Shon Harris - Logical Security
Resources > Videos
Shon Harris Resources Shon Harris Security Practices

Backup Protection
This video gives a brief introduction to the different types of backups that can be done.

View Video


Block Ciphers
This video describes what a block cipher is.

View Video


Buffer Overflow Attacks
This video gives a brief introduction to the topic of buffer overflow attacks.

View Video


Digital Certificates
This video describes what a digital certificate is and how it works.

View Video


Domain Name Services
This video details the components of domain names and how they translate into IP addresses.

View Video


Due Diligence
This video gives a brief introduction to examples of Due Diligence.

View Video


Incident Response
This video details components of an Incident Response team and how to respond to a computer crime.

View Video


ITIL Problem Management
This video describes the procedures of problem management.

View Video


Security Concepts
This video describes different concepts people have about security, flaws and vulnerabilities.

View Video


Wireless Security
This video gives a brief introduction to wireless security and attacks.

View Video


Wireless Integration and Security Course - Introduction to Wireless Integration and Security Course
This section provides an outline of the topics that will be covered in the course, along with an overview of the different Wireless certifications.

View Video


Wireless Integration and Security Course - Module 1 – Introduction to WLANs
This module covers the historical aspects of wireless networking technology, the advantages of using WLAN technology over traditional networking, identifying the various wireless component technology used in WLANs and the definitions of the various types of wireless networks.

View Video


Wireless Integration and Security Course - Module 2 – Radio Frequency Fundamentals
This module covers the basics of RF principles, identification and comprehension of RF behavior, RF concepts associated with antennas, RF units of measurement and how RF components relate to 802.11.

View Video


Wireless Integration and Security Course - Module 3 – Radio Transmission Technologies
This module provides an overview of relevant organizations, transmission technologies and standards that define wireless networking and security.

View Video


Wireless Integration and Security Course - Module 4 – Wireless LAN Devices
This module covers the historical aspects of wireless networking technology and its impact on society, the advantages of using WLAN technology over traditional networks, the identification of various wireless component technology used in WLANs and the definition of various types of WLANs.

View Video


Wireless Integration and Security Course - Module 5 – Antennae
This module provides an overview of antenna, followed by a description of the types of antenna, antenna components, and issues related to antenna design and placement.

View Video


Wireless Integration and Security Course - Module 6 – 802.11 Network Architecture Design
This module covers the design and development of the 802.11 standard and its relationship in the OSI model, how 802.11 maps to the Physical and MAC Layer components and the intricacies of the 802.11 network connection process.

View Video


Wireless Integration and Security Course - Module 7 – WLAN Security
This module addresses the topics of security weaknesses associated with implementing WLAN networks, the different technologies used to secure wireless networks, various methods of attack, how to best security your wireless environment and testing the security of wireless configurations.

View Video


Wireless Integration and Security Course - Module 8 – WLAN Site Surveying and Troubleshooting
The module covers the reasons for and benefits of a good site survey, factors that can degrade the RF signal, how to gather sufficient information and determine proper hardware placement, security needs analysis, documentation requirements and troubleshooting WLANs.

View Video


Wireless Integration and Security Course - Module 9 – WPAN, WWAN and Cellular Technologies
The module provides an overview on WPAN technologies, Wireless Regional Area technology, Wireless Wide Area technology and Cellular technology.

View Video


Wireless Integration and Security Course - Lab 1 - Installation and Configuration of a Wireless Network Interface Card Part 1
This lab provides instruction on installation and configuration of a Wireless Network Interface Card.

View Video


Wireless Integration and Security Course - Lab 1 - Installation and Configuration of a Wireless Network Interface Card Part 2
This lab continues the instruction on installation and configuration of a Wireless Network Interface Card.

View Video


Wireless Integration and Security Course - Lab 2 – Associating with a Wireless Access Point on a Windows Vista Computer
This lab provides instruction on associating with a wireless access point using a computer running Windows Vista.

View Video


Wireless Integration and Security Course - Lab 3 – Understanding Radio Frequency Waves
This lab provides instruction on radio frequency waves.

View Video


Wireless Integration and Security Course - Lab 4 – Decibel Calculations
This lab provides instruction on how to perform Decibel (dB) calculations.

View Video


Wireless Integration and Security Course - Lab 5 – Securing an enterprise grade Wireless Access Point with Cisco 1220 AP
This lab provides instruction on how to secure an enterprise grade wireless access point with a Cisco product.

