Image
 
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 19 guests and 1 member online
EH-Net Donations

Enter Amount:
$

Google Ads
EH-Net News Feeds
Latest Additions
Book Recommendations





 
Advertisement

You are here: Home arrow Forum
Ethical Hacker Community Forums
January 09, 2009, 06:58:59 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: ChicagoCon 2009 - May 4 - 9. Boot Camps & an Ethical Hacking Conf. www.chicagocon.com
 
  Home Help Calendar Login Register  
  Show Posts
Pages: [1] 2
1  Features / /root / Re: [Article]-Intercepted! Windows Hacking via DLL Redirection on: October 16, 2008, 12:11:01 PM
I'm a little confused.  Milw0rm lists this article as posted in November of 2006 - two years ago (http://www.milw0rm.com/author/858).  Is this just a cross post or did Craig Heffner actually produce this content for EHN?  Adding a dig for content posted on milw0rm, packetstorm and other sites seems a little odd.  I did find the PDF format on milw0rm much easier to read (and print/save Smiley.
2  Ethical Hacking Discussions and Related Certifications / Malware / Re: write my own exploits ? on: September 23, 2008, 08:17:59 AM
On the other hand...

If you want to learn about web application exploits knowning C, Perl, and all about memory addressing won't be of very much use (exploiting a C based CGI web application or Perl web application aside).  In order to exploit an application you have to understand the technologies on which it rests.  Web application technology usually relies on a scripting language (PHP, ASP, JSP, etc.), and a database (MS-SQL, Oracle, MySQL). 

That said, I'd like to cite a recent blog post from SecurityBuddah.com (http://securitybuddha.com/2008/09/10/are-you-a-builder-or-a-breaker/).  The point of the post is to ask why so many people in security focus on breaking things rather than building better software.  I think learning to actually program in a language will be a much more valuable endeavor if you really want to learn to write exploits.  Being able to create an application, securely, teaches you much more about the pitfalls of application security than simply learning to write exploits.  The most skilled penetration testers can pull apart a target by analyzing services and software based on their own knowledge of how to build such things, and common points of weakness.  Knowing how to build apps allows you to do actual code level audit of systems, which is more thorough and likely to catch subtle bugs that automated testing will miss.  Sure, it takes a lot longer to learn to build applications and systems than it does to simply break them, but the value is much greater.  Why not learn how to spot weaknesses and offer fixes instead of just how to break things?
3  Resources / Tools / Helix 3 Released on: September 23, 2008, 08:07:29 AM
Helix 3 has been released.  This forensics centric live CD is now Ubuntu based and includes updates to many of the host programs.  From the site:

"Helix has been modified very carefully to NOT touch the host computer in any way and it is forensically sound. Helix wil not auto mount swap space, or auto mount any attached devices. Helix also has a special live side for Incident Response and Forensics."

The new version of Helix can be found at http://www.e-fense.com/helix/
4  Resources / Tools / Re: Login Hacking? on: September 09, 2008, 09:58:38 AM
Brutus AE2 or THC Hydra fit the bill.
5  Ethical Hacking Discussions and Related Certifications / Forensics / Data Recovery on: September 08, 2008, 09:15:44 AM
Hello,

  I'm posting because I have very little experience in forensic recovery but at an event over the weekend I overheard someone tell a casual computer user that if they were going to sell their computer on eBay all they had to do was a "low level format" of the drive to destroy all their data.  The explanation was that if the user formatted the drive from the BIOS menu that the computer would overwrite all the sectors on the hard drive and that only people who could spend hundreds of dollars would be able to recover any data.  The computer in question was an old Windows XP machine with no special security software.  I'm wondering how effective such a formatting is, how easy it would be to recover data off a drive formatted in this way, and basically if this advice holds any water at all?  I'm inclined to think that if you aren't doing a DoD spec wipe you're asking for trouble, and my suggestion was to simply TrueCrypt the drive so data recovery would be impossible.  Does anyone have any thoughts/insights/suggestions about a situation like this?  Thanks in advance.
6  Resources / Tools / Re: OSSEC v1.6 Released on: September 08, 2008, 09:06:26 AM
I think this might be a dupe of  OSSEC v. 1.6 Wink

Version 1.6 might not be completely ready for prime time yet though.  There have been numerous problems reported with the release, including non-functional Windows active response.  The main developer, Daniel Cid,  recently wrote to the OSSEC mailing list:

Hi all,

I think I figured out what was going on. Depending on the argument (if
it had spaces),
the command to block would not be called properly. I am pretty sure it is fixed
on the following snapshot:

http://www.ossec.net/files/snapshots/ossec-win32-080904.exe

Can you try with this version? You don't need to update the server,
just the agent side.

*I will release a v1.6.1 soon with the fixes for some of the reported
bugs so far.


