← Fundamentals Of Ethical Hacking Level Two · Lesson 3 of 9

Module Two

📖 Every lesson in this course is free to read right here, no account needed. Create a free account to track your progress, take the exam, and earn your certificate.
1

Course Outline

Ethical Hacking Level Two · Course Outline

Introduction to Ethical Hacking – Level Two

intermediate · 10–14 weeks
Prerequisites: Ethical Hacking L1, networking, Linux CLI, Kali basics
Delivery: instructor-led / self-paced + hands-on labs
Assessment: quizzes · labs · final project
Learning Objectives
Plan & scope assessments Advanced recon & scanning Exploit wired & wireless Web app (OWASP Top 10) Post-exploitation & lateral Professional reporting
Course Modules
1. Penetration Testing Methodologies
  • PTES, OWASP Testing Guide
  • Rules of engagement & scope
  • MITRE ATT&CK fundamentals
Lab: scope a mock engagement
2. Advanced Recon & OSINT
  • Google Dorking, Shodan, Maltego
  • Nmap NSE, firewall evasion
  • Recon-ng automation
Lab: network reconnaissance
3. Enumeration & Vulnerability Assessment
  • SMB, SNMP, LDAP enumeration
  • Nessus / OpenVAS deployment
  • Risk rating & prioritization
Lab: vulnerability scanning
4. System Hacking & Password Attacks
  • Hydra, John, Hashcat
  • Privilege escalation (Windows / Linux)
  • UAC bypass & Linux vectors
Lab: crack passwords & escalate
5. Web App Hacking – Part 1
  • OWASP Top 10 deep dive
  • SQL injection (error/union/blind)
  • XSS (reflected, stored, DOM)
Lab: SQLi & XSS on DVWA
6. Web App Hacking – Part 2
  • CSRF, command injection
  • File upload vulnerabilities
  • Burp Suite, OWASP ZAP
Lab: full web app pentest
7. Wireless Network Hacking
  • WEP, WPA/WPA2, WPA3
  • Aircrack-ng, Kismet
  • Rogue AP & evil twin
Lab: crack WPA2 handshake
8. Post-Exploitation & Persistence
  • Reverse shells, escalation
  • Persistence & backdoors
  • PowerShell Empire
Lab: maintain access
9. Sniffing & MITM Attacks
  • Wireshark, tcpdump
  • ARP poisoning, DHCP starvation
  • Ettercap & session hijack
Lab: MITM & traffic capture
10. Evasion & Countermeasures
  • IDS/IPS evasion
  • Fragmentation & protocol manipulation
  • Detection avoidance
Lab: evasion techniques
11. Social Engineering Fundamentals
  • Pretexting, phishing, vishing
  • GoPhish, BeEF framework
  • Browser exploitation
Lab: phishing campaign
12. Emerging Tech: Cloud, Mobile, IoT
  • AWS / Azure / GCP attack surfaces
  • OWASP Mobile Top 10
  • IoT/OT architecture
Lab: cloud & IoT scenarios
13. Malware Threats & Analysis
  • Trojans, viruses, ransomware
  • Propagation methods
  • Sandbox fundamentals
Lab: malware detection
14. Professional Reporting
  • Executive summary & technical findings
  • Risk analysis & remediation
  • Stakeholder communication
Final Project: full pentest report
Required Tools & Resources
OS / targets
Kali Linux · Win7/10 VM · Metasploitable2 · DVWA
Network scanning
Nmap, Zenmap, WebMap-Nmap
Vulnerability
Nessus, OpenVAS, Nikto
Web App
Burp Suite, OWASP ZAP, sqlmap, Dirb
Password
Hydra, John the Ripper, Hashcat
Wireless
Aircrack-ng, Kismet
Post‑exp
Metasploit, PowerShell Empire
Sniffing
Wireshark, tcpdump, Ettercap
Social eng.
GoPhish, BeEF, SET
Assessment & Grading
Module Quizzes20%
Hands-on Labs35%
Discussion / Participation15%
Final Penetration Test Project30%
Final project: Technical Report + Executive Summary
Recommended certifications: CEH · OSCP preparation track
2

Module One

Module 1 · Ethical Hacking Level Two

🛡️ Module 1 · Introduction to Ethical Hacking – Level Two

Building on the Basics – Ethics, Reconnaissance & Footprinting


📖 Module Introduction

Welcome back, young cyber heroes! In Level One, you learned what ethical hacking is, why we need good hackers, and the golden rule: always get permission. You also met some basic tools and concepts.

Now, in Level Two, we will go much deeper. We will learn how ethical hackers think and plan their work. We will explore reconnaissance – that is a fancy word for gathering information – and footprinting, which means collecting clues about a target.

Think of yourself as a digital detective. You are not breaking in to cause harm – you are testing the locks and windows to help the owner make them stronger. This module is all about preparation and understanding before we even touch a keyboard.

Remember: everything we learn here is for ethical and legal purposes only. We are learning to protect, not to attack.


🎯 Learning Objectives

By the end of this module, you will be able to:

  • Explain what reconnaissance and footprinting mean.
  • Understand the difference between passive and active reconnaissance.
  • Describe the ethical hacking process step by step.
  • Use basic OSINT (Open Source Intelligence) tools.
  • Understand the importance of documentation.
  • Give examples of reconnaissance from Nigeria and everyday life.
  • Explain the rules of engagement for ethical hackers.

📚 Warm‑up Story: “The Treasure Hunt”

Chidi and his friends love treasure hunts. One day, their teacher gives them a new challenge: find a hidden treasure somewhere in the school. But there is a rule – they cannot just run around breaking things. They must gather clues first.

Chidi starts by looking at the school map (passive reconnaissance). He notes that the treasure is probably in the library because the clue mentions “stories”. He then walks to the library and asks the librarian for help (active reconnaissance). He finds the treasure behind a bookshelf. The librarian is happy because Chidi asked for permission.

This story shows the two types of reconnaissance: passive (looking at maps) and active (asking questions). Ethical hackers do the same – they gather information carefully and respectfully.


📌 Main Lessons

Lesson 1: What is reconnaissance?

Definition: Reconnaissance is the first phase of ethical hacking. It means gathering information about a target before doing any testing.

Why it matters: You cannot protect a system if you do not know what it contains.

Simple explanation: It is like a detective looking for clues before solving a case.

Real‑life example: A security company checks a bank’s public website before testing its network.

School example: A teacher gathers information about students before planning a lesson.

Home example: You check the weather before planning a picnic.

Nigerian example: DataBreed uses reconnaissance before testing a client’s systems.

Illustration:

  Reconnaissance = Gathering information before action
  

Mini summary: Reconnaissance is the step where you collect information about your target.


Lesson 2: Passive vs. Active reconnaissance

Definition: Passive reconnaissance means gathering information without touching the target (e.g., searching online). Active reconnaissance means interacting with the target (e.g., scanning ports).

Why it matters: Passive is safer and less likely to be detected; active gives more detailed information.

Simple explanation: Passive is like reading about a place; active is like visiting it.

Real‑life example: Passive: checking a company’s LinkedIn page. Active: calling the company’s front desk to ask questions.

School example: Passive: looking at the school website. Active: asking a teacher for information.

Home example: Passive: checking a restaurant’s menu online. Active: calling the restaurant to order.

Nigerian example: MTN uses passive reconnaissance to monitor social media for complaints.

Illustration:

  Passive: Look, don't touch
  Active: Touch, but gently
  

Mini summary: Passive reconnaissance is non‑invasive; active involves direct interaction.


Lesson 3: Footprinting – collecting the clues

Definition: Footprinting is the process of collecting detailed information about a target network, such as IP addresses, domain names, and employee details.

Why it matters: The more clues you have, the better you can plan your test.

Simple explanation: It is like leaving a trail of breadcrumbs – but you are the one following the trail.

Real‑life example: An ethical hacker uses WHOIS to find a domain owner.

School example: A student finds the school’s IP address by looking up the school website.

Home example: You find the IP address of your router by checking your computer settings.

Nigerian example: NITDA uses footprinting to secure government websites.

Illustration:

  Footprinting:
  Domain → IP Address → Server Info → Employees
  

Mini summary: Footprinting is the detailed collection of information about a target.


Lesson 4: OSINT – Open Source Intelligence

Definition: OSINT is information that is publicly available, like social media posts, news articles, and government records.

Why it matters: Hackers can learn a lot without ever touching a system.

Simple explanation: It is like reading a newspaper to find out about a person.

Real‑life example: A hacker finds a company employee’s email on LinkedIn.

School example: A student finds the school’s event schedule on the school website.

Home example: You find a recipe online to cook dinner.

Nigerian example: EFCC uses OSINT to investigate fraud cases.

Illustration:

  OSINT Sources:
  - Social media
  - Company websites
  - News articles
  - Government records
  

Mini summary: OSINT is public information that can be used for intelligence gathering.


Lesson 5: The ethical hacking process – step by step

Definition: Ethical hacking follows a process: reconnaissance, scanning, gaining access, maintaining access, and covering tracks.

Why it matters: Following a process ensures you do not miss anything and stay organised.

Simple explanation: It is like a recipe – you follow the steps to get a good result.

Real‑life example: A security firm follows this process for every test.

School example: A student follows a process for a science project.

Home example: You follow a process to bake a cake.

Nigerian example: Cybersecurity firms in Nigeria follow this process.

Illustration:

  Ethical Hacking Process:
  1. Reconnaissance (gather info)
  2. Scanning (find open ports)
  3. Gaining Access (find vulnerabilities)
  4. Maintaining Access (stay inside)
  5. Covering Tracks (remove evidence)
  6. Reporting (tell the owner)
  

Mini summary: Ethical hacking follows a clear, step‑by‑step process.


Lesson 6: Scanning – the next step after reconnaissance

Definition: Scanning is the process of using tools to find open ports, services, and vulnerabilities on a target system.

Why it matters: It helps you find weaknesses before attackers do.

Simple explanation: It is like checking all the doors and windows to see which ones are unlocked.

Real‑life example: Using nmap to scan a network.

School example: Using a tool to scan the school network for vulnerabilities.

Home example: Using a tool to check if your wifi is secure.

Nigerian example: Nigerian banks use scanning tools to check their systems.

Illustration:

  Scanning:
  Tool → Target → Result (open ports, services)
  

Mini summary: Scanning finds vulnerabilities and open ports.


Lesson 7: Gaining access – the goal of a hacker

Definition: Gaining access means exploiting a vulnerability to enter a system.

Why it matters: This shows the weakness that needs to be fixed.

Simple explanation: It is like finding the key to a locked door.

Real‑life example: Using a weak password to log into a system.

School example: A teacher uses a default password to access the school system.

Home example: You guess your parent's password to use the computer.

Nigerian example: Kuda Bank tests its systems to prevent unauthorized access.

Illustration:

  Gaining Access:
  Vulnerability → Exploit → Access
  

Mini summary: Gaining access shows how a hacker could break in.


Lesson 8: Maintaining access – why hackers stay inside

Definition: Maintaining access means ensuring you can return to a system after you have left.

Why it matters: It helps understand how a persistent attacker might operate.

Simple explanation: It is like leaving a backdoor open so you can come back later.

Real‑life example: Installing a backdoor to access a system again.

School example: A student saves their login details to access the school portal.

Home example: You remember the wifi password to connect later.

Nigerian example: Ethical hackers test backdoors to ensure they are closed.

Illustration:

  Maintaining Access:
  Backdoor → Re‑entry → Persistent access
  

Mini summary: Maintaining access ensures you can return to the system.


Lesson 9: Covering tracks – cleaning up after yourself

Definition: Covering tracks means removing any evidence that you were in a system.

Why it matters: Ethical hackers need to show they can clean up to protect the system.

Simple explanation: It is like erasing your footprints so no one knows you were there.

Real‑life example: Clearing log files after testing.

School example: A student clears their browser history after using the school computer.

Home example: You delete your search history on the family computer.

Nigerian example: Cybersecurity teams cover tracks during penetration tests.

Illustration:

  Covering Tracks:
  Logs → Delete → No evidence
  

Mini summary: Covering tracks removes evidence of your activities.


Lesson 10: Reporting – the most important step

Definition: Reporting is the process of documenting everything you did and what you found, and then telling the owner.

Why it matters: Without a report, the owner does not know what to fix.

Simple explanation: It is like giving the teacher your homework – they need it to know what you learned.

Real‑life example: A security firm writes a detailed report for a client.

School example: A student writes a report about a science experiment.

Home example: You explain to your parents what you found when you checked the wifi.

Nigerian example: DataBreed provides detailed reports to its clients.

Illustration:

  Reporting:
  Findings → Recommendations → Client fixes
  

Mini summary: Reporting is how you share your findings with the owner.


Lesson 11: Rules of engagement for ethical hackers

Definition: Rules of engagement are the agreed‑upon boundaries for a penetration test – what you can and cannot do.

Why it matters: They ensure the test is safe and legal.

Simple explanation: It is like the rules of a game – you must follow them.

Real‑life example: An agreement states that a hacker cannot test the payment system.

School example: The school says you can test the website but not the exam system.

Home example: Your parents say you can use the computer but not download games.

Nigerian example: NITDA provides guidelines for ethical hacking.

Illustration:

  Rules of Engagement:
  - What can be tested
  - What cannot be tested
  - When to stop
  - How to report
  

Mini summary: Rules of engagement define the boundaries of a test.


Lesson 12: Nigerian examples of ethical hacking

Definition: In Nigeria, ethical hacking is used by banks, telecoms, and government agencies to protect data.

Why it matters: Nigeria is a big target for cybercriminals, so ethical hackers are very important.

Simple explanation: Ethical hackers are like digital security guards for Nigerian companies.

Real‑life example: GTBank uses ethical hackers to test its online banking.

School example: A school uses ethical hackers to test its student data system.

Home example: Your parents use security software that was tested by ethical hackers.

Nigerian example: NCC uses ethical hackers to protect Nigeria's telecom networks.

Illustration:

  Nigeria + Ethical Hacking = Safer Digital Space
  

Mini summary: Nigerian organisations use ethical hacking to protect themselves.


Lesson 13: Tools for reconnaissance

Definition: There are many tools for reconnaissance, such as WHOIS, nslookup, and theHarvester.

Why it matters: Tools make the process faster and more accurate.

Simple explanation: Tools are like magnifying glasses for detectives.

Real‑life example: Using WHOIS to find a domain owner.

School example: Using nslookup to find a school server's IP.

Home example: Using a website to check if a domain is available.

Nigerian example: Cybersecurity firms use these tools regularly.

Illustration:

  Recon Tools:
  - WHOIS (domain info)
  - nslookup (DNS info)
  - theHarvester (email info)
  

Mini summary: Reconnaissance tools help gather information efficiently.


Lesson 14: Documentation – writing everything down

Definition: Documentation means keeping detailed notes of every step you take during an ethical hack.

Why it matters: Good documentation helps you write a clear report and proves you did the work.

Simple explanation: It is like keeping a diary of your investigation.

Real‑life example: A security firm keeps logs of every action during a test.

School example: A student takes notes during a science project.

Home example: You write down the steps to bake a cake.

Nigerian example: DataBreed keeps detailed documentation for every client.

Illustration:

  Documentation:
  Date → Action → Tool → Result
  

Mini summary: Documentation helps you keep track of your work.


Lesson 15: Bringing it all together – you are a digital detective

Now you know the process of ethical hacking, especially the reconnaissance phase. You understand passive and active reconnaissance, footprinting, OSINT, and the importance of documentation. You also know the rules of engagement and how ethical hacking is used in Nigeria.

Remember: ethical hacking is about helping, not harming. You are a digital detective, gathering clues to make the world safer.

Mini summary: You are now a digital detective, ready for Level Two!


📖 Key Vocabulary

WordSimple definition
ReconnaissanceGathering information before taking action.
FootprintingCollecting detailed information about a target.
OSINTPublic information used for intelligence.
Passive ReconGathering info without touching the target.
Active ReconInteracting with the target to gather info.
ScanningFinding open ports and vulnerabilities.
ExploitA way to take advantage of a vulnerability.
BackdoorA hidden way to access a system.
Rules of EngagementAgreed boundaries for a test.
DocumentationWriting down everything you do.

🧠 Important Concepts

  • Reconnaissance is the first and most important phase of ethical hacking.
  • Passive reconnaissance is safer; active reconnaissance gives more details.
  • OSINT uses publicly available information.
  • The ethical hacking process has five phases: reconnaissance, scanning, gaining access, maintaining access, and covering tracks.
  • Reporting is the most important step – you must tell the owner what you found.
  • Rules of engagement keep the test safe and legal.

🔢 Step‑by‑step: How to do reconnaissance

  1. Identify the target (e.g., a website or a network).
  2. Gather OSINT (check social media, company website, etc.).
  3. Find IP addresses and domain info (using WHOIS).
  4. Search for employee information (using theHarvester).
  5. Document everything you find.
  1. Identify → 2. OSINT → 3. IP/Domain → 4. Employee → 5. Document
  

🌍 Real‑life examples

  • Google: Uses reconnaissance to find weaknesses in its own systems.
  • Microsoft: Has a bug bounty program that uses ethical hacking.
  • Facebook: Uses ethical hackers to find vulnerabilities.

🇳🇬 Nigerian examples

  • GTBank: Uses ethical hacking to test online banking.
  • MTN Nigeria: Uses ethical hackers to protect its network.
  • NITDA: Provides guidelines for ethical hacking in Nigeria.
  • DataBreed: A Nigerian firm that provides ethical hacking services.

🎈 Fun examples for children

  • Roblox: Uses ethical hacking to protect player accounts.
  • Fortnite: Uses ethical hackers to prevent cheating.
  • YouTube: Uses ethical hackers to keep videos safe.

🏠 Everyday examples

  • School: A student uses reconnaissance to find a lost item by checking the lost and found.
  • Home: You use reconnaissance to find out what time a store opens.
  • Community: A community group uses reconnaissance to find out who owns a vacant lot.

👪 Parent tips

Parents can help children understand ethical hacking by discussing the importance of privacy and security online. Talk about how ethical hackers protect personal information and why we need strong passwords.


💡 Interesting facts

  • The term “reconnaissance” comes from the French word meaning “reconnaissance” – to recognise.
  • OSINT has been used by governments for hundreds of years.
  • Ethical hacking is a growing field, with many jobs available.

❓ Did you know?

  • Some ethical hackers are called “white‑hat” hackers.
  • The first ethical hackers were hired by IBM in the 1970s.
  • Nigeria has a growing community of ethical hackers.

🧷 Remember this

  • Reconnaissance is the first step.
  • Always get permission.
  • Passive recon is safer; active recon gives more detail.
  • Document everything.
  • Report your findings.

⚠️ Common mistakes

  • Mistake: Skipping reconnaissance. Correction: Always do recon first.
  • Mistake: Not documenting. Correction: Write everything down.
  • Mistake: Using active recon without permission. Correction: Always have permission.

✅ Best practices

  • Always start with passive reconnaissance.
  • Get written permission before any active testing.
  • Document every step.
  • Follow the rules of engagement.
  • Write a clear, detailed report.

