Image
 
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 29 guests and 2 members online
EH-Net Donations

Enter Amount:
$

Google Ads
ChicagoCon 2008f
chicagocon2008f_125x200banner.jpg
ChicagoCon 2008f
EH-Net News Feeds
Latest Additions
Book Recommendations





 
Advertisement

You are here: Home arrow Forum
Ethical Hacker Community Forums
August 21, 2008, 03:58:42 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Registration Now Open for ChicagoCon 2008f Oct 27 - Nov 2! Visit www.chicagocon.com.
 
  Home Help Calendar Login Register  
  Show Posts
Pages: [1] 2 3
1  Features / Opinions / Re: Metasploit 3 - how easy is too easy? on: April 08, 2007, 02:34:38 PM
is:

gcc sploit.c -o sploit
./sploit

too easy too?  yes...

But at least knowing that sploit has to be run against OS x of patch level y shows some prior knowlegde and understanding.


and Cutaway: I always do good things Grin

I guess I'll just have to study more in order to be one step above the rest.


I suppose some of this stems from a job I use to be in years ago, where people paid me good(ish) money to build bike wheels for them, as there's something of a black art to that. I was terrified that one day people would realise that anyone who could tell left from right and count up to three could do my job.
2  Features / Opinions / Metasploit 3 - how easy is too easy? on: April 07, 2007, 04:48:49 PM
First off, I really really need to thank everyone here. Combined you've manage to get me off my backside and actually do something* - rather than just read (and read and read and...) about infosec, with the occational bit of playing. I've now got my self a lab set up, and set out to learn some thing practical.

Now a while back I had a little go with Metasploit when it was 2.x, and to be frank it was a little scary and confusing. I could tell there was a lot of power under the hood, as it were, but I didn't have the time to get to grips with it.

Now I've just set up a 2k server target and installed Metasploit 3 on my attack machine. Without reading any documentation, I started Metasploit for the first time and five clicks and two IPs added later I had owned the target.



Five clicks and a little common sense.



Is anyone nervous that this might be taking the edge off the skills of your profession? I've been unfortunate enough to work with "paper" MCSEs and CCNAs** who have NO idea about what they're doing, and I don't like the way they dilute the skills pool. I can foresee a rash of idiots with meta and a copy of nessus labeling themselves as security consultants (not to mention IRC channels worldwide filled with skiddies who think themselves uber-leet because they took a live CD into school and now have domain admin).

Now I'm not trying to put the metasploit team down, far from it, I can now use the "power" that was just outside my grasp and I can tell I'm going to have a lot of fun with it  Grin and even after a few mins of use I can tell that some very very smart people have spent a long long time making this.

Nor am I trying to put pro-pentesters down, I know there's more to pentesting than just scanning and running exploits*** and the skilled professionals will survive much longer than the unskilled, but how easy is too easy? Wouldn't you like to keep it just a little bit black-art? or is it good that this tool makes it easier for poeple to aproach the topic and then progress to a higher understanding?





* this is no mean feat by any standards
** in the intrests of honesty  you should know I have neither of these qualifications
*** please tell me I'm right on this one Wink
3  Ethical Hacking Discussions and Related Certifications / Other / Re: To Mac or not to Mac? on: April 03, 2007, 09:53:22 AM
For me getting up to speed on OSX has been a pain in the @$$

I think I found it easier moving from XP to the totally different OSX, than I'm finding it moving from XP to Vista (which I'm finding more annoying than 2k -> XP)
4  Ethical Hacking Discussions and Related Certifications / Other / Re: To Mac or not to Mac? on: April 03, 2007, 07:40:05 AM
I use my PowerBook all the time. (and actually a G5 at work, amongst others). I only ocationally have issues with it.

I like it because it's a nice middle ground between a Lappy with windows or linux. It's still a *nix under the hood but I know that if I've got my not-geek hat on I can download an OSX app and *know* it'll run without any dependacy issues. (and yes, yes I'm a sucker for eyecandy)

As long as you get the developers tools from .Mac you can compile apps to your hearts content.

You can get the free MS virt machine for OSX too.

However, I'm the first to admit they're a little overpriced for what they are. The thing that swung me was i could get educational discount and a free iPod!

At retail prices I'd go with a non-apple. Infact there was a dell with almost the exact hardware as the Macbook Pro, for a lot less, that and the reatail OSx and you could have it all on one box!

5  EH-Net / News Items and General Discussion About EH-Net / Re: [Article]-EH-Net Releases Desktop Backgrounds on: April 03, 2007, 04:15:46 AM
It's got potential, but I would say the text needs a little bit of work. In my opinion "simple != bad" when it comes to desktop bg, don't want it too busy.

Quote from: talkinelf
what i feel is we need to open up for submitting wallpapers for eh-net Wink

Can I smell a wallpaper compo coming on? (like I need another excuse to fire up gimp)

If so, don't forget us widescreen users when sizing!


