Advanced Penetration Testing & Red Team Operations – becoming a true cyber professional.
Advanced Level ⏱️ Estimated duration: 12–16 weeks
Welcome to Level Three – the advanced stage of your ethical hacking journey! In this course, you will learn professional-level techniques used by real penetration testers and red teamers. You will move beyond basic hacking and learn how to chain vulnerabilities, bypass advanced defences, and simulate sophisticated cyber attacks .
This course is designed for students who have completed Levels One and Two and are ready to take their skills to the next level. We will cover Active Directory attacks, cloud security, mobile hacking, wireless security, exploit development, and red team operations . You will also learn how to write professional reports and present your findings to executives.
By the end of this course, you will be able to:
Before starting Level Three, you should have:
By the end of this course, you will be able to:
Once upon a time, in a bustling city in Nigeria, there was a detective named Amara. Amara was not an ordinary detective – she was the best in the country. She could solve the most complex cases that left others confused.
One day, a bank in Lagos was robbed. The thieves left no fingerprints, no witnesses, and no evidence – or so they thought. Amara didn't just look for obvious clues. She examined everything – the security cameras' blind spots, the employees' schedules, the bank's digital logs, and even the garbage outside.
She found a tiny piece of information that everyone else had missed. That piece led her to the thieves. She caught them and returned the money.
That is exactly what Level Three ethical hackers do. They don't just look for easy vulnerabilities. They dig deeper, think like attackers, and find weaknesses that others miss. They are the master detectives of the cyber world.
This course is divided into 14 modules, each focusing on a different area of advanced ethical hacking. The modules are based on industry standards, including the Certified Ethical Hacker (CEH) curriculum and advanced penetration testing frameworks .
Welcome to Level Three! This module introduces the advanced mindset. You will learn about the difference between penetration testing and red teaming, the importance of scoping and rules of engagement, and the legal and ethical considerations of advanced testing .
Topics: Red team vs. penetration testing, scoping and engagement, legal frameworks, professional ethics, and reporting fundamentals.
In Level Two, you learned basic reconnaissance. Now we go deeper. You will learn advanced OSINT techniques, how to gather information from social media, public databases, and even the dark web .
Topics: Advanced OSINT, social media intelligence, Google Dorking, Shodan, Maltego, Recon-ng, and automated reconnaissance.
You already know SQL injection and XSS. Now you will learn advanced techniques like SSRF (Server-Side Request Forgery), XXE (XML External Entity attacks), insecure deserialisation, and business logic flaws .
Topics: SSRF, XXE, insecure deserialisation, business logic flaws, API security, JWT attacks, and OAuth vulnerabilities .
SQL injection is one of the most dangerous attacks. In this module, you will learn advanced SQL injection techniques and how to evade detection .
Topics: Advanced SQLi, blind SQLi, out-of-band SQLi, and evasion techniques.
Modern security systems are smart. Hackers need to evade them. You will learn how to bypass intrusion detection systems (IDS), firewalls, and honeypots .
Topics: IDS/IPS evasion, firewall bypass, packet fragmentation, protocol manipulation, and honeypot detection .
Learn how hackers steal user sessions and launch denial-of-service attacks .
Topics: Session hijacking (application-level and network-level), DoS/DDoS attack techniques, and countermeasures .
Active Directory is used by most large organisations. Hackers love to attack it. You will learn advanced AD attacks, including Kerberoasting, ASREPRoasting, Golden Ticket, and Silver Ticket attacks .
Topics: AD enumeration, Kerberoasting, ASREPRoasting, Golden Ticket, Silver Ticket, DCSync, and lateral movement .
Learn how to exploit Windows and Linux systems at an advanced level. This includes privilege escalation, persistence, and post-exploitation .
Topics: Windows and Linux privilege escalation, persistence mechanisms, UAC bypass, and kernel exploits .
In this module, you will learn advanced wireless hacking techniques, including WPA/WPA2 cracking, WPA3 attacks, and evil twin attacks .
Topics: Wireless reconnaissance, WPA/WPA2/WPA3 attacks, evil twin, rogue access points, and Bluetooth/RFID security .
Mobile devices are everywhere. You will learn how to test Android and iOS apps for vulnerabilities .
Topics: Android security model, iOS security fundamentals, mobile app analysis, rooting and jailbreaking, and API security for mobile .
The Internet of Things (IoT) and Operational Technology (OT) are growing fast. You will learn how to hack smart devices, industrial systems, and critical infrastructure .
Topics: IoT architecture, IoT hacking methodology, OT/SCADA security, and attack countermeasures .
Cloud computing is used by almost every company. You will learn how to assess the security of AWS, Azure, and Google Cloud .
Topics: Cloud concepts, cloud threats, S3 bucket misconfigurations, container security, and serverless security .
This is the most advanced topic. You will learn how to write your own exploits and reverse engineer software .
Topics: Buffer overflows, return-oriented programming (ROP), bypassing modern protections, custom payload development, and using tools like Ghidra and IDA .
You will put everything together in a real-world red team exercise. You will plan, execute, and report on a full-scale security assessment .
Topics: C2 frameworks (Cobalt Strike, Empire), persistence, evasion, physical security testing, and professional reporting .
| Module | Topic | Key Skills |
|---|---|---|
| 1 | Introduction to Advanced Ethical Hacking | Scoping, engagement, legal frameworks |
| 2 | Advanced Reconnaissance and OSINT | OSINT, social media intelligence, Google Dorking |
| 3 | Advanced Web Application Hacking | SSRF, XXE, insecure deserialisation, API hacking |
| 4 | SQL Injection and Evasion | Advanced SQLi, blind SQLi, evasion |
| 5 | Evading IDS, Firewalls, and Honeypots | IDS/IPS bypass, firewall evasion, honeypot detection |
| 6 | Session Hijacking and DoS | Session hijacking, DoS/DDoS attacks |
| 7 | Advanced Active Directory Attacks | Kerberoasting, Golden Ticket, Silver Ticket |
| 8 | Windows and Linux Exploitation | Privilege escalation, persistence, UAC bypass |
| 9 | Wireless Network Hacking | WPA/WPA2/WPA3 cracking, evil twin, Bluetooth |
| 10 | Mobile Application Security | Android/iOS testing, rooting, jailbreaking |
| 11 | IoT and OT Hacking | IoT architecture, OT/SCADA security |
| 12 | Cloud Security | AWS/Azure/GCP, containers, serverless |
| 13 | Exploit Development and Reverse Engineering | Buffer overflows, ROP, Ghidra, IDA |
| 14 | Red Team Operations and Final Project | Cobalt Strike, Empire, professional reporting |
In Level Three, you will use many advanced tools. Here are some of the most important ones :
| Category | Tools |
|---|---|
| Web Testing | Burp Suite Professional, OWASP ZAP, sqlmap, Nikto |
| Network Testing | Nmap, Wireshark, tcpdump, Nessus, OpenVAS |
| Exploitation | Metasploit, PowerShell Empire, Cobalt Strike, Searchsploit |
| Wireless Testing | Aircrack-ng, Kismet, Reaver, Wifite |
| Active Directory | Mimikatz, CrackMapExec, BloodHound, Rubeus |
| Cloud Testing | Pacu (AWS), ScoutSuite, CloudSploit |
| Mobile Testing | MobSF, Frida, Drozer, Burp Suite Mobile Assistant |
| Reverse Engineering | Ghidra, IDA Pro, pwntools, Immunity Debugger |
After completing Level Three, you will be ready to pursue professional certifications. These include :
| Component | Weight | Description |
|---|---|---|
| Module Quizzes | 15% | Short quizzes after each module to test your knowledge. |
| Hands-on Labs | 35% | Practical labs using virtual machines, PortSwigger, and Hack The Box . |
| Midterm Practical Assessment | 20% | A simulated penetration test on a controlled environment. |
| Final Red Team Project | 30% | A full-scope red team exercise with a professional report . |
| Skill Area | Level Two | Level Three |
|---|---|---|
| Web Hacking | Basic SQLi, XSS, CSRF | SSRF, XXE, insecure deserialisation, API hacking |
| Active Directory | Basic AD attacks | Kerberoasting, Golden/Silver Ticket, DCSync |
| Network Security | Basic scanning and sniffing | IDS/IPS evasion, advanced firewall bypass |
| Wireless Security | Basic WPA2 cracking | WPA3 attacks, evil twin, Bluetooth/RFID |
| Cloud Security | Not covered | AWS/Azure/GCP testing, container security |
| Exploit Development | Not covered | Buffer overflows, ROP, custom payloads |
| Reporting | Basic report writing | Professional, risk-prioritised reports and executive briefings |
Start Level Three
|
v
Module 1: Advanced Mindset
|
v
Module 2: Advanced Recon
|
v
Module 3: Advanced Web Hacking
|
v
Module 4: SQL Injection & Evasion
|
v
Module 5: Evading Defences
|
v
Module 6: Session Hijacking & DoS
|
v
Module 7: Active Directory Attacks
|
v
Module 8: Windows/Linux Exploitation
|
v
Module 9: Wireless Hacking
|
v
Module 10: Mobile Security
|
v
Module 11: IoT & OT Hacking
|
v
Module 12: Cloud Security
|
v
Module 13: Exploit Development
|
v
Module 14: Red Team & Final Project
|
v
🎉 You are now a professional ethical hacker! 🎉
After completing Level Three, you will be ready to:
Congratulations – you have completed the Introduction to Ethical Hacking course series! You are now a skilled ethical hacking professional. Keep learning, stay curious, and always use your powers for good. 🎉
🔥 You have completed the entire Ethical Hacking Level Three course outline! 🔥
The Advanced Mindset – thinking like a professional ethical hacker.
Welcome to Level Three! You have made it to the advanced level of ethical hacking. This is where you learn to think and act like a professional.
In Level One, you learned the basics. In Level Two, you learned how to do ethical hacking. Now, in Level Three, you will learn how to be a master.
This module is all about the advanced mindset. What does that mean? It means thinking like a professional – planning carefully, understanding the rules, and always being ethical. It means knowing the difference between penetration testing and red teaming. It means understanding scoping, rules of engagement, and legal frameworks.
Think of it like this: Level One was learning to drive a car. Level Two was driving on the road. Level Three is becoming a professional race car driver. You need to know the track, the rules, the car, and how to push it to the limit – safely.
By the end of this module, you will be able to:
Once upon a time, in a village in Anambra State, there was a carpenter named Chuka. Chuka was a good carpenter – he could build chairs, tables, and doors. His furniture was strong and lasted many years.
But there was another carpenter in the village named Emeka. Emeka was not just a good carpenter – he was a master. His furniture was not just strong; it was beautiful, perfectly made, and lasted forever. People came from far away to buy his furniture.
What made Emeka different? He didn't just know how to cut wood and hammer nails. He understood the wood – the different types, how they behaved, and how to treat them. He planned every project carefully. He knew the tools and when to use each one. He also knew how to communicate with his customers and understand exactly what they wanted.
That's what Level Three is about. You already know the tools and techniques. Now you will learn the mastery – the planning, the understanding, and the professionalism that makes you a true ethical hacking expert.
Definition: The advanced mindset is the way professional ethical hackers think. It includes planning, ethics, communication, and deep understanding.
Why it is important: Without the right mindset, even the best tools are useless. The advanced mindset makes you a true professional.
Simple explanation: It's like being a master chef who knows not just how to cook, but also how to plan a menu, manage a kitchen, and please customers.
Real‑life example: A professional ethical hacker doesn't just run a tool and report the results. They plan the test, think like an attacker, and write a report that helps the client.
School example: A student who just memorises facts is like a beginner. A student who understands how to think, solve problems, and explain ideas is like an advanced learner.
Home example: At home, the advanced mindset is like a parent who not only cleans the house but also organises everything so it stays clean longer.
Nigerian example: A Nigerian ethical hacker with the advanced mindset doesn't just find vulnerabilities. They help the company understand the risks and how to fix them.
Mini summary: The advanced mindset is about thinking like a professional.
Definition: Penetration testing is a focused test to find vulnerabilities. Red teaming is a full-scale attack simulation that tests an organisation's entire security.
Why it is important: Knowing the difference helps you choose the right service for a client.
Simple explanation: Penetration testing is like checking the locks on a door. Red teaming is like hiring a team of robbers to see if they can break into the whole building.
Real‑life example: A bank might hire a penetration tester to check their website. They might hire a red team to test their whole bank – including physical security, employees, and IT systems.
School example: A teacher checking a student's homework is like a penetration test. A whole school inspection is like a red team exercise.
Home example: Checking if your front door is locked is a penetration test. Hiring someone to try to break into your house in every way is a red team.
Nigerian example: A Nigerian company might hire a red team to test their entire security – including their offices in Lagos, their employees, and their cloud systems.
Definition: Scoping is the process of defining exactly what will be tested and what will not be tested.
Why it is important: Without clear scoping, the tester might accidentally break something important or miss something critical.
Simple explanation: It's like drawing a map of what you will explore and what you will leave alone.
Real‑life example: A pentester might scope a test to only include the company's website and not their internal network.
School example: A teacher might say, "For this test, you only need to study chapters 1 to 5." That is scoping.
Home example: You might say, "For this cleaning, I will only clean the living room and kitchen, not the bedrooms." That is scoping.
Nigerian example: A Nigerian fintech company might scope a test to only include their mobile app and API, not their internal servers.
Mini summary: Scoping defines the boundaries of the test.
Definition: Rules of engagement are the rules that the ethical hacker must follow during the test.
Why it is important: Rules of engagement protect both the tester and the client. They make sure everything is legal and safe.
Simple explanation: It's like the rules of a game – they tell you what you can and cannot do.
Real‑life example: A rule of engagement might say, "Do not test during business hours" or "Do not delete any files."
School example: In a school sports game, the rules say, "No pushing" and "Stay on the field." That is a rule of engagement.
Home example: When you play a board game, the rule book tells you what to do and what not to do. That is a rule of engagement.