View Video


Wireless Integration and Security Course - Lab 6 – Securing a high speed 802.11n wireless access point using a Cisco Linksys WRVS4400n access point
This lab provides instruction on how to secure a high speed wireless access point with a Cisco product.

View Video


Wireless Integration and Security Course - Lab 7 – Performing wireless frame analysis using Wireshark, a free sniffer tool
This lab provides instruction on how to perform wireless frame analysis using Wireshark.

View Video


Ethical Hacking and Penetration Testing
In this section, we will be going over the Introduction to Ethical Hacking and Penetration Testing Methodologies, Security Testing, and Building a Test System.

View Video


Footprinting and Reconnaissance
In this section, we will be going through Discovery/Verification, by digging in deep into Gathering of Information, through Corporate Information/Internet Presence, Googling for Passwords, Social Engineering, Networking, and Telephony Attack Types.

View Video


TCP/IP Basics and Scanning
In this section, we will be going through the basics of TCP/IP, Ping Sweeps, and Port Scanning.

View Video


Enumeration and Verification
In this section, we will be going through Operating System Identification, SNMP, Finger, SMTP, NetBIOS, CIFS/SMB, SID to Account-Name Resolution, LDAP/Active Directory, and GUI Tools.

View Video


Hacking and Defending Wireless/Modems
In this section, we will be going through attacking Wireless Systems, reconnaissance, and finishing up with defense countermeasures. This will all you to be able to build a better network design, secure your access points, and understand immerging technologies. This section also covers attacking modems, reconnaissance through these methods, and defenses.

View Video


Hacking and Defending Web Servers
In this section, we will cover the subject of attacking and defending web servers. We will be going through Web Servers in General (HTTP/URL/SSL), Apache Web Servers (Functionality, Attacking, and Defending), Microsoft Internet Information Server (Functionality/Security Features, Attacking, and Defending), then finishing up with Web Server Vulnerability Assessment.

View Video


Hacking and Defending Web Applications
In this section, we will cover the subject of attacking and defending web application servers. Securing web applications and services comes down to secure coding practices, good authentication routines, and patching management. In this section, we will cover best practice methods for preventing input validation attacks as well as SQL injection attacks. In addition to these coding best practices, we will discuss issuing secure cookies, and adding a third authentication factor to web applications to prevent brute-force attacks.

View Video


Sniffers and Session Hijacking
In this section, we will cover the subject of Sniffers (Packet Capturing), both Passive and Active; and Session Hijacking methodology and tools.

View Video


Hacking and Defending Windows Systems
In this section, we will cover critical operating system components, obtaining credentials, system attacks, and hiding tracks in Hacking Windows Systems. Then we will show you how to defend the Windows Systems, by hardening the systems, strong authentication, password auditing, and file permissions.

View Video


Hacking and Defending Unix Systems
In this section, we will cover password, buffer overflow, race condition, format string, and file system attacks, along with hiding tracks on Hacking Unix/Linux systems. After showing you these attacks, we will guide you through defending the Unix/Linux systems, by hardening the systems (Boot Loader Passwords, Strong Password Policies, Single Sign-On Technologies, Tight File Permissions, removing unnecessary services, and hardening scripts), and by using encryption and VPNs on defending the Unix/Linux systems.

View Video


Rootkits, Backdoors, Trojans and Tunnels
In this section, we cover various malicious tools that attackers use to exploit your networks and maintain access. This will be completed through Rootkits (LRK, Windows NT, AFX Rootkit, and Prevention), Backdoors (netcat, VNC, and Prevention/Detection), Trojans (Back Orifice, NetBus, SubSeven, and Prevention/Detection), and Tunnels (Loki, Q-2.4, and Prevention/Detection).

View Video


Denial of Service and Botnets
In this section, we will cover the subject of attacking and defending systems from Denial-of-Service (DoS) attacks and botnets. DoS attacks can have a devastating impact on the target organization or individual system. We will also breakdown what a DoS attack is and what reasons are often behind someone using such an attack. We will also discuss the types of DoS attacks that exist and their outcomes, as well as how attackers can mask their IPs by spoofing the source address.

View Video


Automated Penetration Testing Tools
In this section, we will be covering Automated Penetration and Testing Tools as in Core Impact, Canvas, and Metasploit.

