Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 26 guests online
 
Free Business and Tech Magazines and eBooks

You are here: Home
EH-Net
May 26, 2013, 04:44:17 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
  Home Help Calendar Login Register  
  Show Posts
Pages: 1 2 [3] 4 5 ... 20
31  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Nmap null scans - help needed on: January 26, 2013, 08:08:15 PM
Initially you said they were all closed and that you were receiving RST packets not so?
32  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Nmap null scans - help needed on: January 26, 2013, 07:58:32 PM
Not all systems follow RFC 793 to the letter. A number of them send RST regardless of whether the port is open or not. The result is all ports are labeled as being closed. Some OS that do this are Windows, Cisco devices and IBM OS/400.

For further details check here:http://nmap.org/book/man-port-scanning-techniques.html
33  Resources / Tools / Re: BackTrack Reborn - Kali Linux on: January 23, 2013, 09:43:26 PM
Man, BT and PWB are hogging all the resources. This is why we can't have nice things. I'd rather have AWAE online than stock footage of stuff being smashed.
+1
34  Ethical Hacking Discussions and Related Certifications / Programming / Re: Any got a solution for this programming challenge ? on: January 22, 2013, 10:33:16 AM
Yes..we won't do your homewrok for you Grin Grin Grin Grin

.....just messing with you...
35  Ethical Hacking Discussions and Related Certifications / Web Applications / Re: Web App Fuzzer on: January 21, 2013, 09:54:31 AM
I have also tried w3af, but have not had much luck with it. Recently I have been playing with ZAP(OWASP).

Not entirely a fuzzer, but also been looking at Fiddler.
36  Ethical Hacking Discussions and Related Certifications / Web Applications / Re: Web App Fuzzer on: January 21, 2013, 09:05:22 AM
BurpSuite primarily.
37  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Limited shell on: January 16, 2013, 09:26:00 AM
Ok, here's another problem I have had for way too long now and I want to fix.

Here's the scenario: I have got a limited shell on a server in a lab through a web application vulnerability.

By "limited shell", I mean:
- The shell doesn't give me any output on the screen and I cannot output results of commands in a file
- I can change directory and list files (using a second ASP shell), but that's about it.
- I am able to ftp files/modify files into the web root directory (for example, I have uploaded nc.exe in C:\inetpub\wwwroot)

So for example:
C:\Windows\system32>cd ../..     (works)
C:\>cd inetpub\wwwroot    (works)
C:\inetpub\wwwroot> dir    (doesn't display anything)
C:\inetpub\wwwroot> dir > files.txt    (doesn't create a file)
C:\inetpub\wwwroot> nc.exe -lvp 4444    (doesn't work)
C:\inetpub\wwwroot> nc.exe -v 192.168.1.20 4444    (doesn't work either)

I have tried 5 or 6 different ASP shells, but couldn't get much more out of it.

So what approach should I take at this point? Write my own ASP shell code? Focus on trying to get a full shell (for example, using netcat somehow)? Maybe priv escalation (I don't think so at this point, but I could be wrong)

I really just need a direction so I can continue working on a solution...

Thanks



Are you able to run "net" commands for "net user" etc?
38  Ethical Hacking Discussions and Related Certifications / Security / Re: Training Conundrum on: January 14, 2013, 11:38:16 AM
So I am looking at what to pick for training this year, provided we have a budget for it.  I am torn between a few SANS courses, 2 of which do not have any GIAC certs associated but provide some much needed information.  Those would be SEC575 (mobile security) and 579 (Virtualization/Private Cloud).  575 would benefit my current role at the company.  579 peaks my interest much more because I love me some virtual machines and the architecture behind a properly implemented solution.  As for the cert paths I was looking at SEC501 (Adv Sec Essentials), mostly to formalize my training as a defender. The other option was FOR610 (malware analysis), main goal is to get more formal training on this topic which has been an ongoing self-study effort.

So do I go for the straight up informational training?  Or go for a cert path?  Any choice will help the company really.  I am the only technical/architecture security guy, so increasing my knowledge helps improve things as a whole.  Though if I was to go completely selfish, I would choose FOR610 for both the experience and the cert.  SEC579 would be a close 2nd.

Any thoughts?

Do what genuinely interests you. I agree with doing the CISSP as it seems to be a necessary evil. I have been putting it off for a while now.
39  Ethical Hacking Discussions and Related Certifications / CEH - Certified Ethical Hacker / Re: CEH vs GCIH? on: January 08, 2013, 07:35:48 PM
Okay, I recently took and past the GCIH exam and I'd like to take the CEH test in a few weeks. By studying for the SANS GCIH exam do you think I'm adequately prepared for the CEH exam?

Any areas that I might want to focus on? Also, do you recommend the CEH 7 or 8?

Thanks
Question is whether to recommend the CEH at all....
40  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Bypassing / Defeating Commercial Grade Firewalls on: January 07, 2013, 06:50:48 PM
Anyone able to reference me to some good video tutorials for defeating firewalls?


Check this out http://nmap.org/book/man-bypass-firewalls-ids.html
41  Resources / Career Central / Re: Career X-roads on: January 04, 2013, 09:48:50 AM
@H1tM0nk3y What was your strategy for passing the CISSP? Was it self study/bootcamp/Shon Harris etc? How long was your prep?
42  EH-Net / News Items and General Discussion About EH-Net / EH.Net Spam/Redirects on: January 03, 2013, 09:37:22 AM
Is anybody else having issues with redirects to Alternate-ad-url when you try to access sections of this site?

@Don: Have you considered taking on a few mods to assist with all the spam etc?
43  EH-Net / News Items and General Discussion About EH-Net / Re: What does EthicalHacker.net bring you? on: December 30, 2012, 02:37:31 PM
So two very talented guys not working full time in infosec?? WOW!!!

Just to add my .02, this site actually got me started and for that I am very thankful. I remember when I was thinking about doing the CEH, I actually called Don for advice.

I also agree with what others have said, here you can ask just about anything without getting flamed. You guys are VERY helpful and are always willing to give a listening ear.

I am currently doing the OSCE and I get more support HERE than anywhere else.

To the newbies you are at the right place.
44  Ethical Hacking Discussions and Related Certifications / GCIH - GIAC Certified Incident Handler / Re: Just Passed My GCIH!! on: December 28, 2012, 05:45:24 PM
Whatever path you choose, still do the CISSP. It is a necessary evil. So you might as well get it over and done with.

I will doing it sometime next year.
45  Ethical Hacking Discussions and Related Certifications / General Certification / Re: OSCE... check! on: December 22, 2012, 07:18:41 PM
How was the exam? Was the courseware enough(I think I know the answer but surprise me  Grin) .
Pages: 1 2 [3] 4 5 ... 20
Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.069 seconds with 21 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.