CNIT 127 students should have received
an email from sam.bowne@agentmail.to
showing how to take the final exam
without using Canvas.
Since Canvas is down and I cannot access quiz
scores, your grade will be based on projects
and the final exan only, assuming you got
20 on all the quizzes.
Here is the new grading system:
A: 300
B: 244
C: 133
D: 78
F: 77 or less
I am working on gathering all the extra
credit I sent to Canvas and adding it to
my new scoring system.
If you submitted projects in Canvas, or
have any other issues to discuss, please
email sbowne@ccsf.edu or come to one of my
Twitch sessions shown at the top of
samsclass.info
In the "Select your Institution" drop-down list box, select "City College of San Francisco"
Enter your CCSF email address
Enter the book's title the "Find a Solution..." field
Catalog Description
Learn how to find vulnerabilities and exploit them to gain control of target systems, including Linux, Windows, Mac, and Cisco. This class covers how to write tools, not just how to use them; essential skills for advanced penetration testers and software security professionals.
Advisory: CS 110A or equivalent familiarity with programming
Upon successful completion of this course, the student will be
able to:
Define and explain essential Windows features and their weaknesses
Research, discover and exploit vulnerabilities in Mac OS X as part of ethical, authorized penetration tests
Research, discover and exploit vulnerabilities in Cisco lOS as part of ethical, authorized penetration tests
Evaluate and implement protection mechanisms
Textbook
"The Shellcoder's Handbook: Discovering and Exploiting Security Holes ", by Chris Anley, John Heasman, Felix Lindner, Gerardo Richarte; ASIN: B004P5O38Q
Buy from Amazon
Quizzes
The quizzes are multiple-choice, online, and open-book. However, you may not ask other people to help you during the quizzes. You will need to study the textbook chapter
before the lecture covering it, and take the quiz before that class.
Each quiz is due 30 min. before class. Each quiz has 5 questions, you have ten minutes to take it, and you can make two attempts. If you take the quiz twice, the higher score counts.
Don't use CCSF's Canvas system for this class. Instead, all students
should use this Canvas server:
Each CCSF student must contribute to the Discussion
Board in Canvas. There are dates
listed in the schedule with Discussion assignment
due.
For the topics and requirements, see the Discussion
board in Canvas.
Non-CCSF students don't have a Discussion Board in
Canvas, but are encouraged to join Twitter and engage
in the public discussions there.
Schedule
Date
Due
Topic
Mon 1-12
Mod 1 Ch 1: Before you Begin
Demo: ED 30
Mon 1-19
Holiday -- No Class
Mon 1-26
Ch 1 Quiz *
Ch 2 Quiz
Proj ED 30 due
Mod 2 Ch 2: Stack overflows on Linux
Mon 2-2
Ch 3 Quiz
Proj ED 101 & 102 due
Mod 3 Ch 3: Shellcode
Demo: ED 102, ED 103, ED 104
Mon 2-9
Ch 4 Quiz
Proj ED 103 & 104 due
Mod 4 Ch 4: Introduction to format string bugs
Demo: ED 201, 202, 204 (in the lecture)
Mon 2-16
Holiday -- No Class
Mon 2-23
Ch 5 Quiz
Proj ED 201 & 202 due
Mod 5 Ch 5: Introduction to heap overflows
Demo: ED 203 and ED 205 (in the lecture)
Mon 3-2
Ch 6 Quiz
Proj ED 203 & 204 due
Mod 6 Ch 6: The Wild World of Windows
Demo: Proj ED 308
Mon 3-9
Demos: H 150, H 151, H 140
Mon 3-16
No Quiz
Mod 7 Lecture 7: Intro to 64-Bit Assembler (Not in book)
Demo: ED 220: Intro to 64-bit Assembler (included in lecture)
Demo: ED 230: Hardening ELF Binaries
Demo: ED 309
Mon 3-23
Class cancalled for HackTheBay
Wed 3-30
Holiday: No Class
Mon 4-6
Ch 8a Quiz
Proj ED 205 & 206 due
Mod 8 Ch 8: Windows overflows (Part 1)
Demo: ED 318
Mon 4-13
Ch 8b Quiz
Proj ED 32 or H 2 & ED 308 due
Mod 9 Ch 8: Windows overflows (Part 2)
Demo: ED 301 & 302
Mon 4-20
L 9 Quiz
Proj ED 301 & ED 319 due
Mod 10 L 9: Web Templates and .NET (not in book)
Demos: ED 105: Server Side Template Injection (SSTI)
ED 330 and ED 331 (Dot NET)
Mon 4-27
No Quiz Due
Ch 14: Protection Mechanisms
Demo: ED 303 & H 540
Mon 5-4
Ch 14 Quiz
Proj ED 302 due
Mod 11 Ch 16 and 17 Demo: ED 440 & 441
Mon 5-11
All extra credit due
Last Class
No new material
Mon 5-13 through Wed 5-20
Final Exam available online throughout the week.
You can only take it once.