Nigerian example: A Nigerian company might have rules of engagement that say, "Only test the website, not the internal network" and "Do not use social engineering."
Definition: Legal frameworks are the laws that govern ethical hacking. Ethics are the moral rules that guide your behaviour.
Why it is important: Ethical hackers must follow the law and be ethical. If they don't, they could go to jail or harm people.
Simple explanation: It's like knowing the rules of the road before you drive a car.
Real‑life example: The Cybercrimes Act in Nigeria makes it illegal to hack without permission.
School example: Your school has rules about not cheating. That is an ethical rule.
Home example: Your family has rules about telling the truth. That is an ethical rule.
Nigerian example: The Nigerian Data Protection Regulation (NDPR) protects people's data. Ethical hackers must follow it.
Mini summary: Always follow the law and be ethical.
Definition: Professional reporting is the process of writing a clear, complete report of your findings.
Why it is important: If you don't write a good report, the client won't know what to fix.
Simple explanation: It's like a doctor writing a prescription – you need to tell the patient exactly what medicine to take.
Real‑life example: A penetration testing report includes an executive summary, findings, risk assessment, and recommendations.
School example: Writing a book report is like writing a security report – you need to explain what you found and why it matters.
Home example: If you find a leak in the roof, you write a note for your parents explaining where it is and how to fix it.
Nigerian example: A Nigerian bank needs a clear report to understand its security risks and fix them.
Definition: Understanding the client's business means knowing what they do, what is important to them, and what risks they face.
Why it is important: You need to understand what matters to the client to give them useful advice.
Simple explanation: It's like a doctor understanding your lifestyle before giving you health advice.
Real‑life example: A hospital needs to protect patient records. A bank needs to protect money. Each has different priorities.
School example: A school needs to protect student grades. A shop needs to protect customer information.
Home example: Your family values privacy. A business might value money more. Different things are important.
Nigerian example: A Nigerian company might value customer trust and government regulations.
Definition: Communication skills are the ability to explain complex ideas in a way that others understand.
Why it is important: You need to explain your findings to people who may not know anything about hacking.
Simple explanation: It's like being a translator who speaks both "hacker" and "normal person" languages.
Real‑life example: An ethical hacker explains a vulnerability to a CEO without using technical jargon.
School example: A student explains a math problem to a friend who doesn't understand it.
Home example: You explain to your parents why a new security measure is important.
Nigerian example: An ethical hacker in Nigeria explains risks to a business owner in simple language.
Definition: Continuous learning means always learning new things because cybersecurity changes every day.
Why it is important: New vulnerabilities are discovered every day. You need to keep learning to stay effective.
Simple explanation: It's like a doctor who reads new medical research every week.
Real‑life example: An ethical hacker spends time every week reading about new vulnerabilities and tools.
School example: A student who studies every day, not just before exams.
Home example: Your parents learn how to use new technology to stay safe online.
Nigerian example: A Nigerian ethical hacker joins online communities and attends conferences to learn.
At Level Three, the ethical hacker becomes a trusted advisor. They don't just find vulnerabilities – they help the organisation understand its risks and improve its security over time.
| Word | Simple meaning |
|---|---|
| Penetration testing | A focused test to find vulnerabilities. |
| Red teaming | A full-scale attack simulation. |
| Scoping | Defining what will be tested. |
| Rules of engagement | The rules for the test. |
| Legal framework | Laws that govern ethical hacking. |
| Ethics | Moral rules that guide behaviour. |
| Professional reporting | Writing clear, complete reports. |
| Communication skills | Explaining ideas clearly. |
| Continuous learning | Always learning new things. |
| Trusted advisor | A professional who gives wise advice. |
1. Banking: A bank in London hires a red team to test their entire security. The red team uses social engineering, physical access, and network attacks to find weaknesses.
2. Healthcare: A hospital hires a penetration tester to check their patient portal. The tester finds a vulnerability and helps the hospital fix it.
Use the master carpenter story to introduce the advanced mindset. Emphasise that Level Three is about becoming a professional. Encourage students to think about the ethical and legal rules of ethical hacking.
The Professional Ethical Hacking Process
Scope ----> Rules of Engagement ----> Get Permission
| |
v v
Perform Test <---- Analyse Results <---- Write Report
| |
v v
Present Findings ----> Recommend Fixes ----> Follow Up
Penetration Testing vs Red Teaming
Penetration Testing: Focused, targeted, specific
Red Teaming: Full-scale, all-encompassing, realistic
| Penetration Testing | Red Teaming |
|---|---|
| Focused test | Full-scale simulation |
| Finds vulnerabilities | Tests entire security |
| Short duration | Longer duration |
| Less expensive | More expensive |
| For specific systems | For whole organisation |
| Beginner Mindset | Advanced Mindset |
|---|---|
| Focused on tools | Focused on understanding |
| Finds vulnerabilities | Understands business impact |
| Writes basic reports | Writes professional reports |
| Follows instructions | Thinks creatively |
| Learns from courses | Learns continuously |
In Module One of Level Three, we learned about the advanced mindset – the way professional ethical hackers think. We explored the difference between penetration testing and red teaming, the importance of scoping and rules of engagement, and the legal and ethical rules of ethical hacking. We also learned about professional reporting, communication skills, and continuous learning. Remember, the advanced mindset is what separates a good ethical hacker from a great one.
| Term | Match with |
|---|---|
| 1. Penetration testing | A. Full-scale simulation |
| 2. Red teaming | B. Focused test |
| 3. Scoping | C. Rules for the test |
| 4. Rules of engagement | D. Defining what will be tested |
| 5. Professional reporting | E. Writing clear reports |
Answers: 1-B, 2-A, 3-D, 4-C, 5-E
Scenario: You are an ethical hacker hired by a school in Lagos. The school wants you to test their security. How would you approach this? What would you include in the scope and rules of engagement?
In groups of 4, create a sample scope and rules of engagement for a fictional company. Include what will be tested, what will not be tested, and the rules for the test.
Write a short essay on why the advanced mindset is important for ethical hackers.
Project: Create a professional report template for a penetration test. Include sections for executive summary, findings, risk assessment, and recommendations.
Research the Nigerian Cybercrimes Act. Write a short summary of what it says about hacking and cyber security.
Research how red teaming is used in the military. Write a one-page explanation and describe how it applies to cybersecurity.
In Module Two, we will learn about advanced reconnaissance and OSINT. We will explore how to gather information from social media, public databases, and even the dark web. Make sure you understand the advanced mindset from this module.
🔥 You have completed Module One of Level Three! Keep up the great work. 🔥
Advanced Reconnaissance and OSINT – gathering information like a professional spy.
Welcome to Module Two! In this module, we will learn about advanced reconnaissance and OSINT (Open Source Intelligence). This is the art of gathering information about a target using publicly available sources.
Think of it like being a detective. Before you solve a case, you need to gather clues. OSINT is how ethical hackers gather clues without touching the target's systems. It's like watching a person from a distance before you talk to them.
In Level Two, you learned basic reconnaissance. Now, in Level Three, we go much deeper. We will learn about social media intelligence, Google Dorking, Shodan, Maltego, and Recon-ng. By the end of this module, you will be able to gather information like a professional spy.
By the end of this module, you will be able to:
Once upon a time, in Lagos, there was a journalist named Ngozi. She was known for writing amazing stories that uncovered secrets. But she didn't just ask people questions – she was a master at gathering information.
When Ngozi wanted to write about a new company, she would spend days just watching. She would read their website, check their social media, look at their employees' LinkedIn profiles, and even check what people were saying about them online. She would put all this information together to get a complete picture.
That's exactly what advanced OSINT is – gathering information from many different sources to build a complete picture of your target. Ethical hackers do this to find vulnerabilities and help protect organisations.
Definition: OSINT stands for Open Source Intelligence. It is information that is publicly available and can be used for intelligence gathering.
Why it is important: OSINT helps ethical hackers understand their target before they start testing. This makes the testing more effective.
Simple explanation: It's like reading a book about a country before you visit it.
Real‑life example: A hacker might use OSINT to find an employee's email address to send a phishing email.
School example: A student might look at a teacher's social media to learn about their hobbies.
Home example: A parent might look up a babysitter online to check their background.
Nigerian example: A Nigerian company might use OSINT to check what is being said about them online.
Mini summary: OSINT is gathering information from public sources.
Definition: SOCMINT is OSINT from social media platforms like Facebook, Twitter, LinkedIn, and Instagram.
Why it is important: People share a lot of information on social media. This can be used to understand people and organisations.
Simple explanation: It's like watching what people post on social media to learn about them.
Real‑life example: An ethical hacker might look at a company's LinkedIn page to find employee names.
School example: A student might check a teacher's Facebook page to learn about their interests.
Home example: A parent might check a neighbour's Instagram to see what they like to do.
Nigerian example: A Nigerian business might check social media to see what customers are saying about them.
Mini summary: SOCMINT is OSINT from social media.
Definition: Google Dorking is using special search terms to find hidden information on Google.
Why it is important: Google Dorking can find information that is not normally visible, like passwords or sensitive files.
Simple explanation: It's like using a secret code to find hidden treasure.
Real‑life example: A hacker might use Google Dorking to find a company's internal documents.
School example: A student might use Google Dorking to find old exam papers.
Home example: A family member might use Google Dorking to find their own information that is accidentally online.
Nigerian example: A Nigerian ethical hacker might use Google Dorking to find sensitive information about a company.
Mini summary: Google Dorking is a special way to search Google.
Definition: Shodan is a search engine that finds internet-connected devices like cameras, servers, and routers.
Why it is important: Shodan can find devices that are not properly secured.
Simple explanation: It's like Google for devices instead of websites.
Real‑life example: A hacker might use Shodan to find a security camera that has no password.
School example: A student might use Shodan to find a school server that is open to the internet.
Home example: A parent might use Shodan to check if their home security camera is visible.
Nigerian example: A Nigerian ethical hacker might use Shodan to find exposed devices in a company.
Mini summary: Shodan finds internet-connected devices.
Definition: Maltego is a tool that shows connections between people, organisations, and websites.
Why it is important: Maltego helps you understand relationships and find hidden connections.
Simple explanation: It's like a detective's corkboard with pins and strings showing who knows who.
Real‑life example: A hacker might use Maltego to find a connection between a company and a competitor.
School example: A student might use Maltego to find connections between different teachers.
Home example: A parent might use Maltego to find connections between different people in their neighbourhood.
Nigerian example: A Nigerian journalist might use Maltego to investigate a company's connections.
Mini summary: Maltego shows connections between things.
Definition: Recon-ng is a tool that automates the process of gathering OSINT information.
Why it is important: Recon-ng makes OSINT faster and more efficient.
Simple explanation: It's like a robot that does your detective work for you.
Real‑life example: An ethical hacker might use Recon-ng to gather information about a company in minutes.
School example: A student might use Recon-ng to gather information about a school project.
Home example: A parent might use Recon-ng to check what information is available about their family.
Nigerian example: A Nigerian ethical hacker might use Recon-ng to test a company's information exposure.
Mini summary: Recon-ng automates OSINT.
Definition: The dark web is part of the internet that is not indexed by regular search engines. It requires special software to access.
Why it is important: Hackers sometimes use the dark web to share information. Ethical hackers need to understand it.
Simple explanation: It's like a secret part of the internet that you can't find with Google.
Corporate OSINT is gathering information about a company. This includes checking their website, financial reports, and public records.
Personal OSINT is gathering information about individuals. This includes checking social media, public records, and other sources.
The OSINT Framework is a collection of tools and resources for OSINT. It helps you find the right tool for the job.
OSINT is legal, but it must be used ethically. You should never use OSINT to harm someone or invade their privacy.
Just as you can gather information, others can gather information about you. You should protect your own information.
Google Dorking has many advanced operators. You can find specific file types, search within websites, and much more.
Social media is one of the richest sources of OSINT. You can find photos, locations, friends, and much more.
Ethical hackers use OSINT to find vulnerabilities and help organisations protect themselves.
| Word | Simple meaning |
|---|---|
| OSINT | Information from public sources. |
| SOCMINT | OSINT from social media. |
| Google Dorking | Using special searches to find hidden info. |
| Shodan | A search engine for devices. |
| Maltego | A tool that shows connections. |
| Recon-ng | A tool that automates OSINT. |
| Dark web | A secret part of the internet. |
| Corporate OSINT | Gathering info about a company. |
| Personal OSINT | Gathering info about a person. |
| Ethical OSINT | Using OSINT legally and morally. |
1. Corporate Espionage: A competitor might use OSINT to learn about a company's new product.
2. Journalists: Journalists use OSINT to investigate stories and find sources.
Use the curious journalist story to introduce OSINT. Emphasise that OSINT is legal and ethical. Encourage students to think about how much information is available about them online.
The OSINT Process
Identify Target
|
v
Choose Sources (social media, Google, Shodan)
|
v
Gather Information
|
v
Analyse Information
|
v
Use Information for Investigation
Types of OSINT
OSINT
|
+-- Social Media (SOCMINT)
+-- Search Engines (Google Dorking)
+-- Device Search (Shodan)
+-- Connections (Maltego)
+-- Automated (Recon-ng)
Google Dorking Example
Search: filetype:pdf "password" site:example.com
This finds PDF files on example.com that contain the word "password".
| Shodan | |
|---|---|
| Finds websites | Finds devices |
| Finds web pages | Finds servers, cameras, routers |
| Used by everyone | Used by security professionals |
| Maltego | Recon-ng |
|---|---|
| Shows connections visually | Automates data collection |
| Interactive | Command-line based |
| User-friendly | More powerful for large-scale |
In Module Two, we learned about advanced reconnaissance and OSINT. We explored social media intelligence (SOCMINT), Google Dorking, Shodan, Maltego, and Recon-ng. We also learned about the dark web, corporate OSINT, and personal OSINT. Remember, OSINT is a powerful tool that must be used ethically. Always protect your own information and use OSINT to help, not harm.
| Term | Match with |
|---|---|
| 1. OSINT | A. Search engine for devices |
| 2. SOCMINT | B. Information from public sources |
| 3. Google Dorking | C. OSINT from social media |
| 4. Shodan | D. Tool that shows connections |
| 5. Maltego | E. Using special searches |
Answers: 1-B, 2-C, 3-E, 4-A, 5-D
Scenario: You are an ethical hacker hired by a school in Abuja. You want to find out what information is publicly available about the school. What OSINT techniques would you use?