Thanks,

--
Daniel B. Cid
dcid ( at ) ossec.net
7  Ethical Hacking Discussions and Related Certifications / Other / Re: Chrome - Google Enters the Browser Wars on: September 03, 2008, 06:04:27 PM
Chrome sports quite a few neat security features that are intriguing.

The sandboxed tabs seems to be one of the best features in the new browser, which will limit data leak from one tab to another.  Whereas most browsers run each tab inside the parent process, with Chrome, each tab is it's own independent process.  This means that one tab can't reach into the memory space of another tab (which actually effectively firewalls the tabs from one another, especially nice for the "incognito" tabs).

I'm a little perplexed by the incognito mode frankly.  It seems like a nifty feature, sure, but not all that practical if you're really serious about privacy.  The browser still collects cookies and transmits personal information and doesn't provide any of the protection that anonymous browsing via TOR or the privacy protection of encryption.  Your session can still be sniffed and the only real advantage is none of the data utilized by the browser is written to disk.  This might be nice in that the browser doesn't "remember" the URL's to sites you've visited or cache images, but you can customize most browsers to mimic this functionality.
8  Resources / Tools / OSSEC Version 1.6 Released on: September 03, 2008, 08:12:12 AM
On September 1, OSSEC announced the release of the latest version of the OSSEC-HIDS tool (version 1.6).  This release includes many notable new features including:

  • Support for Microsoft Vista/Server 2008
  • Performance and stability enhancements on Windows
  • Active response on windows
  • Upgraded rootkit checking
  • Added support for more log formats

For a full list of upgrades and enhancements check out the change log.  OSSEC can be downloaded from http://www.ossec.net/main/downloads.

This is the first major release since Third Brigade acquired OSSEC and it looks to be a pretty major upgrade.  Third Brigade now provides commercial support for OSSEC, but the project remains free and open source software (FOSS).

OSSEC is an open source host based intrusion detection system.  It is completely cross platform and works on Unix, Linux, Windows and Mac OS.

--
http://www.MadIrish.net
9  Ethical Hacking Discussions and Related Certifications / Certification / The IACRB on: August 29, 2008, 11:53:48 AM
Jack Koziol was kind enough to leave a response to one of my recent blog postings about the IACRB (specifically concerning their relationship with the InfoSec Institute).  He includes a bunch of great information that I wasn't able to find anywhere else on teh interwebs.  Those interested in understanding the linkage between the two organizations are encouraged to read his responses.  Because the IACRB sponsors such great certification processes I found it odd that the organization was so opaque.  In addition to Jack's comments, the IACRB also seems to be updating its website with some new features and perhaps more information about the organization.  Having passed the CEPT myself, I firmly believe that the IACRB utilizes some of the best certification methods available to ensure the quality of those they certify.  I'm eager to see how the organization lives up to this precedent by offering a clearer picture of their composition, mission and certifications.
10  Ethical Hacking Discussions and Related Certifications / Social Engineering / Re: Advice from Microsoft on: August 29, 2008, 08:42:20 AM
What's even scarier is that tactic fails to prevent many common phishing tactics.  For instance, using a domain name that looks like the target in specific fonts (substituting 1's for lower case L's for instance) or misspelled domain names.  Not to mention that if a link spans multiple lines and it's sometimes tough for users to cut and paste the whole thing.  Microsoft needs to do their security reading (http://people.seas.harvard.edu/~rachna/papers/why_phishing_works.pdf) first before issuing statements like this Sad
11  Ethical Hacking Discussions and Related Certifications / Certification / Re: Is CEH really useful? on: August 25, 2008, 07:57:38 AM
Certification, in the end, stands as independent verification that you passed a test.  The test criteria and the respectability of the certifying body determine the value of the test to others.

Personally, when I interview someone I don't give a second look at the certifications they have.  I look for experience that proves the assertions the certifications make.  Proving you can apply knowledge that a certification tests is much more difficult than just getting a certification.

I have to applaud the CEPT because it has a practical portion that is unstructured, that forces you to apply your knowledge.  If all certifications had this sort of component fewer people would be certified but certification would be worth a lot more.

That said, in the end I think demonstrable knowledge and skill are much more important than a certification, but then again I'm not working in a big box corporation.  For large organizations, the HR departments will insist on some sort of rubber stamp they can use to weed out candidates.  So if that sort of job is your goal, certifications are great.

Certifications are also good if you're freelance or doing consulting.  Having certifications stand in good stead for references (which are probably better).  However, having lots of certifications will make your client feel more confident about you, and allows them to justify their investment in your services to their superiors.  Like the saying goes, nobody ever got fired for choosing the Gartner pick.

