← Fundamentals of Ethical Hacking Level Three · Lesson 11 of 15

Module Ten

📖 Every lesson in this course is free to read right here, no account needed. Create a free account to track your progress, take the exam, and earn your certificate.
1

Course Outline

Level Three · Ethical Hacking Course Outline

🔥 Course Outline · Introduction to Ethical Hacking Level Three

Advanced Penetration Testing & Red Team Operations – becoming a true cyber professional.

Advanced Level ⏱️ Estimated duration: 12–16 weeks

📖 Course Description

Welcome to Level Three – the advanced stage of your ethical hacking journey! In this course, you will learn professional-level techniques used by real penetration testers and red teamers. You will move beyond basic hacking and learn how to chain vulnerabilities, bypass advanced defences, and simulate sophisticated cyber attacks .

This course is designed for students who have completed Levels One and Two and are ready to take their skills to the next level. We will cover Active Directory attacks, cloud security, mobile hacking, wireless security, exploit development, and red team operations . You will also learn how to write professional reports and present your findings to executives.

By the end of this course, you will be able to:

  • Conduct full-scope penetration tests on enterprise networks .
  • Exploit Windows, Linux, and Active Directory environments .
  • Test web applications, APIs, and cloud infrastructure .
  • Perform wireless, mobile, and IoT security assessments .
  • Develop custom exploits and bypass modern protections .
  • Produce professional, risk-prioritized reports .

📌 Prerequisites

Before starting Level Three, you should have:

  • Completed Ethical Hacking Levels One and Two (or have equivalent knowledge).
  • A solid understanding of networking (TCP/IP, DNS, routing) .
  • Experience with Linux and Kali Linux command line .
  • Familiarity with basic scripting (Bash, Python, PowerShell) .
  • Understanding of common vulnerabilities (SQLi, XSS, file inclusion) .
  • Basic knowledge of Active Directory attacks .

🎯 Learning Objectives

By the end of this course, you will be able to:

  • Plan and execute full-scope penetration tests with proper scoping and rules of engagement .
  • Conduct advanced reconnaissance using OSINT and social engineering .
  • Exploit web applications, APIs, and web servers using advanced techniques .
  • Perform SQL injection, XSS, CSRF, SSRF, XXE, and insecure deserialisation attacks .
  • Bypass IDS/IPS, firewalls, and honeypots .
  • Exploit Windows and Linux systems with privilege escalation and lateral movement .
  • Conduct Active Directory attacks (Kerberoasting, Golden Ticket, Silver Ticket) .
  • Test wireless networks, mobile platforms, and IoT devices .
  • Assess cloud security (AWS, Azure, GCP) and container security .
  • Develop custom exploits and bypass modern security protections .
  • Write professional, risk-prioritised reports and deliver executive briefings .

📖 Warm‑up Story · The Master Detective

Once upon a time, in a bustling city in Nigeria, there was a detective named Amara. Amara was not an ordinary detective – she was the best in the country. She could solve the most complex cases that left others confused.

One day, a bank in Lagos was robbed. The thieves left no fingerprints, no witnesses, and no evidence – or so they thought. Amara didn't just look for obvious clues. She examined everything – the security cameras' blind spots, the employees' schedules, the bank's digital logs, and even the garbage outside.

She found a tiny piece of information that everyone else had missed. That piece led her to the thieves. She caught them and returned the money.

That is exactly what Level Three ethical hackers do. They don't just look for easy vulnerabilities. They dig deeper, think like attackers, and find weaknesses that others miss. They are the master detectives of the cyber world.

📚 Course Structure

This course is divided into 14 modules, each focusing on a different area of advanced ethical hacking. The modules are based on industry standards, including the Certified Ethical Hacker (CEH) curriculum and advanced penetration testing frameworks .

📋 Course Modules

Module 1 · Introduction to Advanced Ethical Hacking

Welcome to Level Three! This module introduces the advanced mindset. You will learn about the difference between penetration testing and red teaming, the importance of scoping and rules of engagement, and the legal and ethical considerations of advanced testing .

Topics: Red team vs. penetration testing, scoping and engagement, legal frameworks, professional ethics, and reporting fundamentals.

Module 2 · Advanced Reconnaissance and OSINT

In Level Two, you learned basic reconnaissance. Now we go deeper. You will learn advanced OSINT techniques, how to gather information from social media, public databases, and even the dark web .

Topics: Advanced OSINT, social media intelligence, Google Dorking, Shodan, Maltego, Recon-ng, and automated reconnaissance.

Module 3 · Advanced Web Application Hacking

You already know SQL injection and XSS. Now you will learn advanced techniques like SSRF (Server-Side Request Forgery), XXE (XML External Entity attacks), insecure deserialisation, and business logic flaws .

Topics: SSRF, XXE, insecure deserialisation, business logic flaws, API security, JWT attacks, and OAuth vulnerabilities .

Module 4 · SQL Injection and Evasion Techniques

SQL injection is one of the most dangerous attacks. In this module, you will learn advanced SQL injection techniques and how to evade detection .

Topics: Advanced SQLi, blind SQLi, out-of-band SQLi, and evasion techniques.

Module 5 · Evading IDS, Firewalls, and Honeypots

Modern security systems are smart. Hackers need to evade them. You will learn how to bypass intrusion detection systems (IDS), firewalls, and honeypots .

Topics: IDS/IPS evasion, firewall bypass, packet fragmentation, protocol manipulation, and honeypot detection .

Module 6 · Session Hijacking and DoS Attacks

Learn how hackers steal user sessions and launch denial-of-service attacks .

Topics: Session hijacking (application-level and network-level), DoS/DDoS attack techniques, and countermeasures .

Module 7 · Advanced Active Directory Attacks

Active Directory is used by most large organisations. Hackers love to attack it. You will learn advanced AD attacks, including Kerberoasting, ASREPRoasting, Golden Ticket, and Silver Ticket attacks .

Topics: AD enumeration, Kerberoasting, ASREPRoasting, Golden Ticket, Silver Ticket, DCSync, and lateral movement .

Module 8 · Windows and Linux Exploitation

Learn how to exploit Windows and Linux systems at an advanced level. This includes privilege escalation, persistence, and post-exploitation .

Topics: Windows and Linux privilege escalation, persistence mechanisms, UAC bypass, and kernel exploits .

Module 9 · Wireless Network Hacking

In this module, you will learn advanced wireless hacking techniques, including WPA/WPA2 cracking, WPA3 attacks, and evil twin attacks .

Topics: Wireless reconnaissance, WPA/WPA2/WPA3 attacks, evil twin, rogue access points, and Bluetooth/RFID security .

Module 10 · Mobile Application Security

Mobile devices are everywhere. You will learn how to test Android and iOS apps for vulnerabilities .

Topics: Android security model, iOS security fundamentals, mobile app analysis, rooting and jailbreaking, and API security for mobile .

Module 11 · IoT and OT Hacking

The Internet of Things (IoT) and Operational Technology (OT) are growing fast. You will learn how to hack smart devices, industrial systems, and critical infrastructure .

Topics: IoT architecture, IoT hacking methodology, OT/SCADA security, and attack countermeasures .

Module 12 · Cloud Security (AWS, Azure, GCP)

Cloud computing is used by almost every company. You will learn how to assess the security of AWS, Azure, and Google Cloud .

Topics: Cloud concepts, cloud threats, S3 bucket misconfigurations, container security, and serverless security .

Module 13 · Exploit Development and Reverse Engineering

This is the most advanced topic. You will learn how to write your own exploits and reverse engineer software .

Topics: Buffer overflows, return-oriented programming (ROP), bypassing modern protections, custom payload development, and using tools like Ghidra and IDA .

Module 14 · Red Team Operations and Final Project

You will put everything together in a real-world red team exercise. You will plan, execute, and report on a full-scale security assessment .

Topics: C2 frameworks (Cobalt Strike, Empire), persistence, evasion, physical security testing, and professional reporting .

📊 Course Outline – Modules at a Glance

Module Topic Key Skills
1 Introduction to Advanced Ethical Hacking Scoping, engagement, legal frameworks
2 Advanced Reconnaissance and OSINT OSINT, social media intelligence, Google Dorking
3 Advanced Web Application Hacking SSRF, XXE, insecure deserialisation, API hacking
4 SQL Injection and Evasion Advanced SQLi, blind SQLi, evasion
5 Evading IDS, Firewalls, and Honeypots IDS/IPS bypass, firewall evasion, honeypot detection
6 Session Hijacking and DoS Session hijacking, DoS/DDoS attacks
7 Advanced Active Directory Attacks Kerberoasting, Golden Ticket, Silver Ticket
8 Windows and Linux Exploitation Privilege escalation, persistence, UAC bypass
9 Wireless Network Hacking WPA/WPA2/WPA3 cracking, evil twin, Bluetooth
10 Mobile Application Security Android/iOS testing, rooting, jailbreaking
11 IoT and OT Hacking IoT architecture, OT/SCADA security
12 Cloud Security AWS/Azure/GCP, containers, serverless
13 Exploit Development and Reverse Engineering Buffer overflows, ROP, Ghidra, IDA
14 Red Team Operations and Final Project Cobalt Strike, Empire, professional reporting

🛠️ Recommended Tools

In Level Three, you will use many advanced tools. Here are some of the most important ones :

Category Tools
Web Testing Burp Suite Professional, OWASP ZAP, sqlmap, Nikto
Network Testing Nmap, Wireshark, tcpdump, Nessus, OpenVAS
Exploitation Metasploit, PowerShell Empire, Cobalt Strike, Searchsploit
Wireless Testing Aircrack-ng, Kismet, Reaver, Wifite
Active Directory Mimikatz, CrackMapExec, BloodHound, Rubeus
Cloud Testing Pacu (AWS), ScoutSuite, CloudSploit
Mobile Testing MobSF, Frida, Drozer, Burp Suite Mobile Assistant
Reverse Engineering Ghidra, IDA Pro, pwntools, Immunity Debugger

🎓 Recommended Certifications

After completing Level Three, you will be ready to pursue professional certifications. These include :

  • OSCP (Offensive Security Certified Professional) – the most respected entry-level certification .
  • OSEP (Offensive Security Experienced Penetration Tester) – for advanced evasion and breach techniques .
  • CPENT (Certified Penetration Testing Professional) – EC-Council's advanced certification .
  • CRTO (Certified Red Team Operator) – for red team operations .
  • GPEN (GIAC Penetration Tester) – SANS certification .

📊 Assessment and Grading

Component Weight Description
Module Quizzes 15% Short quizzes after each module to test your knowledge.
Hands-on Labs 35% Practical labs using virtual machines, PortSwigger, and Hack The Box .
Midterm Practical Assessment 20% A simulated penetration test on a controlled environment.
Final Red Team Project 30% A full-scope red team exercise with a professional report .

📋 Comparison Table: Level Two vs Level Three

Skill Area Level Two Level Three
Web Hacking Basic SQLi, XSS, CSRF SSRF, XXE, insecure deserialisation, API hacking
Active Directory Basic AD attacks Kerberoasting, Golden/Silver Ticket, DCSync
Network Security Basic scanning and sniffing IDS/IPS evasion, advanced firewall bypass
Wireless Security Basic WPA2 cracking WPA3 attacks, evil twin, Bluetooth/RFID
Cloud Security Not covered AWS/Azure/GCP testing, container security
Exploit Development Not covered Buffer overflows, ROP, custom payloads
Reporting Basic report writing Professional, risk-prioritised reports and executive briefings

✨ Interesting Facts

💡 The global ethical hacking market is expected to reach $5 billion by 2031 .
💡 Companies that use red teaming are 40% more effective at detecting cyber attacks.

❓ Did You Know?

🔹 Many Nigerian companies now use red team exercises to test their security.
🔹 The OSEP certification (from Offensive Security) focuses on advanced evasion and breach techniques .

🧾 Remember This

⚠️ Always get written permission before testing any system.
🔒 The most advanced hackers are the ones who master the fundamentals.
📱 Keep learning – the cybersecurity field changes every day.

❌ Common Mistakes to Avoid

  • Thinking that tools are more important than knowledge.
  • Not understanding the business impact of vulnerabilities.
  • Ignoring the importance of professional reporting.
  • Not practising regularly – skills get rusty.

✅ Best Practices for Level Three

  • Master the fundamentals before moving to advanced topics.
  • Practice on platforms like Hack The Box and TryHackMe .
  • Keep a hacking journal to document your learning .
  • Learn to write clean, clear, professional reports.
  • Stay ethical and always respect the rules of engagement .

📊 Course Roadmap

    Start Level Three
           |
           v
    Module 1: Advanced Mindset
           |
           v
    Module 2: Advanced Recon
           |
           v
    Module 3: Advanced Web Hacking
           |
           v
    Module 4: SQL Injection & Evasion
           |
           v
    Module 5: Evading Defences
           |
           v
    Module 6: Session Hijacking & DoS
           |
           v
    Module 7: Active Directory Attacks
           |
           v
    Module 8: Windows/Linux Exploitation
           |
           v
    Module 9: Wireless Hacking
           |
           v
    Module 10: Mobile Security
           |
           v
    Module 11: IoT & OT Hacking
           |
           v
    Module 12: Cloud Security
           |
           v
    Module 13: Exploit Development
           |
           v
    Module 14: Red Team & Final Project
           |
           v
    🎉 You are now a professional ethical hacker! 🎉
    

🔑 Key Takeaways

  • Level Three is about advanced, professional skills.
  • You will learn how to chain vulnerabilities together.
  • You will master Active Directory, cloud, mobile, and IoT security.
  • You will learn to write professional reports and brief executives.
  • You will be prepared for advanced certifications like OSCP and OSEP.

❓ Frequently Asked Questions

  1. Q: Is this course harder than Level Two?
    A: Yes, but you are now a more experienced learner. You can handle it!
  2. Q: Do I need to be a programmer for Level Three?
    A: Basic scripting (Python, Bash, PowerShell) is helpful .
  3. Q: What is the difference between penetration testing and red teaming?
    A: Penetration testing focuses on finding vulnerabilities. Red teaming simulates a full adversary attack .
  4. Q: What is the final project?
    A: A complete red team exercise with a professional report .
  5. Q: Can I take the OSCP exam after this course?
    A: Yes, this course prepares you for OSCP and other advanced certifications .
  6. Q: What if I get stuck on a lab?
    A: That is normal! Learning to "Try Harder" is part of the process .
  7. Q: Is this course legal?
    A: Yes, all labs are in controlled environments with permission.
  8. Q: How long does this course take?
    A: Approximately 12–16 weeks with 6–8 hours per week .
  9. Q: What tools will I use?
    A: Cobalt Strike, Burp Suite Professional, Nessus, Aircrack-ng, Ghidra, and many more .
  10. Q: Why is reporting so important?
    A: Clients need to understand the risks and how to fix them. Good reporting makes you a professional .

📌 Review Questions

  1. What is the difference between penetration testing and red teaming?
  2. What is SSRF and why is it dangerous?
  3. What is a Golden Ticket attack?
  4. What is the purpose of a C2 framework like Cobalt Strike?
  5. How does WPA3 improve security over WPA2?
  6. What is insecure deserialisation?
  7. What is the OSEP certification and who is it for?
  8. How can you bypass an IDS?
  9. What is the difference between static and dynamic analysis in reverse engineering?
  10. What should be included in a professional penetration testing report?

🚀 What's Next?

After completing Level Three, you will be ready to:

  • Pursue professional certifications like OSCP, OSEP, and CPENT .
  • Apply for penetration testing and red team positions.
  • Continue learning with advanced courses on exploit development, threat intelligence, and incident response .
  • Join the cybersecurity community and share your knowledge .

Congratulations – you have completed the Introduction to Ethical Hacking course series! You are now a skilled ethical hacking professional. Keep learning, stay curious, and always use your powers for good. 🎉


🔥 You have completed the entire Ethical Hacking Level Three course outline! 🔥

2

Module One

Module One · Ethical Hacking Level Three

🔥 Module One · Introduction to Ethical Hacking Level Three

The Advanced Mindset – thinking like a professional ethical hacker.

📖 Module Introduction

Welcome to Level Three! You have made it to the advanced level of ethical hacking. This is where you learn to think and act like a professional.

In Level One, you learned the basics. In Level Two, you learned how to do ethical hacking. Now, in Level Three, you will learn how to be a master.

This module is all about the advanced mindset. What does that mean? It means thinking like a professional – planning carefully, understanding the rules, and always being ethical. It means knowing the difference between penetration testing and red teaming. It means understanding scoping, rules of engagement, and legal frameworks.

Think of it like this: Level One was learning to drive a car. Level Two was driving on the road. Level Three is becoming a professional race car driver. You need to know the track, the rules, the car, and how to push it to the limit – safely.

🎯 Learning Objectives

By the end of this module, you will be able to:

  • Explain the difference between penetration testing and red teaming.
  • Understand what scoping and rules of engagement are.
  • Know the legal and ethical rules for ethical hacking.
  • Understand the importance of professional reporting.
  • Think like a professional ethical hacker.
  • Apply these ideas to Nigerian businesses and organisations.

📖 Warm‑up Story · The Master Carpenter

Once upon a time, in a village in Anambra State, there was a carpenter named Chuka. Chuka was a good carpenter – he could build chairs, tables, and doors. His furniture was strong and lasted many years.

But there was another carpenter in the village named Emeka. Emeka was not just a good carpenter – he was a master. His furniture was not just strong; it was beautiful, perfectly made, and lasted forever. People came from far away to buy his furniture.

What made Emeka different? He didn't just know how to cut wood and hammer nails. He understood the wood – the different types, how they behaved, and how to treat them. He planned every project carefully. He knew the tools and when to use each one. He also knew how to communicate with his customers and understand exactly what they wanted.

That's what Level Three is about. You already know the tools and techniques. Now you will learn the mastery – the planning, the understanding, and the professionalism that makes you a true ethical hacking expert.

📚 Main Lessons

Lesson 1 · What is the Advanced Mindset?

Definition: The advanced mindset is the way professional ethical hackers think. It includes planning, ethics, communication, and deep understanding.

Why it is important: Without the right mindset, even the best tools are useless. The advanced mindset makes you a true professional.

Simple explanation: It's like being a master chef who knows not just how to cook, but also how to plan a menu, manage a kitchen, and please customers.

Real‑life example: A professional ethical hacker doesn't just run a tool and report the results. They plan the test, think like an attacker, and write a report that helps the client.

School example: A student who just memorises facts is like a beginner. A student who understands how to think, solve problems, and explain ideas is like an advanced learner.

Home example: At home, the advanced mindset is like a parent who not only cleans the house but also organises everything so it stays clean longer.

Nigerian example: A Nigerian ethical hacker with the advanced mindset doesn't just find vulnerabilities. They help the company understand the risks and how to fix them.

Mini summary: The advanced mindset is about thinking like a professional.

Lesson 2 · Penetration Testing vs. Red Teaming

Definition: Penetration testing is a focused test to find vulnerabilities. Red teaming is a full-scale attack simulation that tests an organisation's entire security.

Why it is important: Knowing the difference helps you choose the right service for a client.

Simple explanation: Penetration testing is like checking the locks on a door. Red teaming is like hiring a team of robbers to see if they can break into the whole building.

Real‑life example: A bank might hire a penetration tester to check their website. They might hire a red team to test their whole bank – including physical security, employees, and IT systems.

School example: A teacher checking a student's homework is like a penetration test. A whole school inspection is like a red team exercise.

Home example: Checking if your front door is locked is a penetration test. Hiring someone to try to break into your house in every way is a red team.

Nigerian example: A Nigerian company might hire a red team to test their entire security – including their offices in Lagos, their employees, and their cloud systems.

Lesson 3 · What is Scoping?

Definition: Scoping is the process of defining exactly what will be tested and what will not be tested.

Why it is important: Without clear scoping, the tester might accidentally break something important or miss something critical.

Simple explanation: It's like drawing a map of what you will explore and what you will leave alone.

Real‑life example: A pentester might scope a test to only include the company's website and not their internal network.

School example: A teacher might say, "For this test, you only need to study chapters 1 to 5." That is scoping.

Home example: You might say, "For this cleaning, I will only clean the living room and kitchen, not the bedrooms." That is scoping.

Nigerian example: A Nigerian fintech company might scope a test to only include their mobile app and API, not their internal servers.

Mini summary: Scoping defines the boundaries of the test.

Lesson 4 · Rules of Engagement

Definition: Rules of engagement are the rules that the ethical hacker must follow during the test.

Why it is important: Rules of engagement protect both the tester and the client. They make sure everything is legal and safe.

Simple explanation: It's like the rules of a game – they tell you what you can and cannot do.

Real‑life example: A rule of engagement might say, "Do not test during business hours" or "Do not delete any files."

School example: In a school sports game, the rules say, "No pushing" and "Stay on the field." That is a rule of engagement.

Home example: When you play a board game, the rule book tells you what to do and what not to do. That is a rule of engagement.

Nigerian example: A Nigerian company might have rules of engagement that say, "Only test the website, not the internal network" and "Do not use social engineering."

Lesson 5 · Legal Frameworks and Ethics

Definition: Legal frameworks are the laws that govern ethical hacking. Ethics are the moral rules that guide your behaviour.

Why it is important: Ethical hackers must follow the law and be ethical. If they don't, they could go to jail or harm people.

Simple explanation: It's like knowing the rules of the road before you drive a car.

Real‑life example: The Cybercrimes Act in Nigeria makes it illegal to hack without permission.

School example: Your school has rules about not cheating. That is an ethical rule.

Home example: Your family has rules about telling the truth. That is an ethical rule.

Nigerian example: The Nigerian Data Protection Regulation (NDPR) protects people's data. Ethical hackers must follow it.

Mini summary: Always follow the law and be ethical.

Lesson 6 · Professional Reporting

Definition: Professional reporting is the process of writing a clear, complete report of your findings.

Why it is important: If you don't write a good report, the client won't know what to fix.

Simple explanation: It's like a doctor writing a prescription – you need to tell the patient exactly what medicine to take.

Real‑life example: A penetration testing report includes an executive summary, findings, risk assessment, and recommendations.

School example: Writing a book report is like writing a security report – you need to explain what you found and why it matters.

Home example: If you find a leak in the roof, you write a note for your parents explaining where it is and how to fix it.

Nigerian example: A Nigerian bank needs a clear report to understand its security risks and fix them.

Lesson 7 · Understanding the Client's Business

Definition: Understanding the client's business means knowing what they do, what is important to them, and what risks they face.

Why it is important: You need to understand what matters to the client to give them useful advice.

Simple explanation: It's like a doctor understanding your lifestyle before giving you health advice.

Real‑life example: A hospital needs to protect patient records. A bank needs to protect money. Each has different priorities.

School example: A school needs to protect student grades. A shop needs to protect customer information.

Home example: Your family values privacy. A business might value money more. Different things are important.

Nigerian example: A Nigerian company might value customer trust and government regulations.

Lesson 8 · Communication Skills

Definition: Communication skills are the ability to explain complex ideas in a way that others understand.

Why it is important: You need to explain your findings to people who may not know anything about hacking.

Simple explanation: It's like being a translator who speaks both "hacker" and "normal person" languages.

Real‑life example: An ethical hacker explains a vulnerability to a CEO without using technical jargon.

School example: A student explains a math problem to a friend who doesn't understand it.

Home example: You explain to your parents why a new security measure is important.

Nigerian example: An ethical hacker in Nigeria explains risks to a business owner in simple language.

Lesson 9 · Continuous Learning

Definition: Continuous learning means always learning new things because cybersecurity changes every day.

Why it is important: New vulnerabilities are discovered every day. You need to keep learning to stay effective.

Simple explanation: It's like a doctor who reads new medical research every week.

Real‑life example: An ethical hacker spends time every week reading about new vulnerabilities and tools.

School example: A student who studies every day, not just before exams.

Home example: Your parents learn how to use new technology to stay safe online.

Nigerian example: A Nigerian ethical hacker joins online communities and attends conferences to learn.

Lesson 10 · The Role of the Ethical Hacker in Level Three

At Level Three, the ethical hacker becomes a trusted advisor. They don't just find vulnerabilities – they help the organisation understand its risks and improve its security over time.

📖 Key Vocabulary (Simple Definitions)

WordSimple meaning
Penetration testingA focused test to find vulnerabilities.
Red teamingA full-scale attack simulation.
ScopingDefining what will be tested.
Rules of engagementThe rules for the test.
Legal frameworkLaws that govern ethical hacking.
EthicsMoral rules that guide behaviour.
Professional reportingWriting clear, complete reports.
Communication skillsExplaining ideas clearly.
Continuous learningAlways learning new things.
Trusted advisorA professional who gives wise advice.

🧠 Important Concepts

  • Confidentiality: Keep the client's information secret.
  • Integrity: Be honest and don't cheat.
  • Availability: Don't break systems – make them more secure.
  • Professionalism: Act like a professional at all times.

🔢 Step‑by‑Step: The Professional Ethical Hacking Process

  1. Scope: Define what will be tested.
  2. Rules of engagement: Set the rules for the test.
  3. Get permission: Always get written permission.
  4. Perform the test: Use the right tools and techniques.
  5. Analyse results: Understand what you found.
  6. Write a report: Explain the findings clearly.
  7. Present findings: Communicate with the client.
  8. Recommend fixes: Tell them how to fix the problems.
  9. Follow up: Help them implement the fixes.

🌍 Real‑life Examples

1. Banking: A bank in London hires a red team to test their entire security. The red team uses social engineering, physical access, and network attacks to find weaknesses.

2. Healthcare: A hospital hires a penetration tester to check their patient portal. The tester finds a vulnerability and helps the hospital fix it.

🇳🇬 Nigerian Examples

  • A Nigerian bank uses a penetration tester to check its mobile app.
  • A Nigerian fintech company uses a red team to test its whole system.
  • A Nigerian university hires an ethical hacker to test its student portal.

🎈 Fun Examples for Kids

  • Imagine a game where you have to find all the hidden treasure. Penetration testing is like finding the treasure in one room. Red teaming is like finding it in the whole castle.
  • Scoping is like saying, "I will only look for treasure in the kitchen, not the bedrooms."

🏡 Everyday Examples

  • If you check if your bike lock is strong, that's a penetration test. If you try to break into your whole house, that's a red team.
  • Rules of engagement are like the rules of a game – they tell you what you can and cannot do.

👩‍🏫 Teacher Notes

Use the master carpenter story to introduce the advanced mindset. Emphasise that Level Three is about becoming a professional. Encourage students to think about the ethical and legal rules of ethical hacking.

👪 Parent Tips

  • Talk to your child about the importance of ethics and law.
  • Encourage them to learn about cybersecurity laws in Nigeria.
  • Discuss why communication skills are important.

✨ Interesting Facts

💡 The term "red team" comes from the military. In war games, the red team is the enemy.
💡 The first penetration testing company was founded in 1990.

❓ Did You Know?

🔹 The Nigerian Cybercrimes Act makes it illegal to hack without permission.
🔹 Many Nigerian companies now use red team exercises to test their security.

🧾 Remember This

⚠️ Always get written permission before testing.
🔒 Follow the law and be ethical.
📱 Communicate clearly with the client.

❌ Common Mistakes

  • Not getting permission before testing.
  • Not understanding the client's business.
  • Not writing a clear report.
  • Using too much technical jargon.

✅ Best Practices

  • Always get written permission.
  • Understand the client's business.
  • Write clear, simple reports.
  • Communicate effectively.
  • Keep learning.

📊 ASCII Illustrations & Flowcharts

The Professional Ethical Hacking Process

    Scope  ---->  Rules of Engagement  ---->  Get Permission
          |                                       |
          v                                       v
    Perform Test  <----  Analyse Results  <----  Write Report
          |                                       |
          v                                       v
    Present Findings  ---->  Recommend Fixes  ---->  Follow Up
    

Penetration Testing vs Red Teaming

    Penetration Testing: Focused, targeted, specific
    Red Teaming: Full-scale, all-encompassing, realistic
    

📋 Comparison Table: Penetration Testing vs Red Teaming

Penetration TestingRed Teaming
Focused testFull-scale simulation
Finds vulnerabilitiesTests entire security
Short durationLonger duration
Less expensiveMore expensive
For specific systemsFor whole organisation

📋 Comparison Table: Beginner vs Advanced Mindset

Beginner MindsetAdvanced Mindset
Focused on toolsFocused on understanding
Finds vulnerabilitiesUnderstands business impact
Writes basic reportsWrites professional reports
Follows instructionsThinks creatively
Learns from coursesLearns continuously

📌 Lesson Summaries

  • Lesson 1: The advanced mindset is thinking like a professional.
  • Lesson 2: Penetration testing is focused; red teaming is full-scale.
  • Lesson 3: Scoping defines what will be tested.
  • Lesson 4: Rules of engagement are the rules for the test.
  • Lesson 5: Always follow the law and be ethical.
  • Lesson 6: Professional reporting explains findings clearly.
  • Lesson 7: Understand the client's business.
  • Lesson 8: Communication skills are essential.
  • Lesson 9: Keep learning to stay effective.
  • Lesson 10: Level Three ethical hackers are trusted advisors.

📝 End‑of‑Module Summary

In Module One of Level Three, we learned about the advanced mindset – the way professional ethical hackers think. We explored the difference between penetration testing and red teaming, the importance of scoping and rules of engagement, and the legal and ethical rules of ethical hacking. We also learned about professional reporting, communication skills, and continuous learning. Remember, the advanced mindset is what separates a good ethical hacker from a great one.

❓ Frequently Asked Questions (10)

  1. Q: What is the difference between penetration testing and red teaming?
    A: Penetration testing is focused; red teaming is full-scale.
  2. Q: What is scoping?
    A: Defining what will be tested.
  3. Q: What are rules of engagement?
    A: The rules for the test.
  4. Q: Why is ethics important?
    A: It keeps you legal and safe.
  5. Q: What is professional reporting?
    A: Writing clear, complete reports.
  6. Q: Why is communication important?
    A: You need to explain findings to clients.
  7. Q: What is continuous learning?
    A: Always learning new things.
  8. Q: What is a trusted advisor?
    A: A professional who gives wise advice.
  9. Q: Is red teaming legal?
    A: Yes, with permission.
  10. Q: Why do Nigerian companies need red teaming?
    A: To test their whole security system.

📌 Review Questions (15)

  1. What is the advanced mindset?
  2. What is the difference between penetration testing and red teaming?
  3. What is scoping?
  4. What are rules of engagement?
  5. Why are ethics important in ethical hacking?
  6. What is professional reporting?
  7. Why is communication important?
  8. What is continuous learning?
  9. What is a trusted advisor?
  10. Why should you understand the client's business?
  11. What are the steps in the professional ethical hacking process?
  12. What is the Nigerian Cybercrimes Act?
  13. Why is scoping important?
  14. How does red teaming help Nigerian companies?
  15. What is the most important rule of ethical hacking?

✍️ Fill‑in‑the‑Blank

  1. ________ is a focused test to find vulnerabilities.
  2. ________ is a full-scale attack simulation.
  3. ________ is defining what will be tested.
  4. ________ are the rules for the test.
  5. ________ means always learning new things.

