Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 30 guests and 1 member online
 
Advertisement

You are here: Home
EH-Net
May 18, 2013, 06:40:48 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
  Home Help Calendar Login Register  
  Show Posts
Pages: [1] 2 3 ... 16
1  Ethical Hacking Discussions and Related Certifications / Programming / Re: Need good password crackers to test my encryption algorithm. on: March 22, 2012, 09:36:30 PM
I'll second this.  The sample you provide is insufficient to determine anything about either the algorithm or the keying material.

That being said, rolling your own encryption algorithm is always a bad idea.  Correctly implementing existing encryption libraries can be difficult (ask the Debian team).  Getting your own algorithm built from the ground up is MUCH harder (and likely to be an epic fail).
2  Ethical Hacking Discussions and Related Certifications / Security / Re: CEPT by Infosec Institute on: March 06, 2012, 06:51:19 AM
I'd be interested as well to hear your experiences with the CEPT.  I'm equally interested that Infosec Institute is even still in business considering the plaugerism scandal last year...
3  Ethical Hacking Discussions and Related Certifications / Web Applications / Re: hacme bank prebuilt vmware image by (Ninja-Sec.com) on: March 03, 2012, 10:33:22 AM
FWIW, I downloaded the image and extracted the zip file.  This creates multiple .7z files (a multi-part 7-zip file).  Use 7-zip (free) to put them back together.  The whole process took maybe 5 minutes and was far from rocket science.  No offense, but if you can't reassemble a multi-part archive, even hackme bank is probably a little too advanced for you.
4  Resources / Career Central / Re: Demand for Linux Skills on the Rise, Along With Wages on: March 01, 2012, 07:30:03 PM
Sorry to resurrect an old thread, but for what it's worth, I got my RHCSA for RHEL6 earlier this year.  I'd have taken the RHCE, but my company was only paying for the RHCSA.  In any case, the exam was hard but fair.  I don't know if I'd even bother with the Linux+ exam on my way to RHCSA.  And now RHCSA is required for RHCE too, so in either case you're stuck with it.

The exam is 100% hands on, which means that you have to know your stuff (I passed with a 100% score, so I've got it covered).  I'm obviously bound by NDA, but I'll say that if you are planning to take the exam, you need to prepare by learning what is and isn't in the man pages on a default RHEL6 build.  Memorize what isn't and know where to find everything else.  Also, knowing how to get a broken system to the point where you can actually use a man page is probably a good idea....
5  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Mile2 says CPTE is a much better cert than CEH. True? on: October 14, 2011, 08:00:59 PM
CEH is great for HR only.  When I do technical interviews, I always ask CEH certified folks how they feel CEH has prepared them to work in security.  Those with other certs (who are on the level) usually tell me that it was a cake walk compared to cert X (besides say A+).  Those who only have the CEH regularly tell me how difficult it is and how they are totally prepared to audit, hack, or <insert random security buzzword here> my networks.  These people seriously oversell the certification.  Bottom line, book knowledge doesn't get you anything in security unless you can do it and CEH doesn't measure that.

I agree that OSCP/OSCE is the way to go.  I took the OSCE course and couldn't be happier.  I am yet to sit for the certification due to an insanely busy year, but will certainly hire those that have it over those that have CEH.
6  Resources / Career Central / Re: Secret Clearence already on: April 17, 2011, 02:02:02 PM
No offense, but a secret clearance doesn't really mean anything.  It sure doesn't cost 60k to fund one.

