Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 45 guests and 2 members online
 
Advertisement

You are here: Home
EH-Net
May 22, 2013, 06:25:12 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
  Home Help Calendar Login Register  
  Show Posts
Pages: 1 ... 22 23 [24] 25 26 ... 29
346  Resources / Tools / Re: Nmap 5.50 Released: Now with Gopher Protocol Support! on: January 29, 2011, 08:39:45 PM
Mmm... new scripts. YUM! Nice update. I really like the addition of Firewalk Smiley
347  Ethical Hacking Discussions and Related Certifications / CEH - Certified Ethical Hacker / Re: EC-Council and CEHv7 on: January 28, 2011, 10:44:35 PM
Still only 50 characters. (It did error out on me at 150ish characters) Pretty difficult to say anything in less than 50 characters. Kinda disappointing since I had some good stuff for them. Hope they fix it soon.
348  Ethical Hacking Discussions and Related Certifications / CEH - Certified Ethical Hacker / Re: EC-Council and CEHv7 on: January 27, 2011, 04:34:10 PM
Anyone have the link at the site? (If it's even up yet) Some creative Google searches did not turn up anything outside of some mentions of v7.
349  Ethical Hacking Discussions and Related Certifications / GPEN - GIAC Certified Penetration Tester / Re: Help me passing GPEN on: January 26, 2011, 09:04:41 AM
This list should give you what you need to determine what might be covered by the exam

http://www.giac.org/certbulletin/gpen.php

I found the real exam to be very close to the practice exams and as Ziggy mentioned I did slightly better on it as well.
350  Ethical Hacking Discussions and Related Certifications / CEH - Certified Ethical Hacker / Re: EC-Council and CEHv7 on: January 24, 2011, 09:46:15 AM
I've avoided CEH in the past based on poor feedback from colleagues, but I may have to look into it again after they implement these changes. It's always been on my radar because so many jobs ask for it, but I've always made excuses to postpone because I didn't feel like memorizing the names of every tool on the planet for the exam. Sounds good. Thanks for the info BillV!
351  EH-Net / News Items and General Discussion About EH-Net / Re: EH-Net IRC Channel? on: January 24, 2011, 06:01:03 AM
I would tend to agree with the Freenode suggestion. That's usually where I hang out.
352  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Hacking using tor? on: January 22, 2011, 10:23:54 PM
Tor is soooo slow! Even if there were not issues of confidentiality, I cannot even imagine trying to push any significant traffic through Tor. At least that was my experience a couple years ago when I used for browsing.
353  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: GCIA on: January 21, 2011, 08:26:42 PM
I'm doing GWAPT and SANS Metasploit course in April but I've been seriously considering WCNA after that. It's either that or RHCE. I'm still interested in OSCP but Im thinking I'll wait a bit on that as I've been focusing on the pentest stuff lately and need to round out a bit some of my core skills. I have the WCNA book and it's really good stuff.
354  Ethical Hacking Discussions and Related Certifications / General Certification / Re: Being a SANS Mentor on: January 21, 2011, 12:35:38 PM
I tried it once before about 3 years ago for GSEC in Ft Myers, FL and could not generate enough interest. You have to promote your course. SANS will work with you and send out official correspondence mentioning it and list it on their upcoming events pages but that was not enough. I'm probably going to try to do a GPEN mentor course later this year in Orlando and see if I have better luck. It's a great program but I'm really bad (lazy) at marketing.
355  Resources / Career Central / Re: Penetration Testing – Demand Continues To Outweigh Supply on: January 21, 2011, 12:32:47 PM
Check out http://nbise.org/ in the US. They are finishing a beta round of testing for Crest.
356  Ethical Hacking Discussions and Related Certifications / Web Applications / Re: Web app attacks and using web shells on: January 21, 2011, 08:18:14 AM
Thank you very much! Great read.  Grin
357  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: GCIA on: January 21, 2011, 06:08:15 AM
I always go the http://www.sans.org/security-training/volunteer.php route. $800 for conference attendance + cert + 4 months of Ondemand + some of the best social networking opportunities at the conference, What it does NOT include is bonus materials like SIFT kit, Wireless hardware etc which you will have to pay extra for. For instance I think the SEC508 Forensics course as a volunteer winds up being around $1100 which is still way cheaper. For most courses though this is a non-issue since only a few tracks utilize these extra materials.

For the record, when I did GCIA I did it via OnDemand and had never worked in packet analysis outside of troubleshooting network issues with Wireshark and some very basic work with tcpdump when pentesting.
358  Resources / News from the Outside World / Re: Trend Micro chairman says that Open-Source is more vulnerable on: January 20, 2011, 03:43:42 PM
It's funny, my wife is so pessimistic I have to switch gears when I get home and be the optimist. So very different from how I am at work.
359  Ethical Hacking Discussions and Related Certifications / OSCP - Offensive Security Certified Professional / Re: OSCP Walkthrough on: January 17, 2011, 12:37:03 PM
I probably could, I do have a DroidX with Proxoid setup with ADB for tethering on my linux machine. http://carnal0wnage.blogspot.com/2010/11/tethering-your-droid-to-linux-system.html

I've used that before for reverse connections but it's painful sometimes since my cellular coverage is a bit spotty and I've noticed that some connections tend to get filtered by Vz, but then sometimes they don't. It's almost like some Vz nodes are filtered but if I get routed through a different Vz node it isn't. I suppose if it's inside the VPN tunnel that probably won't be an issue. If I can't get the work cable modem approved I may go that route.

*post edited because I realized that my pondering was a really bad idea. Fun, but not smart*
360  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Security Assessment Inquiry on: January 16, 2011, 08:27:04 AM
We are open to hiring a 3rd party.  However, we are also interested in softwares too.  Just trying to get a feel as to which direction is best. 

A 3rd party test will only give you information current for that point in time that their test was done. It's very useful for initial remediation efforts but you will want some kind of ongoing scheduled scanning/testing solution in place. Whether a 3rd party MSSP provides this service or you do it internally is a business decision you have to make, but you should have some kind of ongoing vulnerability assessment process in place. I know you mentioned something along those lines so you are thinking in the right direction. The biggest challenge is vetting the capabilities of the 3rd party you use for your test. There are a lot of charlatans out there that will sell you a pen test when they are really just doing a vuln scan.

In my environment, I budget about 30k a year for external 3rd party pentests focused on my PCI environment, and spend about 25k (my salary hours focused on these activities + training costs + software expense) on in house conducted pen testing and then another 50k or so on software licensing and 5k or so on salary related expenses for ongoing vulnerability scanning but this scope includes my entire environment, not just a single app so YMMV. It really depends on your scope and complexity as to cost so we could give you a wide range of numbers that may be meaningless for you. You could also buy cheaper software than me, but I really like what I'm currently using and don't want (or plan) to give it up.

(Total cost for me = 110k)

Btw none of these numbers above include actual remediation. There's another group that handles that. I'm not even an admin on the systems I'm testing (by design - but my tools do have appropriate permissions for credentialled scanning) This is just assessment, and documentation of remediation plans and communication to management of the extended business risk from the discovered and verified vulnerabilities so they can make informed decisions and prioritize remediation tasks.

Hope that helps.

Pages: 1 ... 22 23 [24] 25 26 ... 29
Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.069 seconds with 21 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.