In groups of 4, use Google Dorking to find information about a fictional company. Document what you find and how you found it.
Write a short essay on why OSINT is important for ethical hackers.
Project: Create a guide on how to protect personal information from OSINT. Include tips on privacy settings and what not to share.
Search your own name online. Write a report on what you find and suggest ways to protect your information.
Research how Maltego works. Write a one-page explanation and give an example of how it can be used for OSINT.
In Module Three, we will learn about advanced web application hacking. We will explore SSRF, XXE, insecure deserialisation, and API security. Make sure you understand the OSINT concepts from this module.
🔥 You have completed Module Two of Level Three! Keep up the great work. 🔥
Advanced Web Application Hacking – mastering the hidden dangers of the web.
Welcome to Module Three! In this module, we will learn about advanced web application hacking. You already know about SQL injection and XSS from Level Two. Now we will go much deeper.
Think of a website like a house. In Level Two, you learned how to check if the doors and windows are locked. Now, in Level Three, you will learn how to check the walls, the foundation, and even the plumbing – things that most people don't even think about.
We will explore SSRF (Server-Side Request Forgery), XXE (XML External Entity attacks), insecure deserialisation, business logic flaws, and API security. By the end of this module, you will be able to find vulnerabilities that most hackers miss.
By the end of this module, you will be able to:
Once upon a time, in a school in Lagos, there was a secret club. To join the club, you needed an invitation from a member. But one clever student named Tunde found a way to get in without an invitation.
Tunde noticed that the club's website had a form where you could enter your name. He typed something special into the form – not his name, but a command that told the server to give him access. The server did exactly what he said, and Tunde got into the club.
That is exactly what SSRF (Server-Side Request Forgery) is – tricking a server into doing something it shouldn't. In this module, we will learn how these attacks work and how to stop them.
Definition: SSRF is an attack where a hacker tricks a server into making requests to other servers or internal systems.
Why it is important: SSRF can allow hackers to access internal systems that are not normally visible from the internet.
Simple explanation: It's like tricking a security guard into opening a door for you by pretending to be someone you're not.
Real‑life example: A hacker might use SSRF to access a company's internal database.
School example: A student might use SSRF to access the teacher's private files on the school server.
Home example: A family member might use SSRF to access the router's settings from outside the house.
Nigerian example: A Nigerian hacker might use SSRF to access a bank's internal systems.
Mini summary: SSRF tricks a server into making requests it shouldn't.
A hacker finds a website feature that takes a URL as input. The hacker changes the URL to point to an internal system. The server makes the request and returns the response to the hacker.
Definition: XXE is an attack that exploits how XML parsers process external entities. Hackers can use it to read files or make requests.
Why it is important: XXE can allow hackers to read sensitive files on the server.
Simple explanation: It's like putting a secret code in a form that makes the server give you its secrets.
Real‑life example: A hacker might use XXE to read a password file on a server.
School example: A student might use XXE to read the teacher's notes.
Home example: A family member might use XXE to read private documents on a home server.
Nigerian example: A Nigerian company might be vulnerable to XXE, allowing hackers to read customer data.
Mini summary: XXE exploits XML parsers to read files.
A hacker uploads an XML file with a malicious external entity. The XML parser processes the entity and returns sensitive information.
Definition: Insecure deserialisation is when a program takes data from an untrusted source and turns it back into an object, without checking if it's safe.
Why it is important: Hackers can use it to run malicious code on the server.
Simple explanation: It's like opening a package without checking who sent it – it could be a bomb.
Real‑life example: A hacker might send a malicious serialised object to a server to gain control.
School example: A student might send a malicious file to the school server to access the network.
Home example: A hacker might send a malicious file to a family's computer to install malware.
Nigerian example: A Nigerian company might be vulnerable to insecure deserialisation.
Mini summary: Insecure deserialisation allows hackers to run code.
A hacker creates a malicious serialised object and sends it to a server. The server deserialises it and runs the malicious code.
Definition: Business logic flaws are weaknesses in how a website's rules are implemented. Hackers can exploit them to do things they shouldn't.
Why it is important: Business logic flaws can allow hackers to cheat, steal, or break things.
Simple explanation: It's like finding a loophole in a game's rules that lets you win unfairly.
Real‑life example: A hacker might exploit a business logic flaw to get free products from an online store.
School example: A student might exploit a flaw to change their grades.
Home example: A family member might exploit a flaw to get free access to a service.
Nigerian example: A Nigerian e‑commerce site might have a business logic flaw.
Mini summary: Business logic flaws are weaknesses in website rules.
Definition: APIs are how websites talk to each other. API security is about protecting these communications.
Why it is important: If an API is not secure, hackers can access sensitive data.
Simple explanation: It's like protecting the telephone line between two buildings.
Definition: JWT (JSON Web Tokens) are used for authentication. Hackers can attack them by stealing or modifying them.
Simple explanation: It's like stealing someone's ID card.
OAuth is used to allow login with Google or Facebook. Hackers can exploit misconfigurations to steal tokens.
GraphQL is a new way to build APIs. Hackers can exploit it through injections and excessive requests.
Ethical hackers find and report these vulnerabilities before bad hackers can exploit them.
| Word | Simple meaning |
|---|---|
| SSRF | Tricking a server into making requests. |
| XXE | Exploiting XML parsers to read files. |
| Insecure deserialisation | Turning unsafe data into objects. |
| Business logic flaw | A weakness in website rules. |
| API | A way for websites to talk to each other. |
| JWT | A token used for authentication. |
| OAuth | A way to login with Google or Facebook. |
| GraphQL | A newer way to build APIs. |
| Serialisation | Turning an object into data. |
| Deserialisation | Turning data back into an object. |
1. Cloud Services: Hackers use SSRF to access metadata services on AWS and Azure.
2. Payment Systems: Hackers exploit business logic flaws to steal money.
Use the invisible invitation story to introduce SSRF. Emphasise that these are advanced attacks that require deep understanding. Encourage students to think about how they can protect web applications.
SSRF Attack Flow
Hacker sends URL ----> Server makes request
| |
v v
Internal system <---- Response returned
XXE Attack Flow
Hacker uploads XML ----> XML parser processes
| |
v v
External entity <---- Sensitive data returned
Insecure Deserialisation
Hacker sends object ----> Server deserialises
| |
v v
Malicious code <---- Server compromised
| SSRF | XXE |
|---|---|
| Tricks server into making requests | Exploits XML parsers |
| Can access internal systems | Can read files |
| Uses URLs | Uses XML |
| Level Two | Level Three |
|---|---|
| SQL injection | SSRF, XXE |
| XSS | Insecure deserialisation |
| CSRF | Business logic flaws |
| Basic web testing | API security |
In Module Three, we learned about advanced web application hacking. We explored SSRF, XXE, insecure deserialisation, business logic flaws, and API security. These are the types of vulnerabilities that professional ethical hackers look for. Remember, web security is complex, but with the right knowledge, we can protect ourselves and our organisations.
| Term | Match with |
|---|---|
| 1. SSRF | A. Exploits XML parsers |
| 2. XXE | B. Tricking a server into making requests |
| 3. Insecure deserialisation | C. Weakness in website rules |
| 4. Business logic flaw | D. Turning unsafe data into objects |
| 5. API | E. Way for websites to talk |
Answers: 1-B, 2-A, 3-D, 4-C, 5-E
Scenario: You are an ethical hacker hired by a bank in Lagos. The bank's website has a feature that takes a URL input. You suspect it might be vulnerable to SSRF. What would you do?
In groups of 4, create a poster that explains SSRF, XXE, and insecure deserialisation. Include examples and how to protect against them.
Write a short essay on why web application security is important for Nigerian businesses.
Project: Create a security checklist for a web application. Include items for SSRF, XXE, deserialisation, and API security.
Research a real-world SSRF or XXE attack. Write a short report on what happened and how it could have been prevented.
Research how to protect against insecure deserialisation in Java or Python. Write a one-page explanation.
In Module Four, we will learn about SQL injection and evasion techniques. We will explore advanced SQL injection, blind SQLi, and how to evade detection. Make sure you understand the web security concepts from this module.
🔥 You have completed Module Three of Level Three! Keep up the great work. 🔥
Advanced SQL Injection & Evasion Techniques – becoming a master of database attacks.
Welcome to Module Four! In this module, we will learn about advanced SQL injection and evasion techniques. You already learned the basics of SQL injection in Level Two. Now we will go much deeper.
Think of SQL injection like a magic key that opens a door. In Level Two, you learned how to use the key. Now, in Level Three, you will learn how to make the key work even when there are locks, guards, and alarms.
We will explore blind SQL injection, out-of-band SQL injection, and many evasion techniques that hackers use to bypass security filters. By the end of this module, you will be able to find and exploit SQL injection vulnerabilities that most hackers miss.
By the end of this module, you will be able to:
Once upon a time, in a school in Ibadan, there was a secret library that only teachers could enter. The library had a guard at the door. Students were not allowed inside.
One clever student named Chidi really wanted to see what was inside. He couldn't just walk in – the guard would stop him. So he found another way. He noticed that the library had a book return slot. He slipped a note through the slot that said, "Teacher Chidi needs to enter." The guard read the note and opened the door.
That is exactly what blind SQL injection is – you can't see the result directly, but you can use other clues to find what you need. In this module, we will learn how to use these "clues" to perform advanced SQL injection attacks.
Definition: Advanced SQL injection is the use of sophisticated techniques to exploit SQL injection vulnerabilities, even when security measures are in place.
Why it is important: Many websites have basic SQL injection protection. Advanced techniques help you bypass them.
Simple explanation: It's like using a special tool to pick a lock instead of just a regular key.
Real‑life example: A hacker uses advanced SQLi to bypass a web application firewall.
School example: A student uses advanced techniques to access the teacher's grade book.
Home example: A family member uses advanced SQLi to access a home server.
Nigerian example: A Nigerian bank might be attacked with advanced SQLi techniques.
Mini summary: Advanced SQLi bypasses security measures.
Definition: Blind SQL injection is when you don't see the results directly. You use other clues like error messages or time delays.
Why it is important: Many websites don't show errors. Blind SQLi helps you find vulnerabilities anyway.
Simple explanation: It's like trying to find out if a door is locked by listening for a sound.
In error-based blind SQLi, you use error messages to gather information. If the website returns an error, you know the query worked.
In time-based blind SQLi, you use time delays to gather information. If the response takes longer, you know the query worked.
Real‑life example: A hacker sends a query with a 10-second delay. If the response takes 10 seconds, they know it worked.
In boolean-based blind SQLi, you use true/false questions. If the website responds differently to true and false, you know the answer.
Definition: Out-of-band SQL injection is when you use a different channel to get the results, like a DNS request.
Why it is important: Out-of-band SQLi works even when the website doesn't show errors.
Simple explanation: It's like sending a message in a secret code that only you can read.
Evasion techniques help you bypass security filters. Here are some common ones:
sqlmap is a tool that automates SQL injection. In Level Three, you will learn advanced features like:
WAFs are designed to block SQL injection. Hackers use techniques like:
Different databases (MySQL, PostgreSQL, Oracle, SQL Server) have different syntax. You need to know the differences.
Second-order SQL injection is when the attack is stored and executed later. It's harder to find and exploit.
Ethical hackers find SQL injection vulnerabilities and help organisations fix them.
| Word | Simple meaning |
|---|---|
| Blind SQLi | SQL injection without visible results. |
| Error-based SQLi | Using error messages to gather info. |
| Time-based SQLi | Using time delays to gather info. |
| Boolean-based SQLi | Using true/false questions. |
| Out-of-band SQLi | Using a different channel for results. |
| Evasion | Bypassing security filters. |
| sqlmap | A tool that automates SQL injection. |
| WAF | Web Application Firewall. |
| Parameterised query | A safe way to write SQL. |
| Obfuscation | Making something harder to understand. |
1. E-commerce: Hackers use blind SQLi to steal customer data.
2. Government: Hackers use advanced SQLi to access classified information.
Use the secret library story to introduce blind SQLi. Emphasise that advanced SQLi requires patience and skill. Encourage students to think about how they can protect their own databases.
Blind SQLi Process
Send query ----> Observe response
| |
v v
If response matches ----> Gather information
|
v
Repeat for each piece of data
Time-Based Blind SQLi
Send query with delay ----> Wait for response
| |
v v
If delayed ----> Query succeeded ----> Gather info
Evasion Techniques
Encoding ----> URL encode, hex encode
Comments ----> Hide parts of query
Case variation ----> Change uppercase/lowercase
Spacing ----> Use tabs, newlines
Alternate syntax ----> Different ways to write
| Type | How it works | Difficulty |
|---|---|---|
| Error-based | Uses error messages | Easy |
| Time-based | Uses time delays | Medium |
| Boolean-based | Uses true/false | Medium |
| Out-of-band | Uses different channel | Hard |
| Level Two | Level Three |
|---|---|
| Basic SQLi | Advanced SQLi |
| Union-based | Blind SQLi |
| Error-based | Out-of-band SQLi |
| Simple evasion | Advanced evasion |
In Module Four, we learned about advanced SQL injection and evasion techniques. We explored blind SQL injection, time-based, boolean-based, and out-of-band attacks. We also learned about evasion techniques and how to use sqlmap for advanced testing. Remember, SQL injection is one of the most dangerous vulnerabilities. By understanding it, we can better protect our systems.
| Term | Match with |
|---|---|
| 1. Blind SQLi | A. Uses time delays |
| 2. Time-based | B. Without visible results |
| 3. Boolean-based | C. Uses true/false |
| 4. Out-of-band | D. Uses different channel |
| 5. sqlmap | E. Automates SQLi |
Answers: 1-B, 2-A, 3-C, 4-D, 5-E
Scenario: You are an ethical hacker hired by a bank in Abuja. The bank's website has a login form. You suspect it might be vulnerable to SQL injection. However, the website shows no errors. How would you test for blind SQL injection?
