Course syllabus
Course-PM
DAT370 / DIT989 hacking and pentesting lp1 HT26 (7.5 hp)
Course is offered by the department of Computer Science And Engineering
Contact details
Communicate first hand with the Course Responsible, then with the Examiner.
- Examiner: Andrei Sabelfeld
- Course responsible: Francisco Blas Izquierdo Riera
Guest Lecturers (Incomplete list)
- Emilie Barse and Johanna Abrahamsson (both Security Consultants at Assured) September 4th at 10:00 on HA3
- We'll instead see a presentation at SEC-T on September 10th and 11th
- Ove Tjörnhed (Security Consultant at KITS) September 16th at 08:00 on HC4
- Jesper Larsson (Founder of 0x4A, member of Cure53 and co-founder of Säkerhetspodcasten) October 2nd at 10:00 on FB
- ??? (??? at FRA, name kept for security reasons) 16th of October at 10:00 on SB-H8
- (Rest of lecturers will be added as they are confirmed)
Course representatives
You are always welcome to contact the course responsible with any feedback or ideas about the course. But if you prefer, you can also do so through the course representatives for this year:
- MPDSC Daniel Göransson
- MPCSC Geetha Jeyapaul
- MPCSC Jesper Persson
- UTBYTE Andrzej Pultyn
- MPCSC Liam Kral
Course purpose
In this course you will learn through a simulated security engagement how to reason about cybersecurity, how attackers view systems, how to report security issues you find, and more importantly, how to think about the sustainability, legal and ethical consequences of your cybersecurity related activities.
The course will be complemented with various guest lectures, so you can also see how different actors in the cybersecurity world view and reason about system security.
This course is suitable for students wanting to deepen their knowledge and understanding of cybersecurity by learning how to identify vulnerabilities in computer systems and how to successfully report and fix them.
Preparing for the course
No preparation is required ahead of the introduction session. But if you feel your knowledge about using Linux are subpar or you want to recapitulate over them, you should try the Bandit wargame at OverTheWire.
During the course you will need a VM with kali linux or pentoo to perform the lab tasks. You may allso start preparing it already to save yourself time later.
Finally, if it has been a long time since you took Computer Security, the course on ethics or any of the other cybersecurity courses you may allso spend a few hours going through the lecture slides and notes to recap.
Schedule
The updated schedule is available on Time Edit. Check in there to see in which room the activity will be held as it varies from one week to another.
Introduction session;
The introduction session will be on Wednesday the 2nd of Seotember from 08:00 to 09:45 on room FB.
Mandatory sessions;
The seminar on legal aspects of ethical hacking and pentesting will be on Wednesday 9th of September from 08:00 to 09:45 on KC.
The applied ethics workshop will be on Friday 18th of September from 9:00 to 11:45 on SB-H8.
The seminar on responsible disclosure will be on 30th of September from 08:00 to 09:45 on FB.
If any of these activities is missed it will be possible to do a related extra activity (with a much higher workload cost) to compensate for it. The activity will be propossed in agreement with the course responsible and examiner.
Lectures
All lectures are optional and will grant a small amount of points if the quizz at the end is completed sucessfully.
The lecture on continued education will be on 6th of October from 08:00 to 09:45 on HB1.
The lecture on a topic of choice by the students will be on 14th of October from 08:00 to 09:45 on FB.
The final lecture on career possibilities in cybersecurity will be on 23rd of October from 10:00 to 11:45 on FB.
Optional Sessions
IMPORTANT: Remember that you need enough points from these to pass the course!
We try to have sessions as regular as possible but for that, we had to sacrifice in room flexibility and have ended up distributed across the campus. Always check on Time Edit where the session is before going there.
Flag reports (participation required to get the points for each weeks' challenges) will be on Tuesdays from 10:00 to 11:45.
Guest lectures (grant extra points if answering the quizz at the end correctly) will be usually on Fridays from 10:00 to 11:45 (weeks 36, 37, 40 and 42) or Wednesdays from 08:00 to 09:45 (weeks 38, 39, 41, 43).
The social engineering workshop (grants extra points if a report is completed after participating) will be held on Friday 25th of September from 08:00 to 12:45 on TP-L13.
Lab passes:
Lab passes are provided on Thursdays from 13:15 to 17:00 as an alternative for students who cannot (or prefer not to) use their own computer. If you intend to use the lab any of these weeks please send me an e-mail before 08:00 am (local) on the Thursday the week before to ensure that I can allocate the resources to keep the lab open. Bookings done after this deadline will be done on a best effort basis.
