testing, you will first learn how to set up a lab and install needed software to practice penetration testing safely on your own machine, then the course is divided into the four main sections:
1. Information Gathering – This section will teach you how to gather information about your target weather it is a company, website or just a person. You will learn how to discover anything that is associated with your target such as websites, links, companies, people, emails, phone numbers, friends, social networks accounts …etc, you will also learn how to graph all of this information and use it to build a smart attack strategy.
2. Generating Evil Files – In this section you will learn how to generate evil files (files that do tasks you want on the target computer), this includes backdoors, keyloggers, credential harvester and more, you will learn how to generate these files for Windows, OS X and Linux, not only that but you’ll also learn how to enhance these files to make them bypass all anti-virus programs, and make them look and function just like any other file such as an image or a pdf, you’ll also learn how to embed these files in legitimate Microsoft Office documents.
3. Deliver Methods – In this section you will learn a number of social engineering methods to deliver trojans to the target, you will learn how to create fake websites that look identical to websites the target trusts, send emails that appear like they’re coming from people the target trusts and use fake login pages and fake updates to hack into the target system, not only that but you’ll also learn advanced social engineering techniques that would lure the target into visiting an evil URL and hack into the target system without even interacting with them.
4. Post Exploitation – In this section you will learn how to interact with the systems you compromised so far. You’ll learn how to access the file system (read/write/upload/execute), maintain your access, escalate your privileges, spy on the target, use the target computer as a pivot to hack other computer systems and more!
Finally at the end of the course you will learn how to protect yourself and your systems from these attacks.
All the attacks in this course are practical attacks that work against real computers, in each technique you will understand the theory behind it and how it works, then you’ll learn how to use that technique in a real life scenario, so by the end of the course you’ll be able to modify these techniques or combine them to come up with more powerful attacks and adopt them to different scenarios and different operating systems.
- Basic IT Skills.
- No Linux, programming or hacking knowledge required.
- Computer with a minimum of 4GB ram/memory.
- Operating System: Windows / OS X / Linux.
Who this course is for:
- Anybody looking to learn ethical hacking / social engineering.
- Anybody looking to learn how hackers hack into secure systems that do not have any vulnerabilities.
- Anybody looking to learn how to secure their systems from social engineering attacks.
NOTE: This course is created for educational purposes only and all the attacks are launched in my own lab or against devices that I have permission to test.
NOTE: This course is totally a product of Zaid Sabih & zSecurity and No other organization is associated for certification exam for the same.
- Lectures 106
- Quizzes 0
- Duration 12 hours
- Skill level All levels
- Language English
- Students 5116
- Certificate No
- Assessments Yes
Preparation - Creating a Penetration Testing Lab
Preparation - Linux Basics
Information Gathering - Gathering Info About A Company/Website
Information Gathering - Gathering Info About A Person
Windows Malware - Generating Undetectable Backdoors
- Installing Veil Framework
- Veil Overview & Payloads Basics
- Generating An Undetectable Backdoors For Windows
- Listening For Incoming Connections
- Hacking A Windows 10 Machine Using The Generated Backdoor
- Introduction to The Fat Rat
- Generating An Undetectable Backdoor for Windows – Method 2
- Introduction to Empire
- Creating An Empire Listener
- Creating a Windows Powershell Stager & Hacking Windows 10
- Modifying Backdoor Source To Bypass All Anti-virus Programs
Windows Malware - Spying
Windows Malware - Enhancing Malware
Windows Malware - Creating Trojans
- Download & Execute Payload
- Embedding Evil Files With Any File Type Like An Image Or PDF
- Running Evil Files Silently In The Background
- Changing Trojan’s Icon
- Spoofing File Extension from .exe to anything else (pdf, png ..etc)
- Download & Execute Payload (Method 2)
- Embedding Evil Files With Any File Type Like An Image Or PDF (Method 2)
- Embedding backdoor In A Legitimate Microsoft Office Document
- Embedding Any Evil File In A Legitimate Microsoft Office Document
Mac OS X Malware
- Hacking Mac OS X Using A Meterpreter Backdoor
- Hacking Mac OS X Using An Empire Stager
- Converting Basic Backdoor To An Executable
- Embedding A Normal File With Backdoor
- Generating a Basic Trojan For Max OS X
- Changing Trojan’s Icon
- Configuring The Trojan To Run Silently
- Embedding Backdoor In A Legitimate Microsoft Office Document
- Hacking Into Linux-Like Systems Using One Command
- More Advanced Linux Backdoor
- Using A Remote Keylogger To Capture Key Strikes Including Passwords
- Recovering Saved Passwords From A Local Machine
- Execute & Report Payload
- Recovering Saved Passwords From A Remote Machine
- Embedding Evil Code In A Legitimate Linux Package – Part 1
- Embedding Evil Code In A Legitimate Linux Package – Part 2
- Backdooring a Legitimate Android App
- Mail Deliver – Setting up an SMTP Server
- Mail Delivery – Spoofing Emails
- Hacking OS X & Linux Using Pure Social Engineering Without Sending Any Files
- Creating A Replica Of Any Website / Login Page
- Stealing Login Info Using Fake A Login Page
- BeEF Overview & Basic Hook Method
- Injecting BeEF’s Hook In Any Webpage
- Luring Target Into Accessing Evil URL Without Direct Interaction
- Basic BeEF Commands
- Stealing Credentials/Passwords Using A Fake Login Prompt
- Hacking Windows 10 Using A Fake Update
- Hacking Mac OS X Using A Fake Update
- Hacking Linux Using A Fake Update
Using The Above Attacks Outside The Local Network
Post Exploitation - Meterpreter
- Meterpreter Basics
- File System Commands
- Maintaining Access Basic Methods
- Maintaining Access – Using a Reliable & undetectable Method
- Spying – Capturing Key Strikes & Taking Screen Shots
- Pivoting – Theory (What is Pivoting?)
- Pivoting – Exploiting Devices on The Same Network As The Hacked Computer
- Controlling Android Phone & Accessing Mic, Camera, Messages, File System & More
- Maintaining Access On OS X
Post Exploitation - Empire