Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 43 guests online
 
Advertisement

You are here: Home
EH-Net
May 23, 2013, 03:59:15 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
  Home Help Calendar Login Register  
  Show Posts
Pages: 1 [2] 3 4 ... 10
16  Resources / News from the Outside World / Re: UK Cyber Security Challenge on: July 26, 2010, 10:32:18 AM
I signed up yesterday evening. 'Broke' the 'cipher' within an hour.

I'm thinking I may have registered before it was officially open, I may have to re-register.
17  Columns / Haddix / Re: [Article]-Review: eLearnSecurity’s Penetration Testing Pro (PTP) on: April 29, 2010, 10:17:35 AM
Congrats Jason. Great article!  Smiley
18  Ethical Hacking Discussions and Related Certifications / Web Applications / Re: Calculating risk POST assesment? on: March 12, 2010, 10:31:28 AM
The unreleased OSSTMM v3.0 has a section (2.8 Error Handling) which gives information on calculating Auditor error. The acronym they use is TERM (Test Error Risk Margin). This calculation is carried out by the Auditor himself which of course is a biased view however if this is stated, TERM is still useful.

This still leaves:

0days
Scope
Future changes to the tested environment
Possibly more?
19  Ethical Hacking Discussions and Related Certifications / Other / Re: Hakin9 Magazine (any subscribers here?) on: March 12, 2010, 09:13:00 AM
I'm a recent subscriber. My employer paid for my subscription so I'm not sure what price they paid.

You normal get a cd with some material on, the past 2 months they were wireless security I believe. The magazine content is mixed and varied. Some stuff more technical while other not so.

Overall I think it's worth having.
20  Ethical Hacking Discussions and Related Certifications / Web Applications / Calculating risk POST assesment? on: March 12, 2010, 07:24:19 AM
Hi,
This applies to both Network pen testing and web application assessments.

I was wondering if there had been any work done on calculating risk POST web app assessment or network pen testing?

There are a number of risks I can think of POST assessment:

0day vulnerabilities
Missed bugs due to time constraints
The skill/experience of the tester/s
Missed bugs due to tool/s not functioning as expected

Any help with this is much appreciated.

Thank you.
21  Ethical Hacking Discussions and Related Certifications / Web Applications / Re: w3af - cookies on: January 12, 2010, 02:36:44 PM
Sorry to bring up an old topic and thanks for the great script!

For some reason the cookies of a couple of sites I'm testing are not stored in the same place as other cookies. The only difference that I can see from the sites I'm testing and others is that the sites I'm testing are HTTPS. I tried logging into other HTTPS sites and they do seem to be saved into the same sqlite database.

I thought it may have been a problem with the script, however after openning the sqlite database and inspecting the data, the cookies were not there.

The location of my cookies.sqlite file:
/home/user/.mozilla/firefox/apj29vu2.default/cookies.sqlite

Does Firefox save HTTPS cookies in a different location? Is there something else going on here?

Thanks in advance.  Grin

P.S. Firefox 3.0.15 / BackTrack4 Final
22  Ethical Hacking Discussions and Related Certifications / Web Applications / Re: Open Source Web Application Poll on: December 07, 2009, 04:21:51 PM
To be honest I have never used Grendel, I have seen it installed in BackTrack but never had a play. I agree that w3af's authentication settings do need improving, from the top of my head I think w3af uses a cookie jar file from an old version of Firefox?!

Off to play with Grendel.  Smiley
23  Ethical Hacking Discussions and Related Certifications / Web Applications / Re: Open Source Web Application Poll on: December 07, 2009, 02:03:16 PM
@ChrisG - I was surprised too, judging from some of the 'additional comments' they were voting for the Metasploit Framework itself and not the web application modules which was what was intended.

@Jhaddix - Grendel and Paros completely slipped my mind. I added an 'other' option which some people did vote for other applications which weren't on the list.

I think in future I am going to leave the poll run for longer and try to spread the word a little more to get more submissions.
24  Ethical Hacking Discussions and Related Certifications / Web Applications / Re: Open Source Web Application Poll on: December 07, 2009, 07:12:42 AM
Thanks to everyone who submitted responses!  Smiley

Here are the results:
http://www.ethicalhack3r.co.uk/2009/12/07/open-source-web-application-scanner-poll-results/

Thanks again!
25  Ethical Hacking Discussions and Related Certifications / Web Applications / Open Source Web Application Poll on: December 03, 2009, 01:15:59 PM
Hello all,
I am trying to gather some info on which is the most used/favorite open source web application scanner out there. Would be grateful if you could spare 2secs to answer 3-4 questions.

http://spreadsheets.google.com/viewform?formkey=dFNpQmNfUWx4UEFicW0wQXlZTFQyV0E6MA

Thank you!
26  Resources / Career Central / Re: university course on: October 27, 2009, 12:36:23 PM
Hi Richard,
I am a second year Ethical Hacking for Computer Security student Northumbria Uni's CEIS. I guessing the course you will be taking is at Glasgow's Caledonian University?

I'm not sure of the ins and outs of your particular course however at Northumbria they teach us C/C++ programming, Networking (inc CCNA), ORACLE DBMS/SQL, forensics, ethical hacking, consultancy and more. If you completed your degree and wanted to take another path in IT rather than the security one, in my opinion you would have enough knowledge to go into programming, networking or another aspect of IT if you wished.

I would also like to say that I wouldn't expect to learn everthing there is to know about information security within your 4 year degree. A lot of what I have learnt has been learnt outside of university working on projects, experimenting, reading books, online resources, conferences and casual pentest work for different companies.

If you have any other questions let me know.
27  Features / Book Reviews / Re: [Article]-Book Review: Professional Penetration Testing on: September 26, 2009, 05:57:38 AM
Great review Andrew. Will have to add this one to my 'to buy' list.  Smiley
28  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Salaries/Earnings of Top Pen testers on: September 22, 2009, 04:35:47 PM
Heres a security jobs RSS page I put together to keep an eye on the latest jobs in the UK. You can have a look at the salaries they are offering:
http://www.ethicalhack3r.co.uk/wp-content/themes/Fresh-Wordpress/rssjobs.php

Also heres a salary checker from CWJobs:
http://www.cwjobs.co.uk/SalaryChecker/SalaryCheckerSearch.aspx
29  Ethical Hacking Discussions and Related Certifications / Wireless / Re: hacking wireless network at school...help! on: September 20, 2009, 12:09:55 PM
Depending what country your in, you could be breaking the law. Either way what you are trying to accomplish is UN-ethical. This website is for ETHICAL hackers.
30  EH-Net / News Items and General Discussion About EH-Net / Re: [Article]-August 2009 Free Giveaway Sponsor - IronKey on: September 20, 2009, 08:14:35 AM
Who won?
Pages: 1 [2] 3 4 ... 10
Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.075 seconds with 21 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.