Showing posts with label CompTIA Security. Show all posts
Showing posts with label CompTIA Security. Show all posts

Friday, May 6, 2022

DIGITAL FORENSICS:Social engineering attack techniques

 DIGITAL FORENSICS:Social engineering attack techniques 

การทำ Phishing นั้นถือว่าเป็นการโจมตีในรูปแบบที่เรียกว่า Social Engineering ซึ่งเป็นวิธีการที่เน้นโจมตีไปที่คน 

จุดประสงค์

  •  เพื่อศึกษาโปรแกรม Kali Linux และ โปรแกรม Social Engineering Toolkit เพื่อไม่ให้ตกเป็นเหยื่อของผู้ประสงค์ร้าย

โปรแกรม Social Engineering Toolkit (SET) เป็นโปรแกรมที่ใช้ในโจมตีแบบวิศวกรรมสังคมจะเกี่ยวกับการหลอกให้บางคนหลงกลเพื่อเข้าระบบ เช่น การหลอกถามรหัสผ่าน การหลอกให้ส่งที สําคัญให้ ซึ่งการโจมตี ประเภทนีไม่จําต้องใช้ความรู้ความชํานาญเกียวกบคอมพิวเตอร์หรือการเจาะระบบเลย วิศวกรรมสังคมเป็น จุดอ่อนที ป้องกันยากเพราะเกี่ยวข้องกับคน

เริ่มวิธีการสร้าง Phishing Website โดย Tool ที่ชื่อว่า Social-Engineer Toolkit (SET)

เข้าไปที่ Kali และเลือก

เลือก 1) Social-Engineering Attacks

Social-Engineer Toolkit (SET)

เลือก 2) Website Attack Vectors

Social engineering attack techniques

เลือก 2) Site Cloner
ocial engineering attack techniques


Social-Engineer Toolkit (SET)

 ถัดมาขั้นตอนสำคัญ คือจะให้ Clone จาก Site ตาม Case Study นี้แล้วคงเป็น Web ของ facebook.com

set:webattack> Enter the url to clone:https://www.facebook.com

เมื่อใส่ข้อมูลเรียบร้อยทั้งหมดแล้ว Tool จะทำหน้าที่ Clone หน้า Web ขึ่้นมา รอให้เหยื่อเข้า Web และ Tool ก็จะคอยรอรับ input จากเหยื่อด้วย

ocial engineering attack techniques

หน้า Phishing Website  สร้างเรียบร้อย   

social engineering attack techniques
URL ที่ถูกต้องคือ facebook.com
  • สังเกตที่ URL  ในที่นี้เป็น IP ของเครื่อง192.168.18.130  แต่ถ้าเป็นกรณีที่จะโจมตีจริงๆก็จะมีการจด Domain ที่มีความน่าเชื่อถือมากขึ้นเพื่อหลอกให้เหยื่อหลงกลได้

Social-Engineer Toolkit (SET)
เมื่อมีการใส่ข้อมูล Username และ Password เรียบร้อย โปรแกรมก็จะแสดงข้อมูลที่ User ใส่

POSSIBLE USERNAME FIELD FOUND: email=Johnwick                                                                                                                                                                                             

POSSIBLE PASSWORD FIELD FOUND: pass=1234       


อ่านเพิ่มเติม https://informationtreasure.wordpress.com/2014/07/25/social-engineering-toolkit-kali-credential-harvestor-hack-facebook/


ที่มา:     incognitolab 

#WINDOWSFORENSIC #COMPUTERFORENSICS #DFIR #FORENSICS #DIGITALFORENSICS #COMPUTERFORENSIC #INVESTIGATION #CYBERCRIME #FRAUD #หลักสูตรการพิสูจน์หลักฐานทางดิจิทัล


หมายเหตุ:เนื้อหาในเว็บไซต์นี้มีขึ้นเพื่อวัตถุประสงค์ในการให้ข้อมูลและเพื่อการศึกษาเท่านั้น

* หากมีข้อมูลข้อผิดพลาดประการใด ขออภัยมา ณ ที่นี้ด้วย  รบกวนแจ้ง ADMIN เพื่อแก้ไขต่อไป
ขอบคุณครับ

Thursday, March 26, 2020

DIGITAL FORENSICS: CertMaster Learn for IT Fundamentals (ITF+) free

DIGITAL FORENSICS: CertMaster Learn for IT Fundamentals (ITF+)

free

 

To access the free CompTIA CertMaster Learn for IT Fundamentals (ITF+) course visit 

https://certs.comptia.org/means_more/

 


Lesson 1: Common Computing Device

CertMaster Learn for IT Fundamentals (ITF+)

CompTIA IT Fundamentals

Welcome to CompTIA CertMaster Learn for IT Fundamentals+!