✔️ True or False

  1. Penetration testing is the same as red teaming. (False)
  2. Scoping defines what will be tested. (True)
  3. Rules of engagement are not important. (False)
  4. Ethics are important in ethical hacking. (True)
  5. Communication skills are not needed. (False)

🔘 Multiple Choice Questions

  1. What is the advanced mindset?
    A) Thinking like a professional B) Using tools C) Hacking quickly D) Breaking things
    Answer: A
  2. What is the difference between penetration testing and red teaming?
    A) Penetration testing is focused; red teaming is full-scale B) They are the same C) Red teaming is easier D) Penetration testing is illegal
    Answer: A
  3. What is scoping?
    A) Defining what will be tested B) Running tools C) Writing a report D) Breaking into a system
    Answer: A
  4. What are rules of engagement?
    A) The rules for the test B) The tools used C) The report D) The scope
    Answer: A
  5. Why are ethics important?
    A) They keep you legal and safe B) They are not important C) They slow you down D) They are expensive
    Answer: A
  6. What is professional reporting?
    A) Writing clear, complete reports B) Breaking into systems C) Using tools D) Learning new things
    Answer: A
  7. Why is communication important?
    A) To explain findings to clients B) To break things C) To use tools D) To learn new things
    Answer: A
  8. What is continuous learning?
    A) Always learning new things B) Learning once C) Not learning D) Forgetting things
    Answer: A
  9. What is a trusted advisor?
    A) A professional who gives wise advice B) A beginner C) A tool D) A report
    Answer: A
  10. What is the first step in the professional ethical hacking process?
    A) Scope the test B) Run tools C) Write a report D) Present findings
    Answer: A
  11. What is the Nigerian Cybercrimes Act?
    A) A law that makes hacking without permission illegal B) A tool C) A report D) A scope
    Answer: A
  12. Why is scoping important?
    A) It defines what will be tested B) It is not important C) It slows you down D) It is expensive
    Answer: A
  13. How does red teaming help Nigerian companies?
    A) Tests their whole security system B) Finds one vulnerability C) Is cheaper D) Is faster
    Answer: A
  14. What is the most important rule of ethical hacking?
    A) Always get permission B) Use the best tools C) Work fast D) Break things
    Answer: A
  15. What is the difference between a beginner and an advanced mindset?
    A) Advanced mindset is focused on understanding and planning B) Beginner mindset is better C) There is no difference D) Advanced mindset uses more tools
    Answer: A

🔗 Matching Exercise

TermMatch with
1. Penetration testingA. Full-scale simulation
2. Red teamingB. Focused test
3. ScopingC. Rules for the test
4. Rules of engagementD. Defining what will be tested
5. Professional reportingE. Writing clear reports

Answers: 1-B, 2-A, 3-D, 4-C, 5-E

✏️ Short Answer Questions

  1. Explain the difference between penetration testing and red teaming.
  2. Why is scoping important in ethical hacking?
  3. How can you communicate technical findings to a non-technical audience?

🎭 Scenario‑based Exercise

Scenario: You are an ethical hacker hired by a school in Lagos. The school wants you to test their security. How would you approach this? What would you include in the scope and rules of engagement?

👥 Group Activity

In groups of 4, create a sample scope and rules of engagement for a fictional company. Include what will be tested, what will not be tested, and the rules for the test.

🧑‍💻 Individual Activity

Write a short essay on why the advanced mindset is important for ethical hackers.

💬 Classroom Discussion Questions

  • Why is it important to understand the client's business?
  • How can you improve your communication skills?
  • What would you do if a client asked you to do something unethical?

🛠️ Mini Project

Project: Create a professional report template for a penetration test. Include sections for executive summary, findings, risk assessment, and recommendations.

🔧 Practical Assignment

Research the Nigerian Cybercrimes Act. Write a short summary of what it says about hacking and cyber security.

⚡ Challenge Exercise

Research how red teaming is used in the military. Write a one-page explanation and describe how it applies to cybersecurity.

✅ Quiz Answers (Selected)

  • Fill‑in‑the‑blank: 1) Penetration testing, 2) Red teaming, 3) Scoping, 4) Rules of engagement, 5) Continuous learning.
  • True/False: 1F, 2T, 3F, 4T, 5F.

🔑 Key Takeaways

  • The advanced mindset is about thinking like a professional.
  • Penetration testing is focused; red teaming is full-scale.
  • Scoping and rules of engagement are essential.
  • Always follow the law and be ethical.
  • Communication and reporting are key skills.
  • Keep learning to stay effective.

🚀 Preparation for Module Two

In Module Two, we will learn about advanced reconnaissance and OSINT. We will explore how to gather information from social media, public databases, and even the dark web. Make sure you understand the advanced mindset from this module.


🔥 You have completed Module One of Level Three! Keep up the great work. 🔥

3

Module Two

= Module Two · Ethical Hacking Level Three

🔍 Module Two · Introduction to Ethical Hacking Level Three

Advanced Reconnaissance and OSINT – gathering information like a professional spy.

📖 Module Introduction

Welcome to Module Two! In this module, we will learn about advanced reconnaissance and OSINT (Open Source Intelligence). This is the art of gathering information about a target using publicly available sources.

Think of it like being a detective. Before you solve a case, you need to gather clues. OSINT is how ethical hackers gather clues without touching the target's systems. It's like watching a person from a distance before you talk to them.

In Level Two, you learned basic reconnaissance. Now, in Level Three, we go much deeper. We will learn about social media intelligence, Google Dorking, Shodan, Maltego, and Recon-ng. By the end of this module, you will be able to gather information like a professional spy.

🎯 Learning Objectives

By the end of this module, you will be able to:

  • Explain what advanced OSINT is.
  • Understand how to use social media for intelligence gathering.
  • Use Google Dorking to find hidden information.
  • Use Shodan to find internet-connected devices.
  • Use Maltego to find connections between people and organisations.
  • Use Recon-ng for automated reconnaissance.
  • Apply these ideas to Nigerian schools, businesses, and homes.

📖 Warm‑up Story · The Curious Journalist

Once upon a time, in Lagos, there was a journalist named Ngozi. She was known for writing amazing stories that uncovered secrets. But she didn't just ask people questions – she was a master at gathering information.

When Ngozi wanted to write about a new company, she would spend days just watching. She would read their website, check their social media, look at their employees' LinkedIn profiles, and even check what people were saying about them online. She would put all this information together to get a complete picture.

That's exactly what advanced OSINT is – gathering information from many different sources to build a complete picture of your target. Ethical hackers do this to find vulnerabilities and help protect organisations.

📚 Main Lessons

Lesson 1 · What is Advanced OSINT?

Definition: OSINT stands for Open Source Intelligence. It is information that is publicly available and can be used for intelligence gathering.

Why it is important: OSINT helps ethical hackers understand their target before they start testing. This makes the testing more effective.

Simple explanation: It's like reading a book about a country before you visit it.

Real‑life example: A hacker might use OSINT to find an employee's email address to send a phishing email.

School example: A student might look at a teacher's social media to learn about their hobbies.

Home example: A parent might look up a babysitter online to check their background.

Nigerian example: A Nigerian company might use OSINT to check what is being said about them online.

Mini summary: OSINT is gathering information from public sources.

Lesson 2 · Social Media Intelligence (SOCMINT)

Definition: SOCMINT is OSINT from social media platforms like Facebook, Twitter, LinkedIn, and Instagram.

Why it is important: People share a lot of information on social media. This can be used to understand people and organisations.

Simple explanation: It's like watching what people post on social media to learn about them.

Real‑life example: An ethical hacker might look at a company's LinkedIn page to find employee names.

School example: A student might check a teacher's Facebook page to learn about their interests.

Home example: A parent might check a neighbour's Instagram to see what they like to do.

Nigerian example: A Nigerian business might check social media to see what customers are saying about them.

Mini summary: SOCMINT is OSINT from social media.

Lesson 3 · Google Dorking

Definition: Google Dorking is using special search terms to find hidden information on Google.

Why it is important: Google Dorking can find information that is not normally visible, like passwords or sensitive files.

Simple explanation: It's like using a secret code to find hidden treasure.

Real‑life example: A hacker might use Google Dorking to find a company's internal documents.

School example: A student might use Google Dorking to find old exam papers.

Home example: A family member might use Google Dorking to find their own information that is accidentally online.

Nigerian example: A Nigerian ethical hacker might use Google Dorking to find sensitive information about a company.

Mini summary: Google Dorking is a special way to search Google.

Lesson 4 · Shodan – The Search Engine for Devices

Definition: Shodan is a search engine that finds internet-connected devices like cameras, servers, and routers.

Why it is important: Shodan can find devices that are not properly secured.

Simple explanation: It's like Google for devices instead of websites.

Real‑life example: A hacker might use Shodan to find a security camera that has no password.

School example: A student might use Shodan to find a school server that is open to the internet.

Home example: A parent might use Shodan to check if their home security camera is visible.

Nigerian example: A Nigerian ethical hacker might use Shodan to find exposed devices in a company.

Mini summary: Shodan finds internet-connected devices.

Lesson 5 · Maltego – Connecting the Dots

Definition: Maltego is a tool that shows connections between people, organisations, and websites.

Why it is important: Maltego helps you understand relationships and find hidden connections.

Simple explanation: It's like a detective's corkboard with pins and strings showing who knows who.

Real‑life example: A hacker might use Maltego to find a connection between a company and a competitor.

School example: A student might use Maltego to find connections between different teachers.

Home example: A parent might use Maltego to find connections between different people in their neighbourhood.

Nigerian example: A Nigerian journalist might use Maltego to investigate a company's connections.

Mini summary: Maltego shows connections between things.

Lesson 6 · Recon-ng – Automated Reconnaissance

Definition: Recon-ng is a tool that automates the process of gathering OSINT information.

Why it is important: Recon-ng makes OSINT faster and more efficient.

Simple explanation: It's like a robot that does your detective work for you.

Real‑life example: An ethical hacker might use Recon-ng to gather information about a company in minutes.

School example: A student might use Recon-ng to gather information about a school project.

Home example: A parent might use Recon-ng to check what information is available about their family.

Nigerian example: A Nigerian ethical hacker might use Recon-ng to test a company's information exposure.

Mini summary: Recon-ng automates OSINT.

Lesson 7 · Understanding the Dark Web

Definition: The dark web is part of the internet that is not indexed by regular search engines. It requires special software to access.

Why it is important: Hackers sometimes use the dark web to share information. Ethical hackers need to understand it.

Simple explanation: It's like a secret part of the internet that you can't find with Google.

Lesson 8 · Corporate OSINT

Corporate OSINT is gathering information about a company. This includes checking their website, financial reports, and public records.

Lesson 9 · Personal OSINT

Personal OSINT is gathering information about individuals. This includes checking social media, public records, and other sources.

Lesson 10 · The OSINT Framework

The OSINT Framework is a collection of tools and resources for OSINT. It helps you find the right tool for the job.

Lesson 11 · Using OSINT Ethically

OSINT is legal, but it must be used ethically. You should never use OSINT to harm someone or invade their privacy.

Lesson 12 · Protecting Yourself from OSINT

Just as you can gather information, others can gather information about you. You should protect your own information.

Lesson 13 · Advanced Google Dorking

Google Dorking has many advanced operators. You can find specific file types, search within websites, and much more.

Lesson 14 · Using Social Media for OSINT

Social media is one of the richest sources of OSINT. You can find photos, locations, friends, and much more.

Lesson 15 · The Role of Ethical Hackers in OSINT

Ethical hackers use OSINT to find vulnerabilities and help organisations protect themselves.

📖 Key Vocabulary (Simple Definitions)

WordSimple meaning
OSINTInformation from public sources.
SOCMINTOSINT from social media.
Google DorkingUsing special searches to find hidden info.
ShodanA search engine for devices.
MaltegoA tool that shows connections.
Recon-ngA tool that automates OSINT.
Dark webA secret part of the internet.
Corporate OSINTGathering info about a company.
Personal OSINTGathering info about a person.
Ethical OSINTUsing OSINT legally and morally.

🧠 Important Concepts

  • Passive reconnaissance: Gathering information without touching the target's systems.
  • Active reconnaissance: Interacting with the target's systems.
  • Footprinting: The process of gathering information about a target.
  • Privacy: Protecting your own information from OSINT.

🔢 Step‑by‑Step: How to Use Google Dorking

  1. Think about what you want to find.
  2. Use special operators like filetype:pdf or site:example.com.
  3. Add keywords like "password" or "confidential".
  4. Search and review the results.
  5. Use the information to help your investigation.

🌍 Real‑life Examples

1. Corporate Espionage: A competitor might use OSINT to learn about a company's new product.

2. Journalists: Journalists use OSINT to investigate stories and find sources.

🇳🇬 Nigerian Examples

  • A Nigerian journalist uses Maltego to investigate a politician's connections.
  • A Nigerian bank uses OSINT to check what information is available about them.
  • A Nigerian ethical hacker uses Recon-ng to test a company's information exposure.

🎈 Fun Examples for Kids

  • Imagine you want to know who your friend's friends are. You look at their social media to find out – that's OSINT.
  • Google Dorking is like using a secret code to find treasure on the internet.

🏡 Everyday Examples

  • If you search your own name online to see what appears, that's personal OSINT.
  • If you check a restaurant's reviews online before visiting, that's OSINT.

👩‍🏫 Teacher Notes

Use the curious journalist story to introduce OSINT. Emphasise that OSINT is legal and ethical. Encourage students to think about how much information is available about them online.

👪 Parent Tips

  • Teach your child to be careful about what they share online.
  • Show them how to check their own information online.
  • Explain why privacy is important.

✨ Interesting Facts

💡 The term "OSINT" was first used by the military.
💡 Shodan was created in 2009.

❓ Did You Know?

🔹 Many Nigerian companies use OSINT to check what is being said about them online.
🔹 Recon-ng has over 100 different modules for gathering information.

🧾 Remember This

⚠️ Only use OSINT for legal and ethical purposes.
🔒 Protect your own information from OSINT.
📱 Be careful about what you share online.

❌ Common Mistakes

  • Using OSINT for illegal purposes.
  • Sharing too much information online.
  • Not checking your own information exposure.
  • Using tools without understanding how they work.

✅ Best Practices

  • Use OSINT only for legal and ethical purposes.
  • Protect your own information.
  • Understand the tools you use.
  • Keep learning about new OSINT techniques.

📊 ASCII Illustrations & Flowcharts

The OSINT Process

    Identify Target
          |
          v
    Choose Sources (social media, Google, Shodan)
          |
          v
    Gather Information
          |
          v
    Analyse Information
          |
          v
    Use Information for Investigation
    

Types of OSINT

    OSINT
       |
       +-- Social Media (SOCMINT)
       +-- Search Engines (Google Dorking)
       +-- Device Search (Shodan)
       +-- Connections (Maltego)
       +-- Automated (Recon-ng)
    

Google Dorking Example

    Search: filetype:pdf "password" site:example.com
    This finds PDF files on example.com that contain the word "password".
    

📋 Comparison Table: Google vs Shodan

GoogleShodan
Finds websitesFinds devices
Finds web pagesFinds servers, cameras, routers
Used by everyoneUsed by security professionals

📋 Comparison Table: Maltego vs Recon-ng

MaltegoRecon-ng
Shows connections visuallyAutomates data collection
InteractiveCommand-line based
User-friendlyMore powerful for large-scale

📌 Lesson Summaries

  • Lesson 1: OSINT is gathering information from public sources.
  • Lesson 2: SOCMINT is OSINT from social media.
  • Lesson 3: Google Dorking finds hidden information.
  • Lesson 4: Shodan finds internet-connected devices.
  • Lesson 5: Maltego shows connections between things.
  • Lesson 6: Recon-ng automates OSINT.
  • Lesson 7: The dark web is a secret part of the internet.
  • Lesson 8: Corporate OSINT gathers information about companies.
  • Lesson 9: Personal OSINT gathers information about individuals.
  • Lesson 10: The OSINT Framework helps you choose tools.
  • Lesson 11: Use OSINT ethically.
  • Lesson 12: Protect your own information.
  • Lesson 13: Advanced Google Dorking uses special operators.
  • Lesson 14: Social media is a rich source of OSINT.
  • Lesson 15: Ethical hackers use OSINT to find vulnerabilities.

📝 End‑of‑Module Summary

In Module Two, we learned about advanced reconnaissance and OSINT. We explored social media intelligence (SOCMINT), Google Dorking, Shodan, Maltego, and Recon-ng. We also learned about the dark web, corporate OSINT, and personal OSINT. Remember, OSINT is a powerful tool that must be used ethically. Always protect your own information and use OSINT to help, not harm.

❓ Frequently Asked Questions (10)

  1. Q: What is OSINT?
    A: Information from public sources.
  2. Q: What is SOCMINT?
    A: OSINT from social media.
  3. Q: What is Google Dorking?
    A: Using special searches to find hidden info.
  4. Q: What is Shodan?
    A: A search engine for devices.
  5. Q: What is Maltego?
    A: A tool that shows connections.
  6. Q: What is Recon-ng?
    A: A tool that automates OSINT.
  7. Q: What is the dark web?
    A: A secret part of the internet.
  8. Q: Is OSINT legal?
    A: Yes, if used ethically.
  9. Q: How can I protect my information?
    A: Be careful what you share online.
  10. Q: Why do ethical hackers use OSINT?
    A: To find vulnerabilities.

📌 Review Questions (15)

  1. What is OSINT?
  2. What is SOCMINT?
  3. What is Google Dorking?
  4. What is Shodan?
  5. What is Maltego?
  6. What is Recon-ng?
  7. What is the dark web?
  8. What is corporate OSINT?
  9. What is personal OSINT?
  10. What is the OSINT Framework?
  11. How can you use OSINT ethically?
  12. How can you protect your own information?
  13. What is an example of Google Dorking?
  14. Why is social media a rich source of OSINT?
  15. How do Nigerian companies use OSINT?

✍️ Fill‑in‑the‑Blank

  1. ________ is information from public sources.
  2. ________ is OSINT from social media.
  3. ________ is using special searches to find hidden info.
  4. ________ is a search engine for devices.
  5. ________ is a tool that automates OSINT.

✔️ True or False

  1. OSINT is always illegal. (False)
  2. Google Dorking uses special search terms. (True)
  3. Shodan finds websites. (False)
  4. Maltego shows connections. (True)
  5. Recon-ng automates OSINT. (True)

🔘 Multiple Choice Questions

  1. What is OSINT?
    A) Information from public sources B) Information from private sources C) A type of malware D) A firewall
    Answer: A
  2. What is SOCMINT?
    A) OSINT from social media B) OSINT from Google C) OSINT from Shodan D) OSINT from Maltego
    Answer: A
  3. What is Google Dorking?
    A) Using special searches B) Hacking Google C) Breaking into websites D) Stealing passwords
    Answer: A
  4. What is Shodan?
    A) A search engine for devices B) A search engine for websites C) A type of malware D) A firewall
    Answer: A
  5. What is Maltego?
    A) A tool that shows connections B) A search engine C) A type of malware D) A firewall
    Answer: A
  6. What is Recon-ng?
    A) A tool that automates OSINT B) A search engine C) A type of malware D) A firewall
    Answer: A
  7. What is the dark web?
    A) A secret part of the internet B) A type of malware C) A search engine D) A firewall
    Answer: A
  8. What is corporate OSINT?
    A) Gathering info about a company B) Gathering info about a person C) A type of malware D) A firewall
    Answer: A
  9. What is personal OSINT?
    A) Gathering info about a person B) Gathering info about a company C) A type of malware D) A firewall
    Answer: A
  10. Is OSINT legal?
    A) Yes, if used ethically B) No, never C) Sometimes D) Only in Nigeria
    Answer: A
  11. What is the OSINT Framework?
    A) A collection of OSINT tools B) A type of malware C) A search engine D) A firewall
    Answer: A
  12. How can you protect your information?
    A) Be careful what you share B) Share everything C) Ignore privacy D) Use weak passwords
    Answer: A
  13. What is an example of Google Dorking?
    A) filetype:pdf "password" B) google.com C) shodan.io D) maltego.com
    Answer: A
  14. Why is social media a rich source of OSINT?
    A) People share a lot of information B) It's not a good source C) It's always private D) It's too hard to use
    Answer: A
  15. How do Nigerian companies use OSINT?
    A) To check what is said about them B) To steal data C) To spy on competitors D) None
    Answer: A

🔗 Matching Exercise

TermMatch with
1. OSINTA. Search engine for devices
2. SOCMINTB. Information from public sources
3. Google DorkingC. OSINT from social media
4. ShodanD. Tool that shows connections
5. MaltegoE. Using special searches

Answers: 1-B, 2-C, 3-E, 4-A, 5-D

✏️ Short Answer Questions

  1. Explain the difference between OSINT and SOCMINT.
  2. What is Google Dorking and how is it used?
  3. How can you protect your own information from OSINT?

🎭 Scenario‑based Exercise

Scenario: You are an ethical hacker hired by a school in Abuja. You want to find out what information is publicly available about the school. What OSINT techniques would you use?

👥 Group Activity

In groups of 4, use Google Dorking to find information about a fictional company. Document what you find and how you found it.

🧑‍💻 Individual Activity

Write a short essay on why OSINT is important for ethical hackers.

💬 Classroom Discussion Questions

  • How much information is available about you online?
  • How can we educate people about OSINT?
  • What would you do if you found sensitive information through OSINT?

🛠️ Mini Project

Project: Create a guide on how to protect personal information from OSINT. Include tips on privacy settings and what not to share.

🔧 Practical Assignment

Search your own name online. Write a report on what you find and suggest ways to protect your information.

⚡ Challenge Exercise

Research how Maltego works. Write a one-page explanation and give an example of how it can be used for OSINT.

✅ Quiz Answers (Selected)

  • Fill‑in‑the‑blank: 1) OSINT, 2) SOCMINT, 3) Google Dorking, 4) Shodan, 5) Recon-ng.
  • True/False: 1F, 2T, 3F, 4T, 5T.

🔑 Key Takeaways

  • OSINT is gathering information from public sources.
  • Social media is a rich source of OSINT.
  • Google Dorking can find hidden information.
  • Shodan finds internet-connected devices.
  • Maltego shows connections between things.
  • Recon-ng automates OSINT.
  • Always use OSINT ethically and protect your own information.

🚀 Preparation for Module Three

In Module Three, we will learn about advanced web application hacking. We will explore SSRF, XXE, insecure deserialisation, and API security. Make sure you understand the OSINT concepts from this module.


🔥 You have completed Module Two of Level Three! Keep up the great work. 🔥

4

Module Three

Module Three · Ethical Hacking Level Three

🌐 Module Three · Introduction to Ethical Hacking Level Three

Advanced Web Application Hacking – mastering the hidden dangers of the web.

📖 Module Introduction

Welcome to Module Three! In this module, we will learn about advanced web application hacking. You already know about SQL injection and XSS from Level Two. Now we will go much deeper.

Think of a website like a house. In Level Two, you learned how to check if the doors and windows are locked. Now, in Level Three, you will learn how to check the walls, the foundation, and even the plumbing – things that most people don't even think about.

We will explore SSRF (Server-Side Request Forgery), XXE (XML External Entity attacks), insecure deserialisation, business logic flaws, and API security. By the end of this module, you will be able to find vulnerabilities that most hackers miss.

🎯 Learning Objectives

By the end of this module, you will be able to:

  • Explain what SSRF is and how to exploit it.
  • Understand XXE attacks and how they work.
  • Learn about insecure deserialisation.
  • Understand business logic flaws.
  • Learn about API security and common vulnerabilities.
  • Understand JWT attacks.
  • Apply these ideas to Nigerian schools, businesses, and homes.

📖 Warm‑up Story · The Invisible Invitation

Once upon a time, in a school in Lagos, there was a secret club. To join the club, you needed an invitation from a member. But one clever student named Tunde found a way to get in without an invitation.

Tunde noticed that the club's website had a form where you could enter your name. He typed something special into the form – not his name, but a command that told the server to give him access. The server did exactly what he said, and Tunde got into the club.

That is exactly what SSRF (Server-Side Request Forgery) is – tricking a server into doing something it shouldn't. In this module, we will learn how these attacks work and how to stop them.

📚 Main Lessons

Lesson 1 · What is SSRF (Server-Side Request Forgery)?

Definition: SSRF is an attack where a hacker tricks a server into making requests to other servers or internal systems.

Why it is important: SSRF can allow hackers to access internal systems that are not normally visible from the internet.

Simple explanation: It's like tricking a security guard into opening a door for you by pretending to be someone you're not.

Real‑life example: A hacker might use SSRF to access a company's internal database.

School example: A student might use SSRF to access the teacher's private files on the school server.

Home example: A family member might use SSRF to access the router's settings from outside the house.

Nigerian example: A Nigerian hacker might use SSRF to access a bank's internal systems.

Mini summary: SSRF tricks a server into making requests it shouldn't.

Lesson 2 · How SSRF Works

A hacker finds a website feature that takes a URL as input. The hacker changes the URL to point to an internal system. The server makes the request and returns the response to the hacker.

Lesson 3 · Types of SSRF

  • Basic SSRF: The hacker gets the response directly.
  • Blind SSRF: The hacker doesn't get the response but can still cause changes.

Lesson 4 · What is XXE (XML External Entity)?

Definition: XXE is an attack that exploits how XML parsers process external entities. Hackers can use it to read files or make requests.

Why it is important: XXE can allow hackers to read sensitive files on the server.

Simple explanation: It's like putting a secret code in a form that makes the server give you its secrets.

Real‑life example: A hacker might use XXE to read a password file on a server.

School example: A student might use XXE to read the teacher's notes.

Home example: A family member might use XXE to read private documents on a home server.

Nigerian example: A Nigerian company might be vulnerable to XXE, allowing hackers to read customer data.

Mini summary: XXE exploits XML parsers to read files.

Lesson 5 · How XXE Works

A hacker uploads an XML file with a malicious external entity. The XML parser processes the entity and returns sensitive information.

Lesson 6 · What is Insecure Deserialisation?

Definition: Insecure deserialisation is when a program takes data from an untrusted source and turns it back into an object, without checking if it's safe.

Why it is important: Hackers can use it to run malicious code on the server.

Simple explanation: It's like opening a package without checking who sent it – it could be a bomb.

Real‑life example: A hacker might send a malicious serialised object to a server to gain control.

School example: A student might send a malicious file to the school server to access the network.

Home example: A hacker might send a malicious file to a family's computer to install malware.

Nigerian example: A Nigerian company might be vulnerable to insecure deserialisation.

Mini summary: Insecure deserialisation allows hackers to run code.

Lesson 7 · How Insecure Deserialisation Works

A hacker creates a malicious serialised object and sends it to a server. The server deserialises it and runs the malicious code.

Lesson 8 · What are Business Logic Flaws?

Definition: Business logic flaws are weaknesses in how a website's rules are implemented. Hackers can exploit them to do things they shouldn't.

Why it is important: Business logic flaws can allow hackers to cheat, steal, or break things.

Simple explanation: It's like finding a loophole in a game's rules that lets you win unfairly.

Real‑life example: A hacker might exploit a business logic flaw to get free products from an online store.

School example: A student might exploit a flaw to change their grades.

Home example: A family member might exploit a flaw to get free access to a service.

Nigerian example: A Nigerian e‑commerce site might have a business logic flaw.

Mini summary: Business logic flaws are weaknesses in website rules.

Lesson 9 · API Security

Definition: APIs are how websites talk to each other. API security is about protecting these communications.

Why it is important: If an API is not secure, hackers can access sensitive data.

Simple explanation: It's like protecting the telephone line between two buildings.

Lesson 10 · Common API Vulnerabilities

  • Broken object-level authorisation: Users can access data they shouldn't.
  • Broken authentication: Weak login security.
  • Excessive data exposure: APIs give out too much information.

Lesson 11 · JWT Attacks

Definition: JWT (JSON Web Tokens) are used for authentication. Hackers can attack them by stealing or modifying them.

Simple explanation: It's like stealing someone's ID card.

Lesson 12 · OAuth Vulnerabilities

OAuth is used to allow login with Google or Facebook. Hackers can exploit misconfigurations to steal tokens.

Lesson 13 · GraphQL Security

GraphQL is a new way to build APIs. Hackers can exploit it through injections and excessive requests.

Lesson 14 · Protecting Against Advanced Web Attacks

  • Validate all input.
  • Use parameterised queries.
  • Disable dangerous XML features.
  • Use secure deserialisation.
  • Test business logic thoroughly.

Lesson 15 · The Role of Ethical Hackers in Web Security

Ethical hackers find and report these vulnerabilities before bad hackers can exploit them.

📖 Key Vocabulary (Simple Definitions)

WordSimple meaning
SSRFTricking a server into making requests.
XXEExploiting XML parsers to read files.
Insecure deserialisationTurning unsafe data into objects.
Business logic flawA weakness in website rules.
APIA way for websites to talk to each other.
JWTA token used for authentication.
OAuthA way to login with Google or Facebook.
GraphQLA newer way to build APIs.
SerialisationTurning an object into data.
DeserialisationTurning data back into an object.

🧠 Important Concepts

  • Input validation: Always check what users send you.
  • Least privilege: Give users only the access they need.
  • Defence in depth: Use many layers of security.
  • Zero trust: Never trust user input.

🔢 Step‑by‑Step: How an SSRF Attack Works

  1. Hacker finds a feature that takes a URL input.
  2. Hacker changes the URL to point to an internal system.
  3. The server makes the request.
  4. The server returns the internal response to the hacker.
  5. Hacker gets access to internal information.

🌍 Real‑life Examples

1. Cloud Services: Hackers use SSRF to access metadata services on AWS and Azure.

2. Payment Systems: Hackers exploit business logic flaws to steal money.

🇳🇬 Nigerian Examples

  • A Nigerian fintech company uses input validation to prevent SSRF.
  • A Nigerian university tests for XXE vulnerabilities in their student portal.
  • A Nigerian e‑commerce site fixes business logic flaws.

🎈 Fun Examples for Kids

  • Imagine a game where you can type commands. SSRF is like typing a command that makes the game give you extra lives.
  • XXE is like putting a secret code in a form that makes the computer tell you its secrets.

🏡 Everyday Examples

  • If you use a QR code that takes you to a suspicious website, that could be a security risk.
  • If an app asks for too many permissions, that could be a security issue.

👩‍🏫 Teacher Notes

Use the invisible invitation story to introduce SSRF. Emphasise that these are advanced attacks that require deep understanding. Encourage students to think about how they can protect web applications.

👪 Parent Tips

  • Teach your child to be careful about what they click on.
  • Explain why websites need security.
  • Show them how to check if a website is secure.

✨ Interesting Facts

💡 SSRF was first discovered in 2010.
💡 Many cloud services are vulnerable to SSRF attacks.

❓ Did You Know?

🔹 Many Nigerian companies use API security to protect their data.
🔹 Insecure deserialisation is one of the OWASP Top 10 vulnerabilities.

🧾 Remember This

⚠️ Never trust user input.
🔒 Always validate and sanitise data.
📱 Use secure deserialisation.

❌ Common Mistakes

  • Not validating user input.
  • Allowing XML external entities.
  • Using insecure deserialisation.
  • Not testing business logic.

✅ Best Practices

  • Validate all input.
  • Disable external entities in XML.
  • Use secure deserialisation.
  • Test business logic thoroughly.
  • Use API security best practices.

📊 ASCII Illustrations & Flowcharts

SSRF Attack Flow

    Hacker sends URL ---->  Server makes request
                |                      |
                v                      v
            Internal system  <----  Response returned
    

XXE Attack Flow

    Hacker uploads XML ---->  XML parser processes
                |                      |
                v                      v
            External entity  <----  Sensitive data returned
    

Insecure Deserialisation

    Hacker sends object ---->  Server deserialises
                |                      |
                v                      v
            Malicious code  <----  Server compromised
    

📋 Comparison Table: SSRF vs XXE

SSRFXXE
Tricks server into making requestsExploits XML parsers
Can access internal systemsCan read files
Uses URLsUses XML

📋 Comparison Table: Level Two vs Level Three Web Hacking

Level TwoLevel Three
SQL injectionSSRF, XXE
XSSInsecure deserialisation
CSRFBusiness logic flaws
Basic web testingAPI security

📌 Lesson Summaries

  • Lesson 1: SSRF tricks a server into making requests.
  • Lesson 2: SSRF exploits URL inputs.
  • Lesson 3: Basic and blind SSRF are two types.
  • Lesson 4: XXE exploits XML parsers.
  • Lesson 5: XXE can read files.
  • Lesson 6: Insecure deserialisation runs code.
  • Lesson 7: Deserialisation attacks use malicious objects.
  • Lesson 8: Business logic flaws are rule weaknesses.
  • Lesson 9: APIs need security.
  • Lesson 10: Common API vulnerabilities exist.
  • Lesson 11: JWT attacks steal tokens.
  • Lesson 12: OAuth vulnerabilities can be exploited.
  • Lesson 13: GraphQL needs security.
  • Lesson 14: Validate input and use secure deserialisation.
  • Lesson 15: Ethical hackers find and report vulnerabilities.

