|
EH-Net
|
|
May 20, 2013, 02:34:18 AM
|
|
273
|
Ethical Hacking Discussions and Related Certifications / CEH - Certified Ethical Hacker / Re: hi all
|
on: August 26, 2010, 10:56:51 AM
|
|
Its a poorly worded question. He will "Guess the sequence numbers" in order to "Take over the session."
The part of the question where they say he performs sequence prediction on the target OS means that he has done statistical analysis on sequence numbers on the host to make brute forcing the sequence number on an already established session more efficient. But in order to take over the session he must still brute force the sequence numbers of a session in progress.
Hope that helps...
|
|
|
|
|
275
|
Ethical Hacking Discussions and Related Certifications / OSCP - Offensive Security Certified Professional / Re: OSCP exam in 1 week - Advice?
|
on: August 25, 2010, 10:26:35 AM
|
|
I am not a professional pentester, so take what I say with a grain of salt. The answer about how to proceed is "it depends."
From my experience (which as I stated earlier is limited), you get a feel for what is going to be easy and what is going to be difficult. If in your initial scans there is an OS or a port/application that stands out as being easy to get a foothold on, then it might be a good idea to focus in on that first. If the environment is fairly heterogeneous, until your scans drill down into enough detail that the purpose of the box is more obvious, you need to focus on the network as a whole.
|
|
|
|
|
278
|
Ethical Hacking Discussions and Related Certifications / Security / Re: New SANS course - SEC660
|
on: August 20, 2010, 08:37:25 AM
|
|
Jackson, MS
It was a fun week. John Strand instructed the 504 class. He did a mass CTF Thursday night with a big cooler full of beer. It was a good time. Although, the hotel didn't run the heat in the convention hall all week, so it was freezing the whole time!
Hopefully, I'll be able to make it this year, and we can go grab a beer or something! There's a great brewhouse on Decatur.
|
|
|
|
|
Loading...
|