B.Sc. (Computer Science) Ethical Hacking Syllabus - Mumbai University
This is the TY BSc Computer Science syllabus under NEP 2020, in force from the academic year 2026-27. The University still sets the earlier Choice Based papers alongside it — her Summer 2026 third-year timetables name that scheme — so check which scheme your exam form names before you revise.
Loading syllabus...
Syllabus for Ethical Hacking
Module I
- Foundations of Ethical Hacking and Cyber Terminology: Study core terminology including hacking types, hacker classes, hacktivism, ethical hacking phases, and legal boundaries. Prepare a structured lifecycle model of ethical hacking.
- Vulnerability Research and Disclosure Mechanisms: Understand vulnerability lifecycle, CVE identification, CVSS scoring, responsible disclosure, and bug bounty frameworks. Analyze a real vulnerability case study.
- Footprinting and Information Gathering Methodology: Explore passive and active reconnaissance techniques including OSINT, competitive intelligence, and search engine reconnaissance strategies.
- DNS Enumeration and Domain Intelligence: Study DNS structure, record types (A, MX, NS, TXT, CNAME), WHOIS lookup, and ARIN databases to understand infrastructure mapping.
- Social Engineering and Human Exploitation Techniques: Examine psychological manipulation attacks including phishing, pretexting, baiting, and impersonation. Analyze real-world social engineering cases.
- Network Scanning and Port Scanning Techniques: Understand TCP/IP behavior and scanning methodologies including SYN, FIN, NULL, XMAS, and ACK scans, along with firewall detection logic.
- Enumeration and Service Identification: Study enumeration techniques such as SNMP enumeration, NetBIOS scanning, and service fingerprinting to identify exposed system services.
- System Hacking and Privilege Escalation Concepts: Analyze password cracking methods, privilege escalation techniques, rootkits, and spyware technologies from a defensive perspective.
- Cryptography and Password Security Analysis: Differentiate between encryption and hashing mechanisms, password storage models, salting techniques, and cryptographic weaknesses.
- Network Sniffing and Man-in-the-Middle Attacks: Study packet sniffing techniques, ARP poisoning, MAC flooding, DNS spoofing, and countermeasures to secure network communication.
Module II
- Denial of Service and Botnet Architecture: Examine types of DoS/DDoS attacks including SYN flooding and Smurf attacks. Understand botnet structures and mitigation strategies.
- Session Hijacking and Token Security: Analyze session management vulnerabilities, cookie manipulation, sequence prediction, and prevention mechanisms like secure flags and HTTPS.
- Web Server Vulnerabilities and Hardening Techniques: Study common web server misconfigurations, directory traversal attacks, patch management practices, and hardening strategies.
- Web Application Threats and OWASP Vulnerabilities: Examine major web application vulnerabilities (OWASP Top 10), input validation flaws, and search engine exploitation techniques.
- SQL Injection – Attack Logic and Prevention: Understand SQL injection mechanisms, query manipulation techniques, database vulnerabilities, and secure coding practices.
- Buffer Overflow and Memory Exploitation Concepts: Study stack-based buffer overflow, memory layout, return address overwriting, and secure programming techniques.
- Wireless Network Security and Authentication Mechanisms: Compare WEP, WPA, WPA2, WPA3 protocols, wireless sniffing risks, rogue access points, and wireless security best practices.
- Malware, Keyloggers, and Spyware Analysis: Examine the architecture of keyloggers and spyware, detection methods, behavioral analysis, and endpoint protection mechanisms.
- Exploit Frameworks and Ethical Use of Metasploit: Study exploit lifecycle, payload concepts, post-exploitation activities, and ethical/legal considerations of penetration testing tools.
- Penetration Testing Methodologies and Reporting: Understand PTES and OWASP methodologies, penetration testing phases, risk assessment models, and professional report preparation standards.
Text Books
- 1 CEH official Certfied Ethical Hacking Review Guide, Wiley India Edition
- 1 Certified Ethical Hacker: Michael Gregg, Pearson Education
- 2 Certified Ethical Hacker: Matt Walker, TMH.
Reproduced from the University of Mumbai syllabus for B.Sc. (Computer Science) under NEP 2020, in force from the academic year 2026-27. Wording is as printed in that syllabus. Module numbering is as printed there too.