Ninja Security
One of my Beta testers hosts his own infosec training course called “Ninja Security.” I had the pleasure of taking some of the course materials (Real world Penetration Testing) and, even though they were in Arabic language, the OS, presentations, and configuration files were all in English, so it wasn’t hard to follow along at all. He attacks vulnerabilities very creatively and his presentation is very clear. He even uses WEAKERTHAN 3.6 for the WPA(2) Phishing Attack, and WiFiCake-ng! :D The Ninja Security Teams Penetration testing to the Max course is completely in English and his their latest course release.
Ninja Security Syllabus
Information Intelligence Techniques
• Open Source Intelligence Gathering
• Stealth Auditing and Network Scanning
• Advanced Network Reconnaissance
• Enumerating Internal Network From Outside
Web Exploitation Techniques
• Advanced SQL Injection Exploitation (MYSQL + MS-SQL + ORACLE )
• Advanced Blind SQL Injection Exploitation (MYSQL + ORACLE )
• Exploiting File Uploads to Full System Access
• Exploiting Remote File Include to Full System Access
• Exploiting Local File Include to Full System Access
• Exploiting XSS Reflected to Full System Access
• Exploiting XSS Stored to Full System Access
• Exploiting Command Injection to Full System Access
• Exploiting CSRF to Full System Access
Attacking and Owning Techniques
• Owning FULLY PATCHED systems with ( un-guessable/un-crackable passwords and OS protections like ASLR and DEP )
• Owning Windows Domain Controller from Outside
• Owning Windows Domain Controller from Inside
• Owning MS-SQL-Oracle-MySQL Databases
• Attacking and Owning VOIP Systems
Privilege Escalation Techniques
• Privilege Escalation in Windows ( from Guest to System )
• Privilege Escalation in Linux ( from nobody to Root )
Tactical Post Exploitation Techniques
• Tactical Windows Post Exploitation
• Tactical Linux Post Exploitation
• Tactical Mac OS X Post Exploitation
Bypassing and Defeating Techniques
• Bypassing and Escaping Restricted Environments
• Bypassing Group Policy
• Evading Anti-Virus ( 100% clean )
• Defeating PHP security
• Defeating (XSS , Sql Injection , File Upload ) Protections
• Defeating Web Application Firewall (mod security)
• Bypassing Port Security and NAC solutions
• Prerequisites: Students should be familiar with Metasploit, and VMWARE.
• Pricing: 1,500 USD
• what is included : Course Guide , Videos , Tools and Vmware Images are provided.
I’d fully recommend it, [Real World Penetration Testing] even to those who do not speak Arabic, simply for the clear demonstrations, huge amount of hard work planted into the course materials, and for his support. And again, the latest course by the Ninja Security team is completely in English: Penetration testing to the Max. :)
Thank you Ninja Security Team!!
~Douglas.



[...] will see: http://ninja-sec.com/index.php/samurai-skills/ that the price has recently changed since my last post about this course! It’s now cheaper! AND you get a FREE subscription to hakin9 magazine, which isn’t [...]