Image
 
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 18 guests and 1 member online
EH-Net Donations

Enter Amount:
$

Google Ads
EH-Net News Feeds
Latest Additions
Book Recommendations





 
Advertisement

You are here: Home arrow Forum
Ethical Hacker Community Forums
January 08, 2009, 04:59:27 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: ChicagoCon 2009 - May 4 - 9. Boot Camps & an Ethical Hacking Conf. www.chicagocon.com
 
  Home Help Calendar Login Register  
  Show Posts
Pages: 1 2 3 [4] 5 6 ... 164
46  Ethical Hacking Discussions and Related Certifications / Malware / Microsoft Sees 'Huge Increase' in IE Attacks on: December 15, 2008, 03:23:00 PM
Good write-up by By Gregg Keizer, Computerworld
December 15, 2008

Quote

Researchers warn that IE attacks are increasingly being launched from legitimate Web sites; Microsoft says it is working on a patch

Microsoft warned Saturday of a "huge increase" in attacks exploiting a critical unpatched vulnerability in Internet Explorer (IE), and said some originated from hacked pornography sites.

Other researchers confirmed that attacks were increasingly coming from compromised Web sites.

Microsoft noted the upswing in attacks on the company's Malware Protection Center blog late Saturday. "The trend for now is going upwards," said researchers Ziv Mador and Tareq Saadecom on the blog. "We saw a huge increase in the number of reports today compared to yesterday."

Hackers have been exploiting a data binding bug in IE for more than a week, according to researchers who first noted in-the-wild attack code on Chinese servers. The vulnerability, which exists in all versions of the Microsoft browser, including IE5.01, IE6, IE7, and IE8 Beta 2, has so far been exploited only by attack code that targets IE7, the most widely used edition.

Mador and Saadecom said that attacks are increasingly being launched from legitimate Web sites. "Some legitimate Web sites were maliciously modified to include the exploits," the two said. A popular Taiwanese search engine and a Hong Kong-based pornography site were among the sites hacked, then set up to attack visitors running IE.

Researchers at Trend Micro also reported a big increase in hacked sites serving exploits aimed at the new IE bug. On Saturday, the security firm estimated that about 6,000 sites have been infected so far, noting that the count was "quickly increasing in number."

As in previous, large-scale attacks based on legitimate Web sites, this one involves hackers who execute SQL injection attacks to first compromise the site. In a SQL injection attack, hackers exploit vulnerabilities in Web applications that rely on a back-end database, which then gives them a way to add and run malicious code, usually rogue JavaScript, against any browser.

Microsoft acknowledged that attacks have become a significant problem. "Based on our stats, since the vulnerability has gone public, roughly 0.2 percent of users worldwide may have been exposed to Web sites ontaining exploits of this latest vulnerability," Mador and Saadecom said. "That percentage may seem low, however it still means that a significant number of users have been affected."

The move to legitimate, but hacked, sites is a change in tactics. As recently as Thursday, attacks were coming only from malicious sites, most of them in China. Even then, however, Microsoft had warned that hackers would probably expand the scope of their attacks by compromising valid sites.

In related news, Microsoft said it was working on a patch for IE, although it has still not said when it would issue the update. Some researchers expect the company to release a fix outside Microsoft's normal monthly schedule; the next security updates aren't due until Jan. 9, 2009. Microsoft also revised its security advisory for a third time Saturday, adding more information about the recommended actions users should take until a patch is available. The company has offered up a total of nine different workarounds for IE users, several of which require editing of the Windows registry, a chore most users assiduously avoid.


For original story:
http://www.infoworld.com/article/08/12/15/Microsoft_sees_huge_increase_in_IE_attacks_1.html

Don
47  Ethical Hacking Discussions and Related Certifications / Certification / Re: I need some opinions. on: December 14, 2008, 09:31:25 PM
Well done, and the sleep is deserved.

Was this the new Linux+ exam? If so, I'm glad to hear that they did a good job with it. As for remembering all the switches, such is life for an entry level cert. It's like learning all of your multiplication tables before you rely on a calculator.

Don
48  Resources / Tools / Re: Nmap Network Scanning Book Released! on: December 10, 2008, 01:59:02 PM
That's awesome.

Don
49  Ethical Hacking Discussions and Related Certifications / Programming / Re: not static? on: December 09, 2008, 11:38:47 AM
Try this article. Although it comes from the mindset of setting up MS Small Business Server, it still covers all the basics of setting up servers with dynamic IP addresses, costs, etc. Modify for your needs.

http://mitchgarvis.com/blogs/mitch/archive/2008/04/01/hosting-servers-without-a-static-ip-address.aspx

Hope it helps,
Don
50  Resources / Tools / liveusb-creator on: December 08, 2008, 05:20:38 PM
Although made for Fedora, I'm told it can work with other distros. I haven't tried it myself. Anyone out there play with this tool for helping you to create bootabler Linux USB keys?

