Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 43 guests online
 
Advertisement

You are here: Home
EH-Net
May 20, 2013, 02:34:18 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
  Home Help Calendar Login Register  
  Show Posts
Pages: 1 ... 17 18 [19] 20 21 ... 24
271  Ethical Hacking Discussions and Related Certifications / CEH - Certified Ethical Hacker / Re: hi all on: August 27, 2010, 07:26:38 AM
Congratulations!

What's next?

Welcome to EH-Net by the way!
272  Ethical Hacking Discussions and Related Certifications / OSCP - Offensive Security Certified Professional / Re: OSCP exam in 1 week - Advice? on: August 26, 2010, 12:03:25 PM
Nah... I wouldn't know where to begin. My posts at times come across the wrong way to so many people, I think anyone who would buy the book would only do so to throw it at me.

Make it a paperback then!!!  Grin
273  Ethical Hacking Discussions and Related Certifications / CEH - Certified Ethical Hacker / Re: hi all on: August 26, 2010, 10:56:51 AM
Its a poorly worded question. He will "Guess the sequence numbers" in order to "Take over the session."

The part of the question where they say he performs sequence prediction on the target OS means that he has done statistical analysis on sequence numbers on the host to make brute forcing the sequence number on an already established session more efficient. But in order to take over the session he must still brute force the sequence numbers of a session in progress.

Hope that helps...
274  Ethical Hacking Discussions and Related Certifications / OSCP - Offensive Security Certified Professional / Re: OSCP exam in 1 week - Advice? on: August 25, 2010, 03:27:23 PM
@sil

Quote
Starting nmap 3.70 ( http://www.insecure.org/nmap/ ) at 2010-08-25 10:20 EDT

Wow! I think its time to update!  Tongue Grin
275  Ethical Hacking Discussions and Related Certifications / OSCP - Offensive Security Certified Professional / Re: OSCP exam in 1 week - Advice? on: August 25, 2010, 10:26:35 AM
I am not a professional pentester, so take what I say with a grain of salt. The answer about how to proceed is "it depends."

From my experience (which as I stated earlier is limited), you get a feel for what is going to be easy and what is going to be difficult. If in your initial scans there is an OS or a port/application that stands out as being easy to get a foothold on, then it might be a good idea to focus in on that first. If the environment is fairly heterogeneous, until your scans drill down into enough detail that the purpose of the box is more obvious, you need to focus on the network as a whole.


276  Ethical Hacking Discussions and Related Certifications / OSCP - Offensive Security Certified Professional / Re: OSCP exam in 1 week - Advice? on: August 23, 2010, 04:08:15 PM
It sucks that you didn't get the little piece of paper at the end of it all, but congratulations on making through the process and being happy with the outcome! To me, that means you put in the level of effort and got as much out of it as you could. I know if I took the class/exam right now, I'd probably do much worse than 10 points from passing! But, believe it or not, your previous post makes me want to take the class....

I guess I'm a masochist along with you...

277  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Privilege excalation on: August 20, 2010, 09:34:11 AM
To add to hayabusa...there's always a good chance you'll find a misconfiguration or "human mistake" you can leverage, such as private keys carelessly stored, backup shadow files/SAM databases, etc., etc.

Its not the "sexiest" way to escalate your privilege, but usually its the easiest!



278  Ethical Hacking Discussions and Related Certifications / Security / Re: New SANS course - SEC660 on: August 20, 2010, 08:37:25 AM
Jackson, MS

It was a fun week. John Strand instructed the 504 class. He did a mass CTF Thursday night with a big cooler full of beer. It was a good time. Although, the hotel didn't run the heat in the convention hall all week, so it was freezing the whole time!

Hopefully, I'll be able to make it this year, and we can go grab a beer or something! There's a great brewhouse on Decatur.
279  Ethical Hacking Discussions and Related Certifications / Security / Re: New SANS course - SEC660 on: August 19, 2010, 05:34:42 PM
Are you serious?! That's where I facilitated last year SecEast 2010, New Orleans!

Depending on my situation, I may be there next year as well...
280  Ethical Hacking Discussions and Related Certifications / Security / Re: New SANS course - SEC660 on: August 19, 2010, 03:55:02 PM
If you live near a major city where SANS conferences are held, the work study program is A LOT of fun and you get the course and certification for $800!

281  Ethical Hacking Discussions and Related Certifications / Security / New SANS course - SEC660 on: August 19, 2010, 02:56:01 PM
http://www.sans.org/security-training/advanced-penetration-testing-exploits-ethical-hacking-1517-mid

Anyone know much about this? I haven't heard much about it, but it seems pretty damn cool from the daily topics!

282  Ethical Hacking Discussions and Related Certifications / Compliance, Regulations & Standards / Re: PCI Council Unveils Expected Changes for DSS Guidelines on: August 17, 2010, 09:34:41 AM
Thanks for the heads-up, Don. I am unfortunately trying to get management's ear about the updated PCI requirements..

283  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Non-Framework Exploits in Professional Tests? on: August 16, 2010, 03:46:12 PM
If I'm not mistaken, the archive gets updated with an 'apt-get upgrade' in BT4. You'll also notice a nifty little script to search through your local copy of the archive in /pentest/exploits/exploitdb.

284  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Procedure to find services behind open ports on: August 13, 2010, 01:40:37 PM
I apologize. I misunderstood the question. I thought you had access to the boxes.

Yes, Ketchup's suggestions are what I would go with...banner grabbing/analyzing traffic to/from that port is your only option.
285  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Procedure to find services behind open ports on: August 13, 2010, 01:23:20 PM
Windows or Linux/Unix?

Netstat can be used on Windows...I don't remember the switch off the top of my head. On linux/unix you can use lsof -P.
Pages: 1 ... 17 18 [19] 20 21 ... 24
Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.069 seconds with 21 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.