📊 Ethical Hacking Process

  +------------------+
  | 1. Reconnaissance |  (gather info)
  +------------------+
          |
          V
  +------------------+
  | 2. Scanning       |  (find ports)
  +------------------+
          |
          V
  +------------------+
  | 3. Gaining Access |  (exploit)
  +------------------+
          |
          V
  +------------------+
  | 4. Maintaining    |  (backdoor)
  +------------------+
          |
          V
  +------------------+
  | 5. Covering Tracks |  (clean)
  +------------------+
          |
          V
  +------------------+
  | 6. Reporting      |  (tell owner)
  +------------------+
  

Passive vs Active Recon

Passive ReconActive Recon
No direct contact with targetDirect contact with target
Less likely to be detectedMore likely to be detected
Uses public information (OSINT)Uses tools like nmap
Example: Google searchExample: port scan

📝 End‑of‑module summary

In Module 1 of Level Two, we have covered the foundation of ethical hacking. We explored:

  • Reconnaissance and its importance.
  • The difference between passive and active reconnaissance.
  • Footprinting and OSINT.
  • The ethical hacking process: reconnaissance, scanning, gaining access, maintaining access, covering tracks, and reporting.
  • Rules of engagement and the importance of documentation.
  • Nigerian examples of ethical hacking.

You are now ready to move on to the next module, where we will learn about scanning and enumeration – finding open ports and services.


❓ Frequently Asked Questions (10)

  1. What is reconnaissance? Gathering information before taking action.
  2. What is the difference between passive and active recon? Passive is non‑invasive; active involves direct contact.
  3. What is OSINT? Public information used for intelligence.
  4. What are the phases of ethical hacking? Recon, scanning, gaining access, maintaining access, covering tracks, reporting.
  5. Why is reporting important? It tells the owner what to fix.
  6. What are rules of engagement? Agreed boundaries for a test.
  7. What is footprinting? Detailed information gathering about a target.
  8. Can I use these techniques on any system? Only with permission.
  9. Is ethical hacking legal in Nigeria? Yes, when done with proper permission.
  10. What tools are used for reconnaissance? WHOIS, nslookup, theHarvester.

🔗 Matching exercise

Match the term to its description.

TermDescription
1. ReconnaissanceA. The first phase of ethical hacking
2. OSINTB. Publicly available information
3. FootprintingC. Collecting detailed information about a target

Answers: 1-A, 2-B, 3-C


🎭 Scenario‑based exercises

Scenario 1: You are asked to test the security of a school website. What type of reconnaissance would you start with? Why?

Hint: Start with passive recon – check the website, social media, and public records.

Scenario 2: A Nigerian bank wants you to test its online banking system. What rules of engagement would you set?

Hint: Agree on what can be tested, what cannot be tested, and when to stop.


👥 Group activity

In groups, choose a target (like a school or a local business) and create a reconnaissance plan. Decide what passive and active reconnaissance you would do. Present your plan to the class.


🧑‍🏫 Individual activity

Use a search engine to find OSINT about a well‑known company (like a bank or telecom). Write down at least five pieces of information you found (e.g., office address, employee names, social media profiles).


🛠️ Mini project

Create a poster that shows the ethical hacking process with a simple illustration for each phase. Display it in the classroom.


📋 Practical assignment

Write a detailed reconnaissance plan for a hypothetical target (a school or a small business). Include passive and active reconnaissance steps, tools you would use, and how you would document your findings.


🔑 Key takeaways

  • Reconnaissance is the first and most important phase.
  • Passive recon is safer; active recon gives more detail.
  • OSINT is a powerful source of information.
  • The ethical hacking process has clear phases.
  • Documentation and reporting are essential.
  • Always get permission and follow the rules.

🗣️ Classroom discussion questions

  1. Why is reconnaissance the most important phase of ethical hacking?
  2. What are the risks of active reconnaissance without permission?
  3. How can OSINT be used for good and for bad?
  4. Why is documentation so important in ethical hacking?
  5. How can ethical hacking help Nigerian businesses?

🚀 Preparation for Module 2

In Module 2, we will explore Scanning and Enumeration. You will learn how to use tools like nmap to find open ports and services. We will also cover vulnerability assessment – finding weaknesses that attackers could use.

To prepare, download and install a tool like nmap on your computer (with permission) and practise scanning your own network.


End of Module 1 · Introduction to Ethical Hacking – Level Two

3

Module Two

Module 2 · Ethical Hacking Level Two

🛡️ Module 2 · Introduction to Ethical Hacking – Level Two

Scanning & Enumeration – Finding Open Doors


📖 Module Introduction

Welcome back, digital detectives! In Module 1, we learned about reconnaissance – gathering information. Now, we move to the next step: scanning and enumeration. These are the tools and techniques that ethical hackers use to find open doors (open ports) and weak locks (vulnerabilities) on a target system.

Imagine you are a security guard checking a building. You walk around and test every door and window to see which ones are unlocked. That is exactly what scanning does – it checks every "door" (port) on a computer or network to see if it is open.

In this module, we will learn about nmap, the most famous scanning tool, and other techniques like ping sweeps, port scanning, and OS fingerprinting. We will also explore enumeration, which means gathering detailed information like usernames and shared folders.

Remember: always get permission before scanning any system that is not your own. These skills are for ethical and legal use only.


🎯 Learning Objectives

  • Explain what scanning and enumeration are.
  • Understand the difference between ping sweeps, port scans, and OS fingerprinting.
  • Use nmap to perform basic scans.
  • Explain what open ports and services are.
  • Describe enumeration techniques like DNS enumeration and SNMP enumeration.
  • Give examples of scanning in Nigeria.
  • Understand the risks of scanning without permission.

📚 Warm‑up Story: “The School Lab Check”

Chidi is a student helper in the school computer lab. One day, the IT teacher, Mrs. Ade, asks him to check if all the computers are secure. She gives him permission to scan the lab network.

Chidi uses a tool called nmap. He does a ping sweep to see which computers are on. Then he does a port scan to see which services (like file sharing) are running. He finds that one computer has port 445 open – that is a file‑sharing port. He checks and finds that the computer is sharing its files with everyone on the network. That is a security risk!

Mrs. Ade thanks Chidi and fixes the problem. This story shows how scanning helps find security holes.


📌 Main Lessons

Lesson 1: What is scanning?

Definition: Scanning is the process of using tools to find out which devices are on a network, which ports are open, and what services are running.

Why it matters: Scanning helps you identify potential entry points for attackers.

Simple explanation: It is like walking down a street and checking which doors are unlocked.

Real‑life example: A security team scans a company network to find open ports.

School example: A teacher scans the school network to find unsecured computers.

Home example: You scan your home wifi to see which devices are connected.

Nigerian example: Nigerian banks scan their networks to find vulnerabilities.

Illustration:

  Scanning = Finding open doors on a network
  

Mini summary: Scanning finds open ports and devices on a network.


Lesson 2: Ping sweep – finding live devices

Definition: A ping sweep is a technique that sends ping messages to a range of IP addresses to see which devices are online.

Why it matters: It gives you a list of all active devices on a network.

Simple explanation: It is like knocking on every door in a street to see who is home.

Real‑life example: A security team uses a ping sweep to find all computers on a network.

School example: A teacher uses a ping sweep to see which computers are turned on.

Home example: You use a ping sweep to find all devices on your wifi.

Nigerian example: MTN uses ping sweeps to monitor network devices.

Illustration:

  Ping Sweep:
  IP 192.168.1.1 → Reply (online)
  IP 192.168.1.2 → No reply (offline)
  IP 192.168.1.3 → Reply (online)
  

Mini summary: A ping sweep finds which devices are alive on a network.


Lesson 3: Port scanning – finding open doors

Definition: Port scanning is the process of sending packets to a specific IP address to see which ports are open and listening.

Why it matters: Open ports can be entry points for attackers.

Simple explanation: It is like checking every door on a building to see which ones are unlocked.

Real‑life example: Using nmap to scan a server for open ports.

School example: Scanning the school server to find open ports.

Home example: Checking your home router for open ports.

Nigerian example: Cybersecurity firms use port scanning to test systems.

Illustration:

  Port Scan:
  Port 80 → Open (HTTP)
  Port 443 → Open (HTTPS)
  Port 22 → Closed
  Port 21 → Open (FTP)
  

Mini summary: Port scanning finds open ports on a device.


Lesson 4: OS fingerprinting – guessing the operating system

Definition: OS fingerprinting is the process of identifying the operating system (like Windows, Linux, or macOS) of a remote device by analysing its responses.

Why it matters: Different operating systems have different vulnerabilities.

Simple explanation: It is like guessing what brand of car a person drives by looking at the shape of the headlights.

Real‑life example: Nmap can detect that a server is running Linux.

School example: You can find out if the school server runs Windows or Linux.

Home example: You can check if a device on your network is a laptop or a smart TV.

Nigerian example: NITDA uses OS fingerprinting to monitor government systems.

Illustration:

  OS Fingerprinting:
  Server response → TTL=64 → Likely Linux
  Server response → TTL=128 → Likely Windows
  

Mini summary: OS fingerprinting identifies the operating system of a device.


Lesson 5: Nmap – the king of scanning tools

Definition: Nmap (Network Mapper) is a powerful, free tool used for network discovery and security auditing. It can do ping sweeps, port scans, OS fingerprinting, and more.

Why it matters: Nmap is one of the most important tools for ethical hackers.

Simple explanation: It is like a Swiss Army knife for network scanning.

Real‑life example: A security expert uses nmap to scan a company network.

School example: A student uses nmap to scan the school lab network (with permission).

Home example: You use nmap to check your home network.

Nigerian example: DataBreed uses nmap for penetration testing.

Illustration:

  nmap commands:
  nmap -sn 192.168.1.0/24   (ping sweep)
  nmap -sT 192.168.1.1      (TCP scan)
  nmap -O 192.168.1.1       (OS detection)
  

Mini summary: Nmap is a versatile tool for network scanning.


Lesson 6: Common ports and services

Definition: Ports are like doors. Each door is used by a specific service – for example, port 80 is for web traffic (HTTP).

Why it matters: Knowing common ports helps you understand what services are running.

Simple explanation: It is like knowing that the front door is for visitors and the back door is for delivery.

Real‑life example: Port 443 is used for secure websites (HTTPS).

School example: The school website uses port 443.

Home example: Your online game uses a specific port to connect.

Nigerian example: GTBank uses port 443 for online banking.

Illustration:

  Common Ports:
  21: FTP (file transfer)
  22: SSH (secure shell)
  25: SMTP (email)
  80: HTTP (web)
  443: HTTPS (secure web)
  

Mini summary: Common ports are associated with specific services.


Lesson 7: Enumeration – gathering more details

Definition: Enumeration is the process of extracting detailed information from a target system, such as usernames, shared folders, and services.

Why it matters: It helps you understand what resources are available and how they might be exploited.

Simple explanation: It is like not just finding a door, but also looking inside to see what is in the room.

Real‑life example: Enumerating a Windows system to find shared folders.

School example: Finding out which files are shared on the school network.

Home example: Finding shared folders on your home network.

Nigerian example: Cybersecurity teams use enumeration to find sensitive data.

Illustration:

  Enumeration:
  Target → User list → Shared folders → Services
  

Mini summary: Enumeration gathers detailed information about a system.


Lesson 8: DNS enumeration – finding domain information

Definition: DNS enumeration is the process of gathering information about a domain, such as its IP addresses, subdomains, and mail servers.

Why it matters: It helps you understand the structure of a target's network.

Simple explanation: It is like looking up a phone number to find the address and other details.

Real‑life example: Using tools like nslookup to find a domain's IP.

School example: Finding the school's mail server address.

Home example: Finding the IP address of a website you want to visit.

Nigerian example: NCC uses DNS enumeration to monitor domains.

Illustration:

  DNS Enumeration:
  domain.com → IP 192.168.1.1
  sub.domain.com → IP 192.168.1.2
  mail.domain.com → IP 192.168.1.3
  

Mini summary: DNS enumeration gathers information about domains.


Lesson 9: SNMP enumeration – network device info

Definition: SNMP (Simple Network Management Protocol) is used to monitor network devices. SNMP enumeration gathers information from devices that have SNMP enabled.

Why it matters: SNMP can reveal a lot of information, including system details and even passwords.

Simple explanation: It is like asking a network device to tell you everything about itself.

Real‑life example: Gathering SNMP information from a router.

School example: Checking the school router for SNMP information.

Home example: Checking your home router for SNMP.

Nigerian example: MTN uses SNMP to monitor its network devices.

Illustration:

  SNMP Enumeration:
  snmpwalk -v2c -c public 192.168.1.1
  → System info, interfaces, etc.
  

Mini summary: SNMP enumeration gathers information from network devices.


Lesson 10: SMB enumeration – Windows file sharing

Definition: SMB (Server Message Block) is a protocol used for file sharing in Windows networks. SMB enumeration finds shared folders and users.

Why it matters: Misconfigured SMB shares can expose sensitive data.

Simple explanation: It is like checking what files are shared on a Windows computer.

Real‑life example: Using tools like enum4linux to find SMB shares.

School example: Finding shared folders on the school network.

Home example: Checking your family's shared folders.

Nigerian example: Cybersecurity firms check SMB shares during tests.

Illustration:

  SMB Enumeration:
  Share: \\Server\Public
  Share: \\Server\Students
  

Mini summary: SMB enumeration finds shared folders on Windows networks.


Lesson 11: Enumeration tools – beyond nmap

Definition: Besides nmap, there are other tools for enumeration, like enum4linux, dnsrecon, and snmpwalk.

Why it matters: Different tools are better for different tasks.

Simple explanation: It is like having different screwdrivers for different screws.

Real‑life example: Using enum4linux to enumerate SMB shares.

School example: Using dnsrecon to find subdomains of the school website.

Home example: Using snmpwalk to check your router.

Nigerian example: DataBreed uses these tools in penetration tests.

Illustration:

  Enumeration Tools:
  - enum4linux (SMB)
  - dnsrecon (DNS)
  - snmpwalk (SNMP)
  

Mini summary: There are many tools for enumeration, each with a specific purpose.


Lesson 12: The risks of scanning without permission

Definition: Scanning without permission is illegal and unethical. It can cause network issues and is considered an attack.

Why it matters: You must always have written permission before scanning any system.

Simple explanation: It is like walking into someone's house without asking – it is wrong.

Real‑life example: A hacker scanned a company network without permission and was arrested.

School example: A student scanned the school network without permission and got suspended.

Home example: You scan your friend's computer without asking – that is not okay.

Nigerian example: EFCC investigates unauthorised scanning in Nigeria.

Illustration:

  Without Permission = Illegal ❌
  With Permission = Ethical ✅
  

Mini summary: Scanning without permission is illegal and unethical.


Lesson 13: Scanning in Nigeria – real examples

Definition: In Nigeria, ethical hackers scan systems for banks, telecom companies, and government agencies to find vulnerabilities.

Why it matters: This helps protect sensitive data and infrastructure.

Simple explanation: Nigerian ethical hackers are digital protectors.

Real‑life example: GTBank uses ethical hackers to scan its systems.

School example: A school uses ethical hackers to scan its student data system.

Home example: Your parents use security software that was tested by ethical hackers.

Nigerian example: NITDA promotes ethical hacking in Nigeria.

Illustration:

  Nigeria + Ethical Scanning = Safer Digital Space
  

Mini summary: Nigerian organisations use ethical scanning to protect themselves.


Lesson 14: How to stay safe from scanners

Definition: To protect yourself from malicious scanners, you can use a firewall, close unused ports, and use strong passwords.

Why it matters: This makes it harder for attackers to find weaknesses.

Simple explanation: It is like locking all the doors and windows in your house.

Real‑life example: A company uses a firewall to block port scans.

School example: The school uses a firewall to block unwanted scans.

Home example: You use a firewall on your home router.

Nigerian example: Nigerian banks use firewalls to protect their networks.

Illustration:

  Protection:
  1. Firewall
  2. Close unused ports
  3. Strong passwords
  

Mini summary: Firewalls and strong passwords protect you from scanners.


Lesson 15: Bringing it all together – scanning and enumeration

Now you understand scanning and enumeration. You know how to find open ports, identify operating systems, and gather detailed information. You also know the risks of scanning without permission and how to protect against scanners.

Remember: these skills are for ethical use only. Use them to protect, not to attack.

Mini summary: Scanning and enumeration are powerful tools for ethical hackers.


📖 Key Vocabulary

WordSimple definition
ScanningFinding open ports and devices.
EnumerationGathering detailed information about a system.
Ping SweepFinding which devices are online.
Port ScanFinding open ports on a device.
OS FingerprintingIdentifying the operating system of a device.
NmapA powerful scanning tool.
DNS EnumerationGathering domain information.
SNMP EnumerationGathering device information.
SMB EnumerationFinding shared folders on Windows.
FirewallA security system that blocks unwanted traffic.

🧠 Important Concepts

  • Scanning finds open ports and devices.
  • Enumeration gathers detailed information.
  • Ping sweeps find live devices.
  • Port scans find open doors.
  • OS fingerprinting identifies the operating system.
  • Nmap is the most important scanning tool.
  • Always get permission before scanning.
  • Firewalls protect against scanners.

🔢 Step‑by‑step: How to use nmap

  1. Install nmap on your computer.
  2. Open your terminal or command prompt.
  3. Type nmap -sn 192.168.1.0/24 to find live devices.
  4. Type nmap -sT 192.168.1.1 to scan for open ports.
  5. Type nmap -O 192.168.1.1 to identify the OS.
  1. Install → 2. Open terminal → 3. Ping sweep → 4. Port scan → 5. OS detection
  

🌍 Real‑life examples

  • Amazon: Scans its own network to find vulnerabilities.
  • Google: Uses scanning to protect its services.
  • Facebook: Uses ethical hackers to scan for bugs.

🇳🇬 Nigerian examples

  • GTBank: Uses scanning to test online banking security.
  • MTN Nigeria: Scans its network for vulnerabilities.
  • DataBreed: A Nigerian firm that does scanning for clients.
  • NITDA: Provides guidelines for scanning in Nigeria.

🎈 Fun examples for children

  • Roblox: Scans its servers to protect players.
  • Fortnite: Scans for cheaters.
  • YouTube: Scans for malicious content.

🏠 Everyday examples

  • School: A teacher scans the school network for open ports.
  • Home: You scan your home wifi to see if any unknown devices are connected.
  • Community: A community group scans its public wifi for security.

👪 Parent tips

Parents can help children understand scanning by discussing the importance of network security. Show them how to scan their own home network (with permission) and explain why it is important to keep ports closed.


💡 Interesting facts

  • Nmap was created in 1997 by Gordon Lyon.
  • The name "nmap" stands for "Network Mapper".
  • Nmap is used by millions of people worldwide.

❓ Did you know?

  • Some scanners can detect the version of a service running on a port.
  • Enumeration can sometimes reveal default passwords.
  • Nigeria has a growing community of ethical hackers.

🧷 Remember this

  • Scanning finds open ports and devices.
  • Enumeration gathers detailed information.
  • Always get permission before scanning.
  • Nmap is a powerful tool.
  • Firewalls protect against scanners.

⚠️ Common mistakes

  • Mistake: Scanning without permission. Correction: Always have written permission.
  • Mistake: Not closing unused ports. Correction: Close ports you don't need.
  • Mistake: Forgetting to document results. Correction: Write everything down.

