News

03.06.2013

openHPI course "WWW"

Start of the openHPI course "Introduction to Web Technologies" (in German) on openHPI. You can enroll here.
08.04.2013

openHPI course "SQL"

Start of the openHPI course "Data Management with SQL" (in German) on openHPI. You can still enroll in the course ... [more]
05.03.2013

tele-TASK at CeBIT 2013

Also this year the project tele-TASK will be at CeBIT. You can find us at the booth of Hasso Plattner ... [more]

Statistics

userclicks~31 Mio.
lecture4440
activelecturer1665
series357
Lecture-Feed of Series: Internet Security - Weaknesses and Targets (WT 2007/08)Feed of Series: Internet Security - Weaknesses and Targets (WT 2007/08)

Internet Security - Weaknesses and Targets (WT 2007/08)

Prof. Dr. Christoph Meinel

"Internet Security II - Weaknesses and Targets" is based on "Internet Security I - Internet Technology" respectively on "Technical Basics of WWW" and gives a detailed introduction on problems concerning Internet and Intranet security. After starting with some remarks on risk analysis and computer crimes, security weaknesses and targets are discussed in detail. Beside others the following topics are discussed in detail: human factor and technical failures, attacks on accounts and passwords, attacks on Internet protocol, misuse of design and programming errors, weaknesses in common operating systems, targets in the WWW, and viruses. The lecture course concludes with a discussion about the possibilities to detect attacks and intrusions and also describes ethical issuses.

Introduction

Date:17.10.2007
Lang.: en
Dur.:01:21:02
Play full lecture
• Nowdays Internet 00:10:42
• Risks when using Internet-based Information Systems 00:04:44
• Systematic Problem in Internet Security 00:03:19
• Internet is an easy Target 00:11:18
• Improved Opportunities for Intrusion 00:04:37
• Direction of Internet Security 00:06:27
• Complexity of Internet 00:11:51
• Computer Crimes and Damage 00:08:19
• General Risks of Interconnected IT-Systems 00:04:44
• Basic Risk by using Internet 00:14:00
Date:24.10.2007
Lang.: en
Dur.:01:19:26
Play full lecture
• Introduction 00:03:26
• Computer Networks 00:04:32
• Internets and Internet Protocols 00:25:27
• Internet Services and Applications 00:04:42
• WWW 00:15:14
• WWW-Browser and WWW-Server 00:08:06
• History of Internet and WWW 00:09:38
• Who-is-Who 00:04:32
• Internet Standards 00:03:49

Risk Analysis and Cyber Crime

Date:11.10.2007
Lang.: en
Dur.:01:26:55
Play full lecture
• Introduction 00:05:59
• Risks in Internetworking IT-Systems 00:22:23
• Risk Definition 00:02:43
• Phases of Risk Analysis 00:10:55
• Evaluation of Risks 00:28:46
• Basic Risks of Internet 00:16:10
Date:18.10.2007
Lang.: en
Dur.:00:30:07
Play full lecture
• Potential Attackers 00:30:07
Date:18.10.2007
Lang.: en
Dur.:00:47:14
Play full lecture
• First Hackers 00:12:37
• Underground Mailboxes 00:02:03
• Viruses, Worms, Trojan Horses 00:11:43
• Short History of Cyber Crime 00:19:27
• Financial Losses by Cyber Crime 00:01:24