The cost of living at Ft Huachuca is near nil and you are competing with MI instructors with TS clearances and 20 years of experience.  GD underpays everywhere, but in this case 30k is a gift.  If you don't take it, someone else will.  IF you have real skills and want to make money, move to DC.  Of course you can't buy a house there....
7  EH-Net / News Items and General Discussion About EH-Net / Re: A Hacking Christmas to All, and to All a White Hat on: December 24, 2010, 10:05:33 PM
Amen to family time.  Merry Christmas all!
8  Resources / Tutorials / Re: Penetration testing updated windows 7 and bypassing kaspersky internet security on: November 25, 2010, 08:40:56 PM
Sorry dude.  I can't take 30+ minutes of Arabic to see what you are doing to "bypass KIS".  If you are talking about encoding, migrating processes, or simply killing the AV, I'd hardly call that a bypass though.
9  Resources / Tutorials / Re: Penetration testing updated windows 7 and bypassing kaspersky internet security on: November 25, 2010, 10:42:14 AM
If I only I spoke arabic, this would be a great resource.  Can you point me to the specific point in the video where you are bypassing KIS?
10  Ethical Hacking Discussions and Related Certifications / Programming / UAC bypass POC code on: November 24, 2010, 03:15:05 PM
Interesting non-coordinated disclosure of UAC bypass.  Any takers on how long this takes to get into metasploit?

http://www.codeproject.com/KB/vista-security/uac.aspx
11  EH-Net / Calendar Of Events / Re: ShmooCon 2011 on: October 25, 2010, 02:38:32 PM
Again, assuming I can get a ticket I'll be there as well.  I was working on a presentation for the conference but school got in the way and somehow passing became more important than presenting....
12  Ethical Hacking Discussions and Related Certifications / Web Applications / Re: How Application filtering in fire-wall works? on: October 12, 2010, 09:56:11 AM
It sounds like you might be trying to detect illicit software installs on your client machines.  There are much more reliable ways to do that than using a firewall.  Look at client side solutions to protect the endpoint.  These are much more reliable for detecting the sorts of changes you mention.
13  Ethical Hacking Discussions and Related Certifications / Incident Response / Re: My father is hacking me?! on: October 10, 2010, 03:15:33 PM
Reading comprehension ftw:

So the computer has RAS enabled so dad can help out when he's not around...  he doesn't need to be an NSA cracker.  He doesn't even need to be able to hack his way out of a paper bag.  He has access to the machine.  Full disk encryption won't fix that.  It won't even help.

If you are worried about him on the computer, get tech support somewhere else.

Edited:  fixed copy paste error induced by writing response from my droid....
14  Ethical Hacking Discussions and Related Certifications / Web Applications / Re: webapp pricing on: October 08, 2010, 02:37:44 PM
So I'll come full circle with my pricing guess-stimate for this type of work.  When I said $3k, that was a floor value.  I wouldn't expect anything less than that.  If you are doing your own pentests as an independent contractor, you have to cover your E&O insurance, business overhead, time lost negotiating and drawing up a contract, legal fees, etc.  To reflect on what H1t M0nk3y said, I don't think I'd take a week long test as an IC for $3k unless I were desperate for work.  Of course I've got full time job and as much side work as I can handle, YMMV.

One thing I would advise against is doing any pentesting as an IC without having insurance.  Either that or get incorporated.  Anything else and you stand to lose your shirt if something goes wrong (and eventually it will).
15  Ethical Hacking Discussions and Related Certifications / Web Applications / Re: webapp pricing on: October 07, 2010, 07:27:47 PM
Do you need a pen test, a white box code security review, both?  Do you need someone to hit the webapp from the outside or assess the security of the DB server on which the data resides?  They are very different things with very different pricing structures.  I sounds like you want the webapp tested from the outside.  That is cheaper than paying for code review since you can exploit an application without having to understand the code (much larger talent pool for that).  On the other hand, if someone can exploit your service, do you want them to be able to explain how to fix the problem?  You get what you pay for.

That being said, I don't do much webapp stuff and when I do pentesting I'm paid as an independent contractor to do specialty stuff.  I don't know the going rate for general pen testing or the whole package since I don't often interface with the customer.  I do know what I get paid though so I would guess you aren't getting out with any quality testing done for under $3k.
Pages: [1] 2 3 ... 16
Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.072 seconds with 21 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.