✅ Best practices

  • Always get written permission before scanning.
  • Document every scan and result.
  • Close unused ports on your own systems.
  • Use a firewall to protect against unwanted scans.
  • Keep your scanning tools updated.

📊 Scanning Process

  +------------------+
  | 1. Ping Sweep    |  (find live devices)
  +------------------+
          |
          V
  +------------------+
  | 2. Port Scan     |  (find open ports)
  +------------------+
          |
          V
  +------------------+
  | 3. OS Fingerprint |  (identify OS)
  +------------------+
          |
          V
  +------------------+
  | 4. Enumeration   |  (gather details)
  +------------------+
  

Common Ports and Services

PortServiceUse
21FTPFile Transfer
22SSHSecure Shell
25SMTPEmail Sending
80HTTPWeb Traffic
443HTTPSSecure Web

📝 End‑of‑module summary

In Module 2, we explored scanning and enumeration. We learned:

  • Scanning finds open ports and devices.
  • Ping sweeps find live devices.
  • Port scans find open doors.
  • OS fingerprinting identifies the operating system.
  • Nmap is a powerful scanning tool.
  • Enumeration gathers detailed information like usernames and shares.
  • Always get permission before scanning.
  • Firewalls protect against scanners.

You are now ready to move on to the next module, where we will learn about vulnerability assessment – finding weaknesses that can be exploited.


❓ Frequently Asked Questions (10)

  1. What is scanning? Finding open ports and devices.
  2. What is enumeration? Gathering detailed information.
  3. What is a ping sweep? Finding live devices.
  4. What is a port scan? Finding open ports.
  5. What is OS fingerprinting? Identifying the operating system.
  6. What is nmap? A powerful scanning tool.
  7. Is scanning legal? Only with permission.
  8. What is a firewall? A system that blocks unwanted traffic.
  9. What is DNS enumeration? Gathering domain information.
  10. What is SMB enumeration? Finding shared folders on Windows.

🔗 Matching exercise

Match the term to its description.

TermDescription
1. Ping SweepA. Finds open ports
2. Port ScanB. Finds live devices
3. OS FingerprintingC. Identifies the operating system

Answers: 1-B, 2-A, 3-C


🎭 Scenario‑based exercises

Scenario 1: You are an ethical hacker for a Nigerian bank. You need to find all open ports on the bank's network. What tool would you use and why?

Hint: Nmap is the best tool for port scanning.

Scenario 2: A school network has been slow. You suspect a device is sending too much traffic. What scanning technique would you use to find the device?

Hint: A ping sweep can find all active devices.


👥 Group activity

In groups, use nmap (with permission) to scan your school or home network. Document the open ports and services you find. Present your findings to the class.


🧑‍🏫 Individual activity

Write down the common ports for HTTP, HTTPS, FTP, and SSH. Explain what each service does.


🛠️ Mini project

Create a poster that shows the scanning process with a clear illustration of ping sweep, port scan, and OS fingerprinting. Display it in the classroom.


📋 Practical assignment

Write a report on a hypothetical scan of a school network. Include the ping sweep results, open ports found, and recommended fixes.


🔑 Key takeaways

  • Scanning finds open ports and devices.
  • Enumeration gathers detailed information.
  • Nmap is a powerful scanning tool.
  • Always get permission before scanning.
  • Firewalls protect against scanners.
  • Document everything you find.

🗣️ Classroom discussion questions

  1. Why is scanning an important part of ethical hacking?
  2. What are the risks of scanning without permission?
  3. How can a firewall protect against scanning?
  4. What is the difference between scanning and enumeration?
  5. How can Nigerian businesses benefit from ethical scanning?

🚀 Preparation for Module 3

In Module 3, we will explore Vulnerability Assessment – using tools like Nessus and OpenVAS to find weaknesses in systems. We will also learn about the Common Vulnerability Scoring System (CVSS).

To prepare, read about vulnerability assessment and think about what makes a system vulnerable.


End of Module 2 · Introduction to Ethical Hacking – Level Two

4

Module Three

Module 3 · Ethical Hacking Level Two

🛡️ Module 3 · Introduction to Ethical Hacking – Level Two

Vulnerability Assessment – Finding Weaknesses Before Attackers Do


📖 Module Introduction

Welcome back, ethical hackers! In Module 1, we learned about reconnaissance – gathering information. In Module 2, we explored scanning and enumeration – finding open ports and services. Now, in Module 3, we will move to the next step: Vulnerability Assessment.

A vulnerability is a weakness in a system that could be used by an attacker. Vulnerability assessment is the process of finding these weaknesses. Think of it like a doctor checking you for health problems – you want to find and fix issues before they become serious.

In this module, we will learn about common vulnerabilities, how to use vulnerability scanners like Nessus and OpenVAS, and how to interpret the results. We will also explore the Common Vulnerability Scoring System (CVSS), which helps prioritise which vulnerabilities to fix first.

Remember: these skills are for ethical use only. Always have permission before scanning.


🎯 Learning Objectives

  • Explain what a vulnerability is.
  • Describe the vulnerability assessment process.
  • Understand the difference between vulnerability assessment and penetration testing.
  • Use a vulnerability scanner like OpenVAS or Nessus.
  • Explain the Common Vulnerability Scoring System (CVSS).
  • Give examples of common vulnerabilities.
  • Understand how vulnerability assessment is used in Nigeria.
  • Explain the risks of ignoring vulnerabilities.

📚 Warm‑up Story: “The Weak Link”

Chidi is an ethical hacker working for a Nigerian bank. The bank has a website that customers use to check their accounts. One day, Chidi runs a vulnerability scan on the website. The scan finds a weakness – the website is using an old version of a software program that has a known security hole. Attackers could use this hole to steal customer data.

Chidi immediately reports the issue. The bank updates the software and fixes the vulnerability. Later, news breaks that another bank was attacked using the same software flaw – but Chidi’s bank was safe because they had fixed it. This shows how vulnerability assessment protects people.


📌 Main Lessons

Lesson 1: What is a vulnerability?

Definition: A vulnerability is a weakness in a system that could be exploited by an attacker to cause harm.

Why it matters: Vulnerabilities are how attackers get in.

Simple explanation: It is like a crack in a wall – it lets water (or attackers) in.

Real‑life example: A website using an old version of a software library that has a known bug.

School example: A teacher uses a weak password that students can guess.

Home example: Your home wifi uses the default password that came with the router.

Nigerian example: A Nigerian government website using outdated software.

Illustration:

  Vulnerability = Weakness in a system
  

Mini summary: A vulnerability is a weakness that can be used by attackers.


Lesson 2: What is vulnerability assessment?

Definition: Vulnerability assessment is the process of identifying, classifying, and prioritising vulnerabilities in a system.

Why it matters: It helps you know what needs fixing.

Simple explanation: It is like a health check‑up for your computer or network.

Real‑life example: A company runs a vulnerability scan on its network every month.

School example: The school scans its computers to find weaknesses.

Home example: You scan your home network to see if any devices have weak passwords.

Nigerian example: NITDA encourages vulnerability assessments for government systems.

Illustration:

  Vulnerability Assessment:
  1. Identify vulnerabilities
  2. Classify them
  3. Prioritise them
  4. Fix them
  

Mini summary: Vulnerability assessment finds and prioritises weaknesses.


Lesson 3: Vulnerability scanner – Nessus

Definition: Nessus is a popular vulnerability scanner that checks systems for known vulnerabilities.

Why it matters: It automates the process of finding weaknesses.

Simple explanation: It is like a robot that checks every door and window for locks that are broken.

Real‑life example: A security team uses Nessus to scan a company network.

School example: A school uses Nessus to scan its computers.

Home example: You can use Nessus to scan your home network (with permission).

Nigerian example: DataBreed uses Nessus for vulnerability assessments.

Illustration:

  Nessus:
  Target → Scan → Report → Vulnerabilities found
  

Mini summary: Nessus is a tool that finds vulnerabilities automatically.


Lesson 4: Vulnerability scanner – OpenVAS

Definition: OpenVAS is a free, open‑source vulnerability scanner. It is similar to Nessus.

Why it matters: It is free and works well for small organisations.

Simple explanation: It is like a free version of a security guard.

Real‑life example: A small business uses OpenVAS to scan its network.

School example: A school uses OpenVAS because they have a limited budget.

Home example: You can use OpenVAS to scan your home network.

Nigerian example: Nigerian schools can use OpenVAS to protect their networks.

Illustration:

  OpenVAS:
  Target → Scan → Report → Fixes
  

Mini summary: OpenVAS is a free vulnerability scanner.


Lesson 5: Common vulnerabilities – OWASP Top 10

Definition: The OWASP Top 10 is a list of the most common web application vulnerabilities.

Why it matters: It helps developers know what to protect against.

Simple explanation: It is like a list of the most common ways burglars break into houses.

Real‑life example: A developer checks the OWASP Top 10 when building a website.

School example: A school's IT team learns about SQL injection from OWASP.

Home example: You learn about phishing from OWASP.

Nigerian example: NITDA promotes OWASP awareness in Nigeria.

Illustration:

  OWASP Top 10 (common):
  1. Injection
  2. Broken Authentication
  3. Sensitive Data Exposure
  4. XML External Entities (XXE)
  5. Broken Access Control
  

Mini summary: The OWASP Top 10 lists common web vulnerabilities.


Lesson 6: CVSS – scoring vulnerabilities

Definition: The Common Vulnerability Scoring System (CVSS) gives a score (0‑10) to each vulnerability, showing how severe it is.

Why it matters: It helps you decide which vulnerabilities to fix first.

Simple explanation: It is like a traffic light – red means fix now, green means you can wait.

Real‑life example: A vulnerability with a CVSS score of 9.8 is critical and must be fixed immediately.

School example: A vulnerability with a score of 5 is medium and can be fixed later.

Home example: A vulnerability with a score of 2 is low and can be ignored for now.

Nigerian example: Nigerian banks use CVSS to prioritise security fixes.

Illustration:

  CVSS Scores:
  0-3: Low (green)
  4-6: Medium (yellow)
  7-8: High (orange)
  9-10: Critical (red)
  

Mini summary: CVSS helps prioritise vulnerabilities by severity.


Lesson 7: Vulnerability assessment vs Penetration testing

Definition: Vulnerability assessment finds weaknesses; penetration testing exploits them to see if they can be used to break in.

Why it matters: Assessment tells you what is wrong; testing shows you if it can be used.

Simple explanation: Assessment is like a doctor's check‑up; testing is like a stress test.

Real‑life example: First you scan (assessment), then you try to break in (penetration test).

School example: The school scans for weaknesses (assessment) and then tries to hack into a test system (penetration test).

Home example: You check your wifi password strength (assessment) and then try to guess it (penetration test).

Nigerian example: Cybersecurity firms do both assessment and testing.

Illustration:

  Vulnerability Assessment: Find weaknesses
  Penetration Testing: Exploit weaknesses
  

Mini summary: Assessment finds weaknesses; testing tries to break in.


Lesson 8: Risk – what happens if you ignore vulnerabilities

Definition: Risk is the chance that a vulnerability will be exploited and cause damage.

Why it matters: Ignoring vulnerabilities can lead to data breaches, financial loss, and reputational damage.

Simple explanation: It is like leaving your front door open – the risk of a break‑in is high.

Real‑life example: A company that ignores a critical vulnerability might be hacked.

School example: A school that ignores weak passwords might have student data stolen.

Home example: You ignore a vulnerability in your router and your wifi is hacked.

Nigerian example: Nigerian companies face fines and reputation damage if they ignore vulnerabilities.

Illustration:

  Risk = Vulnerability × Threat × Impact
  

Mini summary: Ignoring vulnerabilities creates risk.


Lesson 9: Vulnerability management – a continuous process

Definition: Vulnerability management is the ongoing process of identifying, assessing, and fixing vulnerabilities.

Why it matters: New vulnerabilities are discovered every day.

Simple explanation: It is like cleaning your room – you need to do it regularly, not just once.

Real‑life example: A company runs vulnerability scans every month.

School example: The school scans its network every term.

Home example: You check for updates on your devices every week.

Nigerian example: NITDA recommends regular vulnerability assessments.

Illustration:

  Vulnerability Management Cycle:
  Scan → Assess → Fix → Verify → Repeat
  

Mini summary: Vulnerability management is a continuous process.


Lesson 10: Patching – fixing vulnerabilities

Definition: Patching is the process of applying updates to software to fix vulnerabilities.

Why it matters: Patching is the most common way to fix vulnerabilities.

Simple explanation: It is like patching a hole in a boat – you stop the water from coming in.

Real‑life example: Installing a security update for Windows.

School example: Updating the school's software to fix a bug.

Home example: Updating your phone to get security fixes.

Nigerian example: Nigerian banks patch their systems regularly.

Illustration:

  Patching = Fixing vulnerabilities with updates
  

Mini summary: Patching fixes vulnerabilities by updating software.


Lesson 11: Zero‑day vulnerabilities – the unknown

Definition: A zero‑day vulnerability is a weakness that is unknown to the software vendor and has no patch yet.

Why it matters: Attackers can use zero‑days to break into systems.

Simple explanation: It is like a secret door that no one knows about.

Real‑life example: A hacker discovers a new bug in a popular app and uses it to steal data.

School example: A student finds a way to access the school system that the IT team did not know about.

Home example: A new virus is discovered that can infect your computer.

Nigerian example: Nigerian cybersecurity teams monitor for zero‑day attacks.

Illustration:

  Zero‑day = Unknown vulnerability with no patch
  

Mini summary: Zero‑day vulnerabilities are unknown and have no fix yet.


Lesson 12: Vulnerability assessment in Nigeria

Definition: In Nigeria, vulnerability assessment is used by banks, government agencies, and businesses to protect their systems.

Why it matters: Nigeria is a growing digital economy, and security is important.

Simple explanation: Nigerian organisations use vulnerability assessment to stay safe.

Real‑life example: GTBank uses vulnerability scanners to check its online banking.

School example: A school uses a vulnerability scanner to check its student data system.

Home example: Your parents use a security tool that was tested with vulnerability assessment.

Nigerian example: NITDA encourages vulnerability assessment for all government systems.

Illustration:

  Nigeria + Vulnerability Assessment = Safer Digital Space
  

Mini summary: Nigerian organisations use vulnerability assessment to protect themselves.


Lesson 13: How to protect yourself from vulnerabilities

Definition: You can protect yourself by keeping software updated, using strong passwords, and using a firewall.

Why it matters: Simple steps can prevent most attacks.

Simple explanation: It is like locking your doors and windows.

Real‑life example: A company uses automatic updates to keep software patched.

School example: A school uses a firewall to block unwanted traffic.

Home example: You use strong passwords for your online accounts.

Nigerian example: NITDA provides security tips for citizens.

Illustration:

  Protection:
  1. Update software
  2. Use strong passwords
  3. Use a firewall
  4. Use antivirus
  

Mini summary: Simple steps can protect you from vulnerabilities.


Lesson 14: Reporting vulnerabilities responsibly

Definition: If you find a vulnerability in a system that you do not own, you must report it to the owner responsibly.

Why it matters: This allows the owner to fix it before attackers find it.

Simple explanation: It is like telling someone their door is unlocked.

Real‑life example: An ethical hacker finds a vulnerability and reports it to the company's security team.

School example: A student finds a weakness in the school system and tells the IT teacher.

Home example: You find a vulnerability in a game and tell the game developer.

Nigerian example: DataBreed reports vulnerabilities to its clients.

Illustration:

  Responsible Disclosure:
  1. Find vulnerability
  2. Report to owner
  3. Give time to fix
  4. Publicly disclose (if needed)
  

Mini summary: Report vulnerabilities responsibly to help keep everyone safe.


Lesson 15: Bringing it all together – vulnerability assessment

Now you understand what vulnerabilities are, how to find them, and how to fix them. You know about tools like Nessus and OpenVAS, and you understand the difference between assessment and penetration testing. You also know how to protect yourself and how to report vulnerabilities responsibly.

Remember: vulnerability assessment is a key part of ethical hacking. It helps keep systems safe.

Mini summary: Vulnerability assessment helps keep systems safe.


📖 Key Vocabulary

WordSimple definition
VulnerabilityA weakness in a system.
Vulnerability AssessmentFinding and prioritising weaknesses.
NessusA popular vulnerability scanner.
OpenVASA free vulnerability scanner.
CVSSA scoring system for vulnerabilities.
OWASPA list of common web vulnerabilities.
Penetration TestingExploiting vulnerabilities to test security.
PatchingFixing vulnerabilities with updates.
Zero‑dayAn unknown vulnerability with no patch.
RiskThe chance a vulnerability will be exploited.

🧠 Important Concepts

  • A vulnerability is a weakness in a system.
  • Vulnerability assessment finds and prioritises weaknesses.
  • Nessus and OpenVAS are vulnerability scanners.
  • CVSS scores vulnerabilities from 0‑10.
  • OWASP Top 10 lists common web vulnerabilities.
  • Assessment finds weaknesses; testing exploits them.
  • Ignoring vulnerabilities creates risk.
  • Patching is the most common way to fix vulnerabilities.

🔢 Step‑by‑step: How to run a vulnerability scan

  1. Install a vulnerability scanner (e.g., Nessus or OpenVAS).
  2. Configure the scanner with the target IP address.
  3. Start the scan.
  4. Wait for the scan to finish.
  5. Review the report.
  6. Prioritise vulnerabilities by CVSS score.
  7. Fix the vulnerabilities (patch, update, etc.).
  1. Install → 2. Configure → 3. Scan → 4. Wait → 5. Review → 6. Prioritise → 7. Fix
  

🌍 Real‑life examples

  • Google: Uses vulnerability assessments to protect its services.
  • Amazon: Scans its systems for vulnerabilities regularly.
  • Facebook: Has a bug bounty program that uses vulnerability assessments.

🇳🇬 Nigerian examples

  • GTBank: Uses vulnerability scanners to protect online banking.
  • MTN Nigeria: Scans its network for vulnerabilities.
  • DataBreed: A Nigerian firm that does vulnerability assessments for clients.
  • NITDA: Promotes vulnerability awareness in Nigeria.

🎈 Fun examples for children

  • Roblox: Uses vulnerability assessments to protect players.
  • Fortnite: Scans for cheaters and exploits.
  • YouTube: Uses assessments to keep videos safe.

🏠 Everyday examples

  • School: A teacher scans the school network for vulnerabilities.
  • Home: You scan your home network to find weak points.
  • Community: A community group scans its public wifi for security.

👪 Parent tips

Parents can help children understand vulnerability assessment by discussing the importance of keeping software updated and using strong passwords. Show them how to run a basic vulnerability scan on their own network (with permission).


💡 Interesting facts

  • The first vulnerability scanner was developed in the 1990s.
  • Nessus has over 100,000 plugins for detecting vulnerabilities.
  • OpenVAS was originally part of Nessus.

❓ Did you know?

  • Some vulnerabilities have been around for years and still exist.
  • The CVSS score is calculated using a complex formula.
  • Nigeria has a growing community of ethical hackers.

