Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 39 guests online
 
Advertisement

You are here: Home
EH-Net
May 23, 2013, 03:40:01 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
  Home Help Calendar Login Register  
  Show Posts
Pages: 1 ... 4 5 [6] 7 8
76  Ethical Hacking Discussions and Related Certifications / Incident Response / Re: blog hacked. so , what to do? on: August 09, 2012, 10:04:22 AM
Hope you guys are visiting this site from an unimportant machine. If I wanted to target a bunch of security professionals this is exactly how I'd do it.

 Grin

I too suffer from a healthy dose of paranoia caution. I used netcat to view it. Smiley
77  Ethical Hacking Discussions and Related Certifications / Incident Response / Re: blog hacked. so , what to do? on: August 09, 2012, 08:03:01 AM
Pretty sure you posted a the same question here before. You were advised to upgrade your WordPress installation and plugins.
78  Ethical Hacking Discussions and Related Certifications / Other / Re: Just Curious on: August 08, 2012, 03:02:58 PM
There's always someone better?
79  Resources / Tutorials / Re: Imma 1337 h4x02 : The super hard but most rewarding 1337 h4x02 guide! on: August 08, 2012, 03:00:31 PM
I'll give you some constructive criticism. Please don't take it the wrong way, but look at it as a way to improve your tutorial and future tutorials that you write. I think it's admirable that you want to write a guide to help newbies out, but I believe it could use a bit of work.

First, your tutorial is all over the place. Basically everything you wrote could be condensed to:

1. learn programming
2. read books
3. setup virtual lab
4. use BackBox

However you don't actually provide any detailed information about anything. If I'm looking for a guide on how to write Android apps, and I find someting on the Internet that says "Ultimate Guide To Android Programming", and tells me nothing other than to use Google and buy a book to read, then what's the point of the guide?

If I were a newbie I wouldn't understand what you've written, therefore it's failed as a guide to newbies. What's Backtrack? What's Backbox? Why is it different? One has Flash and one doesn't? So what? Can't I install Flash on BackTrack? I should learn Assembly? Why? What can I do with it? Why is CEH better? Better than what? OSCP? SANS?

Then you talk about hacking a wireless router, but you're not going to show how it's done? So you're pointing me to another guide that does what yours doesn't?

In essence, you've created a contents page telling me, if you want to learn how to do ______, Google it.

I'm afraid that doesn't help newbies at all.

I suggest having a look at some of the other guides online, and learning from their structure and content. A thorough guide takes time, certainly more than a day to work on.

Finally, and this is just my own personal opinion, I suggest changing the title to something less script-kiddie-ish.

Again, please don't take my comments as an attack on your work. Good articles, papers, and books go through multiple drafts and reviews before they get published.

Good luck!
80  Ethical Hacking Discussions and Related Certifications / Other / Re: Copyright Infringement on: August 07, 2012, 11:30:36 PM
As a note to myself to work as hard as I can I just got “Try Harder” tattooed on my wrist! Do you think Offensive Security will sue me for copyright infringement?

Pictures or it didn't happen! Wink
81  Resources / Tools / Re: backtrack vs back box on: August 07, 2012, 04:19:02 PM
If you are new to linux, try Ubuntu or Mepis first and get acquainted with basic commands and concepts. Then jump into Backtrack.

The latest revision is Backtrack 5r2, r3 is due very soon. You can get it here:

http://www.backtrack-linux.org/

along with lots of good free info
Im not new in ubuntu and i have backtrack too i can do whatever with it my point is backbox not backtrack i wanna know that if is it a good idea to work with it or not

No one can answer that for you, so try it yourself and decide. It's free after all, you've got nothing to lose.

A lot of the tools on either distribution can easily be ported into any other Linux distribution. If you're familiar with Backtrack, then you should be able to quickly notice any differences in Backbox and decide whether you like it or not. Personally, I prefer Backtrack to Backbox, simply because I'm used to it and I like where everything is stored.
82  Ethical Hacking Discussions and Related Certifications / Programming / Re: Super Awesome *FREE* Programming Courses!!! on: August 07, 2012, 02:48:27 PM
MIT OpenCourseWare is another free resource: http://ocw.mit.edu/index.htm
83  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: please shed some light on: August 07, 2012, 11:53:53 AM
True. it is completely new to . I went back and looked at my ccna and ccnp security and it was all packet filtering and port forwarding stuff. nothing on how to attack a system. haha.

