Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 39 guests and 1 member online
 
Advertisement

You are here: Home
EH-Net
May 25, 2013, 05:59:46 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
  Home Help Calendar Login Register  
  Show Posts
Pages: 1 2 3 [4] 5 6 ... 20
46  Ethical Hacking Discussions and Related Certifications / General Certification / Re: SANS GXPN Review on: December 14, 2012, 10:34:40 AM
So my next question is, when if EVER do you use your exploit-dev skills on a pentest? Most environments can be pwned without needing the heavy artillery not so?

Your response maybe that I said most, but how often do you get to go up against an environment that requires OSCE etc skillz?
47  Ethical Hacking Discussions and Related Certifications / General Certification / Re: SANS GXPN Review on: December 14, 2012, 08:30:37 AM
OSCE vs GXPN vs Corelan...go


 Smiley Smiley Smiley
48  Features / Skillz / Re: SANS Holiday Challenge 2012 on: December 13, 2012, 12:37:41 PM
Unsure if there was an 'easier' way, but I took the parts I could make out and improvised the possibilities on the rest, until I got that part.
And I have FOUR eyes Smiley
49  Features / Skillz / Re: SANS Holiday Challenge 2012 on: December 12, 2012, 07:52:36 PM
Pretty interesting.. finding it hard to read the numbers... if you know what i mean...
Yeah I cant make them out for nothing. Must be another easier way.
50  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: How to protect Domain Admin? on: November 27, 2012, 08:57:00 PM
I knew I read about this somewhere before....have a look at this
http://computer-forensics.sans.org/blog/2012/02/21/protecting-privileged-domain-account-safeguarding-password-hashes
51  Ethical Hacking Discussions and Related Certifications / General Certification / Re: SEC503: Intrusion Detection In-Depth-- A like on: November 23, 2012, 06:57:28 AM
What do you want to know?
52  Resources / Career Central / Re: Job Openings Australia (New and Experienced) on: November 19, 2012, 11:51:33 AM
Do you guys really think you could survive an interview with MaXe..I mean seriously  Grin Grin Grin
53  Ethical Hacking Discussions and Related Certifications / Other / Re: Thomas Wilhelm - STILL IGNORING HIS CUSTOMERS on: November 19, 2012, 11:49:32 AM
Quote
On a lighter note: My wife IS a lawyer
Lucky you!! But mine was a model...  Wink

Good luck with your Hacking Dojo! Like you said, Tom's book is very good, so are the De-Ice vulnerable VMs. His a good guy for sure, things will be fine for you very soon...

U sure about that  Grin Grin Grin Grin Grin
54  Ethical Hacking Discussions and Related Certifications / Other / Re: Thomas Wilhelm - STILL IGNORING HIS CUSTOMERS on: November 19, 2012, 12:59:27 AM
................All seems to be working out..
55  Ethical Hacking Discussions and Related Certifications / Web Applications / Re: Web App Pen Testing training on: November 13, 2012, 10:30:44 AM
Can anyone recommend some web application pen testing training that is not quite as expensive as the sans classes?

I would love to find some online live or recorded instructor lead classes.

Thanks,

Wayne
WAHH2 - http://www.amazon.com/Web-Application-Hackers-Handbook-Exploiting/dp/1118026470
56  Ethical Hacking Discussions and Related Certifications / Web Applications / Re: Mapping the Application on: November 06, 2012, 01:13:41 PM
For me, I am working with
1. BurpSuite for web application crawling and mapping.
2. DirBuster for directory or file name enumeration.
3. HTTrack for saving some web contents in order to extract interesting metadata.
4. nikto for checking web server configuration
5. w3af for quick web application scanning

These activities pave a way to the next step.
......have you had issues doing authenticated scans with w3af?
57  Ethical Hacking Discussions and Related Certifications / Web Applications / Re: Mapping the Application on: November 05, 2012, 09:01:12 PM
@MaXe what settings do you typically use for Dirbuster? Are you also using the raft wordlist

Wordlist: http://code.google.com/p/raft/downloads/detail?name=raft-wordlists-20110803.7z
58  Ethical Hacking Discussions and Related Certifications / General Certification / Re: My SANS GCIH experience on: October 26, 2012, 03:00:40 PM
Congratulations alucian! SANS courses are so addictive...

I can see from your signature  Smiley

Thanks!

Congrats alucian.......I think certs in general are addictive Smiley
59  Ethical Hacking Discussions and Related Certifications / OSCP - Offensive Security Certified Professional / Re: programming and OSCP on: October 23, 2012, 12:53:20 PM
The OSCP will require a lot more than just knowledge of python. At least that was my experience when I did it. Keep in mind that I didn't know python either.

As it relates to progressing through languages, I would focus on the fundamentals i.e programming paradigms OOP/Procedural, control structures and so on.

Once you have mastered that it comes down to syntax and knowing how each language implements a particular concept.
60  Ethical Hacking Discussions and Related Certifications / General Certification / Re: SANS GXPN Review on: October 23, 2012, 11:59:05 AM
Congratz...check pm

Couple questions:

Building a Metasploit Module:
The candidate will demonstrate a high-level understanding of how to create a Metasploit module


Q:How does this differ from the msf module in the OSCP?

Python and Scapy For Pen Testers   
The candidate will demonstrate an understanding of the ability to read and modify Python scripts and packet crafting using Scapy to enhance functionality as required during a penetration test

Q: How deep do you into using scapy?

Advanced Stack Smashing   The candidate will demonstrate an understanding of how to write advanced stack overflow exploits against canary-protected programs and ASLR
Q:Is this partial overwrite technique?

In terms of value for money which would you say would better suite a pentester the OSCE or GXPN?
Pages: 1 2 3 [4] 5 6 ... 20
Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.082 seconds with 21 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Free Business and Tech Magazines and eBooks

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.