Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 58 guests and 3 members online
 
Free Business and Tech Magazines and eBooks

You are here: Home
EH-Net
May 18, 2013, 05:42:56 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
  Home Help Calendar Login Register  
  Show Posts
Pages: [1] 2 3 ... 9
1  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Questionnaire for Pen Test. on: May 26, 2011, 02:14:45 PM
I require a formal questionnaire which would be provided to the client used for penetration test .

If no one is having it how about if some of you guys list up some of questions which you might ask considering the fact that pen test is of network + web app .
2  Resources / Looking For Work / GCC on: February 04, 2011, 04:07:53 AM
Hey Everyone ,
             

Didn't get other are to post this stuff so apologies if this is out of topic .

I was searching for a job in GCC countries related to Network Security Engineer/Cisco Engineer having 3 years of solution provider experience .

Let me know if you guys can help in this regard .

Regards,
MCP, CCNA, CCSP, OSCP.
3  Ethical Hacking Discussions and Related Certifications / GCIH - GIAC Certified Incident Handler / Re: GCIH Challenge Registration Question, please help on: November 29, 2010, 01:19:27 PM
For challenge exam email to info@giac.org rather then @sans .
4  Resources / Tutorials / Re: Penetration testing updated windows 7 and bypassing kaspersky internet security on: November 26, 2010, 07:18:37 PM
نعم ، إذا كنت لا أن جيدة مع الناس ربما الإنجليزية الأخرى يمكن أن تساعدك مع هذا
5  Ethical Hacking Discussions and Related Certifications / CEH - Certified Ethical Hacker / Re: Help needed for CEH exam on: November 26, 2010, 05:20:19 PM
If you need to appear for a CEH exam you dont need to use your credit card , or western union etc .  You can contact the testing centre in your area and pay them for the exam and they will register it . VUE and Prometric are 2 well known testing centres but I am not sure which one offers exams for CEH , maybe its VUE . You can check offical websites of these testing centres , get local contact numbers and then call them .
6  Resources / Tutorials / Re: Penetration testing updated windows 7 and bypassing kaspersky internet security on: November 25, 2010, 11:57:03 PM
Try to make one in English , if you cant speak good English you can type what you are doing in a notepad in English so that the international community can have a look into whats going on .
7  Resources / Tutorials / Re: Penetration testing updated windows 7 and bypassing kaspersky internet security on: November 25, 2010, 03:50:39 AM
Thanks I m watching it now ... BTW are you the same guy starting some sort of online Pen Testing Classes ??


Update : I cant understand anything , maybe its going to be one of the finest videos because the technologies used are latest . Can you try to make one in English ?
8  Ethical Hacking Discussions and Related Certifications / Other / Cheapest VPS on: November 23, 2010, 05:55:09 PM
I was looking for some VPS solutions for personal use and I found this one . Has anyone of EH members used this one ?

hxxp://unixy.net/99/
9  Ethical Hacking Discussions and Related Certifications / CEH - Certified Ethical Hacker / Re: Step by step guide to setup 2 home networks on: November 19, 2010, 10:42:19 PM
Also check LAMP Security CTF , http://sourceforge.net/projects/lampsecurity/
10  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: PortScanning Solaris on: November 19, 2010, 04:59:23 PM
have you tried changing the boxes ? I did scan a host located in other country ( SUN SPARC - SOLARIS Server ) and the results came up in 80 seconds which I think is perty much fine using nmap along with nse
11  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Detecting virtualization on servers located behind routers? on: November 19, 2010, 04:49:45 PM
Code:
I did a -A scan and got the folllowing line which might be interesting

MAC Address: 00:50:56:BC:7B:D9 (VMware)

If you dont have money to invest then better google pfsence , smoothwall , they are good all in one firewall type solutions and open source .

Thanks for your idea sir,but if possible can you tell me the possible mac address range for the vmware?

and pfsense and smoothwall supports NAT uhh?
can i use them to play my NAT enumeration on them?

Code:

Agreed, performing OS detection will determine, in my experience, a system running in a VM.

Also, Hak5 did a video on turning a mini-PC into a router/firewall. I enjoyed it u dutil they changed the firewall software they were using in another video...

I don't know how OS determination will help us in identifying the virtualization technology used on the target,besides mac address what are the other things i should look for to identify the virtualization?

Also if it is hosted using virtualization other than vmware workstation means how can we detect them?




As per wikipedia following are the features supported by Pfsence 

    * Firewall
    * State Table
    * NAT
    * Redundancy
          o CARP - CARP from OpenBSD allows for hardware failover. Two or more firewalls can be configured as a failover group. If one interface fails on the primary or the primary goes offline entirely, the secondary becomes active. pfSense also includes configuration synchronization capabilities where changes made to the primary firewall will automatically synchronize to the secondary firewall.
          o pfsync - pfsync ensures the firewall's state table is replicated to all failover configured firewalls. This means your existing connections will be maintained in the case of failure, which is important to prevent network disruptions.
    * Outbound and Inbound Load Balancing
    * VPN - IPsec, OpenVPN, PPTP
    * PPPoE Server
    * RRD Graphs Reporting
    * Real Time Information - Using AJAX
    * Dynamic DNS
    * Captive portal
    * DHCP Server and Relay
    * Live CD Version Available
    * Proxy server
    * Support for software extensions.
          o Notable expansions are : Squid proxy server and Snort intrusion prevention/detection system.


Also if you are in LAN subnet you can issue a ping command and then check the local arp table for mac address conformation , then you can match it with nmap results .
12  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Detecting virtualization on servers located behind routers? on: November 18, 2010, 03:06:31 PM
I did a -A scan and got the folllowing line which might be interesting

MAC Address: 00:50:56:BC:7B:D9 (VMware)

If you dont have money to invest then better google pfsence , smoothwall , they are good all in one firewall type solutions and open source .
13  Resources / Career Central / Re: So which countries need CEH CHFI at present on: November 16, 2010, 05:36:01 AM
These kinds of jobs are more available in USA or European countries .  You would not get some good offers from Dubai , if you get it will most probably be compliance+pen testing . Try different jobs sites and ofcourse linkedin but I am afraid that you wont be able to get sponsored work visa from the company unless you are distinguished person or have some thing extra-ordinary . 
14  Ethical Hacking Discussions and Related Certifications / General Certification / Re: CCNA info on: November 09, 2010, 08:16:21 AM
When it comes to cisco computer based CBT I will always recommend companies like INE or IPExpert since they are far more specialized and better in Cisco then anyother company like CBTNuggets .

http://www.ine.com/self-paced/ccna/bootcamps.htm#Training/ccna-bootcamp

Maybe 500USD is expensive for a training but its far more better then any normal Instructor Led though this one is Self Placed . Other then that they are offering 30% Discount at the moment on all self placed materials .

As book is concerned Todd Lammel is one of the best in CCNA .

When it comes to hardware I would recommend to concentrating on purchasing L3 Switching equipment rather then putting money on RTR because you can easily emulate them on GNS3 which rocks . IT works excellent if you have a linux box with 2GB of ram depending on how much routers you want to emulate . Consider getting and LXDE interface in linux which can help save some memory on GUI .
15  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Ethical Hackers Wanted for Global Cyber Warfare Simulation on: November 09, 2010, 08:05:41 AM
ping 127.0.0.1
Pages: [1] 2 3 ... 9
Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.078 seconds with 21 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.