Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 46 guests and 1 member online
 
Advertisement

You are here: Home
EH-Net
May 24, 2013, 08:18:31 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
  Home Help Calendar Login Register  
  Show Posts
Pages: 1 2 3 [4]
46  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Debian Weak Keys Vuln. on: March 12, 2009, 01:56:43 PM
I have a question about the feasibility of exploiting the openssl -- predictable random number generator found in Debian.

I know it's a very dangerous vulnerability, but if a system vulnerable with it, but no keys were generated on that system, and there is no way for anyone to sniff the traffic between this server and clients, brute force will not work because three bad logins and the IP is banned indefinitely(unless it was reset manually) how an attacker will be able to attack the system?

Thx
47  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Clietn exploit best practices on: March 12, 2009, 01:39:29 PM
Thank you Ketchup! I don't think I will go this route.

What I'm thinking of is something simple and legal. For example, set a web page on a dedicated server, can the user use some social engineering then send an email and wait and watch may take an hour or so, then remove the page.

But I'm not sure if this can be consider a good practice or not.
48  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Nmap version scanning results on: March 12, 2009, 01:00:41 PM
Yes, I use v 4.76
49  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Nmap version scanning results on: March 09, 2009, 07:52:21 PM
I don't know timmedin but with me its not.
50  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Clietn exploit best practices on: March 09, 2009, 07:50:18 PM
Thank you for the advise guys!

Would you recommend having a dedicated hosting with a hosting company, that one can secure then use for carrying out such tests, of course one needs to be careful that no one else will use it etc?

51  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Clietn exploit best practices on: March 08, 2009, 06:32:07 PM
Hello,

I would like to ask those who carried out pen tests where client-side exploits were allowed in the rules of engagement. Now you are going to place the exploit on a web server so the victim/client will access it and you will get for example a shell to their machines. What is the best location for this web server that will help you avoid any legal issues?

Thx

52  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Nmap version scanning results on: March 07, 2009, 09:22:58 PM
Thank you xXxKrisxXx, -A is equivalent to -O + -sV so I guess the method should be the same.
53  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Nmap version scanning results on: March 07, 2009, 02:16:21 PM
Hello everyone,

I did a nmap scan to a webserver using the following:

#nmap -A 10.10.1.1

The result was

PORT    STATE  SERVICE      VERSION
80/tcp  open   http?

Then I did another scan but this time specifying the port

#nmap -sV 10.10.1.1 -p 80

The result was

PORT   STATE SERVICE VERSION
80/tcp open  http    Microsoft IIS webserver 6.0

So I wonder why nmap was unable to find the version using -A while -sV showed correctly?

Did anyone came across something like that?

Thx
54  Ethical Hacking Discussions and Related Certifications / GPEN - GIAC Certified Penetration Tester / Re: SANS 542: Build Your Own Army of Darkness: XSS Frameworks for Zombies and Profit on: March 01, 2009, 11:08:43 AM
Thank you Seth for the link.

I was waiting for a while for an OnDemand version of the course, can we expected to be out in March/April 2009?
55  Ethical Hacking Discussions and Related Certifications / General Certification / Re: GIAC Exams on: February 03, 2009, 11:14:42 AM
Thanks a lot guys, very helpful tips indeed. I started making my own index, which I think is a very good idea in the preparation for the exam.

56  Ethical Hacking Discussions and Related Certifications / General Certification / Re: GIAC Exams on: February 01, 2009, 09:11:06 AM
Thank you so much geekyone, BillV, and vijay2 that helps.

BillV, vijay2, do you guys think if you passed the practice you will pass the actual test too?

vijay2, I'm preparing for taking the exam you passed short while ago, the GPEH. It will be my first GIAC exam.
57  Ethical Hacking Discussions and Related Certifications / General Certification / GIAC Exams on: February 01, 2009, 01:52:25 AM
I would like to ask those who took GIAC certificate exams, about the difference between the practice exams and the real exam? I know the practice exam will prepare you for the real exam and give you a chance to see the areas you need to work on, but can one expect to see some questions in the real exam already she/he saw in the practice exam? Is there a big difference between the two? If one passed both practice exams what are the chances she/he will pass the real exam?

Thank you,

-D
58  EH-Net / Special Events / Re: Q&A for Pen Testing Perfect Storm Part II: Client-Side Mutiny on: February 01, 2009, 01:47:17 AM
Thank you vijay2 for the links, much appreciate it.
59  EH-Net / Special Events / Re: Q&A for Pen Testing Perfect Storm Part II: Client-Side Mutiny on: January 24, 2009, 12:49:36 AM
Hello,

I although I registered to this webcast, I couldn't make it on time. Is the archive available?

Thx
Pages: 1 2 3 [4]
Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.09 seconds with 21 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.