🧷 Remember this

  • A vulnerability is a weakness in a system.
  • Vulnerability assessment finds and prioritises weaknesses.
  • Nessus and OpenVAS are vulnerability scanners.
  • CVSS scores help prioritise fixes.
  • Always have permission before scanning.

⚠️ Common mistakes

  • Mistake: Scanning without permission. Correction: Always have permission.
  • Mistake: Ignoring high‑score vulnerabilities. Correction: Fix critical ones first.
  • Mistake: Not patching regularly. Correction: Apply updates as soon as possible.

✅ Best practices

  • Run vulnerability scans regularly.
  • Prioritise fixes by CVSS score.
  • Apply patches quickly.
  • Document all findings and fixes.
  • Report vulnerabilities responsibly.

📊 Vulnerability Management Cycle

  +------------------+
  | 1. Scan          |  (find vulnerabilities)
  +------------------+
          |
          V
  +------------------+
  | 2. Assess        |  (prioritise by CVSS)
  +------------------+
          |
          V
  +------------------+
  | 3. Fix           |  (patch, update)
  +------------------+
          |
          V
  +------------------+
  | 4. Verify        |  (check it is fixed)
  +------------------+
          |
          V
  +------------------+
  | 5. Repeat        |  (continuous)
  +------------------+
  

CVSS Score Table

ScoreSeverityAction
0-3LowFix when time permits
4-6MediumFix in next 30 days
7-8HighFix in next 7 days
9-10CriticalFix immediately

📝 End‑of‑module summary

In Module 3, we explored vulnerability assessment. We learned:

  • A vulnerability is a weakness in a system.
  • Vulnerability assessment finds and prioritises weaknesses.
  • Nessus and OpenVAS are vulnerability scanners.
  • CVSS scores help prioritise fixes.
  • OWASP Top 10 lists common web vulnerabilities.
  • Assessment finds weaknesses; testing exploits them.
  • Ignoring vulnerabilities creates risk.
  • Patching is the most common way to fix vulnerabilities.

You are now ready to move on to the next module, where we will learn about Exploitation – using vulnerabilities to gain access.


❓ Frequently Asked Questions (10)

  1. What is a vulnerability? A weakness in a system.
  2. What is vulnerability assessment? Finding and prioritising weaknesses.
  3. What is Nessus? A vulnerability scanner.
  4. What is OpenVAS? A free vulnerability scanner.
  5. What is CVSS? A scoring system for vulnerabilities.
  6. What is OWASP? A list of common web vulnerabilities.
  7. What is the difference between assessment and testing? Assessment finds weaknesses; testing exploits them.
  8. What is patching? Fixing vulnerabilities with updates.
  9. What is a zero‑day? An unknown vulnerability with no patch.
  10. Why is vulnerability assessment important? It helps fix weaknesses before attackers use them.

🔗 Matching exercise

Match the term to its description.

TermDescription
1. VulnerabilityA. A tool that finds weaknesses
2. NessusB. A weakness in a system
3. CVSSC. A scoring system for vulnerabilities

Answers: 1-B, 2-A, 3-C


🎭 Scenario‑based exercises

Scenario 1: You are an ethical hacker for a Nigerian school. You run a vulnerability scan and find a high‑score vulnerability in the school's student data system. What do you do?

Hint: Report it immediately and help fix it.

Scenario 2: A small business has a limited budget. Which vulnerability scanner would you recommend and why?

Hint: OpenVAS is free and works well for small organisations.


👥 Group activity

In groups, research the OWASP Top 10. Choose one vulnerability and explain how it works and how to prevent it. Present to the class.


🧑‍🏫 Individual activity

Write down the CVSS score for a hypothetical vulnerability with a score of 8.5. Explain what action you would take.


🛠️ Mini project

Create a poster that shows the vulnerability management cycle with a clear illustration of each step. Display it in the classroom.


📋 Practical assignment

Install OpenVAS (or Nessus if available) and run a scan on your own network (with permission). Write a report on the vulnerabilities you find and how to fix them.


🔑 Key takeaways

  • Vulnerabilities are weaknesses in systems.
  • Vulnerability assessment finds and prioritises weaknesses.
  • Nessus and OpenVAS are vulnerability scanners.
  • CVSS scores help prioritise fixes.
  • OWASP Top 10 lists common web vulnerabilities.
  • Always have permission before scanning.

🗣️ Classroom discussion questions

  1. Why is vulnerability assessment important?
  2. What is the difference between a vulnerability and a risk?
  3. How can a school protect itself from vulnerabilities?
  4. What would you do if you found a vulnerability in a system you do not own?
  5. How can Nigerian businesses benefit from vulnerability assessment?

🚀 Preparation for Module 4

In Module 4, we will explore Exploitation – using vulnerabilities to gain access. We will learn about tools like Metasploit and understand the importance of ethical exploitation.

To prepare, read about Metasploit and think about how vulnerabilities can be used to break into systems.


End of Module 3 · Introduction to Ethical Hacking – Level Two

5

Module Four

Module 4 · Ethical Hacking Level Two

🛡️ Module 4 · Introduction to Ethical Hacking – Level Two

Exploitation & Metasploit – Breaking In to Help Fix


📖 Module Introduction

Welcome back, digital detectives! In Module 1, we learned reconnaissance – gathering information. In Module 2, we scanned for open ports. In Module 3, we found vulnerabilities. Now, in Module 4, we will learn about exploitation – the step where we actually use those vulnerabilities to get into a system.

Exploitation is like using a key to open a locked door. In ethical hacking, we do this to prove that a vulnerability is real and to understand how an attacker could break in. This helps the owner fix the problem before a real attacker finds it.

In this module, we will learn about the most famous exploitation framework: Metasploit. We will also cover payloads, shells, and how to use exploits ethically and safely.

Remember: exploitation is only legal with explicit written permission. These skills are for ethical use only.


🎯 Learning Objectives

  • Explain what exploitation is.
  • Understand the difference between an exploit and a payload.
  • Use Metasploit to perform basic exploitation.
  • Describe what a shell is.
  • Explain the difference between bind and reverse shells.
  • Understand the risks of exploitation.
  • Give examples of exploitation in Nigeria.
  • Explain the ethics of exploitation.

📚 Warm‑up Story: “The Safe Test”

Chidi is an ethical hacker for a bank. The bank has a new safe that they want to test. They ask Chidi to try to break into it. Chidi knows the safe has a known weakness – the keypad can be tricked with a special code. He uses that code to open the safe. He shows the bank manager how he did it.

The bank manager thanks Chidi and fixes the keypad so the trick no longer works. This is exploitation – using a vulnerability to show that it exists, and then helping to fix it.


📌 Main Lessons

Lesson 1: What is exploitation?

Definition: Exploitation is the process of using a vulnerability to gain unauthorised access to a system.

Why it matters: It shows that a vulnerability is real and dangerous.

Simple explanation: It is like using a spare key to open a door.

Real‑life example: A hacker uses a buffer overflow to get into a server.

School example: A student uses a teacher's weak password to log into the school system.

Home example: You guess your parent's password to use the computer.

Nigerian example: DataBreed uses exploitation to test its clients.

Illustration:

  Exploitation = Using a vulnerability to break in
  

Mini summary: Exploitation is using a vulnerability to gain access.


Lesson 2: Exploit vs. Payload

Definition: An exploit is the code that takes advantage of a vulnerability. A payload is the code that runs after a successful exploit.

Why it matters: The exploit opens the door; the payload does the work.

Simple explanation: The exploit is the key; the payload is what you do after you open the door.

Real‑life example: An exploit that uses a buffer overflow to open a shell, and a payload that gives the attacker a command prompt.

School example: A student uses a trick to get the teacher's password (exploit) and then changes grades (payload).

Home example: You find a way to unlock your phone (exploit) and then install a game (payload).

Nigerian example: Ethical hackers use exploits and payloads in tests.

Illustration:

  Exploit = Opens the door
  Payload = Does something after
  

Mini summary: Exploit breaks in; payload does the work.


Lesson 3: Introduction to Metasploit

Definition: Metasploit is a powerful framework that provides exploits, payloads, and tools for ethical hacking.

Why it matters: It is the most widely used exploitation tool.

Simple explanation: It is like a Swiss Army knife for hacking.

Real‑life example: A penetration tester uses Metasploit to test a company's network.

School example: A teacher uses Metasploit (with permission) to demonstrate security.

Home example: You can use Metasploit on your own lab.

Nigerian example: Cybersecurity firms in Nigeria use Metasploit.

Illustration:

  Metasploit:
  Exploits → Payloads → Tools
  

Mini summary: Metasploit is a powerful exploitation framework.


Lesson 4: Metasploit console – msfconsole

Definition: msfconsole is the command‑line interface for Metasploit. It is where you type commands to use exploits and payloads.

Why it matters: It is the main way to interact with Metasploit.

Simple explanation: It is like a command centre for your hacking tools.

Real‑life example: A hacker types use exploit/windows/smb/ms17_010_eternalblue in msfconsole.

School example: A student types commands in msfconsole (with permission).

Home example: You use msfconsole in your lab.

Nigerian example: DataBreed uses msfconsole in penetration tests.

Illustration:

  msfconsole:
  msf > use exploit/windows/smb/ms17_010_eternalblue
  msf > set RHOSTS 192.168.1.10
  msf > exploit
  

Mini summary: msfconsole is the command line for Metasploit.


Lesson 5: Common Metasploit commands

Definition: Here are some common commands: use, set, show, exploit, and sessions.

Why it matters: These commands let you control Metasploit.

Simple explanation: They are like instructions you give to the tool.

Real‑life example: Using show options to see what you need to set.

School example: A teacher shows students how to use these commands.

Home example: You use these commands in your lab.

Nigerian example: Ethical hackers use these commands daily.

Illustration:

  Common Commands:
  use        → select an exploit
  set        → set a variable (like IP address)
  show       → display options
  exploit    → run the exploit
  sessions   → see active connections
  

Mini summary: Metasploit has simple commands to control it.


Lesson 6: Shell – what is it?

Definition: A shell is a command interface that lets you run commands on a remote system.

Why it matters: It is how you control the target after exploiting it.

Simple explanation: It is like having a remote control for the target computer.

Real‑life example: You get a shell on a server and can run commands like dir or whoami.

School example: A student gets a shell on a test server and lists files.

Home example: You get a shell on your own laptop to test security.

Nigerian example: Ethical hackers get shells to test systems.

Illustration:

  Shell:
  Attacker → Exploit → Shell → Control
  

Mini summary: A shell gives you command control of a remote system.


Lesson 7: Bind shells vs. Reverse shells

Definition: A bind shell opens a port on the target for the attacker to connect to. A reverse shell makes the target connect back to the attacker.

Why it matters: Reverse shells are usually more reliable because firewalls often block inbound connections but allow outbound ones.

Simple explanation: Bind shell: you call the target. Reverse shell: the target calls you.

Real‑life example: A hacker uses a reverse shell to get past a firewall.

School example: A student uses a reverse shell to access the school network from home.

Home example: You use a reverse shell to connect to your home computer from school.

Nigerian example: Ethical hackers use reverse shells in tests.

Illustration:

  Bind Shell: Target opens port ← Attacker connects
  Reverse Shell: Target connects → Attacker listens
  

Mini summary: Reverse shells are better for bypassing firewalls.


Lesson 8: Meterpreter – the advanced payload

Definition: Meterpreter is an advanced Metasploit payload that gives you a powerful, interactive shell with many features.

Why it matters: It lets you upload, download, and even take screenshots.

Simple explanation: It is like a super‑charged remote control.

Real‑life example: A hacker gets a Meterpreter shell and takes a screenshot of the target's desktop.

School example: A student uses Meterpreter to see what is on a test computer.

Home example: You use Meterpreter to explore your own system.

Nigerian example: DataBreed uses Meterpreter in tests.

Illustration:

  Meterpreter:
  upload /path/to/file
  download /path/to/file
  screenshot
  help
  

Mini summary: Meterpreter is a powerful, feature‑rich payload.


Lesson 9: Post‑exploitation – what to do after breaking in

Definition: Post‑exploitation is everything you do after gaining access: gathering information, escalating privileges, and maintaining access.

Why it matters: It helps you understand what an attacker could do.

Simple explanation: It is like exploring a house after you have unlocked the door.

Real‑life example: A hacker finds passwords stored on the target system.

School example: A student finds sensitive files on the school network.

Home example: You find old passwords on your own computer.

Nigerian example: Ethical hackers do post‑exploitation to find risks.

Illustration:

  Post‑Exploitation:
  1. Gather info
  2. Escalate privileges
  3. Maintain access
  4. Cover tracks
  

Mini summary: Post‑exploitation is what you do after gaining access.


Lesson 10: Privilege escalation – getting more power

Definition: Privilege escalation is the process of gaining higher privileges on a system (like becoming an administrator).

Why it matters: More privileges mean more control.

Simple explanation: It is like getting a master key after using a regular key.

Real‑life example: A hacker exploits a local vulnerability to become administrator.

School example: A student finds a way to become an admin on the school computer.

Home example: You find a way to become an admin on your own computer.

Nigerian example: Ethical hackers test for privilege escalation.

Illustration:

  Privilege Escalation:
  User → Admin → System
  

Mini summary: Privilege escalation gives you more control.


Lesson 11: Maintaining access – backdoors

Definition: Maintaining access means ensuring you can return to a system after you leave.

Why it matters: It tests how an attacker could persist.

Simple explanation: It is like leaving a key under the doormat.

Real‑life example: A hacker installs a backdoor on a server.

School example: A student leaves a hidden way to access the school system.

Home example: You leave a way to access your own computer.

Nigerian example: Ethical hackers test for backdoors.

Illustration:

  Maintaining Access:
  Backdoor → Re‑entry → Persistent
  

Mini summary: Backdoors let you return to a system.


Lesson 12: The ethics of exploitation

Definition: Ethical exploitation is only allowed with explicit permission and is used to improve security.

Why it matters: Unauthorised exploitation is illegal and harmful.

Simple explanation: It is like being a locksmith – you only open doors for people who own them.

Real‑life example: A company hires ethical hackers to test their systems.

School example: A teacher gives permission for students to test a lab.

Home example: You only exploit your own systems.

Nigerian example: NITDA promotes ethical exploitation.

Illustration:

  Ethical Exploitation:
  Permission → Test → Report → Fix
  

Mini summary: Ethical exploitation requires permission and is used to help.


Lesson 13: Exploitation in Nigeria

Definition: In Nigeria, ethical hackers use exploitation to test banks, telecoms, and government systems.

Why it matters: This helps protect sensitive data and infrastructure.

Simple explanation: Nigerian ethical hackers are digital protectors.

Real‑life example: GTBank uses ethical hackers to test systems.

School example: A school uses ethical hackers to test its data system.

Home example: Your parents use security software tested by ethical hackers.

Nigerian example: DataBreed does exploitation tests in Nigeria.

Illustration:

  Nigeria + Ethical Exploitation = Safer Digital Space
  

Mini summary: Nigerian organisations use ethical exploitation for protection.


Lesson 14: How to protect against exploitation

Definition: You can protect against exploitation by patching vulnerabilities, using firewalls, and using strong passwords.

Why it matters: Prevention is better than cure.

Simple explanation: It is like locking your doors and windows.

Real‑life example: A company applies security patches immediately.

School example: A school updates its software regularly.

Home example: You keep your devices updated.

Nigerian example: NITDA provides security tips.

Illustration:

  Protection:
  1. Patch vulnerabilities
  2. Use a firewall
  3. Use strong passwords
  

Mini summary: Patching and strong passwords protect against exploitation.


Lesson 15: Bringing it all together – exploitation

Now you understand exploitation – what it is, how it works, and how to do it ethically. You know about Metasploit, payloads, shells, and post‑exploitation. You also know how to protect against exploitation.

Remember: these skills are for ethical use only. Use them to protect, not to harm.

Mini summary: Exploitation is a key part of ethical hacking.


📖 Key Vocabulary

WordSimple definition
ExploitationUsing a vulnerability to break in.
ExploitCode that takes advantage of a vulnerability.
PayloadCode that runs after a successful exploit.
ShellA command interface on a remote system.
Bind ShellTarget opens a port for the attacker.
Reverse ShellTarget connects back to the attacker.
MeterpreterAn advanced payload.
Post‑exploitationActions after gaining access.
Privilege EscalationGetting higher privileges.
BackdoorA hidden way to access a system.

🧠 Important Concepts

  • Exploitation uses vulnerabilities to gain access.
  • Metasploit is the most powerful exploitation framework.
  • Reverse shells are better for bypassing firewalls.
  • Meterpreter is a feature‑rich payload.
  • Post‑exploitation includes gathering info and maintaining access.
  • Ethical exploitation requires permission.
  • Patching protects against exploitation.

🔢 Step‑by‑step: How to use Metasploit

  1. Open msfconsole.
  2. Find an exploit using search.
  3. Select the exploit with use.
  4. Set required options (like RHOSTS).
  5. Select a payload.
  6. Run the exploit with exploit.
  1. msfconsole
  2. search exploit
  3. use exploit/...
  4. set RHOSTS 192.168.1.10
  5. set PAYLOAD windows/meterpreter/reverse_tcp
  6. exploit
  

🌍 Real‑life examples

  • Google: Uses exploitation in its bug bounty program.
  • Microsoft: Uses exploitation to test its own systems.
  • Facebook: Uses ethical hackers for exploitation.

🇳🇬 Nigerian examples

  • GTBank: Uses exploitation to test online banking.
  • MTN Nigeria: Uses exploitation to test its network.
  • DataBreed: A Nigerian firm that does exploitation tests.
  • NITDA: Provides guidelines for ethical exploitation.

🎈 Fun examples for children

  • Roblox: Uses exploitation to protect players.
  • Fortnite: Uses exploitation to find cheaters.
  • YouTube: Uses exploitation to keep videos safe.

🏠 Everyday examples

  • School: A teacher uses exploitation to test the school network.
  • Home: You use exploitation to test your own network.
  • Community: A community group uses exploitation to test its wifi.

👪 Parent tips

Parents can help children understand exploitation by discussing the importance of ethics and permission. Show them how to use Metasploit only on their own systems.


💡 Interesting facts

  • Metasploit was created in 2003 by H.D. Moore.
  • Metasploit has over 1,500 exploits.
  • Meterpreter stands for "Meta‑interpreter".

❓ Did you know?

  • Some exploits have names like "EternalBlue" and "Heartbleed".
  • Metasploit is used by both ethical and malicious hackers.
  • Nigeria has a growing community of ethical hackers.

🧷 Remember this

  • Exploitation is using vulnerabilities to break in.
  • Metasploit is a powerful exploitation framework.
  • Reverse shells are better for bypassing firewalls.
  • Always get permission before exploiting.
  • Use your skills to protect, not to harm.

⚠️ Common mistakes

  • Mistake: Exploiting without permission. Correction: Always have written permission.
  • Mistake: Using the wrong payload. Correction: Choose the right payload for the target.
  • Mistake: Not documenting. Correction: Write down everything you do.

✅ Best practices

  • Always get written permission before exploiting.
  • Use reverse shells to bypass firewalls.
  • Document every step.
  • Report findings responsibly.
  • Keep your tools updated.

