SEC 335 Home - Oliver-Mustoe/Oliver-Mustoe-Tech-Journal GitHub Wiki

Welcome to my SEC-335 Tech Journal!!!

This is my landing page for SEC-335, where you will find the following:

Class description

Taken from course Canvas:

Operating Systems and Internet-based applications are common sources of security breaches. Students will learn about the information security flaws in
  
software systems, vulnerabilities inherent in common network services, ways to secure Internet servers and services, and increasing security awareness in 

organizations. Students will also learn the methodologies and tools used to probe networks for vulnerabilities and propose solutions. Hands-on activities 

will give the necessary background to assess security. Scenarios will provide opportunities to discuss security, ethics, and incident response.

Chronological Journal for SEC-335

Below is a dropdown with chronological details about each week in SEC-335

Week 1

  • Took notes in SEC-335-W1-Notes
  • Participated in class activity about ethical hacking rules
  • Worked on default formatting for this and other high level classes github pages
  • Completed Assignment 1.2 - Kali VM (links to technical documentation of assignment)
  • Learned about rules of engagement from NASA and what "War Dialing" is

Week 2

Week 3

  • As there was no lecture or required reading, I did not really take any notes (outside of the labs)
  • Learned about DNS enumeration in Class Activity 3.1 - DNS Enumeration
  • Learned that nslookup uses UDP by default
    • And the “-vc” flag "Specifies to use a virtual circuit (TCP connection) to transport queries to the name server or datagrams (UDP)." - IBM

Week 4

  • Did not take lecture notes (Activity covers the concepts)
  • Complete my first engagement with the vulnerable machine "cupcake" in Activity 4.1 - Exploiting Cupcake
  • Learned about hacking laws

Week 5

Week 6

Week 7 - BREAK

Week 8

Week 9

Week 10

Week 11

Week 12

Week 13


Tool references for SEC-335

Below are resources for tools that I found helpful while completing assignments (in the dropdown)

NMAP

Passwords guessing & cracking (cewl, rsmangler, hydra, JtR, hashcat, content on /etc/shadow and passwd)

Below is curated technical journals that cover tools related to password guessing and cracking (shows workflow aswell):

Weevely


Ordered Technical journals

Below are journal pages for technical assignments ordered first to last in order of completion:

⚠️ **GitHub.com Fallback** ⚠️