Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 38 guests and 1 member online
 
Free Business and Tech Magazines and eBooks

You are here: Home
EH-Net
May 24, 2013, 04:27:06 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
  Home Help Calendar Login Register  
  Show Posts
Pages: [1] 2 3 ... 24
1  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Cracking salted MD5 hash on: May 17, 2013, 11:01:14 AM
Try the "--rules" option in John. That will mangle the words in your dictionary with some default rules in your john.conf file. There are also some very useful rule sets released by Kore Logic a few years back. You can find them here:

http://contest-2010.korelogic.com/rules.html


I use a "for loop" to go through and use all those rules similar to this:

Code:
for rules in `grep KoreLogicRules /etc/john/john.conf | cut -f2 -d: | cut -d\] -f1`; do john --session=kore --format=<format> --wordlist=<wordlist> --rules=$rules <hashfile>; done

Obviously, you'll need to insert the proper fields into your command, but you get the idea.

Hope that helps!
2  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: You'll find this funny but I'm pretty serious. Need my own servers "hacked" on: May 06, 2013, 12:51:03 PM
What you're asking for is called a penetration test. There are lots of people on this forum (myself included) that are professional penetration testers and get paid to do exactly what you're asking for.

If you're interested in having a quality penetration test done, it won't come free. I would suggest doing a little research on Google to find a reputable consulting firm to contact about your needs. Call around to a few of them to get an idea of what services they provide and an idea of what the price would be. The numbers and services will vary greatly depending on the firm you contact, so shop around and find the best fit for your needs.

Good luck!

 
3  Ethical Hacking Discussions and Related Certifications / Other / Re: Managing Usernames & Pass-Phrases on: April 26, 2013, 09:32:22 AM
Quote
(BTW, I assume using your E-mail or LastName-FirstInitial for a username isn't such a good idea, right?)

I find it ironic that you reply to 'ajohnson' about username choices and mention that its a bad idea use initials and names in username creation.  Grin Grin Grin

Quote
For example, could I have the same Username for my MacBook and WiTopia log-ins?

Honestly, although the username is part of the authentication, they are usually publicly (or somewhat publicly) available. I'm not sure there's such a thing as a "secure" username.
4  Ethical Hacking Discussions and Related Certifications / Incident Response / Re: SANS vLive vs Onsite Training? on: April 15, 2013, 11:17:40 PM
I've taken both. Each format has its strengths and weaknesses.

Live pros:
  • Networking opportunities
  • One on one access to the instructor
  • Natural language/body language
  • SANS @Night and other extracurricular activities

Live cons:
  • The most expensive way to train
  • Time away from your family
  • Lost productivity at work
  • The sheer amount of information thrown at you in 6 days' time

vLive pros:
  • Slow pace fosters more in depth understanding
  • Feeling of disconnectedness seems to make the students more willing to work together
  • Less expensive with no travel costs

vLive cons:
  • Evenings are shot on nights of the class
  • Less networking opportunities...there's only one class
  • Some topics can feel disjointed with the shorter class meetings

Edit: I meant to say that I would highly recommend the vLive format. I was weary at first, but after about week 1 I decided I really liked it!
5  EH-Net / News Items and General Discussion About EH-Net / Re: Change is Coming to EH-Net!! on: April 08, 2013, 03:37:02 PM
Personally, I'm excited to see the new EH-Net!

To answer your specific questions:

1) Absolutely. A few growing pains that I may or may not feel are not going to drive me away from such a helpful community! Its worth the pain for me to stick around.
2) I like having the PM available, but I really don't use PM's that often.
3) Depending on the time commitment (I have 3 kids under the age of 6 and travel about 25%), I would be interested in blogging for EH-Net from time to time.
4) *raises his hand*
5) *twiddles his thumbs*
6) I'm sure someone has useful expertise on PHP, MySQL, and design, but it ain't me!
7) I don't have a strong feeling toward OpenID one way or another, but I will tell you that I typically do not link my GMail credentials (I don't use Twitter or Facebook) to very many other sites through OpenID.

