Image
 
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 19 guests and 2 members online
EH-Net Donations

Enter Amount:
$

Google Ads
EH-Net News Feeds
Latest Additions
Book Recommendations





 
Advertisement

You are here: Home arrow Forum
Ethical Hacker Community Forums
November 21, 2008, 10:08:36 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: ChicagoCon 2-Day Ethical Hacking Conference with MS Blue Hats Oct 31 - Nov 1. Tickets Only $100! www.chicagocon.com/content/view/103/51/
 
  Home Help Calendar Login Register  
  Show Posts
Pages: [1] 2
1  Resources / Tools / Re: NetWitness Investigator is now free! on: Yesterday at 05:13:12 PM
Netwitness is fantastic.  Thanks for the posting the link.
2  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Metasploit Question on: November 14, 2008, 06:33:55 PM
Thanks.  I was hoping I could do something with MetaSploit but maybe i'll wait for  that.

Cheers

Syn
3  Columns / Gates / Re: Post Exploitation on: November 14, 2008, 06:31:38 PM
Hi Chris,

In my opinion its all about the data, so effective methods of finding and extracting data from the network are pretty important.

Also, different ways of covering tracks is quite interesting, maybe overwriting tools by piping larger files into them using type (type bigfile.exe > evil.exe)

Also playing with the time on devices/hosts to make the forensics more interesting.  oh and log file manipulation, thats always fun.

Regards

Syn
4  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Metasploit Question on: November 13, 2008, 05:44:48 PM
Hi guys, I have a question regarding Metasploit. 

I'm happy with the process for running Metasploit against a remote host and with using the msfpayload function of Metasploit but...

Is it possible to create an executable using Metasploit that will exploit a vulnerabilty on the local machine that is running in the context of a restricted user to raise the priviledges of the user or execute any other payload that is specified such as create an Administrative Account or install a VNC server and connect back to another host?

Maybe i have missed something, but to run a payload that was created with msfpayload it seems to asume that the user/victim already has administrative rights on the target PC.
5  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: IP Address Block Enumeration on: November 13, 2008, 05:34:03 PM
The reverse DNS i was well aware ofbut the traceroute and ping method is pretty interesting.  I had thought that traceroute might be useful for certain types of mapping or helping to ID honeynets but your method certainly sounds useful.

Thanks. Smiley
6  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: IP Address Block Enumeration on: November 10, 2008, 10:52:23 AM
Thanks Jimbob.  Again, these are methods I already use.  Maybe I was looking for a tool that does the same as Senseposts qtrace.pl but it doesn't exist.

Thanks for the reply though.
7  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: IP Address Block Enumeration on: November 09, 2008, 05:29:02 PM
Thanks RoleReversal.  That was one of my methods (nmap xxx.xxx.xxx.xxx/24 -sP) and then look for typical boundary type devices such as routers or firewalls.  Obviously this method isn't that reliable and I was hoping that there was another more reliable option for footprinting the target.

Oh well, worth a try.

Cheers.

Syn
8  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: IP Address Block Enumeration on: November 07, 2008, 12:03:14 PM
I find that in general a whois might give me the isp assigned block.  but where i have found a host in a range by using something like Fierce, i want to find the size of that range assigned to the target network..
9  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / IP Address Block Enumeration on: November 06, 2008, 12:19:20 PM
I would like to what tools and methods other people may use for IP address block enumeration.  I have used qtrace.pl in the past but i'm not aware of any other tools / websites that may be of use.

I find that in books, articles and websites there is often very little emphasis on clearly identify the network boundaries of the target.

Does anyone have any suggestions?

Thanks

SynJunkie
10  Ethical Hacking Discussions and Related Certifications / Certification / Re: Security+ Study Guide on: June 07, 2008, 09:42:26 AM


Dengar13

I have a holiday coming up, so my plan is to study as much as possible and take it in the next 8 weeks.  I have a pretty good idea of the types of questions and I think after a week or 2 of good studying I'll be ready.  I've been taking some of the practice tests at cccure.org for the CISSP and i'm averaging about 90% on the domains I have studied so far so hopefully i'll do okay.  Following the Security+ i'll get my head back in the CISSP study guide.
11  Ethical Hacking Discussions and Related Certifications / Certification / Security+ Study Guide on: June 07, 2008, 04:29:08 AM
Hi

I'm currently studying for the CISSP but I would like to take the Security+ beforehand to make sure i'm on the right track.  Has anyone taken the Security+ recently and if so could you recommend a study guide?  There are many on Amazon but the reviews are quite poor.

Many thanks.

Syn
12  Resources / Links to cool sites. / Re: ITRadio.com.au - Australian IT Podcasts on: May 29, 2008, 07:26:39 AM
I'm a big fan of this podcast also. They have had some fantastic guests on the show. and the content always seems to be bang upto date.

Watch out pauldotcom!

For anyone interested, theres a new security podcast been started recently that shows potential called Securabit.  One of the hosts is Chris Gurling who some may recognise from Hak.5

And while i'm on the subject, a podcast i'm really hoping takes off is Armored Penguin.  This ones focuses on Linux Security and Episode 0 was very promising.  Links to both are below.

http://securabit.com/

http://www.armoredpenguin.net/
13  Ethical Hacking Discussions and Related Certifications / Forensics / Re: Keyloggers on: May 26, 2008, 12:10:36 PM
if w1mmy is interested in learning more about keyloggers and compiling his own, a couple of options are available on irongeeks site:

http://www.irongeek.com/i.php?page=security/keylogger

and on White Scorpions site:

http://www.white-scorpion.nl/programs/index.html

The source is available so these can be adapted for your own need or modified to work work with you favorite AV.

Syn
14  Ethical Hacking Discussions and Related Certifications / Other / Re: Vista - Firewall & Anti-Virus? on: May 19, 2008, 04:01:28 PM
Regarding the firewall question, I've been reading about a firewall from Comodo.  It looks okay if your that way inclined but I must admit I haven't used it myself yet.  My suggestion is based purely on the write up from the website and from what i heard on a podcast recently.


http://www.comodo.com

I used to be a big fan of the Sygate firewall but it got brought up by Norton I think and was no longer developed.  Shame, it was quite good. Probably wouldn't work on Vista ...bastards..thank god for linux.  Sorry, i'm rambling now.





 
15  Ethical Hacking Discussions and Related Certifications / Other / Re: Vista - Firewall & Anti-Virus? on: May 15, 2008, 02:33:01 PM
I agree, the built in FW does work well.

I'm a big fan of Avast for AV but I have heard that AVG has recently upgraded it's free version so that may be worth a look.

What do anyone use for anti-spyware? I like spybot S&D but I havent tried many others.  I like to think that patching, careful browsing, Firefox and NoScript help alot.

Oh, and using a well patched linux system for the majority of web activity is nice too.
Pages: [1] 2
Powered by MySQL Powered by PHP Powered by SMF 1.1.7 | SMF © 2006-2008, Simple Machines LLC
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.055 seconds with 21 queries.
 
Sponsors

cwnp_moto__120x90.gif

Polls
During the most recent election, I:
 
Support EH-Net


Support EH-Net by
Buying all of your
Amazon items using
the search bar above.

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!
Recent Forum Topics
Vote For EH-Net

progenic.com
Click here to Vote!

Sadikhov.com
Top IT Cert Sites

binarica.com
Binarica Logo

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2008 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.