Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 127 guests and 2 members online
EH-Net News Feeds
Latest Additions
 
Advertisement

You are here: Home arrow Forum
EH-Net
February 10, 2012, 05:46:43 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Advertise on EH-Net!! - Reasonable Rates, Highly Targeted Audience.
 
  Home Help Calendar Login Register  
  Show Posts
Pages: [1] 2 3 ... 78
1  Ethical Hacking Discussions and Related Certifications / Web Applications / Re: How to test if website is writable on: December 20, 2011, 09:52:14 PM
check http allowed options and see if you can HTTP PUT or use webdav to write to a directory.
2  Ethical Hacking Discussions and Related Certifications / Mobile / Re: Using Mobile Devices For Pentesting on: December 20, 2011, 09:47:14 PM
you can do it but the keyboards on the tablets make things unfun to do anything serious.
3  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: msfencode on: November 29, 2011, 08:13:49 AM
here are a couple of links that may help

http://www.scriptjunkie.us/2011/04/why-encoding-does-not-matter-and-how-metasploit-generates-exes/

http://www.scriptjunkie.us/2011/08/custom-payloads-in-metasploit-4/

this thread from msf mailing list
http://mail.metasploit.com/pipermail/framework/2011-April/007630.html
4  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Hardware you should have during an onsite pentest? on: November 19, 2011, 10:11:37 AM
boot disk to change local admin passwords

something like the elcomsoft system recovery disk

http://www.elcomsoft.com/esr.html

5  Resources / Links to cool sites. / Re: Excellent resource for professional pentesting on: November 19, 2011, 10:04:53 AM
the technical guide will probably help too

http://www.pentest-standard.org/index.php/PTES_Technical_Guidelines

its more of the "how to do it" of the PTES
6  Resources / Career Central / Re: Remote work on: November 19, 2011, 10:03:20 AM
most of the security consultancies let you live anywhere and just fly when you need to go to customer's location. so having any airport reasonably close would be the only requirement.

you could check out fishnet, trustwave, rapid7, accuvant, etc
7  Columns / Gates / Re: [Article]-Oracle Web Hacking Part I on: April 26, 2011, 03:05:24 PM
so every web app is different from a default content point of view, privilege escalation, XSS, sqli would be dependent on both the backend DB and the oracle application itself.

hope that makes sense. 
8  Columns / Gates / Re: [Article]-Oracle Web Hacking Part I on: April 22, 2011, 09:27:44 PM
thanks Don!

questions or comments send them my way.
9  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Xen Testing on: November 12, 2010, 06:37:26 AM
they are metasploit modules.  maybe if you are more specific about where you are stuck?!
10  Ethical Hacking Discussions and Related Certifications / Web Applications / Re: Padding Oracle Vulnerability on: November 08, 2010, 02:56:48 PM
I have,
this is a pretty good writeup on it

http://blog.securitywhole.com/2010/10/21/net-padding-oracle-attack-padbusterpl-and-the-microsoft-recommended-workarounds.aspx
11  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Reverse shell on IIS 6.0 on: June 19, 2010, 08:47:41 AM
i've reread this post a few times to try to find the question but i think you are asking other ways to get files on the server.

obviously the blog post is about exploiting webdav shares or writeable shares via normal windows networking.  you could also use some of those techniques if a site allows file uploads as well.  the same caveats would *usually* apply that you cant upload .exe or .asp(x) files in that case it the bypass method may still work for you.

hope that helps

12  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Hacking Oracle on: June 19, 2010, 08:30:37 AM
you can check out my whitepaper from Blackhat to get you started

http://www.blackhat.com/presentations/bh-usa-09/GATES/BHUSA09-Gates-OracleMetasploit-PAPER.pdf

you may also need to check out the metasploit wiki to get the gem installed to use the oracle mixin

http://www.metasploit.com/redmine/projects/framework/wiki/OracleUsage
13  Ethical Hacking Discussions and Related Certifications / CEH - Certified Ethical Hacker / Re: DO I need math to become a hacker? on: June 19, 2010, 08:06:04 AM
you need to be able to count to 16
14  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: A cautionary tale for Penetration testers on live networks on: March 06, 2010, 07:42:39 PM
perhaps the takeaway from that experience should have been to not be able to lock out a service account that causes that amount of loss per hour. instead create a rule in their SEIM to alert on failed logins for those accounts as that should NEVER happen.

15  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Question when exploit target via metasploit ms08-06_netapi on: December 24, 2009, 11:49:00 AM
my guess is that the return is bad or something like DEP is preventing code execution. try manually setting the target.
Pages: [1] 2 3 ... 78
Powered by MySQL Powered by PHP Powered by SMF 1.1.16 | SMF © 2011, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.459 seconds with 22 queries.
 

gk_static-ad_feb2012.jpg
Global Knowledge Training: Build Security Skills to Protect and Defend

offsec_130x200-2_jan-feb2012.png
Offensive Security
AWE Live in the Caribbean!
March 5 - 9, 2012

SANS Deals 4 EH-Netters
$150 OFF Any SANS Course in Any Format!
Coupon Code: Refer_EHN
Including SANS Phoenix 2012, SANS 2012
Recent Forum Topics

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!

Vote For EH-Net

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2012 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.