View Video


Intrusion Detection Systems
In this section, we will be covering Intrusion Detection Systems (IDSs), starting with an introduction to IDSs, introduction to Snort, and attacking an IDS. Attacking an IDS has a few separate steps, to include Detection, Eluding, and Testing.

View Video


Firewalls
In this section, we will be covering Firewalls. We will be going through firewall types and architectures, IPTables/Netfilters, and exploiting of firewalls.

View Video


Honeypots and Honeynets
In this section, we will cover the subject of attacking and defending networks through the use of honeypots and honeynets. This will be accomplished by going through the background, types and categories, and implementing of Honeypots. All types of Honeypots will be discussed, along with implementing of a Honeypot, and finishing up with legal considerations of honeypot implementation.

View Video


Ethics and Legal Issues
In this section, we will be covering the Ethical, Proper Ethical Disclosure of Bugs/Vulnerabilities, and Legal Issues of Ethical Hacking and Penetration Testing.

View Video


CISSP Essentials training: Domain 1, Security Management Practices
In this video, Shon Harris details how security management facilitates an enterprise's security vision by formalizing the infrastructure, defining the activities, and applying the tools and techniques necessary to control, monitor and coordinate security efforts across an organization.

View Video


CISSP Essentials training: Domain 2, Access Control
In this video, Shon Harris details how access controls support the core security principles of confidentiality, integrity and availability by inducing subjects to positively identify themselves, verify they possess appropriate credentials and the necessary rights and privileges to obtain access to the target resource and its information. Key focus areas include access control principles; administration and practices; models and technologies; types, methods and techniques; and threat monitoring.

View Video


CISSP Essentials training: Domain 3, Cryptography
In this video featuring Shon Harris, learn how cryptography, its components, methods and uses are employed in the enterprise to store and transmit messages safely.

View Video


CISSP Essentials training: Domain 4, Security Models and Architecture
In this video, Shon Harris investigates the framework and structures that make up typical computer systems. The special video presentation sketches the evolution of security models and evaluation methods as they have struggled to keep pace with changing technology needs.

View Video


CISSP Essentials training: Domain 5, Telecommunications and networking
In this video, Shon Harris describes how networking is one of the more complex topics in the computer field, mainly because so many components are involved.

View Video


CISSP Essentials training: Domain 6, Application and System Development
In this video, Shon Harris details how applications and systems are structured, what security mechanisms and strategies are commonly used to secure data during access, processing and storage; it also presents some of the common threats and countermeasures.

View Video


CISSP Essentials training: Domain 7, Business Continuity
In this video, Shon Harris details how disaster recovery processes make it possible to survive a disaster and respond effectively immediately following a disaster event.

View Video


CISSP Essentials training: Domain 8, Law, Investigations and Ethics
In this video, Shon Harris details how the issues of investigating computer crimes, the role of forensics, types of evidence and how to ensure that companies are compliant to applicable laws.

View Video


CISSP Essentials training: Domain 9, Physical Security
In this video, Shon Harris details Domain 9 of the Common Body of Knowledge, which addresses the challenges of securing the physical space, its systems and the people who work within it by use of administrative, technical and physical controls.

View Video


CISSP Essentials training: Domain 10, Operations Security
In this video, Shon Harris details the process of understanding enterprise security operations from a competitor's/enemy's/hacker's viewpoint and then developing and applying countermeasures to mitigate identified threats.

View Video


Incident Response
Shaun Drutar briefly describes the definition of incident response and the security incident handling process.

View Video


Ethical Hacking - TCP/IP and Scanning
View Allen Harper's presentation on TCP/IP and Scanning. Please note that there is only a limited amount of audio during the presentation.

View Video


Ethical Hacking - Enumeration and Verification
View Allen Harper's presentation on Enumeration and Verification. Please note that there is only a limited amount of audio during the presentation.

View Video


Ethical Hacking - Penetration Testing Methodology
View Allen Harper's presentation on Penetration Testing Methodology. Please note that there is only a limited amount of audio during the presentation.

View Video


Ethical Hacking - Footprinting and Reconnaissance
View Allen Harper's presentation on Footprinting and Reconnaissance. Please note that there is only a limited amount of audio during the presentation.

View Video


Logical Security
Shon Harris describes her company, Logical Security, and its CISSP products and courses.

View Video


Rainbow Tables

Shaun Drutar briefly describes the definition and use of Rainbow Tables.

View Video

© Logical Security