Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 43 guests online
 
Free Business and Tech Magazines and eBooks

You are here: Home
EH-Net
May 24, 2013, 03:17:23 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
  Home Help Calendar Login Register  
  Show Posts
Pages: [1] 2 3 ... 22
1  Ethical Hacking Discussions and Related Certifications / Forensics / Re: EnCase training on: April 28, 2010, 01:46:14 PM
Thank you for the good recommendations!  Initially, my use for EnCase will be to look for the existence of specific files, programs in memory, and may expand from there.
2  Ethical Hacking Discussions and Related Certifications / Forensics / EnCase training on: April 28, 2010, 11:41:54 AM
I am finally getting to play with more tools at work.  One of the most exciting ones is EnCase.  Apparently, licensing is expensive, and training is even more so.  I want to show that I am deserving of training, by being the self-starter I am.  Are there any good books out there for EnCase?

I have Books24x7 through work with access to "EnCase Computer Forensics: The Official EnCE: EnCase Certified Examiner Study Guide, Second Edition".  This pretty much seems to be the only book out there which deals with EnCase specifically.

Are there any other good books that deal specifically with EnCase, or even a forensics book which deals with EnCase specifically?\

Also, anyone have experience with EnCase training?  I think our department may opt for the OnDemand training due to budgeting issues.
3  Resources / News from the Outside World / VisibleRisk Pod Cast: APT - Advanced Persistent Threat on: April 23, 2010, 10:15:40 AM
Visible Risk (http://visiblerisk.com) posted a podcast hosted by Rocky DeStefano (Visible Risk), along with Rob Lee (SANS / Mandiant), Richard Bejtlich (GE / Tao of Security), Mike Cloppert (Lockheed Martin), and Shawn Carpenter (Netwitness).  Interesting discussion on Advanced Persistent Threat from some of thought leaders in the field.  The audio volume is really low, but it is worth cranking the volume.

http://www.visiblerisk.com/storage/media/VIsibleRisk_Episode_001_APT_Audio.mp3

Good schtuff.
4  Ethical Hacking Discussions and Related Certifications / CEH - Certified Ethical Hacker / Re: how to penetrate pc through NAT ?? on: April 23, 2010, 07:48:07 AM
For your scenario, you can shovel a shell/reverse shell using NetCat.  How do you get NetCat on the machine from the outside?  It is so small it can fit inside a buffer overflow or you can combine it with another executable which is run on the inside.
5  Resources / News from the Outside World / Re: security consultant/ethical hacker redefined on: April 23, 2010, 07:45:30 AM
Quote
Narcissistic Vulnerability Pimp: One who – solely for the purpose of self-glorification and self-gratification – harms business and society by irresponsibly disclosing information that makes things less secure.

Sounds like Verizon is using their head to find that stick that is up their ass.  Not all vulnerability researchers are classified this way.  I have read numerous personal accounts and methods for being an ethical security researcher and there comes a point where the needs of the many out weight the needs of a few businesses.

Regardless of that fact, security needs these "pimps".  The more we know about the vulnerabilities the more we can mitigation.
6  Resources / News from the Outside World / Security researcher hacks police records. on: April 22, 2010, 07:41:53 PM
Here is a great write-up of a group of security professionals playing urban golf in Seattle.  Basically, a pub crawl while hitting a foam ball down the street.  An innocent bystander was hit with the ball and called the police.  Eric Rachner, who was with the group refused to ID himself and was promptly arrested.  The charges were dropped and the case thrown out, but not before they police said the video of the incident was lost.  Rachner, with the help of his lawyer, reviewed the video systems documents and found there is a log of all the video activity, he requested the log and found the video was not deleted.  Police eventually turned over the video.

Also involved with the group of 20-30 people, was Dan Kaminsky.  I wonder who else was there and why they were all in Seattle?

http://www.seattlepi.com/local/418746_video.html
7  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Router and Firewall questions on: April 22, 2010, 09:05:48 AM
As stated, your router is blocking the traffic.  If you want to test the security of each of the different distributions you may want to invest a few bucks on a cheap 10/100 hub.  A router will only send traffic out to specific ports, unless you flood it and make it fail back to be a hub, or you use ARP spoofing, or any number of other tricks.  But if you are just doing it for testing, then get a hub which sends traffic to all ports, regardless of which computer it is destined for.
8  EH-Net / News Items and General Discussion About EH-Net / Re: Long time lurker on: April 22, 2010, 09:02:42 AM
Welcome to the site.  I took a similar approach to information security by coming up through grunt work at the helldesk.  It was strange, I never had much interest in getting my MCSE or whatnot, but once I got into security I've taken off in regards to my certifications.  Security Plus was my first step and it was a good one.

