Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 36 guests and 2 members online
 
Free Business and Tech Magazines and eBooks

You are here: Home
EH-Net
May 25, 2013, 08:44:28 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
  Home Help Calendar Login Register  
  Show Posts
Pages: 1 2 [3] 4 5 ... 69
31  Ethical Hacking Discussions and Related Certifications / Forensics / Re: Starting off Pay on: October 15, 2010, 07:10:54 AM
Probably because they are no more than that, opinions.  It's all based on personal experience and prior knowledge.
32  Ethical Hacking Discussions and Related Certifications / Forensics / Re: Starting off Pay on: October 14, 2010, 02:47:35 PM
I think that certs in Computer Forensics are generally respected, especially in the consulting world.  The CCE is a particularly good cert to have in the private sector because some states are starting to require it.  Another one you may want to consider is EnCE.    In my company, we definitely value certs, but not anywhere as much as experience.   

I think that the certs will get your foot in the door, but you may want to be prepared doing entry level work for a couple of years.  You would likely be imaging computers, keeping evidence paperwork, logging cases, etc.  You can also consider government work.  Former FBI, Secret Service, Customs, etc agents are highly sought after in the forensics consulting circles.  With any of these, you would likely be a regular agent before you can transition into forensics.  Still, the feds pay well at first.  Most agencies require you to in the DC area initially for training.

As far as salaries are concerned, take a look at this link for government positions:

http://www.fbijobs.gov/113.asp

For the private sector, I think that 40k to $45k is reasonable for an entry level position.   Although, considering the current economy, it may be lower.
33  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Using Metasploit Expres on web application on: October 13, 2010, 04:48:23 PM
Welcome to the forums.   

I am not entirely sure what you are asking.   MSF Express is primarily a penetration testing tool with many publicly available exploits.  However, it's much more than that.  Do you have a specific question about MSF express?  You can review the getting started guide:

http://www.metasploit.com/documents/express/GettingStartedGuide.pdf
34  Ethical Hacking Discussions and Related Certifications / General Certification / Re: Countdown to the RWSP exam on: October 13, 2010, 04:44:23 PM
Sil, good luck to you on the exam.   From reading your post, it sounds like the exam is a win-win situation.  At the very least you will learn where you stand.  I it sounds like the exam will be real-world scenarios, which is always great.   
35  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Custom exploits // fuzzing on: October 12, 2010, 03:36:52 PM
I think this really depends on your engagement.  Arguably, all software has some sort of vulnerability, that given enough time you can exploit.  In a consulting engagement, you don't always have the time. 

I usually try to find the path of least resistance.   Like MaXe said, it may be easier to find a SQL injection vulnerability in a web application, than to fuzz and exploit some proprietary app.  That's not always the case.  Sometimes developers subscribe to the theory of security by obscurity.  Sometimes a simple network monitor session will reveal all kinds of goofy things.   More often, I find myself modifying a PoC, rather than starting completely from scratch.  Still, there may be times when starting from scratch is all you have.
36  Ethical Hacking Discussions and Related Certifications / Forensics / FTK Imager 3.0 Released on: October 07, 2010, 06:14:31 PM
Access Data has released FTK Imager 3.0.   It continues to be a free product.  Some of the new features are:

Quote
• A new feature allows users to mount an image as a drive or physical device. Mount
E01, S01, and RAW/dd images physically, or mount E01, S01, and RAW/dd partition
images, and AD1, L01 custom content images logically. (19064)
• FTK Imager 3.0 can now read and create Advanced Forensics Format (AFF) images.
(18054)
• FTK Imager 3.0 now provides support for VXFS, exFAT, and Ext4 file systems.
• Safely mount a forensic Image (AFF/DD/RAW/001/E01/S01) as a physical device
or logically as a drive letter. Once mounted, the read-only media is available to any 3rd
party Windows application and exposes the same file system artifacts as FTK Imager.
For example you can mount an HFS+ image, and it will show up as a volume on the
examiner's machine in the explorer view. (18593)

