SECURITY + or MICROSOFT Course 2810    Review Study Slides

Check this out while it lasts...Free Security+ Chapter from Training Kit

Exam Cram Study Notes!

  get latest powerpoint viewer here (need 2002 support for these slides) 

 

 

 

 

 

 


Lesson 1  Identifying Security Threats

SOCIAL ENGINEERING ATTACKS

A history of Hacking

Security Best Practices

Basics of Security

Social Engineering Fundamentals, Part I   many excellent links at the bottom of this page too!

SANS Institute:  Social Engineering

FRONTLINE SPECIAL:  A report on the exploit of hackers

White Hat vs. Black Hat

Confessions of a White Hat Hacker

Attacks and Countermeasures

Hacking and Securing Windows 2000/NT

How to harden the TCP/IP stack against denial of service attacks

NETWORK ATTACKS

Gibson Research:  Shields Up port scanner

Free Security Port Scan

BlackCode Port Scan

Find out what TCP and UDP ports your remote host is using

"SuperScan" 3.0

On the lookout for "Dsniff":  IBM

SANS:  Finding Dsniff on your network

Distributed Denial of Service Attacks

SOFTWARE BASED ATTACKS

Cost of Malicious Code to Businesses  requires acrobat reader

Major Online Security Threats  requires acrobat reader

How to check if "Back Orifice" is installed

Back Orifice Overview

Back Orifice Help

NetBus and BO attack info

Symantec information on BO and NetBUS

Deconstructing SubSeven:  The Trojan Horse of Choice: SANS

Distributed Denial of Service Attacks and You    Microsoft TechNet

Threat and Vulnerability Analysis Table

How to Prevent Windows from Storing a LAN Manager Hash of Your Password in Active Directory and Local SAM Databases  Q299656

Bell-LaPadula Model know for MAC system

 

Lesson  2  Hardening Internal Systems and Services

Introduction to Windows 2000 Security

Security Toolkit :  Guides, Updates and Tools

Securing an Existing 2000 System

Kerberos v5 Administrator's Guide

The Moron's Guide to Kerberos

Securing a new 2000 System

Windows XP Baseline Security Checklist

Lophtcrack Download site

Download SANS Acceptable Use Policy

Business Introduction to Security

MBSA white paper

MBSA Download

Step-by-step guide to using the Security Configuration and Analysis

2000 Security Templates defined

XP Security Templates defined

The Common Criteria

Microsoft Virus Protection Strategies

Active Directory Schema

What is LDAP?

 

 

Lesson 3  Hardening Internetwork Devices and Services

Hardening Systems and Services :  Checklists and Guides

Additional Registry Settings for Network Attacks

IIS Lock Down Tool

IIS Lockdown Download

Open SSH

VanDyke vShell SSH2/SFTP Server for Windows

VanDyke Secure FX SSH2/SFTP client for Windows

Security Policy Tips from Novell

Exchange 2000 Server Resource Kit Online

Chapter 30 from Resource Kit on Exchange Security

Security Resources for Exchange

Whati is MAIL RELAY?

third party mail relay

S/MIME and PGP

S/MIME overview at RSA

What is PGP:  RSA

 


Lesson 4: Securing Network Communications

IPSEC resources

802.11 Webopedia

Wi-Fialliance

WiFI Glossary of Terms

D-Link Wireless Products

3-COM 802.11b PDF download paper

Cisco Wireless Links

Microsoft Solutions for Securing Wireless LANs

Securing Remote Client Access in 2000

 

 


Lesson 5: Managing Public Key Infrastructure (PKI)

PKI and Certificates

 

 


Lesson 6: Managing Certificates

PKI and Certificates


Lesson 7: Enforcing Organizational Security Policy

Sample Information Security Policy at TechRepublic (login/profile required)

Security Glossary of Terms

 


Lesson 8: Monitoring the Security Infrastructure

Anatomy of Hacking: CNET

Hacking Tips

Known ports vulnerable to DOS attacks

Which protocols to filter

"SuperScan" 3.0

Intrusion SecurityAnalyst

SMBRelay:  Symantec Article

HIDS vs NIDS:  ZDNet

RealSecure Desktop Protection:  DEMO too

HoneyPot at Webopedia

Outline for Incident Response

Department of Information Technology Michigan Incident Respone

Anatomy of a Security Info Response Team

Expectations for Computer Security Incident Response:  RFC 2350