In groups of 4, create a poster that explains the different types of blind SQL injection. Include examples and how to test for each.
Write a short essay on why SQL injection is still a major threat to Nigerian businesses.
Project: Create a guide on how to prevent SQL injection. Include examples of parameterised queries and input validation.
Research a real-world SQL injection attack. Write a short report on what happened and how it could have been prevented.
Research how sqlmap works. Write a one-page explanation and describe how it can be used for ethical testing.
In Module Five, we will learn about evading IDS, firewalls, and honeypots. We will explore how hackers bypass these security systems and how to protect against them. Make sure you understand the SQL injection concepts from this module.
🔥 You have completed Module Four of Level Three! Keep up the great work. 🔥
Evading IDS, Firewalls, and Honeypots – becoming invisible to security systems.
Welcome to Module Five! In this module, we will learn about evading IDS, firewalls, and honeypots. These are the security systems that protect networks. Hackers need to bypass them to carry out attacks.
Think of it like a game of hide and seek. The IDS (Intrusion Detection System) and firewall are the seekers. The hacker is the hider. We will learn how hackers hide and how defenders can find them.
We will explore fragmentation, protocol manipulation, encryption evasion, and honeypot detection. By the end of this module, you will understand how hackers avoid detection and how to protect against these techniques.
By the end of this module, you will be able to:
Once upon a time, in a village in Oyo State, there was a thief named Bola. He was very good at stealing, but the village had guards everywhere. The guards watched all the entrances.
Bola had a clever idea. He didn't try to go through the main gate. Instead, he found a hole in the fence. He climbed through the hole, stole what he wanted, and climbed back out. The guards never saw him.
That is exactly what evasion is – finding a way to bypass security systems. In this module, we will learn how hackers find the "holes" in security systems and how to patch them.
Definition: An IDS (Intrusion Detection System) watches for suspicious activity. An IPS (Intrusion Prevention System) blocks it. A firewall filters network traffic.
Why they are important: They are the first line of defence against hackers.
Simple explanation: An IDS is like a security camera. An IPS is like a guard who stops intruders. A firewall is like a locked door.
Real‑life example: A company uses an IDS to detect hackers and a firewall to block unwanted traffic.
School example: A school uses a firewall to block bad websites.
Home example: A family uses a firewall on their router.
Nigerian example: A Nigerian bank uses an IPS to block attacks.
Mini summary: IDS watches, IPS blocks, firewalls filter.
Hackers evade security systems to:
Definition: Fragmentation is breaking data into small pieces. Hackers use it to split malicious packets so IDS might not detect them.
Why it is important: Some IDS only look at whole packets. If a hacker splits the packet, the IDS might miss it.
Simple explanation: It's like hiding a message by writing one word on each of 10 different pieces of paper.
Real‑life example: A hacker splits a malicious payload into many small packets.
School example: A student sends a message in parts to avoid the teacher seeing it.
Home example: A family member sends a file in parts to avoid detection.
Nigerian example: A Nigerian hacker uses fragmentation to bypass a bank's IDS.
Mini summary: Fragmentation splits data to avoid detection.
Hackers split their attack into many small packets. The IDS might not see the full picture until it's too late.
Definition: Protocol manipulation is changing how data is sent to avoid detection. For example, using a different port or header.
Simple explanation: It's like using a secret knock instead of a doorbell.
Real‑life example: A hacker uses port 80 (for web traffic) to send malicious data.
Definition: Hackers use encryption to hide their malicious data. Since the data is scrambled, security systems can't read it.
Why it is dangerous: Encryption is good for privacy, but hackers use it to hide their attacks.
Simple explanation: It's like speaking in a secret code that the guards don't understand.
Definition: IP spoofing is faking the source IP address to hide the hacker's real location.
Simple explanation: It's like wearing a mask so the security cameras don't recognise you.
Hackers use multiple proxies to hide their real location. Each proxy adds another layer of hiding.
Definition: A honeypot is a fake system designed to trap hackers. It looks real but is actually monitored.
Why it is important: Honeypots help catch hackers and learn their techniques.
Simple explanation: It's like leaving a fake treasure chest to catch a thief.
Real‑life example: A company sets up a honeypot to catch hackers.
School example: A school sets up a fake student portal to catch cheaters.
Home example: A family sets up a fake network to catch hackers.
Nigerian example: A Nigerian bank uses honeypots to catch cybercriminals.
Mini summary: Honeypots are traps for hackers.
Hackers try to detect honeypots by looking for signs like unusual network behaviour or fake data.
Ethical hackers use evasion techniques to test security systems. They help find weaknesses and fix them.
| Word | Simple meaning |
|---|---|
| IDS | Intrusion Detection System – watches for attacks. |
| IPS | Intrusion Prevention System – blocks attacks. |
| Firewall | A system that filters network traffic. |
| Fragmentation | Splitting data into small pieces. |
| Protocol manipulation | Changing how data is sent. |
| Encryption evasion | Using encryption to hide attacks. |
| IP spoofing | Faking the source IP address. |
| Proxy chaining | Using multiple proxies to hide location. |
| Honeypot | A trap for hackers. |
| Deep packet inspection | Checking the contents of packets. |
1. Banking: Hackers use fragmentation to bypass a bank's IDS.
2. Government: Hackers use encryption evasion to hide their activities.
Use the invisible thief story to introduce evasion. Emphasise that ethical hackers use these techniques to test security. Encourage students to think about how they can protect their own systems.
Evasion Techniques Overview
Hacker Attack
|
v
Evasion Techniques
(fragmentation, encryption, spoofing)
|
v
Security Systems
(IDS, IPS, Firewall)
|
v
Detected or Evaded?
Fragmentation Attack
Full Packet ----> Split into fragments
|
v
Send fragments separately ----> IDS misses
|
v
Reassemble at target ----> Attack succeeds
Honeypot Detection
Hacker probes network
|
v
Detects honeypot (unusual behaviour)
|
v
Avoids honeypot
| IDS | IPS |
|---|---|
| Detects attacks | Detects and blocks attacks |
| Passive monitoring | Active prevention |
| Alerts admin | Blocks automatically |
| Technique | How it works |
|---|---|
| Fragmentation | Splits data into small pieces |
| Encryption | Scrambles data |
| Protocol Manipulation | Changes how data is sent |
| IP Spoofing | Fakes the source IP |
| Proxy Chaining | Hides location through multiple proxies |
In Module Five, we learned about evading IDS, firewalls, and honeypots. We explored fragmentation, protocol manipulation, encryption evasion, and IP spoofing. We also learned about honeypots and how hackers try to detect them. Remember, the game between attackers and defenders is always changing. By understanding both sides, we can better protect our systems.
| Term | Match with |
|---|---|
| 1. IDS | A. Blocks attacks |
| 2. IPS | B. Watches for attacks |
| 3. Firewall | C. Splitting data |
| 4. Fragmentation | D. Filters traffic |
| 5. Honeypot | E. Trap for hackers |
Answers: 1-B, 2-A, 3-D, 4-C, 5-E
Scenario: You are an ethical hacker hired by a bank in Lagos. You discover that hackers are using fragmentation to bypass the bank's IDS. What would you recommend?
In groups of 4, create a poster that explains evasion techniques and how to stop them. Include examples of fragmentation, encryption, and IP spoofing.
Write a short essay on why defence in depth is important for Nigerian businesses.
Project: Create a security plan that includes countermeasures for evasion techniques. Include IDS/IPS, firewalls, and detection strategies.
Research how a modern IDS/IPS works. Write a short report and include examples of how it detects evasion techniques.
Research how packet fragmentation can be used to evade detection. Write a one-page explanation and describe how to stop it.
In Module Six, we will learn about session hijacking and DoS attacks. We will explore how hackers steal sessions and launch denial-of-service attacks. Make sure you understand the evasion concepts from this module.
🔥 You have completed Module Five of Level Three! Keep up the great work. 🔥
Session Hijacking & DoS Attacks – stealing identities and breaking systems.
Welcome to Module Six! In this module, we will learn about session hijacking and Denial of Service (DoS) attacks. These are attacks that either steal your identity or make websites unavailable.
Think of session hijacking like someone stealing your ID card and pretending to be you. They can do everything you can do – change your password, read your messages, and even spend your money.
Think of DoS attacks like a crowd of people blocking the entrance to a shop. No one else can get in. The shop is not broken – it's just overwhelmed.
We will learn how these attacks work and how to protect against them. By the end of this module, you will understand how to keep your sessions safe and how to prevent DoS attacks.
By the end of this module, you will be able to:
Once upon a time, in a school in Abuja, there was a student named Zainab. She had an ID card that let her access the library, the computer lab, and even the staff room.
One day, a clever student named Emeka wanted to get into the staff room. He couldn't get his own ID card, so he watched Zainab. He noticed that she often left her ID card on her desk. One day, he took it, copied it, and put it back.
Now Emeka could pretend to be Zainab. He could go anywhere she could go. He had stolen her identity. That is exactly what session hijacking is – stealing someone's identity to access their accounts.
Now imagine hundreds of students all trying to enter the computer lab at the same time. The teacher can't open the door because there are too many people. That's a Denial of Service attack – overwhelming a system so it can't work properly.
Definition: Session hijacking is when a hacker steals a user's session ID and pretends to be that user.
Why it is important: Once a hacker hijacks a session, they can do anything the user can do – like checking email, transferring money, or changing passwords.
Simple explanation: It's like someone stealing your ID card and pretending to be you.
Real‑life example: A hacker steals your session token from a banking website and logs in as you.
School example: A student steals another student's login cookie and accesses their grades.
Home example: A family member steals your session on a shopping website and buys things with your account.
Nigerian example: A hacker in Nigeria steals a session token from a bank's website.
Mini summary: Session hijacking steals a user's identity.
When you log into a website, the server gives you a session ID. This ID is like a ticket that proves you are logged in. Every time you make a request, you show your ticket.
Application-level hijacking targets the session ID itself. Hackers steal the session token through:
Network-level hijacking targets the communication between the user and the server. Hackers use:
Definition: Session fixation is when a hacker sets a user's session ID to a known value, then uses that value to log in as the user.
Simple explanation: It's like giving someone a ticket to a show, but keeping a copy of the same ticket.
Definition: Session prediction is when a hacker guesses a valid session ID. If the session IDs are predictable, the hacker can guess them.
Simple explanation: It's like guessing someone's password because it's based on their birthday.
Definition: A DoS attack is when a hacker makes a system unavailable to users.
Why it is dangerous: DoS attacks can stop businesses from working, causing financial losses.
Simple explanation: It's like a crowd blocking the entrance to a shop – no one can get in.
Real‑life example: A hacker sends so many requests to a website that it crashes.
School example: Many students try to access the school portal at the same time, slowing it down.
Home example: A family member downloads a huge file, slowing down the internet for everyone.
Nigerian example: A Nigerian bank's website is attacked with a DoS attack, stopping customers from banking.
Mini summary: DoS attacks make systems unavailable.
Definition: DDoS is a DoS attack that comes from many computers at the same time. Hackers use botnets (networks of infected computers).
Simple explanation: It's like a crowd coming from all directions, blocking every entrance.
A botnet is a network of infected computers that hackers use to launch DDoS attacks. Each computer is called a "bot".
Ethical hackers test for session hijacking and DoS vulnerabilities to help organisations protect themselves.
| Word | Simple meaning |
|---|---|
| Session ID | A ticket that proves you are logged in. |
| Session hijacking | Stealing a user's session ID. |
| Session fixation | Setting a user's session ID to a known value. |
| Session prediction | Guessing a session ID. |
| DoS | Denial of Service – making a system unavailable. |
| DDoS | Distributed DoS from many computers. |
| Botnet | A network of infected computers. |
| SYN Flood | Sending many connection requests. |
| UDP Flood | Sending many UDP packets. |
| HTTP Flood | Sending many HTTP requests. |
1. Banking: A bank's website is hit with a DDoS attack, stopping customers from banking.
2. Gaming: A game server is attacked with a DDoS, making it unplayable.
Use the stolen ID card story to introduce session hijacking. Emphasise the importance of encryption and multi-factor authentication. Encourage students to think about how they can protect their own sessions.
Session Hijacking Attack
User logs in ----> Server issues session ID
| |
v v
Hacker steals session ID ----> Hacker pretends to be user
| |
v v
Hacker accesses user's account
DDoS Attack
Hacker controls botnet
|
v
Sends millions of requests
|
v
Target server overwhelmed
|
v
Legitimate users blocked
SYN Flood Attack
Hacker sends SYN packets
|
v
Server waits for ACK
|
v
Server resources exhausted
|
v
Server crashes
| Session Hijacking | DoS/DDoS |
|---|---|
| Steals user identity | Makes systems unavailable |
| Targets specific user | Targets whole system |
| Requires stealth | Often loud and obvious |
| Used for theft | Used for disruption |
| DoS | DDoS |
|---|---|
| From one computer | From many computers |
| Easier to stop | Harder to stop |
| Less powerful | More powerful |
| Uses one IP address | Uses many IP addresses |
In Module Six, we learned about session hijacking and Denial of Service attacks. We explored how hackers steal session IDs and pretend to be legitimate users. We also learned about DoS and DDoS attacks that overwhelm systems and make them unavailable. Remember, protecting sessions requires encryption, multi-factor authentication, and careful monitoring. Protecting against DoS requires rate limiting, load balancing, and DDoS protection services.
| Term | Match with |
|---|---|
| 1. Session hijacking | A. Making a system unavailable |
| 2. DoS | B. Stealing a session ID |
| 3. DDoS | C. Network of infected computers |
| 4. Botnet | D. DoS from many computers |
| 5. SYN flood | E. Sending many connection requests |
Answers: 1-B, 2-A, 3-D, 4-C, 5-E
Scenario: You are an ethical hacker hired by a bank in Lagos. You discover that the bank's website is vulnerable to session hijacking. What would you recommend?