Opening the lab occupies limited resources that could be used to provide you a better course so please think of the following:
- Using the lab computers will likely be more difficult than using your own computer due to the lack of proper persistence. Use your own computer if you can (all you need is to run a VM with kali linux or pentoo and configure wireguard).
- Book the lab only if you intend to attend, and unbook it as soon as you know you won't be able to attend.
- Penalties (loss of points) will be applied to those who abuse the lab resources or make bookings repeatedly without attending the sessions.
Needless to say, if the lab is open you are welcome to drop in and ask questions although Francisco may not be the one opening the lab (in which case the quality of the answers you get may be worse than if you asked Francisco over e-mail).
The lab will be open by Francisco during the first week so students can come ask for help configuring the tools on their own systems.
To book the lab use this google sheet (and mail Francisco if you are the first one booking or the last one unbooking a specific day).
Course literature
No course literature is given. Students are expected to be able to find handbooks and other materials for the tools they intend to use by themselves.
Course design
This course tries to the extent possible to emulate an actual pentesting engagement where the students will have their own environment (cyberrange) to explore and exploit. The main project of the course entails the student researching by themselves how to exploit different systems to obtain flags and then attend, turn in a short report with their finding before the deadline and then attending the corresponding flag report to discuss their findings with their colleagues. Credit is granted only if the students perform all of the tasks before the deadline.
To ensure students act responsibly and profesionally, the students are provided with a SoW and an NDA which they have to read and sign if they want to do the normal course project. During the duration of the course, breaking the NDA will be considered breaking academic honesty. After the course is over, while the university will not enforce the NDA terms, students are strongly discouraged from publishing their findings as that will reflect badly on their ability to maintain confidentiality if they intend to work on Cybersecurity.
At the end of the course students are expected to prepare a short (15 to 30 minutes, exact time still to be decided) debriefing meeting where they will discuss their findings with the "customer" who ordered the pentest. Before the debriefing meeting students must also produce a pentest report with all of their findings and with risk evaluations and recommendations.
To ensure the students will use their knowledge responsibly there are two mandatory lectures (on legal aspects and responsible disclosure). The students will complete a quizz at the end of the lecture to prove attendance.
There is also a workshop on ethics (for which students must prepare ahead of time). The students will then discuss the ethical implications of different approaches for the provided dilemma during the workshop.
If students miss one of the mandatory lectures or the workshop, an alternative task can be provided in agreement with the course responsible and examiner.
After the lectures and the workshop the students are expected to provide a written page with their reflections and how they would apply the knowledge from the lectures to the presented dilemma.
An optional workshop in social engineering is provided. Students participating on the workshop can turn in a short (1 page) report with risks and recommendations after the workshop to gain a small amount of credit.
Finally, additional lectures and guest lectures covering a variety of related topics will be taught. After the lecture students will get a quizz to earn extra points.
Digital resources
Canvas is the main communication tool for the MSc. version of the course. Communication should happen preferably as canvas messages targetting first the course responsible.
Canvas is also the place where reports and other assignments are handed in and where quizzes will be performed.
Additionally, a Cyberrange accesible using wireguard from a Chalmers IP is provided. The Cyberrange includes a ctfd instance where you are expected to report the flags you have found and where you can trade some of your points for hints.
Maximizing your learning
To maximize your learning you should try to give all the challenges by yourself and try to find appropriate tools and navigate their documentation to figure out correct usage by yourself. Try also to avoid using hints to the extent possible.
Also, attend and participate actively during the guest lectures, the lecturers will be able to provide you a lot of interesting views and knowledge that you may not be able to find elsewhere.
Finally, never hesitate to ask questions. There are no stupid questions and many others may also be wondering the same thing as you. If you need a way to communicate questions so that you feel safer, please contact the course responsible.
AI usage policy
As a profesional, you will always be responsible for anything you say and do even if you delegated that to an AI. Hence you are completely responsible for the use of AI you make during the course and for any actions and inaccuracies the AI you use makes and says on your name. Nevertheless, AI is actively used in the cybersecurity world as an aid and you are advised to use it as a way to speed up your work without harming your learning.
Remember that at the debriefing meeting you will have to defend your reports and you will have a very hard time doing so if you do not have a good understanding because you have let AI do all of your work.