Weaknesses and Targets

Date:25.10.2007
Lang.: en
Dur.:00:47:15
Play full lecture
• Technical Failure 00:07:33
• Defective Design 00:08:39
• Lack of Knowledge and Carelessness 00:09:06
• Social Hacking 00:07:24
• Defective Organization 00:03:57
• Unprotected Hardware 00:02:57
• Most Typical Break-in Methods 00:07:39
Date:07.11.2007
Lang.: en
Dur.:00:29:53
Play full lecture
• Introduction 00:05:26
• Passive Recon 00:12:56
• Web Recon 00:06:17
• Active Recon 00:05:14
Date:07.11.2007
Lang.: en
Dur.:00:35:21
Play full lecture
• Introduction 00:02:15
• Telnet Session Negotiation/Banners 00:05:48
• TCP Stack Fingerprinting 00:12:49
• Passive Fingerprinting 00:05:06
• Fuzzy OS Fingerprinting 00:05:35
• TCP/IP Timeout Detection 00:03:48
Date:21.11.2007
Lang.: en
Dur.:00:50:42
Play full lecture
• Introduction 00:07:42
• Password Guessing 00:04:54
• Password Cracking 00:23:22
• Password Sniffering 00:02:42
• Password Monitoring 00:01:38
• Phishing - Password Fishing 00:05:47
• Protection Against Password Theft 00:04:37
Date:28.11.2007
Lang.: en
Dur.:01:26:04
Play full lecture
• Introduction 00:12:33
• Attack Scenarios 00:02:50
• IP Address Spoofing 00:08:19
• ICMP - Attacks 00:25:18
• Internet - Routing - Attacks 00:13:44
• ARP - Routing - Attacks 00:07:07
• IP - Fragmentation Attacks 00:11:02
• IP - Bombing 00:05:11
Date:05.12.2007
Lang.: en
Dur.:01:25:42
Play full lecture
• Introduction 00:11:16
• Attack Scenarios 00:02:24
• SYN - Flooding 00:07:18
• TCP-Sequence-Number Attack 00:19:25
• Cancel/Hijack TCP-Connection 00:07:01
• UDP Attack 00:03:36
• DNS Attacks 00:07:57
• SMTP Attacks 00:04:11
• Telnet Attacks 00:04:49
• FTP Attacks 00:06:16
• Weakness of VoIP Protocals 00:11:29
Date:12.12.2007
Lang.: en
Dur.:00:44:15
Play full lecture
• Introduction 00:02:45
• Buffer Overflow 00:22:58
• Defective Syntax Check 00:09:53
• Race Conditions 00:08:39
Date:19.12.2007
Lang.: en
Dur.:01:26:42
Play full lecture
• Security Architecture of Unix 00:13:12
• Attacks at Boot-Time 00:04:03
• Password Attacks in Unix 00:09:55
• Breaking Out of Chroot Jail 00:03:44
• Network Attacks in Unix 00:10:57
• Network Attacks in Unix via rlogin and rsh 00:06:46
• Network Attacks in Unix via TFTP 00:03:43
• Network Attacks in Unix via NFS 00:05:45
• Network Attacks in Unix via NIS 00:03:29
• Network Attacks in Unix via NTP 00:06:14
• Network Attacks in Unix via X.11/X-window System 00:18:54
Date:09.01.2008
Lang.: en
Dur.:01:10:39
Play full lecture
• Introduction 00:03:38
• Already Discussed Attacks on Unix/Linux 00:00:44
• Attacks via Unix Applications 00:02:49
• Abuse of Symbolic Links 00:06:50
• Sendmail Attack 00:03:57
• DNS/BIND Vulnerabilities 00:03:06
• Apache Vulnerabilities 00:02:52
• Social Hacking with finger and whois 00:04:15
• Strategies to Protect Unix System 00:11:20
• Strategies to Protect Unix System: WWW Security 00:08:12
• Strategies to Protect Unix System: FTP 00:01:56
• Strategies to Protect Unix System: DNS/BIND 00:02:23
• Strategies to Protect Unix System: Mail/Sendmail 00:03:31
• Strategies to Protect Unix System: Kernel-level Hardening 00:04:56
• Strategies to Protect Unix System: Host-based Firewalls 00:01:43
• Strategies to Protect Unix System: Apache with SSL 00:00:40
• Strategies to Protect Unix System: Security Scanner 00:02:50
• Strategies to Protect Unix System: Examination of Passwords 00:02:22
• Information about Unix-Security 00:02:35
Date:16.01.2008
Lang.: en
Dur.:01:23:45
Play full lecture
• Introduction 00:06:32
• SMB Attack 00:08:15
• UPnP Attack 00:09:42
• Help Center Attack 00:08:50
• Remote Attacks 00:07:59
• MS Windows Server 00:01:59
• Kerberos Authentication Attacks 00:03:19
• Kerberos Authentication Review 00:08:28
• Cross-Domain Network Resources 00:03:34
• Weakness in Kerberos Protocol 00:07:56
• Defeating Buffer Overflow Prevention 00:05:04
• PKI and Smart Card Hacking 00:05:54
• Hardware Reverse Engineering 00:01:30
• EEPROM Trapping 00:04:43
Date:23.01.2008
Lang.: en
Dur.:01:01:30
Play full lecture
• Introduction 00:03:12
• Target Web-Browser 00:01:19
• Spying Out Personal Data 00:13:24
• Java 00:21:13
• JavaScript 00:13:30
• ActiveX 00:03:28
• Protective Measure for Web-Browsers 00:05:24
Date:30.01.2008
Lang.: en
Dur.:01:13:11
Play full lecture
• Introduction 00:04:35
• Break into Web-Servers 00:01:50
• CGI-Attacks 00:04:22
• URL-Attacks 00:05:40
• SQL-Injection 00:11:58
• Cross-Site Scripting 00:12:34
• Current Challenges of SOA Security 00:05:38
• WS-Security 00:12:52
• Current Challenges of Web 2.0 Security 00:13:42
Date:06.02.2008
Lang.: en
Dur.:01:23:57
Play full lecture
• Introduction 00:04:46
• IEEE 802.11 Wireless LAN - WLAN 00:17:21
• WLAN Parameters 00:04:08
• WLAN Security Mechanisms 00:07:43
• WLAN Security Weaknesses 00:11:00
• WLAN Security with IEEE 802.1x 00:05:20
• Extended WLAN Security 00:14:32
• WLAN Security in Practice 00:05:21
• Cellular Phone Technologies 00:05:48
• Secure Connections with Mobile Devices 00:02:56
• Weaknesses of GSM Technologies 00:02:05
• Summary 00:02:57

