Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 29 guests online
 
Free Business and Tech Magazines and eBooks

You are here: Home
EH-Net
May 18, 2013, 07:17:36 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
  Home Help Calendar Login Register  
  Show Posts
Pages: 1 ... 9 10 [11] 12 13 ... 15
151  Ethical Hacking Discussions and Related Certifications / General Certification / Re: Ready for Security+, got a bargain on: November 24, 2010, 08:09:12 AM
On the site cccure.org there are some test for CISSP. I found the one with a medium and less level that are the level of Security+.

If you only want to pass the exam do the crams, but if you want to understand... study  Smiley

I found that Sec+ covers half of the study for CISSP so this can be your next move.

Good Luck!
152  Resources / News from the Outside World / Re: Phrack #67 on: November 19, 2010, 12:26:24 PM
Very interesting articles.

Thanks!
153  Resources / Tools / Re: Canvas versus Metasploit on: November 17, 2010, 08:04:46 AM
Thank you for the videos!

We really appreciate that you take the time to share your knowledge/experience with us.


Also, if it is possible, it will be preferable to comment (voice instead of music) what you are doing.

Thanks again!
154  EH-Net / Calendar Of Events / Re: BSidesOttawa 2010 on: November 16, 2010, 07:54:12 AM
I had the pleasure to participate to this conference.
I only have good words about it. Everything was perfect: the place (a nice club), organisation, the speakers and the audience.
Giving the fact that we were inside a club, and only around 100 participants, the atmosphere was very intimate and the presentations had sometimes the form of public discutions.

In the first day the presentations covered general security subjects. The speakers had a lot of humour and they tried to get the audience involved.
In the second day the subjects were a little bit more technical, but the speakers tried to keep them general enough in order not to lose any of the participants (some of them were very tired after the 1st day party  Cool )

For me it was an excellent opportunity to meet interesting people (I have met H1t M0nk3y which I only knew from this forum). I also discovered that I am not paranoid when it comes to security, and that there are others that have the same problems as I do.

Thank you very much to the wonderful people that made this conference possible!
155  Ethical Hacking Discussions and Related Certifications / eCPPT - eLearnSecurity Certified Professional Penetration Tester / Re: eLearnSecurity opinions? on: November 15, 2010, 02:31:35 PM

To who would you recommend this course? Novice?

I would definitely recommend the web part for the novice students (as I was). The course is taking you from the beginning and it teaches you a lot. Each chapter contains theory and then the tools that help you automate the attacks.
The videos of the tools are very useful, too.
This course opened a new world for me, in an easy way. I will try to continue the exploration by myself, but it is always easier when you have a “master” that points you on the good direction.
156  Ethical Hacking Discussions and Related Certifications / eCPPT - eLearnSecurity Certified Professional Penetration Tester / Re: eLearnSecurity opinions? on: November 11, 2010, 01:28:51 PM
I was wondering if anyone who's received their eLearnSecurity's ePPT certificate/certification would mind sharing it with us.. Maybe block out the name if that would pose a problem...

I only received a pdf that it is a diploma. I don't know if I'll receive a printed one.

Alucian  How long did you wait for your exam results?

I waited a month until I had an answer. Initially they asked me to redo the report, because it didn't look so good (I made it in one day so..). Also, I had put the wrong names for some vulnerabilities, plus I went a little further than the scope of the test, so I had to remove a find.
These comments made me think that he really looked very carefull at my report.

So, I had a week to redo the formatting of the report, not to redo the test. If my refined report wasn't good enough in terms of findings I would had to redo the test, but it was good enough to receive the certification.
I really appreciated this, and I am sure that Armando is extremely busy.

Good luck and be patient.
157  Ethical Hacking Discussions and Related Certifications / eCPPT - eLearnSecurity Certified Professional Penetration Tester / Re: eLearnSecurity opinions? on: November 10, 2010, 08:48:10 AM
I just got the results today from the exam, so from now on I am an eCPPT!

I really liked the course. It is very well structured, and a very important advantage is that you can access it any time.

Now I am doing some checks for work and I use the course as a guide for the most important steps. I recommend following the course multiple times, because there is so much information so you can't digest it in a single shot.

I just wait for the new course they will produce (supposed to be an advanced one).

I found this course to take you from the novice to an intermediate level for the web application part, and this is what I wanted. The other two modules are at an intermediate level.
158  Resources / Tools / Re: Vulnerability scanning / pentesting tools on: November 10, 2010, 08:21:34 AM
THANK YOU VERY MUCH!

I am analyzing your list, and I will see what I will propose (maybe next week).

I think I wasn't specific enough with my list. For each category only the fist element is chosen; the others are just to do an analysis of the available products.

Anyway, my company will not invest so much money in vulnerability management. Also, it will be very difficult to convince them to buy Canvas or Core Impact. I need an excellent business case for this.