In groups of 4, create a poster that explains session hijacking and DDoS attacks. Include examples and how to protect against them.
Write a short essay on why session hijacking is a serious threat to Nigerian businesses.
Project: Create a security guide on how to prevent session hijacking. Include tips on using HTTPS, secure cookies, and multi-factor authentication.
Research a real-world DDoS attack. Write a short report on what happened and how it could have been prevented.
Research how HTTPS protects against session hijacking. Write a one-page explanation.
In Module Seven, we will learn about advanced Active Directory attacks. We will explore Kerberoasting, Golden Ticket, Silver Ticket, and DCSync attacks. Make sure you understand the session and DoS concepts from this module.
🔥 You have completed Module Six of Level Three! Keep up the great work. 🔥
Advanced Active Directory Attacks – becoming the king of the network.
Welcome to Module Seven! In this module, we will learn about advanced Active Directory (AD) attacks. Active Directory is like the brain of a company's network. It manages who can access what.
Think of Active Directory like a school's main office. It keeps track of all the students, teachers, and what each person is allowed to do. If a hacker can control the main office, they can control everything.
We will explore Kerberoasting, ASREPRoasting, Golden Ticket, Silver Ticket, and DCSync attacks. By the end of this module, you will understand how hackers take over entire networks and how to protect against them.
By the end of this module, you will be able to:
Once upon a time, in a kingdom in Nigeria, there was a king who ruled over a vast land. The king wore a special crown that proved he was the ruler. Everyone in the kingdom had to obey whoever wore the crown.
One day, a clever thief named Chidi stole the king's crown. He put it on and told everyone, "I am the king now!" Everyone obeyed him. He could do anything he wanted – open any door, take any treasure, and give orders to anyone.
That is exactly what a Golden Ticket attack is – stealing the "crown" of a network (the domain controller) and becoming the ruler of the entire network.
In this module, we will learn how hackers steal these "crowns" and how to protect them.
Definition: Active Directory (AD) is a system that manages users, computers, and permissions in a network.
Why it is important: Most large organisations use Active Directory. If a hacker controls AD, they control the whole network.
Simple explanation: It's like a school's main office that keeps track of all students and teachers.
Real‑life example: A company uses AD to manage employee logins and access to files.
School example: A school uses AD to manage student and teacher accounts.
Home example: A family might use a simpler system to manage users on their home network.
Nigerian example: A Nigerian bank uses AD to manage employee access to customer data.
Mini summary: Active Directory manages users and permissions in a network.
Definition: Kerberos is the authentication system used by Active Directory. It uses tickets to verify users.
Why it is important: Understanding Kerberos is essential for understanding AD attacks.
Simple explanation: It's like a ticket system at a concert – you need a ticket to get in.
When a user logs in, the server gives them a Ticket Granting Ticket (TGT). This TGT is used to get access to specific services.
Definition: Kerberoasting is an attack that steals service account passwords from Active Directory.
Why it is important: Service accounts often have high privileges. If a hacker cracks their password, they can do a lot of damage.
Simple explanation: It's like stealing the keys to the teacher's office.
Real‑life example: A hacker uses Kerberoasting to steal a service account's password and access a company's database.
School example: A student steals a teacher's password and changes their grades.
Home example: A hacker steals a service account password to access a home server.
Nigerian example: A Nigerian company might be attacked with Kerberoasting to steal service account passwords.
Mini summary: Kerberoasting steals service account passwords.
A hacker requests a service ticket for a service account. The ticket is encrypted with the service account's password. The hacker then cracks the password offline.
Definition: ASREPRoasting is an attack that targets users who don't have pre-authentication enabled. Hackers can steal their password hashes and crack them.
Why it is important: ASREPRoasting can be used to crack passwords without triggering alerts.
Simple explanation: It's like finding a door that doesn't require a key and using it to get inside.
Definition: A Golden Ticket attack is when a hacker steals the password hash of the domain controller's KRBTGT account and creates a fake TGT. This allows them to impersonate anyone.
Why it is important: With a Golden Ticket, a hacker can become the "king" of the network – they can do anything.
Simple explanation: It's like stealing the king's crown and becoming the ruler.
Real‑life example: A hacker uses a Golden Ticket to access any system in a company's network.
School example: A student creates a fake admin ticket and accesses the school's entire system.
Home example: A hacker uses a Golden Ticket to control a home network.
Nigerian example: A Nigerian bank might be hit by a Golden Ticket attack, allowing hackers to steal customer data.
Mini summary: Golden Ticket attacks give hackers full control.
Definition: A Silver Ticket attack is similar to a Golden Ticket, but it targets a specific service instead of the whole domain.
Why it is important: Silver Tickets are harder to detect and can be used to access specific resources.
Simple explanation: It's like stealing a key to a specific room instead of the whole building.
Definition: DCSync is an attack that tricks a domain controller into sending password hashes to the hacker, as if they were doing a synchronisation.
Why it is important: DCSync allows hackers to steal all password hashes from Active Directory.
Simple explanation: It's like tricking the main office into giving you a copy of everyone's keys.
Ethical hackers test Active Directory for vulnerabilities and help organisations protect themselves.
| Word | Simple meaning |
|---|---|
| Active Directory | A system that manages users and permissions. |
| Kerberos | The authentication system used by AD. |
| Kerberoasting | Stealing service account passwords. |
| ASREPRoasting | Stealing password hashes without pre-authentication. |
| Golden Ticket | A fake TGT that gives full control. |
| Silver Ticket | A fake ticket for a specific service. |
| DCSync | Tricking a domain controller into giving password hashes. |
| KRBTGT | The master account for the domain. |
| TGT | Ticket Granting Ticket – the first ticket. |
| Mimikatz | A tool for stealing passwords. |
1. Corporate Espionage: Hackers use Golden Tickets to steal trade secrets.
2. Government: Hackers use DCSync to steal government passwords.
Use the king's crown story to introduce Golden Ticket attacks. Emphasise that Active Directory is a critical system that needs strong protection. Encourage students to think about how they would protect their own AD environment.
Kerberoasting Attack
Hacker requests service ticket
|
v
Ticket encrypted with service account password
|
v
Hacker cracks password offline
|
v
Hacker gains service account access
Golden Ticket Attack
Hacker steals KRBTGT hash
|
v
Creates fake TGT (Golden Ticket)
|
v
Authenticates as any user
|
v
Full control over domain
DCSync Attack
Hacker requests replication
|
v
Domain controller sends password hashes
|
v
Hacker steals all passwords
|
v
Hacker gains full access
| Golden Ticket | Silver Ticket |
|---|---|
| Full domain control | Specific service control |
| Uses KRBTGT hash | Uses service account hash |
| Harder to detect | Easier to detect |
| Can impersonate anyone | Can impersonate specific user |
| Kerberoasting | ASREPRoasting |
|---|---|
| Targets service accounts | Targets users without pre-auth |
| Requires service ticket | Requires AS-REQ/AS-REP |
| More common | Less common |
| Can be triggered by any user | Requires specific configuration |
In Module Seven, we learned about advanced Active Directory attacks. We explored Kerberoasting, ASREPRoasting, Golden Ticket, Silver Ticket, and DCSync attacks. These are some of the most dangerous attacks in cybersecurity because they give hackers control over entire networks. Remember, protecting Active Directory requires strong passwords, regular monitoring, and careful management of the KRBTGT account.
| Term | Match with |
|---|---|
| 1. Kerberoasting | A. Fake TGT that gives full control |
| 2. Golden Ticket | B. Stealing service account passwords |
| 3. Silver Ticket | C. Stealing password hashes from AD |
| 4. DCSync | D. Fake ticket for a specific service |
| 5. KRBTGT | E. Master account for the domain |
Answers: 1-B, 2-A, 3-D, 4-C, 5-E
Scenario: You are an ethical hacker hired by a bank in Lagos. The bank's Active Directory has been compromised. You suspect a Golden Ticket attack. What would you do?
In groups of 4, create a poster that explains the different AD attacks and how to protect against them.
Write a short essay on why Active Directory security is important for Nigerian businesses.
Project: Create a security checklist for Active Directory. Include items for Kerberoasting, Golden Ticket, Silver Ticket, and DCSync protection.
Research a real-world Golden Ticket attack. Write a short report on what happened and how it could have been prevented.
Research how BloodHound works. Write a one-page explanation and describe how it can be used for AD security.
In Module Eight, we will learn about Windows and Linux exploitation. We will explore privilege escalation, persistence, and kernel exploits. Make sure you understand the AD concepts from this module.
🔥 You have completed Module Seven of Level Three! Keep up the great work. 🔥
Windows and Linux Exploitation – gaining control and staying inside.
Welcome to Module Eight! In this module, we will learn about Windows and Linux exploitation. This is where hackers take full control of systems and make sure they can stay there.
Think of it like a thief who breaks into a house. First, they need to get inside (that's the initial attack). Then they need to find the master key to open all the doors (privilege escalation). Finally, they need to make sure they can come back anytime (persistence).
We will explore privilege escalation on both Windows and Linux, UAC bypass, kernel exploits, and persistence mechanisms. By the end of this module, you will understand how hackers take over systems and how to stop them.
By the end of this module, you will be able to:
Once upon a time, in a school in Lagos, there was a janitor named Bola. Bola had a master key that could open every door in the school – the classrooms, the staff room, and even the principal's office.
One day, a student named Kunle wanted to get into the staff room. He noticed that Bola often left his keys on the desk. Kunle took the keys, copied them, and put them back. Now Kunle could open any door in the school.
That is exactly what privilege escalation is – getting a master key that gives you access to everything. In this module, we will learn how hackers get these master keys and how to protect them.
Definition: Privilege escalation is when a hacker gains higher access rights than they should have.
Why it is important: Once a hacker becomes an administrator, they can do anything on the system.
Simple explanation: It's like a student getting a teacher's key card.
Real‑life example: A hacker uses a vulnerability to get administrator access on a Windows server.
School example: A student finds a way to access the teacher's grade book.
Home example: A family member gains admin access to the home computer.
Nigerian example: A Nigerian company might be attacked with privilege escalation.
Mini summary: Privilege escalation is gaining higher access rights.
Windows has many ways to escalate privileges, including using UAC bypass or exploiting vulnerabilities in services.
Definition: UAC is a Windows feature that asks for permission before making changes. Hackers bypass it to run malicious code without alerts.
Simple explanation: It's like a security guard who asks for ID, but you trick them into letting you in anyway.
Services on Windows run with high privileges. If a hacker can exploit a service, they can gain high privileges.
Scheduled tasks run automatically. Hackers can exploit misconfigured scheduled tasks to run their code with high privileges.
The Windows registry contains many settings. Hackers can exploit weak permissions on registry keys to escalate privileges.
Linux has its own methods for privilege escalation, like using sudo vulnerabilities or exploiting misconfigured permissions.
Definition: Sudo allows users to run commands as root. If sudo is misconfigured, hackers can exploit it.
Simple explanation: It's like having a key that can open any door if you know the right command.
SUID binaries run with the owner's privileges. If a hacker finds a vulnerable SUID binary, they can escalate privileges.
Definition: Kernel exploits target the core of the operating system. They are very powerful and can give hackers full control.
Why it is dangerous: Kernel exploits work on both Windows and Linux and are often hard to detect.
Simple explanation: It's like breaking the main lock on the building instead of picking individual door locks.
Definition: Persistence is the ability of a hacker to maintain access to a system, even after a restart or password change.
Why it is important: Hackers want to keep access so they can come back later.
Simple explanation: It's like a thief making a copy of your house key so they can come back.
Ethical hackers use these techniques to test systems and find weaknesses. They then report their findings so that the weaknesses can be fixed.
| Word | Simple meaning |
|---|---|
| Privilege escalation | Gaining higher access rights. |
| UAC bypass | Tricking Windows security. |
| Kernel exploit | Attacking the core of the OS. |
| Persistence | Maintaining access to a system. |
| Sudo | A Linux command to run as root. |
| SUID | A Linux file permission. |
| Cron job | A scheduled task on Linux. |
| Registry key | A setting on Windows. |
| Service | A background program. |
| EDR | Endpoint Detection and Response. |
1. Corporate: Hackers use privilege escalation to access sensitive company data.
2. Government: Hackers use kernel exploits to gain control of government systems.
Use the master key story to introduce privilege escalation. Emphasise that ethical hackers use these techniques to test systems. Encourage students to think about how they would protect their own systems.
Privilege Escalation
Low Privileges ----> Find Vulnerability ----> Exploit
| | |
v v v
High Privileges <---- Gain Access <---- Run Malicious Code
Windows Persistence Mechanisms
Scheduled Tasks ----> Run automatically
Registry Keys ----> Run at startup
Services ----> Run as background
Startup Folder ----> Run when user logs in
Linux Persistence Mechanisms
Cron Jobs ----> Run at scheduled times
Startup Scripts ----> Run at boot
SSH Keys ----> Login without password
Systemd Services ----> Run automatically
| Windows | Linux |
|---|---|
| UAC bypass | Sudo exploitation |
| Service exploitation | SUID binaries |
| Scheduled tasks | Cron jobs |
| Registry attacks | File permissions |
| Kernel exploits | Kernel exploits |
| Privilege Escalation | Persistence |
|---|---|
| Gaining higher access | Maintaining access |
| One-time exploit | Ongoing access |
| Gives more power | Gives staying power |
| Often noisy | Often quiet |
In Module Eight, we learned about Windows and Linux exploitation. We explored privilege escalation, UAC bypass, kernel exploits, and persistence mechanisms. These are the techniques that hackers use to take control of systems and stay there. Remember, protecting systems requires regular updates, least privilege, and careful monitoring. By understanding these techniques, we can better protect our systems.
| Term | Match with |
|---|---|
| 1. Privilege escalation | A. Maintaining access |
| 2. Persistence | B. Gaining higher access |
| 3. UAC bypass | C. Linux command to run as root |
| 4. Sudo | D. Tricking Windows security |
| 5. Kernel exploit | E. Attacking the core of the OS |
Answers: 1-B, 2-A, 3-D, 4-C, 5-E
Scenario: You are an ethical hacker hired by a bank in Lagos. The bank's Windows server has been compromised. You suspect privilege escalation. What would you do?