To help you navigate this complex topic here are some suggestions on how to use AI without harming your learning.
- Ask for ideas or tools that can be helpful to approach any of the tasks.
- Summarize documentation and find specific answers in it. Specially if you use the AI as a way to find the actual references you are interested in from the tool documentation. (And yes, that includes also this Course PM).
- If stuck, provide feedback and ideas on why an approach does not work.
- After writing a report, provide feedback on how to improve a report clarity and readability.
- Help with design and styling of reports.
Changes made since the last occasion
This is the first edition of this course so no changes.
Learning objectives
Knowledge and understanding
- Localize independently adequate resources to further develop their own knowledge into ethical hacking, penetration testing, and offensive security.
- Explain based on current practices the importance of risk, impact, and likelihood when communicating and modeling cybersecurity issues.
- Describe in detail the different stages of a penetration test and which tools and procedures can be useful on each of them.
- Present overall the laws, regulations, policies and ethical implications related to ethical hacking and cybersecurity.
- Distinguish and describe in outline the different principles and techniques used by cybercriminals to gain access to IT systems.
Skills and abilities
- Perform professionally security assessments in an ethical and legal way.
- Identify, find, and use adequately the appropriate tools for offensive security tasks.
- Report comprehensively the results of a security engagement, both in writing and orally, in an understandable way using a risk-based approach.
Judgement ability and approach
- Assess critically the ethical and societal implications of cybersecurity operations, including the implications from the perspective of the United Nations Sustainable Development Goals.
- Prioritize methodically vulnerability assessment tasks in time-constrained settings utilizing risk, impact and likelihood.
- Evaluate systematically vulnerability impact using industry standards.
- Recommend with clear support on current best practices, the most appropriate course of action to strengthen IT security in IT systems.
Syllabus
Syllabus at Chalmers and at Göteborgs Universitet.
Examination form
In order to pass the course the students have to complete all the obligatory parts and obtain enough points from the optional parts. The grade will then be defined by the amount of points obtained from the optional parts.
Mandatory parts
To get any passing grade, students must complete all of the mandatory parts described below.
The students must attend the ethics workshop and the lectures on legal aspects and responsible disclosure. They must also actively participate on the activities associated to these and turn in a one page report applying their own knowledge and reflections on the provided dilemma.
Students performing the standard course project must sign and accept the SoW and the NDA. They must capture all the flags (even if late and using the full hint) to prove they have learned how to perform the tasks. They must also turn in a final pentest report covering all of their finding and, after turning in their report, they must also present and defend their findings during a debriefing session. Students can have any written and presentation aids they need during the debriefing session but must show enough knowledge of the activities they performed to convince the TA thay they understand the tasks they performed, what the vulnerabilities entail for the system and what can be done about them. The use of AI or any kind or help by a third party during the debriefing session is strictly forbidden.
IMPORTANT: To pass students need to get at least 700 points from the optional parts.
Optional parts
To get points for capturing the flags on time, students must enter the obtained flags on CRL before 12:00 (Stockholm time) the day before the flag report session. They must also turn in a short report (at most one page) describing how they captured the flag. Finally they have to participate on the corresponding flag report session.
To get points from the social engineering workshop you are expected to participate actively during the workshop and turn in a short report including your reflections,
To get points from the optional lectures and the guest lectures you are expected to participate actively and pass the quizz that will be presented at the end.
Points (and deadlines) per task
All flags and descriptions must be turned in before midday (12:00 Stockholm time) the day before the flag report.
- Alpha: 80 (week 3)
- Bravo: 100 (week 2)
- Charlie: 60 (week 3)
- Delta: 60 (week 2)
- Echo: 80 (week 3)
- Foxtrot: 80 (week 4)
- Golf: 80 (week 5)
- Hotel: 100 (week 4)
- India: 80 (week 5)
- Juliett: 80 (week 6)
- Kilo: 160 (week 6)
- Lima: 180 (week 7)
- Mike: 60 (week 8)
- Social Engineering Workshop: 100
- Optional and guest lectures: 30 each
Grade scale
- points < 700 → fail
- 700 <= points < 950 points → 3
- 950 <= points < 1150 → 4
- 1150 <= points → 5
- Max points is 1200 from challenges, 100 from the social engineering workshop and up to 330 from the optional and guest lectures.
Course summary:
| Date | Details | Due |
|---|---|---|