Lucian
159  Resources / Tools / Vulnerability scanning / pentesting tools on: November 09, 2010, 02:12:25 PM
Hello guys,

I need your help in choosing some security tools. We will improve our security program and I have to propose some vulnerability scanning / penetration testing tools that we will buy.
Our network has around 3000 active IPs, and we have almost 40 IPs in the DMZ.
 I have thought about some tools, and I should provide my managers some reasons why I did choose a particular one (for example in category Networks scanners I chose Nessus, and I can justify this on a Forrester research). Here are my categories and my picks:

Network scanning:
1.   Nessus (cheaper ~ 3600$ for 3 licenses, very good product, and we already have it)
2.   Nexpose (very good but will cost us 40.000$ /year)
3.   Qualys

Database vulnerability scanners
1.   DB Audit – good reviews; 4500$ for 10 servers
2.   Appdetective – more expensive
3.   Pangolin – amazing SQL injection tool. It costs 2000$ and maybe I will convince them to buy it together with DB Audit

Web application
1.   Burpsuite pro – 225$ plus Accunetix – 5000$
2.   Webinspect – 6000$
3.   Appscan – 15.000$

Penetration testing
1.   Core impact – 20.000$ plus Metasploit framework
2.   Metasploit express – 3000$
3.   Saint exploit – 20.000$ ?

Besides this we will use some open source tools, but we need also good commercial tools (management get excited about support  Cool )

If I miss some categories please tell me.
So, I would like hear your suggestions and opinions.
Thanks!
160  Ethical Hacking Discussions and Related Certifications / Other / Re: Convincing upper management on: November 05, 2010, 07:28:15 AM
I realy understand your feelings.
I my company we have a team, we have some tools (and we will buy more) but our direct manager (which is not technical at all, and he is comming from mainframe via cobit implementation) is stopping us (mostly me) to do our jobs.
I understand the reason why the guys from the operations don't want me to do Nessus scans using credentials, but the fact that my boss agrees to any stupid reason drives me crazy  Undecided. I even thought to move.

Anyway, I will be more patient and I will try to sell my ideas to the upper mgmt.
In another hand, a friend of mine works for a big company and he told me that they have no problems having operations implementing their demands. It seems that he's company had been hacked in the past and now security became extremely important.

@H1t M0nk3y  Be happy that you are not the only security guy in the company. If you'll get hacked you'll be blamed. Just stay cool and prepare yourself for better times (like next week-end when we'll have a beer in Ottawa  Cool )
161  Ethical Hacking Discussions and Related Certifications / Security / Re: Real World Security Professional (RWSP) Day Two on: October 27, 2010, 11:30:16 AM
I am impressed, really.
162  Features / Book Reviews / Beautiful Security - an amazing book on: October 21, 2010, 08:47:22 AM
Hello guys,
Lately I had the chance to read “Beautiful Security” and I found it an amazing book. Every chapter covers a different subject and it is written by a SME in his field.

Just to give you an idea:
Ch 7. The Evolution of PGP’s Web of Trust is written by the creator of the PGP – Phil Zimmermann
Ch 13. Beautiful Log Handling is written by Dr. Anton Chuvakin
CH 4. The economy of security breaches (one of my favourites) is written by Dr. Chenxi Wang from Forrester
and many more.

This is not an extremely technical book, and the authors explain why security is so beautiful, everyone speaking about a different field.

There some stories in the book, they are speaking about current problems and concepts, and there are many advices that everyone can benefit from. I took many notes from this book on how to improve some processes on my company. Also, there are some concepts  I would like to implement in my company in order to improve security.

I recommend this book to everyone that does security, and some of the chapters must be read by the non-security people in that specific department (for example the developers should read Ch10 Security by design, the managers ch 1,3,4 and so on).

Hope you’ll enjoy it as much as I did.
163  Ethical Hacking Discussions and Related Certifications / OSWP - Offensive Security Wireless Professional / Re: I passed the OSWP on: October 12, 2010, 08:54:48 AM
Congrats!

@H1t M0nk3y
It is outdated. For the current standards the couse is like a soldier which have only a revolver. If you send him to fight in an university campus (not MIT) it might be successful, but if you send him to war... no big chances.
164  Ethical Hacking Discussions and Related Certifications / Other / Re: illuminati on: October 12, 2010, 08:49:52 AM
 Shocked

Interesting Smiley
165  Resources / Tutorials / Re: Metasploit Megaprimer 300+ mins of video tute on: October 08, 2010, 07:27:35 AM
Thank you for the videos!

I downloaded some of them a couple of weeks ago and started to study.

Very much appreciate your effort!
Pages: 1 ... 9 10 [11] 12 13 ... 15
Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.095 seconds with 21 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.