In groups of 4, create a poster that explains privilege escalation and persistence on Windows and Linux. Include examples and how to protect against them.
Write a short essay on why privilege escalation is a serious threat to Nigerian businesses.
Project: Create a security checklist for a Windows or Linux system. Include items for privilege escalation and persistence protection.
Research a real-world privilege escalation attack. Write a short report on what happened and how it could have been prevented.
Research how kernel exploits work. Write a one-page explanation and describe how to protect against them.
In Module Nine, we will learn about wireless network hacking. We will explore WPA/WPA2 cracking, evil twin attacks, and Bluetooth security. Make sure you understand the exploitation concepts from this module.
🔥 You have completed Module Eight of Level Three! Keep up the great work. 🔥
Advanced Wireless Network Hacking – mastering the invisible battlefield.
Welcome to Module Nine! In this module, we will learn about advanced wireless network hacking. Wi-Fi is everywhere – in our homes, schools, offices, and even in the air around us. But Wi-Fi can also be a door that hackers use to break in.
Think of wireless networks like invisible conversations happening in the air. Anyone with the right tools can listen in. Hackers use this to steal passwords, spy on people, and break into networks.
We will explore WPA/WPA2 cracking, WPA3 attacks, evil twin attacks, Bluetooth security, and RFID hacking. By the end of this module, you will understand how to protect wireless networks from advanced attacks.
By the end of this module, you will be able to:
Once upon a time, in a busy market in Lagos, two friends were having a conversation. They were talking about a secret plan. But they didn't realize that a stranger was listening to their conversation from behind a stall.
The stranger heard everything – the time, the place, and the secret code. He used that information to beat them to the treasure.
That is exactly what wireless hacking is – listening to invisible conversations and using that information to break in. In this module, we will learn how these conversations happen, how hackers listen in, and how to stop them.
Definition: Wi-Fi security protects wireless networks from unauthorized access. It uses encryption to scramble data so only the right people can read it.
Why it is important: Without Wi-Fi security, anyone can listen to your conversations and steal your information.
Simple explanation: It's like having a secret code that only you and your friends know.
Real‑life example: A coffee shop uses WPA2 to protect its Wi-Fi network.
School example: A school uses Wi-Fi security to protect student data.
Home example: A family uses a password to protect their home Wi-Fi.
Nigerian example: A Nigerian business uses WPA2 to protect its network.
Mini summary: Wi-Fi security protects wireless networks.
Definition: WEP is an old Wi-Fi security protocol that is very weak. Hackers can crack it in minutes.
Why it is not safe: WEP is broken – it should never be used.
Simple explanation: It's like a lock that can be opened with a paperclip.
Definition: WPA and WPA2 are stronger Wi-Fi security protocols. WPA2 is the most common.
Why they are better: They use stronger encryption and are much harder to crack.
Simple explanation: It's like a lock that requires a special key.
Definition: WPA/WPA2 cracking is the process of stealing the password by capturing the handshake and using brute-force or dictionary attacks.
Why it is important: Understanding how cracking works helps us protect our networks.
Simple explanation: It's like capturing a copy of the key and trying to copy it.
Real‑life example: A hacker captures a handshake and cracks the password using a wordlist.
School example: A student tries to crack the school's Wi-Fi password.
Home example: A neighbour tries to crack your home Wi-Fi password.
Nigerian example: A hacker tries to crack a Nigerian company's Wi-Fi.
Mini summary: WPA/WPA2 cracking steals Wi-Fi passwords.
The four-way handshake is the process that happens when a device connects to a WPA/WPA2 network. Hackers capture this handshake to crack the password.
Definition: WPA3 is the newest Wi-Fi security protocol. It fixes many problems with WPA2.
Why it is better: WPA3 uses stronger encryption and protects against common attacks.
Simple explanation: It's like upgrading from a regular lock to a high-tech electronic lock.
Even WPA3 has some vulnerabilities. Hackers have found ways to attack it, including side-channel attacks and downgrade attacks.
Definition: An evil twin attack is when a hacker creates a fake Wi-Fi network that looks like a real one.
Why it is dangerous: Users connect to the fake network and give away their passwords.
Simple explanation: It's like a fake coffee shop that looks real but steals your money.
Real‑life example: A hacker sets up a fake network called "CoffeeShop_WiFi" to steal passwords.
School example: A student sets up a fake network called "School_WiFi" to steal passwords.
Home example: A neighbour sets up a fake network called "Your_Network" to steal your information.
Nigerian example: A hacker in Lagos uses an evil twin attack at a cybercafé.
Mini summary: Evil twin attacks use fake networks.
Definition: A rogue access point is an unauthorized Wi-Fi device connected to a network. Hackers use them to break in.
A deauthentication attack sends fake deauth packets to disconnect a device from a network. Hackers use this to capture handshakes.
Definition: Bluetooth is a wireless technology used for short-range communication. Hackers can exploit it to steal data.
Why it is important: Bluetooth is used in phones, speakers, and cars. It can be a security risk.
Simple explanation: It's like a secret handshake that can be copied.
Definition: RFID (Radio Frequency Identification) and NFC (Near Field Communication) are used for contactless payments and access cards. Hackers can clone them.
Simple explanation: It's like copying someone's key card.
Ethical hackers test wireless networks for vulnerabilities and help organisations protect themselves.
| Word | Simple meaning |
|---|---|
| WEP | A weak Wi-Fi security protocol. |
| WPA/WPA2 | Wi-Fi security protocols. |
| WPA3 | The newest Wi-Fi security protocol. |
| Handshake | The process of connecting to Wi-Fi. |
| Evil Twin | A fake Wi-Fi network. |
| Rogue Access Point | An unauthorized Wi-Fi device. |
| Deauth attack | An attack that disconnects a device. |
| Bluetooth | A short-range wireless technology. |
| RFID | Radio Frequency Identification. |
| NFC | Near Field Communication. |
1. Coffee Shop: A hacker uses an evil twin attack to steal passwords from customers.
2. Hotel: A hotel's Wi-Fi is hacked, exposing guest information.
Use the invisible conversation story to introduce wireless hacking. Emphasise the importance of strong passwords and encryption. Encourage students to check their own home Wi-Fi settings.
Wi-Fi Security Comparison
WEP ---- Weak (cracked in minutes)
WPA ---- Better but still vulnerable
WPA2 ---- Most common, strong
WPA3 ---- Best, most secure
WPA/WPA2 Cracking Process
Capture Handshake
|
v
Run Dictionary Attack
|
v
Password Found?
|
v
Yes ----> Access Wi-Fi
No ----> Try More
Evil Twin Attack
Hacker sets up fake network
|
v
Victim connects to fake network
|
v
Hacker steals victim's information
| Protocol | Strength | Security Level |
|---|---|---|
| WEP | Very weak | Can be cracked in minutes |
| WPA | Weak | Vulnerable to some attacks |
| WPA2 | Strong | Most common, secure |
| WPA3 | Very strong | Newest, most secure |
| Level Two | Level Three |
|---|---|
| Basic WPA2 cracking | WPA3 attacks, evil twin, Bluetooth |
| Simple deauth attacks | Advanced evasion techniques |
| Basic tools | Advanced tools and custom scripts |
| Focused on Wi-Fi | Includes Bluetooth, RFID, NFC |
In Module Nine, we learned about advanced wireless network hacking. We explored WEP, WPA, WPA2, and WPA3, and learned how hackers crack Wi-Fi passwords. We also learned about evil twin attacks, rogue access points, Bluetooth security, and RFID hacking. Remember, wireless security is essential in today's connected world. By understanding how hackers attack, we can better protect our networks.
| Term | Match with |
|---|---|
| 1. WEP | A. The newest Wi-Fi protocol |
| 2. WPA2 | B. Weak Wi-Fi protocol |
| 3. WPA3 | C. Most common Wi-Fi protocol |
| 4. Evil Twin | D. Fake Wi-Fi network |
| 5. Deauth attack | E. Disconnects a device |
Answers: 1-B, 2-C, 3-A, 4-D, 5-E
Scenario: You are an ethical hacker hired by a school in Abuja. The school uses WEP for their Wi-Fi network. You discover that the password is easily cracked. What would you recommend?
In groups of 4, create a poster that explains how to secure a Wi-Fi network. Include tips on choosing a strong password and using the right security protocol.
Write a short essay on why wireless security is important for Nigerian businesses.
Project: Create a Wi-Fi security checklist for a small business. Include items like using WPA2, disabling WPS, and changing the default SSID.
Use your home Wi-Fi router's settings to check which security protocol it uses. If it's WEP, change it to WPA2. Write a short report on what you found.
Research how WPA3 improves on WPA2. Write a one-page explanation and give examples of its benefits.
In Module Ten, we will learn about mobile application security. We will explore Android and iOS security, rooting and jailbreaking, and mobile app analysis. Make sure you understand the wireless concepts from this module.
🔥 You have completed Module Nine of Level Three! Keep up the great work 🔥
Mobile Application Security – protecting the devices in our pockets.
Welcome to Module Ten! In this module, we will learn about mobile application security. Almost everyone has a smartphone today. We use them for banking, shopping, messaging, and even controlling our homes. But these powerful devices can also be targets for hackers.
Think of your phone like a mini-computer that you carry everywhere. It stores your photos, messages, passwords, and even your location. If a hacker breaks into your phone, they can steal everything.
We will explore Android and iOS security, rooting and jailbreaking, mobile app analysis, and the OWASP Mobile Top 10. By the end of this module, you will understand how to protect mobile devices from attacks.
By the end of this module, you will be able to:
Once upon a time, in a school in Abuja, there was a student named Fatima. She had a super phone that could do everything – take pictures, play games, and even do her homework.
One day, Fatima downloaded a game from a random website. The game looked fun, but it had a hidden secret. It was a malicious app that stole all her contacts and photos. Fatima didn't know until her friends started getting strange messages from her number.
That is exactly what mobile hacking is – using malicious apps to steal information from phones. In this module, we will learn how these attacks work and how to protect ourselves.
Definition: Mobile application security is the protection of mobile devices and the apps on them from attacks.
Why it is important: Mobile devices store a lot of personal information. If they are hacked, your privacy is at risk.
Simple explanation: It's like putting a lock on your phone to keep your secrets safe.
Real‑life example: A bank's mobile app uses encryption to protect your financial data.
School example: A school uses a secure app for students to check their grades.
Home example: A family uses a secure messaging app to share photos.
Nigerian example: A Nigerian fintech company uses mobile security to protect customer data.
Mini summary: Mobile security protects phones and apps.
Definition: Android is an open operating system. It uses a permission system to control what apps can do.
Why it is important: Understanding Android security helps us protect our devices.
Simple explanation: It's like a bouncer who checks your ID before letting you into a club.
Definition: iOS is a closed operating system. It has strict security measures to protect users.
Why it is important: iOS is generally more secure than Android, but it's not perfect.
Simple explanation: It's like a VIP club where only certain people are allowed in.
Definition: Rooting is the process of gaining full control of an Android device. It removes restrictions.
Why it is dangerous: Rooting can make the device more vulnerable to attacks.
Simple explanation: It's like becoming the king of your phone and having all the power.
Real‑life example: A hacker roots a phone to install malicious software.
School example: A student roots their phone to bypass school restrictions.
Home example: A family member roots their phone to install custom software.
Nigerian example: A Nigerian hacker roots a phone to steal data.
Mini summary: Rooting gives full control of Android.
Definition: Jailbreaking is the process of removing restrictions on iOS devices.
Why it is dangerous: Jailbreaking can make the device more vulnerable to attacks.
Simple explanation: It's like breaking out of prison to get more freedom.
The OWASP Mobile Top 10 is a list of the most critical mobile security risks. These include:
Many apps store sensitive data on the device without encryption. Hackers can steal this data.
Weak login methods can allow hackers to access your account.
If an app doesn't use encryption, hackers can intercept the data.
Mobile malware is bad software that infects phones. It can steal data, send messages, or even spy on you.
Static analysis: Looking at the app's code without running it.
Dynamic analysis: Running the app to see what it does.
Ethical hackers test mobile apps for vulnerabilities and help developers fix them.
| Word | Simple meaning |
|---|---|
| Rooting | Gaining full control of Android. |
| Jailbreaking | Removing restrictions on iOS. |
| OWASP Mobile Top 10 | A list of top mobile vulnerabilities. |
| Static analysis | Looking at code without running it. |
| Dynamic analysis | Running the app to test it. |
| MobSF | A mobile app analysis tool. |
| Frida | A dynamic analysis tool. |
| Malware | Bad software that harms devices. |
| Encryption | Scrambling data to protect it. |
| Authentication | Verifying a user's identity. |
1. Banking: A bank's mobile app is tested for security vulnerabilities.
2. Social Media: A social media app is hacked to steal user data.
Use the super phone story to introduce mobile security. Emphasise that mobile devices need protection just like computers. Encourage students to think about the permissions they grant to apps.