Detection of Attacks and Intrusions

Date:23.01.2008
Lang.: en
Dur.:01:09:58
Play full lecture
• Introduction 00:07:57
• Audit Log Reduction 00:02:47
• Anomalies and Attack Signatures 00:01:58
• Anomalies 00:05:20
• Detecting Anomalies 00:11:09
• Attack Signatures 00:06:15
• Implementation of IDS 00:01:48
• Network-based IDS 00:05:24
• Host-based IDS 00:04:54
• Implementation of Intrusion Dection System 00:03:29
• Reactions on Attacks 00:04:59
• Intrusion Response 00:03:47
• Limitations of Intrusion Dection Systems 00:10:11

Legal and Ethical in Internet Security

Date:06.02.2008
Lang.: en
Dur.:01:20:00
Play full lecture
• Legal Systems 00:17:14
• Example: German Criminal Law 00:12:23
• Case Studies 00:17:38
• Responsibility of IT_Managers 00:03:32
• Ethical Issues 00:13:39
• Case Studies 00:06:58
• Case of Ethics 00:08:36
Tags added to this content

No tags have been added to this content so far.

Tag this content

Please enable javascript to use this function.

Dear user,
with the tagging function you'll be able to add taggs to videos.
However, in order to link all your tags with your user profile it is required that you
login to the tele-TASK portal to use this functionality.
If you don't have an account yet, you may register for a tele-TASK account here.
Links added to this content

No links have been added to this content so far.

Add Link to this content

Please enable javascript to use this function.

Dear user,
with the links function you'll be able to add links to other resources to this content.
However, in order to link all your links with your user profile it is required that you
login to the tele-TASK portal to use this functionality.
If you don't have an account yet, you may register for a tele-TASK account here.