Quote

liveusb-creator

The liveusb-creator is a cross-platform tool for easily installing live operating systems on to USB flash drives.

Features

- Completely non-destructive install. There is no need to deal with formatting or partitioning your USB key.
- Supports downloading various Fedora releases, including Fedora 9 and above!
- Automatically detects all of your removable devices
- Persistent storage creation. This lets you to allocate extra space on your USB stick, allowing you to save files and make modifications to your live operating system that will persist after you reboot. This essentially lets you carry your own personalized Fedora with you at all times. (Note: only works with Fedora 9 and above)
- SHA1 checksum verification of known releases, to ensure that you've downloaded the correct bits
- Works in Windows and Linux.


https://fedorahosted.org/liveusb-creator/

Don
51  Ethical Hacking Discussions and Related Certifications / CEH - Certified Ethical Hacker / Re: CEH v6 Outline on: December 08, 2008, 04:33:53 PM
I had a lot of the same feelings and asked EC-Council about them in an interview earlier this year. It may help:

Interview: EC-Council Offers Details and Insights on CEH v6

Don
52  Features / Dec 08 - Santa Claus Is Hacking to Town / [Article]-Santa Claus is Hacking to Town on: December 05, 2008, 02:38:36 AM
This is Ed's 5th Xmas-themed challenge overall, and third annual on EH-Net. Have fun!

Permanent link: [Article]-Santa Claus is Hacking to Town
Quote



Happy holidays, challenge fans!  In the spirit of the season, I’ve written a Santa Claus challenge for you, titled “Santa Claus is Hacking to Town.”  This one is adapted from the classic 1970 Rankin & Bass television production, which used stop-motion animation and nifty puppets to tell the story of Kris Kringle.  As a child, this was one of my favorite Christmas TV specials, and I’m thrilled to recast it as an ethical hacking challenge.  You don’t need to be familiar with the original TV show to participate in the challenge, of course.  Analyze the clues, devise your strategy, and carefully answer the questions to win a prize.  Answers are due by December 31, 2008.  We’ll choose three winners (best technical answer, most creative answer that is technically correct, and a random draw winner) to get a copy of my book, Counter Hack Reloaded, the ultimate stocking stuffer.  Even if you can’t answer all the questions, send in your best guess to qualify for that random draw slot.

Even though you don’t have to be familiar with the original TV show to answer the challenge questions, for those of you who haven’t seen the original Santa Claus is Coming to Town TV show or want to relive that childhood wonder of watching Kris Kringle grow up into Santa, you can watch its five parts on YouTube here:

"Santa Claus is Coming to Town" Part 1 - Part 2 - Part 3 - Part 4 - Part 5
And now… on with the challenge!


--Ed Skoudis
Co-Founder, InGuardians, SANS Fellow, EthicalHacker.net Challenge Master, Author of Counter Hack Reloaded, Santa Elf Trainee



Good luck,
Don
53  Columns / Heffner / [Article]-Plug-N-Play Network Hacking on: December 04, 2008, 01:47:37 AM
Although Craig has been continuing to submit articles to EH-Net, he was not allowed to officially have a 'column' due to his employer. That restriction has been lifted, so welcome back to the family.

Permanent link: [Article]-Plug-N-Play Network Hacking

Quote



Universal Plug-N-Play (UPnP) is a protocol that allows various network devices to auto-configure themselves. One of the most common uses of this protocol is to allow devices or programs to open up ports on your home router in order to communicate properly with the outside world (Xbox, for example, does this). The UPnP protocol is built on top of pre-existing protocols and specifications, most notably, UDP, SSDP, SOAP and XML.

This article will address some of the security issues related to UPNP, briefly describe the inner workings of the protocol, and show how to identify and analyze UPNP devices on a network using open source tools. While we will be specifically focusing on IGDs (Internet Gateway Devices, aka, routers), it is important to remember that there are many other devices and systems that support UPNP as well, and they may be vulnerable to similar attacks.


As always, please add your feedback here and make any suggestions for future articles.

Don
54  Ethical Hacking Discussions and Related Certifications / Certification / Re: CREA Certified Reverse Engineering Analyst on: December 03, 2008, 10:41:25 AM
Please continue posting individual thoughts in this thread, as I'm sure many want to be kept in the loop during your training. Let's take the article discussion of board.

Don
55  Ethical Hacking Discussions and Related Certifications / Certification / Re: CREA Certified Reverse Engineering Analyst on: December 03, 2008, 10:09:29 AM
Do you have a place to publish that review? Wink wink nod nod.