Outside of consulting and big corporations though, in that other murky realm inhabited by your peers, a certification is going to be worth the paper it's printed on.  Other security professionals, especially those who are familiar with certifications, view certifications with quite a bit of skepticism.  Proving to this audience that you know your stuff will require quite a bit more.  In this arena I would say a published article is worth a lot more than a certification.  Working on an open source project, producing white papers, publishing exploits and the like will go a lot farther to prove your credibility than producing a certification that shows you memorized the answers to a hundred multiple choice questions.

Of course, going to a hiring officer at a large company and saying "I published the remote root compromise of servers running foobar 1.2" will probably just get you a blank look.  On the flip side, if you do something like that, someone might just come looking for you with a job offer.  I never heard of anyone trolling the CISSP registrations looking to hire their next rock star though...
12  Resources / Tools / OWASP releases DirBuster 0.11.1 on: August 22, 2008, 10:37:33 AM
Two days ago OWASP (http://www.owasp.org) announced the release of a new version of their DirBuster tool.  DirBuster is a Java based web application scanner.  Basically you give it a host and it scans that host for directories on the host.  DirBuster can utilize a list of directories and files or it can brute force them.  DirBuster is nice because it can find files directories that might not be directly linked to.  This can be used to expose information on the host that you might not find otherwise.  DirBuster will also parse the HTML of files that it does discover, allowing it to follow links present in discoverable files as well.  You can find more information about DirBuster at the OWASP site at https://www.owasp.org/index.php/Category:OWASP_DirBuster_Project.
13  Ethical Hacking Discussions and Related Certifications / Other / Re: Simple Question on: August 19, 2008, 07:31:47 AM
There is a growing trend amongst infosec circles, especially with information assurance people, to concede that compromise in inevitable.  If you subscribe to this school of thought then backups are your best friend.  In an economic analysis, when you take compromise as a given, it makes the most sense to spend your time/energy investing in returning services to availability rather than exploit prevention.  To that end I'd say your backups are a very, very wise way to devote your time.  Because law enforcement agencies rarely take on cases of cyber crime I would suggest that any forensic analysis you do should be to discover the vulnerability utilized to compromise your systems so you can patch them (rather than worrying about chain of evidence to build a criminal case).  If you're going to pursue a criminal case law enforcement is going to insist on doing the forensic investigation anyways.  Just my $.02.
14  Ethical Hacking Discussions and Related Certifications / Web Applications / Re: Web App Hacking on: August 14, 2008, 02:54:15 PM
WebGoat is pretty solid, but for my money I'd recommend cruising the vulnerability announcements for well known web apps and installing vulnerable versions and exploiting them yourself.  Many of the most popular web systems have vulnerable versions at some point.  Installing them and figuring out how to exploit the vulnerability is, I think, a lot more worthwhile than poking at a training application.  Of course, you've got a lot more overhead installing and configuring applications that you may not intend to use other than as an exploitation experiment.  Just my $.02.  Getting familiar with tools like Paros and the Firefox Tamper Data plugin will go a long way towards getting you up to speed also.
15  Features / Opinions / Re: 1st 5 Books for newbie on: August 14, 2008, 09:47:10 AM
The Art of Software Security Assessment by Dowd, McDonald and Schuh
-Wonderful overall assessment of the modern state of security (this book is HUGE)

Network Security Assessment by Chris McNabb
-This O'Reilly book is one of the best hands on guides I've found.

Linux Hacker Tools by Ivan Sklyarov
-This book explains how to build tools yourself, and in the process explores a lot of the underpinnings of many such tools.

Hacking, the Art of Exploitation by Erickson
-This is a great book that goes through a lot of hands on exercises valuable to penn testers.

Security in Computing by Pfleeger and Pfleeger
-The obligatory textbook to cover everything not covered above Smiley

I have to disagree with some of the other recommendations.  I find the Hacking Exposed series has jumped the shark and tries to be too much for too many people.  You get a real scattershot with that book in the latest edition.  I found Art of Deception to be interesting, but it's all about social engineering.  I'm not sure that would be in my top 5 for penn testers (I think finding technical security holes is more valuable to penn test clients, but that's just my opinion).

I do agree that a programming book or twenty are useful.  At the very least you should memorize the O'Reilly Practical C Programming by Loudon.  If you don't know how to program in a language or use a technology you have to rely on tools to find vulnerabilities.  Building Secure Software by McGraw and Viega is an invaluable resource.

http://www.MadIrish.net

Pages: [1] 2
Powered by MySQL Powered by PHP Powered by SMF 1.1.7 | SMF © 2006-2007, Simple Machines LLC
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.069 seconds with 21 queries.
 
Sponsors

cwnp_moto__120x90.gif

Polls
How many security events including conferences and training do you attend a year:
 
Support EH-Net


Support EH-Net by
Buying all of your
Amazon items using
the search bar above.

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!
Recent Forum Topics
Vote For EH-Net

progenic.com
Click here to Vote!

binarica.com
Binarica Logo

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2009 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.