|
EH-Net
|
|
May 22, 2013, 07:23:30 PM
|
Show Posts
|
|
Pages: 1 2 3 [4] 5 6 ... 71
|
|
49
|
Ethical Hacking Discussions and Related Certifications / Wireless / Re: JetPack SSID and password
|
on: April 05, 2013, 06:25:23 PM
|
|
Secure tunneling protocols are designed so an attacker can observe the handshake but not use that information to decrypt the encrypted data in transit.
It's possible to man-in-the-middle these connections, but the success depends on the user ignoring warnings and proceeding without caution. These attacks work when an attacker can intercept communications, not just observe them.
In such cases, there are actually two connections, one between you and the attacker, and one between the attacker and the intended destination. Both of these connections and valid and secure; it's just that the attacker controls these channels, so the data can be decrypted and collected, and then reencrypted and retransmitted to the intended recipient. There are tools that make this process fairly transparent and effortless.
However, most applications will warn you that something odd is going on. SSL/TLS will warn you that the certificate isn't valid (which is why it's important to use a valid certificate; otherwise you will become accustomed to ignoring this warning), SSH will tell you that the server's fingerprint has changed, and so on.
|
|
|
|
|
50
|
Ethical Hacking Discussions and Related Certifications / Wireless / Re: JetPack SSID and password
|
on: April 05, 2013, 01:01:11 PM
|
|
If you just want to encrypt web traffic on public networks, and this ties into your other thread about VPNS, look at setting up an SSH SOCKS proxy. You can even configure your browser to send DNS requests through the proxy (at least with Firefox), so anyone sniffing traffic won't even see what websites you're requesting. I hit my VPS, but you could just as easily set it up at home. With keys-based authentication, it's easy and secure.
|
|
|
|
|
52
|
Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Resources: Engagement Documents
|
on: April 03, 2013, 04:06:18 PM
|
Also http://www.counterhack.net/permission_memo.htmlHowever, if you're serious, I'd recommend having legal counsel, who is familiar with this type of service, put something together for you. You should also get the proper insurance. Doing this wrong can ruin your career. If anyone's interested, send me a PM, and I'll put you in touch with the guy I used. I think it was around $1000-1500 for the SoW template and contract. It's not cheap, but these are critical items to get right, and the cost of things going wrong will be substantially higher.
|
|
|
|
|
53
|
Ethical Hacking Discussions and Related Certifications / Wireless / Re: JetPack SSID and password
|
on: April 03, 2013, 02:42:59 PM
|
O_o I carry all of my tech in a backpack, or messenger bag. I never, NEVER, leave it un-attended. I only take out what I need. Usually the laptop. The jetpack, take it out start it up, confirm the laptop connects, and then put it back in the bag. If I need to move, for whatever reason, the laptop goes back in the bag and the bag goes with me. Even just to wee.
Yep. If I'm at a coffee shop and need to hit the restroom, I pack everything up and bring my bag with me. Everyone else probably thinks I need a porn break, but that's better than leaving my system unattended, even for a few minutes.
|
|
|
|
|
58
|
Resources / Tools / Re: CrackStation's Password Cracking Dictionary
|
on: March 24, 2013, 09:03:00 PM
|
How do you use the file with JTR? Everytime I try it I get: fopen: /root/Desktop/crackstation.txt.gz: Value too large for defined data type Are you passing JTR the compressed file? You need to extract it first.
|
|
|
|
|
59
|
Resources / Career Central / Re: I think the bar is dropping...
|
on: March 22, 2013, 05:42:26 PM
|
|
The problem with a lot of offensive positions is that you often have to be willing to relocate and/or travel. We've struggled filling the couple positions we've opened over the last year, and I know many other organizations are having the difficulty. MaXe literally moved halfway around the world for the gig he's at now. Working out the logistics may be more challenging than actually finding a position.
|
|
|
|
|
Loading...
|