📝 End‑of‑Module Summary

In Module Three, we learned about advanced web application hacking. We explored SSRF, XXE, insecure deserialisation, business logic flaws, and API security. These are the types of vulnerabilities that professional ethical hackers look for. Remember, web security is complex, but with the right knowledge, we can protect ourselves and our organisations.

❓ Frequently Asked Questions (10)

  1. Q: What is SSRF?
    A: Tricking a server into making requests.
  2. Q: What is XXE?
    A: Exploiting XML parsers to read files.
  3. Q: What is insecure deserialisation?
    A: Turning unsafe data into objects.
  4. Q: What is a business logic flaw?
    A: A weakness in website rules.
  5. Q: What is an API?
    A: A way for websites to talk to each other.
  6. Q: What is JWT?
    A: A token used for authentication.
  7. Q: What is OAuth?
    A: A way to login with Google or Facebook.
  8. Q: What is GraphQL?
    A: A newer way to build APIs.
  9. Q: How can I protect against SSRF?
    A: Validate all input.
  10. Q: How can I protect against XXE?
    A: Disable external entities.

📌 Review Questions (15)

  1. What is SSRF?
  2. How does SSRF work?
  3. What is XXE?
  4. How does XXE work?
  5. What is insecure deserialisation?
  6. What is a business logic flaw?
  7. What is an API?
  8. What is JWT?
  9. What is OAuth?
  10. What is GraphQL?
  11. How can you protect against SSRF?
  12. How can you protect against XXE?
  13. How can you protect against insecure deserialisation?
  14. What are common API vulnerabilities?
  15. Why are Nigerian businesses at risk from these attacks?

✍️ Fill‑in‑the‑Blank

  1. ________ tricks a server into making requests.
  2. ________ exploits XML parsers.
  3. ________ turns unsafe data into objects.
  4. ________ is a weakness in website rules.
  5. ________ is a way for websites to talk to each other.

✔️ True or False

  1. SSRF can access internal systems. (True)
  2. XXE can read files on a server. (True)
  3. Insecure deserialisation is safe. (False)
  4. Business logic flaws are not dangerous. (False)
  5. APIs don't need security. (False)

🔘 Multiple Choice Questions

  1. What is SSRF?
    A) Tricking a server into making requests B) A type of malware C) A firewall D) A browser
    Answer: A
  2. What is XXE?
    A) Exploiting XML parsers B) A type of malware C) A firewall D) A browser
    Answer: A
  3. What is insecure deserialisation?
    A) Turning unsafe data into objects B) A type of malware C) A firewall D) A browser
    Answer: A
  4. What is a business logic flaw?
    A) A weakness in website rules B) A type of malware C) A firewall D) A browser
    Answer: A
  5. What is an API?
    A) A way for websites to talk B) A type of malware C) A firewall D) A browser
    Answer: A
  6. What is JWT?
    A) A token for authentication B) A type of malware C) A firewall D) A browser
    Answer: A
  7. What is OAuth?
    A) A login method B) A type of malware C) A firewall D) A browser
    Answer: A
  8. What is GraphQL?
    A) A newer way to build APIs B) A type of malware C) A firewall D) A browser
    Answer: A
  9. How can you protect against SSRF?
    A) Validate all input B) Use weak passwords C) Ignore security D) Disable security
    Answer: A
  10. How can you protect against XXE?
    A) Disable external entities B) Use weak passwords C) Ignore security D) Disable security
    Answer: A
  11. How can you protect against insecure deserialisation?
    A) Use secure deserialisation B) Use weak passwords C) Ignore security D) Disable security
    Answer: A
  12. What is the OWASP Top 10?
    A) A list of web vulnerabilities B) A type of malware C) A firewall D) A browser
    Answer: A
  13. What is a common API vulnerability?
    A) Broken object-level authorisation B) Strong passwords C) Good security D) Encryption
    Answer: A
  14. What should you do if you find a vulnerability?
    A) Report it B) Exploit it C) Ignore it D) Share it
    Answer: A
  15. Why do Nigerian companies need web security?
    A) To protect their data B) To make their websites faster C) To save money D) None
    Answer: A

🔗 Matching Exercise

TermMatch with
1. SSRFA. Exploits XML parsers
2. XXEB. Tricking a server into making requests
3. Insecure deserialisationC. Weakness in website rules
4. Business logic flawD. Turning unsafe data into objects
5. APIE. Way for websites to talk

Answers: 1-B, 2-A, 3-D, 4-C, 5-E

✏️ Short Answer Questions

  1. Explain the difference between SSRF and XXE.
  2. What is insecure deserialisation and why is it dangerous?
  3. How can you protect a web application from these attacks?

🎭 Scenario‑based Exercise

Scenario: You are an ethical hacker hired by a bank in Lagos. The bank's website has a feature that takes a URL input. You suspect it might be vulnerable to SSRF. What would you do?

👥 Group Activity

In groups of 4, create a poster that explains SSRF, XXE, and insecure deserialisation. Include examples and how to protect against them.

🧑‍💻 Individual Activity

Write a short essay on why web application security is important for Nigerian businesses.

💬 Classroom Discussion Questions

  • Why do you think advanced web vulnerabilities are so common?
  • How can we educate developers about these risks?
  • What would you do if you discovered a vulnerability in a website you use?

🛠️ Mini Project

Project: Create a security checklist for a web application. Include items for SSRF, XXE, deserialisation, and API security.

🔧 Practical Assignment

Research a real-world SSRF or XXE attack. Write a short report on what happened and how it could have been prevented.

⚡ Challenge Exercise

Research how to protect against insecure deserialisation in Java or Python. Write a one-page explanation.

✅ Quiz Answers (Selected)

  • Fill‑in‑the‑blank: 1) SSRF, 2) XXE, 3) Insecure deserialisation, 4) Business logic flaw, 5) API.
  • True/False: 1T, 2T, 3F, 4F, 5F.

🔑 Key Takeaways

  • SSRF tricks servers into making requests.
  • XXE exploits XML parsers to read files.
  • Insecure deserialisation can run malicious code.
  • Business logic flaws are weaknesses in website rules.
  • APIs need strong security.
  • Always validate input and use secure deserialisation.

🚀 Preparation for Module Four

In Module Four, we will learn about SQL injection and evasion techniques. We will explore advanced SQL injection, blind SQLi, and how to evade detection. Make sure you understand the web security concepts from this module.


🔥 You have completed Module Three of Level Three! Keep up the great work. 🔥

5

Module Four

Module Four · Ethical Hacking Level Three

🗄️ Module Four · Introduction to Ethical Hacking Level Three

Advanced SQL Injection & Evasion Techniques – becoming a master of database attacks.

📖 Module Introduction

Welcome to Module Four! In this module, we will learn about advanced SQL injection and evasion techniques. You already learned the basics of SQL injection in Level Two. Now we will go much deeper.

Think of SQL injection like a magic key that opens a door. In Level Two, you learned how to use the key. Now, in Level Three, you will learn how to make the key work even when there are locks, guards, and alarms.

We will explore blind SQL injection, out-of-band SQL injection, and many evasion techniques that hackers use to bypass security filters. By the end of this module, you will be able to find and exploit SQL injection vulnerabilities that most hackers miss.

🎯 Learning Objectives

By the end of this module, you will be able to:

  • Explain what advanced SQL injection is.
  • Understand blind SQL injection and how it works.
  • Learn about out-of-band SQL injection.
  • Understand time-based and error-based blind SQLi.
  • Learn about SQL injection evasion techniques.
  • Understand how to use sqlmap for advanced SQLi.
  • Apply these ideas to Nigerian schools, businesses, and homes.

📖 Warm‑up Story · The Secret Library

Once upon a time, in a school in Ibadan, there was a secret library that only teachers could enter. The library had a guard at the door. Students were not allowed inside.

One clever student named Chidi really wanted to see what was inside. He couldn't just walk in – the guard would stop him. So he found another way. He noticed that the library had a book return slot. He slipped a note through the slot that said, "Teacher Chidi needs to enter." The guard read the note and opened the door.

That is exactly what blind SQL injection is – you can't see the result directly, but you can use other clues to find what you need. In this module, we will learn how to use these "clues" to perform advanced SQL injection attacks.

📚 Main Lessons

Lesson 1 · What is Advanced SQL Injection?

Definition: Advanced SQL injection is the use of sophisticated techniques to exploit SQL injection vulnerabilities, even when security measures are in place.

Why it is important: Many websites have basic SQL injection protection. Advanced techniques help you bypass them.

Simple explanation: It's like using a special tool to pick a lock instead of just a regular key.

Real‑life example: A hacker uses advanced SQLi to bypass a web application firewall.

School example: A student uses advanced techniques to access the teacher's grade book.

Home example: A family member uses advanced SQLi to access a home server.

Nigerian example: A Nigerian bank might be attacked with advanced SQLi techniques.

Mini summary: Advanced SQLi bypasses security measures.

Lesson 2 · Blind SQL Injection

Definition: Blind SQL injection is when you don't see the results directly. You use other clues like error messages or time delays.

Why it is important: Many websites don't show errors. Blind SQLi helps you find vulnerabilities anyway.

Simple explanation: It's like trying to find out if a door is locked by listening for a sound.

Lesson 3 · Error-Based Blind SQLi

In error-based blind SQLi, you use error messages to gather information. If the website returns an error, you know the query worked.

Lesson 4 · Time-Based Blind SQLi

In time-based blind SQLi, you use time delays to gather information. If the response takes longer, you know the query worked.

Real‑life example: A hacker sends a query with a 10-second delay. If the response takes 10 seconds, they know it worked.

Lesson 5 · Boolean-Based Blind SQLi

In boolean-based blind SQLi, you use true/false questions. If the website responds differently to true and false, you know the answer.

Lesson 6 · Out-of-Band SQL Injection

Definition: Out-of-band SQL injection is when you use a different channel to get the results, like a DNS request.

Why it is important: Out-of-band SQLi works even when the website doesn't show errors.

Simple explanation: It's like sending a message in a secret code that only you can read.

Lesson 7 · SQL Injection Evasion Techniques

Evasion techniques help you bypass security filters. Here are some common ones:

  • Encoding: Using URL encoding, hex encoding, or base64.
  • Comments: Using comments to hide parts of the query.
  • Case variation: Changing uppercase to lowercase.
  • Spacing: Using tabs, newlines, or comments instead of spaces.
  • Alternate syntax: Using different ways to write the same thing.

Lesson 8 · Using sqlmap for Advanced SQLi

sqlmap is a tool that automates SQL injection. In Level Three, you will learn advanced features like:

  • Bypassing WAF (Web Application Firewalls).
  • Using custom evasion techniques.
  • Performing blind SQL injection automatically.

Lesson 9 · Bypassing Web Application Firewalls

WAFs are designed to block SQL injection. Hackers use techniques like:

  • Using obfuscation.
  • Using fragmentation.
  • Using special characters.

Lesson 10 · SQL Injection in Different Databases

Different databases (MySQL, PostgreSQL, Oracle, SQL Server) have different syntax. You need to know the differences.

Lesson 11 · Second-Order SQL Injection

Second-order SQL injection is when the attack is stored and executed later. It's harder to find and exploit.

Lesson 12 · Protecting Against Advanced SQLi

  • Use parameterised queries.
  • Use stored procedures.
  • Use input validation.
  • Use a WAF.

Lesson 13 · The Role of Ethical Hackers in SQLi

Ethical hackers find SQL injection vulnerabilities and help organisations fix them.

📖 Key Vocabulary (Simple Definitions)

WordSimple meaning
Blind SQLiSQL injection without visible results.
Error-based SQLiUsing error messages to gather info.
Time-based SQLiUsing time delays to gather info.
Boolean-based SQLiUsing true/false questions.
Out-of-band SQLiUsing a different channel for results.
EvasionBypassing security filters.
sqlmapA tool that automates SQL injection.
WAFWeb Application Firewall.
Parameterised queryA safe way to write SQL.
ObfuscationMaking something harder to understand.

🧠 Important Concepts

  • Input validation: Always check what users send.
  • Parameterised queries: Use them to prevent SQLi.
  • Least privilege: Give the database only the access it needs.
  • Defence in depth: Use many layers of security.

🔢 Step‑by‑Step: How a Time-Based Blind SQLi Works

  1. Hacker finds a vulnerable input field.
  2. Hacker sends a query with a 10-second delay.
  3. If the response takes 10 seconds, the query worked.
  4. Hacker uses this to ask true/false questions.
  5. Hacker gradually extracts information.

🌍 Real‑life Examples

1. E-commerce: Hackers use blind SQLi to steal customer data.

2. Government: Hackers use advanced SQLi to access classified information.

🇳🇬 Nigerian Examples

  • A Nigerian bank uses parameterised queries to prevent SQLi.
  • A Nigerian e‑commerce site tests for blind SQLi.
  • A Nigerian ethical hacker uses sqlmap to test a company's website.

🎈 Fun Examples for Kids

  • Imagine you're playing a game where you ask yes/no questions. If the game responds differently, you learn something. That's boolean-based blind SQLi.
  • Blind SQLi is like asking a friend a question, and they only respond by blinking once for yes and twice for no.

🏡 Everyday Examples

  • If you try to guess a password and the computer pauses before saying "incorrect", that could be a time-based clue.
  • If you ask someone a question and they look at their watch before answering, that could give you a clue.

👩‍🏫 Teacher Notes

Use the secret library story to introduce blind SQLi. Emphasise that advanced SQLi requires patience and skill. Encourage students to think about how they can protect their own databases.

👪 Parent Tips

  • Teach your child to be careful about what they enter on websites.
  • Explain why websites need to protect their databases.
  • Show them how to check if a website is secure.

✨ Interesting Facts

💡 SQL injection was first discovered in 1998.
💡 sqlmap was created in 2006 and is still used today.

❓ Did You Know?

🔹 Many Nigerian companies use WAFs to protect against SQLi.
🔹 Blind SQL injection can take hours or days to exploit fully.

🧾 Remember This

⚠️ Always validate user input.
🔒 Use parameterised queries to prevent SQLi.
📱 Use a WAF for extra protection.

❌ Common Mistakes

  • Not validating user input.
  • Using dynamic SQL queries.
  • Not using a WAF.
  • Not testing for blind SQLi.

✅ Best Practices

  • Use parameterised queries.
  • Use stored procedures.
  • Use input validation.
  • Use a WAF.
  • Regularly test for SQLi.

📊 ASCII Illustrations & Flowcharts

Blind SQLi Process

    Send query  ---->  Observe response
          |                      |
          v                      v
    If response matches  ---->  Gather information
          |
          v
    Repeat for each piece of data
    

Time-Based Blind SQLi

    Send query with delay  ---->  Wait for response
          |                         |
          v                         v
    If delayed  ---->  Query succeeded  ---->  Gather info
    

Evasion Techniques

    Encoding  ---->  URL encode, hex encode
    Comments  ---->  Hide parts of query
    Case variation  ---->  Change uppercase/lowercase
    Spacing  ---->  Use tabs, newlines
    Alternate syntax  ---->  Different ways to write
    

📋 Comparison Table: Types of Blind SQLi

TypeHow it worksDifficulty
Error-basedUses error messagesEasy
Time-basedUses time delaysMedium
Boolean-basedUses true/falseMedium
Out-of-bandUses different channelHard

📋 Comparison Table: Level Two vs Level Three SQLi

Level TwoLevel Three
Basic SQLiAdvanced SQLi
Union-basedBlind SQLi
Error-basedOut-of-band SQLi
Simple evasionAdvanced evasion

📌 Lesson Summaries

  • Lesson 1: Advanced SQLi bypasses security measures.
  • Lesson 2: Blind SQLi uses clues instead of direct results.
  • Lesson 3: Error-based SQLi uses error messages.
  • Lesson 4: Time-based SQLi uses time delays.
  • Lesson 5: Boolean-based SQLi uses true/false.
  • Lesson 6: Out-of-band SQLi uses a different channel.
  • Lesson 7: Evasion techniques bypass security filters.
  • Lesson 8: sqlmap automates advanced SQLi.
  • Lesson 9: WAFs can be bypassed with advanced techniques.
  • Lesson 10: Different databases have different syntax.
  • Lesson 11: Second-order SQLi is stored and executed later.
  • Lesson 12: Use parameterised queries to protect against SQLi.
  • Lesson 13: Ethical hackers find and fix SQLi vulnerabilities.

📝 End‑of‑Module Summary

In Module Four, we learned about advanced SQL injection and evasion techniques. We explored blind SQL injection, time-based, boolean-based, and out-of-band attacks. We also learned about evasion techniques and how to use sqlmap for advanced testing. Remember, SQL injection is one of the most dangerous vulnerabilities. By understanding it, we can better protect our systems.

❓ Frequently Asked Questions (10)

  1. Q: What is blind SQL injection?
    A: SQL injection without visible results.
  2. Q: What is time-based blind SQLi?
    A: Using time delays to gather info.
  3. Q: What is boolean-based blind SQLi?
    A: Using true/false questions.
  4. Q: What is out-of-band SQLi?
    A: Using a different channel for results.
  5. Q: What are evasion techniques?
    A: Bypassing security filters.
  6. Q: What is sqlmap?
    A: A tool that automates SQL injection.
  7. Q: What is a WAF?
    A: Web Application Firewall.
  8. Q: How can I protect against SQLi?
    A: Use parameterised queries.
  9. Q: What is second-order SQLi?
    A: Stored and executed later.
  10. Q: Can ethical hackers use sqlmap?
    A: Yes, with permission.

📌 Review Questions (15)

  1. What is advanced SQL injection?
  2. What is blind SQL injection?
  3. What is time-based blind SQLi?
  4. What is boolean-based blind SQLi?
  5. What is out-of-band SQLi?
  6. What are evasion techniques?
  7. What is sqlmap?
  8. What is a WAF?
  9. How can you protect against SQLi?
  10. What is second-order SQLi?
  11. What is the difference between error-based and time-based SQLi?
  12. How does encoding help with evasion?
  13. What is the OWASP Top 10?
  14. Why are Nigerian businesses at risk from SQLi?
  15. What should you do if you find a SQLi vulnerability?

✍️ Fill‑in‑the‑Blank

  1. ________ is SQL injection without visible results.
  2. ________ uses time delays to gather information.
  3. ________ uses true/false questions.
  4. ________ uses a different channel for results.
  5. ________ is a tool that automates SQL injection.

✔️ True or False

  1. Blind SQL injection shows results directly. (False)
  2. Time-based SQLi uses time delays. (True)
  3. Boolean-based SQLi uses true/false questions. (True)
  4. Out-of-band SQLi uses a different channel. (True)
  5. sqlmap is a game. (False)

🔘 Multiple Choice Questions

  1. What is blind SQL injection?
    A) Without visible results B) With visible results C) A type of malware D) A firewall
    Answer: A
  2. What is time-based blind SQLi?
    A) Using time delays B) Using error messages C) Using true/false D) Using a different channel
    Answer: A
  3. What is boolean-based blind SQLi?
    A) Using true/false questions B) Using time delays C) Using error messages D) Using a different channel
    Answer: A
  4. What is out-of-band SQLi?
    A) Using a different channel B) Using time delays C) Using error messages D) Using true/false
    Answer: A
  5. What are evasion techniques?
    A) Bypassing security filters B) A type of malware C) A firewall D) A browser
    Answer: A
  6. What is sqlmap?
    A) A tool that automates SQLi B) A type of malware C) A firewall D) A browser
    Answer: A
  7. What is a WAF?
    A) Web Application Firewall B) A type of malware C) A firewall D) A browser
    Answer: A
  8. How can you protect against SQLi?
    A) Use parameterised queries B) Use weak passwords C) Ignore security D) Disable security
    Answer: A
  9. What is second-order SQLi?
    A) Stored and executed later B) A type of malware C) A firewall D) A browser
    Answer: A
  10. What is the OWASP Top 10?
    A) A list of web vulnerabilities B) A type of malware C) A firewall D) A browser
    Answer: A
  11. What is the difference between error-based and time-based SQLi?
    A) Error-based uses errors; time-based uses delays B) They are the same C) Error-based is harder D) Time-based is easier
    Answer: A
  12. How does encoding help with evasion?
    A) It hides the attack B) It makes it faster C) It makes it louder D) It doesn't help
    Answer: A
  13. What should you do if you find a SQLi vulnerability?
    A) Report it B) Exploit it C) Ignore it D) Share it
    Answer: A
  14. Why are Nigerian businesses at risk from SQLi?
    A) They may not have proper security B) They have strong security C) They are not at risk D) None
    Answer: A
  15. What is the most dangerous type of SQLi?
    A) Blind SQLi B) Error-based C) Union-based D) They are all dangerous
    Answer: D

🔗 Matching Exercise

TermMatch with
1. Blind SQLiA. Uses time delays
2. Time-basedB. Without visible results
3. Boolean-basedC. Uses true/false
4. Out-of-bandD. Uses different channel
5. sqlmapE. Automates SQLi

Answers: 1-B, 2-A, 3-C, 4-D, 5-E

✏️ Short Answer Questions

  1. Explain the difference between time-based and boolean-based blind SQLi.
  2. What is out-of-band SQL injection and when is it used?
  3. How can you protect a website from SQL injection?

🎭 Scenario‑based Exercise

Scenario: You are an ethical hacker hired by a bank in Abuja. The bank's website has a login form. You suspect it might be vulnerable to SQL injection. However, the website shows no errors. How would you test for blind SQL injection?

👥 Group Activity

In groups of 4, create a poster that explains the different types of blind SQL injection. Include examples and how to test for each.

🧑‍💻 Individual Activity

Write a short essay on why SQL injection is still a major threat to Nigerian businesses.

💬 Classroom Discussion Questions

  • Why do you think SQL injection is still so common?
  • How can we educate developers about SQL injection?
  • What would you do if you found a SQL injection vulnerability in a website you use?

🛠️ Mini Project

Project: Create a guide on how to prevent SQL injection. Include examples of parameterised queries and input validation.

🔧 Practical Assignment

Research a real-world SQL injection attack. Write a short report on what happened and how it could have been prevented.

⚡ Challenge Exercise

Research how sqlmap works. Write a one-page explanation and describe how it can be used for ethical testing.

✅ Quiz Answers (Selected)

  • Fill‑in‑the‑blank: 1) Blind SQLi, 2) Time-based, 3) Boolean-based, 4) Out-of-band, 5) sqlmap.
  • True/False: 1F, 2T, 3T, 4T, 5F.

🔑 Key Takeaways

  • Advanced SQLi bypasses security measures.
  • Blind SQLi uses clues instead of direct results.
  • Time-based, boolean-based, and out-of-band are types of blind SQLi.
  • Evasion techniques help bypass security filters.
  • sqlmap automates advanced SQL injection.
  • Always use parameterised queries to protect against SQLi.

🚀 Preparation for Module Five

In Module Five, we will learn about evading IDS, firewalls, and honeypots. We will explore how hackers bypass these security systems and how to protect against them. Make sure you understand the SQL injection concepts from this module.


🔥 You have completed Module Four of Level Three! Keep up the great work. 🔥

6

Module Five

Module Five · Ethical Hacking Level Three

🛡️ Module Five · Introduction to Ethical Hacking Level Three

Evading IDS, Firewalls, and Honeypots – becoming invisible to security systems.

📖 Module Introduction

Welcome to Module Five! In this module, we will learn about evading IDS, firewalls, and honeypots. These are the security systems that protect networks. Hackers need to bypass them to carry out attacks.

Think of it like a game of hide and seek. The IDS (Intrusion Detection System) and firewall are the seekers. The hacker is the hider. We will learn how hackers hide and how defenders can find them.

We will explore fragmentation, protocol manipulation, encryption evasion, and honeypot detection. By the end of this module, you will understand how hackers avoid detection and how to protect against these techniques.

🎯 Learning Objectives

By the end of this module, you will be able to:

  • Explain what IDS, IPS, and firewalls are.
  • Understand how hackers evade detection.
  • Learn about fragmentation and packet splitting.
  • Understand protocol manipulation.
  • Learn about encryption evasion.
  • Understand honeypot detection.
  • Apply these ideas to Nigerian schools, businesses, and homes.

📖 Warm‑up Story · The Invisible Thief

Once upon a time, in a village in Oyo State, there was a thief named Bola. He was very good at stealing, but the village had guards everywhere. The guards watched all the entrances.

Bola had a clever idea. He didn't try to go through the main gate. Instead, he found a hole in the fence. He climbed through the hole, stole what he wanted, and climbed back out. The guards never saw him.

That is exactly what evasion is – finding a way to bypass security systems. In this module, we will learn how hackers find the "holes" in security systems and how to patch them.

📚 Main Lessons

Lesson 1 · What are IDS, IPS, and Firewalls?

Definition: An IDS (Intrusion Detection System) watches for suspicious activity. An IPS (Intrusion Prevention System) blocks it. A firewall filters network traffic.

Why they are important: They are the first line of defence against hackers.

Simple explanation: An IDS is like a security camera. An IPS is like a guard who stops intruders. A firewall is like a locked door.

Real‑life example: A company uses an IDS to detect hackers and a firewall to block unwanted traffic.

School example: A school uses a firewall to block bad websites.

Home example: A family uses a firewall on their router.

Nigerian example: A Nigerian bank uses an IPS to block attacks.

Mini summary: IDS watches, IPS blocks, firewalls filter.

Lesson 2 · Why Hackers Evade Security Systems

Hackers evade security systems to:

  • Bypass firewalls.
  • Hide their activities.
  • Stay inside a system longer.
  • Avoid getting caught.

Lesson 3 · Fragmentation – Splitting Packets

Definition: Fragmentation is breaking data into small pieces. Hackers use it to split malicious packets so IDS might not detect them.

Why it is important: Some IDS only look at whole packets. If a hacker splits the packet, the IDS might miss it.

Simple explanation: It's like hiding a message by writing one word on each of 10 different pieces of paper.

Real‑life example: A hacker splits a malicious payload into many small packets.

School example: A student sends a message in parts to avoid the teacher seeing it.

Home example: A family member sends a file in parts to avoid detection.

Nigerian example: A Nigerian hacker uses fragmentation to bypass a bank's IDS.

Mini summary: Fragmentation splits data to avoid detection.

Lesson 4 · How Fragmentation Works

Hackers split their attack into many small packets. The IDS might not see the full picture until it's too late.

Lesson 5 · Protocol Manipulation

Definition: Protocol manipulation is changing how data is sent to avoid detection. For example, using a different port or header.

Simple explanation: It's like using a secret knock instead of a doorbell.

Real‑life example: A hacker uses port 80 (for web traffic) to send malicious data.

Lesson 6 · Encryption Evasion

Definition: Hackers use encryption to hide their malicious data. Since the data is scrambled, security systems can't read it.

Why it is dangerous: Encryption is good for privacy, but hackers use it to hide their attacks.

Simple explanation: It's like speaking in a secret code that the guards don't understand.

Lesson 7 · IP Spoofing – Faking the Source

Definition: IP spoofing is faking the source IP address to hide the hacker's real location.

Simple explanation: It's like wearing a mask so the security cameras don't recognise you.

Lesson 8 · Proxy Chaining

Hackers use multiple proxies to hide their real location. Each proxy adds another layer of hiding.

Lesson 9 · Honeypots – The Trap

Definition: A honeypot is a fake system designed to trap hackers. It looks real but is actually monitored.

Why it is important: Honeypots help catch hackers and learn their techniques.

Simple explanation: It's like leaving a fake treasure chest to catch a thief.

Real‑life example: A company sets up a honeypot to catch hackers.

School example: A school sets up a fake student portal to catch cheaters.

Home example: A family sets up a fake network to catch hackers.

Nigerian example: A Nigerian bank uses honeypots to catch cybercriminals.

Mini summary: Honeypots are traps for hackers.

Lesson 10 · Detecting Honeypots

Hackers try to detect honeypots by looking for signs like unusual network behaviour or fake data.

Lesson 11 · Countermeasures Against Evasion

  • Use stateful firewalls.
  • Use deep packet inspection.
  • Use anomaly-based detection.
  • Use honeypots to catch hackers.

Lesson 12 · The Role of Ethical Hackers

Ethical hackers use evasion techniques to test security systems. They help find weaknesses and fix them.

📖 Key Vocabulary (Simple Definitions)

WordSimple meaning
IDSIntrusion Detection System – watches for attacks.
IPSIntrusion Prevention System – blocks attacks.
FirewallA system that filters network traffic.
FragmentationSplitting data into small pieces.
Protocol manipulationChanging how data is sent.
Encryption evasionUsing encryption to hide attacks.
IP spoofingFaking the source IP address.
Proxy chainingUsing multiple proxies to hide location.
HoneypotA trap for hackers.
Deep packet inspectionChecking the contents of packets.

🧠 Important Concepts

  • Defence in depth: Using many layers of security.
  • Stateful firewall: Remembers the state of connections.
  • Anomaly-based detection: Looks for unusual behaviour.
  • Signature-based detection: Looks for known attack patterns.

🔢 Step‑by‑Step: How a Fragmentation Attack Works

  1. Hacker creates a malicious packet.
  2. Hacker splits it into many small fragments.
  3. Each fragment is sent separately.
  4. The IDS might miss the attack because it doesn't see the whole packet.
  5. The fragments are reassembled at the target and executed.

🌍 Real‑life Examples

1. Banking: Hackers use fragmentation to bypass a bank's IDS.

2. Government: Hackers use encryption evasion to hide their activities.

🇳🇬 Nigerian Examples

  • A Nigerian bank uses deep packet inspection to stop fragmentation attacks.
  • A Nigerian university uses honeypots to catch hackers.
  • A Nigerian company uses a stateful firewall to block attacks.

🎈 Fun Examples for Kids

  • Imagine a game of hide and seek. Evasion is like hiding behind a curtain. Countermeasures are like the seeker knowing all the hiding spots.
  • Fragmentation is like writing a message on a puzzle and sending the pieces separately.

🏡 Everyday Examples

  • Your home router has a firewall – that's a security system.
  • If you use a VPN to hide your browsing, that's an evasion technique.

👩‍🏫 Teacher Notes

Use the invisible thief story to introduce evasion. Emphasise that ethical hackers use these techniques to test security. Encourage students to think about how they can protect their own systems.

👪 Parent Tips

  • Teach your child to keep software updated.
  • Explain why firewalls are important.
  • Show them how to check for suspicious activity on their devices.

✨ Interesting Facts

💡 The first IDS was developed in 1987.
💡 Many advanced hackers use multiple evasion techniques together.

❓ Did You Know?

🔹 Nigerian companies are increasingly using IPS to stop evasive attacks.
🔹 Some hackers use "packet fragmentation" to bypass firewalls.

🧾 Remember This

⚠️ Hackers use evasion to hide from security.
🔒 Defenders use countermeasures to stop them.
📱 Always keep your security tools updated.

❌ Common Mistakes

  • Thinking that one security tool is enough.
  • Not updating IDS/IPS signatures.
  • Ignoring unusual network activity.
  • Not using encryption for sensitive data.

✅ Best Practices

  • Use multiple layers of security (defence in depth).
  • Keep IDS/IPS signatures updated.
  • Monitor network traffic regularly.
  • Use encryption to protect data.

📊 ASCII Illustrations & Flowcharts

Evasion Techniques Overview

    Hacker Attack
          |
          v
    Evasion Techniques
    (fragmentation, encryption, spoofing)
          |
          v
    Security Systems
    (IDS, IPS, Firewall)
          |
          v
    Detected or Evaded?
    