Quote from: don
You will see it in a Special EH-Net Version of BackTrack2 (Hint Hint) coming soon.

Doh, just finished burning BT2 this morning. I am very intruged though.

6  Ethical Hacking Discussions and Related Certifications / Other / Re: Fluxbox on: March 26, 2007, 01:29:27 PM
If CentOs = Redhat then you could just download the RPMs, I know it's not as fun as compiling you own, but it is easier Wink

Just grab the fedora pakage from: http://fluxbox.sourceforge.net/download.php

install as root with
Code:
rpm -i downloadedFile.rpm

it's only 0.9 but it should still work.
7  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Handles on: March 25, 2007, 01:46:32 PM
OK. The problem with hackthissite.org is that it is all about hacking websites, not networks.

No it's not. there's some rev-eng stuff, some database stuff, some crypto stuff, etc. It's all hacking. Don't try and compartmentalise everything, just go with the flow and absorb everything you can.

I've complete all the challenges there, if you stick with it you'll learn a lot.
8  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Help... Worm? on: March 25, 2007, 01:42:03 PM
As far as I'm aware (I'm sure someone will correct me if I'm wrong) commands only appear in start > run if they've been run from there. So someone had access to his desktop.

There has been a large increase in scanning for VNC servers recently, so I would suspect that was point of entry.
9  Columns / Gates / Re: Shmoocon Day 2 on: March 25, 2007, 05:48:57 AM
Ace. Cons sound like a blast! Thanks for the coverage ChirsG it's been good reading it.

Now that I want to go to a con even more than before, does anyone know of any sec cons that happen in the UK?
10  Ethical Hacking Discussions and Related Certifications / CEH - Certified Ethical Hacker / Re: Journalist writing an article on ethical hacking on: March 25, 2007, 05:41:31 AM
another question for you is do you plan on giving a negative or positive spin to ethical hacking in your interview?

I think that depends on which paper it for, looking at Guys page he's seems to do a lot for broadsheets (good) but one or two peices for tabloids (boooo!)

I'd be happy to talk to him, but I'm a "hobbyist", as Guy put it, not a pro  and there are many better candidates for interview here. (but at least  I'm in the right country)
11  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Do you need to know programming to hack? on: March 21, 2007, 06:29:23 PM
Sounds stupid, which is the easiest to learn?

Don't think that sounds stupid at all.

I think different languages suit different people.

And it depends on what you're using it for, are you using it just to learn how to program or you've got a x that need to do y to and you want to learn how?

Take a look at a few tutorials for different languages and go with the one you feel most comfortable with till you've got the basics, then look at a more specific/useful one if it doesn't meet your needs.

I would recommend looking at perl at some point as there's tons of tutorials and documentation out there and I find it very useful.
12  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Handles on: March 21, 2007, 05:23:50 PM
I would think hackers are much more likely to use a handle than crackers are to use their real name. Smiley

I don't try to hide my real name, it's just easier to type "plik". It means something to me but is unlikely to be registered on forums etc.
13  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Weird Firewall scan results on: March 20, 2007, 07:10:31 PM
I wonder if those scan results are reflective from something my ISP has setup in front of my firewall.

I pondered this too, but couldn't work out why you'd want to do the full handshake for services that aren't there. And why those ports?



If you can connect that's my NAT idea down the drain!
14  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Weird Firewall scan results on: March 20, 2007, 06:48:45 PM
I've not heard of nmap having false positive issues with connect scans before. So I think we can assume you scanned *something* the lack of 1023 returning makes me think the scan never reached your box. Are you sure you scanned the right IP Smiley
Traceroute turn up anything interesting?

Can you actually reach ssh and webtool?

-stab in dark-
Because *something* has responded on those ports I'd say it was a routing/NAT issue. Do you have any windows boxes running IIS and mail on site?
-/stab in dark-
15  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Weird Firewall scan results on: March 20, 2007, 02:51:00 PM
What version of nmap, on what OS?

and what type of scan were you running?
Pages: [1] 2 3
Powered by MySQL Powered by PHP Powered by SMF 1.1.5 | SMF © 2006-2008, Simple Machines LLC
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.065 seconds with 21 queries.
 

EH-Net's
2nd Annual
Tweener Party
 

Thanks all. Click HERE for details.

Polls
Best for daily desktop use:
 
Support EH-Net
chicagocon2008f_125x200banner.jpg
ChicagoCon 2008f


Support EH-Net by
Buying all of your
Amazon items using
the search bar above.

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!
Recent Forum Topics
Vote For EH-Net

progenic.com
Click here to Vote!

Sadikhov.com
Top IT Cert Sites

binarica.com
Binarica Logo

Add to Technorati Favorites
technorati fave

chicagocon2008f_125x200banner.jpg
ChicagoCon 2008f
 
         
Advertisement

© 2008 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.