Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 41 guests online
 
Advertisement

You are here: Home
EH-Net
May 24, 2013, 03:31:35 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
  Home Help Calendar Login Register  
  Show Posts
Pages: 1 ... 13 14 [15]
211  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: MAN DOWN on: October 17, 2009, 12:30:14 AM
De-ice is the basic one, but it will be better for you if you'll gonna start reading some basic hacking books. Given that you are at least CCNA, you can start with one of the CEH books, in order to better understand the whole process. Then you are good to go with the tools (or better do both in the same time).
 
Just my noob opinion.
212  Ethical Hacking Discussions and Related Certifications / Wireless / Re: Capture WEP and WPA association / authentication traffic on: October 11, 2009, 01:51:28 PM
WG511t works fine in backtrack. You can inject packets with it, I am using it and it is very good.

The better way to do it is to start airmon on the specific channel of your net

airmon-ng start wlan0 x (x is the channel)

In order to collect packets you should type:

airodump-ng -c x (x is the channel) --bssid AP_MAC -w name_capture_file mon0

-c and --bssid are optional, but like this you'll only capture the traffic for your ip.

This command will generate a file with the extension cap, wich you can open with wireshark. For more if type airodump-ng --help  Wink

About your old laptop, here is a list with the compatible laptops for backtrack 3:

http://backtrack.offensive-security.com/index.php/HCL:Laptops
213  Ethical Hacking Discussions and Related Certifications / General Certification / Re: Decent Sec+ Study Guide for SY0-201 (aka 2008) exam? on: October 09, 2009, 07:33:14 AM
I had both Sybex and Syngress books. If you are short on money there is a post somewhere with sites where you can find free books; even it is not so ethical it is good for the one that want to study.
The questions on the Syngress one are closer than the one from the exam.
Also, pm me for some tests I have.
214  Ethical Hacking Discussions and Related Certifications / General Certification / Re: Decent Sec+ Study Guide for SY0-201 (aka 2008) exam? on: September 25, 2009, 12:41:48 PM
I recommend you to go for Security+ Study Guide
http://www.amazon.com/Security-Study-Guide-Ido-Dubrawsky/dp/1597491535/ref=sr_1_1?ie=UTF8&s=books&qid=1253899893&sr=8-1
It is the most complet and the questions in the book are close to the ones from the actual exam. Also, try to find preplogic software with the questions for the exam. This will help you to pass the exam. I consider that this exam is a very good introduction to the security world.
When you'll finish the exam, you'll have a better undertandig about all the domains of the security, and you'll be able to choose one that suits better your character. I find this to be very important. I think that someone that has the spirit of a hacker (we are on the eh site) will not like to do a full time job as a firewall technician, just to give an example. But there are others that like to do this, that like to configure networks, and not to try to circumvent the security mechanisms implemented by others.
This is my personal opinion, others can give you other examples and opinions.
215  Ethical Hacking Discussions and Related Certifications / General Certification / Re: Heorot.net Intermediate Penetration Testing Course Vs Offensive security on: September 15, 2009, 12:56:37 AM
Hello guys,
If I really well understand, according to Jhaddix and Kev, it is better to do Heorot training in order to be able to do a good job as pentester (I mean to be able to work as a consultant and to do a good job, and not to be some security guy on a company's payroll). This training seems to give the business knowledge of the job, besides the technical skills.
I'd like to do both of their levels, but because I have to pay for them by myself it is a big problem.   Cry

Maybe I will wait to see what elearnsecurity will bring to the scene (a combination of both Heorot's levels wold be nice).

In the mean time I am doing OSWP and starting to read Fyodor's book.

Good luck to everybody.
216  Ethical Hacking Discussions and Related Certifications / General Certification / Re: Reply… on: July 22, 2009, 04:47:51 PM
I found this book to be the best one for the exam:
http://www.amazon.com/Security-Study-Guide-Ido-Dubrawsky/dp/1597491535/ref=sr_1_12?ie=UTF8&s=books&qid=1248297814&sr=8-12
217  Ethical Hacking Discussions and Related Certifications / General Certification / Re: CISSP Test on: July 19, 2009, 02:14:53 AM
The best videos for the CISSP are the Shon Harris ones. Use them along with her book, and you'll be prepared.
It is a difficile test to pass. Belive me, after finnishing the exam you'll pray God to pass it because you'll not want to study again for it. It is very broad, the questions are very smart, and you really have to understand the principles. There are some realtively easy questions but there are many of them very tricky.

Just to have an ideea you have here some questions from the internet:

1 (relatively easy one)
Acceptable risk is achieved when:
A. residual risk is minimized.
B. transferred risk is minimized.
C. control risk equals acceptable risk.
D. residual risk equals transferred risk.

