Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 70 guests and 1 member online
EH-Net News Feeds
Latest Additions
 
Advertisement

You are here: Home arrow Forum
EH-Net
May 16, 2012, 04:42:41 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Advertise on EH-Net!! - Reasonable Rates, Highly Targeted Audience.
 
  Home Help Calendar Login Register  
  Show Posts
Pages: 1 2 [3] 4 5 ... 68
31  Resources / News from the Outside World / Demo of the ASP.NET Crypto Attack on: September 20, 2010, 10:02:15 PM
Quote
In this video, researchers Juliano Rizzo and Thai Duong demonstrate the technique they developed for stealing cryptographic keys for ASP.NET Web applications, enabling them to compromise virtually any app built on ASP.NET.

http://threatpost.com/en_us/blogs/demo-aspnet-padding-oracle-attack-091710?utm_source=Threatpost&utm_medium=Tabs&utm_campaign=Today%27s+Most+Popular
32  Ethical Hacking Discussions and Related Certifications / Cyber Warfare / Re: Xerxes Video - Th3J35t3r on: September 16, 2010, 10:59:03 AM
To me it seems that that there must be an element of a new attack there.  All of the old smurf, fraggle, etc attacks are fairly effective blocked by most modern firewalls.  Jester says that his attack is effective against 90% of the sites on the Internet.  It seems like the majority of the infrastructures would have patched their routers and firewalls to block simple stuff like the smurfs, fraggles, and PODs. 
33  Ethical Hacking Discussions and Related Certifications / General Certification / Re: CBT Nuggets Mobile App on: September 16, 2010, 10:26:49 AM
This is awesome!  For those with long commutes, this is a great opportunity. 
34  Columns / Editor-In-Chief / Re: Jack Koziol Interviews Donald C. Donzal on: September 13, 2010, 10:27:35 PM
Very nice read indeed, Don.
35  Ethical Hacking Discussions and Related Certifications / Hardware / Re: Hardware Firewall Purchase on: September 13, 2010, 09:28:24 PM
It's hard to recommend a particular firewall.  I think it comes down to a matter of preference and familiarity.  You would probably find Cisco products to be the most supported, but they aren't cheap.  I know a bunch of people using Watchguard products (they have recently gotten much better).  They are affordable and you should be able to find something your price range.

Like former33t said, there are also a bunch of Linux-based firewalls out there, some offering commercial support.  Endian is one such example.  They sell a hardware solution as well.
36  Resources / Career Central / Re: How to pass HR screenings: load up on certs or go back to school? on: September 13, 2010, 09:23:57 PM
I wanted to piggy back on what Sil said about job descriptions.  Quite often, they are indeed written by those who don't understand the position.  I also see quite a few instances of very targeted, but almost impossible list of qualifications obviously written by those you would be reporting to directly.   I have done this myself, not realizing it.   Quite often, you will see technical managers throw everything, including the kitchen sink, into the job description, hoping to land the perfect candidate.   However, most are willing to sacrifice at least some items from their wish list.   
37  Resources / News from the Outside World / Re: HP to buy Arcsight on: September 13, 2010, 09:13:55 PM
I am not a fan of this either. I am quite unhappy with HP support. I am dissatisfied to the point where I will do my best to stay away from their products.  I remember never having to be on hold for Compaq support, back in the day.  After the HP merger, support almost instantly went to crap.  

I actually think that McAfee does acquisitions correctly.  They tend to maintain some form of autonomy in the acquired companies.
38  Resources / News from the Outside World / Re: 2010 DC3 Digital Forensics Challenge on: September 13, 2010, 09:08:12 PM
This seems cool.  If I have time, I may try muck at this.  I've never done a pure forensics challenge before.  It's always interesting to see how others approach an investigation.
39  EH-Net / News Items and General Discussion About EH-Net / Re: [Article]-August 2010 Free Giveaway Winners - CareerAcademy.com on: September 05, 2010, 08:15:10 PM
Nice!  Congratulations!
40  EH-Net / Calendar Of Events / Re: BSidesDelaware 2010 on: September 03, 2010, 06:18:26 AM
Hmm, this is close to me.   Anyone else thinking about going to this one?
41  Ethical Hacking Discussions and Related Certifications / Web Applications / Re: MySQL HTTP Header injection help on: September 02, 2010, 08:45:18 AM
Well, I believe that mysql_query will essentially prevent you from running stacked queries.  So, adding a semicolon and another statement wouldn't work.  One thing is clear, you can insert anything you want into that table.   I think that you are back looking to see where that data is displayed.   You can then implement a CSRF / XSS vector.   The CSRF vector is especially nice since an admin would likely be reviewing the logs.
42  Ethical Hacking Discussions and Related Certifications / General Certification / Re: will pay to be taught how to hack wireless credit card networks(plz dont ban me) on: September 02, 2010, 08:30:21 AM
What SPAM lovelies should we sign him up for?  I am thinking some sort of Snuggie newsletter.
43  Ethical Hacking Discussions and Related Certifications / Web Applications / Re: MySQL HTTP Header injection help on: September 01, 2010, 06:08:59 PM
I would say that at least you can pollute the log file with a bunch of junk, and possibly some sensitive data.  Is the usrlog table being displayed elsewhere?  You can inject an XSS vector. 

Are you using PHP?  mysql_query?
44  Ethical Hacking Discussions and Related Certifications / Other / Re: Starting Hacker / Computer Group on: September 01, 2010, 05:34:26 PM
I considered going down this road before as well.  I then realized that there are a few local groups in my area, like others have pointed out.  The 2600 has a group in just about every major city.  (http://www.2600.com/meetings/mtg.html)  Unfortunately, I have yet to attend a meeting due to scheduling issues.
45  Ethical Hacking Discussions and Related Certifications / Security / Re: Advise wanted For next step on: September 01, 2010, 05:20:30 PM
OSCP is great.   I also think that some self-study will help you with web app security.  For example, you can look into Damn Vulnerable Web Application.  It has your typical web app vulnerabilities.  There are also sites like hackthissite.org.  that offer tutorials and missions for hacking web apps. 
Pages: 1 2 [3] 4 5 ... 68
Powered by MySQL Powered by PHP Powered by SMF 1.1.16 | SMF © 2011, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.072 seconds with 19 queries.
 

gk_static-ad_feb2012.jpg
Global Knowledge: Build Security Skills to Protect & Defend

els_130x200fixed2.gif
eLearnSecurity Student Course Now Live!
5% Off with Code
ELS-EH-5

SANS Deals 4 EH-Netters
$150 OFF Any SANS Course in Any Format!
Coupon Code: EHN_Connect Including SANS Security West 2012 & SANSFIRE 2012
Recent Forum Topics

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!

Vote For EH-Net

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2012 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.