📊 Exploitation Process

  +------------------+
  | 1. Recon         |  (gather info)
  +------------------+
          |
          V
  +------------------+
  | 2. Scanning      |  (find open ports)
  +------------------+
          |
          V
  +------------------+
  | 3. Vulnerability |  (find weaknesses)
  +------------------+
          |
          V
  +------------------+
  | 4. Exploitation  |  (break in)
  +------------------+
          |
          V
  +------------------+
  | 5. Post‑exploit  |  (gather, maintain)
  +------------------+
  

Bind vs. Reverse Shells

Bind ShellReverse Shell
Target opens a portTarget connects back
Attacker connects to targetAttacker listens for connection
Blocked by firewallsBypasses most firewalls

📝 End‑of‑module summary

In Module 4, we explored exploitation. We learned:

  • Exploitation is using vulnerabilities to break in.
  • Metasploit is the most powerful exploitation framework.
  • Reverse shells are better for bypassing firewalls.
  • Meterpreter is a feature‑rich payload.
  • Post‑exploitation includes gathering info and maintaining access.
  • Ethical exploitation requires permission.
  • Patching protects against exploitation.

You are now ready to move on to the next module, where we will learn about Post‑Exploitation and Reporting.


❓ Frequently Asked Questions (10)

  1. What is exploitation? Using a vulnerability to break in.
  2. What is Metasploit? A powerful exploitation framework.
  3. What is a shell? A command interface on a remote system.
  4. What is the difference between bind and reverse shells? Bind: target opens port; reverse: target connects back.
  5. What is Meterpreter? An advanced payload.
  6. What is post‑exploitation? Actions after gaining access.
  7. What is privilege escalation? Getting higher privileges.
  8. Is exploitation legal? Only with permission.
  9. How can I protect against exploitation? Patch vulnerabilities, use firewalls.
  10. What are the risks of exploitation? It can cause damage if done incorrectly.

🔗 Matching exercise

Match the term to its description.

TermDescription
1. ExploitA. Code that runs after breaking in
2. PayloadB. Code that takes advantage of a vulnerability
3. ShellC. A command interface on a remote system

Answers: 1-B, 2-A, 3-C


🎭 Scenario‑based exercises

Scenario 1: You are an ethical hacker for a Nigerian school. You find a vulnerability in the school system. You want to show it to the IT team. What would you do?

Hint: Use a safe exploit (with permission) to demonstrate the vulnerability and then report it.

Scenario 2: A bank wants you to test its online banking system. What type of shell would you use and why?

Hint: Use a reverse shell to bypass the firewall.


👥 Group activity

In groups, research a famous exploit (like EternalBlue). Present how it works, what it does, and how to protect against it.


🧑‍🏫 Individual activity

Write down the steps to use a reverse shell in Metasploit. Explain each step in your own words.


🛠️ Mini project

Create a poster that shows the exploitation process with clear illustrations for each step. Display it in the classroom.


📋 Practical assignment

Set up a lab environment (with permission) and use Metasploit to exploit a test system. Document your steps and findings.


🔑 Key takeaways

  • Exploitation is using vulnerabilities to break in.
  • Metasploit is a powerful exploitation framework.
  • Reverse shells are better for bypassing firewalls.
  • Meterpreter is a feature‑rich payload.
  • Always get permission before exploiting.
  • Use your skills to protect, not to harm.

🗣️ Classroom discussion questions

  1. Why is exploitation important in ethical hacking?
  2. What are the risks of using Metasploit?
  3. How can a school protect itself from exploitation?
  4. What is the difference between a bind and a reverse shell?
  5. How can Nigerian businesses benefit from ethical exploitation?

🚀 Preparation for Module 5

In Module 5, we will explore Post‑Exploitation and Reporting. We will learn how to gather evidence, escalate privileges, and write a professional report.

To prepare, think about what you would do after gaining access to a system.


End of Module 4 · Introduction to Ethical Hacking – Level Two

6

Module Five

Module 5 · Ethical Hacking Level Two

🛡️ Module 5 · Introduction to Ethical Hacking – Level Two

Post‑Exploitation & Reporting – What to Do After You Break In


📖 Module Introduction

Welcome back, ethical hackers! In Module 1, we gathered information. In Module 2, we scanned for open ports. In Module 3, we found vulnerabilities. In Module 4, we exploited them to gain access. Now, in Module 5, we will learn what to do after we have access: post‑exploitation and reporting.

Post‑exploitation is what you do once you are inside the system. It includes gathering more information, escalating privileges, and maintaining access. Reporting is the final step – you tell the owner what you found and how to fix it. This is the most important part because without reporting, the owner cannot fix the vulnerabilities.

Remember: these skills are for ethical use only. Always have permission and report everything.


🎯 Learning Objectives

  • Explain what post‑exploitation is.
  • Describe the post‑exploitation phases.
  • Understand privilege escalation.
  • Explain data exfiltration and why it is tested.
  • Understand persistence and backdoors.
  • Learn how to cover tracks.
  • Write a professional report.
  • Give examples of post‑exploitation in Nigeria.
  • Understand the ethics of post‑exploitation.

📚 Warm‑up Story: “The Bank Investigation”

Chidi is an ethical hacker testing a bank's security. He has exploited a vulnerability and gained access to the bank's network. Now, he explores the network – he finds sensitive customer data, old passwords, and even a way to become an administrator (privilege escalation).

He takes careful notes and leaves no trace. He then writes a detailed report for the bank manager, explaining exactly what he found and how to fix it. The bank fixes everything, and Chidi is a hero. This shows how post‑exploitation and reporting work together to improve security.


📌 Main Lessons

Lesson 1: What is post‑exploitation?

Definition: Post‑exploitation is everything you do after gaining access to a system – gathering info, escalating privileges, maintaining access, and covering tracks.

Why it matters: It helps you understand what an attacker could do and what damage they could cause.

Simple explanation: It is like exploring a house after you have unlocked the door.

Real‑life example: A hacker finds passwords stored on a server.

School example: A student finds sensitive files on the school network.

Home example: You find old passwords on your own computer.

Nigerian example: Ethical hackers do post‑exploitation to find risks.

Illustration:

  Post‑Exploitation:
  1. Gather info
  2. Escalate privileges
  3. Maintain access
  4. Cover tracks
  5. Report
  

Mini summary: Post‑exploitation is what you do after gaining access.


Lesson 2: Information gathering – what can you find?

Definition: Information gathering inside a system means looking for files, passwords, network information, and other data.

Why it matters: It shows how much data an attacker could steal.

Simple explanation: It is like looking inside a filing cabinet.

Real‑life example: A hacker finds a file with all the employee passwords.

School example: A student finds a file with exam answers.

Home example: You find a file with your family's wifi passwords.

Nigerian example: Ethical hackers look for sensitive data during tests.

Illustration:

  Information Gathering:
  - User accounts
  - Passwords
  - Network maps
  - Sensitive files
  

Mini summary: Information gathering shows what data is at risk.


Lesson 3: Privilege escalation – becoming the boss

Definition: Privilege escalation is gaining higher privileges on a system, like becoming an administrator or root.

Why it matters: With more privileges, you have more control and can access more data.

Simple explanation: It is like getting a master key after using a regular key.

Real‑life example: A hacker finds a vulnerability to become an admin.

School example: A student finds a way to become an admin on the school computer.

Home example: You find a way to become an admin on your own computer.

Nigerian example: Ethical hackers test for privilege escalation.

Illustration:

  Privilege Escalation:
  User → Admin → System
  

Mini summary: Privilege escalation gives you more control.


Lesson 4: Data exfiltration – testing data theft

Definition: Data exfiltration is copying sensitive data from the target system to the attacker's system.

Why it matters: It shows what data could be stolen.

Simple explanation: It is like stealing a document from a file cabinet.

Real‑life example: A hacker copies a customer database.

School example: A student copies exam papers.

Home example: You copy a file from your own computer.

Nigerian example: Ethical hackers test data exfiltration.

Illustration:

  Data Exfiltration:
  Target → Copy → Attacker
  

Mini summary: Data exfiltration shows what data could be stolen.


Lesson 5: Persistence – staying inside

Definition: Persistence is installing a backdoor to keep access to a system even after it is rebooted.

Why it matters: It shows how an attacker could maintain access.

Simple explanation: It is like leaving a spare key under the doormat.

Real‑life example: A hacker installs a service that runs at startup.

School example: A student installs a script to keep access.

Home example: You install a tool to access your own computer.

Nigerian example: Ethical hackers test for persistence.

Illustration:

  Persistence:
  Backdoor → Reboot → Still have access
  

Mini summary: Persistence keeps you inside the system.


Lesson 6: Covering tracks – erasing evidence

Definition: Covering tracks means removing logs and other evidence of your activities on the target.

Why it matters: It shows how an attacker could hide their presence.

Simple explanation: It is like wiping your footprints from the sand.

Real‑life example: A hacker deletes system logs.

School example: A student clears their search history.

Home example: You delete your browser history.

Nigerian example: Ethical hackers cover tracks during tests.

Illustration:

  Covering Tracks:
  Logs → Delete → No evidence
  

Mini summary: Covering tracks removes evidence.


Lesson 7: Reporting – the most important step

Definition: Reporting is the process of writing a clear, detailed document about your findings and how to fix them.

Why it matters: Without a report, the owner cannot fix the issues.

Simple explanation: It is like giving your teacher your homework.

Real‑life example: A security firm writes a report for a client.

School example: A student writes a report about a science project.

Home example: You explain to your parents what you found on the computer.

Nigerian example: DataBreed provides detailed reports to clients.

Illustration:

  Reporting:
  Findings → Recommendations → Client fixes
  

Mini summary: Reporting tells the owner what to fix.


Lesson 8: What to include in a report

Definition: A good report includes: executive summary, methodology, findings, evidence, and recommendations.

Why it matters: It helps the owner understand and fix the issues.

Simple explanation: It is like a doctor's report – it tells you what is wrong and how to fix it.

Real‑life example: A report lists vulnerabilities, CVSS scores, and fixes.

School example: A report lists problems found on the school network.

Home example: A report lists security issues on your home network.

Nigerian example: DataBreed writes detailed reports for clients.

Illustration:

  Report Sections:
  1. Executive summary
  2. Methodology
  3. Findings
  4. Evidence
  5. Recommendations
  

Mini summary: A good report is clear and actionable.


Lesson 9: Writing a professional report – tips

Definition: A professional report is clear, well‑organized, and uses simple language.

Why it matters: The owner needs to understand the report to take action.

Simple explanation: It is like giving clear instructions to a friend.

Real‑life example: A report uses bullet points and headings.

School example: A report uses a clear structure.

Home example: You write clear instructions for your family.

Nigerian example: Cybersecurity firms use professional reports.

Illustration:

  Professional Report:
  - Use headings
  - Use bullet points
  - Include screenshots
  - Be clear and simple
  

Mini summary: Write clear, well‑organized reports.


Lesson 10: Remediation – fixing the issues

Definition: Remediation is the process of fixing the vulnerabilities you found.

Why it matters: This is the goal of ethical hacking – to make systems secure.

Simple explanation: It is like fixing a broken lock.

Real‑life example: A company applies patches to fix vulnerabilities.

School example: A school updates its software.

Home example: You update your router's firmware.

Nigerian example: Nigerian banks remediate vulnerabilities.

Illustration:

  Remediation:
  Find → Fix → Verify → Secure
  

Mini summary: Remediation is fixing vulnerabilities.


Lesson 11: Post‑exploitation in Nigeria

Definition: In Nigeria, ethical hackers do post‑exploitation to test banks, telecoms, and government systems.

Why it matters: This helps protect sensitive data and infrastructure.

Simple explanation: Nigerian ethical hackers are digital protectors.

Real‑life example: GTBank uses ethical hackers to test systems.

School example: A school uses ethical hackers to test its data system.

Home example: Your parents use security software tested by ethical hackers.

Nigerian example: DataBreed does post‑exploitation tests.

Illustration:

  Nigeria + Ethical Post‑Exploitation = Safer Digital Space
  

Mini summary: Nigerian organisations use ethical post‑exploitation for protection.


Lesson 12: The ethics of post‑exploitation

Definition: Ethical post‑exploitation is only allowed with explicit permission and is used to improve security.

Why it matters: Unauthorised post‑exploitation is illegal and harmful.

Simple explanation: It is like being a security guard – you only patrol the building you are paid to protect.

Real‑life example: A company hires ethical hackers to test their systems.

School example: A teacher gives permission for students to test a lab.

Home example: You only test your own systems.

Nigerian example: NITDA promotes ethical post‑exploitation.

Illustration:

  Ethical Post‑Exploitation:
  Permission → Test → Report → Fix
  

Mini summary: Ethical post‑exploitation requires permission and helps protect.


Lesson 13: How to protect against post‑exploitation

Definition: You can protect by monitoring logs, using intrusion detection, and applying patches.

Why it matters: It makes it harder for attackers to stay inside.

Simple explanation: It is like having security cameras that record everything.

Real‑life example: A company uses SIEM to monitor logs.

School example: A school uses monitoring tools.

Home example: You check your computer logs.

Nigerian example: Nigerian banks use monitoring tools.

Illustration:

  Protection:
  1. Monitor logs
  2. Use intrusion detection
  3. Apply patches
  

Mini summary: Monitoring and patches protect against post‑exploitation.


Lesson 14: The importance of documentation

Definition: Documentation is the practice of writing down every step you take during a test.

Why it matters: It helps you write a good report and proves you did the work.

Simple explanation: It is like keeping a diary of your investigation.

Real‑life example: A security firm keeps logs of every action.

School example: A student takes notes during a project.

Home example: You write down the steps to bake a cake.

Nigerian example: DataBreed keeps detailed documentation.

Illustration:

  Documentation:
  Date → Action → Tool → Result
  

Mini summary: Documentation helps you keep track of your work.


Lesson 15: Bringing it all together – post‑exploitation and reporting

Now you understand post‑exploitation and reporting. You know how to gather information, escalate privileges, maintain access, cover tracks, and write a report. These are essential skills for any ethical hacker.

Remember: the goal is to help, not to harm. Use your skills to protect and improve security.

Mini summary: Post‑exploitation and reporting are key to ethical hacking.


📖 Key Vocabulary

WordSimple definition
Post‑ExploitationActions after gaining access.
Privilege EscalationGetting higher privileges.
Data ExfiltrationCopying data from the target.
PersistenceKeeping access to a system.
Covering TracksRemoving evidence.
ReportingWriting a document about findings.
RemediationFixing vulnerabilities.
DocumentationWriting down every step.

🧠 Important Concepts

  • Post‑exploitation includes gathering info, escalating privileges, maintaining access, and covering tracks.
  • Reporting tells the owner what to fix.
  • Remediation fixes vulnerabilities.
  • Documentation is essential for good reporting.
  • Ethical post‑exploitation requires permission.

🔢 Step‑by‑step: Post‑exploitation process

  1. Gather information (files, passwords, network info).
  2. Escalate privileges if needed.
  3. Exfiltrate a sample of data (with permission).
  4. Maintain access (test persistence).
  5. Cover tracks (clear logs).
  6. Write a report with findings and recommendations.
  1. Gather → 2. Escalate → 3. Exfiltrate → 4. Persist → 5. Cover → 6. Report
  

🌍 Real‑life examples

  • Google: Uses post‑exploitation in bug bounty programs.
  • Amazon: Uses post‑exploitation to test its own systems.
  • Facebook: Uses ethical hackers for post‑exploitation.

🇳🇬 Nigerian examples

  • GTBank: Uses post‑exploitation to test online banking.
  • MTN Nigeria: Uses post‑exploitation to test its network.
  • DataBreed: A Nigerian firm that does post‑exploitation tests.
  • NITDA: Provides guidelines for ethical post‑exploitation.

🎈 Fun examples for children

  • Roblox: Uses post‑exploitation to protect players.
  • Fortnite: Uses post‑exploitation to find cheaters.
  • YouTube: Uses post‑exploitation to keep videos safe.

🏠 Everyday examples

  • School: A teacher uses post‑exploitation to test the school network.
  • Home: You use post‑exploitation to test your own network.
  • Community: A community group uses post‑exploitation to test its wifi.

👪 Parent tips

Parents can help children understand post‑exploitation by discussing the importance of ethics and reporting. Show them how to write a clear report about security findings.


💡 Interesting facts

  • Post‑exploitation is often the longest phase of a penetration test.
  • Many breaches are discovered during post‑exploitation monitoring.
  • Nigeria has a growing community of ethical hackers.

❓ Did you know?

  • Some ethical hackers specialise only in post‑exploitation.
  • Reporting is considered the most important step in ethical hacking.
  • NITDA promotes ethical hacking in Nigeria.

🧷 Remember this

  • Post‑exploitation is what you do after gaining access.
  • Reporting tells the owner what to fix.
  • Remediation fixes vulnerabilities.
  • Documentation is essential.
  • Always have permission.

⚠️ Common mistakes

  • Mistake: Not documenting your actions. Correction: Write everything down.
  • Mistake: Not reporting important findings. Correction: Report every vulnerability.
  • Mistake: Using post‑exploitation without permission. Correction: Always have permission.

✅ Best practices

  • Always document every step.
  • Write clear, professional reports.
  • Include recommendations for fixes.
  • Get permission before any post‑exploitation.
  • Keep your tools updated.

📊 Post‑Exploitation Process

  +------------------+
  | 1. Gather Info   |  (files, passwords, etc.)
  +------------------+
          |
          V
  +------------------+
  | 2. Escalate      |  (become admin)
  +------------------+
          |
          V
  +------------------+
  | 3. Exfiltrate    |  (copy data)
  +------------------+
          |
          V
  +------------------+
  | 4. Persist       |  (backdoor)
  +------------------+
          |
          V
  +------------------+
  | 5. Cover Tracks  |  (delete logs)
  +------------------+
          |
          V
  +------------------+
  | 6. Report        |  (tell owner)
  +------------------+
  

Report Structure

SectionContent
Executive SummaryHigh‑level overview
MethodologyHow you tested
FindingsWhat you found
EvidenceScreenshots, logs
RecommendationsHow to fix

📝 End‑of‑module summary

In Module 5, we explored post‑exploitation and reporting. We learned:

  • Post‑exploitation includes gathering info, escalating privileges, maintaining access, and covering tracks.
  • Reporting tells the owner what to fix.
  • Remediation fixes vulnerabilities.
  • Documentation is essential for good reporting.
  • Ethical post‑exploitation requires permission.

You are now ready to move on to the next module, where we will learn about Web Application Security.


❓ Frequently Asked Questions (10)

  1. What is post‑exploitation? Actions after gaining access.
  2. What is privilege escalation? Getting higher privileges.
  3. What is data exfiltration? Copying data from the target.
  4. What is persistence? Keeping access to a system.
  5. What is covering tracks? Removing evidence.
  6. What is reporting? Writing a document about findings.
  7. What is remediation? Fixing vulnerabilities.
  8. Why is documentation important? It helps you write a good report.
  9. Is post‑exploitation legal? Only with permission.
  10. What are the risks of post‑exploitation? It can cause damage if done incorrectly.

🔗 Matching exercise

Match the term to its description.

