Hands-On Ethical Hacking and Network Defense, Third Edition 1-1
Chapter 01
Ethical Hacking Overview
At a Glance
Instructor’s Manual Table of Contents
Overview
Objectives
Teaching Tips
Quick Quizzes
Hands-On Ethical Hacking and Network Defense, Third Edition 1-2
Lecture Notes
Overview
This chapter provides an introduction to ethical hacking concepts, including the term ethical
hacker, as well as penetration and security tests and the differences between them. Students will
learn the differences between the terms hacker, cracker, and script kiddies. Next, they will learn
about the white box, black box, and gray box models for conducting penetration testing.
Chapter Objectives
After reading this chapter and completing the exercises, the student will be able to:
Describe the role of an ethical hacker
Teaching Tips
Introduction to Ethical Hacking
1. Clearly define the following concepts: ethical hacking, penetration test, vulnerability
2. Explain the differences between penetration tests and security tests. Emphasize that this
The Role of Security and Penetration Testers
1. Discuss the role of security and penetration testers by defining concepts such as hacker,
2. Give a definition of the term script. Mention the programming languages that are often
used by penetration and security tester to write scripts:
3. Introduce students to the term “hacktivist”. Explain that this term is used to define a
person who hacks computer systems for political or social reasons.
Teaching
Tip
What is a script? Look at the following Web site to learn more:
http://frontier.userland.com/tutorial/whatIsAScript.
4. Discuss the requirements for a typical penetration tester.
a. Perform vulnerability, attack, and penetration assessments in Internet, intranet,
and wireless environments.
b. Perform discovery and scanning for open ports and services.
Penetration-Testing Methodologies
1. Explain the characteristics of the white box model. Use Figure 1-1 to illustrate a
network diagram that can be used during a white-box-based penetration test.
2. Explain the characteristics of the black box model.
a. The company staff does not know about the test.
3. Explain the characteristics of the gray box model.
4. Discuss the main advantages and disadvantages of each model, as well as how to
Hands-On Ethical Hacking and Network Defense, Third Edition 1-4
Certification Programs for Network Security Personnel
1. Mention that there are certification programs available in almost every area of network
security.
2. Explain how the CompTIA’s Security+ and Security+ certifications can help prepare an
3. Provide a brief explanation of the following certification programs:
Offensive Security Certified Professional (OSCP)
Certified Ethical Hacker (CEH) from the International Council of Electronic
4. Encourage your students to find out more about these certifications and to pursue one or
more of them.
Teaching
Tip
If you hold any of these (or other) certifications share your experience with your
students. Specifically, share stories about preparing for the exams and how a
certification can enrich your professional life.
Quick Quiz 1
1. Which term describes when an ethical hacker attempts to break into a company’s
network to find the weakest link in that network or network system?
A. security test
B. script test
C. packet test
D. penetration test
2. Which of the following terms are used to describe a set of instructions that run in
sequence to perform tasks on a computer system?
A. script
B. assessment
C. packet
D. black box
3. True or False: Crackers might simply want to prove how vulnerable a system is by
accessing the computer or network without destroying any data.
4. What is the name of the model that is a hybrid of the white and black box models?
What You Can Do Legally
1. Introduce the legal aspect of network security to your students. Any penetration or
2. Laws change from state to state, and country to country. Encourage your students to
Laws of the Land
2. Use Table 1-1 to illustrate some of the most infamous recent hacking cases and how the
U.S. government handled each case.
Is Port Scanning Legal?
1. Depending on your state laws, port scanning is either legal or illegal. Explain to your
2. Discuss with your students the current legal status of port scanning (and other similar
3. Define the term “Acceptable Use Policy”, which is issued by your ISP. Use Figure 1-2
Federal Laws
1. Discuss the computer hacking and intellectual property branch of the government and
its role in computer crime.
2. Use Table 1-2 to explain some federal laws regarding computer crimes.
Teaching
Tip
You can use your local laws regarding computer hacking and intellectual
property issues to complement the discussion of federal laws.
What You Cannot Do Legally
1. Define some actions that are not considered legal, including the following:
a. Accessing a computer, destroying data, and copying information without the
2. It is important that your students clearly understand that preventing the client’s
Get It in Writing
2. Give your opinion on this topic. Remember that the position of the book is that a written
contract is just good business.
3. If you decide to use a contract, recommend that your students ask an attorney to look at
Hands-On Ethical Hacking and Network Defense, Third Edition 1-7
Ethical Hacking in a Nutshell
1. Introduce and explain the different skills required for any security tester:
a. Knowledge of network and computer technology
Quick Quiz 2
1. True or False: Laws involving computer technology change as rapidly as technology
itself.
2. Which of the following is a program that sends automatic responses to users, giving the
appearance of a person being on the other side of the connection.
A. script
B. packet
C. IRC bot
D. AUP
3. What is the name of the new government branch that handles cybercrimes and
intellectual property issues?
4. True or False: Hacking tools are always illegal to posses.
Class Discussion Topics
1. What are the advantages of using a written contract when engaged in a computer
consulting job? Why is it important that your attorney read over the contract before you
sign it?
2. Why do you think the government does not define a common law for computer-related
crimes, rather than allowing each state to address these issues?
Hands-On Ethical Hacking and Network Defense, Third Edition 1-8
Additional Projects
1. Ask your local law enforcement agency which hacking activities are considered legal or
2. Ask your ISP for its “Acceptable Use Policy” and read it. Write one to two paragraphs
of your own interpretation of such a policy. What activities are you allowed to conduct?
Can you run IRC “bots”?
Additional Resources
2. Certification for Ethical Hackers:
3. Benefits of Penetration Testing:
4. The Pros and Cons of Ethical Hacking:
5. Hacking Laws:
Key Terms
See Glossary for definitions of Key Terms.
black box model
Hands-On Ethical Hacking and Network Defense, Third Edition 1-9
ethical hackers
Global Information Assurance Certification (GIAC)
gray box model
hacker
hacktivist
Institute for Security and Open Methodologies (ISECOM)
Offensive Security Certified Professional (OCSP)
Technical Notes for Activities
Activity 1-1: This activity requires a Web browser and an Internet connection.
Activity 1-2: This activity requires a Web browser and an Internet connection.