2  Which of the following is the MOST effective in preventing attacks that exploit weaknesses in operating systems?
A. Patch management
B. Change management
C. Security baselines
D. Acquisition management

3 (you'll see many "BEST" questions like these ones)
Access to a sensitive intranet application by mobile users can BEST be accomplished through:
A. data encryption.
B. digital signatures.
C. strong passwords.
D. two-factor authentication.

4 (very probable one)
The BEST way to determine if an anomaly-based intrusion detection system (IDS) is properly installed is to:
A. simulate an attack and review IDS performance.
B. use a honeypot to check for unusual activity.
C. review the configuration of the IDS.
D. benchmark the IDS against a peer site.

Anyway, the opinins about this examn differs according to the level of expertise and the level of education of peers. Study well, use cccure's questions, level pro and you'll pass.

Good luck!
218  Ethical Hacking Discussions and Related Certifications / Physical Security / Re: Bomb Parts Smuggled into 10 Federal Buildings During Test on: July 19, 2009, 01:06:35 AM
Isn't this investigation a little bit exagerated??
219  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: New OffSec Course: Metasploit Unleashed – Mastering the Framework on: July 16, 2009, 11:44:15 PM
Sounds very interesting.
I think I will take it after OSWP and before OSCP.
220  Ethical Hacking Discussions and Related Certifications / Hardware / Re: Laptop for wireless pentest? on: June 22, 2009, 10:52:49 AM
I am using WRT54GL router (with tomato firmware) for 2 years now, and I ordered on ebay a WG511T wireless card.

I saw a video somewhere about a replay attack, I think, and the guy was running backtrack on vmware and as host xp. If I'll do this my system will be very slow.
221  Ethical Hacking Discussions and Related Certifications / Hardware / Laptop for wireless pentest? on: June 22, 2009, 10:20:06 AM
Hello guys,

I have an old thinkpad, centrino 1.4 GHz, 14 in, and with 512MB RAM. Do you think it is good enough to start study wireless pentest (I plan to do OSWP) or I should buy a better one?

If you suggest to buy a better one, do you suggest a bigger display?

Thanks
222  Ethical Hacking Discussions and Related Certifications / General Certification / Re: Best cert for practical experience in pen testing on: June 18, 2009, 11:33:04 PM
Thanks awesec for your advice.
In fact, I want to do OSWP during the summer and in September I'll do OSCP. I am sure I'll enjoy them, I just hope I'll have the time to do it (job, kids, moving...  Huh )
I'll inform you guys what I'll do about them.
Happy summer to you all!
223  Ethical Hacking Discussions and Related Certifications / General Certification / Re: Best cert for practical experience in pen testing on: April 26, 2009, 11:51:07 AM
Hello,
I have a question related to the same subject.
I want to take a certification to help me doing vulnerability assessment, not necessary penetration testing. I still can't decide between CEH and OSCP. I already am CISSP and CISM, but I want something more hands-on.
What do you suggest??
Thanks!
224  Ethical Hacking Discussions and Related Certifications / CEH - Certified Ethical Hacker / Re: Passed CEH on: March 21, 2009, 01:29:46 AM
Congratulation for the Certification.
Nice comment also.

Can I ask why did you choose CEH and not OSCP?

I am in a big dilemma. I want to do another certification, a technical one. I am about to graduate a Master in Infosec, I am Security+ and passed CISSP, but my experience is more managerial, BC and DR, and I want to go deeper in the technical field (I really like the adrenaline that comes with pentest). I really don't know which one to choose. I started to study for CEH, but on this forum I read a lot about OSCP and it seems very interesting.
What advise do you give me?
I am thinking about reading Michael Gregg's CEH prep guide and Build Your Own Security Lab A Field Guide for Network Testing. Also, I want to go and practice nmap, linux scripts, leo and then take OSCP and not CEH (the company I am working now don't want to pay for certifications so I'll have to choose only one).
The problem is that if this would take more than 2 month I will have to reschedule it for the late fall, because I'm in Canada now and I want to spend the summer with my kids, and the 6 month of winter with the study  Undecided
Do you think that I should go now for the CEH v5 and during the winter for the OSCP? Can CEH help me more to do vulnerability assessment and, maybe, for BIA?
Thank's again. This forum became my daily journal.
225  Ethical Hacking Discussions and Related Certifications / CEH - Certified Ethical Hacker / Re: What video series and books do you recommend for CEH? on: March 03, 2009, 08:47:08 PM
Hello guys,
I am studying for CEH, and I really want to do some practice questions, to have an idea of my level of preparation. So, where can I find Pass 4 Sure v2.73-4 test questions? I tried their website with no success.
Thank you!
Pages: 1 ... 13 14 [15]
Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.083 seconds with 21 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.