Fragmentation Attack

    Full Packet  ---->  Split into fragments
                              |
                              v
    Send fragments separately  ---->  IDS misses
                              |
                              v
    Reassemble at target  ---->  Attack succeeds
    

Honeypot Detection

    Hacker probes network
          |
          v
    Detects honeypot (unusual behaviour)
          |
          v
    Avoids honeypot
    

📋 Comparison Table: IDS vs IPS

IDSIPS
Detects attacksDetects and blocks attacks
Passive monitoringActive prevention
Alerts adminBlocks automatically

📋 Comparison Table: Evasion Techniques

TechniqueHow it works
FragmentationSplits data into small pieces
EncryptionScrambles data
Protocol ManipulationChanges how data is sent
IP SpoofingFakes the source IP
Proxy ChainingHides location through multiple proxies

📌 Lesson Summaries

  • Lesson 1: IDS watches, IPS blocks, firewalls filter.
  • Lesson 2: Hackers evade to bypass security.
  • Lesson 3: Fragmentation splits data to avoid detection.
  • Lesson 4: Fragmentation sends pieces separately.
  • Lesson 5: Protocol manipulation changes data transmission.
  • Lesson 6: Encryption hides malicious data.
  • Lesson 7: IP spoofing fakes the source.
  • Lesson 8: Proxy chaining hides location.
  • Lesson 9: Honeypots are traps for hackers.
  • Lesson 10: Hackers try to detect honeypots.
  • Lesson 11: Use deep packet inspection and anomaly detection.
  • Lesson 12: Ethical hackers test and improve security.

📝 End‑of‑Module Summary

In Module Five, we learned about evading IDS, firewalls, and honeypots. We explored fragmentation, protocol manipulation, encryption evasion, and IP spoofing. We also learned about honeypots and how hackers try to detect them. Remember, the game between attackers and defenders is always changing. By understanding both sides, we can better protect our systems.

❓ Frequently Asked Questions (10)

  1. Q: What is an IDS?
    A: Intrusion Detection System – watches for attacks.
  2. Q: What is an IPS?
    A: Intrusion Prevention System – blocks attacks.
  3. Q: What is a firewall?
    A: A system that filters network traffic.
  4. Q: What is fragmentation?
    A: Splitting data into small pieces.
  5. Q: What is protocol manipulation?
    A: Changing how data is sent.
  6. Q: What is encryption evasion?
    A: Using encryption to hide attacks.
  7. Q: What is IP spoofing?
    A: Faking the source IP address.
  8. Q: What is a honeypot?
    A: A trap for hackers.
  9. Q: How can you stop evasion?
    A: Use deep packet inspection and anomaly detection.
  10. Q: Can ethical hackers use evasion?
    A: Yes, with permission.

📌 Review Questions (15)

  1. What is an IDS?
  2. What is an IPS?
  3. What is a firewall?
  4. What is fragmentation?
  5. How does fragmentation help hackers?
  6. What is protocol manipulation?
  7. What is encryption evasion?
  8. What is IP spoofing?
  9. What is proxy chaining?
  10. What is a honeypot?
  11. How do hackers detect honeypots?
  12. What is deep packet inspection?
  13. What is anomaly-based detection?
  14. What is defence in depth?
  15. How do Nigerian companies stop evasion?

✍️ Fill‑in‑the‑Blank

  1. ________ watches for attacks.
  2. ________ blocks attacks.
  3. ________ splits data into small pieces.
  4. ________ is a trap for hackers.
  5. ________ fakes the source IP address.

✔️ True or False

  1. An IDS blocks attacks. (False)
  2. An IPS blocks attacks. (True)
  3. Fragmentation splits data into pieces. (True)
  4. A honeypot is a real system. (False)
  5. Encryption can be used to hide attacks. (True)

🔘 Multiple Choice Questions

  1. What is an IDS?
    A) Watches for attacks B) Blocks attacks C) Filters traffic D) A type of malware
    Answer: A
  2. What is an IPS?
    A) Blocks attacks B) Watches for attacks C) Filters traffic D) A type of malware
    Answer: A
  3. What is a firewall?
    A) Filters traffic B) Watches for attacks C) Blocks attacks D) A type of malware
    Answer: A
  4. What is fragmentation?
    A) Splitting data B) Encrypting data C) Faking IPs D) Using proxies
    Answer: A
  5. What is protocol manipulation?
    A) Changing how data is sent B) Splitting data C) Encrypting data D) Faking IPs
    Answer: A
  6. What is encryption evasion?
    A) Using encryption to hide attacks B) Splitting data C) Faking IPs D) Using proxies
    Answer: A
  7. What is IP spoofing?
    A) Faking the source IP B) Splitting data C) Encrypting data D) Using proxies
    Answer: A
  8. What is proxy chaining?
    A) Using multiple proxies B) Splitting data C) Encrypting data D) Faking IPs
    Answer: A
  9. What is a honeypot?
    A) A trap for hackers B) A type of malware C) A firewall D) A browser
    Answer: A
  10. How can you stop fragmentation attacks?
    A) Use deep packet inspection B) Ignore them C) Disable security D) Use weak passwords
    Answer: A
  11. What is deep packet inspection?
    A) Checking packet contents B) Splitting packets C) Encrypting packets D) Faking packets
    Answer: A
  12. What is anomaly-based detection?
    A) Looking for unusual behaviour B) Looking for known patterns C) Splitting packets D) Encrypting packets
    Answer: A
  13. What is defence in depth?
    A) Using multiple security layers B) Using one security layer C) No security D) Weak security
    Answer: A
  14. Why do Nigerian companies use IPS?
    A) To stop attacks B) To allow attacks C) To save money D) None
    Answer: A
  15. What is the best way to stop evasion?
    A) Use multiple security layers B) Use one tool C) Ignore attacks D) Disable security
    Answer: A

🔗 Matching Exercise

TermMatch with
1. IDSA. Blocks attacks
2. IPSB. Watches for attacks
3. FirewallC. Splitting data
4. FragmentationD. Filters traffic
5. HoneypotE. Trap for hackers

Answers: 1-B, 2-A, 3-D, 4-C, 5-E

✏️ Short Answer Questions

  1. Explain the difference between IDS and IPS.
  2. How does fragmentation help hackers evade detection?
  3. What is a honeypot and how is it used?

🎭 Scenario‑based Exercise

Scenario: You are an ethical hacker hired by a bank in Lagos. You discover that hackers are using fragmentation to bypass the bank's IDS. What would you recommend?

👥 Group Activity

In groups of 4, create a poster that explains evasion techniques and how to stop them. Include examples of fragmentation, encryption, and IP spoofing.

🧑‍💻 Individual Activity

Write a short essay on why defence in depth is important for Nigerian businesses.

💬 Classroom Discussion Questions

  • Why do you think hackers use evasion techniques?
  • How can we improve security to detect evasion?
  • What would you do if you suspected someone was using evasion on your network?

🛠️ Mini Project

Project: Create a security plan that includes countermeasures for evasion techniques. Include IDS/IPS, firewalls, and detection strategies.

🔧 Practical Assignment

Research how a modern IDS/IPS works. Write a short report and include examples of how it detects evasion techniques.

⚡ Challenge Exercise

Research how packet fragmentation can be used to evade detection. Write a one-page explanation and describe how to stop it.

✅ Quiz Answers (Selected)

  • Fill‑in‑the‑blank: 1) IDS, 2) IPS, 3) Fragmentation, 4) Honeypot, 5) IP spoofing.
  • True/False: 1F, 2T, 3T, 4F, 5T.

🔑 Key Takeaways

  • IDS watches, IPS blocks, firewalls filter traffic.
  • Fragmentation, encryption, and IP spoofing are common evasion techniques.
  • Honeypots are traps for hackers.
  • Deep packet inspection and anomaly detection stop evasion.
  • Defence in depth is essential for good security.
  • Ethical hackers use evasion techniques to test and improve security.

🚀 Preparation for Module Six

In Module Six, we will learn about session hijacking and DoS attacks. We will explore how hackers steal sessions and launch denial-of-service attacks. Make sure you understand the evasion concepts from this module.


🔥 You have completed Module Five of Level Three! Keep up the great work. 🔥

7

Module SIx

Module Six · Ethical Hacking Level Three

🔀 Module Six · Introduction to Ethical Hacking Level Three

Session Hijacking & DoS Attacks – stealing identities and breaking systems.

📖 Module Introduction

Welcome to Module Six! In this module, we will learn about session hijacking and Denial of Service (DoS) attacks. These are attacks that either steal your identity or make websites unavailable.

Think of session hijacking like someone stealing your ID card and pretending to be you. They can do everything you can do – change your password, read your messages, and even spend your money.

Think of DoS attacks like a crowd of people blocking the entrance to a shop. No one else can get in. The shop is not broken – it's just overwhelmed.

We will learn how these attacks work and how to protect against them. By the end of this module, you will understand how to keep your sessions safe and how to prevent DoS attacks.

🎯 Learning Objectives

By the end of this module, you will be able to:

  • Explain what session hijacking is.
  • Understand application-level and network-level hijacking.
  • Learn about DoS and DDoS attacks.
  • Understand common DoS techniques.
  • Learn about session fixation and prediction.
  • Understand how to protect against these attacks.
  • Apply these ideas to Nigerian schools, businesses, and homes.

📖 Warm‑up Story · The Stolen ID Card

Once upon a time, in a school in Abuja, there was a student named Zainab. She had an ID card that let her access the library, the computer lab, and even the staff room.

One day, a clever student named Emeka wanted to get into the staff room. He couldn't get his own ID card, so he watched Zainab. He noticed that she often left her ID card on her desk. One day, he took it, copied it, and put it back.

Now Emeka could pretend to be Zainab. He could go anywhere she could go. He had stolen her identity. That is exactly what session hijacking is – stealing someone's identity to access their accounts.

Now imagine hundreds of students all trying to enter the computer lab at the same time. The teacher can't open the door because there are too many people. That's a Denial of Service attack – overwhelming a system so it can't work properly.

📚 Main Lessons

Lesson 1 · What is Session Hijacking?

Definition: Session hijacking is when a hacker steals a user's session ID and pretends to be that user.

Why it is important: Once a hacker hijacks a session, they can do anything the user can do – like checking email, transferring money, or changing passwords.

Simple explanation: It's like someone stealing your ID card and pretending to be you.

Real‑life example: A hacker steals your session token from a banking website and logs in as you.

School example: A student steals another student's login cookie and accesses their grades.

Home example: A family member steals your session on a shopping website and buys things with your account.

Nigerian example: A hacker in Nigeria steals a session token from a bank's website.

Mini summary: Session hijacking steals a user's identity.

Lesson 2 · How Sessions Work

When you log into a website, the server gives you a session ID. This ID is like a ticket that proves you are logged in. Every time you make a request, you show your ticket.

Lesson 3 · Application-Level Session Hijacking

Application-level hijacking targets the session ID itself. Hackers steal the session token through:

  • XSS (Cross-Site Scripting): Injecting scripts to steal cookies.
  • Session fixation: Forcing a user to use a known session ID.
  • Session prediction: Guessing a session ID.

Lesson 4 · Network-Level Session Hijacking

Network-level hijacking targets the communication between the user and the server. Hackers use:

  • Packet sniffing: Listening to network traffic.
  • Man-in-the-Middle (MITM): Intercepting communication.
  • ARP spoofing: Tricking the network.

Lesson 5 · Session Fixation

Definition: Session fixation is when a hacker sets a user's session ID to a known value, then uses that value to log in as the user.

Simple explanation: It's like giving someone a ticket to a show, but keeping a copy of the same ticket.

Lesson 6 · Session Prediction

Definition: Session prediction is when a hacker guesses a valid session ID. If the session IDs are predictable, the hacker can guess them.

Simple explanation: It's like guessing someone's password because it's based on their birthday.

Lesson 7 · What is a Denial of Service (DoS) Attack?

Definition: A DoS attack is when a hacker makes a system unavailable to users.

Why it is dangerous: DoS attacks can stop businesses from working, causing financial losses.

Simple explanation: It's like a crowd blocking the entrance to a shop – no one can get in.

Real‑life example: A hacker sends so many requests to a website that it crashes.

School example: Many students try to access the school portal at the same time, slowing it down.

Home example: A family member downloads a huge file, slowing down the internet for everyone.

Nigerian example: A Nigerian bank's website is attacked with a DoS attack, stopping customers from banking.

Mini summary: DoS attacks make systems unavailable.

Lesson 8 · DDoS – Distributed Denial of Service

Definition: DDoS is a DoS attack that comes from many computers at the same time. Hackers use botnets (networks of infected computers).

Simple explanation: It's like a crowd coming from all directions, blocking every entrance.

Lesson 9 · Common DoS Techniques

  • SYN Flood: Sending many connection requests.
  • UDP Flood: Sending many UDP packets.
  • HTTP Flood: Sending many HTTP requests.
  • ICMP Flood: Sending many ping requests.

Lesson 10 · Botnets – The Hacker's Army

A botnet is a network of infected computers that hackers use to launch DDoS attacks. Each computer is called a "bot".

Lesson 11 · Protecting Against Session Hijacking

  • Use HTTPS to encrypt traffic.
  • Use secure cookies (HttpOnly, Secure flags).
  • Regenerate session IDs after login.
  • Use short session timeouts.
  • Use multi-factor authentication.

Lesson 12 · Protecting Against DoS Attacks

  • Use rate limiting.
  • Use load balancers.
  • Use DDoS protection services.
  • Monitor network traffic.

Lesson 13 · The Role of Ethical Hackers

Ethical hackers test for session hijacking and DoS vulnerabilities to help organisations protect themselves.

📖 Key Vocabulary (Simple Definitions)

WordSimple meaning
Session IDA ticket that proves you are logged in.
Session hijackingStealing a user's session ID.
Session fixationSetting a user's session ID to a known value.
Session predictionGuessing a session ID.
DoSDenial of Service – making a system unavailable.
DDoSDistributed DoS from many computers.
BotnetA network of infected computers.
SYN FloodSending many connection requests.
UDP FloodSending many UDP packets.
HTTP FloodSending many HTTP requests.

🧠 Important Concepts

  • Encryption: Protects data from being intercepted.
  • Authentication: Verifies a user's identity.
  • Rate limiting: Limits the number of requests.
  • Load balancing: Distributes traffic across servers.

🔢 Step‑by‑Step: How a DDoS Attack Works

  1. Hacker infects many computers with malware to create a botnet.
  2. Hacker uses the botnet to send millions of requests to a target.
  3. The target's servers become overwhelmed.
  4. Legitimate users can't access the target.
  5. The target may crash or slow down.

🌍 Real‑life Examples

1. Banking: A bank's website is hit with a DDoS attack, stopping customers from banking.

2. Gaming: A game server is attacked with a DDoS, making it unplayable.

🇳🇬 Nigerian Examples

  • A Nigerian bank uses DDoS protection services.
  • A Nigerian university uses rate limiting to prevent DoS.
  • A Nigerian company uses load balancers to distribute traffic.

🎈 Fun Examples for Kids

  • Imagine someone steals your movie ticket and goes to the show instead of you – that's session hijacking.
  • Imagine a group of people standing in the school doorway, blocking everyone else – that's a DoS attack.

🏡 Everyday Examples

  • If someone steals your Wi‑Fi password and uses it, that's like session hijacking.
  • If too many people try to use your Wi‑Fi at once, it slows down – that's a mini DoS.

👩‍🏫 Teacher Notes

Use the stolen ID card story to introduce session hijacking. Emphasise the importance of encryption and multi-factor authentication. Encourage students to think about how they can protect their own sessions.

👪 Parent Tips

  • Teach your child to log out of websites after use.
  • Explain why HTTPS is important.
  • Show them how to recognise suspicious activity.

✨ Interesting Facts

💡 The largest DDoS attack recorded was over 2 Tbps.
💡 Session hijacking was first discovered in the 1990s.

❓ Did You Know?

🔹 Many Nigerian companies use DDoS protection services like Cloudflare.
🔹 Botnets can be used to launch attacks without the owners knowing.

🧾 Remember This

⚠️ Always log out of websites when you're done.
🔒 Use HTTPS and multi-factor authentication.
📱 Be careful about what you click on.

❌ Common Mistakes

  • Not logging out of websites.
  • Using unsecured networks.
  • Not using multi-factor authentication.
  • Not using DDoS protection.

✅ Best Practices

  • Always use HTTPS.
  • Use multi-factor authentication.
  • Log out of websites.
  • Use DDoS protection services.
  • Monitor network traffic.

📊 ASCII Illustrations & Flowcharts

Session Hijacking Attack

    User logs in  ---->  Server issues session ID
          |                      |
          v                      v
    Hacker steals session ID  ---->  Hacker pretends to be user
          |                      |
          v                      v
    Hacker accesses user's account
    

DDoS Attack

    Hacker controls botnet
          |
          v
    Sends millions of requests
          |
          v
    Target server overwhelmed
          |
          v
    Legitimate users blocked
    

SYN Flood Attack

    Hacker sends SYN packets
          |
          v
    Server waits for ACK
          |
          v
    Server resources exhausted
          |
          v
    Server crashes
    

📋 Comparison Table: Session Hijacking vs DoS

Session HijackingDoS/DDoS
Steals user identityMakes systems unavailable
Targets specific userTargets whole system
Requires stealthOften loud and obvious
Used for theftUsed for disruption

📋 Comparison Table: DoS vs DDoS

DoSDDoS
From one computerFrom many computers
Easier to stopHarder to stop
Less powerfulMore powerful
Uses one IP addressUses many IP addresses

📌 Lesson Summaries

  • Lesson 1: Session hijacking steals a user's identity.
  • Lesson 2: Sessions use IDs to track users.
  • Lesson 3: Application-level hijacking targets session IDs.
  • Lesson 4: Network-level hijacking targets communication.
  • Lesson 5: Session fixation sets a known session ID.
  • Lesson 6: Session prediction guesses session IDs.
  • Lesson 7: DoS attacks make systems unavailable.
  • Lesson 8: DDoS uses many computers.
  • Lesson 9: SYN floods, UDP floods, and HTTP floods are common.
  • Lesson 10: Botnets are networks of infected computers.
  • Lesson 11: Use HTTPS and multi-factor authentication to protect sessions.
  • Lesson 12: Use rate limiting and DDoS protection.
  • Lesson 13: Ethical hackers test and protect against these attacks.

📝 End‑of‑Module Summary

In Module Six, we learned about session hijacking and Denial of Service attacks. We explored how hackers steal session IDs and pretend to be legitimate users. We also learned about DoS and DDoS attacks that overwhelm systems and make them unavailable. Remember, protecting sessions requires encryption, multi-factor authentication, and careful monitoring. Protecting against DoS requires rate limiting, load balancing, and DDoS protection services.

❓ Frequently Asked Questions (10)

  1. Q: What is session hijacking?
    A: Stealing a user's session ID.
  2. Q: What is a session ID?
    A: A ticket that proves you are logged in.
  3. Q: What is session fixation?
    A: Setting a user's session ID to a known value.
  4. Q: What is session prediction?
    A: Guessing a session ID.
  5. Q: What is DoS?
    A: Making a system unavailable.
  6. Q: What is DDoS?
    A: DoS from many computers.
  7. Q: What is a botnet?
    A: A network of infected computers.
  8. Q: How can you protect against session hijacking?
    A: Use HTTPS and multi-factor authentication.
  9. Q: How can you protect against DoS?
    A: Use rate limiting and DDoS protection.
  10. Q: Can ethical hackers test for these attacks?
    A: Yes, with permission.

📌 Review Questions (15)

  1. What is session hijacking?
  2. What is a session ID?
  3. What is session fixation?
  4. What is session prediction?
  5. What is DoS?
  6. What is DDoS?
  7. What is a botnet?
  8. What is a SYN flood?
  9. What is an HTTP flood?
  10. How can you protect against session hijacking?
  11. How can you protect against DoS?
  12. What is the difference between DoS and DDoS?
  13. What is the difference between application-level and network-level hijacking?
  14. What is rate limiting?
  15. Why do Nigerian companies need DDoS protection?

✍️ Fill‑in‑the‑Blank

  1. ________ is stealing a user's session ID.
  2. ________ is making a system unavailable.
  3. ________ is DoS from many computers.
  4. ________ is a network of infected computers.
  5. ________ is sending many connection requests.

✔️ True or False

  1. Session hijacking steals a user's identity. (True)
  2. DoS attacks only affect one computer. (False)
  3. DDoS uses many computers. (True)
  4. HTTPS can help protect against session hijacking. (True)
  5. Rate limiting stops DoS attacks. (True)

🔘 Multiple Choice Questions

  1. What is session hijacking?
    A) Stealing a session ID B) Stealing a password C) A type of malware D) A firewall
    Answer: A
  2. What is a session ID?
    A) A ticket that proves you are logged in B) A password C) A type of malware D) A firewall
    Answer: A
  3. What is session fixation?
    A) Setting a known session ID B) Stealing a password C) A type of malware D) A firewall
    Answer: A
  4. What is session prediction?
    A) Guessing a session ID B) Stealing a password C) A type of malware D) A firewall
    Answer: A
  5. What is DoS?
    A) Making a system unavailable B) Stealing passwords C) A type of malware D) A firewall
    Answer: A
  6. What is DDoS?
    A) DoS from many computers B) Stealing passwords C) A type of malware D) A firewall
    Answer: A
  7. What is a botnet?
    A) A network of infected computers B) A type of malware C) A firewall D) A browser
    Answer: A
  8. What is a SYN flood?
    A) Sending many connection requests B) Stealing passwords C) A type of malware D) A firewall
    Answer: A
  9. What is an HTTP flood?
    A) Sending many HTTP requests B) Stealing passwords C) A type of malware D) A firewall
    Answer: A
  10. How can you protect against session hijacking?
    A) Use HTTPS B) Use weak passwords C) Ignore security D) Disable security
    Answer: A
  11. How can you protect against DoS?
    A) Use rate limiting B) Use weak passwords C) Ignore security D) Disable security
    Answer: A
  12. What is the difference between DoS and DDoS?
    A) DDoS uses many computers B) They are the same C) DoS uses many computers D) DDoS is weaker
    Answer: A
  13. What is the difference between application-level and network-level hijacking?
    A) Application-level targets the session ID; network-level targets communication B) They are the same C) Network-level targets the session ID D) Application-level is easier
    Answer: A
  14. What is rate limiting?
    A) Limiting the number of requests B) Stealing passwords C) A type of malware D) A firewall
    Answer: A
  15. Why do Nigerian companies need DDoS protection?
    A) To stop attacks B) To allow attacks C) To save money D) None
    Answer: A

🔗 Matching Exercise

TermMatch with
1. Session hijackingA. Making a system unavailable
2. DoSB. Stealing a session ID
3. DDoSC. Network of infected computers
4. BotnetD. DoS from many computers
5. SYN floodE. Sending many connection requests

Answers: 1-B, 2-A, 3-D, 4-C, 5-E

✏️ Short Answer Questions

  1. Explain the difference between session hijacking and DoS.
  2. How does a DDoS attack work?
  3. How can you protect a website from session hijacking?

🎭 Scenario‑based Exercise

Scenario: You are an ethical hacker hired by a bank in Lagos. You discover that the bank's website is vulnerable to session hijacking. What would you recommend?

👥 Group Activity

In groups of 4, create a poster that explains session hijacking and DDoS attacks. Include examples and how to protect against them.

🧑‍💻 Individual Activity

Write a short essay on why session hijacking is a serious threat to Nigerian businesses.

💬 Classroom Discussion Questions

  • Why do you think DDoS attacks are so common?
  • How can we educate people about session hijacking?
  • What would you do if you discovered a session hijacking vulnerability?

🛠️ Mini Project

Project: Create a security guide on how to prevent session hijacking. Include tips on using HTTPS, secure cookies, and multi-factor authentication.

🔧 Practical Assignment

Research a real-world DDoS attack. Write a short report on what happened and how it could have been prevented.

⚡ Challenge Exercise

Research how HTTPS protects against session hijacking. Write a one-page explanation.

✅ Quiz Answers (Selected)

  • Fill‑in‑the‑blank: 1) Session hijacking, 2) DoS, 3) DDoS, 4) Botnet, 5) SYN flood.
  • True/False: 1T, 2F, 3T, 4T, 5T.

🔑 Key Takeaways

  • Session hijacking steals a user's identity.
  • DoS and DDoS attacks make systems unavailable.
  • HTTPS and multi-factor authentication protect against session hijacking.
  • Rate limiting and DDoS protection stop DoS attacks.
  • Ethical hackers help test and protect against these attacks.

🚀 Preparation for Module Seven

In Module Seven, we will learn about advanced Active Directory attacks. We will explore Kerberoasting, Golden Ticket, Silver Ticket, and DCSync attacks. Make sure you understand the session and DoS concepts from this module.


🔥 You have completed Module Six of Level Three! Keep up the great work. 🔥

8

Module Seven

Module Seven · Ethical Hacking Level Three

🏛️ Module Seven · Introduction to Ethical Hacking Level Three

Advanced Active Directory Attacks – becoming the king of the network.

📖 Module Introduction

Welcome to Module Seven! In this module, we will learn about advanced Active Directory (AD) attacks. Active Directory is like the brain of a company's network. It manages who can access what.

Think of Active Directory like a school's main office. It keeps track of all the students, teachers, and what each person is allowed to do. If a hacker can control the main office, they can control everything.

We will explore Kerberoasting, ASREPRoasting, Golden Ticket, Silver Ticket, and DCSync attacks. By the end of this module, you will understand how hackers take over entire networks and how to protect against them.

🎯 Learning Objectives

By the end of this module, you will be able to:

  • Explain what Active Directory is.
  • Understand Kerberos authentication.
  • Learn about Kerberoasting attacks.
  • Understand ASREPRoasting attacks.
  • Learn about Golden Ticket attacks.
  • Understand Silver Ticket attacks.
  • Learn about DCSync attacks.
  • Apply these ideas to Nigerian businesses and organisations.

📖 Warm‑up Story · The King's Crown

Once upon a time, in a kingdom in Nigeria, there was a king who ruled over a vast land. The king wore a special crown that proved he was the ruler. Everyone in the kingdom had to obey whoever wore the crown.

One day, a clever thief named Chidi stole the king's crown. He put it on and told everyone, "I am the king now!" Everyone obeyed him. He could do anything he wanted – open any door, take any treasure, and give orders to anyone.

That is exactly what a Golden Ticket attack is – stealing the "crown" of a network (the domain controller) and becoming the ruler of the entire network.

In this module, we will learn how hackers steal these "crowns" and how to protect them.

📚 Main Lessons

Lesson 1 · What is Active Directory?

Definition: Active Directory (AD) is a system that manages users, computers, and permissions in a network.

Why it is important: Most large organisations use Active Directory. If a hacker controls AD, they control the whole network.

Simple explanation: It's like a school's main office that keeps track of all students and teachers.

Real‑life example: A company uses AD to manage employee logins and access to files.

School example: A school uses AD to manage student and teacher accounts.

Home example: A family might use a simpler system to manage users on their home network.

Nigerian example: A Nigerian bank uses AD to manage employee access to customer data.

Mini summary: Active Directory manages users and permissions in a network.

Lesson 2 · What is Kerberos Authentication?

Definition: Kerberos is the authentication system used by Active Directory. It uses tickets to verify users.

Why it is important: Understanding Kerberos is essential for understanding AD attacks.

Simple explanation: It's like a ticket system at a concert – you need a ticket to get in.

Lesson 3 · How Kerberos Works

When a user logs in, the server gives them a Ticket Granting Ticket (TGT). This TGT is used to get access to specific services.

Lesson 4 · What is Kerberoasting?

Definition: Kerberoasting is an attack that steals service account passwords from Active Directory.

Why it is important: Service accounts often have high privileges. If a hacker cracks their password, they can do a lot of damage.

Simple explanation: It's like stealing the keys to the teacher's office.

Real‑life example: A hacker uses Kerberoasting to steal a service account's password and access a company's database.

School example: A student steals a teacher's password and changes their grades.

Home example: A hacker steals a service account password to access a home server.

Nigerian example: A Nigerian company might be attacked with Kerberoasting to steal service account passwords.

Mini summary: Kerberoasting steals service account passwords.

Lesson 5 · How Kerberoasting Works

A hacker requests a service ticket for a service account. The ticket is encrypted with the service account's password. The hacker then cracks the password offline.

Lesson 6 · What is ASREPRoasting?

Definition: ASREPRoasting is an attack that targets users who don't have pre-authentication enabled. Hackers can steal their password hashes and crack them.

Why it is important: ASREPRoasting can be used to crack passwords without triggering alerts.

Simple explanation: It's like finding a door that doesn't require a key and using it to get inside.

Lesson 7 · What is a Golden Ticket Attack?

Definition: A Golden Ticket attack is when a hacker steals the password hash of the domain controller's KRBTGT account and creates a fake TGT. This allows them to impersonate anyone.

Why it is important: With a Golden Ticket, a hacker can become the "king" of the network – they can do anything.

Simple explanation: It's like stealing the king's crown and becoming the ruler.

Real‑life example: A hacker uses a Golden Ticket to access any system in a company's network.

School example: A student creates a fake admin ticket and accesses the school's entire system.

Home example: A hacker uses a Golden Ticket to control a home network.

Nigerian example: A Nigerian bank might be hit by a Golden Ticket attack, allowing hackers to steal customer data.

Mini summary: Golden Ticket attacks give hackers full control.

Lesson 8 · What is a Silver Ticket Attack?

Definition: A Silver Ticket attack is similar to a Golden Ticket, but it targets a specific service instead of the whole domain.

Why it is important: Silver Tickets are harder to detect and can be used to access specific resources.

Simple explanation: It's like stealing a key to a specific room instead of the whole building.

Lesson 9 · What is DCSync?

Definition: DCSync is an attack that tricks a domain controller into sending password hashes to the hacker, as if they were doing a synchronisation.

Why it is important: DCSync allows hackers to steal all password hashes from Active Directory.

Simple explanation: It's like tricking the main office into giving you a copy of everyone's keys.

Lesson 10 · Protecting Against AD Attacks

  • Use strong passwords for service accounts.
  • Enable pre-authentication for all users.
  • Monitor for unusual Kerberos activity.
  • Rotate the KRBTGT password regularly.
  • Limit administrative privileges.

Lesson 11 · Tools for AD Attacks

  • Mimikatz: A tool for stealing passwords and tickets.
  • Rubeus: A tool for Kerberos attacks.
  • BloodHound: A tool for mapping AD relationships.
  • CrackMapExec: A tool for AD enumeration.

Lesson 12 · The Role of Ethical Hackers in AD Security

Ethical hackers test Active Directory for vulnerabilities and help organisations protect themselves.

📖 Key Vocabulary (Simple Definitions)

WordSimple meaning
Active DirectoryA system that manages users and permissions.
KerberosThe authentication system used by AD.
KerberoastingStealing service account passwords.
ASREPRoastingStealing password hashes without pre-authentication.
Golden TicketA fake TGT that gives full control.
Silver TicketA fake ticket for a specific service.
DCSyncTricking a domain controller into giving password hashes.
KRBTGTThe master account for the domain.
TGTTicket Granting Ticket – the first ticket.
MimikatzA tool for stealing passwords.

🧠 Important Concepts

  • Domain Controller: The server that manages Active Directory.
  • KRBTGT: The account that issues TGTs.
  • Service Account: An account used by services.
  • Pre-authentication: An extra step in Kerberos authentication.

🔢 Step‑by‑Step: How a Golden Ticket Attack Works

  1. Hacker steals the KRBTGT password hash using DCSync or other methods.
  2. Hacker creates a fake TGT (Golden Ticket) using Mimikatz.
  3. Hacker uses the Golden Ticket to authenticate as any user.
  4. Hacker can access any system in the domain.
  5. Hacker maintains full control until the KRBTGT password is changed.

