 |
| |
| |
|
Who's Online |
|
We have 29 guests online |
|
| |
|
|
 |
|
EH-Net
|
|
May 24, 2013, 09:28:51 PM
|
Show Posts
|
|
Pages: 1 ... 19 20 [21] 22
|
|
301
|
Ethical Hacking Discussions and Related Certifications / GCIH - GIAC Certified Incident Handler / Re: Should I go for GCIH after CEH?
|
on: February 24, 2009, 08:29:51 AM
|
|
GCIH was my first choice, but I took CEH because my departmental budget was not finalized. I am really enjoying the CEH material and look forward to GCIH. I missed out on the Orlando SANS, but maybe my manager will shell out the cash for the at home training. Especially since I would be using my own time, but the companies money. When sending someone to training they weight the costs of the actual course and how much the employee makes that week.
Once I am done with CEH, I'll take a low approach with Counter Hack Reloaded.
|
|
|
|
|
302
|
Ethical Hacking Discussions and Related Certifications / GCIH - GIAC Certified Incident Handler / Re: Should I go for GCIH after CEH?
|
on: February 20, 2009, 08:47:32 AM
|
|
Thank you all for the information regarding GCIH. My team is moving towards a security operations center (CIRT level 1) role and I think once I self study I can get my manager to pop for the cheapest SANS training option.
Thanks for the link to the CNDA application. I may be able to swing it, as long as their interpretation of US Govt. Agency is loose. I work for a big company who is good friends with the government and I have enough ties to an agency/program to be able to keep "secrets".
Does anyone have experience with converting a CEH to CNDA?
|
|
|
|
|
304
|
Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Better Hacking tools = Good or Bad?
|
on: February 19, 2009, 12:48:05 PM
|
|
let me paraphrase Michael Gregg from the Exam Prep CEH. Script kiddies are like a series of furious shot gun blasts and true hackers are like a well placed shot in the night. Basically, give a script kiddie a tool and they will make a lot of detectable noise while using it. Letting these automated tools get in the hands of unskilled script kiddies should not be of much concern because, as security professionals we should have protected ourselves and our companies from the hurd of elephants.
In response to giving the tools to Admins, nothing will replace the skills of a security expert. Admins may be able to use the tools to spot check their systems, but in order to properly plan and protect they still need us.
Just my quick two cents.
|
|
|
|
|
306
|
Ethical Hacking Discussions and Related Certifications / General Certification / Re: A question on becoming CEH certified
|
on: February 19, 2009, 08:31:13 AM
|
|
Welcome to the CEH track. I am on the same track myself. I think that would be a good option, but since you have a limited budget I will recommend the cheapest options first rather than spending a ton of money up front. Check your local library (either county or college), for $1.50 in late fees you can get a good CEH education. I would highly recommend the CEH Official by Kimberly Graves to give you a good understanding of what you need, then fore a deeper dive you have the Exam Prep CEH by Michael Gregg. Gregg gives a really good explanation of everything you read in the Graves book and them some. Including exercises at the end of each chapter. I haven't been through the exercises yet, but I would imaging if you just downloaded Backtrack you would be able to follow along.
If you are unable to locate the books at the library then you may be able to use Craigslist or Freecycle to get the books for free. (Information Security is all about giving back!)
If you are employed in a technical role, you may be able to get the company to purchase the materials for you. At the very least see if your company has access to Books24x7. There are a few CEH books on there and they add new books each week!
I am lucky that where I work there are others who have taken the CEH, we have Books 24x7, I have a good college library, and my company also provides money for a training budget.
Good luck and don't give up your dream!
|
|
|
|
|
307
|
Ethical Hacking Discussions and Related Certifications / General Certification / Re: Scheduled CEH for March 20th
|
on: February 18, 2009, 10:38:01 AM
|
It may be good to consider a virtual machine as your attack box so you could switch between your attack box with XP and your linux box with ease. Just wanted to say goodluck in advanced! Let us know how you do.
Thank you for the luck. I'll post a full review after the test. I've considered that. I would just need some more ram. Speaking of virtual machines, does anyone have recommendations? I used to use a open source software which had a bunch of preconfigured images. Oh, I just remember Backtrack having a virtual machine configuration... hhmm... Thanks!!!
|
|
|
|
|
308
|
Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Anybody have experience in helping residential wireless customers get secured?
|
on: February 18, 2009, 08:11:06 AM
|
|
<devil's advocate> Personally, I think this business model based solely on residential pen testing is a horrible idea. It's not just you. I used to frequent the Netstumbler forum where every week a different newbie discovered Netstumbler and came up with the same plan. Think about it from the users perspective. If they would have cared enough to setup encryption then they would have read the quick start guide that came with their hardware. All routers I have setup come with it, you don't even need to read the bigger manual. I don't know why someone would decide to pay $25 or $50 for it (Well, unless some helpless grandmother was cornered by the Nerd Herd).
Additionally, a business model based only upon securing wireless access points is not going to earn you much. Maybe you should consider doing a basic computer service, which might include anti-virus update / installing patches / removing spyware / scandisk-defrag-del temp files.