TermDescription
1. Data ExfiltrationA. Keeping access to a system
2. PersistenceB. Copying data from the target
3. RemediationC. Fixing vulnerabilities

Answers: 1-B, 2-A, 3-C


🎭 Scenario‑based exercises

Scenario 1: You are an ethical hacker for a Nigerian school. You have gained access to the school network. What post‑exploitation steps would you take?

Hint: Gather information, escalate privileges if needed, document everything, and write a report.

Scenario 2: A bank wants you to test its systems. After exploitation, you find a file with customer data. What should you do?

Hint: Do not copy the data – just document it. Report it to the bank.


👥 Group activity

In groups, write a sample report for a hypothetical penetration test. Include all sections: executive summary, methodology, findings, evidence, and recommendations.


🧑‍🏫 Individual activity

Write down the post‑exploitation steps you would take in a test. Explain why each step is important.


🛠️ Mini project

Create a poster that shows the post‑exploitation process with clear illustrations for each step. Display it in the classroom.


📋 Practical assignment

Set up a lab environment (with permission) and perform post‑exploitation on a test system. Write a detailed report of your findings.


🔑 Key takeaways

  • Post‑exploitation includes gathering info, escalating privileges, maintaining access, and covering tracks.
  • Reporting tells the owner what to fix.
  • Remediation fixes vulnerabilities.
  • Documentation is essential.
  • Always have permission.

🗣️ Classroom discussion questions

  1. Why is reporting the most important step?
  2. What are the risks of not covering tracks?
  3. How can a school protect itself from post‑exploitation?
  4. What is the difference between persistence and a backdoor?
  5. How can Nigerian businesses benefit from ethical post‑exploitation?

🚀 Preparation for Module 6

In Module 6, we will explore Web Application Security. We will learn about common vulnerabilities like SQL injection and cross‑site scripting (XSS), and how to test for them.

To prepare, read about the OWASP Top 10 and think about how websites can be attacked.


End of Module 5 · Introduction to Ethical Hacking – Level Two

7

Module Six

Module 6 · Ethical Hacking Level Two

🛡️ Module 6 · Introduction to Ethical Hacking – Level Two

Web Application Security – OWASP & Common Vulnerabilities


📖 Module Introduction

Welcome back, ethical hackers! In Modules 1–5, we learned about reconnaissance, scanning, vulnerability assessment, exploitation, and post‑exploitation. Now, in Module 6, we will focus on a very important area: Web Application Security.

Web applications are everywhere – from online banking to social media to games. Unfortunately, they are also a common target for attackers. In this module, we will learn about the OWASP Top 10, which is a list of the most common web vulnerabilities. We will explore vulnerabilities like SQL injection, Cross‑Site Scripting (XSS), and Broken Authentication.

By the end, you will understand how attackers target web applications and how to protect them. Remember: these skills are for ethical use only. Always have permission before testing any website.


🎯 Learning Objectives

  • Explain what web application security is.
  • Describe the OWASP Top 10.
  • Understand SQL injection and how it works.
  • Explain Cross‑Site Scripting (XSS).
  • Describe Broken Authentication.
  • Understand Security Misconfiguration.
  • Explain how to test for vulnerabilities.
  • Give examples of web vulnerabilities in Nigeria.
  • Explain the importance of secure coding.

📚 Warm‑up Story: “The School Portal”

Chidi's school has a portal where students can check their grades. One day, a student named Tunde discovers that he can type special characters into the search box and see other students' grades. He tells the IT teacher, who realises that the portal is vulnerable to SQL injection.

The IT teacher fixes the problem by using parameterised queries (a safe way to handle input). Now, the portal is secure. This story shows how common web vulnerabilities can be found and fixed.


📌 Main Lessons

Lesson 1: What is web application security?

Definition: Web application security is the practice of protecting websites and web applications from attacks.

Why it matters: Web applications handle sensitive data like passwords, bank details, and personal information.

Simple explanation: It is like putting locks and alarms on a website to keep it safe.

Real‑life example: A bank's online portal uses HTTPS and other security measures.

School example: The school website uses security to protect student data.

Home example: Your family's online shopping accounts need security.

Nigerian example: GTBank uses web security to protect online banking.

Illustration:

  Web Application Security = Protecting websites from attacks
  

Mini summary: Web application security protects websites and user data.


Lesson 2: OWASP Top 10 – the most common vulnerabilities

Definition: OWASP (Open Web Application Security Project) is a non‑profit organisation that provides security guidance. The OWASP Top 10 is a list of the most critical web application vulnerabilities.

Why it matters: It helps developers and security professionals focus on the most important risks.

Simple explanation: It is like a list of the most common ways burglars break into houses.

Real‑life example: A developer checks the OWASP Top 10 when building a website.

School example: A teacher learns about OWASP to teach students.

Home example: You learn about OWASP to stay safe online.

Nigerian example: NITDA promotes OWASP awareness in Nigeria.

Illustration:

  OWASP Top 10 (common):
  1. Injection
  2. Broken Authentication
  3. Sensitive Data Exposure
  4. XXE (XML External Entities)
  5. Broken Access Control
  6. Security Misconfiguration
  7. XSS (Cross‑Site Scripting)
  8. Insecure Deserialization
  9. Using Components with Known Vulnerabilities
  10. Insufficient Logging & Monitoring
  

Mini summary: The OWASP Top 10 lists the most common web vulnerabilities.


Lesson 3: SQL Injection – tricking the database

Definition: SQL injection is an attack where an attacker inserts malicious SQL code into a query to manipulate the database.

Why it matters: It can let attackers read, modify, or delete data.

Simple explanation: It is like tricking a librarian into giving you books you are not allowed to see.

Real‑life example: A hacker uses ' OR '1'='1 to log in as an admin.

School example: A student types ' OR '1'='1 into the search box and sees all records.

Home example: You could use it to see other people's orders on a shopping site.

Nigerian example: Nigerian banks protect against SQL injection.

Illustration:

  SQL Injection:
  SELECT * FROM users WHERE username = 'admin' OR '1'='1';
  

Mini summary: SQL injection manipulates databases through malicious input.


Lesson 4: Cross‑Site Scripting (XSS) – injecting scripts

Definition: XSS is an attack where an attacker injects malicious scripts into a website, which then run in the user's browser.

Why it matters: It can steal cookies, session tokens, or perform actions on behalf of the user.

Simple explanation: It is like putting a note on a website that tricks visitors.

Real‑life example: An attacker injects a script that steals a user's session cookie.

School example: A student injects a script that shows a pop‑up on the school website.

Home example: You see an ad that takes you to a malicious website.

Nigerian example: Nigerian websites are sometimes vulnerable to XSS.

Illustration:

  XSS:
  
  

Mini summary: XSS injects scripts into websites to steal data.


Lesson 5: Broken Authentication – weak login systems

Definition: Broken authentication occurs when a website's login system is weak, allowing attackers to guess passwords or hijack sessions.

Why it matters: It lets attackers impersonate users.

Simple explanation: It is like having a lock that can be opened with any key.

Real‑life example: A website allows unlimited login attempts, so an attacker can brute‑force passwords.

School example: The school portal allows students to guess each other's passwords.

Home example: You use a weak password for your email.

Nigerian example: Nigerian companies use multi‑factor authentication to protect against this.

Illustration:

  Broken Authentication:
  Attacker → Guesses password → Gains access
  

Mini summary: Broken authentication lets attackers bypass login systems.


Lesson 6: Security Misconfiguration – leaving doors open

Definition: Security misconfiguration occurs when a website is not configured securely – like using default passwords or leaving debug features on.

Why it matters: It gives attackers easy access.

Simple explanation: It is like leaving your front door wide open.

Real‑life example: A website uses the default admin password.

School example: The school server uses default settings that are known to be insecure.

Home example: Your router uses the default password that came with it.

Nigerian example: Nigerian companies often secure misconfigurations.

Illustration:

  Security Misconfiguration:
  Default password → Easy access
  

Mini summary: Security misconfiguration means insecure settings.


Lesson 7: Sensitive Data Exposure – leaking information

Definition: Sensitive data exposure occurs when a website does not properly protect sensitive information like passwords, credit card numbers, or personal data.

Why it matters: It can lead to identity theft and financial loss.

Simple explanation: It is like leaving your bank statement on a bus.

Real‑life example: A website stores passwords in plain text.

School example: The school stores student names and addresses without encryption.

Home example: You store passwords in a text file on your computer.

Nigerian example: Nigerian banks encrypt customer data.

Illustration:

  Sensitive Data Exposure:
  Unencrypted data → Attacker reads it
  

Mini summary: Sensitive data exposure leaks important information.


Lesson 8: Broken Access Control – seeing what you should not

Definition: Broken access control occurs when a user can access resources or perform actions they are not authorised to.

Why it matters: It lets users see or change other people's data.

Simple explanation: It is like being able to open your teacher's desk.

Real‑life example: A user changes the ID in the URL and sees another user's profile.

School example: A student changes a number in the URL to see other students' grades.

Home example: You see someone else's shopping cart.

Nigerian example: Nigerian companies protect against this.

Illustration:

  Broken Access Control:
  User changes ID → Sees another user's data
  

Mini summary: Broken access control lets users see unauthorised data.


Lesson 9: Testing for web vulnerabilities – tools

Definition: There are many tools for testing web vulnerabilities, such as Burp Suite, OWASP ZAP, and Nikto.

Why it matters: Tools automate the testing process.

Simple explanation: Tools are like special spyglasses for finding weaknesses.

Real‑life example: A security team uses Burp Suite to test a website.

School example: A teacher uses OWASP ZAP to show students security.

Home example: You use Nikto to test your own website.

Nigerian example: DataBreed uses these tools in tests.

Illustration:

  Web Security Tools:
  - Burp Suite
  - OWASP ZAP
  - Nikto
  

Mini summary: Tools help test web applications for vulnerabilities.


Lesson 10: How to protect against web vulnerabilities

Definition: You can protect web applications by using secure coding practices, validating input, using HTTPS, and applying patches.

Why it matters: Prevention is better than cure.

Simple explanation: It is like following safety rules to prevent accidents.

Real‑life example: A developer uses parameterised queries to prevent SQL injection.

School example: The school uses HTTPS to protect student data.

Home example: Your parents use secure websites for shopping.

Nigerian example: NITDA provides guidelines for secure coding.

Illustration:

  Protection:
  1. Validate input
  2. Use HTTPS
  3. Use parameterised queries
  4. Apply patches
  

Mini summary: Secure coding and HTTPS protect web applications.


Lesson 11: Web vulnerabilities in Nigeria

Definition: In Nigeria, web vulnerabilities are a serious concern. Banks, government agencies, and businesses are targets.

Why it matters: Nigeria is a growing digital economy, and security is important.

Simple explanation: Nigerian organisations need to protect their websites.

Real‑life example: GTBank protects its online banking from SQL injection.

School example: A school uses web security to protect student data.

Home example: Your parents use secure websites for banking.

Nigerian example: NITDA promotes web security awareness.

Illustration:

  Nigeria + Web Security = Safer Digital Space
  

Mini summary: Nigerian organisations use web security to protect themselves.


Lesson 12: The importance of secure coding

Definition: Secure coding is the practice of writing code that is free from vulnerabilities.

Why it matters: Most vulnerabilities come from poor coding practices.

Simple explanation: It is like building a house with strong materials.

Real‑life example: A developer writes code that validates all user input.

School example: A teacher teaches students to write secure code.

Home example: You learn to code securely.

Nigerian example: NITDA encourages secure coding.

Illustration:

  Secure Coding = Writing code without vulnerabilities
  

Mini summary: Secure coding prevents vulnerabilities.


Lesson 13: How to report web vulnerabilities

Definition: If you find a vulnerability in a website, you should report it responsibly to the owner.

Why it matters: This allows the owner to fix it before attackers find it.

Simple explanation: It is like telling someone their door is unlocked.

Real‑life example: An ethical hacker finds a vulnerability and reports it to the company.

School example: A student finds a weakness in the school portal and tells the IT teacher.

Home example: You find a vulnerability in a game and tell the developer.

Nigerian example: DataBreed reports vulnerabilities to clients.

Illustration:

  Responsible Disclosure:
  1. Find vulnerability
  2. Report to owner
  3. Give time to fix
  

Mini summary: Report vulnerabilities responsibly.


Lesson 14: The future of web security

Definition: Web security is constantly evolving. New threats appear every day, and we must stay updated.

Why it matters: To keep data safe, we need to learn continuously.

Simple explanation: It is like playing a game that keeps adding new levels.

Real‑life example: New tools and frameworks are developed to improve security.

School example: Schools teach updated security practices.

Home example: You keep your software updated.

Nigerian example: NITDA promotes continuous learning.

Illustration:

  Future = New threats + New protections
  

Mini summary: Web security is always evolving.


Lesson 15: Bringing it all together – web security

Now you understand the basics of web application security. You know about the OWASP Top 10, SQL injection, XSS, and other common vulnerabilities. You also know how to protect against them and how to report vulnerabilities responsibly.

Remember: these skills are for ethical use only. Use them to make the web safer.

Mini summary: Web security is about protecting websites and users.


📖 Key Vocabulary

WordSimple definition
SQL InjectionAttacking a database by injecting code.
XSSInjecting scripts into a website.
Broken AuthenticationWeak login systems.
Security MisconfigurationInsecure settings.
Sensitive Data ExposureLeaking private information.
Broken Access ControlSeeing unauthorised data.
OWASPOrganisation for web security.
Burp SuiteA tool for testing web security.
Secure CodingWriting code without vulnerabilities.
Responsible DisclosureReporting vulnerabilities to the owner.

🧠 Important Concepts

  • The OWASP Top 10 lists the most common web vulnerabilities.
  • SQL injection manipulates databases.
  • XSS injects malicious scripts.
  • Broken authentication lets attackers log in.
  • Security misconfiguration means insecure settings.
  • Secure coding prevents vulnerabilities.
  • Always report vulnerabilities responsibly.

🔢 Step‑by‑step: How to test for SQL injection

  1. Find a website with a search box or login form.
  2. Type ' OR '1'='1 into the search box.
  3. Check if the website returns all records.
  4. If it does, the site is vulnerable.
  5. Report the vulnerability to the owner.
  1. Find input → 2. Type ' OR '1'='1 → 3. Check results → 4. Report
  

🌍 Real‑life examples

  • Google: Uses bug bounty programs to find web vulnerabilities.
  • Amazon: Tests its websites for SQL injection.
  • Facebook: Uses ethical hackers for web security.

🇳🇬 Nigerian examples

  • GTBank: Tests its online banking for SQL injection.
  • MTN Nigeria: Protects its websites from attacks.
  • DataBreed: A Nigerian firm that tests web applications.
  • NITDA: Promotes web security awareness.

🎈 Fun examples for children

  • Roblox: Protects its website from XSS.
  • Fortnite: Uses web security to protect players.
  • YouTube: Protects its platform from attacks.

🏠 Everyday examples

  • School: A teacher tests the school portal for vulnerabilities.
  • Home: You test your own website for security.
  • Community: A group tests a community website.

👪 Parent tips

Parents can help children understand web security by discussing the importance of using secure websites and strong passwords. Show them how to spot suspicious websites.


💡 Interesting facts

  • SQL injection has been around since the late 1990s.
  • XSS is one of the most common vulnerabilities.
  • OWASP is a non‑profit organisation founded in 2001.

❓ Did you know?

  • Many websites still have SQL injection vulnerabilities.
  • Using HTTPS is one of the best ways to protect sensitive data.
  • Nigeria has a growing community of web security experts.

🧷 Remember this

  • The OWASP Top 10 lists common web vulnerabilities.
  • SQL injection and XSS are major threats.
  • Secure coding prevents vulnerabilities.
  • Always report vulnerabilities responsibly.

⚠️ Common mistakes

  • Mistake: Not validating user input. Correction: Always validate input.
  • Mistake: Using default passwords. Correction: Change default passwords.
  • Mistake: Not using HTTPS. Correction: Always use HTTPS.

✅ Best practices

  • Validate all user input.
  • Use parameterised queries to prevent SQL injection.
  • Use HTTPS to encrypt data.
  • Apply security patches regularly.
  • Test your applications for vulnerabilities.

📊 OWASP Top 10 (Simplified)

  +-----------------------------------------+
  |           OWASP TOP 10                   |
  +-----------------------------------------+
  | 1. Injection                            |
  | 2. Broken Authentication                |
  | 3. Sensitive Data Exposure              |
  | 4. XXE                                 |
  | 5. Broken Access Control                |
  | 6. Security Misconfiguration            |
  | 7. XSS                                 |
  | 8. Insecure Deserialization             |
  | 9. Using Vulnerable Components          |
  | 10. Insufficient Logging & Monitoring   |
  +-----------------------------------------+
  

Comparison table: SQL Injection vs XSS

SQL InjectionXSS
Attacks the databaseAttacks the user
Can read, modify, delete dataCan steal cookies, session tokens
Prevent with parameterised queriesPrevent with input validation

📝 End‑of‑module summary

In Module 6, we explored web application security. We learned:

  • The OWASP Top 10 lists the most common web vulnerabilities.
  • SQL injection manipulates databases.
  • XSS injects malicious scripts.
  • Broken authentication lets attackers bypass login.
  • Secure coding prevents vulnerabilities.
  • Always report vulnerabilities responsibly.

You are now ready to move on to the next module, where we will learn about Wireless Security.


❓ Frequently Asked Questions (10)

  1. What is SQL injection? An attack that manipulates a database.
  2. What is XSS? An attack that injects scripts into a website.
  3. What is the OWASP Top 10? A list of common web vulnerabilities.
  4. What is broken authentication? Weak login systems.
  5. What is security misconfiguration? Insecure settings.
  6. What is sensitive data exposure? Leaking private information.
  7. What is broken access control? Seeing unauthorised data.
  8. What is secure coding? Writing code without vulnerabilities.
  9. What is responsible disclosure? Reporting vulnerabilities to the owner.
  10. How can I protect my website? Validate input, use HTTPS, apply patches.

🔗 Matching exercise

Match the vulnerability to its description.

VulnerabilityDescription
1. SQL InjectionA. Injects scripts into a website
2. XSSB. Manipulates a database
3. Broken AuthenticationC. Weak login systems

Answers: 1-B, 2-A, 3-C


🎭 Scenario‑based exercises

Scenario 1: You are an ethical hacker testing a school portal. You find a search box that is vulnerable to SQL injection. What do you do?

Hint: Demonstrate the vulnerability to the IT team and recommend a fix.

Scenario 2: A Nigerian bank wants you to test its online banking. What are the top three vulnerabilities you would look for?

Hint: SQL injection, XSS, and broken authentication.


👥 Group activity

In groups, research the OWASP Top 10. Choose three vulnerabilities and explain how they work and how to prevent them. Present to the class.


🧑‍🏫 Individual activity

Write down the steps to prevent SQL injection in a web application. Explain why each step is important.


🛠️ Mini project

Create a poster that shows the OWASP Top 10 with a simple explanation for each vulnerability. Display it in the classroom.


📋 Practical assignment

Set up a test website (with permission) and use OWASP ZAP or Burp Suite to find vulnerabilities. Write a report on your findings.


🔑 Key takeaways

  • The OWASP Top 10 lists common web vulnerabilities.
  • SQL injection and XSS are major threats.
  • Secure coding prevents vulnerabilities.
  • Always report vulnerabilities responsibly.
  • Use HTTPS and validate input.