🌍 Real‑life Examples

1. Corporate Espionage: Hackers use Golden Tickets to steal trade secrets.

2. Government: Hackers use DCSync to steal government passwords.

🇳🇬 Nigerian Examples

  • A Nigerian bank uses strong passwords for service accounts to prevent Kerberoasting.
  • A Nigerian company monitors for unusual Kerberos activity.
  • A Nigerian university uses BloodHound to map their AD environment.

🎈 Fun Examples for Kids

  • Imagine a school where you need a special ticket to enter the teacher's office. Golden Ticket is like creating a fake ticket that lets you enter any room.
  • Kerberoasting is like getting a teacher's keys and copying them.

🏡 Everyday Examples

  • If you lose your house key and someone finds it, they can enter your house – that's like a stolen ticket.
  • If you have a master key that opens all doors, losing it is like a Golden Ticket attack.

👩‍🏫 Teacher Notes

Use the king's crown story to introduce Golden Ticket attacks. Emphasise that Active Directory is a critical system that needs strong protection. Encourage students to think about how they would protect their own AD environment.

👪 Parent Tips

  • Explain why strong passwords are important.
  • Teach your child to be careful about what they share.
  • Discuss why companies need to protect their networks.

✨ Interesting Facts

💡 Golden Ticket attacks were first discovered in 2014.
💡 BloodHound is a popular tool for mapping AD relationships.

❓ Did You Know?

🔹 Many Nigerian companies use BloodHound to understand their AD environment.
🔹 Changing the KRBTGT password twice can prevent Golden Ticket attacks.

🧾 Remember This

⚠️ Always protect the KRBTGT account.
🔒 Use strong passwords for service accounts.
📱 Monitor for unusual Kerberos activity.

❌ Common Mistakes

  • Using weak passwords for service accounts.
  • Not monitoring for unusual Kerberos activity.
  • Not rotating the KRBTGT password.
  • Giving too many privileges to service accounts.

✅ Best Practices

  • Use strong passwords for service accounts.
  • Enable pre-authentication for all users.
  • Monitor for unusual Kerberos activity.
  • Rotate the KRBTGT password regularly.
  • Limit administrative privileges.

📊 ASCII Illustrations & Flowcharts

Kerberoasting Attack

    Hacker requests service ticket
          |
          v
    Ticket encrypted with service account password
          |
          v
    Hacker cracks password offline
          |
          v
    Hacker gains service account access
    

Golden Ticket Attack

    Hacker steals KRBTGT hash
          |
          v
    Creates fake TGT (Golden Ticket)
          |
          v
    Authenticates as any user
          |
          v
    Full control over domain
    

DCSync Attack

    Hacker requests replication
          |
          v
    Domain controller sends password hashes
          |
          v
    Hacker steals all passwords
          |
          v
    Hacker gains full access
    

📋 Comparison Table: Golden vs Silver Tickets

Golden TicketSilver Ticket
Full domain controlSpecific service control
Uses KRBTGT hashUses service account hash
Harder to detectEasier to detect
Can impersonate anyoneCan impersonate specific user

📋 Comparison Table: Kerberoasting vs ASREPRoasting

KerberoastingASREPRoasting
Targets service accountsTargets users without pre-auth
Requires service ticketRequires AS-REQ/AS-REP
More commonLess common
Can be triggered by any userRequires specific configuration

📌 Lesson Summaries

  • Lesson 1: Active Directory manages users and permissions.
  • Lesson 2: Kerberos uses tickets for authentication.
  • Lesson 3: Kerberos uses TGTs and service tickets.
  • Lesson 4: Kerberoasting steals service account passwords.
  • Lesson 5: Kerberoasting cracks tickets offline.
  • Lesson 6: ASREPRoasting targets users without pre-auth.
  • Lesson 7: Golden Ticket gives full domain control.
  • Lesson 8: Silver Ticket targets specific services.
  • Lesson 9: DCSync steals password hashes.
  • Lesson 10: Use strong passwords and monitor activity.
  • Lesson 11: Tools like Mimikatz and BloodHound help.
  • Lesson 12: Ethical hackers test and secure AD.

📝 End‑of‑Module Summary

In Module Seven, we learned about advanced Active Directory attacks. We explored Kerberoasting, ASREPRoasting, Golden Ticket, Silver Ticket, and DCSync attacks. These are some of the most dangerous attacks in cybersecurity because they give hackers control over entire networks. Remember, protecting Active Directory requires strong passwords, regular monitoring, and careful management of the KRBTGT account.

❓ Frequently Asked Questions (10)

  1. Q: What is Active Directory?
    A: A system that manages users and permissions.
  2. Q: What is Kerberos?
    A: The authentication system used by AD.
  3. Q: What is Kerberoasting?
    A: Stealing service account passwords.
  4. Q: What is ASREPRoasting?
    A: Stealing passwords without pre-auth.
  5. Q: What is a Golden Ticket?
    A: A fake TGT that gives full control.
  6. Q: What is a Silver Ticket?
    A: A fake ticket for a specific service.
  7. Q: What is DCSync?
    A: Stealing password hashes from AD.
  8. Q: What is KRBTGT?
    A: The master account for the domain.
  9. Q: How can you protect against Golden Ticket attacks?
    A: Rotate the KRBTGT password regularly.
  10. Q: Can ethical hackers use these techniques?
    A: Yes, with permission.

📌 Review Questions (15)

  1. What is Active Directory?
  2. What is Kerberos?
  3. What is Kerberoasting?
  4. How does Kerberoasting work?
  5. What is ASREPRoasting?
  6. What is a Golden Ticket?
  7. How does a Golden Ticket attack work?
  8. What is a Silver Ticket?
  9. What is DCSync?
  10. What is the KRBTGT account?
  11. How can you protect against Kerberoasting?
  12. How can you protect against Golden Ticket attacks?
  13. What is Mimikatz?
  14. What is BloodHound?
  15. Why are Nigerian businesses at risk from AD attacks?

✍️ Fill‑in‑the‑Blank

  1. ________ is a system that manages users and permissions.
  2. ________ steals service account passwords.
  3. ________ is a fake TGT that gives full control.
  4. ________ steals password hashes from AD.
  5. ________ is the master account for the domain.

✔️ True or False

  1. Active Directory manages users and permissions. (True)
  2. Kerberoasting steals user passwords. (False)
  3. Golden Ticket gives full domain control. (True)
  4. DCSync steals password hashes. (True)
  5. KRBTGT is not important. (False)

🔘 Multiple Choice Questions

  1. What is Active Directory?
    A) A system that manages users B) A type of malware C) A firewall D) A browser
    Answer: A
  2. What is Kerberoasting?
    A) Stealing service account passwords B) Stealing user passwords C) A type of malware D) A firewall
    Answer: A
  3. What is a Golden Ticket?
    A) A fake TGT that gives full control B) A type of malware C) A firewall D) A browser
    Answer: A
  4. What is a Silver Ticket?
    A) A fake ticket for a specific service B) A type of malware C) A firewall D) A browser
    Answer: A
  5. What is DCSync?
    A) Stealing password hashes from AD B) A type of malware C) A firewall D) A browser
    Answer: A
  6. What is the KRBTGT account?
    A) The master account for the domain B) A type of malware C) A firewall D) A browser
    Answer: A
  7. What is ASREPRoasting?
    A) Stealing passwords without pre-auth B) Stealing service account passwords C) A type of malware D) A firewall
    Answer: A
  8. What is Mimikatz?
    A) A tool for stealing passwords B) A type of malware C) A firewall D) A browser
    Answer: A
  9. What is BloodHound?
    A) A tool for mapping AD relationships B) A type of malware C) A firewall D) A browser
    Answer: A
  10. How can you protect against Golden Ticket attacks?
    A) Rotate KRBTGT password B) Use weak passwords C) Ignore security D) Disable security
    Answer: A
  11. How can you protect against Kerberoasting?
    A) Use strong passwords B) Use weak passwords C) Ignore security D) Disable security
    Answer: A
  12. What is pre-authentication?
    A) An extra Kerberos step B) A type of malware C) A firewall D) A browser
    Answer: A
  13. What is a TGT?
    A) Ticket Granting Ticket B) A type of malware C) A firewall D) A browser
    Answer: A
  14. What is a service account?
    A) An account used by services B) A user account C) A type of malware D) A firewall
    Answer: A
  15. Why do Nigerian companies need AD security?
    A) To protect their networks B) To allow attacks C) To save money D) None
    Answer: A

🔗 Matching Exercise

TermMatch with
1. KerberoastingA. Fake TGT that gives full control
2. Golden TicketB. Stealing service account passwords
3. Silver TicketC. Stealing password hashes from AD
4. DCSyncD. Fake ticket for a specific service
5. KRBTGTE. Master account for the domain

Answers: 1-B, 2-A, 3-D, 4-C, 5-E

✏️ Short Answer Questions

  1. Explain the difference between Kerberoasting and ASREPRoasting.
  2. What is a Golden Ticket attack and how does it work?
  3. How can you protect Active Directory from these attacks?

🎭 Scenario‑based Exercise

Scenario: You are an ethical hacker hired by a bank in Lagos. The bank's Active Directory has been compromised. You suspect a Golden Ticket attack. What would you do?

👥 Group Activity

In groups of 4, create a poster that explains the different AD attacks and how to protect against them.

🧑‍💻 Individual Activity

Write a short essay on why Active Directory security is important for Nigerian businesses.

💬 Classroom Discussion Questions

  • Why do you think AD attacks are so dangerous?
  • How can we educate companies about AD security?
  • What would you do if you discovered a vulnerability in your company's AD?

🛠️ Mini Project

Project: Create a security checklist for Active Directory. Include items for Kerberoasting, Golden Ticket, Silver Ticket, and DCSync protection.

🔧 Practical Assignment

Research a real-world Golden Ticket attack. Write a short report on what happened and how it could have been prevented.

⚡ Challenge Exercise

Research how BloodHound works. Write a one-page explanation and describe how it can be used for AD security.

✅ Quiz Answers (Selected)

  • Fill‑in‑the‑blank: 1) Active Directory, 2) Kerberoasting, 3) Golden Ticket, 4) DCSync, 5) KRBTGT.
  • True/False: 1T, 2F, 3T, 4T, 5F.

🔑 Key Takeaways

  • Active Directory is the brain of a company's network.
  • Kerberoasting and ASREPRoasting steal passwords.
  • Golden Ticket and Silver Ticket attacks give hackers control.
  • DCSync steals password hashes.
  • Protect AD with strong passwords, monitoring, and KRBTGT rotation.
  • Ethical hackers test and secure AD environments.

🚀 Preparation for Module Eight

In Module Eight, we will learn about Windows and Linux exploitation. We will explore privilege escalation, persistence, and kernel exploits. Make sure you understand the AD concepts from this module.


🔥 You have completed Module Seven of Level Three! Keep up the great work. 🔥

9

Module Eight

Module Eight · Ethical Hacking Level Three

🖥️ Module Eight · Introduction to Ethical Hacking Level Three

Windows and Linux Exploitation – gaining control and staying inside.

📖 Module Introduction

Welcome to Module Eight! In this module, we will learn about Windows and Linux exploitation. This is where hackers take full control of systems and make sure they can stay there.

Think of it like a thief who breaks into a house. First, they need to get inside (that's the initial attack). Then they need to find the master key to open all the doors (privilege escalation). Finally, they need to make sure they can come back anytime (persistence).

We will explore privilege escalation on both Windows and Linux, UAC bypass, kernel exploits, and persistence mechanisms. By the end of this module, you will understand how hackers take over systems and how to stop them.

🎯 Learning Objectives

By the end of this module, you will be able to:

  • Explain what privilege escalation is.
  • Understand Windows privilege escalation techniques.
  • Learn about UAC bypass on Windows.
  • Understand Linux privilege escalation.
  • Learn about kernel exploits.
  • Understand persistence mechanisms.
  • Apply these ideas to Nigerian businesses and organisations.

📖 Warm‑up Story · The Master Key

Once upon a time, in a school in Lagos, there was a janitor named Bola. Bola had a master key that could open every door in the school – the classrooms, the staff room, and even the principal's office.

One day, a student named Kunle wanted to get into the staff room. He noticed that Bola often left his keys on the desk. Kunle took the keys, copied them, and put them back. Now Kunle could open any door in the school.

That is exactly what privilege escalation is – getting a master key that gives you access to everything. In this module, we will learn how hackers get these master keys and how to protect them.

📚 Main Lessons

Lesson 1 · What is Privilege Escalation?

Definition: Privilege escalation is when a hacker gains higher access rights than they should have.

Why it is important: Once a hacker becomes an administrator, they can do anything on the system.

Simple explanation: It's like a student getting a teacher's key card.

Real‑life example: A hacker uses a vulnerability to get administrator access on a Windows server.

School example: A student finds a way to access the teacher's grade book.

Home example: A family member gains admin access to the home computer.

Nigerian example: A Nigerian company might be attacked with privilege escalation.

Mini summary: Privilege escalation is gaining higher access rights.

Lesson 2 · Windows Privilege Escalation

Windows has many ways to escalate privileges, including using UAC bypass or exploiting vulnerabilities in services.

Lesson 3 · UAC Bypass (User Account Control)

Definition: UAC is a Windows feature that asks for permission before making changes. Hackers bypass it to run malicious code without alerts.

Simple explanation: It's like a security guard who asks for ID, but you trick them into letting you in anyway.

Lesson 4 · Windows Service Exploitation

Services on Windows run with high privileges. If a hacker can exploit a service, they can gain high privileges.

Lesson 5 · Windows Scheduled Tasks

Scheduled tasks run automatically. Hackers can exploit misconfigured scheduled tasks to run their code with high privileges.

Lesson 6 · Windows Registry Attacks

The Windows registry contains many settings. Hackers can exploit weak permissions on registry keys to escalate privileges.

Lesson 7 · Linux Privilege Escalation

Linux has its own methods for privilege escalation, like using sudo vulnerabilities or exploiting misconfigured permissions.

Lesson 8 · Sudo Exploitation

Definition: Sudo allows users to run commands as root. If sudo is misconfigured, hackers can exploit it.

Simple explanation: It's like having a key that can open any door if you know the right command.

Lesson 9 · Linux SUID Binaries

SUID binaries run with the owner's privileges. If a hacker finds a vulnerable SUID binary, they can escalate privileges.

Lesson 10 · Kernel Exploits

Definition: Kernel exploits target the core of the operating system. They are very powerful and can give hackers full control.

Why it is dangerous: Kernel exploits work on both Windows and Linux and are often hard to detect.

Simple explanation: It's like breaking the main lock on the building instead of picking individual door locks.

Lesson 11 · What is Persistence?

Definition: Persistence is the ability of a hacker to maintain access to a system, even after a restart or password change.

Why it is important: Hackers want to keep access so they can come back later.

Simple explanation: It's like a thief making a copy of your house key so they can come back.

Lesson 12 · Windows Persistence Mechanisms

  • Scheduled tasks: A program that runs automatically.
  • Registry keys: Settings that run programs when the system starts.
  • Services: Background programs that can be set to run automatically.
  • Startup folder: Programs that run when a user logs in.

Lesson 13 · Linux Persistence Mechanisms

  • Cron jobs: Scheduled tasks that run at certain times.
  • Startup scripts: Scripts that run when the system boots.
  • SSH keys: Allowing the hacker to log in without a password.
  • Systemd services: Services that run automatically.

Lesson 14 · Detecting Privilege Escalation and Persistence

  • Monitor for unusual processes.
  • Check for new user accounts.
  • Look for unexpected scheduled tasks.
  • Use EDR (Endpoint Detection and Response) tools.

Lesson 15 · The Role of Ethical Hackers

Ethical hackers use these techniques to test systems and find weaknesses. They then report their findings so that the weaknesses can be fixed.

📖 Key Vocabulary (Simple Definitions)

WordSimple meaning
Privilege escalationGaining higher access rights.
UAC bypassTricking Windows security.
Kernel exploitAttacking the core of the OS.
PersistenceMaintaining access to a system.
SudoA Linux command to run as root.
SUIDA Linux file permission.
Cron jobA scheduled task on Linux.
Registry keyA setting on Windows.
ServiceA background program.
EDREndpoint Detection and Response.

🧠 Important Concepts

  • Least privilege: Giving users only the minimum access they need.
  • Defence in depth: Using many layers of security.
  • Monitoring: Watching for unusual activity.
  • Patching: Keeping systems updated.

🔢 Step‑by‑Step: How a Windows Privilege Escalation Works

  1. Hacker finds a vulnerability in a service.
  2. Hacker exploits the vulnerability to run code.
  3. The code runs with SYSTEM privileges (highest level).
  4. Hacker creates a new administrator account.
  5. Hacker can now do anything on the system.

🌍 Real‑life Examples

1. Corporate: Hackers use privilege escalation to access sensitive company data.

2. Government: Hackers use kernel exploits to gain control of government systems.

🇳🇬 Nigerian Examples

  • A Nigerian bank uses EDR tools to detect privilege escalation.
  • A Nigerian company monitors for unusual scheduled tasks.
  • A Nigerian university uses least privilege to protect its systems.

🎈 Fun Examples for Kids

  • Imagine a game where you start as a regular player but find a way to become the game master – that's privilege escalation.
  • Persistence is like leaving a hidden door in your game so you can come back anytime.

🏡 Everyday Examples

  • If someone finds your house key and makes a copy, that's persistence.
  • If a friend gets the master key to your house, that's privilege escalation.

👩‍🏫 Teacher Notes

Use the master key story to introduce privilege escalation. Emphasise that ethical hackers use these techniques to test systems. Encourage students to think about how they would protect their own systems.

👪 Parent Tips

  • Teach your child to keep software updated.
  • Explain why it's important to have strong passwords.
  • Show them how to check for unusual activity on their computer.

✨ Interesting Facts

💡 The first privilege escalation attacks were discovered in the 1990s.
💡 Kernel exploits are the most dangerous type of exploit.

❓ Did You Know?

🔹 Many Nigerian companies use EDR tools to detect privilege escalation.
🔹 Some Linux privilege escalation techniques can be detected with basic monitoring.

🧾 Remember This

⚠️ Always keep systems updated.
🔒 Use the principle of least privilege.
📱 Monitor for unusual activity.

❌ Common Mistakes

  • Not updating systems.
  • Giving users too many privileges.
  • Not monitoring for unusual activity.
  • Ignoring kernel vulnerabilities.

✅ Best Practices

  • Keep systems updated.
  • Use least privilege.
  • Monitor for unusual activity.
  • Use EDR tools.
  • Regularly audit user accounts.

📊 ASCII Illustrations & Flowcharts

Privilege Escalation

    Low Privileges  ---->  Find Vulnerability  ---->  Exploit
          |                         |                      |
          v                         v                      v
    High Privileges  <----  Gain Access  <----  Run Malicious Code
    

Windows Persistence Mechanisms

    Scheduled Tasks  ---->  Run automatically
    Registry Keys    ---->  Run at startup
    Services         ---->  Run as background
    Startup Folder   ---->  Run when user logs in
    

Linux Persistence Mechanisms

    Cron Jobs        ---->  Run at scheduled times
    Startup Scripts  ---->  Run at boot
    SSH Keys         ---->  Login without password
    Systemd Services ---->  Run automatically
    

📋 Comparison Table: Windows vs Linux Privilege Escalation

WindowsLinux
UAC bypassSudo exploitation
Service exploitationSUID binaries
Scheduled tasksCron jobs
Registry attacksFile permissions
Kernel exploitsKernel exploits

📋 Comparison Table: Privilege Escalation vs Persistence

Privilege EscalationPersistence
Gaining higher accessMaintaining access
One-time exploitOngoing access
Gives more powerGives staying power
Often noisyOften quiet

📌 Lesson Summaries

  • Lesson 1: Privilege escalation gives higher access.
  • Lesson 2: Windows has many escalation methods.
  • Lesson 3: UAC bypass tricks Windows security.
  • Lesson 4: Services can be exploited for escalation.
  • Lesson 5: Scheduled tasks can be misused.
  • Lesson 6: Registry attacks are another method.
  • Lesson 7: Linux has its own escalation methods.
  • Lesson 8: Sudo can be exploited.
  • Lesson 9: SUID binaries are a risk.
  • Lesson 10: Kernel exploits are very dangerous.
  • Lesson 11: Persistence maintains access.
  • Lesson 12: Windows uses scheduled tasks, registry, and services.
  • Lesson 13: Linux uses cron, startup scripts, and SSH keys.
  • Lesson 14: Monitor for unusual activity.
  • Lesson 15: Ethical hackers test and report vulnerabilities.

📝 End‑of‑Module Summary

In Module Eight, we learned about Windows and Linux exploitation. We explored privilege escalation, UAC bypass, kernel exploits, and persistence mechanisms. These are the techniques that hackers use to take control of systems and stay there. Remember, protecting systems requires regular updates, least privilege, and careful monitoring. By understanding these techniques, we can better protect our systems.

❓ Frequently Asked Questions (10)

  1. Q: What is privilege escalation?
    A: Gaining higher access rights.
  2. Q: What is UAC bypass?
    A: Tricking Windows security.
  3. Q: What is a kernel exploit?
    A: Attacking the core of the OS.
  4. Q: What is persistence?
    A: Maintaining access to a system.
  5. Q: What is sudo?
    A: A Linux command to run as root.
  6. Q: What is SUID?
    A: A Linux file permission.
  7. Q: What is a cron job?
    A: A scheduled task on Linux.
  8. Q: What is a registry key?
    A: A setting on Windows.
  9. Q: How can you detect privilege escalation?
    A: Monitor for unusual activity.
  10. Q: Can ethical hackers use these techniques?
    A: Yes, with permission.

📌 Review Questions (15)

  1. What is privilege escalation?
  2. What is UAC bypass?
  3. What is a kernel exploit?
  4. What is persistence?
  5. How can you escalate privileges on Windows?
  6. How can you escalate privileges on Linux?
  7. What is sudo?
  8. What is SUID?
  9. What is a cron job?
  10. What is a registry key?
  11. What is the difference between privilege escalation and persistence?
  12. How can you detect privilege escalation?
  13. How can you detect persistence?
  14. What is least privilege?
  15. Why are Nigerian companies at risk from these attacks?

✍️ Fill‑in‑the‑Blank

  1. ________ is gaining higher access rights.
  2. ________ is maintaining access to a system.
  3. ________ is tricking Windows security.
  4. ________ is a Linux command to run as root.
  5. ________ is a scheduled task on Linux.

✔️ True or False

  1. Privilege escalation gives higher access rights. (True)
  2. Persistence is not important. (False)
  3. UAC bypass is a Windows security feature. (False)
  4. Kernel exploits are very dangerous. (True)
  5. SUID binaries are only on Windows. (False)

🔘 Multiple Choice Questions

  1. What is privilege escalation?
    A) Gaining higher access B) Losing access C) A type of malware D) A firewall
    Answer: A
  2. What is UAC bypass?
    A) Tricking Windows security B) A type of malware C) A firewall D) A browser
    Answer: A
  3. What is a kernel exploit?
    A) Attacking the core of the OS B) A type of malware C) A firewall D) A browser
    Answer: A
  4. What is persistence?
    A) Maintaining access B) Losing access C) A type of malware D) A firewall
    Answer: A
  5. What is sudo?
    A) A Linux command to run as root B) A type of malware C) A firewall D) A browser
    Answer: A
  6. What is SUID?
    A) A Linux file permission B) A type of malware C) A firewall D) A browser
    Answer: A
  7. What is a cron job?
    A) A scheduled task on Linux B) A type of malware C) A firewall D) A browser
    Answer: A
  8. What is a registry key?
    A) A setting on Windows B) A type of malware C) A firewall D) A browser
    Answer: A
  9. How can you detect privilege escalation?
    A) Monitor for unusual activity B) Ignore activity C) Disable security D) Use weak passwords
    Answer: A
  10. What is least privilege?
    A) Giving minimal access B) Giving full access C) A type of malware D) A firewall
    Answer: A
  11. What is a scheduled task on Windows?
    A) A program that runs automatically B) A type of malware C) A firewall D) A browser
    Answer: A
  12. What is a systemd service on Linux?
    A) A service that runs automatically B) A type of malware C) A firewall D) A browser
    Answer: A
  13. What is an SSH key used for?
    A) Logging in without a password B) A type of malware C) A firewall D) A browser
    Answer: A
  14. What is the difference between privilege escalation and persistence?
    A) Privilege escalation gives more power; persistence maintains it B) They are the same C) Persistence gives more power D) Privilege escalation maintains it
    Answer: A
  15. Why do Nigerian companies need to protect against these attacks?
    A) To protect their data B) To allow attacks C) To save money D) None
    Answer: A

🔗 Matching Exercise

TermMatch with
1. Privilege escalationA. Maintaining access
2. PersistenceB. Gaining higher access
3. UAC bypassC. Linux command to run as root
4. SudoD. Tricking Windows security
5. Kernel exploitE. Attacking the core of the OS

Answers: 1-B, 2-A, 3-D, 4-C, 5-E

✏️ Short Answer Questions

  1. Explain the difference between privilege escalation and persistence.
  2. How does a UAC bypass work?
  3. How can you protect a system from these attacks?

🎭 Scenario‑based Exercise

Scenario: You are an ethical hacker hired by a bank in Lagos. The bank's Windows server has been compromised. You suspect privilege escalation. What would you do?

👥 Group Activity

In groups of 4, create a poster that explains privilege escalation and persistence on Windows and Linux. Include examples and how to protect against them.

🧑‍💻 Individual Activity

Write a short essay on why privilege escalation is a serious threat to Nigerian businesses.

💬 Classroom Discussion Questions

  • Why do you think privilege escalation attacks are so common?
  • How can we educate companies about these risks?
  • What would you do if you discovered a privilege escalation vulnerability?

🛠️ Mini Project

Project: Create a security checklist for a Windows or Linux system. Include items for privilege escalation and persistence protection.

🔧 Practical Assignment

Research a real-world privilege escalation attack. Write a short report on what happened and how it could have been prevented.

⚡ Challenge Exercise

Research how kernel exploits work. Write a one-page explanation and describe how to protect against them.

✅ Quiz Answers (Selected)

  • Fill‑in‑the‑blank: 1) Privilege escalation, 2) Persistence, 3) UAC bypass, 4) Sudo, 5) Cron job.
  • True/False: 1T, 2F, 3F, 4T, 5F.

🔑 Key Takeaways

  • Privilege escalation gives hackers higher access rights.
  • Windows and Linux have different escalation methods.
  • UAC bypass and kernel exploits are common techniques.
  • Persistence maintains access through scheduled tasks, registry keys, and cron jobs.
  • Protect systems with updates, least privilege, and monitoring.
  • Ethical hackers help find and fix these vulnerabilities.

🚀 Preparation for Module Nine

In Module Nine, we will learn about wireless network hacking. We will explore WPA/WPA2 cracking, evil twin attacks, and Bluetooth security. Make sure you understand the exploitation concepts from this module.


🔥 You have completed Module Eight of Level Three! Keep up the great work. 🔥

10

Module Nine

Module Nine · Ethical Hacking Level Three

📶 Module Nine · Introduction to Ethical Hacking Level Three

Advanced Wireless Network Hacking – mastering the invisible battlefield.

📖 Module Introduction

Welcome to Module Nine! In this module, we will learn about advanced wireless network hacking. Wi-Fi is everywhere – in our homes, schools, offices, and even in the air around us. But Wi-Fi can also be a door that hackers use to break in.

Think of wireless networks like invisible conversations happening in the air. Anyone with the right tools can listen in. Hackers use this to steal passwords, spy on people, and break into networks.

We will explore WPA/WPA2 cracking, WPA3 attacks, evil twin attacks, Bluetooth security, and RFID hacking. By the end of this module, you will understand how to protect wireless networks from advanced attacks.

🎯 Learning Objectives

By the end of this module, you will be able to:

  • Explain how Wi-Fi security works.
  • Understand WPA/WPA2 cracking techniques.
  • Learn about WPA3 and its vulnerabilities.
  • Understand evil twin and rogue access point attacks.
  • Learn about Bluetooth security risks.
  • Understand RFID and NFC hacking.
  • Apply these ideas to Nigerian businesses and homes.

📖 Warm‑up Story · The Invisible Conversation

Once upon a time, in a busy market in Lagos, two friends were having a conversation. They were talking about a secret plan. But they didn't realize that a stranger was listening to their conversation from behind a stall.

The stranger heard everything – the time, the place, and the secret code. He used that information to beat them to the treasure.

That is exactly what wireless hacking is – listening to invisible conversations and using that information to break in. In this module, we will learn how these conversations happen, how hackers listen in, and how to stop them.

📚 Main Lessons

Lesson 1 · How Wi-Fi Security Works

Definition: Wi-Fi security protects wireless networks from unauthorized access. It uses encryption to scramble data so only the right people can read it.

Why it is important: Without Wi-Fi security, anyone can listen to your conversations and steal your information.

Simple explanation: It's like having a secret code that only you and your friends know.

Real‑life example: A coffee shop uses WPA2 to protect its Wi-Fi network.

School example: A school uses Wi-Fi security to protect student data.

Home example: A family uses a password to protect their home Wi-Fi.

Nigerian example: A Nigerian business uses WPA2 to protect its network.

Mini summary: Wi-Fi security protects wireless networks.

Lesson 2 · WEP – The Weakest Link

Definition: WEP is an old Wi-Fi security protocol that is very weak. Hackers can crack it in minutes.

Why it is not safe: WEP is broken – it should never be used.

Simple explanation: It's like a lock that can be opened with a paperclip.

Lesson 3 · WPA and WPA2

Definition: WPA and WPA2 are stronger Wi-Fi security protocols. WPA2 is the most common.

Why they are better: They use stronger encryption and are much harder to crack.

Simple explanation: It's like a lock that requires a special key.

Lesson 4 · WPA/WPA2 Cracking

Definition: WPA/WPA2 cracking is the process of stealing the password by capturing the handshake and using brute-force or dictionary attacks.

Why it is important: Understanding how cracking works helps us protect our networks.

Simple explanation: It's like capturing a copy of the key and trying to copy it.

Real‑life example: A hacker captures a handshake and cracks the password using a wordlist.

School example: A student tries to crack the school's Wi-Fi password.

Home example: A neighbour tries to crack your home Wi-Fi password.

Nigerian example: A hacker tries to crack a Nigerian company's Wi-Fi.

Mini summary: WPA/WPA2 cracking steals Wi-Fi passwords.

Lesson 5 · The Four-Way Handshake

The four-way handshake is the process that happens when a device connects to a WPA/WPA2 network. Hackers capture this handshake to crack the password.

Lesson 6 · WPA3 – The New Standard

Definition: WPA3 is the newest Wi-Fi security protocol. It fixes many problems with WPA2.

Why it is better: WPA3 uses stronger encryption and protects against common attacks.

Simple explanation: It's like upgrading from a regular lock to a high-tech electronic lock.

Lesson 7 · WPA3 Vulnerabilities

Even WPA3 has some vulnerabilities. Hackers have found ways to attack it, including side-channel attacks and downgrade attacks.

Lesson 8 · Evil Twin Attacks

Definition: An evil twin attack is when a hacker creates a fake Wi-Fi network that looks like a real one.

Why it is dangerous: Users connect to the fake network and give away their passwords.

Simple explanation: It's like a fake coffee shop that looks real but steals your money.

Real‑life example: A hacker sets up a fake network called "CoffeeShop_WiFi" to steal passwords.

School example: A student sets up a fake network called "School_WiFi" to steal passwords.

Home example: A neighbour sets up a fake network called "Your_Network" to steal your information.

Nigerian example: A hacker in Lagos uses an evil twin attack at a cybercafé.

Mini summary: Evil twin attacks use fake networks.

Lesson 9 · Rogue Access Points

Definition: A rogue access point is an unauthorized Wi-Fi device connected to a network. Hackers use them to break in.

Lesson 10 · Deauthentication Attacks

A deauthentication attack sends fake deauth packets to disconnect a device from a network. Hackers use this to capture handshakes.