I don't think starting your own business is a bad idea, just look at it differently. </devil's advocate>
|
|
|
|
|
309
|
Ethical Hacking Discussions and Related Certifications / General Certification / Scheduled CEH for March 20th
|
on: February 17, 2009, 01:24:38 PM
|
|
I'm all set for the CEH V5 on March 20th, a little over a month away.
I've read the official CEH book by Graves, viewed the Career Academy video series, and I started reading the Exam Prep CEH by Michael Gregg. I plan on working the lab exercises from Exam Prep on my lab (w2k3 DC, w2k3 ISS and MSSQL, my attack laptop with WinXP, while considering if I want to install Linux or just use a live CD on another PC.
I do vulnerability scanning, so I am familiar with NMAP and various vulnerabilities and exploits. I've used Ethereal (Wireshark) and I am comfortable with them. I plan on focusing on Snort, Nessus, and Metasploit.
I am feeling really good about this.
|
|
|
|
|
310
|
Ethical Hacking Discussions and Related Certifications / General Certification / Re: Certification MCSO Brazil
|
on: February 16, 2009, 12:50:21 PM
|
Hello, I am studying for this certification.
it is for managers of information security, has strong recognition in Brazil.
the test has 140 questions $250 or R$548 reais
Topics
Information security concepts risk management policy of information security classification of information business continuity management physical security and operational management of people in information security laws and regulations and ethical standards organization of information security cryptography and public key infrastructure access control security in networks and telecommunications security in hosts architecture and security models
see you
Sounds a lot like CISSP. Brazil has a count of 238 current CISSPs.
|
|
|
|
|
311
|
Ethical Hacking Discussions and Related Certifications / GCIH - GIAC Certified Incident Handler / Should I go for GCIH after CEH?
|
on: February 12, 2009, 11:45:31 AM
|
|
I am burning my way through CEH self study and I am going to test in a few weeks. I wanted to know if it would be worth my while to also go back for GCIH. GCIH was my first pick for my next certification, but due to department budget issues not being resolved, I went with my second choice. Is there a lot of overlap in CEH and GCIH? I've been told that GCIH focuses more on defense and incident response, where CEH is more of attack (which is what I am finding).
Your opinions are appreciated!
|
|
|
|
|
313
|
Ethical Hacking Discussions and Related Certifications / General Certification / Re: certification free?
|
on: February 11, 2009, 08:34:07 AM
|
The best way I found to get free certifications is to find a company that is willing to pay for them! A lot of companies are willing to refund you for certifications that you pass just ask your boss or HR department.
That is always a good option. Even with the lowest paying help desk jobs they paid for certifications. Other than that, most companies would require you to stay a year, or pay them back, and the cert should be related to your duties.
|
|
|
|
|
315
|
Ethical Hacking Discussions and Related Certifications / General Certification / Re: certification free?
|
on: February 10, 2009, 12:26:46 PM
|
The only free certifications I have seen that are actually worth something tend to be the beta certifications where they give you the certification if you pass the test. I think Microsoft does this and one other group.... Free training on the other hand is around if you look for it. There are videos on YouTube, of course like http://www.youtube.com/user/fslabs. These combined with Real Player plus and you can download the videos (or use some other free tools from www.sf.net). For a variety of infosec how to's I would recommend Iron Geek's Hacking Illustrated guide ( http://www.irongeek.com/i.php?page=security/hackingillustrated). Yes, his speech is unique, but do not underestimate the information. Another one of my favorite video sites is the CERT Virtual Training Environment https://www.vte.cert.org/vteweb/. Listening to podcasts like: * Security Now! - http://grc.com/securitynow.htm* PaulDotCom Security Weekly - http://www.pauldotcom.com/* Crypto-Gram Security Podcast - http://crypto-gram.libsyn.com/* Network Security Podcast - http://netsecpodcast.com/* CyberSpeak Podcast - http://cyberspeak.libsyn.com/* Hak5 Video Podcast - http://www.hak5.org/* Blue Box: The VoIP Security Podcast - http://www.blueboxpodcast.com/* SearchSecurity Podcasts (including Security Wire Weekly) - http://searchsecurity.techtarget.com/generic/0,295582,sid14_gci1146071,00.html* The Silver Bullet Security Podcast - http://www.cigital.com/silverbullet/Reading, your local library may be surprisingly up to date on books. You could get a lot of security training for $1.50 in late fees. Also read blogs, learn from others. One of my favorite blogs is the Security Monkey over at Toolbox. Look up all his old case files and watch him catch the bad guys with his faithful sidekick Scraps, http://it.toolbox.com/blogs/securitymonkey. Also Security Bloggers Network is an RSS feed for security blogs, http://networks.feedburner.com/Security-Bloggers-Network. EDIT: I forgot there are plenty of user groups out there where you can join for free, Linux User Groups (LUG) or even the shadier side of hacker groups like Binrev ( www.binrev.com/forums) or 2600 ( www.2600.com). Oh, also, you can use/abuse books stores which carry information security magazines. they won't kick you out for reading a magazine, like Hakin9. Whew, that was a lot of information. Maybe I should make an article about this.
|
|
|
|
|
Loading...
|
|
 |
|