That will come in handy. Some attacks require you to analyze network traffic (fuzzing, man-in-the-middle, etc), and having a solid understanding of networks will help you when it comes time to pivot through internal networks.
84  Ethical Hacking Discussions and Related Certifications / OSCP - Offensive Security Certified Professional / Re: Is python needed? Bash enough? on: August 07, 2012, 11:43:06 AM
Python is easy enough to pick up that you should learn it anyway. You probably won't need anything overly advanced, but you should be able to write some simple scripts that use sockets.
85  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: please shed some light on: August 07, 2012, 08:10:44 AM
I feel somewhat dumb in a way. i cant believe i struggle on levle one. haha. there is no way i could have figured it out by myself with out the movies. haha.

If you're new to this, you should expect to struggle for the first few attempts. As you progress you'll start to learn what to look for and things will become a little easier. There will always be some degree of trial and error, especially when you get to more challenging machines, but there's no substitute for experience and lots of practice.
86  Ethical Hacking Discussions and Related Certifications / OSCP - Offensive Security Certified Professional / Re: Finally took the plunge, started 08/05/12 on: August 06, 2012, 05:13:08 PM
This is also a pretty handy resource, using vulnserver: http://www.backtrack-linux.org/forums/showthread.php?t=203
87  Ethical Hacking Discussions and Related Certifications / Programming / Re: Gcc segmentation fault error help on: August 06, 2012, 02:33:40 AM
Seems broken. This one works better: http://www.exploit-db.com/exploits/15203/

Couple of points:

This is meant to be run on Windows, so compiling it with gcc and trying to run it on Linux will fail. So you have two options: compile it on Windows, or figure out how to compile it on Linux (hint: read up on mingw)

Lots of exploits are designed to be broken to prevent script kiddies from using it... or worse, the shellcode could be be designed to wipe out your system or open a backdoor. Learn to create your own shellcode (hint: read up on msfvenom and msfpayload).

For instance, that exploit you found could have been easily generated with msfvenom:

Code:
msfvenom --payload windows/adduser --format exe > adduser.exe

Also, in order for the exploit to work, the user running it needs to be part of the Administrators group (or SYSTEM). Otherwise you'll just get an access denied error. So it makes more sense to use it as shellcode for an exploit.

Finally, you seem relatively new to this, so unless the machine you're targeting is your own, I suggest treading carefully. Doing things blindly can cause more harm than good.

Good luck.
88  Ethical Hacking Discussions and Related Certifications / General Certification / Re: Advice Please on: August 03, 2012, 10:11:57 PM
I recommend learning some programming. At the least, shell scripting and python to start with. Python is quick to pick up. That should at least give you the ability to make sense of code written in C. Once you've mastered one language, you'll be able to learn others much quicker. Knowing programming will give you an advantage when it comes to hands on pentesting courses.

You'll need to write your own tools sometimes to speed things up, or modify exploit code, or even write your own.
89  Ethical Hacking Discussions and Related Certifications / General Certification / Re: from hacking on: August 03, 2012, 02:34:30 PM
If the problem is with WordPress, you should probably upgrade it, and all the plugins to the latest release. Make sure you have strong passwords as well. Depending on the what was vulnerable, your entire system could be compromised and you may need to format and reinstall to wipe out any backdoors. Some WordPress vulnerabilities allow attackers to execute remote code on your server which eventually leads to remote access.

90  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: please shed some light on: August 01, 2012, 02:53:20 PM
last minute question. i notice in the dvd lectures thomas always says to practice against de-ice1.101. i do not and can not find de-ice 1.101. i can find 1.110 but not 1.101.

Not sure about that... maybe he's referring to an older release of 1.110, or just recorded it wrong.
Pages: 1 ... 4 5 [6] 7 8
Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.061 seconds with 21 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.