Home > Screencasts: On-screen demonstrations of today's IT tools
Screencast:
EMAIL THIS

Screencasts: On-screen demonstrations of today's IT tools

07 Apr 2009 | SearchSecurity.com

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

When it comes to analyzing a network, protecting enterprise data, or fighting malware, there are a variety of free and commercial products available to help. In our screencasts, SearchSecurity.com's best experts will walk you through today's popular information security tools and techniques.

   Maltego
   Cain and Abel
   Network Miner
   Metagoofil
   Tor
   Nipper
   Wikto
   Wireshark
   WinHex
   OSSTMM
   Metasploit
   Nessus
   Network Security Toolkit
   Snort
   Google Hacking
   UTM

Want on-screen demos of a particular tool that hasn't been featured? Email us your suggestions.


SCREENCASTS

Maltego
Maltego demo: Identifying a website's trust relationships
Learn how the Maltego tool can be most effectively used during the information-gathering phase of a penetration test. In this on-screen demo, Peter Giannoulis reveals some of the trust relationships of SearchSecurity.com itself.


Cain and Abel
Recovering lost passwords with Cain & Abel
Brute-forcing Windows passwords is easier than you think. Peter Giannoulis explains how the Cain and Abel tool can be used to recover your precious credentials.





Network Miner
How to gather host-level data with Network Miner
One particular open source network sniffer hasn't received the attention that it deserves, at least according to Peter Giannoulis. Watch as Peter demonstrates how to use Network Miner, a free, Windows-based tool, to identify ports, protocols, operating systems and other services.


Metagoofil
Collecting metadata with Metagoofil
Metagoofil, a free tool, provides users with the ability to extract hidden metadata from public documents, including Word docs, PowerPoints and PDFs. Learn how penetration testers can use this tool to analyze a network and assess the security of a website or Web server.



Tor
How Tor improves Web surfing privacy and security audits
Tor, a security tool that permits anonymous Web surfing, can be used for both good and bad. In this demonstration, learn how network administrators can mask their locations and improve their audits.




Nipper
How to use Nipper to create network security reports
Nipper, a free and open source network infrastructure parser, can do more than make your config look pretty. Learn how the tool can produce security audit reports on your network devices. Peter Giannoulis demonstrates how to review your network topology and see where you can enhance it.


Wikto
How to use Wikto for Web server assessment
Penetration testers who are looking for flaws in their Internet-facing Web servers can use the freely available Wikto. See for yourself what kinds of information that Wikto can gather about a specific website -- including its good and bad directories -- and which plug-ins will allow you to get the most out of the free tool.


Wireshark
Catching network traffic with Wireshark
Wireshark, a favorite network protocol analyzer, has plenty of forensic capabilities. See the kinds of traffic that the free tool can catch, including files from tcpdump, Microsoft Network Monitor, Sniffer Pro -- and even recorded VoIP calls.



WinHex
Recovering lost data with WinHex
WinHex performs forensics and also specializes in low-level data processing, drive imaging and file or program analysis. It can even prevent security leaks because of its ability to destroy or wipe data securely. Watch Peter Giannoulis as he reviews one of the Winhex's main functions: its ability to find and return deleted folders and lost data.


OSSTMM
An introduction to the Open Source Security Testing Methodology Manual
The Open Source Security Testing Methodology Manual (OSSTMM) allows you to perform many security tests on your firewalls, intrusion detection systems, passwords and much more. Watch Peter Giannoulis as he introduces the manual and demonstrates how it can be used to defend machines from a brute-force dictionary attack. Learn which parts of a security architecture need to be tested and how to properly measure your results.


Metasploit
Penetration testing with Metasploit
Metasploit allows hackers and security professionals alike to examine how well a given system can handle known exploits and payloads. Expert Peter Giannoulis demonstrates how the freely available tool can be used to test commercial and custom-made applications, servers and operating systems. In his presentation, Giannoulis shows how one unfortunate Windows user's machine can be easily taken advantage of.


Nessus
Finding vulnerabilities with Nessus
Nessus is the granddaddy of all information security tools. While no longer an open source tool, it still exists as freeware and is actively supported with new signatures. In this screencast, Peter Giannoulis of Bones Consulting demonstrates how enterprises can use Nessus to assess vulnerabilities and help protect critical systems and networks.


Network Security Toolkit
Opening up the Network Security Toolkit
Built upon Insecure.org's "100 Best Tools," the Network Security Toolkit is improving the jobs of information security professionals everywhere. Tom Bowers, managing director of security think tank and industry analyst firm Security Constructs, uses this latest screencast to explore the collection of networking and security gear. Bowers reviews the basics of the browser-based security toolbox, including proper configurations and tool selection.


Snort
Snort -- Tactics for basic network analysis
Snort is a robust tool that can be used in a number of ways to assess the security posture of a network, but it takes time to learn, and it can be tricky to obtain all the data that Snort can provide. SearchSecurity.com contributor Tom Bowers provides a demo for those using the tool for the first time. Bowers offers a brief introduction and history of Snort and explains what the IDS can do for information security pros.

Google hacking
Google hacking, infosec style
Search engines and related tools are not only handy when it comes to finding information on the Web, but they can also help security professionals ensure an organization's intellectual property doesn't slip off the network and into the public domain. Tom Bowers demonstrates how a few basic "Google hacking" methods can offer fascinating competitive intelligence for your enterprise. .

UTM
How to configure a UTM device
Unified threat management technologies provide protection against various network attacks, but properly configuring UTM boxes can be a whole other battle. In this exclusive screencast, expert David Strom gives an easy-to-follow, on-screen demonstration of the configuration options available in SonicWall's unified threat management product. In simple steps, Strom explains how to set up a SonicWall box, interpret its alerts and adjust security policies accordingly to ensure that a network has optimum protection.



BROWSE BY TAG
Open Source Security Tools and Applications,   Application and Platform Security,   VIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Open Source Security Tools and Applications
Screencast: Samurai offers pen-testing nirvana
Rootkit Hunter demo: Detect and remove Linux rootkits
When to use open source security tools over commercial products
Maltego demo: Identifying a website's trust relationships
Free HP SWFScan tool detects Adobe Flash flaws
L0phtCrack returns
How to use (almost) free tools to find sensitive data
Should open source disk-encryption software be used?
Open source security concerns can trump cost savings
Is there a free enterprise-caliber password-management tool?

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
Blowfish  (SearchSecurity.com)
Kermit  (SearchSecurity.com)
Open Source Hardening Project  (SearchSecurity.com)
SnortSnarf  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary




Search Additional Security Research and Solutions
Find Security Channel Research for Resellers and Partners
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts