|
EH-Net
|
|
May 16, 2012, 04:42:41 PM
|
Show Posts
|
|
Pages: 1 2 [3] 4 5 ... 68
|
|
32
|
Ethical Hacking Discussions and Related Certifications / Cyber Warfare / Re: Xerxes Video - Th3J35t3r
|
on: September 16, 2010, 10:59:03 AM
|
|
To me it seems that that there must be an element of a new attack there. All of the old smurf, fraggle, etc attacks are fairly effective blocked by most modern firewalls. Jester says that his attack is effective against 90% of the sites on the Internet. It seems like the majority of the infrastructures would have patched their routers and firewalls to block simple stuff like the smurfs, fraggles, and PODs.
|
|
|
|
|
35
|
Ethical Hacking Discussions and Related Certifications / Hardware / Re: Hardware Firewall Purchase
|
on: September 13, 2010, 09:28:24 PM
|
|
It's hard to recommend a particular firewall. I think it comes down to a matter of preference and familiarity. You would probably find Cisco products to be the most supported, but they aren't cheap. I know a bunch of people using Watchguard products (they have recently gotten much better). They are affordable and you should be able to find something your price range.
Like former33t said, there are also a bunch of Linux-based firewalls out there, some offering commercial support. Endian is one such example. They sell a hardware solution as well.
|
|
|
|
|
36
|
Resources / Career Central / Re: How to pass HR screenings: load up on certs or go back to school?
|
on: September 13, 2010, 09:23:57 PM
|
|
I wanted to piggy back on what Sil said about job descriptions. Quite often, they are indeed written by those who don't understand the position. I also see quite a few instances of very targeted, but almost impossible list of qualifications obviously written by those you would be reporting to directly. I have done this myself, not realizing it. Quite often, you will see technical managers throw everything, including the kitchen sink, into the job description, hoping to land the perfect candidate. However, most are willing to sacrifice at least some items from their wish list.
|
|
|
|
|
37
|
Resources / News from the Outside World / Re: HP to buy Arcsight
|
on: September 13, 2010, 09:13:55 PM
|
|
I am not a fan of this either. I am quite unhappy with HP support. I am dissatisfied to the point where I will do my best to stay away from their products. I remember never having to be on hold for Compaq support, back in the day. After the HP merger, support almost instantly went to crap.
I actually think that McAfee does acquisitions correctly. They tend to maintain some form of autonomy in the acquired companies.
|
|
|
|
|
41
|
Ethical Hacking Discussions and Related Certifications / Web Applications / Re: MySQL HTTP Header injection help
|
on: September 02, 2010, 08:45:18 AM
|
|
Well, I believe that mysql_query will essentially prevent you from running stacked queries. So, adding a semicolon and another statement wouldn't work. One thing is clear, you can insert anything you want into that table. I think that you are back looking to see where that data is displayed. You can then implement a CSRF / XSS vector. The CSRF vector is especially nice since an admin would likely be reviewing the logs.
|
|
|
|
|
Loading...
|