🗣️ Classroom discussion questions

  1. Why is SQL injection a serious threat?
  2. How can XSS be used to steal information?
  3. What are the benefits of using HTTPS?
  4. How can Nigerian businesses improve web security?
  5. What would you do if you found a vulnerability in a website?

🚀 Preparation for Module 7

In Module 7, we will explore Wireless Security. We will learn about Wi‑Fi vulnerabilities, how to secure wireless networks, and tools like Aircrack‑ng.

To prepare, think about the Wi‑Fi networks you use at home and at school. How secure are they?


End of Module 6 · Introduction to Ethical Hacking – Level Two

8

Module Seven

Module 7 · Ethical Hacking Level Two

🛡️ Module 7 · Introduction to Ethical Hacking – Level Two

Wireless Security – Protecting Wi‑Fi Networks


📖 Module Introduction

Welcome back, ethical hackers! In Modules 1–6, we covered reconnaissance, scanning, vulnerability assessment, exploitation, post‑exploitation, and web security. Now, in Module 7, we will explore Wireless Security.

Wireless networks (Wi‑Fi) are everywhere – at home, at school, in cafes, and in offices. They are very convenient, but they also come with security risks. Because data travels through the air, attackers can "listen" to it if the network is not secure.

In this module, we will learn about Wi‑Fi security protocols like WEP, WPA, and WPA2. We will also explore common attacks like sniffing, deauthentication, and password cracking. We will also look at tools like Aircrack‑ng.

Remember: these skills are for ethical use only. Never test a network that you do not own or have permission to test.


🎯 Learning Objectives

  • Explain what wireless security is.
  • Describe the Wi‑Fi security protocols (WEP, WPA, WPA2, WPA3).
  • Understand common wireless attacks.
  • Explain sniffing and deauthentication attacks.
  • Describe WPS attacks.
  • Use Aircrack‑ng for ethical testing.
  • Explain how to secure Wi‑Fi networks.
  • Give examples of wireless security in Nigeria.

📚 Warm‑up Story: “The Cafe Wi‑Fi”

Chidi is at a cafe in Lagos, using the free Wi‑Fi to do his homework. He notices that the network is not password‑protected. He tells the cafe owner about the risk – anyone can see the data being sent over the network.

The owner asks Chidi for help. Chidi sets up a secure network with WPA2 encryption and a strong password. Now, customers can use the Wi‑Fi safely. This story shows how important it is to secure wireless networks.


📌 Main Lessons

Lesson 1: What is wireless security?

Definition: Wireless security is the practice of protecting Wi‑Fi networks from unauthorised access and attacks.

Why it matters: Wireless data travels through the air and can be intercepted.

Simple explanation: It is like making sure your radio signals are not heard by strangers.

Real‑life example: A home router uses WPA2 to protect the network.

School example: The school uses a secure Wi‑Fi network.

Home example: Your family uses a password‑protected Wi‑Fi.

Nigerian example: MTN Nigeria secures its Wi‑Fi hotspots.

Illustration:

  Wireless Security = Protecting Wi‑Fi from eavesdroppers
  

Mini summary: Wireless security protects Wi‑Fi networks from attacks.


Lesson 2: Wi‑Fi security protocols – WEP, WPA, WPA2, WPA3

Definition: Security protocols are rules that protect wireless networks. The most common are WEP, WPA, WPA2, and WPA3.

Why it matters: These protocols encrypt the data so that attackers cannot read it.

Simple explanation: They are like different types of locks for your Wi‑Fi door.

Real‑life example: Most modern routers use WPA2 or WPA3.

School example: The school uses WPA2 for security.

Home example: Your router uses WPA2.

Nigerian example: Nigerian companies use WPA2 or WPA3.

Illustration:

  Security Protocols:
  WEP (weak) → WPA (better) → WPA2 (strong) → WPA3 (strongest)
  

Mini summary: WPA2 and WPA3 are the best wireless security protocols.


Lesson 3: Why WEP is not secure

Definition: WEP (Wired Equivalent Privacy) is an old security protocol that can be cracked easily.

Why it matters: Attackers can break WEP in minutes.

Simple explanation: It is like a lock that can be opened with a paperclip.

Real‑life example: Many older routers still use WEP.

School example: A school using WEP is at high risk.

Home example: Your old router might use WEP.

Nigerian example: NITDA advises against using WEP.

Illustration:

  WEP = Weak and easily cracked
  

Mini summary: WEP is not secure – avoid it.


Lesson 4: Sniffing – listening to wireless traffic

Definition: Sniffing is the act of capturing and listening to data that is being transmitted over a wireless network.

Why it matters: If the data is not encrypted, an attacker can read it.

Simple explanation: It is like eavesdropping on a conversation.

Real‑life example: An attacker uses a tool like Wireshark to capture packets.

School example: A student captures data on the school network (with permission).

Home example: You capture packets on your own network.

Nigerian example: Ethical hackers use sniffing for testing.

Illustration:

  Sniffing = Capturing wireless data packets
  

Mini summary: Sniffing captures data from wireless networks.


Lesson 5: Deauthentication attack – kicking users off

Definition: A deauthentication attack sends fake messages to disconnect a user from a Wi‑Fi network.

Why it matters: It can be used to force a user to reconnect, allowing the attacker to capture the handshake (the password exchange).

Simple explanation: It is like someone shouting "stop!" to interrupt a conversation.

Real‑life example: An attacker uses a tool like aireplay‑ng to deauthenticate a user.

School example: A student tests deauthentication on the school network (with permission).

Home example: You test deauthentication on your own network.

Nigerian example: Ethical hackers use deauthentication attacks in tests.

Illustration:

  Deauthentication:
  Attacker → Fake disconnect → User reconnects → Handshake captured
  

Mini summary: Deauthentication forces a user to reconnect, allowing handshake capture.


Lesson 6: Password cracking – breaking Wi‑Fi passwords

Definition: Password cracking is the process of guessing a Wi‑Fi password by trying many possible combinations.

Why it matters: If the password is weak, it can be cracked easily.

Simple explanation: It is like trying every key on a keychain until one fits.

Real‑life example: An attacker uses a tool like Aircrack‑ng to crack a password.

School example: A student tests password strength (with permission).

Home example: You test your own Wi‑Fi password.

Nigerian example: Nigerian companies use strong passwords to prevent cracking.

Illustration:

  Password Cracking:
  Capture handshake → Try passwords → Find the correct one
  

Mini summary: Password cracking tries to guess Wi‑Fi passwords.


Lesson 7: WPS – a weak spot

Definition: WPS (Wi‑Fi Protected Setup) is a feature that lets users connect to a network using a PIN instead of a password. It has a security flaw.

Why it matters: Attackers can brute‑force the WPS PIN to get the password.

Simple explanation: It is like having a secret code that is easy to guess.

Real‑life example: An attacker uses a tool like Reaver to break WPS.

School example: A student tests WPS security (with permission).

Home example: You disable WPS on your router.

Nigerian example: Nigerian companies disable WPS to improve security.

Illustration:

  WPS = Easy to crack – disable it!
  

Mini summary: WPS is a weak feature – it should be disabled.


Lesson 8: Aircrack‑ng – the wireless hacking toolkit

Definition: Aircrack‑ng is a suite of tools for testing wireless network security. It can capture packets, deauthenticate users, and crack passwords.

Why it matters: It is the most popular wireless security tool.

Simple explanation: It is like a Swiss Army knife for Wi‑Fi hacking.

Real‑life example: An ethical hacker uses Aircrack‑ng to test a network.

School example: A student uses Aircrack‑ng (with permission).

Home example: You use Aircrack‑ng on your own network.

Nigerian example: DataBreed uses Aircrack‑ng in tests.

Illustration:

  Aircrack‑ng tools:
  airodump-ng (capture)
  aireplay-ng (deauth)
  aircrack-ng (crack)
  

Mini summary: Aircrack‑ng is a powerful wireless hacking toolkit.


Lesson 9: How to secure a Wi‑Fi network

Definition: You can secure a Wi‑Fi network by using WPA2 or WPA3, using a strong password, disabling WPS, and hiding the SSID.

Why it matters: It makes it much harder for attackers to break in.

Simple explanation: It is like locking all the doors and windows.

Real‑life example: A home router is set up with WPA2 and a strong password.

School example: The school uses WPA2 and a guest network.

Home example: You change your router's default password.

Nigerian example: Nigerian companies use these practices.

Illustration:

  Secure Wi‑Fi:
  1. Use WPA2/WPA3
  2. Use a strong password
  3. Disable WPS
  4. Hide SSID (optional)
  

Mini summary: WPA2, strong passwords, and disabling WPS secure your Wi‑Fi.


Lesson 10: Wireless security in Nigeria

Definition: In Nigeria, wireless security is important for businesses, schools, and homes. Many organisations use WPA2 and strong passwords.

Why it matters: Nigeria has a growing digital economy, and secure Wi‑Fi is essential.

Simple explanation: Nigerian organisations use wireless security to protect data.

Real‑life example: GTBank uses secure Wi‑Fi for its branches.

School example: A school uses WPA2 for its network.

Home example: Your parents use a secure Wi‑Fi.

Nigerian example: NITDA promotes wireless security awareness.

Illustration:

  Nigeria + Wireless Security = Safer Connections
  

Mini summary: Nigerian organisations use wireless security to protect data.


Lesson 11: How to test your own Wi‑Fi security

Definition: You can test your own Wi‑Fi security by trying to capture a handshake and cracking it.

Why it matters: It helps you see if your password is strong enough.

Simple explanation: It is like checking if your lock can be picked.

Real‑life example: An ethical hacker tests their own home network.

School example: A student tests the school network (with permission).

Home example: You test your own Wi‑Fi.

Nigerian example: Nigerian businesses test their networks.

Illustration:

  Test Your Wi‑Fi:
  1. Capture handshake
  2. Try to crack it
  3. If cracked → change password
  

Mini summary: Test your own Wi‑Fi to see if it is secure.


Lesson 12: Evil twin – a fake Wi‑Fi network

Definition: An evil twin is a fake Wi‑Fi network that looks like a real one. It tricks users into connecting to it.

Why it matters: Attackers can steal data from users who connect to the fake network.

Simple explanation: It is like a fake shop that looks like a real one but steals your money.

Real‑life example: An attacker sets up a fake network called "Free Wi‑Fi" in a cafe.

School example: A student sets up a fake network (with permission).

Home example: You set up a fake network to test security.

Nigerian example: Ethical hackers test for evil twins.

Illustration:

  Evil Twin:
  Attacker → Fake network → User connects → Data stolen
  

Mini summary: Evil twin attacks use fake networks to steal data.


Lesson 13: How to protect against evil twin attacks

Definition: You can protect against evil twin attacks by using a VPN, verifying the network name, and using HTTPS.

Why it matters: It prevents attackers from stealing your data.

Simple explanation: It is like checking if a store is real before entering.

Real‑life example: A user checks the network name before connecting.

School example: The school educates students about evil twins.

Home example: You use a VPN on public Wi‑Fi.

Nigerian example: NITDA provides tips on avoiding evil twins.

Illustration:

  Protect Against Evil Twins:
  1. Use a VPN
  2. Verify network name
  3. Use HTTPS
  

Mini summary: Use a VPN and verify network names to stay safe.


Lesson 14: The ethics of wireless testing

Definition: Testing wireless networks is only ethical with explicit permission from the owner.

Why it matters: Unauthorised testing is illegal and can cause harm.

Simple explanation: It is like checking if a door is locked – but only if you own the door.

Real‑life example: A company hires an ethical hacker to test its Wi‑Fi.

School example: A teacher gives permission for wireless testing.

Home example: You only test your own network.

Nigerian example: NITDA promotes ethical wireless testing.

Illustration:

  Ethical Testing = Permission + Responsibility
  

Mini summary: Only test networks you have permission to test.


Lesson 15: Bringing it all together – wireless security

Now you understand the basics of wireless security. You know about Wi‑Fi protocols, sniffing, deauthentication attacks, password cracking, and tools like Aircrack‑ng. You also know how to secure a Wi‑Fi network and test it ethically.

Remember: wireless security is essential for protecting data. Use your skills to help others stay safe.

Mini summary: Wireless security protects data travelling through the air.


📖 Key Vocabulary

WordSimple definition
WEPAn old, insecure Wi‑Fi protocol.
WPA2A secure Wi‑Fi protocol.
SniffingCapturing wireless data.
DeauthenticationForcing a user to disconnect.
HandshakeThe password exchange when connecting to Wi‑Fi.
Password CrackingGuessing a password.
WPSA weak Wi‑Fi feature.
Aircrack‑ngA wireless hacking toolkit.
Evil TwinA fake Wi‑Fi network.
VPNA secure connection for privacy.

🧠 Important Concepts

  • WPA2 and WPA3 are the best Wi‑Fi security protocols.
  • WEP is insecure and should not be used.
  • Sniffing captures wireless data.
  • Deauthentication forces users to reconnect, capturing the handshake.
  • WPS is a weak feature – disable it.
  • Aircrack‑ng is a powerful wireless testing toolkit.
  • Always test networks ethically.

🔢 Step‑by‑step: How to test your Wi‑Fi

  1. Install Aircrack‑ng on your computer.
  2. Put your wireless card in monitor mode.
  3. Capture packets using airodump‑ng.
  4. Force a user to reconnect using aireplay‑ng.
  5. Capture the handshake.
  6. Crack the password using aircrack‑ng.
  1. Install → 2. Monitor mode → 3. Capture → 4. Deauth → 5. Handshake → 6. Crack
  

🌍 Real‑life examples

  • Google: Secures its office Wi‑Fi with WPA2.
  • Amazon: Uses wireless security to protect data.
  • Facebook: Uses ethical hackers to test wireless security.

🇳🇬 Nigerian examples

  • GTBank: Uses secure Wi‑Fi for its branches.
  • MTN Nigeria: Secures its Wi‑Fi hotspots.
  • DataBreed: A Nigerian firm that tests wireless security.
  • NITDA: Promotes wireless security awareness.

🎈 Fun examples for children

  • Roblox: Uses secure Wi‑Fi to protect players.
  • Fortnite: Uses wireless security to prevent cheating.
  • YouTube: Uses secure connections to stream videos.

🏠 Everyday examples

  • School: The school uses WPA2 for its network.
  • Home: Your family uses a password‑protected Wi‑Fi.
  • Community: A community centre uses secure Wi‑Fi.

👪 Parent tips

Parents can help children understand wireless security by setting up a secure home network. Show them how to set a strong password and disable WPS.


💡 Interesting facts

  • WEP was introduced in 1997.
  • WPA2 has been around since 2004.
  • Aircrack‑ng was created in 2006.

❓ Did you know?

  • Many public Wi‑Fi networks are not secure.
  • Using a VPN protects you on public Wi‑Fi.
  • Nigeria has a growing community of wireless security experts.

🧷 Remember this

  • WPA2 and WPA3 are the best Wi‑Fi security protocols.
  • WEP is insecure – avoid it.
  • Disable WPS to improve security.
  • Always test networks ethically.

⚠️ Common mistakes

  • Mistake: Using WEP. Correction: Use WPA2 or WPA3.
  • Mistake: Using a weak password. Correction: Use a strong password.
  • Mistake: Leaving WPS enabled. Correction: Disable WPS.

✅ Best practices

  • Use WPA2 or WPA3.
  • Use a strong, unique password.
  • Disable WPS.
  • Use a VPN on public Wi‑Fi.
  • Test your own network to check its security.

📊 Wireless Security Process

  +------------------+
  | 1. Sniff         |  (capture packets)
  +------------------+
          |
          V
  +------------------+
  | 2. Deauth        |  (force reconnect)
  +------------------+
          |
          V
  +------------------+
  | 3. Handshake     |  (capture password exchange)
  +------------------+
          |
          V
  +------------------+
  | 4. Crack         |  (guess the password)
  +------------------+
  

Comparison table: WEP vs WPA2

WEPWPA2
Old and weakModern and secure
Easy to crackHard to crack
Not recommendedRecommended

📝 End‑of‑module summary

In Module 7, we explored wireless security. We learned:

  • WPA2 and WPA3 are the best Wi‑Fi security protocols.
  • WEP is insecure and should not be used.
  • Sniffing captures wireless data.
  • Deauthentication forces users to reconnect, capturing the handshake.
  • WPS is a weak feature – disable it.
  • Aircrack‑ng is a powerful wireless testing toolkit.
  • Always test networks ethically.

You are now ready to move on to the next module, where we will learn about Ethical Hacking in the Cloud.


❓ Frequently Asked Questions (10)

  1. What is wireless security? Protecting Wi‑Fi networks.
  2. What is WPA2? A secure Wi‑Fi protocol.
  3. Why is WEP not secure? It can be cracked easily.
  4. What is sniffing? Capturing wireless data.
  5. What is a deauthentication attack? Forcing a user to disconnect.
  6. What is a handshake? The password exchange on Wi‑Fi.
  7. What is WPS? A weak Wi‑Fi feature.
  8. What is Aircrack‑ng? A wireless hacking toolkit.
  9. How can I secure my Wi‑Fi? Use WPA2, strong password, disable WPS.
  10. Is wireless hacking legal? Only with permission.

🔗 Matching exercise

Match the term to its description.

TermDescription
1. WPA2A. Weak Wi‑Fi feature
2. WPSB. Secure Wi‑Fi protocol
3. SniffingC. Capturing wireless data

Answers: 1-B, 2-A, 3-C


🎭 Scenario‑based exercises

Scenario 1: You are an ethical hacker testing a school's Wi‑Fi. The network uses WEP. What should you do?

Hint: Report that WEP is insecure and recommend WPA2.

Scenario 2: A Nigerian cafe wants to secure its Wi‑Fi. What three recommendations would you give?

Hint: WPA2, strong password, disable WPS.


👥 Group activity

In groups, research the steps to set up a secure Wi‑Fi network at home. Create a checklist and present it to the class.


🧑‍🏫 Individual activity

Write down the steps to capture a handshake using Aircrack‑ng. Explain each step in your own words.


🛠️ Mini project

Create a poster that shows the Wi‑Fi security protocols (WEP, WPA, WPA2, WPA3) with simple explanations. Display it in the classroom.


📋 Practical assignment

Set up a test Wi‑Fi network (with permission) and use Aircrack‑ng to test its security. Write a report on your findings.


🔑 Key takeaways

  • WPA2 and WPA3 are the best Wi‑Fi security protocols.
  • WEP is insecure – avoid it.
  • Disable WPS to improve security.
  • Use a strong password.
  • Always test networks ethically.

🗣️ Classroom discussion questions

  1. Why is WEP not used anymore?
  2. What are the risks of using public Wi‑Fi?
  3. How can a VPN protect you on public Wi‑Fi?
  4. What are the ethical issues of wireless hacking?
  5. How can Nigerian businesses improve their wireless security?

🚀 Preparation for Module 8

In Module 8, we will explore Ethical Hacking in the Cloud. We will learn about cloud computing, common cloud vulnerabilities, and how to secure cloud environments.

To prepare, think about the cloud services you use (like Google Drive or iCloud) and how they are secured.


