Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 24 guests and 1 member online
 
Advertisement

You are here: Home
EH-Net
May 25, 2013, 05:39:44 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
  Home Help Calendar Login Register  
  Show Posts
Pages: 1 ... 3 4 [5] 6 7 ... 69
61  Ethical Hacking Discussions and Related Certifications / Security / Re: Advise wanted For next step on: September 01, 2010, 05:20:30 PM
OSCP is great.   I also think that some self-study will help you with web app security.  For example, you can look into Damn Vulnerable Web Application.  It has your typical web app vulnerabilities.  There are also sites like hackthissite.org.  that offer tutorials and missions for hacking web apps. 
62  Ethical Hacking Discussions and Related Certifications / Wireless / Re: Does Mobile Security Deserve New Board? on: September 01, 2010, 05:16:09 PM
My vote is for a new board.   There are some topics that cover physical security, or hardware security (jail-braking an iPhone for example) that don't really have anything to do with Wireless.
63  Resources / News from the Outside World / Hackers accidentally give Microsoft their code on: August 27, 2010, 01:50:58 PM
Quote
When hackers crash their systems while developing viruses, the code is often sent directly to Microsoft, according to one of its senior security architects, Rocky Heckman.

http://www.zdnet.com.au/hackers-accidentally-give-microsoft-their-code-339305548.htm?omnRef=http%3A%2F%2Fslashdot.org%2F
64  Resources / Career Central / Re: Resume Assistance on: August 27, 2010, 01:41:27 PM
Sil, that's hilarious!
65  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Recommendation for an SQL fuzzer? on: August 16, 2010, 04:25:34 PM
That depends on your input entirely.   WebScarab works from a text file template of SQL commands and such.  SQLMap has quite a few payloads, including some MSF webshells.   
66  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Recommendation for an SQL fuzzer? on: August 16, 2010, 01:51:49 PM
WebScarab has a neat fuzzing capability, as most of proxy tools.   W3AF can also do this.  I use SQLMap primarily for automated SQL Inject testing.  I find it to be very flexible and somewhat accurate. 
67  Resources / News from the Outside World / Re: Google Briefly Punishes Oracle by Removal from Google Search on: August 14, 2010, 10:35:11 PM
I am not sure what removing Oracle from Google's search engines really accomplishes.  They aren't exactly unknown in the industry.   It certainly makes Google look stupid though.
68  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Non-Framework Exploits in Professional Tests? on: August 13, 2010, 01:31:17 PM

Shame on you!... Wink

mkdir /usr/work/exploits/{linux,bsd,solaris,windows}
mkdir /usr/work/exploits/bsd/{open,net,free}
mkdir /usr/worl/exploits/windows/{xp,vista,nt,9x,2003,2008}


You are absolutely correct.  I need more up to date archives.  I am going to try to make this a project.  I can't tell you how many times I have searched long and hard for some exploit code for a weird service.   Next time I needed to use the same exploit, I ended up searching again.   Smiley
69  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Procedure to find services behind open ports on: August 13, 2010, 01:28:11 PM
You can telnet or netcat to the port, send some commands and see what it comes back with.  You can also attempt to run nmap against it see what it finds.   You should be watching the communication in Wireshark as you are doing either one of these.
70  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Procedure to find services behind open ports on: August 13, 2010, 01:26:53 PM
netstat -anb on Windows.
71  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Non-Framework Exploits in Professional Tests? on: August 12, 2010, 01:37:28 PM
I hear you!  Budget and time constraints are probably one of the biggest challenges.  Three days isn't much time. 
72  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Non-Framework Exploits in Professional Tests? on: August 11, 2010, 09:01:43 PM
I use non-framework exploits.  I use any exploit I can reasonably verify won't do too much damage.  The way I look at it is the bad guys will use anything available to them. 

I usually have an archive or two on my laptop, but they are almost always too outdated.  I just forget to update them.  What I usually do is maintain an SSH account on a standard port and some odd port.  Part of pen testing is to see what egress filtering and content filtering is present on the network.  If I can't get to a site like exploit-db.com, I use my SSH account to proxy out.  This is actually another good test to see what outbound services are permitted. 

Just my thoughts.
73  Ethical Hacking Discussions and Related Certifications / Other / Re: DefCon: What I liked and didn't like on: August 09, 2010, 07:00:57 PM
Quote
The most memorable talks by far were "How I met your girlfriend" where the speaker talked about merging web hacking with the real world and "My life as a spyware developer."  While the latter was a little light on tech, the guy presented well and it was well put together.

This was the best presentation at Blackhat imho as well.
74  EH-Net / Calendar Of Events / Re: ShmooCon 2011 on: August 09, 2010, 06:59:23 PM
I am thinking about it.  I didn't see much info on their site about 2011, but I've always wanted to go.
75  Resources / Career Central / Re: Resume Assistance on: August 04, 2010, 10:35:53 AM
Something I was told a while back was to not concentrate on the job description.   Like Sil said, you have to make a business case for your employer to hire your.  You can do this by highlighting your accomplishments, rather than day to day tasks.   If you saved the company money but running a particular project, this is much more important to a recruiter.    I list all the interesting projects I have worked on, and make it a point to explain the impact of these, like Sil indicated. 
Pages: 1 ... 3 4 [5] 6 7 ... 69
Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.076 seconds with 22 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Free Business and Tech Magazines and eBooks

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.