Download URL:
http://www.accessdata.com/downloads.html

Complete Release Notes:
http://www.accessdata.com/downloads/current_releases/imager/FTKImager_ReleaseNotes.pdf
37  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Reverse Attacking and tracking down bot-nets? on: October 06, 2010, 04:05:28 PM
It's not legal for you to hack one of the bots.  Remember, the bot is a victim here.  The best you can is report the attack to the authorities. 
38  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Reverse Attacking and tracking down bot-nets? on: October 06, 2010, 11:01:17 AM
Botnets get shutdown, it just takes time.  Like Sil said, the challenge is trying to figure out who is controlling the botnet.  Going after the poor dope whos computer was infected hardly makes any sense.  Another one will easily take his place. 

Recently, the Mariposa botnet was shut down.   It took a ridiculous amount of collaboration to shut it down:

http://www.net-security.org/secworld.php?id=8962
39  Resources / News from the Outside World / Blackberry Encryption Cracked on: October 06, 2010, 10:53:48 AM
Quote
Russian software developer ElcomSoft, which, with its Russian competitor AccentSoft, has developed effective password-cracking programs for most common desktop encryption formats, is at it again. Now, it's targeted the BlackBerry with a Phone Password Breaker that was previously limited to Apple mobile devices.

http://www.infoworld.com/t/mobile-device-management/you-can-no-longer-rely-encryption-protect-blackberry-436
40  Resources / News from the Outside World / Re: HDCP key is out... on: October 05, 2010, 04:00:21 PM
Quote
Intel threatened legal action Friday against anybody who uses its proprietary crypto key

Nice, so instead of fixing the issue, they threaten legal action. 
41  EH-Net / News Items and General Discussion About EH-Net / Re: [Article]-September 2010 Free Giveaway Winner - APT by Joe McCray on: October 05, 2010, 12:53:37 PM
Congratulations Jason!
42  Ethical Hacking Discussions and Related Certifications / Forensics / Re: Looking to get into the forensics field, few questions. on: September 26, 2010, 11:50:53 PM
I work in both forensics and hacking.  I can tell form experience that they definitely complement each.  However, like sil mentioned, they are entirely different animals.  While hacking knowledge provides a certain insight into a hacking case, we have plenty of good forensics investigators that are capable of catching a hacker without any hacking knowledge what-so-ever.  They are mostly ex-cops and ex-feds with serious investigative backgrounds.  That's the part that's key.  Don't forget that very few investigation deal with hackers. 

While you can teach the technical knowledge required for forensics work, in my experience, the investigative skills almost entirely come from experience.  A good investigator has solved enough cases where he or she can easily assume the role of the person their investigating, regardless of the circumstances.  Think of a detective in a serial killer investigation.  The detective obvious has been in the shoes of a killer, but he is able to think like one.

Those are just my two cents.
43  Ethical Hacking Discussions and Related Certifications / Hardware / Re: Hardware Firewall Purchase on: September 26, 2010, 11:41:54 PM
I had no idea Dell made firewalls.  From experience with their switches, the interface and language seems to be pretty similar to Cisco's.  I am guessing they license the code.  The boxes and hardware are significantly different.  I like Dell's support much better than Cisco's.  I am not a big fan of rebranded hardware, but I do like Dell's support. 
44  Ethical Hacking Discussions and Related Certifications / Hardware / Re: Bank Card backup and restore for the home user on: September 24, 2010, 05:42:30 AM
I am not sure how a "backup" will help with any legitimate uses.  You can hardly show up at Target with an all-white credit card, with "Wachovia" written in sharpie on it.  Although, I would love to see the face of a cashier when it actually works.
45  Ethical Hacking Discussions and Related Certifications / Other / Re: Free anonymous email forwarder on: September 24, 2010, 05:36:53 AM
Yahoo offers "disposable" email addresses.   They allow you to create a temporary address linked to your real address.  When you are done with the site, you just delete the address.  Yahoo will also flag those messages a different color. 
Pages: 1 2 [3] 4 5 ... 69
Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.096 seconds with 22 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.