End of Module 7 · Introduction to Ethical Hacking – Level Two

9

Module Eight

Module 8 · Ethical Hacking Level Two

🛡️ Module 8 · Introduction to Ethical Hacking – Level Two

Ethical Hacking in the Cloud – Securing the Digital Sky


📖 Module Introduction

Welcome back, ethical hackers! In Modules 1–7, we covered reconnaissance, scanning, vulnerability assessment, exploitation, post‑exploitation, web security, and wireless security. Now, in Module 8, we will explore a very modern and important topic: Ethical Hacking in the Cloud.

The cloud is like a giant, digital warehouse where we store files, run applications, and even host websites. Companies like Amazon Web Services (AWS), Microsoft Azure, and Google Cloud provide cloud services. But because the cloud is accessed over the internet, it can be a target for attackers.

In this module, we will learn about cloud computing, common cloud vulnerabilities, and how to secure cloud environments. We will also look at tools like ScoutSuite and Prowler for cloud security testing.

Remember: these skills are for ethical use only. Never test a cloud environment that you do not own or have permission to test.


🎯 Learning Objectives

  • Explain what cloud computing is.
  • Describe the cloud service models (IaaS, PaaS, SaaS).
  • Understand cloud deployment models (public, private, hybrid).
  • Identify common cloud vulnerabilities.
  • Explain misconfigured cloud storage (like open S3 buckets).
  • Use ScoutSuite to assess cloud security.
  • Describe cloud security best practices.
  • Give examples of cloud security in Nigeria.

📚 Warm‑up Story: “The Open Storage Bucket”

Chidi is an ethical hacker working for a Nigerian startup. The startup uses AWS to store customer data. Chidi runs a security scan and finds that a storage bucket (called an S3 bucket) is open to the public – anyone can read the files inside.

He immediately reports this to the CTO. The CTO fixes the setting, making the bucket private. This story shows how easy it is to misconfigure cloud storage and why ethical hackers are needed to find these issues.


📌 Main Lessons

Lesson 1: What is cloud computing?

Definition: Cloud computing is the delivery of computing services (like storage, servers, and software) over the internet.

Why it matters: It allows businesses to scale quickly without buying physical hardware.

Simple explanation: It is like renting a computer or a storage space instead of buying one.

Real‑life example: Using Google Drive to store files is cloud computing.

School example: The school uses Microsoft 365 for email and documents.

Home example: Your family uses iCloud to back up photos.

Nigerian example: Flutterwave uses cloud services to power its payment platform.

Illustration:

  Cloud Computing = Using internet services instead of owning hardware
  

Mini summary: Cloud computing is using internet‑based services for computing needs.


Lesson 2: Cloud service models – IaaS, PaaS, SaaS

Definition: There are three main cloud service models: Infrastructure as a Service (IaaS), Platform as a Service (PaaS), and Software as a Service (SaaS).

Why it matters: Each model has different security responsibilities.

Simple explanation: IaaS gives you a computer; PaaS gives you a computer with tools; SaaS gives you an app.

Real‑life example: AWS EC2 is IaaS, Google App Engine is PaaS, and Gmail is SaaS.

School example: The school uses IaaS for a web server, PaaS for a development platform, and SaaS for email.

Home example: You use SaaS when you use Google Docs.

Nigerian example: Kuda Bank uses IaaS for its servers.

Illustration:

  IaaS (Infrastructure) → PaaS (Platform) → SaaS (Software)
  

Mini summary: IaaS, PaaS, and SaaS are the three cloud service models.


Lesson 3: Cloud deployment models – public, private, hybrid

Definition: Cloud deployment models describe where the cloud is hosted. Public cloud is shared, private cloud is for one organisation, and hybrid is a mix.

Why it matters: The choice affects security and control.

Simple explanation: Public is like a library (shared), private is like your own room, hybrid is a mix.

Real‑life example: AWS is public cloud, a company's own private cloud is private, and a mix is hybrid.

School example: The school uses a public cloud for email and a private cloud for sensitive data.

Home example: You use public cloud for storage.

Nigerian example: GTBank uses a hybrid cloud model.

Illustration:

  Public (shared) → Private (your own) → Hybrid (mix)
  

Mini summary: Public, private, and hybrid are the main cloud deployment models.


Lesson 4: Common cloud vulnerabilities

Definition: Common cloud vulnerabilities include misconfigured storage, weak passwords, and insecure APIs.

Why it matters: These vulnerabilities can lead to data breaches.

Simple explanation: It is like leaving the door to a storage room unlocked.

Real‑life example: An open S3 bucket exposes customer data.

School example: A misconfigured cloud storage exposes student records.

Home example: A weak password on your cloud account.

Nigerian example: Nigerian companies have had open cloud storage incidents.

Illustration:

  Common Cloud Vulnerabilities:
  - Misconfigured storage
  - Weak passwords
  - Insecure APIs
  - Lack of encryption
  

Mini summary: Common cloud vulnerabilities include misconfigurations and weak security.


Lesson 5: Misconfigured cloud storage – open S3 buckets

Definition: An S3 bucket is a storage container in AWS. A misconfigured bucket is one that is open to the public, allowing anyone to read or even write files.

Why it matters: It can expose sensitive data like passwords, customer information, and business secrets.

Simple explanation: It is like leaving a filing cabinet open in a public place.

Real‑life example: Many companies have accidentally exposed data in open S3 buckets.

School example: A school's open bucket exposes student data.

Home example: An open cloud storage folder exposes family photos.

Nigerian example: Nigerian startups have had open S3 buckets.

Illustration:

  Open S3 Bucket:
  Attacker → Finds open bucket → Downloads data
  

Mini summary: Misconfigured cloud storage can expose sensitive data.


Lesson 6: Cloud security tools – ScoutSuite

Definition: ScoutSuite is an open‑source tool that scans cloud environments for security misconfigurations.

Why it matters: It helps identify vulnerabilities before attackers find them.

Simple explanation: It is like a security guard that checks all the doors and windows.

Real‑life example: A security team uses ScoutSuite to check AWS accounts.

School example: A school uses ScoutSuite to check its cloud storage.

Home example: You use ScoutSuite to check your own cloud accounts.

Nigerian example: DataBreed uses ScoutSuite in cloud tests.

Illustration:

  ScoutSuite:
  Scan cloud → Report misconfigurations → Fix them
  

Mini summary: ScoutSuite scans cloud environments for security issues.


Lesson 7: Cloud security tools – Prowler

Definition: Prowler is an open‑source tool specifically for AWS that checks for security best practices.

Why it matters: It helps ensure AWS accounts are configured securely.

Simple explanation: It is like a checklist for AWS security.

Real‑life example: A company uses Prowler to audit its AWS setup.

School example: A school uses Prowler to check its AWS accounts.

Home example: You use Prowler to check your own AWS setup.

Nigerian example: Nigerian companies use Prowler for AWS security.

Illustration:

  Prowler:
  Run audit → Get report → Fix issues
  

Mini summary: Prowler audits AWS security best practices.


Lesson 8: Cloud security best practices – the basics

Definition: Cloud security best practices include using strong passwords, enabling multi‑factor authentication (MFA), encrypting data, and regularly reviewing permissions.

Why it matters: They help protect cloud data from attackers.

Simple explanation: It is like locking all the doors and windows of your house.

Real‑life example: A company enables MFA for all cloud accounts.

School example: The school uses MFA for its cloud accounts.

Home example: You enable MFA on your cloud storage.

Nigerian example: Nigerian businesses are adopting MFA.

Illustration:

  Cloud Security Best Practices:
  1. Use MFA
  2. Encrypt data
  3. Review permissions
  4. Use strong passwords
  

Mini summary: MFA, encryption, and permission reviews are key cloud security practices.


Lesson 9: The shared responsibility model

Definition: In the cloud, security is a shared responsibility. The cloud provider secures the infrastructure, and the customer secures their data and applications.

Why it matters: You cannot just rely on the cloud provider – you must also do your part.

Simple explanation: It is like renting an apartment – the building is secure, but you must lock your own door.

Real‑life example: AWS secures the servers, but you must secure your data.

School example: The school secures its data, while the cloud provider secures the servers.

Home example: You secure your files, while the provider secures the servers.

Nigerian example: Nigerian companies understand shared responsibility.

Illustration:

  Shared Responsibility:
  Cloud provider → Secures infrastructure
  Customer → Secures data and apps
  

Mini summary: Security is a shared responsibility – both provider and customer have roles.


Lesson 10: Cloud penetration testing – ethics and rules

Definition: Cloud penetration testing is testing cloud environments for vulnerabilities. It must be done with permission and within the provider's rules.

Why it matters: Unauthorised testing can violate the cloud provider's terms of service.

Simple explanation: It is like asking permission before testing someone else's property.

Real‑life example: A company gets permission from AWS before testing.

School example: A school gets permission from the cloud provider.

Home example: You only test your own cloud accounts.

Nigerian example: DataBreed follows cloud provider rules.

Illustration:

  Cloud Penetration Testing:
  Permission → Test → Report → Fix
  

Mini summary: Always get permission before testing cloud environments.


Lesson 11: Cloud security in Nigeria

Definition: In Nigeria, cloud security is becoming very important. Banks, fintech companies, and government agencies are using the cloud and need to secure it.

Why it matters: Nigeria's digital economy depends on secure cloud services.

Simple explanation: Nigerian organisations use cloud security to protect data.

Real‑life example: Flutterwave uses cloud security to protect payments.

School example: A school uses cloud security to protect student data.

Home example: Your parents use cloud storage with security.

Nigerian example: NITDA promotes cloud security awareness.

Illustration:

  Nigeria + Cloud Security = Safer Digital Economy
  

Mini summary: Nigerian organisations use cloud security to protect data.


Lesson 12: How to protect cloud data

Definition: Protect cloud data by encrypting it, using MFA, limiting access, and monitoring activity.

Why it matters: It prevents unauthorised access.

Simple explanation: It is like putting important documents in a safe.

Real‑life example: A company encrypts all cloud data.

School example: The school encrypts student records.

Home example: You encrypt sensitive files in the cloud.

Nigerian example: Nigerian banks encrypt customer data.

Illustration:

  Protect Cloud Data:
  1. Encrypt data
  2. Use MFA
  3. Limit access
  4. Monitor activity
  

Mini summary: Encryption, MFA, and monitoring protect cloud data.


Lesson 13: The future of cloud security

Definition: Cloud security is evolving. New tools and practices are being developed to keep data safe.

Why it matters: As more data moves to the cloud, security becomes more important.

Simple explanation: It is like a game that keeps adding new levels.

Real‑life example: AI is being used to detect cloud threats.

School example: Schools are adopting new cloud security tools.

Home example: You use new security features in cloud apps.

Nigerian example: NITDA is promoting cloud security innovation.

Illustration:

  Future Cloud Security = AI + Automation + Better tools
  

Mini summary: Cloud security is constantly evolving.


Lesson 14: How to report cloud vulnerabilities

Definition: If you find a vulnerability in a cloud service, report it to the cloud provider or the owner.

Why it matters: This helps fix the issue before attackers find it.

Simple explanation: It is like telling the building manager about a broken lock.

Real‑life example: An ethical hacker reports a vulnerability to AWS.

School example: A student reports a vulnerability to the school's IT team.

Home example: You report a vulnerability to the app developer.

Nigerian example: DataBreed reports vulnerabilities to clients.

Illustration:

  Responsible Disclosure:
  1. Find vulnerability
  2. Report to owner
  3. Give time to fix
  

Mini summary: Report cloud vulnerabilities responsibly.


Lesson 15: Bringing it all together – cloud security

Now you understand the basics of cloud security. You know about cloud service models, common vulnerabilities, and tools like ScoutSuite and Prowler. You also know how to protect cloud data and report vulnerabilities.

Remember: the cloud is a powerful tool, but it must be secured. Use your skills to help keep the cloud safe.

Mini summary: Cloud security is essential for protecting data in the digital sky.


📖 Key Vocabulary

WordSimple definition
Cloud ComputingUsing internet services instead of owning hardware.
IaaSInfrastructure as a Service (e.g., AWS EC2).
PaaSPlatform as a Service (e.g., Google App Engine).
SaaSSoftware as a Service (e.g., Gmail).
S3 BucketA storage container in AWS.
ScoutSuiteA tool for scanning cloud security.
ProwlerA tool for auditing AWS security.
MFAMulti‑Factor Authentication – extra security layer.
Shared ResponsibilitySecurity is shared between provider and customer.

🧠 Important Concepts

  • Cloud computing delivers services over the internet.
  • IaaS, PaaS, and SaaS are the three service models.
  • Public, private, and hybrid are deployment models.
  • Misconfigured cloud storage is a major risk.
  • ScoutSuite and Prowler are cloud security tools.
  • MFA and encryption are essential for cloud security.
  • Security is a shared responsibility.

🔢 Step‑by‑step: How to use ScoutSuite

  1. Install ScoutSuite using pip.
  2. Configure your cloud credentials (AWS, Azure, etc.).
  3. Run ScoutSuite with the scout command.
  4. Wait for the scan to complete.
  5. Review the HTML report.
  6. Fix any misconfigurations found.
  1. Install → 2. Configure → 3. Run → 4. Wait → 5. Review → 6. Fix
  

🌍 Real‑life examples

  • Google: Uses cloud security to protect Gmail and Drive.
  • Amazon: Secures its AWS cloud.
  • Facebook: Uses cloud security to protect data.

🇳🇬 Nigerian examples

  • Flutterwave: Uses cloud security to protect payments.
  • Kuda Bank: Secures its cloud infrastructure.
  • DataBreed: A Nigerian firm that tests cloud security.
  • NITDA: Promotes cloud security awareness.

🎈 Fun examples for children

  • Roblox: Uses cloud security to protect players.
  • Fortnite: Secures its cloud‑based game.
  • YouTube: Uses cloud security for video streaming.

🏠 Everyday examples

  • School: The school uses cloud security for student data.
  • Home: Your family uses cloud security for photos.
  • Community: A community group uses cloud storage with security.

👪 Parent tips

Parents can help children understand cloud security by explaining how cloud storage works and why it needs protection. Show them how to enable MFA on their cloud accounts.


💡 Interesting facts

  • AWS was launched in 2006.
  • ScoutSuite was created by a security researcher.
  • Cloud computing is growing rapidly in Nigeria.

❓ Did you know?

  • Open S3 buckets have exposed billions of records.
  • MFA can prevent most account takeovers.
  • NITDA has a cloud security framework for Nigeria.

🧷 Remember this

  • Cloud computing delivers services over the internet.
  • Misconfigured cloud storage is a major risk.
  • Use MFA and encryption for cloud security.
  • Always test cloud environments with permission.

⚠️ Common mistakes

  • Mistake: Leaving cloud storage open. Correction: Make it private.
  • Mistake: Not using MFA. Correction: Enable MFA.
  • Mistake: Not encrypting data. Correction: Encrypt sensitive data.

✅ Best practices

  • Enable MFA on all cloud accounts.
  • Encrypt sensitive data.
  • Review permissions regularly.
  • Use cloud security tools like ScoutSuite.
  • Test cloud environments with permission.

📊 Cloud Security Process

  +------------------+
  | 1. Identify      |  (find cloud resources)
  +------------------+
          |
          V
  +------------------+
  | 2. Scan          |  (use ScoutSuite/Prowler)
  +------------------+
          |
          V
  +------------------+
  | 3. Report        |  (list vulnerabilities)
  +------------------+
          |
          V
  +------------------+
  | 4. Fix           |  (apply fixes)
  +------------------+
  

Comparison table: IaaS vs PaaS vs SaaS

IaaSPaaSSaaS
InfrastructurePlatformSoftware
You manage everythingYou manage appsProvider manages everything
Example: AWS EC2Example: Google App EngineExample: Gmail

📝 End‑of‑module summary

In Module 8, we explored cloud security. We learned:

  • Cloud computing delivers services over the internet.
  • IaaS, PaaS, and SaaS are the service models.
  • Public, private, and hybrid are deployment models.
  • Misconfigured cloud storage is a major risk.
  • ScoutSuite and Prowler are cloud security tools.
  • MFA and encryption are essential for cloud security.
  • Security is a shared responsibility.

You are now ready to move on to the next module, where we will learn about Social Engineering.


❓ Frequently Asked Questions (10)

  1. What is cloud computing? Using internet services instead of owning hardware.
  2. What are the cloud service models? IaaS, PaaS, SaaS.
  3. What is an open S3 bucket? A publicly accessible storage container.
  4. What is ScoutSuite? A tool for scanning cloud security.
  5. What is Prowler? A tool for auditing AWS security.
  6. What is MFA? Multi‑Factor Authentication.
  7. What is the shared responsibility model? Security is shared between provider and customer.
  8. How can I secure my cloud data? Use MFA, encryption, and review permissions.
  9. Is cloud hacking legal? Only with permission.
  10. How is cloud security used in Nigeria? To protect banks, fintech, and government data.

🔗 Matching exercise

Match the term to its description.

TermDescription
1. IaaSA. Software as a Service
2. SaaSB. Infrastructure as a Service
3. MFAC. Multi‑Factor Authentication

Answers: 1-B, 2-A, 3-C


🎭 Scenario‑based exercises

Scenario 1: You are an ethical hacker testing a Nigerian startup's AWS account. You find an open S3 bucket with customer data. What do you do?

Hint: Report it immediately and recommend making it private.

Scenario 2: A company wants to secure its cloud environment. What three best practices would you recommend?

Hint: MFA, encryption, and regular security scans.


👥 Group activity

In groups, research the shared responsibility model for a cloud provider (e.g., AWS). Present the responsibilities of the provider and the customer.


🧑‍🏫 Individual activity

Write down the steps to enable MFA on a cloud account. Explain why MFA is important.


🛠️ Mini project

Create a poster that shows the cloud service models (IaaS, PaaS, SaaS) with examples. Display it in the classroom.


📋 Practical assignment

Set up a free AWS account (with permission) and use ScoutSuite to scan it for misconfigurations. Write a report on your findings.


🔑 Key takeaways

  • Cloud computing delivers services over the internet.
  • Misconfigured cloud storage is a major risk.
  • Use MFA and encryption for cloud security.
  • ScoutSuite and Prowler are useful cloud security tools.
  • Always test cloud environments with permission.

🗣️ Classroom discussion questions

  1. Why is cloud security important?
  2. What are the risks of open cloud storage?
  3. How can MFA protect cloud accounts?
  4. What is the shared responsibility model?
  5. How can Nigerian businesses improve cloud security?

🚀 Preparation for Module 9

In Module 9, we will explore Social Engineering – the art of manipulating people to get information. We will learn about phishing, pretexting, and other psychological tricks.

To prepare, think about a time someone tried to trick you into giving information online.


End of Module 8 · Introduction to Ethical Hacking – Level Two

🏆 Get Certified

🔒

Earn this certificate

Every lesson is already free to read. Sign up, pass the exam, and unlock Practice Tools plus a verified certificate with your name on it — ₦4,000/month.

🎓 Sign Up & Unlock for ₦4,000/month
🛠️ Practice Tools
Hands-on simulators & labs - subscription required.
→
🎯 Internship Tasks
Real-world tasks to build your portfolio - try them free for 7 days, no card required.
→