  1. Go to the CompTIA CertMaster Learn Registration Page.
  2. Enter the access code and click continue.
  3. If you have previously used CertMaster Learn or CertMaster CE and have a user account, select Log In.  If you do not have a user account, enter Full Name, Email, and Password as directed. 
  4. Now that your access code has been redeemed, access the new course at any time from the CertMaster Learn Log-In page.







 หลักสูตรอบรมออนไลน์ 

 Ref:

https://learn.comptia.org


หมายเหตุ:เนื้อหาในเว็บไซต์นี้มีขึ้นเพื่อวัตถุประสงค์ในการให้ข้อมูลและเพื่อการศึกษาเท่านั้น

* หากมีข้อมูลข้อผิดพลาดประการใด ขออภัยมา ณ ที่นี้ด้วย  รบกวนแจ้ง Admin เพื่อแก้ไขต่อไป
ขอบคุณครับ

#WindowsForensic #ComputerForensics #dfir #forensics #digitalforensics #computerforensic #investigation #cybercrime #fraud

Saturday, October 8, 2016

DIGITAL FORENSICS:CompTIA Security+ Course สอบ

DIGITAL FORENSICS:CompTIA Security+ Course สอบ
วิชา ระบบความมั่นคงปลอดภัย


CompTIA Security+ คือใบรับรองทางมาตรฐานวิชาชีพที่เป็นกลางไม่อิงผู้ขายและผู้ผลิตอุปกรณ์รายใด ข้อสอบ CompTIA Security+ เป็นที่ยอมรับในระดับสากลด้านความรู้และทักษะการรักษาความปลอดภัยในระดับซึ่งเป็นรากฐาน และถูกนำไปประยุกต์ใช้อย่างแพร่หลายโดยองค์กรและผู้เชี่ยวชาญด้านการรักษาความปลอดภัยทั่วโลก

Cybersecurity Specialist Certifications

Exam Objectives (Domains)

CompTIA Security+ focuses on five major cybersecurity domains. Each domain and the measure to which it is represented in the exam are listed as follows: [+]

DomainPercentage of Examination
Attacks, Threats, and Vulnerabilities24%
Architecture and Design21%
Implementation25%
Operations and Incident Response16%
Governance, Risk, and Compliance14%

(1) Attacks, Threats, and Vulnerabilities

  • เปรียบเทียบความคล้ายและความแตกต่างของเทคนิควิศวกรรมสังคมประเภทต่าง ๆ
  • วิเคราะห์สัญญาณบ่งชี้ที่เป็นไปได้เพื่อระบุประเภทการโจมตี
  • วิเคราะห์สัญญาณบ่งชี้ที่เกี่ยวข้องกับการโจมตัแอปพลิเคชัน
  • วิเคราะห์สัญญาณบ่งชี้ที่เกี่ยวข้องกับการโจมตีเครือข่าย
  • อธิบาย Threat Actor , Vector และแหล่งข่าวกรองต่าง ๆ
  • อธิบายข้อกังวลด้านการรักษาความปลอดภัยที่เกี่ยวข้องกับช่องโหว่ประเภทต่าง ๆ
  • สรุปเทคนิคที่ใช้ในการประเมินการรักษาความปลอดภัย
  • อธิบายเทคนิคที่ใช้ในการทดสอบเจาะระบบ
(2) Architecture and Design

