Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 58 guests and 2 members online
 
Advertisement

You are here: Home
EH-Net
May 22, 2013, 07:17:31 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
  Home Help Calendar Login Register  
  Show Posts
Pages: 1 ... 62 63 [64] 65 66 ... 71
946  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Powershell on: June 27, 2010, 05:53:43 PM
It's worth noting that powershell is included in all Windows versions going forward, as well as other MS server products such as Exchange, SQL Server, etc.

Powershell is really powerful, and if it's there, I don't see any reason not to use it.

Also, if you haven't seen it, check out this module: http://code.msdn.microsoft.com/bsonposh
947  Ethical Hacking Discussions and Related Certifications / Other / Re: How are you using twitter? on: June 27, 2010, 03:48:02 PM
Just for following infosec news. I really don't care what my friends are doing every second (if fact, I'd rather often not know).

I've amassed a pretty good selection of people to follow. I'm sure I'm missing some, and I know I need to weed out some that post mostly fluff, but it's a decent start: www.twitter.com/infosiege
948  Ethical Hacking Discussions and Related Certifications / Other / Re: CREA - GPEN or GREM on: June 26, 2010, 08:34:42 PM
Nah no way bro.. Come on you and PaulBoz have been mopping the floor with me while I've been lallygagging between CCIE on and CCIE off retardation. I hear they *may* rename some of the SANS testing centers to Dynamik Boz Testing Centers Wink

Maybe in terms of putting letters behind our names, but I don't think that is representative of overall technical knowledge. You had a detailed learning path for penetration testing written and published when I was just getting started out, so I'm going to have to respectfully disagree with you with there. I'm flattered you don't consider me a total noob though :p

To be honest with you, dynamik... There are a lot of cool people @ TExams and I admire the work and effort put into passing tests. Me... I'm pure technical and don't care for books Sad ADHD ...

I totally understand. Honestly, I just chase after certs because they force me to learn things that I may not normally go out of my way for. They're just a challenge and a way to verify that I've retained a small amount of knowledge in whatever subject. Plus, if I learn something, I might as well pad the resume whenever I can.

I feel the ADHD pain as well. I'm lucky if I can get through a paragraph or two without my mind wandering Sad

Two weeks ago, I was amped... CISM I SWORE I would take my time this time. With 4 hours I finished in like 1:05 and I seriously took my time Sad I even decided "No ... Know something not going to do this again... Let me re-check my answers..." 5 minutes later I got bored. I was actually anxious to go home and play with my Juniper SA Sad I suck at exams because I'm too confrontational and am always debating some of the answers since they make little "real world" sense.

Sad I need to play by the books and remember "the answer is what they want it to be" not what I know to be true.

Ah, ISACA exams, making (ISC)2 exams appear to be straight-forward. I took the CISA on the same day. I couldn't stand to look at that material anymore, no way was I staying around longer to check my answers. That's the only exam I've taken that I am legitimately concerned about. The CISSP wasn't easy, but I left cautiously optimistic. With this one, it was like, "What's the greatest risk? Being set on fire, or having an artery severed?" You could spend all day making arguments either way. I tear the questions apart on exams like those as well.

In the interim, I forgot about the SANS challenges... I need to spend 3k by November (company paid) so I want to do something worthwhile. GPEN I mentioned just to keep in tune with pentesting... To be honest though I've never even needed the cert on interviews, etc. its more or less 1) appeasing management, 2) boredumb 3) why not... eventually I do learn... 4) I like to annoy with 10+ acronyms on my business cards.

Like I said, I really don't see you getting a lot out of the GPEN. Any interest in web app or wireless pen testing? The web app one actually falls under their "programming" umbrella, and the guys at the office who have taken both thought the GWAPT was more intense. The wireless one (GAWN) looks insane; I believe that's the highest level course that they offer a certification for. Also, if you just want to learn and aren't too concerned about getting letters behind your name, don't forget that SANS offers a lot of courses that don't have corresponding certifications.

Here are a few that seemed fun:

709 - Developing Exploits for Penetration Testers and Security Researchers
567 - Power Packet Crafting with Scapy (short course)
558 - Network Forensics

A full list is here: http://www.sans.org/security-training/courses.php

Also, what about OffSec's OSCE?