Don
56  EH-Net / Calendar Of Events / BOSS Conference 2009 on: December 01, 2008, 03:38:36 PM
BOSS (Besy of Open Source Security) Conference 2009
Feb 8 - 10, 2009
Las Vegas, NV


Welcome to the First Annual BOSS Conference & Sourcefire Users Summit!
The debate is over. Time and experience have proven open source security (OSS) technology to be both reliable and secure. The use of OSS products has become mainstream, adopted by the largest of enterprises and government agencies around the world.

Welcome to BOSS—the industry’s first IT security conference dedicated to promoting open source security technologies and the commercial products that embrace them. This conference brings together passionate OSS advocates and innovative Sourcefire customers and partners under the same roof to share ideas and experiences.

What better place to launch this exciting new conference than the historic Flamingo Las Vegas! Positioned at the center of the Las Vegas Strip, the Flamingo started it all. Today, the Flamingo features a 77,000 square foot casino, more than 3,600 hotel rooms, and modern conference amenities. And Las Vegas itself provides a fitting venue, reflecting the excitement, innovation and growth of the OSS industry.

We hope you will join us in Las Vegas in February 2009 for this compelling IT security event.

Flamingo Las Vegas
http://www.flamingolasvegas.com/

For more info:
http://www.bossconference.com/

Don
57  EH-Net / Calendar Of Events / CSI SX 2009 on: December 01, 2008, 03:32:01 PM
CSI SX 2009
May 17 - 21, 2009
Las Vegas, NV


This event is held in conjunction with Interop Las Vegas 2009.

CSI SX: Security Exchange offers a unique opportunity to meet and interact with security experts and peers in a collaborative and intimate setting. Discussions at SX look beyond the surface and give you real and proven solutions—strategy, policy and technical—that will work in your organization.

Mandalay Bay
http://www.mandalaybay.com/

For more info:
http://www.csisx.com/

Don
58  EH-Net / Calendar Of Events / Security OPUS Spring 2009 on: December 01, 2008, 03:27:13 PM
Security OPUS Spring 2009
March 16 - 20
San Francisco, CA


Community forum:
Monday March 16th

Conference:
Tuesday 17th & Wednesday March 18th

Training:
Thursday March 19th & Friday March 20th

The San Francisco Bay Area is home to some of the best and brightest in Information Security. Silicon Valley is one of the world's major technology centers.

This conference is crafted to give the attendee a high-value experience. The presentation format is single track, so you don't miss a single speaker! Exceptional catering and special evening events make it a snap to get the most out of networking with speakers, sponsors, and other attendees.

Venue being finalized

For more info:
http://www.securityopus.com/

Don
59  EH-Net / Calendar Of Events / CanSecWest 2009 on: December 01, 2008, 03:21:42 PM
CanSecWest 2009
March 16 - 20, 2009
Vancouver, British Columbia

Interact with the security community


CanSecWest, the world's most advanced conference focusing on applied digital security, is about bringing the industry luminaries together in a relaxed environment which promotes collaboration and social networking. The conference lasts for three days and features a single track of thought provoking presentations, each prepared by an experienced professional and talented educator who is at the cutting edge of his or her field. We give preference to new and innovative material, highlighting important, emergent technologies, techniques, or best industry practices.

The conference is single track, with one hour presentations over the duration beginning at 9:00 a.m. The registration fee includes the catered meals, and there will be a vendor display and lounge/eating area, where wireless internet access will be available (as well as in the speaking theater).

Sheraton Wall Centre
http://www.sheratonvancouver.com/

For more info:
http://cansecwest.com/

Don
60  EH-Net / Calendar Of Events / Carolinacon 2009 on: December 01, 2008, 03:17:31 PM
Carolinacon 2009
March 13 - 14, 2009
Chapel Hill, NC


Greetings, hackers, thinkers, makers, posers, spooks, InfoSec professionals, IT slackers, overdrive creatives, and persona non-corporeal!

Carolinacon is coming back yet again! Yes, for about the price of your average movie admission with popcorn and a smuggled beverage from home, YOU are invited to join us for yet another intimate and informative weekend of technology education and mayhem.

Holiday Inn in Chapel Hill
http://www.hichapelhill.com/

For more info:
http://www.carolinacon.org/

Don
Pages: 1 2 3 [4] 5 6 ... 164
Powered by MySQL Powered by PHP Powered by SMF 1.1.7 | SMF © 2006-2007, Simple Machines LLC
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.064 seconds with 21 queries.
 
Sponsors

cwnp_moto__120x90.gif

Polls
How many security events including conferences and training do you attend a year:
 
Support EH-Net


Support EH-Net by
Buying all of your
Amazon items using
the search bar above.

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!
Recent Forum Topics
Vote For EH-Net

progenic.com
Click here to Vote!

binarica.com
Binarica Logo

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2009 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.