Lesson 11 · Bluetooth Security

Definition: Bluetooth is a wireless technology used for short-range communication. Hackers can exploit it to steal data.

Why it is important: Bluetooth is used in phones, speakers, and cars. It can be a security risk.

Simple explanation: It's like a secret handshake that can be copied.

Lesson 12 · RFID and NFC Hacking

Definition: RFID (Radio Frequency Identification) and NFC (Near Field Communication) are used for contactless payments and access cards. Hackers can clone them.

Simple explanation: It's like copying someone's key card.

Lesson 13 · Protecting Wireless Networks

  • Use WPA2 or WPA3.
  • Use a strong, long password.
  • Disable WPS.
  • Hide your SSID (network name).
  • Use a VPN.

Lesson 14 · The Role of Ethical Hackers

Ethical hackers test wireless networks for vulnerabilities and help organisations protect themselves.

📖 Key Vocabulary (Simple Definitions)

WordSimple meaning
WEPA weak Wi-Fi security protocol.
WPA/WPA2Wi-Fi security protocols.
WPA3The newest Wi-Fi security protocol.
HandshakeThe process of connecting to Wi-Fi.
Evil TwinA fake Wi-Fi network.
Rogue Access PointAn unauthorized Wi-Fi device.
Deauth attackAn attack that disconnects a device.
BluetoothA short-range wireless technology.
RFIDRadio Frequency Identification.
NFCNear Field Communication.

🧠 Important Concepts

  • Encryption: Scrambling data to protect it.
  • SSID: The name of a Wi-Fi network.
  • MAC Address: A unique identifier for a device.
  • WPS: Wi-Fi Protected Setup – often vulnerable.

🔢 Step‑by‑Step: How WPA/WPA2 Cracking Works

  1. Hacker captures a Wi-Fi handshake using a tool like Aircrack-ng.
  2. Hacker uses a dictionary or brute-force attack to guess the password.
  3. If the password is weak, it is cracked.
  4. Hacker uses the password to connect to the network.

🌍 Real‑life Examples

1. Coffee Shop: A hacker uses an evil twin attack to steal passwords from customers.

2. Hotel: A hotel's Wi-Fi is hacked, exposing guest information.

🇳🇬 Nigerian Examples

  • A Nigerian bank uses WPA2 to protect its internal Wi-Fi.
  • A Nigerian university uses deauth attacks to test its Wi-Fi security.
  • A small business in Kano uses a strong password to protect its Wi-Fi.

🎈 Fun Examples for Kids

  • Imagine your Wi-Fi is like a treehouse. A strong password is like a strong lock on the door. A weak password is like leaving the door wide open.
  • An evil twin is like a fake treehouse that looks real but is actually a trap.

🏡 Everyday Examples

  • Your home Wi-Fi – if you use a weak password, someone could use your internet.
  • Your school Wi-Fi – if it's not secure, students might be able to access restricted content.

👩‍🏫 Teacher Notes

Use the invisible conversation story to introduce wireless hacking. Emphasise the importance of strong passwords and encryption. Encourage students to check their own home Wi-Fi settings.

👪 Parent Tips

  • Change your home Wi-Fi password regularly.
  • Use WPA2 or WPA3 for your Wi-Fi.
  • Show your child how to check which devices are connected to your Wi-Fi.

✨ Interesting Facts

💡 The first version of WEP was released in 1997.
💡 Aircrack-ng was created in 2004 and is still used today.

❓ Did You Know?

🔹 In Nigeria, many homes still use WEP because they don't know it's unsafe.
🔹 WPA3 was introduced in 2018 to fix WPA2 vulnerabilities.

🧾 Remember This

⚠️ Never use WEP for your Wi-Fi.
🔒 Use a strong, long password for your Wi-Fi.
📱 Turn off WPS if you don't need it.

❌ Common Mistakes

  • Using WEP encryption.
  • Using weak passwords like "password" or "12345678".
  • Leaving WPS enabled.
  • Not updating router firmware.

✅ Best Practices

  • Use WPA2 or WPA3.
  • Use a strong, unique password.
  • Disable WPS.
  • Change the default SSID.
  • Update your router's firmware regularly.

📊 ASCII Illustrations & Flowcharts

Wi-Fi Security Comparison

    WEP    ----  Weak (cracked in minutes)
    WPA    ----  Better but still vulnerable
    WPA2   ----  Most common, strong
    WPA3   ----  Best, most secure
    

WPA/WPA2 Cracking Process

    Capture Handshake
           |
           v
    Run Dictionary Attack
           |
           v
    Password Found?
           |
           v
    Yes  ---->  Access Wi-Fi
    No   ---->  Try More
    

Evil Twin Attack

    Hacker sets up fake network
           |
           v
    Victim connects to fake network
           |
           v
    Hacker steals victim's information
    

📋 Comparison Table: Wi-Fi Security Protocols

ProtocolStrengthSecurity Level
WEPVery weakCan be cracked in minutes
WPAWeakVulnerable to some attacks
WPA2StrongMost common, secure
WPA3Very strongNewest, most secure

📋 Comparison Table: Level Two vs Level Three Wireless Hacking

Level TwoLevel Three
Basic WPA2 crackingWPA3 attacks, evil twin, Bluetooth
Simple deauth attacksAdvanced evasion techniques
Basic toolsAdvanced tools and custom scripts
Focused on Wi-FiIncludes Bluetooth, RFID, NFC

📌 Lesson Summaries

  • Lesson 1: Wi-Fi security protects wireless networks.
  • Lesson 2: WEP is very weak and unsafe.
  • Lesson 3: WPA and WPA2 are stronger protocols.
  • Lesson 4: WPA/WPA2 cracking steals passwords.
  • Lesson 5: The four-way handshake is used for cracking.
  • Lesson 6: WPA3 is the newest standard.
  • Lesson 7: WPA3 has some vulnerabilities.
  • Lesson 8: Evil twin attacks use fake networks.
  • Lesson 9: Rogue access points are unauthorized devices.
  • Lesson 10: Deauth attacks disconnect devices.
  • Lesson 11: Bluetooth has security risks.
  • Lesson 12: RFID and NFC can be cloned.
  • Lesson 13: Use WPA2/WPA3 and strong passwords.
  • Lesson 14: Ethical hackers test wireless security.

📝 End‑of‑Module Summary

In Module Nine, we learned about advanced wireless network hacking. We explored WEP, WPA, WPA2, and WPA3, and learned how hackers crack Wi-Fi passwords. We also learned about evil twin attacks, rogue access points, Bluetooth security, and RFID hacking. Remember, wireless security is essential in today's connected world. By understanding how hackers attack, we can better protect our networks.

❓ Frequently Asked Questions (10)

  1. Q: What is WEP?
    A: A weak Wi-Fi security protocol.
  2. Q: What is WPA2?
    A: The most common Wi-Fi security protocol.
  3. Q: What is WPA3?
    A: The newest Wi-Fi security protocol.
  4. Q: What is a handshake?
    A: The process of connecting to Wi-Fi.
  5. Q: What is an evil twin attack?
    A: A fake Wi-Fi network.
  6. Q: What is a deauth attack?
    A: An attack that disconnects a device.
  7. Q: What is Bluetooth hacking?
    A: Exploiting Bluetooth vulnerabilities.
  8. Q: What is RFID hacking?
    A: Cloning RFID cards.
  9. Q: How can I protect my Wi-Fi?
    A: Use WPA2/WPA3 and a strong password.
  10. Q: Can ethical hackers test Wi-Fi?
    A: Yes, with permission.

📌 Review Questions (15)

  1. What is WEP and why is it weak?
  2. What is WPA2?
  3. What is WPA3?
  4. What is a handshake?
  5. What is an evil twin attack?
  6. What is a rogue access point?
  7. What is a deauth attack?
  8. What are Bluetooth security risks?
  9. What is RFID hacking?
  10. How can you protect your Wi-Fi?
  11. What is the difference between WEP and WPA2?
  12. What is the difference between WPA2 and WPA3?
  13. What is a side-channel attack on WPA3?
  14. What is a downgrade attack?
  15. Why do Nigerian companies need wireless security?

✍️ Fill‑in‑the‑Blank

  1. ________ is a weak Wi-Fi security protocol.
  2. ________ is the most common Wi-Fi security protocol.
  3. ________ is the newest Wi-Fi security protocol.
  4. ________ is a fake Wi-Fi network.
  5. ________ is an attack that disconnects a device.

✔️ True or False

  1. WEP is a secure Wi-Fi protocol. (False)
  2. WPA2 is more secure than WEP. (True)
  3. WPA3 is the newest standard. (True)
  4. An evil twin is a real network. (False)
  5. Bluetooth is always secure. (False)

🔘 Multiple Choice Questions

  1. What is WEP?
    A) A weak Wi-Fi protocol B) A strong Wi-Fi protocol C) A type of malware D) A firewall
    Answer: A
  2. What is WPA2?
    A) A strong Wi-Fi protocol B) A weak Wi-Fi protocol C) A type of malware D) A firewall
    Answer: A
  3. What is WPA3?
    A) The newest Wi-Fi protocol B) A weak Wi-Fi protocol C) A type of malware D) A firewall
    Answer: A
  4. What is a handshake?
    A) The process of connecting to Wi-Fi B) A type of malware C) A firewall D) A browser
    Answer: A
  5. What is an evil twin attack?
    A) A fake Wi-Fi network B) A real Wi-Fi network C) A type of malware D) A firewall
    Answer: A
  6. What is a rogue access point?
    A) An unauthorized Wi-Fi device B) A real Wi-Fi device C) A type of malware D) A firewall
    Answer: A
  7. What is a deauth attack?
    A) An attack that disconnects a device B) A type of malware C) A firewall D) A browser
    Answer: A
  8. What is Bluetooth hacking?
    A) Exploiting Bluetooth vulnerabilities B) A type of malware C) A firewall D) A browser
    Answer: A
  9. What is RFID hacking?
    A) Cloning RFID cards B) A type of malware C) A firewall D) A browser
    Answer: A
  10. How can you protect your Wi-Fi?
    A) Use WPA2/WPA3 B) Use WEP C) Use no password D) Use a weak password
    Answer: A
  11. What is the difference between WEP and WPA2?
    A) WPA2 is much stronger B) They are the same C) WEP is stronger D) WPA2 is weaker
    Answer: A
  12. What is the difference between WPA2 and WPA3?
    A) WPA3 is newer and stronger B) They are the same C) WPA2 is newer D) WPA3 is weaker
    Answer: A
  13. What is a side-channel attack?
    A) An attack on WPA3 B) A type of malware C) A firewall D) A browser
    Answer: A
  14. What is a downgrade attack?
    A) Forcing a device to use weaker security B) A type of malware C) A firewall D) A browser
    Answer: A
  15. Why do Nigerian companies need wireless security?
    A) To protect their networks B) To allow attacks C) To save money D) None
    Answer: A

🔗 Matching Exercise

TermMatch with
1. WEPA. The newest Wi-Fi protocol
2. WPA2B. Weak Wi-Fi protocol
3. WPA3C. Most common Wi-Fi protocol
4. Evil TwinD. Fake Wi-Fi network
5. Deauth attackE. Disconnects a device

Answers: 1-B, 2-C, 3-A, 4-D, 5-E

✏️ Short Answer Questions

  1. Explain the difference between WEP, WPA2, and WPA3.
  2. What is an evil twin attack and why is it dangerous?
  3. How can you protect your home Wi-Fi network?

🎭 Scenario‑based Exercise

Scenario: You are an ethical hacker hired by a school in Abuja. The school uses WEP for their Wi-Fi network. You discover that the password is easily cracked. What would you recommend?

👥 Group Activity

In groups of 4, create a poster that explains how to secure a Wi-Fi network. Include tips on choosing a strong password and using the right security protocol.

🧑‍💻 Individual Activity

Write a short essay on why wireless security is important for Nigerian businesses.

💬 Classroom Discussion Questions

  • Why do you think many people still use WEP?
  • How can we educate people about Wi-Fi security?
  • What would you do if you discovered your Wi-Fi was being hacked?

🛠️ Mini Project

Project: Create a Wi-Fi security checklist for a small business. Include items like using WPA2, disabling WPS, and changing the default SSID.

🔧 Practical Assignment

Use your home Wi-Fi router's settings to check which security protocol it uses. If it's WEP, change it to WPA2. Write a short report on what you found.

⚡ Challenge Exercise

Research how WPA3 improves on WPA2. Write a one-page explanation and give examples of its benefits.

✅ Quiz Answers (Selected)

  • Fill‑in‑the‑blank: 1) WEP, 2) WPA2, 3) WPA3, 4) Evil Twin, 5) Deauth.
  • True/False: 1F, 2T, 3T, 4F, 5F.

🔑 Key Takeaways

  • WEP is weak and unsafe.
  • WPA2 and WPA3 are much stronger.
  • Evil twin attacks use fake networks.
  • Bluetooth and RFID have security risks.
  • Use strong passwords and keep your router updated.
  • Ethical hackers test and secure wireless networks.

🚀 Preparation for Module Ten

In Module Ten, we will learn about mobile application security. We will explore Android and iOS security, rooting and jailbreaking, and mobile app analysis. Make sure you understand the wireless concepts from this module.


🔥 You have completed Module Nine of Level Three! Keep up the great work 🔥

11

Module Ten

Module Ten · Ethical Hacking Level Three

📱 Module Ten · Introduction to Ethical Hacking Level Three

Mobile Application Security – protecting the devices in our pockets.

📖 Module Introduction

Welcome to Module Ten! In this module, we will learn about mobile application security. Almost everyone has a smartphone today. We use them for banking, shopping, messaging, and even controlling our homes. But these powerful devices can also be targets for hackers.

Think of your phone like a mini-computer that you carry everywhere. It stores your photos, messages, passwords, and even your location. If a hacker breaks into your phone, they can steal everything.

We will explore Android and iOS security, rooting and jailbreaking, mobile app analysis, and the OWASP Mobile Top 10. By the end of this module, you will understand how to protect mobile devices from attacks.

🎯 Learning Objectives

By the end of this module, you will be able to:

  • Explain how mobile security works.
  • Understand the Android security model.
  • Understand the iOS security model.
  • Learn about rooting and jailbreaking.
  • Understand the OWASP Mobile Top 10.
  • Learn about mobile app analysis tools.
  • Apply these ideas to Nigerian mobile users.

📖 Warm‑up Story · The Super Phone

Once upon a time, in a school in Abuja, there was a student named Fatima. She had a super phone that could do everything – take pictures, play games, and even do her homework.

One day, Fatima downloaded a game from a random website. The game looked fun, but it had a hidden secret. It was a malicious app that stole all her contacts and photos. Fatima didn't know until her friends started getting strange messages from her number.

That is exactly what mobile hacking is – using malicious apps to steal information from phones. In this module, we will learn how these attacks work and how to protect ourselves.

📚 Main Lessons

Lesson 1 · What is Mobile Application Security?

Definition: Mobile application security is the protection of mobile devices and the apps on them from attacks.

Why it is important: Mobile devices store a lot of personal information. If they are hacked, your privacy is at risk.

Simple explanation: It's like putting a lock on your phone to keep your secrets safe.

Real‑life example: A bank's mobile app uses encryption to protect your financial data.

School example: A school uses a secure app for students to check their grades.

Home example: A family uses a secure messaging app to share photos.

Nigerian example: A Nigerian fintech company uses mobile security to protect customer data.

Mini summary: Mobile security protects phones and apps.

Lesson 2 · The Android Security Model

Definition: Android is an open operating system. It uses a permission system to control what apps can do.

Why it is important: Understanding Android security helps us protect our devices.

Simple explanation: It's like a bouncer who checks your ID before letting you into a club.

Lesson 3 · The iOS Security Model

Definition: iOS is a closed operating system. It has strict security measures to protect users.

Why it is important: iOS is generally more secure than Android, but it's not perfect.

Simple explanation: It's like a VIP club where only certain people are allowed in.

Lesson 4 · What is Rooting?

Definition: Rooting is the process of gaining full control of an Android device. It removes restrictions.

Why it is dangerous: Rooting can make the device more vulnerable to attacks.

Simple explanation: It's like becoming the king of your phone and having all the power.

Real‑life example: A hacker roots a phone to install malicious software.

School example: A student roots their phone to bypass school restrictions.

Home example: A family member roots their phone to install custom software.

Nigerian example: A Nigerian hacker roots a phone to steal data.

Mini summary: Rooting gives full control of Android.

Lesson 5 · What is Jailbreaking?

Definition: Jailbreaking is the process of removing restrictions on iOS devices.

Why it is dangerous: Jailbreaking can make the device more vulnerable to attacks.

Simple explanation: It's like breaking out of prison to get more freedom.

Lesson 6 · OWASP Mobile Top 10

The OWASP Mobile Top 10 is a list of the most critical mobile security risks. These include:

  • Insecure data storage: Storing passwords without encryption.
  • Weak authentication: Weak login methods.
  • Insecure communication: Sending data without encryption.
  • Poor code quality: Apps with bugs.

Lesson 7 · Insecure Data Storage

Many apps store sensitive data on the device without encryption. Hackers can steal this data.

Lesson 8 · Weak Authentication and Authorization

Weak login methods can allow hackers to access your account.

Lesson 9 · Insecure Communication

If an app doesn't use encryption, hackers can intercept the data.

Lesson 10 · Mobile Malware

Mobile malware is bad software that infects phones. It can steal data, send messages, or even spy on you.

Lesson 11 · Mobile App Analysis Tools

  • MobSF: A tool for analysing mobile apps.
  • Frida: A tool for dynamic analysis.
  • Drozer: A tool for testing Android apps.
  • Burp Suite: Used for testing mobile app APIs.

Lesson 12 · Dynamic vs Static Analysis

Static analysis: Looking at the app's code without running it.

Dynamic analysis: Running the app to see what it does.

Lesson 13 · Protecting Mobile Devices

  • Only download apps from official stores.
  • Keep your device updated.
  • Use strong passwords or biometrics.
  • Use a VPN on public Wi-Fi.
  • Be careful what permissions you grant.

Lesson 14 · The Role of Ethical Hackers

Ethical hackers test mobile apps for vulnerabilities and help developers fix them.

📖 Key Vocabulary (Simple Definitions)

WordSimple meaning
RootingGaining full control of Android.
JailbreakingRemoving restrictions on iOS.
OWASP Mobile Top 10A list of top mobile vulnerabilities.
Static analysisLooking at code without running it.
Dynamic analysisRunning the app to test it.
MobSFA mobile app analysis tool.
FridaA dynamic analysis tool.
MalwareBad software that harms devices.
EncryptionScrambling data to protect it.
AuthenticationVerifying a user's identity.

🧠 Important Concepts

  • Permission system: Controls what apps can do.
  • Sandboxing: Isolating apps so they can't interfere with each other.
  • Code obfuscation: Making code harder to understand.
  • App signing: Verifying the authenticity of an app.

🔢 Step‑by‑Step: How to Analyze a Mobile App

  1. Download the app from the app store.
  2. Use static analysis to examine the code.
  3. Use dynamic analysis to run the app and watch its behaviour.
  4. Check for insecure data storage.
  5. Check for insecure communication.
  6. Check for weak authentication.
  7. Report the findings.

🌍 Real‑life Examples

1. Banking: A bank's mobile app is tested for security vulnerabilities.

2. Social Media: A social media app is hacked to steal user data.

🇳🇬 Nigerian Examples

  • A Nigerian fintech company uses MobSF to test its mobile app.
  • A Nigerian university uses Frida to analyse student apps.
  • A Nigerian bank uses strong encryption to protect its mobile app.

🎈 Fun Examples for Kids

  • Imagine a game that asks for permission to access your contacts. If it doesn't need them, it might be suspicious.
  • Rooting is like becoming the game master of your phone – you can change anything.

🏡 Everyday Examples

  • If you download a flashlight app that asks for permission to access your contacts, that's suspicious.
  • If you get a message from a friend with a strange link, don't click it.

👩‍🏫 Teacher Notes

Use the super phone story to introduce mobile security. Emphasise that mobile devices need protection just like computers. Encourage students to think about the permissions they grant to apps.

👪 Parent Tips

  • Teach your child to only download apps from official stores.
  • Show them how to check app permissions.
  • Explain why it's important to keep devices updated.

✨ Interesting Facts

💡 The first mobile malware was discovered in 2004.
💡 Over 2.5 billion people use Android devices.

❓ Did You Know?

🔹 In Nigeria, mobile banking apps are a common target for hackers.
🔹 The OWASP Mobile Top 10 is updated every few years.

🧾 Remember This

⚠️ Only download apps from official stores.
🔒 Keep your device updated.
📱 Check app permissions before granting them.

❌ Common Mistakes

  • Downloading apps from unofficial sources.
  • Granting unnecessary permissions.
  • Not updating the device.
  • Using weak passwords.

✅ Best Practices

  • Download from official stores.
  • Check app permissions.
  • Keep the device updated.
  • Use strong passwords or biometrics.
  • Use a VPN on public Wi-Fi.

📊 ASCII Illustrations & Flowcharts

Mobile App Analysis Process

    Get the app
          |
          v
    Static Analysis (look at code)
          |
          v
    Dynamic Analysis (run the app)
          |
          v
    Check for vulnerabilities
          |
          v
    Report findings
    

Android Security Model

    App requests permission
          |
          v
    User grants or denies
          |
          v
    If granted, app can access
          |
          v
    If denied, app cannot access
    

OWASP Mobile Top 10

    1. Insecure Data Storage
    2. Weak Authentication
    3. Insecure Communication
    4. Poor Code Quality
    5. Reverse Engineering
    6. Improper Platform Usage
    7. Insufficient Cryptography
    8. Client-side Injection
    9. Security Decisions via Untrusted Inputs
    10. Session Handling
    

📋 Comparison Table: Android vs iOS Security

AndroidiOS
Open systemClosed system
More malwareLess malware
More customisableMore restrictive
Rooting gives full controlJailbreaking removes restrictions

📋 Comparison Table: Static vs Dynamic Analysis

Static AnalysisDynamic Analysis
Without running the appRunning the app
FasterSlower
SaferRequires sandbox
Less informationMore information

📌 Lesson Summaries

  • Lesson 1: Mobile security protects phones and apps.
  • Lesson 2: Android uses a permission system.
  • Lesson 3: iOS has strict security measures.
  • Lesson 4: Rooting gives full control of Android.
  • Lesson 5: Jailbreaking removes iOS restrictions.
  • Lesson 6: OWASP Mobile Top 10 lists key vulnerabilities.
  • Lesson 7: Insecure data storage is a common risk.
  • Lesson 8: Weak authentication is a risk.
  • Lesson 9: Insecure communication is a risk.
  • Lesson 10: Mobile malware can steal data.
  • Lesson 11: Tools like MobSF help test apps.
  • Lesson 12: Static and dynamic analysis are different.
  • Lesson 13: Protect devices with updates and strong passwords.
  • Lesson 14: Ethical hackers test mobile security.

📝 End‑of‑Module Summary

In Module Ten, we learned about mobile application security. We explored the Android and iOS security models, rooting and jailbreaking, and the OWASP Mobile Top 10. We also learned about mobile app analysis tools and how to protect our devices. Remember, mobile devices are powerful and convenient, but they need proper security. By understanding the risks, we can keep our devices safe.

❓ Frequently Asked Questions (10)

  1. Q: What is mobile application security?
    A: Protecting phones and apps.
  2. Q: What is rooting?
    A: Gaining full control of Android.
  3. Q: What is jailbreaking?
    A: Removing iOS restrictions.
  4. Q: What is the OWASP Mobile Top 10?
    A: A list of top mobile vulnerabilities.
  5. Q: What is static analysis?
    A: Looking at code without running it.
  6. Q: What is dynamic analysis?
    A: Running the app to test it.
  7. Q: What is MobSF?
    A: A mobile app analysis tool.
  8. Q: What is Frida?
    A: A dynamic analysis tool.
  9. Q: How can I protect my phone?
    A: Use official stores and keep it updated.
  10. Q: Can ethical hackers test mobile apps?
    A: Yes, with permission.

📌 Review Questions (15)

  1. What is mobile application security?
  2. What is the Android security model?
  3. What is the iOS security model?
  4. What is rooting?
  5. What is jailbreaking?
  6. What is the OWASP Mobile Top 10?
  7. What is insecure data storage?
  8. What is weak authentication?
  9. What is insecure communication?
  10. What is mobile malware?
  11. What is MobSF?
  12. What is Frida?
  13. What is the difference between static and dynamic analysis?
  14. How can you protect your mobile device?
  15. Why do Nigerian companies need mobile security?

✍️ Fill‑in‑the‑Blank

  1. ________ is gaining full control of Android.
  2. ________ is removing iOS restrictions.
  3. ________ is a list of top mobile vulnerabilities.
  4. ________ is looking at code without running it.
  5. ________ is a mobile app analysis tool.

✔️ True or False

  1. Android is more secure than iOS. (False)
  2. Rooting gives full control of Android. (True)
  3. Jailbreaking removes iOS restrictions. (True)
  4. OWASP Mobile Top 10 is a list of vulnerabilities. (True)
  5. Mobile malware is not dangerous. (False)

🔘 Multiple Choice Questions

  1. What is rooting?
    A) Gaining full control of Android B) Removing iOS restrictions C) A type of malware D) A firewall
    Answer: A
  2. What is jailbreaking?
    A) Removing iOS restrictions B) Gaining full control of Android C) A type of malware D) A firewall
    Answer: A
  3. What is the OWASP Mobile Top 10?
    A) A list of mobile vulnerabilities B) A type of malware C) A firewall D) A browser
    Answer: A
  4. What is static analysis?
    A) Looking at code without running it B) Running the app C) A type of malware D) A firewall
    Answer: A
  5. What is dynamic analysis?
    A) Running the app to test it B) Looking at code without running it C) A type of malware D) A firewall
    Answer: A
  6. What is MobSF?
    A) A mobile app analysis tool B) A type of malware C) A firewall D) A browser
    Answer: A
  7. What is Frida?
    A) A dynamic analysis tool B) A type of malware C) A firewall D) A browser
    Answer: A
  8. What is mobile malware?
    A) Bad software for phones B) A type of firewall C) A browser D) A game
    Answer: A
  9. What is insecure data storage?
    A) Storing data without encryption B) A type of malware C) A firewall D) A browser
    Answer: A
  10. What is weak authentication?
    A) Weak login methods B) A type of malware C) A firewall D) A browser
    Answer: A
  11. What is insecure communication?
    A) Sending data without encryption B) A type of malware C) A firewall D) A browser
    Answer: A
  12. How can you protect your phone?
    A) Use official stores and update B) Download from anywhere C) Ignore updates D) Use weak passwords
    Answer: A
  13. What is the permission system?
    A) Controls what apps can do B) A type of malware C) A firewall D) A browser
    Answer: A
  14. What is sandboxing?
    A) Isolating apps B) A type of malware C) A firewall D) A browser
    Answer: A
  15. Why do Nigerian companies need mobile security?
    A) To protect customer data B) To allow attacks C) To save money D) None
    Answer: A

🔗 Matching Exercise

TermMatch with
1. RootingA. Removing iOS restrictions
2. JailbreakingB. Gaining full control of Android
3. OWASP Mobile Top 10C. List of mobile vulnerabilities
4. Static analysisD. Looking at code without running
5. Dynamic analysisE. Running the app to test it

Answers: 1-B, 2-A, 3-C, 4-D, 5-E

✏️ Short Answer Questions

  1. Explain the difference between rooting and jailbreaking.
  2. What is the OWASP Mobile Top 10?
  3. How can you protect your mobile device from attacks?

🎭 Scenario‑based Exercise

Scenario: You are an ethical hacker hired by a school in Lagos. The school uses a mobile app for student registration. You suspect it might have vulnerabilities. What would you do?

👥 Group Activity

In groups of 4, create a poster that explains the OWASP Mobile Top 10. Include examples and how to protect against each vulnerability.

🧑‍💻 Individual Activity

Write a short essay on why mobile security is important for Nigerian businesses.

💬 Classroom Discussion Questions

  • Why do you think mobile devices are targeted by hackers?
  • How can we educate people about mobile security?
  • What would you do if you discovered a vulnerability in a mobile app you use?

🛠️ Mini Project

Project: Create a mobile security checklist for a small business. Include items like using official stores, checking permissions, and updating devices.

🔧 Practical Assignment

Research a real-world mobile malware attack. Write a short report on what happened and how it could have been prevented.

⚡ Challenge Exercise

Research how MobSF works. Write a one-page explanation and describe how it can be used for ethical testing.

✅ Quiz Answers (Selected)

  • Fill‑in‑the‑blank: 1) Rooting, 2) Jailbreaking, 3) OWASP Mobile Top 10, 4) Static analysis, 5) MobSF.
  • True/False: 1F, 2T, 3T, 4T, 5F.

🔑 Key Takeaways

  • Mobile devices need strong security.
  • Rooting and jailbreaking can make devices vulnerable.
  • OWASP Mobile Top 10 lists key vulnerabilities.
  • Use official stores, updates, and strong passwords.
  • Ethical hackers test mobile security.
  • Always check app permissions.

🚀 Preparation for Module Eleven

In Module Eleven, we will learn about IoT and OT hacking. We will explore the Internet of Things, smart devices, and industrial control systems. Make sure you understand the mobile security concepts from this module.


🔥 You have completed Module Ten of Level Three! Keep up the great work. 🔥

12

Module Eleven

Module Eleven · Ethical Hacking Level Three

🏠 Module Eleven · Introduction to Ethical Hacking Level Three

IoT and OT Hacking – the hidden dangers of smart devices and industrial systems.

📖 Module Introduction

Welcome to Module Eleven! In this module, we will learn about IoT (Internet of Things) and OT (Operational Technology) hacking. These are the devices and systems that run our modern world – smart fridges, security cameras, power plants, and factories.

Think of IoT like a world where everything has a brain. Your fridge can tell you when you're out of milk. Your watch can track your heart rate. Your car can drive itself. But these brains can also be hacked.

We will explore IoT architecture, common IoT vulnerabilities, OT/SCADA security, and famous IoT attacks like the Mirai botnet. By the end of this module, you will understand how to protect the smart world around you.

🎯 Learning Objectives

By the end of this module, you will be able to:

  • Explain what IoT and OT are.
  • Understand the architecture of IoT systems.
  • Learn about common IoT vulnerabilities.
  • Understand OT and SCADA security.
  • Learn about the Mirai botnet attack.
  • Understand how to secure IoT devices.
  • Apply these ideas to Nigerian homes and businesses.

📖 Warm‑up Story · The Smart Fridge

Once upon a time, in a modern home in Abuja, there was a family who had a smart fridge. The fridge could tell you when you were out of milk and even order groceries online. It was connected to the internet.

One day, a hacker found a vulnerability in the fridge's software. They used it to get into the family's Wi-Fi network and steal their personal information. The family was shocked – a fridge had helped a hacker break in!

That is exactly what we will learn in this module – how smart devices can be hacked, and how to protect them.

📚 Main Lessons

Lesson 1 · What is IoT?

Definition: IoT stands for Internet of Things. It refers to everyday devices that are connected to the internet – like smart fridges, cameras, and thermostats.

Why it is important: IoT devices are everywhere. If they are not secure, hackers can use them to break into networks or cause harm.

Simple explanation: It's like having a toaster that can talk to the internet.

Real‑life example: A smart home has devices that can be controlled from a phone.

School example: A school uses smart cameras for security.

Home example: A family uses a smart thermostat to control the temperature.

Nigerian example: Many Nigerian homes are using smart devices like smart TVs and security cameras.

Mini summary: IoT is everyday devices connected to the internet.

Lesson 2 · What is OT?

Definition: OT stands for Operational Technology. It refers to the hardware and software used to control industrial systems – like power plants, water treatment plants, and factories.

Why it is important: OT systems control critical infrastructure. If they are hacked, it can cause real-world damage.