Maybe I should slow down on the certs up the ante and go to either NYU, Polytechnic or something... RPI told me "we h8 you never apply here!" Cheesy Hows that for slackerness/education. So now I'm in need of more puzzles Sad Challenges... More technical exams! Hence me always studying for the CCIE. My avg on written floats at about the 94% range Sad The lab scares me... Besides the cost of the lab is pretty pricey to be failing... I could get by telling the powers that be in my company "So what I failed... I'm like 8 for 9 with one failed CISM that I don't care for" The cost of the CISM and others pale in comparison to failing the CCIE lab. Pimping "passed CCIE written" means nothing Wink and no, I won't go CCENT, CCNA, CCSP, CCIE Security, why bother if my core focus is CCIE(S). Might as well go hard!

1 1/2 Year Game plan (maybe) ... GPEN||GREM||CREA (will decide soon), JNxxx (because much of my work nowadays is on SSG, SRX, SA), CISA (to annoy), ISRM.

Yea, that sounds like that should keep you busy. I used to try to plan this stuff out far in advance, but I've found that I never stick to it. Like you, I'm kind of fickle about some of these things, and even if I have the perfect plan, something new and interesting always seem to come out of the blue, and my path totally changes. Now I just line up the next challenge and worry about what's next only after I'm done with that.
949  EH-Net / News Items and General Discussion About EH-Net / Re: Ethical Hacking Swag on: June 26, 2010, 03:30:28 PM
I like the ones that embody the spirit/purpose of EH, such as "Pwning for good" and "Have you tested your security today?"

Witty one-liners like "And God said, \"nc -L -p 7777 -e /bin/sh\" and there was root" (which was awesome) don't really convey an actual message. That may not be the goal though; that's just my two cents. It just seems like there are plenty of other stores, such as Think Geek and Jinx that already have a lot of things like that.

As far as the designs go, I think it would be more aesthetically pleasing to put the URL on the back (not sure if that's possible there). The current designs look a bit cluttered on the front. Alternate colors (white text instead of navy) would also be nice for the darker shirts.
950  Ethical Hacking Discussions and Related Certifications / Other / Re: CREA - GPEN or GREM on: June 26, 2010, 12:44:10 PM
From what I know about you, I think the GPEN course would be a waste for you. However, it's hot and looks good on a resume. You should do what I did and just challenge it. You don't get any course materials, but you do get two practice exams to gauge areas where you may need improvement. I did the exam in about an hour and ended up with a 91. I also skipped the lab exercises because the lag was unbearable, and those were about 1/3 of the questions I got "wrong." I'd say it falls in between the CEH and OSCP in terms of technical difficultly. I know your knowledge/skills crush mine, so you should be able to pass that exam in your sleep.

I don't have any personal experience with it, but there's a teaser of GREM material here: http://vimeo.com/9474345 I don't think there's any question that the courses are quality; it's just whether or not you already know the material.

951  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Test Labs on: May 27, 2010, 02:33:28 PM
I highly recommend getting a Technet subscription. I use that extensively.

After I perform a clean install, I typically take a snapshot. I may make one more after significant configuration changes (i.e. setting up a new domain, installing DNS, DHCP, etc.). That way I can always have a semi-usable network, but I still have a great deal of flexibility where I can test things quickly. I can always copy one of the clean installs, test whatever I need to, and then blow it away when I'm done with it.
952  Ethical Hacking Discussions and Related Certifications / Hardware / Re: VMware or VirtualBox? on: May 26, 2010, 08:19:10 AM
I use VMware Workstation 7. VMware Player or VirtualBox will certainly get you by if you don't want to shell out any money. Workstation just has a lot of additional features, such as the ability to simulate slow WAN links.
953  EH-Net / News Items and General Discussion About EH-Net / Re: Been hanging around for a few months... on: May 25, 2010, 10:52:28 PM
Which Dell server do you have? Sometimes you can get storage working if you disable RAID.
954  Ethical Hacking Discussions and Related Certifications / Wireless / Re: BackTrack VM on: May 25, 2010, 10:44:18 PM
I'm not sure what virtualization packages you're having problems with, but USB pass-through works very well in VMware Workstation 7.