  • อธิบายความสำคัญของแนวคิดด้านการรักษาความปลอดภัยในสภาพแวดล้อมองค์กร
  • สรุปแนวคิดเกี่ยวกับระบบเสมือนและการประมวลผลแบบ Cloud
  • สรุปแนวคิดเกี่ยวกับการพัฒนาแอปพลิเคชันที่ปลอดภัย การใช้งาน และการทำงานอัตโนมัติ
  • สรุปแนวคิดการออกแบบการตรวจสอบสิทธิ์และการอนุญาต
  • ใช้การเตรียมพร้อมรับมือด้านความปลอดภัยทางไซเบอร์
  • อธิบายผลกระทบด้านการรักษาความปลอดภัยจากระบบฝังตัวและระบบเฉพาะทาง
  • อธิบายควาสำคัญของการควบคุมการรักษาความปลอดภัยแบบ Physical Security
  • สรุปพื้นฐานแนวคิดเกี่ยวกับ Cryptographic
(3) Implementation

  • การใช้ Secure Protocol
  • การใช้โซลูชั่นด้านการรักษาความปลอดภัยของโฮสต์ หรือ แอปพลิเคชัน
  • การใช้ Secure Network Design
  • การติดตั้งและกำหนดการตั้งค่า Wireless Security
  • การใช้โซลูชั่น Secure Mobile
  • การปรับใช้โซลูชันความปลอดภัยทางไซเบอร์กับ Cloud
  • การควบคุม Identity และการบริหารจัดการแอคเคาท์
  • การใช้โซลูชั่นตรวจสอบสิทธิ์และการอนุญาต
  • การใช้โครงสร้าง Public Key
(4) Operations and Incident Response

  • การใช้เดรื่องมือที่เหมาะสมเพื่อประเมินการรักษาความปลอดภัยขององค์กร
  • สรุปความสำคัญของ Policy , Process และ ขั้นตอนการทำ Incident Response
  • การใช้แหล่งข้อมูลที่เหมาะสมเพื่อสนับสนุนการสืบสวนสอบสวน
  • การใช้เทคนิคเพื่อควบคุมหรือลดความเสียหายเพื่อรักษาความปลอดภัยของสภาพแวดล้อม
  • อธิบายหลักการสำคัญของ Digital Forensics
(5) Governance, Risk, and Compliance

  • เปรียบเทียบความคล้ายและความแตกต่างของ Control ประเภทต่าง ๆ
  • อธิบายความสำคัญของข้อบังคับ มาตรฐาน หรือ Framework ที่มีผลบังคับใช้กับ Security Posture ขององค์กร
  • อธิบายความสำคัญของ Policy ต่อการรักษาความปลอดภัยขององค์กร
  • สรุปแนวคิดและกระบวนการจัดการความเสี่ยง
  • อธิบายแนวคิดด้าน Privacy และ Sensitive Data ที่เกี่ยวข้องกับการรักษาความปลอดภัย

clipboard Exam Structure

  • Maximum of 90 questions
  • Questions are multiple-choice and performance-based (using simulations of things like firewalls, networks diagrams, or operating systems)
  • Passing score is 750 (on a scale of 100-900)

  • Section 1 – Attacks, Threats, and Vulnerabilities

  • Section 2 – Architecture and Design

  • Section 3 – Implementation

  • Section 4 – Operations and Incident Response

  • Section 5 – Governance, Risk, and Compliance


  • SY0-601 Security+ Study Group Replays

Comptia security Sy0-601

CompTIA Security+ Passed

CompTIA Security+  SY0-601

อ่านเพิ่มเติม CompTIA Security+  cheat sheet

                         SY0-601


Ref:
7 คำถามทดสอบ CompTIA Security+ (SY0-601) ,ARIT ,October 25, 2022



หมายเหตุ:เนื้อหาในเว็บไซต์นี้มีขึ้นเพื่อวัตถุประสงค์ในการให้ข้อมูลและเพื่อการศึกษาเท่านั้น

* หากมีข้อมูลข้อผิดพลาดประการใด ขออภัยมา ณ ที่นี้ด้วย  รบกวนแจ้ง Admin เพื่อแก้ไขต่อไป
ขอบคุณครับ

#WindowsForensic #ComputerForensics #dfir #forensics #digitalforensics #computerforensic #investigation #cybercrime #fraud

Volatility Lab

Volatility Lab  Image Wanna.vmem P.73 windows.info #python3  vol.py   -f '/home/kali/Desktop/Wanna/Wanna-MEM.vmem' windows.info     ...