Simple explanation: It's like the brains of a factory or power plant.

Lesson 3 · IoT Architecture

IoT systems have three layers:

  • Sensors: Devices that collect data (like temperature sensors).
  • Network: The connection between devices and the internet.
  • Cloud: Where data is stored and processed.

Lesson 4 · Common IoT Vulnerabilities

  • Default passwords: Many devices come with passwords like "admin" or "1234".
  • Lack of updates: IoT devices rarely get security updates.
  • Insecure communication: Data sent from IoT devices is often not encrypted.
  • Physical security: Devices can be physically accessed and tampered with.

Lesson 5 · Default Passwords

Definition: Default passwords are the passwords that come with a device. Hackers know these passwords and use them to break in.

Why it is dangerous: Many people never change the default password, making it easy for hackers.

Simple explanation: It's like buying a lock that comes with a key that everyone knows.

Real‑life example: A hacker uses the default password "admin" to access a smart camera.

School example: A school forgets to change the default password on its security cameras.

Home example: A family uses the default password on their smart TV.

Nigerian example: Many Nigerian homes use default passwords on their routers and smart devices.

Mini summary: Default passwords are a big security risk.

Lesson 6 · Lack of Updates

IoT devices often don't receive security updates. This means known vulnerabilities stay unpatched.

Lesson 7 · Insecure Communication

Many IoT devices send data without encryption. Hackers can intercept and read this data.

Lesson 8 · What is SCADA?

Definition: SCADA stands for Supervisory Control and Data Acquisition. It is a system used to control industrial processes.

Why it is important: SCADA systems control critical infrastructure like power grids and water treatment plants.

Simple explanation: It's like the control room of a factory.

Lesson 9 · OT/SCADA Security

OT/SCADA systems are often older and less secure than IT systems. They are also harder to update because downtime is not allowed.

Lesson 10 · The Mirai Botnet

Definition: The Mirai botnet was a massive attack in 2016 that used insecure IoT devices to launch a DDoS attack.

Why it is important: The Mirai attack showed how dangerous insecure IoT devices can be.

Simple explanation: It was like an army of smart devices attacking the internet.

Real‑life example: The Mirai attack took down major websites like Twitter and Netflix.

School example: A school's network could be used in a botnet attack.

Home example: A family's smart devices could be part of a botnet without them knowing.

Nigerian example: Nigerian IoT devices could be used in botnet attacks.

Mini summary: The Mirai botnet used insecure IoT devices.

Lesson 11 · Securing IoT Devices

  • Change default passwords.
  • Keep devices updated.
  • Use a separate network for IoT devices.
  • Disable unused features.
  • Use encryption.

Lesson 12 · Securing OT/SCADA Systems

  • Use network segmentation.
  • Monitor for unusual activity.
  • Use firewalls.
  • Regularly audit systems.

Lesson 13 · The Role of Ethical Hackers

Ethical hackers test IoT and OT systems to find vulnerabilities and help protect them.

📖 Key Vocabulary (Simple Definitions)

WordSimple meaning
IoTEveryday devices connected to the internet.
OTSystems that control industrial processes.
SCADAA system for controlling industrial processes.
BotnetA network of infected devices used for attacks.
Default passwordThe password that comes with a device.
EncryptionScrambling data to protect it.
Network segmentationSeparating networks for security.
FirmwareThe software inside a device.
VulnerabilityA weakness that can be exploited.
DDoSDistributed Denial of Service attack.

🧠 Important Concepts

  • Defence in depth: Using many layers of security.
  • Segmentation: Isolating IoT devices from critical networks.
  • Zero trust: Never trusting any device by default.
  • Patch management: Keeping devices updated.

🔢 Step‑by‑Step: How the Mirai Botnet Worked

  1. Hackers scanned the internet for IoT devices with default passwords.
  2. They infected these devices with Mirai malware.
  3. The infected devices became a botnet.
  4. The botnet was used to launch a massive DDoS attack.
  5. Major websites were taken offline.

🌍 Real‑life Examples

1. Power Grid: A hacker attacks a power grid's OT system, causing a blackout.

2. Healthcare: A hospital's IoT devices are hacked, disrupting patient care.

🇳🇬 Nigerian Examples

  • A Nigerian factory uses OT systems to control its machinery.
  • A Nigerian home uses smart devices that need to be secured.
  • A Nigerian company uses network segmentation to protect its IoT devices.

🎈 Fun Examples for Kids

  • Imagine a smart toy that connects to the internet. If it's not secure, a hacker could play with it remotely!
  • A botnet is like an army of robots that a hacker controls.

🏡 Everyday Examples

  • Your family's smart TV – if it's not updated, hackers could access it.
  • Your phone's apps – if they ask for too many permissions, they might be up to something.

👩‍🏫 Teacher Notes

Use the smart fridge story to introduce IoT. Emphasise that new technologies bring new risks. Encourage students to think about how they can protect their own devices.

👪 Parent Tips

  • Change default passwords on all smart devices.
  • Keep devices updated.
  • Use a separate Wi-Fi network for IoT devices.

✨ Interesting Facts

💡 There are more than 20 billion IoT devices in the world.
💡 The Mirai botnet attack in 2016 was one of the biggest DDoS attacks ever.

❓ Did You Know?

🔹 In Nigeria, smart home devices are becoming more popular.
🔹 Many OT systems are still running on outdated software.

🧾 Remember This

⚠️ Always change default passwords on devices.
🔒 Keep all devices updated.
📱 Use a separate network for IoT devices.

❌ Common Mistakes

  • Using default passwords on IoT devices.
  • Not updating devices.
  • Connecting IoT devices to the main network.
  • Ignoring IoT security.

✅ Best Practices

  • Change default passwords.
  • Keep devices updated.
  • Use separate networks.
  • Monitor for unusual activity.
  • Disable unused features.

📊 ASCII Illustrations & Flowcharts

IoT Architecture

    Sensors  ---->  Network  ---->  Cloud
    (devices)    (Wi-Fi)      (storage)
    

Mirai Botnet Attack

    Hackers scan for IoT devices
           |
           v
    Infect devices with Mirai
           |
           v
    Create botnet
           |
           v
    Launch DDoS attack
           |
           v
    Websites go down
    

IoT Security Checklist

    Change default passwords
    Keep devices updated
    Use separate network
    Disable unused features
    Use encryption
    

📋 Comparison Table: IoT vs OT

IoTOT
Consumer devicesIndustrial systems
Smart homeFactory control
Easier to secureHarder to secure
Often consumer-gradeOften enterprise-grade

📋 Comparison Table: Level Two vs Level Three IoT Hacking

Level TwoLevel Three
Basic IoT vulnerabilitiesAdvanced IoT attacks
Simple device hackingBotnet creation
Basic securityOT/SCADA security
Focused on home devicesIncludes industrial systems

📌 Lesson Summaries

  • Lesson 1: IoT is everyday devices connected to the internet.
  • Lesson 2: OT controls industrial systems.
  • Lesson 3: IoT has sensors, network, and cloud layers.
  • Lesson 4: Default passwords and lack of updates are common issues.
  • Lesson 5: Default passwords are a major risk.
  • Lesson 6: Lack of updates leaves devices vulnerable.
  • Lesson 7: Insecure communication can be intercepted.
  • Lesson 8: SCADA controls critical infrastructure.
  • Lesson 9: OT systems are harder to secure.
  • Lesson 10: The Mirai botnet used insecure IoT devices.
  • Lesson 11: Change passwords and update devices.
  • Lesson 12: Use segmentation and monitoring for OT.
  • Lesson 13: Ethical hackers test and secure IoT/OT.

📝 End‑of‑Module Summary

In Module Eleven, we learned about IoT and OT hacking. We explored the Internet of Things, smart devices, and industrial control systems. We learned about common vulnerabilities like default passwords and lack of updates, and we studied the Mirai botnet attack. Remember, IoT and OT devices are everywhere, and they need proper security to protect our homes, businesses, and critical infrastructure.

❓ Frequently Asked Questions (10)

  1. Q: What is IoT?
    A: Everyday devices connected to the internet.
  2. Q: What is OT?
    A: Systems that control industrial processes.
  3. Q: What is SCADA?
    A: A system for controlling industrial processes.
  4. Q: What is a botnet?
    A: A network of infected devices.
  5. Q: What is a default password?
    A: The password that comes with a device.
  6. Q: What was the Mirai botnet?
    A: A massive IoT attack in 2016.
  7. Q: How can I secure my IoT devices?
    A: Change default passwords and keep them updated.
  8. Q: What is network segmentation?
    A: Separating networks for security.
  9. Q: Why are OT systems hard to secure?
    A: They are old and downtime is not allowed.
  10. Q: Can ethical hackers test IoT/OT systems?
    A: Yes, with permission.

📌 Review Questions (15)

  1. What is IoT?
  2. What is OT?
  3. What is SCADA?
  4. What is a botnet?
  5. What is a default password?
  6. What was the Mirai botnet?
  7. How can you secure IoT devices?
  8. What is network segmentation?
  9. Why are OT systems hard to secure?
  10. What is the difference between IoT and OT?
  11. What is the three-layer architecture of IoT?
  12. What are common IoT vulnerabilities?
  13. What is encryption and why is it important?
  14. What is defence in depth?
  15. Why do Nigerian companies need IoT/OT security?

✍️ Fill‑in‑the‑Blank

  1. ________ is everyday devices connected to the internet.
  2. ________ is a system for controlling industrial processes.
  3. ________ is a network of infected devices.
  4. ________ is the password that comes with a device.
  5. ________ was a massive IoT attack in 2016.

✔️ True or False

  1. IoT devices are always secure. (False)
  2. Default passwords are a security risk. (True)
  3. OT systems are easy to update. (False)
  4. The Mirai botnet used insecure IoT devices. (True)
  5. Encryption is not important for IoT. (False)

🔘 Multiple Choice Questions

  1. What is IoT?
    A) Everyday devices connected to the internet B) A type of malware C) A firewall D) A browser
    Answer: A
  2. What is OT?
    A) Systems that control industrial processes B) A type of malware C) A firewall D) A browser
    Answer: A
  3. What is SCADA?
    A) A system for controlling industrial processes B) A type of malware C) A firewall D) A browser
    Answer: A
  4. What is a botnet?
    A) A network of infected devices B) A type of malware C) A firewall D) A browser
    Answer: A
  5. What is a default password?
    A) The password that comes with a device B) A type of malware C) A firewall D) A browser
    Answer: A
  6. What was the Mirai botnet?
    A) A massive IoT attack B) A type of malware C) A firewall D) A browser
    Answer: A
  7. How can you secure IoT devices?
    A) Change default passwords B) Use weak passwords C) Ignore updates D) Disable security
    Answer: A
  8. What is network segmentation?
    A) Separating networks for security B) A type of malware C) A firewall D) A browser
    Answer: A
  9. Why are OT systems hard to secure?
    A) They are old and downtime is not allowed B) They are too new C) They are not important D) They are easy to update
    Answer: A
  10. What is the three-layer architecture of IoT?
    A) Sensors, network, cloud B) A type of malware C) A firewall D) A browser
    Answer: A
  11. What is a common IoT vulnerability?
    A) Default passwords B) Strong passwords C) Encryption D) Updates
    Answer: A
  12. What is encryption?
    A) Scrambling data to protect it B) A type of malware C) A firewall D) A browser
    Answer: A
  13. What is defence in depth?
    A) Using many layers of security B) A type of malware C) A firewall D) A browser
    Answer: A
  14. What is the difference between IoT and OT?
    A) IoT is consumer devices; OT is industrial B) They are the same C) OT is consumer devices D) IoT is industrial
    Answer: A
  15. Why do Nigerian companies need IoT/OT security?
    A) To protect their systems B) To allow attacks C) To save money D) None
    Answer: A

🔗 Matching Exercise

TermMatch with
1. IoTA. Industrial control systems
2. OTB. Everyday devices connected to the internet
3. SCADAC. Network of infected devices
4. BotnetD. Password that comes with a device
5. Default passwordE. System for controlling industrial processes

Answers: 1-B, 2-A, 3-E, 4-C, 5-D

✏️ Short Answer Questions

  1. Explain the difference between IoT and OT.
  2. What was the Mirai botnet and why was it important?
  3. How can you secure IoT devices in your home?

🎭 Scenario‑based Exercise

Scenario: You are an ethical hacker hired by a factory in Lagos. The factory uses IoT devices and an OT system. You discover that many devices have default passwords and are not updated. What would you recommend?

👥 Group Activity

In groups of 4, create a poster that explains IoT and OT security risks and how to protect against them.

🧑‍💻 Individual Activity

Write a short essay on why IoT security is important for Nigerian homes and businesses.

💬 Classroom Discussion Questions

  • Why do you think IoT devices are often insecure?
  • How can we educate people about IoT security?
  • What would you do if you discovered a vulnerability in a smart device you use?

🛠️ Mini Project

Project: Create an IoT security checklist for a family. Include items like changing default passwords, using separate networks, and keeping devices updated.

🔧 Practical Assignment

Research a real-world IoT or OT attack. Write a short report on what happened and how it could have been prevented.

⚡ Challenge Exercise

Research how SCADA systems work. Write a one-page explanation and describe the security risks.

✅ Quiz Answers (Selected)

  • Fill‑in‑the‑blank: 1) IoT, 2) SCADA, 3) Botnet, 4) Default password, 5) Mirai.
  • True/False: 1F, 2T, 3F, 4T, 5F.

🔑 Key Takeaways

  • IoT is everyday devices connected to the internet.
  • OT controls industrial systems like factories and power plants.
  • Default passwords and lack of updates are common IoT vulnerabilities.
  • The Mirai botnet showed how dangerous insecure IoT devices can be.
  • Secure IoT devices by changing passwords and keeping them updated.
  • OT systems need extra protection because they control critical infrastructure.

🚀 Preparation for Module Twelve

In Module Twelve, we will learn about cloud security. We will explore AWS, Azure, GCP, and container security. Make sure you understand the IoT and OT concepts from this module.


🔥 You have completed Module Eleven of Level Three! Keep up the great work. 🔥

13

Module Twelve

Module Twelve · Ethical Hacking Level Three

☁️ Module Twelve · Introduction to Ethical Hacking Level Three

Cloud Security – protecting data in the sky.

📖 Module Introduction

Welcome to Module Twelve! In this module, we will learn about cloud security. Cloud computing is like renting a computer in the sky. Instead of buying your own servers, you use someone else's – like Amazon Web Services (AWS), Microsoft Azure, or Google Cloud Platform (GCP).

Think of the cloud like a storage unit in a big building. You can store your things there, and you can access them from anywhere. But if the building is not secure, your things can be stolen.

We will explore cloud concepts, common cloud threats, S3 bucket misconfigurations, container security, and serverless security. By the end of this module, you will understand how to protect data in the cloud.

🎯 Learning Objectives

By the end of this module, you will be able to:

  • Explain what cloud computing is.
  • Understand the shared responsibility model.
  • Learn about common cloud threats.
  • Understand S3 bucket misconfigurations.
  • Learn about container security.
  • Understand serverless security.
  • Apply these ideas to Nigerian businesses.

📖 Warm‑up Story · The Storage Unit

Once upon a time, in Lagos, a business owner named Chidi wanted to store his important documents. He didn't have space in his office, so he rented a storage unit. He put all his documents there and locked the door.

One day, he forgot to lock the door properly. A thief walked in, took all his documents, and disappeared. Chidi lost everything.

That is exactly what cloud misconfiguration is – leaving the door open for hackers. In this module, we will learn how to lock the door properly and protect our data in the cloud.

📚 Main Lessons

Lesson 1 · What is Cloud Computing?

Definition: Cloud computing is using the internet to access computing services – like storage, servers, and software – instead of using your own computer.

Why it is important: Many businesses use the cloud. If a cloud service is hacked, it can affect millions of people.

Simple explanation: It's like renting a storage unit for your files instead of keeping them at home.

Real‑life example: Google Drive, Dropbox, and Amazon Web Services (AWS) are cloud services.

School example: A school might use Google Classroom to store student work.

Home example: A family might use iCloud to store photos.

Nigerian example: Many Nigerian businesses use cloud services like AWS and Microsoft Azure.

Mini summary: Cloud computing is using internet-based services.

Lesson 2 · The Shared Responsibility Model

Definition: The shared responsibility model means that cloud security is shared between the cloud provider and the customer.

Why it is important: The cloud provider secures the cloud, but the customer must secure what they put in the cloud.

Simple explanation: It's like a building – the owner keeps the building safe, but you must lock your own door.

Lesson 3 · Cloud Service Models

  • IaaS (Infrastructure as a Service): You rent servers and storage.
  • PaaS (Platform as a Service): You rent a platform to build apps.
  • SaaS (Software as a Service): You rent software like email.

Lesson 4 · Common Cloud Threats

  • Misconfigurations: Cloud services are often set up incorrectly.
  • Data breaches: Hackers steal data from the cloud.
  • Insecure APIs: The tools that connect to the cloud can be vulnerable.
  • Account hijacking: Hackers steal cloud account passwords.
  • Insider threats: Employees can misuse their access.

Lesson 5 · S3 Bucket Misconfigurations

Definition: S3 buckets are storage containers in Amazon Web Services. Sometimes they are left open to the public, allowing anyone to access the data.

Why it is dangerous: S3 buckets can contain sensitive customer data.

Simple explanation: It's like leaving your storage unit door wide open.

Real‑life example: A company accidentally makes their S3 bucket public, exposing customer data.

School example: A school leaves its student data bucket open.

Home example: A family leaves their photo bucket open.

Nigerian example: A Nigerian company might accidentally leave their S3 bucket open.

Mini summary: S3 bucket misconfigurations expose data.

Lesson 6 · How to Secure S3 Buckets

  • Make buckets private.
  • Use encryption.
  • Enable logging.
  • Monitor access.
  • Use the principle of least privilege.

Lesson 7 · Container Security

Definition: Containers are lightweight packages that contain everything an app needs to run. They are used in the cloud.

Why it is important: If containers are not secure, hackers can break out of them and access the host system.

Simple explanation: It's like a suitcase that contains everything you need for a trip.

Lesson 8 · Common Container Vulnerabilities

  • Insecure images: Using images with known vulnerabilities.
  • Misconfigurations: Setting up containers incorrectly.
  • Privilege escalation: Gaining higher access inside a container.

Lesson 9 · Securing Containers

  • Use trusted images.
  • Keep images updated.
  • Run containers with least privilege.
  • Scan for vulnerabilities.

Lesson 10 · Serverless Security

Definition: Serverless computing lets you run code without managing servers. It's like renting a function instead of a server.

Why it is important: Serverless functions can have vulnerabilities like insecure dependencies.

Simple explanation: It's like renting a small tool instead of buying the whole workshop.

Lesson 11 · Cloud Security Best Practices

  • Use strong passwords and multi-factor authentication.
  • Check cloud configurations regularly.
  • Encrypt data stored in the cloud.
  • Monitor for suspicious activity.
  • Use cloud security tools.

Lesson 12 · Cloud Security Tools

  • Pacu: A tool for testing AWS security.
  • ScoutSuite: A tool for auditing cloud security.
  • CloudSploit: A tool for scanning cloud configurations.

Lesson 13 · The Role of Ethical Hackers

Ethical hackers test cloud security and help organisations protect their data.

📖 Key Vocabulary (Simple Definitions)

WordSimple meaning
Cloud computingUsing internet-based services.
S3 bucketA storage container in the cloud.
MisconfigurationSetting something up incorrectly.
ContainerA lightweight package for apps.
ServerlessRunning code without managing servers.
IaaSInfrastructure as a Service.
PaaSPlatform as a Service.
SaaSSoftware as a Service.
EncryptionScrambling data to protect it.
Multi-factor authenticationUsing two things to log in.

🧠 Important Concepts

  • Shared responsibility: The cloud provider secures the cloud; the customer secures what's in the cloud.
  • Zero trust: Never trust any device or user by default.
  • Defence in depth: Using multiple layers of security.
  • Least privilege: Give users only the access they need.

🔢 Step‑by‑Step: How an S3 Bucket Misconfiguration Happens

  1. A company sets up an S3 bucket to store customer data.
  2. The administrator forgets to make the bucket private.
  3. Anyone with the bucket URL can access the data.
  4. A hacker finds the URL and downloads all the data.
  5. The company suffers a data breach.

🌍 Real‑life Examples

1. Cloud: A misconfigured cloud server exposed millions of customer records.

2. Containers: A hacker escaped a container and accessed the host system.

🇳🇬 Nigerian Examples

  • A Nigerian bank uses cloud services to store customer data and hires ethical hackers to test its cloud security.
  • A Nigerian company uses containers and scans them for vulnerabilities.
  • A Nigerian startup uses serverless functions and secures them properly.

🎈 Fun Examples for Kids

  • Imagine a toy box in the cloud. If you leave it open, anyone can take your toys.
  • Containers are like lunchboxes – if you don't close them properly, the food spills.

🏡 Everyday Examples

  • Your family's photos in iCloud – if you don't use a strong password, someone could steal them.
  • Your school's Google Drive – if it's not secure, students' work could be stolen.

👩‍🏫 Teacher Notes

Use the storage unit story to introduce cloud security. Emphasise that the cloud is convenient but needs proper security. Encourage students to think about how they can protect their own cloud data.

👪 Parent Tips

  • Teach your child to use strong passwords for cloud accounts.
  • Explain why multi-factor authentication is important.
  • Show them how to check cloud settings for privacy.

✨ Interesting Facts

💡 Many cloud breaches are caused by misconfigurations, not hacks.
💡 AWS was launched in 2006 and is the largest cloud provider.

❓ Did You Know?

🔹 In Nigeria, many businesses use cloud services without proper security.
🔹 Containers are used by over 90% of cloud users.

🧾 Remember This

⚠️ Always secure your cloud configurations.
🔒 Use encryption to protect cloud data.
📱 Enable multi-factor authentication.

❌ Common Mistakes

  • Using default settings in the cloud.
  • Not using encryption.
  • Not enabling multi-factor authentication.
  • Not monitoring cloud activity.

✅ Best Practices

  • Use strong passwords and multi-factor authentication.
  • Check cloud configurations regularly.
  • Encrypt data stored in the cloud.
  • Monitor for suspicious activity.
  • Use cloud security tools.

📊 ASCII Illustrations & Flowcharts

Cloud Security Risks

    Misconfiguration  ---->  Data Exposure
    Weak Passwords    ---->  Account Hijacking
    Insecure APIs     ---->  Data Breach
    Insider Threats   ---->  Data Theft
    

S3 Bucket Misconfiguration

    Bucket created  ---->  Made public
                              |
                              v
    Data exposed  ---->  Hacker finds it  ---->  Data stolen
    

Container Security Checklist

    Use trusted images
    Keep images updated
    Run with least privilege
    Scan for vulnerabilities
    Isolate containers
    

📋 Comparison Table: Cloud Service Models

IaaSPaaSSaaS
Rent serversRent a platformRent software
More controlLess controlLeast control
AWS EC2Google App EngineGmail

📋 Comparison Table: Level Two vs Level Three Cloud Security

Level TwoLevel Three
Basic cloud conceptsAdvanced cloud attacks
Simple S3 bucketsMisconfiguration exploitation
Basic securityContainer and serverless security
Focused on basicsIncludes advanced tools

📌 Lesson Summaries

  • Lesson 1: Cloud computing uses internet-based services.
  • Lesson 2: Security is shared between provider and customer.
  • Lesson 3: IaaS, PaaS, and SaaS are cloud models.
  • Lesson 4: Misconfigurations and data breaches are common threats.
  • Lesson 5: S3 buckets can be left open accidentally.
  • Lesson 6: Secure S3 buckets with encryption and monitoring.
  • Lesson 7: Containers are lightweight app packages.
  • Lesson 8: Insecure images and misconfigurations are risks.
  • Lesson 9: Secure containers with trusted images and least privilege.
  • Lesson 10: Serverless runs code without managing servers.
  • Lesson 11: Use strong passwords, encryption, and monitoring.
  • Lesson 12: Tools like Pacu and ScoutSuite help test security.
  • Lesson 13: Ethical hackers test and secure cloud environments.

📝 End‑of‑Module Summary

In Module Twelve, we learned about cloud security. We explored cloud computing, the shared responsibility model, and common cloud threats. We learned about S3 bucket misconfigurations, container security, and serverless security. Remember, the cloud is powerful but needs strong security. By understanding the risks, we can protect our data and our organisations.

❓ Frequently Asked Questions (10)

  1. Q: What is cloud computing?
    A: Using internet-based services.
  2. Q: What is the shared responsibility model?
    A: Security is shared between provider and customer.
  3. Q: What is IaaS?
    A: Infrastructure as a Service – rent servers.
  4. Q: What is PaaS?
    A: Platform as a Service – rent a platform.
  5. Q: What is SaaS?
    A: Software as a Service – rent software.
  6. Q: What is an S3 bucket?
    A: A storage container in the cloud.
  7. Q: What is a container?
    A: A lightweight package for apps.
  8. Q: What is serverless?
    A: Running code without managing servers.
  9. Q: How can I secure my cloud data?
    A: Use strong passwords, encryption, and monitoring.
  10. Q: Can ethical hackers test cloud security?
    A: Yes, with permission.

📌 Review Questions (15)

  1. What is cloud computing?
  2. What is the shared responsibility model?
  3. What are the three cloud service models?
  4. What are common cloud threats?
  5. What is an S3 bucket misconfiguration?
  6. How can you secure S3 buckets?
  7. What is a container?
  8. What are common container vulnerabilities?
  9. How can you secure containers?
  10. What is serverless computing?
  11. What are cloud security best practices?
  12. What is Pacu?
  13. What is ScoutSuite?
  14. What is the principle of least privilege?
  15. Why do Nigerian companies need cloud security?

✍️ Fill‑in‑the‑Blank

  1. ________ is using internet-based services.
  2. ________ is Infrastructure as a Service.
  3. ________ is a storage container in the cloud.
  4. ________ is a lightweight package for apps.
  5. ________ is running code without managing servers.

✔️ True or False

  1. Cloud computing is always secure. (False)
  2. S3 buckets can be left open accidentally. (True)
  3. Containers are always secure. (False)
  4. Serverless is a type of cloud computing. (True)
  5. Ethical hackers can test cloud security. (True)

🔘 Multiple Choice Questions

  1. What is cloud computing?
    A) Internet-based services B) On-premise servers C) A type of malware D) A firewall
    Answer: A
  2. What is IaaS?
    A) Infrastructure as a Service B) A type of malware C) A firewall D) A browser
    Answer: A
  3. What is PaaS?
    A) Platform as a Service B) A type of malware C) A firewall D) A browser
    Answer: A
  4. What is SaaS?
    A) Software as a Service B) A type of malware C) A firewall D) A browser
    Answer: A
  5. What is an S3 bucket?
    A) A storage container in the cloud B) A type of malware C) A firewall D) A browser
    Answer: A
  6. What is a container?
    A) A lightweight package for apps B) A type of malware C) A firewall D) A browser
    Answer: A
  7. What is serverless?
    A) Running code without managing servers B) A type of malware C) A firewall D) A browser
    Answer: A
  8. What is a common cloud threat?
    A) Misconfiguration B) Strong passwords C) Encryption D) Updates
    Answer: A
  9. How can you secure S3 buckets?
    A) Make them private B) Leave them open C) Use weak passwords D) Ignore security
    Answer: A
  10. How can you secure containers?
    A) Use trusted images B) Use unverified images C) Ignore updates D) Disable security
    Answer: A
  11. What is the shared responsibility model?
    A) Security is shared between provider and customer B) The provider does everything C) The customer does everything D) Security is not needed
    Answer: A
  12. What is encryption?
    A) Scrambling data to protect it B) A type of malware C) A firewall D) A browser
    Answer: A
  13. What is multi-factor authentication?
    A) Using two things to log in B) A type of malware C) A firewall D) A browser
    Answer: A
  14. What is Pacu?
    A) A tool for testing AWS security B) A type of malware C) A firewall D) A browser
    Answer: A
  15. Why do Nigerian companies need cloud security?
    A) To protect their data B) To allow attacks C) To save money D) None
    Answer: A

🔗 Matching Exercise

TermMatch with
1. IaaSA. Rent software
2. PaaSB. Rent servers
3. SaaSC. Rent a platform
4. S3 bucketD. Lightweight package for apps
5. ContainerE. Storage container in the cloud

Answers: 1-B, 2-C, 3-A, 4-E, 5-D

✏️ Short Answer Questions

  1. Explain the shared responsibility model in cloud computing.
  2. What is an S3 bucket misconfiguration and why is it dangerous?
  3. How can you secure containers in the cloud?

🎭 Scenario‑based Exercise

Scenario: You are an ethical hacker hired by a school in Lagos. The school uses cloud storage for student records. You discover that the S3 bucket is public. What would you recommend?

👥 Group Activity

In groups of 4, create a poster that explains cloud security risks and how to protect against them. Include S3 buckets, containers, and serverless.

🧑‍💻 Individual Activity

Write a short essay on why cloud security is important for Nigerian businesses.

💬 Classroom Discussion Questions

  • Why do you think cloud misconfigurations are so common?
  • How can we educate people about cloud security?
  • What would you do if you discovered a cloud vulnerability?

🛠️ Mini Project

Project: Create a cloud security checklist for a small business. Include items like securing S3 buckets, using encryption, and enabling MFA.

🔧 Practical Assignment

Research a real-world cloud data breach. Write a short report on what happened and how it could have been prevented.

⚡ Challenge Exercise

Research how Pacu works. Write a one-page explanation and describe how it can be used for ethical testing.

✅ Quiz Answers (Selected)

  • Fill‑in‑the‑blank: 1) Cloud computing, 2) IaaS, 3) S3 bucket, 4) Container, 5) Serverless.
  • True/False: 1F, 2T, 3F, 4T, 5T.

🔑 Key Takeaways

  • Cloud computing uses internet-based services.
  • Security is shared between provider and customer.
  • S3 bucket misconfigurations are a common risk.
  • Containers and serverless need proper security.
  • Use strong passwords, encryption, and monitoring.
  • Ethical hackers test and secure cloud environments.

🚀 Preparation for Module Thirteen

In Module Thirteen, we will learn about exploit development and reverse engineering. We will explore buffer overflows, ROP, and custom payload development. Make sure you understand the cloud security concepts from this module.


🔥 You have completed Module Twelve of Level Three! Keep up the great work. 🔥

14

Module Thirteen

Module Thirteen · Ethical Hacking Level Three

🔧 Module Thirteen · Introduction to Ethical Hacking Level Three

Exploit Development and Reverse Engineering – building your own weapons.

📖 Module Introduction

Welcome to Module Thirteen! This is the most advanced module in Level Three. We will learn about exploit development and reverse engineering – the art of building your own hacking tools.

Think of it like being a master craftsman. Instead of buying tools from a shop, you build your own. You understand how every tool works, and you can customise it for any situation.

We will explore buffer overflows, return-oriented programming (ROP), bypassing modern protections, and custom payload development. We will also learn about Ghidra and IDA – tools for reverse engineering. By the end of this module, you will understand how exploits are built and how to protect against them.

🎯 Learning Objectives

By the end of this module, you will be able to:

  • Explain what exploit development is.
  • Understand buffer overflow vulnerabilities.
  • Learn about return-oriented programming (ROP).
  • Understand how to bypass modern protections.
  • Learn about custom payload development.
  • Understand reverse engineering tools like Ghidra and IDA.
  • Apply these ideas to Nigerian cybersecurity.

📖 Warm‑up Story · The Master Locksmith

Once upon a time, in a village in Oyo State, there was a master locksmith named Tunde. Tunde could open any lock in the world. But he didn't use magic – he understood how locks worked.

Tunde would look at a lock and see how it was made. He would find the weak points and create a key that could open it. He built his own tools from scratch.