Here's the new revision of that adapter that some of us have been purchasing (I haven't really had a chance to play with it yet): http://www.amazon.com/High-Gain-Long-Rang-Alfa-9dBi-Mount/dp/B0038Q4AIG/ref=wl_it_dp_o?ie=UTF8&coliid=I3LTWBRPXRYBBQ&colid=BQRJ4R1QKAS2

If you're just looking for network connectivity, the physical hardware won't matter for a VM. However, if you're trying to work specifically with wireless (i.e. injection), you're going to need to have the adapter appear as a wireless connection in the VM.
955  Resources / Tools / Re: KeePass Password Safe on: May 25, 2010, 04:33:13 PM
That's what I use; I like it a lot.

I've seen favorable things for Password Safe as well (but I've never used it myself): http://passwordsafe.sourceforge.net/
956  Ethical Hacking Discussions and Related Certifications / Cyber Warfare / Re: Degrees? on: May 25, 2010, 01:18:37 PM
Nope, I'm wrapping up a psychology degree at the University of Minnesota. I'm leaning towards an MSIS at Nova once I complete that.
957  Ethical Hacking Discussions and Related Certifications / OSWP - Offensive Security Wireless Professional / Re: WiFu - One Week To Get Materials? on: May 24, 2010, 08:28:08 AM
The PDF and videos will be watermarked with your personal information. In my experience it doesn't take them that long to prepare the materials for you, so it probably is a little bit of a buffer.
958  Resources / News from the Outside World / Re: Google now offers encrypted search on: May 23, 2010, 12:43:00 AM
I don't see how this is that useful. While the search query itself may be concealed, if the next activity is accessing a site with, "Hot @#$ #$@$#@ing #@$ @#$," in the title, it's going to be pretty obvious what you searched for...
959  Ethical Hacking Discussions and Related Certifications / OS / Re: I have been dealing with my hacker on my own, now I need some help. on: May 22, 2010, 08:59:40 AM
I just would never expect a hacker being so obssessed with maintaining access to an ordinary user. and this note exchanging? wow!

I wasn't giving you a hard time; I have a difficult time believing the story as well. Especially when it comes from a fiction writer Wink

Several things struck me as odd.

*Using a high percentage of your CPU doesn't cause your desk to shake.

*What processes does she have to kill every day?

*She studied Unix but can't reload OSX or simply disconnect the machine from the network/internet?

*How did he damage the installation disc?

*Losing the respect of kids over a computer problem seems pretty harsh. It sounds like they would have the savvy to backup files and reload the OS.

*How did the place of employment also get hacked? Is it the same OS? Using the same credentials password? Are the same applications from the internet being installed?

*Careers have been ruined and book deals have been lost? Yet she knows how to boot to a live CD. Why not just save the files on a USB stick at that point?

The whole thing is overly dramatic and doesn't provide very basic technical details (i.e. how were they communicating?). The fact that this occurred on OSX doesn't lend a lot of credibility to the story as well. That's obviously not "hack proof," but it significantly less likely to get owned than Windows. Were random applications from the internet being install?

This would take some serious dedication from the attacker, and most people with the time and abilities would go after financial gain, not harass some random woman on the internet.

I'm not saying this is absolutely fabricated, but it does seem really far-fetched. I just skimmed the other blog posts, but I didn't see any other mention of this, and the other entries have been pretty open (to say the least). I'm also skeptical of new members with "critical issues" that never bother to follow-up and work through the problem.

This seems like a great way to start a social engineering attack. The next post may be asking to help move millions of dollars before the hacker can compromise the account information Wink

Anyway, no offense is intended to the OP. If this is true, please provide more details, so we can get some idea of what's actually going on. You've gotten a lot of good advice for such a scenario. I'd add that you would want to perform a credit check as well; look for any suspicious activity or accounts.
960  Ethical Hacking Discussions and Related Certifications / OS / Re: I have been dealing with my hacker on my own, now I need some help. on: May 21, 2010, 05:12:36 PM
I seriously cannot believe that this is really a true story.

Why? Doesn't your entire desk shake when you use a high percentage of your CPU?

Google the OP a bit. There are some other pretty outrageous stories out there...
Pages: 1 ... 62 63 [64] 65 66 ... 71
Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.095 seconds with 22 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.