Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 26 guests online
 
Advertisement

You are here: Home
EH-Net
May 22, 2013, 06:47:20 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
  Home Help Calendar Login Register  
  Show Posts
Pages: 1 [2] 3 4 ... 24
16  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Evading Anti-virus Detection with Metasploit - Live Webcast on: January 25, 2013, 11:34:16 AM
All the Rapid7 webcast I've seen have been that way.

The information you get makes it worthwhile, though.
17  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Metasploit payload question on: January 24, 2013, 10:00:16 AM
I guess I should read your posts more carefully! I didn't pick up on the "piped" part of the question!  Grin
18  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Metasploit payload question on: January 24, 2013, 07:43:15 AM
A staged payload uses a stager to instruct the exploit on how to shovel the payload to the victim over the network connection. Non-staged payloads are fully self-contained. The advantage to staged payloads is that they can fit into very small sections of memory, but they're not always as reliable.

You can read more here:

http://www.room362.com/blog/2011/6/26/metasploit-payloads-explained-part-1.html
19  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: How do you import your tools armoury for external engagements on: January 18, 2013, 08:39:21 AM
Typically when I run across situations like this where the customer is trying to put restrictions on how we conduct the test, I try to explain that without the restrictions the client will get a more valuable report. If they continue to insist, I work within the Rules of Engagement and caveat the report where necessary.

Our normal setup for internal-type assessments is a laptop with pre-installed VMs with all our attack/assessment tools installed.
20  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Limited shell on: January 16, 2013, 08:56:01 AM
The link below is Linux specific, but there's quite a bit that could be adapted to Windows.

http://pen-testing.sans.org/blog/pen-testing/2012/06/06/escaping-restricted-linux-shells

Also, maybe something in there will click for you and give you some further avenues to explore.

Good luck!
21  Ethical Hacking Discussions and Related Certifications / Compliance, Regulations & Standards / Re: Approved Scanning Vendor - PCI on: January 14, 2013, 01:51:39 PM
Also, after re-reading your original post, I see there might be some confusion on what an ASV is.

A company is certified as being an ASV. The "V" stands for vendor. There are not individual (person) ASVs. You can verify this by browsing the published list:

https://www.pcisecuritystandards.org/approved_companies_providers/approved_scanning_vendors.php#

Any person can use the ASV products of any of these companies to produce scan reports that will be accepted for a PCI QSA audit. It doesn't matter if you are an employee of an ASV, the company being scanned, or some other third-party.
22  Ethical Hacking Discussions and Related Certifications / Compliance, Regulations & Standards / Re: Approved Scanning Vendor - PCI on: January 14, 2013, 10:20:29 AM
External scan reports must be generated through an ASV company. An important distinction is that the person running the scan does not have to be an employee of the ASV company. You can manage your own scans through the ASV's portal. The report will contain a page that has the ASV number associated with the company that performed the scan. If you're ever audited or have to submit your report to your acquiring bank, the auditor/bank will be looking for that number on the report. Basically, you cannot scan your own perimeter with your own copy of Nessus, generate a report, and say you're compliant. It must be done by an ASV company.

Internal scan reports can be done by anyone knowledgeable in Vulnerability Scanning/Management. It should not be managed by a person responsible for maintaining the systems being scanned, though (separation of duties).

Hope that helps.
23  Features / Opinions / Re: Disney and RFID bracelets..... on: January 09, 2013, 03:30:50 PM
I don't have any further information about how Disney plans to implement this, but fraud within the parks would be very easy to detect. They're using RFID to track visitors. Each RFID chip will be uniquely identifiable, so they would be able to detect you pulling Fast Passes at the Magic Kingdom while simultaneously shopping at Downtown Disney.

The question is, will they implement fraud detection in the system? If the fraud becomes rampant enough that they're losing money, they will.
24  Ethical Hacking Discussions and Related Certifications / Other / Re: Where are you from? on: January 07, 2013, 04:13:35 PM
Quote
For me in Canada, there's currently 2 feet of snow outside.

Funny thing is if you accumulate all the snow that's fallen my entire life in Mississippi, it probably would just barely be 2 feet of snow.

On an unrelated but uncanny note, I'm in Toronto with a foot or so of snow on the ground at the moment.
25  Ethical Hacking Discussions and Related Certifications / Other / Re: Where are you from? on: January 05, 2013, 10:12:44 AM
Jackson, MS

I know what some of you are thinking and YES, we have computers in Mississippi!!!  Grin Grin Grin

We sometimes even wear shoes.
26  Resources / Career Central / Re: Question about penetration testing specialties on: January 02, 2013, 10:38:17 AM
In my limited experience, the level of specialization required of a pentester is directly proportional to the size of the consulting firm you work for. The bigger the firm, the more specialization you can have. Smaller firms tend to need consultants that can do a lot of things well.
27  EH-Net / News Items and General Discussion About EH-Net / Re: [Article]-October 2012 Free Giveaway Winner of LearningGate Training on: December 28, 2012, 02:26:29 PM
Congratz! And Happy New Year! I know what both of you will be making as a New Year Resolution!!!  Grin Grin Grin
28  EH-Net / News Items and General Discussion About EH-Net / Re: [Article]-April 2012 Free Giveaway Winners of eLearnSecurity Training on: December 23, 2012, 09:48:58 PM
Thanks, all!

Quote
Congrats, ziggy!  (Just got my pass email from OSCE, today, as well!)

Great job!  What's next?

I really should do my CISSP, but I'm trying for a facilitator slot at SANS Sec West. So, whichever class they put me in will probably be the next cert I go for.

And, congratz to you on the OSCE!!!
29  EH-Net / News Items and General Discussion About EH-Net / Re: [Article]-April 2012 Free Giveaway Winners of eLearnSecurity Training on: December 23, 2012, 09:05:54 AM
So I found out yesterday that I passed! I'm now officially an eCPPT.

When work slows down a little bit, I'll post a review. There are a number of reviews out there already, but hopefully, I can add something to the conversation.

Thanks, Don! I thoroughly enjoyed the experience and did get a lot out of it.
30  EH-Net / Special Events / Re: [Article]-Webcast: Abusing Windows Remote Management (WinRM) with Metasploit on: December 04, 2012, 12:14:34 PM
Did the date for this change?

When I registered, I clicked on the "Import this event into your calendar" link and it showed up on my calendar for the 6th.

I'll still be attending, but I thought it odd.
Pages: 1 [2] 3 4 ... 24
Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.068 seconds with 21 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.