Mobile App Analysis Process
Get the app
|
v
Static Analysis (look at code)
|
v
Dynamic Analysis (run the app)
|
v
Check for vulnerabilities
|
v
Report findings
Android Security Model
App requests permission
|
v
User grants or denies
|
v
If granted, app can access
|
v
If denied, app cannot access
OWASP Mobile Top 10
1. Insecure Data Storage
2. Weak Authentication
3. Insecure Communication
4. Poor Code Quality
5. Reverse Engineering
6. Improper Platform Usage
7. Insufficient Cryptography
8. Client-side Injection
9. Security Decisions via Untrusted Inputs
10. Session Handling
| Android | iOS |
|---|---|
| Open system | Closed system |
| More malware | Less malware |
| More customisable | More restrictive |
| Rooting gives full control | Jailbreaking removes restrictions |
| Static Analysis | Dynamic Analysis |
|---|---|
| Without running the app | Running the app |
| Faster | Slower |
| Safer | Requires sandbox |
| Less information | More information |
In Module Ten, we learned about mobile application security. We explored the Android and iOS security models, rooting and jailbreaking, and the OWASP Mobile Top 10. We also learned about mobile app analysis tools and how to protect our devices. Remember, mobile devices are powerful and convenient, but they need proper security. By understanding the risks, we can keep our devices safe.
| Term | Match with |
|---|---|
| 1. Rooting | A. Removing iOS restrictions |
| 2. Jailbreaking | B. Gaining full control of Android |
| 3. OWASP Mobile Top 10 | C. List of mobile vulnerabilities |
| 4. Static analysis | D. Looking at code without running |
| 5. Dynamic analysis | E. Running the app to test it |
Answers: 1-B, 2-A, 3-C, 4-D, 5-E
Scenario: You are an ethical hacker hired by a school in Lagos. The school uses a mobile app for student registration. You suspect it might have vulnerabilities. What would you do?
In groups of 4, create a poster that explains the OWASP Mobile Top 10. Include examples and how to protect against each vulnerability.
Write a short essay on why mobile security is important for Nigerian businesses.
Project: Create a mobile security checklist for a small business. Include items like using official stores, checking permissions, and updating devices.
Research a real-world mobile malware attack. Write a short report on what happened and how it could have been prevented.
Research how MobSF works. Write a one-page explanation and describe how it can be used for ethical testing.
In Module Eleven, we will learn about IoT and OT hacking. We will explore the Internet of Things, smart devices, and industrial control systems. Make sure you understand the mobile security concepts from this module.
🔥 You have completed Module Ten of Level Three! Keep up the great work. 🔥
IoT and OT Hacking – the hidden dangers of smart devices and industrial systems.
Welcome to Module Eleven! In this module, we will learn about IoT (Internet of Things) and OT (Operational Technology) hacking. These are the devices and systems that run our modern world – smart fridges, security cameras, power plants, and factories.
Think of IoT like a world where everything has a brain. Your fridge can tell you when you're out of milk. Your watch can track your heart rate. Your car can drive itself. But these brains can also be hacked.
We will explore IoT architecture, common IoT vulnerabilities, OT/SCADA security, and famous IoT attacks like the Mirai botnet. By the end of this module, you will understand how to protect the smart world around you.
By the end of this module, you will be able to:
Once upon a time, in a modern home in Abuja, there was a family who had a smart fridge. The fridge could tell you when you were out of milk and even order groceries online. It was connected to the internet.
One day, a hacker found a vulnerability in the fridge's software. They used it to get into the family's Wi-Fi network and steal their personal information. The family was shocked – a fridge had helped a hacker break in!
That is exactly what we will learn in this module – how smart devices can be hacked, and how to protect them.
Definition: IoT stands for Internet of Things. It refers to everyday devices that are connected to the internet – like smart fridges, cameras, and thermostats.
Why it is important: IoT devices are everywhere. If they are not secure, hackers can use them to break into networks or cause harm.
Simple explanation: It's like having a toaster that can talk to the internet.
Real‑life example: A smart home has devices that can be controlled from a phone.
School example: A school uses smart cameras for security.
Home example: A family uses a smart thermostat to control the temperature.
Nigerian example: Many Nigerian homes are using smart devices like smart TVs and security cameras.
Mini summary: IoT is everyday devices connected to the internet.
Definition: OT stands for Operational Technology. It refers to the hardware and software used to control industrial systems – like power plants, water treatment plants, and factories.
Why it is important: OT systems control critical infrastructure. If they are hacked, it can cause real-world damage.
Simple explanation: It's like the brains of a factory or power plant.
IoT systems have three layers:
Definition: Default passwords are the passwords that come with a device. Hackers know these passwords and use them to break in.
Why it is dangerous: Many people never change the default password, making it easy for hackers.
Simple explanation: It's like buying a lock that comes with a key that everyone knows.
Real‑life example: A hacker uses the default password "admin" to access a smart camera.
School example: A school forgets to change the default password on its security cameras.
Home example: A family uses the default password on their smart TV.
Nigerian example: Many Nigerian homes use default passwords on their routers and smart devices.
Mini summary: Default passwords are a big security risk.
IoT devices often don't receive security updates. This means known vulnerabilities stay unpatched.
Many IoT devices send data without encryption. Hackers can intercept and read this data.
Definition: SCADA stands for Supervisory Control and Data Acquisition. It is a system used to control industrial processes.
Why it is important: SCADA systems control critical infrastructure like power grids and water treatment plants.
Simple explanation: It's like the control room of a factory.
OT/SCADA systems are often older and less secure than IT systems. They are also harder to update because downtime is not allowed.
Definition: The Mirai botnet was a massive attack in 2016 that used insecure IoT devices to launch a DDoS attack.
Why it is important: The Mirai attack showed how dangerous insecure IoT devices can be.
Simple explanation: It was like an army of smart devices attacking the internet.
Real‑life example: The Mirai attack took down major websites like Twitter and Netflix.
School example: A school's network could be used in a botnet attack.
Home example: A family's smart devices could be part of a botnet without them knowing.
Nigerian example: Nigerian IoT devices could be used in botnet attacks.
Mini summary: The Mirai botnet used insecure IoT devices.
Ethical hackers test IoT and OT systems to find vulnerabilities and help protect them.
| Word | Simple meaning |
|---|---|
| IoT | Everyday devices connected to the internet. |
| OT | Systems that control industrial processes. |
| SCADA | A system for controlling industrial processes. |
| Botnet | A network of infected devices used for attacks. |
| Default password | The password that comes with a device. |
| Encryption | Scrambling data to protect it. |
| Network segmentation | Separating networks for security. |
| Firmware | The software inside a device. |
| Vulnerability | A weakness that can be exploited. |
| DDoS | Distributed Denial of Service attack. |
1. Power Grid: A hacker attacks a power grid's OT system, causing a blackout.
2. Healthcare: A hospital's IoT devices are hacked, disrupting patient care.
Use the smart fridge story to introduce IoT. Emphasise that new technologies bring new risks. Encourage students to think about how they can protect their own devices.
IoT Architecture
Sensors ----> Network ----> Cloud
(devices) (Wi-Fi) (storage)
Mirai Botnet Attack
Hackers scan for IoT devices
|
v
Infect devices with Mirai
|
v
Create botnet
|
v
Launch DDoS attack
|
v
Websites go down
IoT Security Checklist
Change default passwords
Keep devices updated
Use separate network
Disable unused features
Use encryption
| IoT | OT |
|---|---|
| Consumer devices | Industrial systems |
| Smart home | Factory control |
| Easier to secure | Harder to secure |
| Often consumer-grade | Often enterprise-grade |
| Level Two | Level Three |
|---|---|
| Basic IoT vulnerabilities | Advanced IoT attacks |
| Simple device hacking | Botnet creation |
| Basic security | OT/SCADA security |
| Focused on home devices | Includes industrial systems |
In Module Eleven, we learned about IoT and OT hacking. We explored the Internet of Things, smart devices, and industrial control systems. We learned about common vulnerabilities like default passwords and lack of updates, and we studied the Mirai botnet attack. Remember, IoT and OT devices are everywhere, and they need proper security to protect our homes, businesses, and critical infrastructure.
| Term | Match with |
|---|---|
| 1. IoT | A. Industrial control systems |
| 2. OT | B. Everyday devices connected to the internet |
| 3. SCADA | C. Network of infected devices |
| 4. Botnet | D. Password that comes with a device |
| 5. Default password | E. System for controlling industrial processes |
Answers: 1-B, 2-A, 3-E, 4-C, 5-D
Scenario: You are an ethical hacker hired by a factory in Lagos. The factory uses IoT devices and an OT system. You discover that many devices have default passwords and are not updated. What would you recommend?
In groups of 4, create a poster that explains IoT and OT security risks and how to protect against them.
Write a short essay on why IoT security is important for Nigerian homes and businesses.
Project: Create an IoT security checklist for a family. Include items like changing default passwords, using separate networks, and keeping devices updated.
Research a real-world IoT or OT attack. Write a short report on what happened and how it could have been prevented.
Research how SCADA systems work. Write a one-page explanation and describe the security risks.
In Module Twelve, we will learn about cloud security. We will explore AWS, Azure, GCP, and container security. Make sure you understand the IoT and OT concepts from this module.
🔥 You have completed Module Eleven of Level Three! Keep up the great work. 🔥
Cloud Security – protecting data in the sky.
Welcome to Module Twelve! In this module, we will learn about cloud security. Cloud computing is like renting a computer in the sky. Instead of buying your own servers, you use someone else's – like Amazon Web Services (AWS), Microsoft Azure, or Google Cloud Platform (GCP).
Think of the cloud like a storage unit in a big building. You can store your things there, and you can access them from anywhere. But if the building is not secure, your things can be stolen.
We will explore cloud concepts, common cloud threats, S3 bucket misconfigurations, container security, and serverless security. By the end of this module, you will understand how to protect data in the cloud.
By the end of this module, you will be able to:
Once upon a time, in Lagos, a business owner named Chidi wanted to store his important documents. He didn't have space in his office, so he rented a storage unit. He put all his documents there and locked the door.
One day, he forgot to lock the door properly. A thief walked in, took all his documents, and disappeared. Chidi lost everything.
That is exactly what cloud misconfiguration is – leaving the door open for hackers. In this module, we will learn how to lock the door properly and protect our data in the cloud.
Definition: Cloud computing is using the internet to access computing services – like storage, servers, and software – instead of using your own computer.
Why it is important: Many businesses use the cloud. If a cloud service is hacked, it can affect millions of people.
Simple explanation: It's like renting a storage unit for your files instead of keeping them at home.
Real‑life example: Google Drive, Dropbox, and Amazon Web Services (AWS) are cloud services.
School example: A school might use Google Classroom to store student work.
Home example: A family might use iCloud to store photos.
Nigerian example: Many Nigerian businesses use cloud services like AWS and Microsoft Azure.
Mini summary: Cloud computing is using internet-based services.
Definition: The shared responsibility model means that cloud security is shared between the cloud provider and the customer.
Why it is important: The cloud provider secures the cloud, but the customer must secure what they put in the cloud.
Simple explanation: It's like a building – the owner keeps the building safe, but you must lock your own door.
Definition: S3 buckets are storage containers in Amazon Web Services. Sometimes they are left open to the public, allowing anyone to access the data.
Why it is dangerous: S3 buckets can contain sensitive customer data.
Simple explanation: It's like leaving your storage unit door wide open.
Real‑life example: A company accidentally makes their S3 bucket public, exposing customer data.
School example: A school leaves its student data bucket open.
Home example: A family leaves their photo bucket open.
Nigerian example: A Nigerian company might accidentally leave their S3 bucket open.
Mini summary: S3 bucket misconfigurations expose data.
Definition: Containers are lightweight packages that contain everything an app needs to run. They are used in the cloud.
Why it is important: If containers are not secure, hackers can break out of them and access the host system.
Simple explanation: It's like a suitcase that contains everything you need for a trip.
Definition: Serverless computing lets you run code without managing servers. It's like renting a function instead of a server.
Why it is important: Serverless functions can have vulnerabilities like insecure dependencies.
Simple explanation: It's like renting a small tool instead of buying the whole workshop.
Ethical hackers test cloud security and help organisations protect their data.
| Word | Simple meaning |
|---|---|
| Cloud computing | Using internet-based services. |
| S3 bucket | A storage container in the cloud. |
| Misconfiguration | Setting something up incorrectly. |
| Container | A lightweight package for apps. |
| Serverless | Running code without managing servers. |
| IaaS | Infrastructure as a Service. |
| PaaS | Platform as a Service. |
| SaaS | Software as a Service. |
| Encryption | Scrambling data to protect it. |
| Multi-factor authentication | Using two things to log in. |
1. Cloud: A misconfigured cloud server exposed millions of customer records.
2. Containers: A hacker escaped a container and accessed the host system.
Use the storage unit story to introduce cloud security. Emphasise that the cloud is convenient but needs proper security. Encourage students to think about how they can protect their own cloud data.
Cloud Security Risks
Misconfiguration ----> Data Exposure
Weak Passwords ----> Account Hijacking
Insecure APIs ----> Data Breach
Insider Threats ----> Data Theft
S3 Bucket Misconfiguration
Bucket created ----> Made public
|
v
Data exposed ----> Hacker finds it ----> Data stolen
Container Security Checklist
Use trusted images
Keep images updated
Run with least privilege
Scan for vulnerabilities
Isolate containers
| IaaS | PaaS | SaaS |
|---|---|---|
| Rent servers | Rent a platform | Rent software |
| More control | Less control | Least control |
| AWS EC2 | Google App Engine | Gmail |
| Level Two | Level Three |
|---|---|
| Basic cloud concepts | Advanced cloud attacks |
| Simple S3 buckets | Misconfiguration exploitation |
| Basic security | Container and serverless security |
| Focused on basics | Includes advanced tools |
In Module Twelve, we learned about cloud security. We explored cloud computing, the shared responsibility model, and common cloud threats. We learned about S3 bucket misconfigurations, container security, and serverless security. Remember, the cloud is powerful but needs strong security. By understanding the risks, we can protect our data and our organisations.
| Term | Match with |
|---|---|
| 1. IaaS | A. Rent software |
| 2. PaaS | B. Rent servers |
| 3. SaaS | C. Rent a platform |
| 4. S3 bucket | D. Lightweight package for apps |
| 5. Container | E. Storage container in the cloud |
Answers: 1-B, 2-C, 3-A, 4-E, 5-D
Scenario: You are an ethical hacker hired by a school in Lagos. The school uses cloud storage for student records. You discover that the S3 bucket is public. What would you recommend?
In groups of 4, create a poster that explains cloud security risks and how to protect against them. Include S3 buckets, containers, and serverless.