That is exactly what exploit development is – understanding how software works, finding the weak points, and building your own tools to exploit them. In this module, we will learn how to become master locksmiths of the digital world.

📚 Main Lessons

Lesson 1 · What is Exploit Development?

Definition: Exploit development is the process of creating code that takes advantage of a vulnerability.

Why it is important: Understanding exploit development helps us create better defences.

Simple explanation: It's like building a special key to open a specific lock.

Real‑life example: A security researcher creates an exploit for a Windows vulnerability.

School example: A student writes a program to bypass a school's website filter.

Home example: A family member writes a script to automate a task.

Nigerian example: A Nigerian security researcher develops exploits to test local systems.

Mini summary: Exploit development is creating code to exploit vulnerabilities.

Lesson 2 · What is Reverse Engineering?

Definition: Reverse engineering is the process of taking something apart to understand how it works.

Why it is important: Reverse engineering helps us understand malware and find vulnerabilities.

Simple explanation: It's like taking apart a clock to see how the gears work.

Lesson 3 · Buffer Overflow Attacks

Definition: A buffer overflow is when a program writes data beyond the end of a buffer (a temporary storage area). This can overwrite important data and let hackers run their own code.

Why it is dangerous: Buffer overflows are one of the oldest and most dangerous vulnerabilities.

Simple explanation: It's like pouring more water into a glass than it can hold – the water spills out.

Real‑life example: The Morris worm used a buffer overflow to spread in 1988.

School example: A student sends a very long input to a program that crashes it.

Home example: A program crashes when you type too many characters.

Nigerian example: A Nigerian company might have buffer overflow vulnerabilities in old software.

Mini summary: Buffer overflows overwrite memory and can run code.

Lesson 4 · How Buffer Overflows Work

A program allocates a buffer of a certain size. If a hacker sends more data than the buffer can hold, the extra data overwrites the return address. When the function returns, it jumps to the hacker's code.

Lesson 5 · Stack vs Heap Overflows

  • Stack overflow: Overwrites data on the stack.
  • Heap overflow: Overwrites data in the heap.

Lesson 6 · Modern Protections

Modern systems have protections to stop exploits:

  • ASLR (Address Space Layout Randomisation): Randomises memory addresses.
  • DEP (Data Execution Prevention): Prevents code from running in certain memory areas.
  • Stack canaries: Special values that detect buffer overflows.

Lesson 7 · Return-Oriented Programming (ROP)

Definition: ROP is an advanced technique that chains together small pieces of existing code (called "gadgets") to bypass protections.

Why it is important: ROP bypasses DEP because it uses existing code.

Simple explanation: It's like using Lego blocks – you can build anything using existing pieces.

Real‑life example: Hackers use ROP to bypass DEP and execute code.

School example: A student uses existing code snippets to create a new program.

Home example: You use existing ingredients to make a new recipe.

Nigerian example: Nigerian researchers use ROP to test security.

Mini summary: ROP chains together existing code pieces.

Lesson 8 · Bypassing ASLR

Hackers can bypass ASLR by leaking memory addresses through other vulnerabilities.

Lesson 9 · Bypassing Stack Canaries

Stack canaries can be bypassed by reading them through other vulnerabilities or by overwriting them without detection.

Lesson 10 · Custom Payload Development

Definition: A payload is the code that runs after an exploit succeeds. Custom payloads are tailored for specific targets.

Simple explanation: It's like choosing the right tool for the job.

Lesson 11 · Tools for Exploit Development

  • Ghidra: A free reverse engineering tool from the NSA.
  • IDA Pro: A commercial reverse engineering tool.
  • pwntools: A Python library for exploit development.
  • Immunity Debugger: A debugger for Windows.

Lesson 12 · Using Ghidra

Ghidra is a powerful tool for reverse engineering. You can use it to analyse binaries and understand how they work.

Lesson 13 · Using IDA Pro

IDA Pro is the industry standard for reverse engineering. It is used by security researchers worldwide.

Lesson 14 · Protecting Against Exploits

  • Keep software updated.
  • Use ASLR and DEP.
  • Use stack canaries.
  • Use code reviews.
  • Use fuzzing.

Lesson 15 · The Role of Ethical Hackers

Ethical hackers use exploit development and reverse engineering to find vulnerabilities and help protect systems.

📖 Key Vocabulary (Simple Definitions)

WordSimple meaning
Buffer overflowWriting more data than a buffer can hold.
ROPReturn-Oriented Programming – chaining code pieces.
ASLRRandomising memory addresses.
DEPPreventing code execution in some memory.
Stack canaryA special value that detects overflows.
PayloadThe code that runs after an exploit.
GhidraA free reverse engineering tool.
IDA ProA commercial reverse engineering tool.
Reverse engineeringTaking something apart to understand it.
ExploitCode that takes advantage of a vulnerability.

🧠 Important Concepts

  • Memory safety: Ensuring programs don't access memory incorrectly.
  • Code review: Checking code for vulnerabilities.
  • Fuzzing: Sending random data to find bugs.
  • Sandboxing: Isolating programs to prevent damage.

🔢 Step‑by‑Step: How a Buffer Overflow Exploit Works

  1. Hacker finds a program with a buffer overflow.
  2. Hacker sends more data than the buffer can hold.
  3. The extra data overwrites the return address.
  4. The return address points to the hacker's shellcode.
  5. When the function returns, the shellcode executes.
  6. The hacker gains control of the system.

🌍 Real‑life Examples

1. Heartbleed: A bug in OpenSSL that allowed hackers to steal data.

2. Shellshock: A vulnerability in Bash that allowed remote code execution.

🇳🇬 Nigerian Examples

  • A Nigerian security researcher uses Ghidra to analyse malware.
  • A Nigerian company uses fuzzing to find vulnerabilities.
  • A Nigerian ethical hacker develops custom exploits for testing.

🎈 Fun Examples for Kids

  • Imagine a glass that can only hold 10 marbles. If you put 12 marbles in, they spill out – that's a buffer overflow.
  • ROP is like using Lego pieces to build something new.

🏡 Everyday Examples

  • If you type too many characters into a form and it crashes, that might be a buffer overflow.
  • If a program runs differently than expected, it might have a vulnerability.

👩‍🏫 Teacher Notes

Use the master locksmith story to introduce exploit development. Emphasise that this is advanced material and requires patience. Encourage students to practice in controlled environments.

👪 Parent Tips

  • Teach your child to keep software updated.
  • Explain why understanding code is important for security.
  • Show them how to use online resources to learn.

✨ Interesting Facts

💡 The first buffer overflow was discovered in 1988.
💡 Ghidra was released by the NSA in 2019.

❓ Did You Know?

🔹 In Nigeria, reverse engineering is used to analyse mobile malware.
🔹 ROP is used by many advanced hackers.

🧾 Remember This

⚠️ Only use exploit techniques ethically and with permission.
🔒 Keep systems updated to prevent exploits.
📱 Use modern protections like ASLR and DEP.

❌ Common Mistakes

  • Not using modern protections.
  • Not updating software.
  • Ignoring memory safety.
  • Not using code reviews.

✅ Best Practices

  • Keep software updated.
  • Use ASLR and DEP.
  • Use stack canaries.
  • Use code reviews.
  • Use fuzzing.

📊 ASCII Illustrations & Flowcharts

Buffer Overflow

    Normal:  [buffer][return address]
    Overflow: [buffer][hacker's code][return address]
              (overwritten)
    

ROP Attack

    Gadget 1  ---->  Gadget 2  ---->  Gadget 3  ---->  Shellcode
    (pop)          (mov)           (jmp)           (exec)
    

Exploit Development Process

    Find Vulnerability
          |
          v
    Develop Exploit
          |
          v
    Test in Sandbox
          |
          v
    Refine Exploit
          |
          v
    Deploy Ethically
    

📋 Comparison Table: Ghidra vs IDA Pro

GhidraIDA Pro
FreeCommercial (paid)
Open sourceClosed source
Good for beginnersIndustry standard
SlowerFaster
Created by NSACreated by Hex-Rays

📋 Comparison Table: Buffer Overflow vs ROP

Buffer OverflowROP
Overwrites memoryChains existing code
Can be blocked by DEPBypasses DEP
Older techniqueModern technique
Easier to executeMore complex

📌 Lesson Summaries

  • Lesson 1: Exploit development creates code to exploit vulnerabilities.
  • Lesson 2: Reverse engineering takes things apart to understand them.
  • Lesson 3: Buffer overflows overwrite memory and can run code.
  • Lesson 4: Buffer overflows overwrite the return address.
  • Lesson 5: Stack and heap overflows are two types.
  • Lesson 6: ASLR, DEP, and stack canaries are modern protections.
  • Lesson 7: ROP chains existing code to bypass protections.
  • Lesson 8: ASLR can be bypassed with memory leaks.
  • Lesson 9: Stack canaries can be bypassed with other vulnerabilities.
  • Lesson 10: Custom payloads are tailored for specific targets.
  • Lesson 11: Ghidra, IDA Pro, and pwntools are key tools.
  • Lesson 12: Ghidra is a free reverse engineering tool.
  • Lesson 13: IDA Pro is the industry standard.
  • Lesson 14: Keep software updated and use protections.
  • Lesson 15: Ethical hackers use these techniques to find vulnerabilities.

📝 End‑of‑Module Summary

In Module Thirteen, we learned about exploit development and reverse engineering. We explored buffer overflows, return-oriented programming (ROP), and modern protections like ASLR and DEP. We also learned about tools like Ghidra and IDA Pro. Remember, exploit development is a powerful skill that must be used ethically. By understanding how exploits work, we can better protect our systems.

❓ Frequently Asked Questions (10)

  1. Q: What is exploit development?
    A: Creating code to exploit vulnerabilities.
  2. Q: What is reverse engineering?
    A: Taking things apart to understand them.
  3. Q: What is a buffer overflow?
    A: Writing more data than a buffer can hold.
  4. Q: What is ROP?
    A: Chaining existing code to bypass protections.
  5. Q: What is ASLR?
    A: Randomising memory addresses.
  6. Q: What is DEP?
    A: Preventing code execution in some memory.
  7. Q: What is a stack canary?
    A: A special value that detects overflows.
  8. Q: What is Ghidra?
    A: A free reverse engineering tool.
  9. Q: What is IDA Pro?
    A: A commercial reverse engineering tool.
  10. Q: Can ethical hackers use these techniques?
    A: Yes, with permission.

📌 Review Questions (15)

  1. What is exploit development?
  2. What is reverse engineering?
  3. What is a buffer overflow?
  4. How does a buffer overflow work?
  5. What are modern protections?
  6. What is ROP?
  7. How does ROP bypass DEP?
  8. What is ASLR?
  9. How can ASLR be bypassed?
  10. What is a stack canary?
  11. What is Ghidra?
  12. What is IDA Pro?
  13. What is a payload?
  14. How can you protect against buffer overflows?
  15. Why do Nigerian companies need exploit protection?

✍️ Fill‑in‑the‑Blank

  1. ________ is creating code to exploit vulnerabilities.
  2. ________ is taking things apart to understand them.
  3. ________ is writing more data than a buffer can hold.
  4. ________ is chaining existing code to bypass protections.
  5. ________ is a free reverse engineering tool.

✔️ True or False

  1. Buffer overflows are no longer a problem. (False)
  2. ASLR randomises memory addresses. (True)
  3. DEP prevents code execution in some memory. (True)
  4. ROP is an old technique. (False)
  5. Ghidra is a commercial tool. (False)

🔘 Multiple Choice Questions

  1. What is exploit development?
    A) Creating code to exploit vulnerabilities B) A type of malware C) A firewall D) A browser
    Answer: A
  2. What is reverse engineering?
    A) Taking things apart to understand them B) A type of malware C) A firewall D) A browser
    Answer: A
  3. What is a buffer overflow?
    A) Writing more data than a buffer can hold B) A type of malware C) A firewall D) A browser
    Answer: A
  4. What is ROP?
    A) Chaining existing code B) A type of malware C) A firewall D) A browser
    Answer: A
  5. What is ASLR?
    A) Randomising memory addresses B) A type of malware C) A firewall D) A browser
    Answer: A
  6. What is DEP?
    A) Preventing code execution in some memory B) A type of malware C) A firewall D) A browser
    Answer: A
  7. What is a stack canary?
    A) A special value that detects overflows B) A type of malware C) A firewall D) A browser
    Answer: A
  8. What is Ghidra?
    A) A free reverse engineering tool B) A type of malware C) A firewall D) A browser
    Answer: A
  9. What is IDA Pro?
    A) A commercial reverse engineering tool B) A type of malware C) A firewall D) A browser
    Answer: A
  10. What is a payload?
    A) The code that runs after an exploit B) A type of malware C) A firewall D) A browser
    Answer: A
  11. How can you protect against buffer overflows?
    A) Use stack canaries B) Use weak passwords C) Ignore security D) Disable security
    Answer: A
  12. What is pwntools?
    A) A Python library for exploit development B) A type of malware C) A firewall D) A browser
    Answer: A
  13. What is Immunity Debugger?
    A) A debugger for Windows B) A type of malware C) A firewall D) A browser
    Answer: A
  14. What is the difference between buffer overflow and ROP?
    A) ROP bypasses DEP B) They are the same C) Buffer overflow bypasses DEP D) ROP is older
    Answer: A
  15. Why do Nigerian companies need exploit protection?
    A) To protect their systems B) To allow attacks C) To save money D) None
    Answer: A

🔗 Matching Exercise

TermMatch with
1. Buffer overflowA. Chaining existing code
2. ROPB. Randomising memory addresses
3. ASLRC. Writing more data than a buffer can hold
4. DEPD. Free reverse engineering tool
5. GhidraE. Preventing code execution

Answers: 1-C, 2-A, 3-B, 4-E, 5-D

✏️ Short Answer Questions

  1. Explain the difference between a buffer overflow and ROP.
  2. How does ASLR protect against exploits?
  3. What is the role of Ghidra in reverse engineering?

🎭 Scenario‑based Exercise

Scenario: You are an ethical hacker hired by a bank in Lagos. The bank uses an old application that might have buffer overflow vulnerabilities. What would you do?

👥 Group Activity

In groups of 4, create a poster that explains buffer overflows and how to protect against them.

🧑‍💻 Individual Activity

Write a short essay on why exploit development is important for cybersecurity.

💬 Classroom Discussion Questions

  • Why do you think buffer overflows are still a problem?
  • How can we protect against exploit development?
  • What would you do if you discovered a buffer overflow vulnerability?

🛠️ Mini Project

Project: Create a guide on how to prevent buffer overflows. Include tips on using modern protections and code reviews.

🔧 Practical Assignment

Research a real-world buffer overflow attack. Write a short report on what happened and how it could have been prevented.

⚡ Challenge Exercise

Research how ROP works. Write a one-page explanation and describe how it can be used for ethical testing.

✅ Quiz Answers (Selected)

  • Fill‑in‑the‑blank: 1) Exploit development, 2) Reverse engineering, 3) Buffer overflow, 4) ROP, 5) Ghidra.
  • True/False: 1F, 2T, 3T, 4F, 5F.

🔑 Key Takeaways

  • Exploit development creates code to exploit vulnerabilities.
  • Reverse engineering helps us understand how things work.
  • Buffer overflows are a dangerous vulnerability.
  • ROP bypasses modern protections.
  • ASLR, DEP, and stack canaries protect systems.
  • Ghidra and IDA Pro are important reverse engineering tools.
  • Always use these techniques ethically and with permission.

🚀 Preparation for Module Fourteen

In Module Fourteen, we will learn about red team operations and the final project. We will bring everything together in a real-world exercise. Make sure you understand the exploit concepts from this module.


🔥 You have completed Module Thirteen of Level Three! Keep up the great work. 🔥

15

Module Fourteen

Module Fourteen · Ethical Hacking Level Three

🎯 Module Fourteen · Introduction to Ethical Hacking Level Three

Red Team Operations and Final Project – becoming a true cyber professional.

📖 Module Introduction

Welcome to Module Fourteen – the final module of Level Three! In this module, we will learn about red team operations and you will complete your final project.

Think of a red team like a group of actors who pretend to be the bad guys. They try to break into a company's systems – but they do it with permission. Their job is to find weaknesses before the real bad guys do.

We will explore Command and Control (C2) frameworks like Cobalt Strike and Empire, persistence, evasion, physical security testing, and professional reporting. Then you will put everything you've learned into practice with a full-scale red team exercise.

🎯 Learning Objectives

By the end of this module, you will be able to:

  • Explain what red team operations are.
  • Understand Command and Control (C2) frameworks.
  • Learn about Cobalt Strike and Empire.
  • Understand persistence and evasion techniques.
  • Learn about physical security testing.
  • Understand professional reporting for red teams.
  • Complete a full-scale red team exercise.

📖 Warm‑up Story · The Security Drill

Once upon a time, in a big company in Lagos, the security team wanted to test their defences. They hired a group of ethical hackers to pretend to be the bad guys. This group was called the red team.

The red team had one week to break into the company's systems. They used social engineering, physical security tricks, and advanced hacking techniques. At the end of the week, they had found 15 vulnerabilities that the security team didn't know about.

The company fixed all the vulnerabilities and became much safer. The red team had done their job – they had helped protect the company.

That is exactly what we will learn in this module – how to be a red team and help organisations improve their security.

📚 Main Lessons

Lesson 1 · What is Red Teaming?

Definition: Red teaming is a full-scale attack simulation that tests an organisation's entire security – people, processes, and technology.

Why it is important: Red teaming finds weaknesses that penetration testing might miss.

Simple explanation: It's like a fire drill for cybersecurity.

Real‑life example: A bank hires a red team to test their security.

School example: A school has a lockdown drill – that's like a red team exercise.

Home example: A family practices what to do in a fire – that's like a red team drill.

Nigerian example: A Nigerian company hires a red team to test its security.

Mini summary: Red teaming tests an organisation's entire security.

Lesson 2 · Red Team vs Penetration Testing

Penetration testing focuses on finding vulnerabilities. Red teaming focuses on simulating a real attack, including evasion and persistence.

Lesson 3 · Command and Control (C2) Frameworks

Definition: C2 frameworks are tools that help hackers control compromised systems remotely.

Why it is important: C2 frameworks are used by both hackers and red teams.

Simple explanation: It's like a remote control for computers.

Lesson 4 · Cobalt Strike

Definition: Cobalt Strike is a popular C2 framework used by red teams and hackers. It simulates advanced attacks.

Why it is important: Cobalt Strike is the industry standard for red teaming.

Simple explanation: It's like a Swiss army knife for hackers.

Real‑life example: A red team uses Cobalt Strike to test a company's defences.

School example: A student uses a tool to simulate attacks in a lab.

Home example: A family member uses a tool to test their home network.

Nigerian example: A Nigerian red team uses Cobalt Strike for testing.

Mini summary: Cobalt Strike is a powerful C2 framework.

Lesson 5 · PowerShell Empire

Definition: Empire is a C2 framework that uses PowerShell on Windows systems.

Why it is important: Empire is powerful and can evade detection.

Simple explanation: It's like a tool that controls Windows computers remotely.

Lesson 6 · Persistence in Red Teaming

Red teams need to maintain access to systems. They use persistence mechanisms like scheduled tasks, registry keys, and cron jobs.

Lesson 7 · Evasion in Red Teaming

Red teams must evade detection. They use techniques like encryption, obfuscation, and protocol manipulation.

Lesson 8 · Physical Security Testing

Definition: Physical security testing is when red teams try to physically enter a building to test security.

Why it is important: Many security breaches happen through physical access.

Simple explanation: It's like a movie where spies break into a building.

Real‑life example: A red team tries to enter a company's office without a badge.

School example: A student tests whether they can enter the staff room.

Home example: A family member tests if the front door lock is strong.

Nigerian example: A Nigerian red team tests physical security.

Mini summary: Physical security testing checks physical barriers.

Lesson 9 · Social Engineering in Red Teaming

Red teams use social engineering to trick employees into giving information.

Lesson 10 · Reporting in Red Teaming

Red teams write professional reports that explain their findings and how to fix them.

Lesson 11 · The Red Team Process

  1. Planning: Define the scope and rules.
  2. Reconnaissance: Gather information.
  3. Attack: Use various techniques to break in.
  4. Persistence: Maintain access.
  5. Evasion: Avoid detection.
  6. Reporting: Document everything.

Lesson 12 · Tools for Red Teaming

  • Cobalt Strike: C2 framework.
  • Empire: PowerShell C2 framework.
  • Mythic: Another C2 framework.
  • BloodHound: AD mapping tool.
  • Metasploit: Exploit framework.

Lesson 13 · The Role of Ethical Hackers in Red Teaming

Ethical hackers form the red team. They help organisations find and fix weaknesses.

Lesson 14 · Final Project Overview

The final project is a full-scale red team exercise. You will plan, execute, and report on a simulated attack.

📖 Key Vocabulary (Simple Definitions)

WordSimple meaning
Red teamA group that simulates attacks.
C2Command and Control – a system to control compromised computers.
Cobalt StrikeA popular C2 framework.
EmpireA PowerShell C2 framework.
PersistenceMaintaining access to a system.
EvasionAvoiding detection.
Physical securityProtecting buildings and physical assets.
Social engineeringTricking people to get information.
ReportingDocumenting findings.
FrameworksTools and methods used in red teaming.

🧠 Important Concepts

  • Defence in depth: Using many layers of security.
  • Zero trust: Never trusting any device or user by default.
  • Detection: Finding attacks in real-time.
  • Response: Reacting to attacks effectively.

🔢 Step‑by‑Step: The Red Team Process

  1. Plan: Define the scope and rules of engagement.
  2. Recon: Gather information about the target.
  3. Attack: Use techniques to break in.
  4. Maintain: Keep access with persistence.
  5. Evade: Avoid detection.
  6. Report: Write a professional report.

🌍 Real‑life Examples

1. Government: Red teams test government systems for vulnerabilities.

2. Banking: Banks use red teams to test their security.

🇳🇬 Nigerian Examples

  • A Nigerian bank uses a red team to test its security.
  • A Nigerian company uses Cobalt Strike for red team exercises.
  • A Nigerian security firm offers red team services.

🎈 Fun Examples for Kids

  • Imagine a school safety drill where students pretend to be firefighters – that's like a red team.
  • A C2 framework is like a remote control for a toy car.

🏡 Everyday Examples

  • If you test whether your front door is locked, that's like physical security testing.
  • If you check if your family knows the emergency plan, that's like red teaming.

👩‍🏫 Teacher Notes

Use the security drill story to introduce red teaming. Emphasise that red teaming is about helping organisations improve. Encourage students to think about how they would approach a red team exercise.

👪 Parent Tips

  • Teach your child about the importance of security drills.
  • Explain why companies need to test their security.
  • Show them how to be careful about what they share online.

✨ Interesting Facts

💡 The term "red team" comes from the military.
💡 Cobalt Strike was created by a security researcher.

❓ Did You Know?

🔹 Many Nigerian companies now use red teams to test their security.
🔹 Red team exercises can last from a few days to several months.

🧾 Remember This

⚠️ Always have permission before red teaming.
🔒 Red teaming helps improve security.
📱 Report findings professionally.

❌ Common Mistakes

  • Not getting permission.
  • Not staying within scope.
  • Not reporting findings.
  • Ignoring physical security.

✅ Best Practices

  • Always have permission.
  • Stay within scope.
  • Write clear reports.
  • Test physical security too.
  • Use the right tools.

📊 ASCII Illustrations & Flowcharts

The Red Team Process

    Plan  ---->  Recon  ---->  Attack  ---->  Maintain  ---->  Evade  ---->  Report
    

Red Team vs Penetration Testing

    Penetration Testing: Focused, short, finds vulnerabilities
    Red Teaming: Full-scale, long, simulates real attacks
    

Final Project Overview

    Scope  ---->  Recon  ---->  Exploit  ---->  Persistence  ---->  Report
    

📋 Comparison Table: Red Team vs Penetration Testing

Red TeamPenetration Testing
Full-scale simulationFocused test
Tests people, processes, technologyTests technology
Longer durationShorter duration
More realisticLess realistic

📋 Comparison Table: Cobalt Strike vs Empire

Cobalt StrikeEmpire
Commercial (paid)Free and open-source
More featuresPowerShell focused
Industry standardPopular for Windows
More advancedEasier to use

📌 Lesson Summaries

  • Lesson 1: Red teaming simulates real attacks.
  • Lesson 2: Red teaming is broader than penetration testing.
  • Lesson 3: C2 frameworks control compromised systems.
  • Lesson 4: Cobalt Strike is a popular C2 tool.
  • Lesson 5: Empire uses PowerShell for C2.
  • Lesson 6: Persistence maintains access.
  • Lesson 7: Evasion avoids detection.
  • Lesson 8: Physical security testing checks buildings.
  • Lesson 9: Social engineering tricks people.
  • Lesson 10: Reporting shares findings.
  • Lesson 11: The red team process has clear steps.
  • Lesson 12: Many tools are used in red teaming.
  • Lesson 13: Ethical hackers make great red teamers.
  • Lesson 14: The final project is a full-scale exercise.

📝 End‑of‑Module Summary

In Module Fourteen, we learned about red team operations and the final project. We explored C2 frameworks like Cobalt Strike and Empire, persistence, evasion, physical security testing, and professional reporting. Remember, red teaming is about helping organisations improve their security. By simulating real attacks, we can find weaknesses before the bad guys do.

❓ Frequently Asked Questions (10)

  1. Q: What is red teaming?
    A: Simulating real attacks to test security.
  2. Q: What is a C2 framework?
    A: A tool to control compromised systems.
  3. Q: What is Cobalt Strike?
    A: A popular C2 framework.
  4. Q: What is Empire?
    A: A PowerShell C2 framework.
  5. Q: What is persistence?
    A: Maintaining access to a system.
  6. Q: What is evasion?
    A: Avoiding detection.
  7. Q: What is physical security testing?
    A: Testing physical barriers.
  8. Q: What is social engineering?
    A: Tricking people for information.
  9. Q: What is the final project?
    A: A full-scale red team exercise.
  10. Q: Can ethical hackers do red teaming?
    A: Yes, with permission.

📌 Review Questions (15)

  1. What is red teaming?
  2. What is the difference between red teaming and penetration testing?
  3. What is a C2 framework?
  4. What is Cobalt Strike?
  5. What is Empire?
  6. What is persistence?
  7. What is evasion?
  8. What is physical security testing?
  9. What is social engineering?
  10. What is the red team process?
  11. What tools are used in red teaming?
  12. What is the role of ethical hackers in red teaming?
  13. What is the final project?
  14. Why is reporting important?
  15. Why do Nigerian companies need red teaming?

✍️ Fill‑in‑the‑Blank

  1. ________ simulates real attacks to test security.
  2. ________ is a tool to control compromised systems.
  3. ________ is a popular C2 framework.
  4. ________ is maintaining access to a system.
  5. ________ is avoiding detection.

✔️ True or False

  1. Red teaming is the same as penetration testing. (False)
  2. Cobalt Strike is a C2 framework. (True)
  3. Empire uses PowerShell. (True)
  4. Persistence is not important. (False)
  5. Physical security testing is part of red teaming. (True)

🔘 Multiple Choice Questions

  1. What is red teaming?
    A) Simulating real attacks B) A type of malware C) A firewall D) A browser
    Answer: A
  2. What is a C2 framework?
    A) A tool to control compromised systems B) A type of malware C) A firewall D) A browser
    Answer: A
  3. What is Cobalt Strike?
    A) A popular C2 framework B) A type of malware C) A firewall D) A browser
    Answer: A
  4. What is Empire?
    A) A PowerShell C2 framework B) A type of malware C) A firewall D) A browser
    Answer: A
  5. What is persistence?
    A) Maintaining access B) A type of malware C) A firewall D) A browser
    Answer: A
  6. What is evasion?
    A) Avoiding detection B) A type of malware C) A firewall D) A browser
    Answer: A
  7. What is physical security testing?
    A) Testing physical barriers B) A type of malware C) A firewall D) A browser
    Answer: A
  8. What is social engineering?
    A) Tricking people for information B) A type of malware C) A firewall D) A browser
    Answer: A
  9. What is the red team process?
    A) Plan, recon, attack, maintain, evade, report B) A type of malware C) A firewall D) A browser
    Answer: A
  10. What is the difference between red teaming and penetration testing?
    A) Red teaming is broader B) They are the same C) Penetration testing is broader D) Red teaming is easier
    Answer: A
  11. What is the final project?
    A) A full-scale red team exercise B) A type of malware C) A firewall D) A browser
    Answer: A
  12. What is the role of ethical hackers in red teaming?
    A) To test and improve security B) To attack systems C) A type of malware D) A firewall
    Answer: A
  13. Why is reporting important?
    A) To share findings and recommendations B) To hide results C) A type of malware D) A firewall
    Answer: A
  14. What is the best practice for red teaming?
    A) Always have permission B) Use weak passwords C) Ignore security D) Disable security
    Answer: A
  15. Why do Nigerian companies need red teaming?
    A) To improve their security B) To allow attacks C) To save money D) None
    Answer: A

🔗 Matching Exercise

TermMatch with
1. Red teamA. PowerShell C2 framework
2. Cobalt StrikeB. Simulates attacks
3. EmpireC. Maintaining access
4. PersistenceD. Popular C2 framework
5. EvasionE. Avoiding detection

Answers: 1-B, 2-D, 3-A, 4-C, 5-E

✏️ Short Answer Questions

  1. Explain the difference between red teaming and penetration testing.
  2. What is the red team process?
  3. Why is reporting important in red teaming?

🎭 Scenario‑based Exercise

Scenario: You are the leader of a red team hired by a bank in Lagos. The bank wants you to test their entire security. How would you approach this?

👥 Group Activity

In groups of 4, create a red team plan for a fictional company. Include scope, reconnaissance, attack techniques, and reporting.

🧑‍💻 Individual Activity

Write a short essay on why red teaming is important for Nigerian businesses.

💬 Classroom Discussion Questions

  • Why do you think red teaming is important?
  • How can we make red teaming more effective?
  • What would you do if you were on a red team?

🛠️ Mini Project

Project: Create a red team report template. Include sections for executive summary, findings, risk assessment, and recommendations.

🔧 Practical Assignment

Research a real-world red team engagement. Write a short report on what happened and how it helped the organisation.

⚡ Challenge Exercise

Research how Cobalt Strike works. Write a one-page explanation and describe how it can be used for ethical testing.

✅ Quiz Answers (Selected)

  • Fill‑in‑the‑blank: 1) Red teaming, 2) C2 framework, 3) Cobalt Strike, 4) Persistence, 5) Evasion.
  • True/False: 1F, 2T, 3T, 4F, 5T.

🔑 Key Takeaways

  • Red teaming simulates real attacks to improve security.
  • C2 frameworks like Cobalt Strike and Empire are used in red teaming.
  • Persistence and evasion are key red team techniques.
  • Physical security and social engineering are important parts of red teaming.
  • Professional reporting is essential for red team success.
  • Ethical hackers make excellent red team members.

🚀 The Final Project

Congratulations! You have completed all the modules of Level Three. Now it's time for your final project – a full-scale red team exercise.

You will need to:

  • Plan and scope the exercise.
  • Perform reconnaissance.
  • Exploit vulnerabilities.
  • Maintain persistence.
  • Evade detection.
  • Write a professional report.

Your instructor will provide you with a test environment and specific instructions. Good luck!


🎉 You have completed the Introduction to Ethical Hacking Level Three course! You are now a skilled ethical hacking professional. Keep learning, stay curious, and always use your powers for good. 🎉

🏆 Get Certified

🔒

Earn this certificate

Every lesson is already free to read. Sign up, pass the exam, and unlock Practice Tools plus a verified certificate with your name on it — ₦4,000/month.

🎓 Sign Up & Unlock for ₦4,000/month
🛠️ Practice Tools
Hands-on simulators & labs - subscription required.
→
🎯 Internship Tasks
Real-world tasks to build your portfolio - try them free for 7 days, no card required.
→