Thanks for all the hard work you put into this site, Don! I'm always willing to give back where I can and am looking forward to all the changes you have in store!
6  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Common vulnerabilities you expose during engagements on: March 14, 2013, 08:20:49 AM
SSL issues are very common as well. They're not super-sexy, remotely exploitable....but there still out there.
7  Ethical Hacking Discussions and Related Certifications / Other / Re: Cyber Challenge Games on: February 26, 2013, 02:32:12 PM
I get a 500 error on level 5 through 8.
8  Ethical Hacking Discussions and Related Certifications / eCPPT - eLearnSecurity Certified Professional Penetration Tester / Re: Flat 30 days vs 30 Hr prepaid model? on: February 26, 2013, 08:06:47 AM
I used less than 10 hours to go through all the labs they had at the time I was taking the class. They've added a couple labs since that I keep telling myself I should go back and do. The labs are fun and are a good way to cement what you learn in the slides. There's nothing earth shattering in there though. A lot of it you could set up in a home lab.

I would HIGHLY recommend buying time in the Coliseum (especially if you're planning on taking the certification)! That was a very cool setup that I learned a lot from. My understanding is that there is only a subscription plan for the Coliseum (but I may be wrong). If you can devote an hour or two a day to it, I think a 30 day subscription would be adequate for most people.
9  Ethical Hacking Discussions and Related Certifications / Cyber Warfare / Re: APT1: Exposing One of China's Cyber Espionage Units on: February 20, 2013, 04:13:02 PM
Quote
My only fear about all this is that we suck at defense. I'm not sure we (USA)  could withstand a serious attack...

Fortunately, I don't think we're the only ones!  Grin Grin Grin
10  EH-Net / Calendar Of Events / Re: BSides Memphis 2013 on: February 20, 2013, 02:21:37 PM
If anyone else from EH-Net is gonna' be there, I've already got my ticket.
11  Ethical Hacking Discussions and Related Certifications / General Certification / Re: SANS Work-Study experience on: February 13, 2013, 09:09:19 AM
The work-study program is a huge discount, but as you point out it can still be fairly expensive if you're traveling across the country (and in your case a second country)!

I've taken three SANS course. I've attended a conference as a regular attendee, I've taken a vLive course, and I've attended a conference as a facilitator. Of the three formats, I would recommend the facilitator route every time! The networking you get as a facilitator is very different than the networking as a regular attendee.

I can understand where you're coming from on the cost vs benefit, though. In the three classes I've taken, not one cent of the costs came out of my pocket.


12  EH-Net / News Items and General Discussion About EH-Net / Re: [Article]-February 2013 Free Giveaway Sponsor - SANS on: February 12, 2013, 02:45:18 PM
*drool*

That's a great one, Don!!!
13  Ethical Hacking Discussions and Related Certifications / Forensics / Re: Web site forensics on: February 04, 2013, 10:03:23 AM
Logs?

IDS/IPS alerts?

Regardless of whether you're looking for compromise on a workstation, webserver, or whatever....it all boils down to what logging do you have in place. Without the logs, you can't do much investigating....

If adequate logging is in place, the incident response/investigation process does not deviate just because it's a webserver.
14  Ethical Hacking Discussions and Related Certifications / Programming / Re: Complete newbie on: January 31, 2013, 10:23:50 PM
You want to talk about feeling old? My "typing" class in high school was split between (first semester) typewriters and (2nd semester) computers...how many on this board learned to type on a typewriter?

Just sayin....
15  Ethical Hacking Discussions and Related Certifications / Programming / Re: Complete newbie on: January 30, 2013, 07:36:25 AM
Another great resource is Google's Python training class. They released videos and printed material/exercises that go with the class here:

https://developers.google.com/edu/python/set-up
Pages: [1] 2 3 ... 24
Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.077 seconds with 21 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Free Business and Tech Magazines and eBooks

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.