Write a short essay on why cloud security is important for Nigerian businesses.
Project: Create a cloud security checklist for a small business. Include items like securing S3 buckets, using encryption, and enabling MFA.
Research a real-world cloud data breach. Write a short report on what happened and how it could have been prevented.
Research how Pacu works. Write a one-page explanation and describe how it can be used for ethical testing.
In Module Thirteen, we will learn about exploit development and reverse engineering. We will explore buffer overflows, ROP, and custom payload development. Make sure you understand the cloud security concepts from this module.
🔥 You have completed Module Twelve of Level Three! Keep up the great work. 🔥
Exploit Development and Reverse Engineering – building your own weapons.
Welcome to Module Thirteen! This is the most advanced module in Level Three. We will learn about exploit development and reverse engineering – the art of building your own hacking tools.
Think of it like being a master craftsman. Instead of buying tools from a shop, you build your own. You understand how every tool works, and you can customise it for any situation.
We will explore buffer overflows, return-oriented programming (ROP), bypassing modern protections, and custom payload development. We will also learn about Ghidra and IDA – tools for reverse engineering. By the end of this module, you will understand how exploits are built and how to protect against them.
By the end of this module, you will be able to:
Once upon a time, in a village in Oyo State, there was a master locksmith named Tunde. Tunde could open any lock in the world. But he didn't use magic – he understood how locks worked.
Tunde would look at a lock and see how it was made. He would find the weak points and create a key that could open it. He built his own tools from scratch.
That is exactly what exploit development is – understanding how software works, finding the weak points, and building your own tools to exploit them. In this module, we will learn how to become master locksmiths of the digital world.
Definition: Exploit development is the process of creating code that takes advantage of a vulnerability.
Why it is important: Understanding exploit development helps us create better defences.
Simple explanation: It's like building a special key to open a specific lock.
Real‑life example: A security researcher creates an exploit for a Windows vulnerability.
School example: A student writes a program to bypass a school's website filter.
Home example: A family member writes a script to automate a task.
Nigerian example: A Nigerian security researcher develops exploits to test local systems.
Mini summary: Exploit development is creating code to exploit vulnerabilities.
Definition: Reverse engineering is the process of taking something apart to understand how it works.
Why it is important: Reverse engineering helps us understand malware and find vulnerabilities.
Simple explanation: It's like taking apart a clock to see how the gears work.
Definition: A buffer overflow is when a program writes data beyond the end of a buffer (a temporary storage area). This can overwrite important data and let hackers run their own code.
Why it is dangerous: Buffer overflows are one of the oldest and most dangerous vulnerabilities.
Simple explanation: It's like pouring more water into a glass than it can hold – the water spills out.
Real‑life example: The Morris worm used a buffer overflow to spread in 1988.
School example: A student sends a very long input to a program that crashes it.
Home example: A program crashes when you type too many characters.
Nigerian example: A Nigerian company might have buffer overflow vulnerabilities in old software.
Mini summary: Buffer overflows overwrite memory and can run code.
A program allocates a buffer of a certain size. If a hacker sends more data than the buffer can hold, the extra data overwrites the return address. When the function returns, it jumps to the hacker's code.
Modern systems have protections to stop exploits:
Definition: ROP is an advanced technique that chains together small pieces of existing code (called "gadgets") to bypass protections.
Why it is important: ROP bypasses DEP because it uses existing code.
Simple explanation: It's like using Lego blocks – you can build anything using existing pieces.
Real‑life example: Hackers use ROP to bypass DEP and execute code.
School example: A student uses existing code snippets to create a new program.
Home example: You use existing ingredients to make a new recipe.
Nigerian example: Nigerian researchers use ROP to test security.
Mini summary: ROP chains together existing code pieces.
Hackers can bypass ASLR by leaking memory addresses through other vulnerabilities.
Stack canaries can be bypassed by reading them through other vulnerabilities or by overwriting them without detection.
Definition: A payload is the code that runs after an exploit succeeds. Custom payloads are tailored for specific targets.
Simple explanation: It's like choosing the right tool for the job.
Ghidra is a powerful tool for reverse engineering. You can use it to analyse binaries and understand how they work.
IDA Pro is the industry standard for reverse engineering. It is used by security researchers worldwide.
Ethical hackers use exploit development and reverse engineering to find vulnerabilities and help protect systems.
| Word | Simple meaning |
|---|---|
| Buffer overflow | Writing more data than a buffer can hold. |
| ROP | Return-Oriented Programming – chaining code pieces. |
| ASLR | Randomising memory addresses. |
| DEP | Preventing code execution in some memory. |
| Stack canary | A special value that detects overflows. |
| Payload | The code that runs after an exploit. |
| Ghidra | A free reverse engineering tool. |
| IDA Pro | A commercial reverse engineering tool. |
| Reverse engineering | Taking something apart to understand it. |
| Exploit | Code that takes advantage of a vulnerability. |
1. Heartbleed: A bug in OpenSSL that allowed hackers to steal data.
2. Shellshock: A vulnerability in Bash that allowed remote code execution.
Use the master locksmith story to introduce exploit development. Emphasise that this is advanced material and requires patience. Encourage students to practice in controlled environments.
Buffer Overflow
Normal: [buffer][return address]
Overflow: [buffer][hacker's code][return address]
(overwritten)
ROP Attack
Gadget 1 ----> Gadget 2 ----> Gadget 3 ----> Shellcode
(pop) (mov) (jmp) (exec)
Exploit Development Process
Find Vulnerability
|
v
Develop Exploit
|
v
Test in Sandbox
|
v
Refine Exploit
|
v
Deploy Ethically
| Ghidra | IDA Pro |
|---|---|
| Free | Commercial (paid) |
| Open source | Closed source |
| Good for beginners | Industry standard |
| Slower | Faster |
| Created by NSA | Created by Hex-Rays |
| Buffer Overflow | ROP |
|---|---|
| Overwrites memory | Chains existing code |
| Can be blocked by DEP | Bypasses DEP |
| Older technique | Modern technique |
| Easier to execute | More complex |
In Module Thirteen, we learned about exploit development and reverse engineering. We explored buffer overflows, return-oriented programming (ROP), and modern protections like ASLR and DEP. We also learned about tools like Ghidra and IDA Pro. Remember, exploit development is a powerful skill that must be used ethically. By understanding how exploits work, we can better protect our systems.
| Term | Match with |
|---|---|
| 1. Buffer overflow | A. Chaining existing code |
| 2. ROP | B. Randomising memory addresses |
| 3. ASLR | C. Writing more data than a buffer can hold |
| 4. DEP | D. Free reverse engineering tool |
| 5. Ghidra | E. Preventing code execution |
Answers: 1-C, 2-A, 3-B, 4-E, 5-D
Scenario: You are an ethical hacker hired by a bank in Lagos. The bank uses an old application that might have buffer overflow vulnerabilities. What would you do?
In groups of 4, create a poster that explains buffer overflows and how to protect against them.
Write a short essay on why exploit development is important for cybersecurity.
Project: Create a guide on how to prevent buffer overflows. Include tips on using modern protections and code reviews.
Research a real-world buffer overflow attack. Write a short report on what happened and how it could have been prevented.
Research how ROP works. Write a one-page explanation and describe how it can be used for ethical testing.
In Module Fourteen, we will learn about red team operations and the final project. We will bring everything together in a real-world exercise. Make sure you understand the exploit concepts from this module.
🔥 You have completed Module Thirteen of Level Three! Keep up the great work. 🔥
Red Team Operations and Final Project – becoming a true cyber professional.
Welcome to Module Fourteen – the final module of Level Three! In this module, we will learn about red team operations and you will complete your final project.
Think of a red team like a group of actors who pretend to be the bad guys. They try to break into a company's systems – but they do it with permission. Their job is to find weaknesses before the real bad guys do.
We will explore Command and Control (C2) frameworks like Cobalt Strike and Empire, persistence, evasion, physical security testing, and professional reporting. Then you will put everything you've learned into practice with a full-scale red team exercise.
By the end of this module, you will be able to:
Once upon a time, in a big company in Lagos, the security team wanted to test their defences. They hired a group of ethical hackers to pretend to be the bad guys. This group was called the red team.
The red team had one week to break into the company's systems. They used social engineering, physical security tricks, and advanced hacking techniques. At the end of the week, they had found 15 vulnerabilities that the security team didn't know about.
The company fixed all the vulnerabilities and became much safer. The red team had done their job – they had helped protect the company.
That is exactly what we will learn in this module – how to be a red team and help organisations improve their security.
Definition: Red teaming is a full-scale attack simulation that tests an organisation's entire security – people, processes, and technology.
Why it is important: Red teaming finds weaknesses that penetration testing might miss.
Simple explanation: It's like a fire drill for cybersecurity.
Real‑life example: A bank hires a red team to test their security.
School example: A school has a lockdown drill – that's like a red team exercise.
Home example: A family practices what to do in a fire – that's like a red team drill.
Nigerian example: A Nigerian company hires a red team to test its security.
Mini summary: Red teaming tests an organisation's entire security.
Penetration testing focuses on finding vulnerabilities. Red teaming focuses on simulating a real attack, including evasion and persistence.
Definition: C2 frameworks are tools that help hackers control compromised systems remotely.
Why it is important: C2 frameworks are used by both hackers and red teams.
Simple explanation: It's like a remote control for computers.
Definition: Cobalt Strike is a popular C2 framework used by red teams and hackers. It simulates advanced attacks.
Why it is important: Cobalt Strike is the industry standard for red teaming.
Simple explanation: It's like a Swiss army knife for hackers.
Real‑life example: A red team uses Cobalt Strike to test a company's defences.
School example: A student uses a tool to simulate attacks in a lab.
Home example: A family member uses a tool to test their home network.
Nigerian example: A Nigerian red team uses Cobalt Strike for testing.
Mini summary: Cobalt Strike is a powerful C2 framework.
Definition: Empire is a C2 framework that uses PowerShell on Windows systems.
Why it is important: Empire is powerful and can evade detection.
Simple explanation: It's like a tool that controls Windows computers remotely.
Red teams need to maintain access to systems. They use persistence mechanisms like scheduled tasks, registry keys, and cron jobs.
Red teams must evade detection. They use techniques like encryption, obfuscation, and protocol manipulation.
Definition: Physical security testing is when red teams try to physically enter a building to test security.
Why it is important: Many security breaches happen through physical access.
Simple explanation: It's like a movie where spies break into a building.
Real‑life example: A red team tries to enter a company's office without a badge.
School example: A student tests whether they can enter the staff room.
Home example: A family member tests if the front door lock is strong.
Nigerian example: A Nigerian red team tests physical security.
Mini summary: Physical security testing checks physical barriers.
Red teams use social engineering to trick employees into giving information.
Red teams write professional reports that explain their findings and how to fix them.
Ethical hackers form the red team. They help organisations find and fix weaknesses.
The final project is a full-scale red team exercise. You will plan, execute, and report on a simulated attack.
| Word | Simple meaning |
|---|---|
| Red team | A group that simulates attacks. |
| C2 | Command and Control – a system to control compromised computers. |
| Cobalt Strike | A popular C2 framework. |
| Empire | A PowerShell C2 framework. |
| Persistence | Maintaining access to a system. |
| Evasion | Avoiding detection. |
| Physical security | Protecting buildings and physical assets. |
| Social engineering | Tricking people to get information. |
| Reporting | Documenting findings. |
| Frameworks | Tools and methods used in red teaming. |
1. Government: Red teams test government systems for vulnerabilities.
2. Banking: Banks use red teams to test their security.
Use the security drill story to introduce red teaming. Emphasise that red teaming is about helping organisations improve. Encourage students to think about how they would approach a red team exercise.
The Red Team Process
Plan ----> Recon ----> Attack ----> Maintain ----> Evade ----> Report
Red Team vs Penetration Testing
Penetration Testing: Focused, short, finds vulnerabilities
Red Teaming: Full-scale, long, simulates real attacks
Final Project Overview
Scope ----> Recon ----> Exploit ----> Persistence ----> Report
| Red Team | Penetration Testing |
|---|---|
| Full-scale simulation | Focused test |
| Tests people, processes, technology | Tests technology |
| Longer duration | Shorter duration |
| More realistic | Less realistic |
| Cobalt Strike | Empire |
|---|---|
| Commercial (paid) | Free and open-source |
| More features | PowerShell focused |
| Industry standard | Popular for Windows |
| More advanced | Easier to use |
In Module Fourteen, we learned about red team operations and the final project. We explored C2 frameworks like Cobalt Strike and Empire, persistence, evasion, physical security testing, and professional reporting. Remember, red teaming is about helping organisations improve their security. By simulating real attacks, we can find weaknesses before the bad guys do.
| Term | Match with |
|---|---|
| 1. Red team | A. PowerShell C2 framework |
| 2. Cobalt Strike | B. Simulates attacks |
| 3. Empire | C. Maintaining access |
| 4. Persistence | D. Popular C2 framework |
| 5. Evasion | E. Avoiding detection |
Answers: 1-B, 2-D, 3-A, 4-C, 5-E
Scenario: You are the leader of a red team hired by a bank in Lagos. The bank wants you to test their entire security. How would you approach this?
In groups of 4, create a red team plan for a fictional company. Include scope, reconnaissance, attack techniques, and reporting.
Write a short essay on why red teaming is important for Nigerian businesses.
Project: Create a red team report template. Include sections for executive summary, findings, risk assessment, and recommendations.
Research a real-world red team engagement. Write a short report on what happened and how it helped the organisation.
Research how Cobalt Strike works. Write a one-page explanation and describe how it can be used for ethical testing.
Congratulations! You have completed all the modules of Level Three. Now it's time for your final project – a full-scale red team exercise.
You will need to:
Your instructor will provide you with a test environment and specific instructions. Good luck!
🎉 You have completed the Introduction to Ethical Hacking Level Three course! You are now a skilled ethical hacking professional. Keep learning, stay curious, and always use your powers for good. 🎉