Again, welcome.  If you have any questions, let us know.
9  Ethical Hacking Discussions and Related Certifications / Other / Re: What EXACTLY are protocols? Does anyone really know? on: April 21, 2010, 01:11:26 PM
http://www.youtube.com/watch?v=x9XWxD6cJuY

'Nuff said.
10  Ethical Hacking Discussions and Related Certifications / GPEN - GIAC Certified Penetration Tester / Re: SANS GPEN Self-Study alternative ? on: April 12, 2010, 10:38:59 AM
GPEN is not for the faint of heart.  It is super technical.  My co-worker and brother have taken the course and they both were both dumb founded by the amount of technical information.  They are both well experienced and certified individuals, and are not stupid in any way.

As a holder of two GIAC certs and one on the way, with one self study and two courses, I can safely state without any previous experience it may be near impossible to pass without having the SANS course ware.

With that being said, there are a lot of options when going for a SANS course.  You can do OnDemand, Self Study, life training, and even work study at live training (where you work at the conference, get the training, materials, and certification attempt for around $800).  I think if you are starting off with no experience, then it would take all of your being to do self-study to bring you up to a level where you would be lucky if you drowned in the level of technical details the course offers.

I do not know your experience or commitment level, but you could probably do well to self-study and do the GPEN course.  If you are looking for a more long term and lower budget option, you may want to go the self-study route for Security+ to lay the security foundation > CEH to lay the pen testing foundation with methodology and tools > GPEN.

I would also recommend Counter Hack, because it is a good read, and it not only gives you a lot of the hacker tools and methodology, but it also gives you insight on how to defend these tools.  You would also do well to start learning some of the tools like NMAP, Wireshark, Metasploit, and Cain and Able.  Heck, just start playing with anything on http://sectools.org/. Smiley

Good luck!
11  Ethical Hacking Discussions and Related Certifications / Security / Re: Discount Security+ voucher early expire on: April 05, 2010, 12:10:44 PM
I fully support this website.  I used it when I was still a contractor and paying for my own certifications.  It really helped save me a few pennies.  They are really easy to deal with.
12  Features / Opinions / Re: real hackers.... on: March 25, 2010, 02:13:00 PM
Man, I fit into most of the categories on the original post, and some in the second.... this is funny.
13  Ethical Hacking Discussions and Related Certifications / General Certification / Re: Signed up for my GCIA attempt. on: March 25, 2010, 02:08:51 PM
Sorry, my co-workers won out.  I'll have more practice tests in the future!  One for GCWN and GSEC. Smiley
14  Ethical Hacking Discussions and Related Certifications / General Certification / Re: Signed up for my GCIA attempt. on: March 25, 2010, 09:49:51 AM
Ok, I passed my GCIA yesterday with an hour to go.  My final score was 85%.  I was less about my score than with my GCIH (94%).  I just wanted to pass, then I was able to take it easy.  The test got a lot easier once I passed. Smiley  This was much harder than the GCIH.  A lot of packet reading.  I made easy mistakes when counting the hex and converting.  I made the mistake of not taking a break, I was more concerned about just finishing the test and getting out of there because of personal issues.

It was a good experience.  Now I can move onto my GCWN.  I will am going to offer the practice test to my group, if I do not get an immediate response my next stop will be here. itg33k has first dibs, but I think I may have a simple little quiz to answer to make it fair. Smiley
15  Ethical Hacking Discussions and Related Certifications / General Certification / Re: Signed up for my GCIA attempt. on: March 19, 2010, 01:14:43 PM
Thank you for all your well wishes.  I am going to be doing a dry run of my index with a practice test this weekend.  Then I may have my second GCIA practice test up for grabs if nobody in my department wants it.
Pages: [1] 2 3 ... 22
Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.1 seconds with 21 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.