 |
| |
| |
|
Who's Online |
|
We have 47 guests and 1 member online |
|
| |
|
|
 |
|
EH-Net
|
|
May 24, 2013, 02:13:13 PM
|
Show Posts
|
|
Pages: 1 [2] 3 4
|
|
16
|
EH-Net / News Items and General Discussion About EH-Net / Re: Change is Coming to EH-Net!!
|
on: April 08, 2013, 08:04:20 PM
|
|
This is exciting news. To answer your questions:
1. Definitely. Looking forward to it.
2. Not very much at all.
3. Unsure.
4. I'd be willing to help test.
5. If it means less spam, then yes, I'd be willing to help moderate. I work full time but I'm on EH pretty much everyday, so sure.
6. Not me forte.
7. Doesn't matter to me.
|
|
|
|
|
20
|
Ethical Hacking Discussions and Related Certifications / OSCP - Offensive Security Certified Professional / Re: OSCP - Module 6 Buffer Overflows Question
|
on: March 13, 2013, 10:04:05 AM
|
Well regarding the material, I was able to get the windows sample on the module plus aditional excercises from Vivek (mini share, FreeSSH, Easy Chat - SEH Based) plus Stephen Bradshaw material on info sec institute. Right now I can do this type of overflows in a really consistent manner plus a few others taken from the exploit DB that are not in the form of tutorials but I was able to adapt them to fit both Vivek and Stephen methodologies.
Sounds like you're ready. If you want more practice, search for buffer overflows at Exploit-DB. In some cases, the vulnerable software is included so you can download it and recreate the exploit. Hey! I checked your website and you have awesome material! One question regarding your pivoting series. if I want to recreate your setup do I have to use a GNS3 setup or can I use, say a 2003 server with RRAS configured to act as a router? I think this tutorials are great to avoid using metasploit for pivoting on the exam, in case you need to pivot, and maybe save the opportunity to use it for a harder machine! Thanks again for your amazing website! You can use whatever setup you want really. The main thing is your pivot point (in my case the web server) has access to both networks and your attacking machine only has access to the web server. Glad you found the articles useful. 
|
|
|
|
|
21
|
Ethical Hacking Discussions and Related Certifications / OSCP - Offensive Security Certified Professional / Re: OSCP - Module 6 Buffer Overflows Question
|
on: March 12, 2013, 11:33:31 PM
|
Well regarding the material, I was able to get the windows sample on the module plus aditional excercises from Vivek (mini share, FreeSSH, Easy Chat - SEH Based) plus Stephen Bradshaw material on info sec institute. Right now I can do this type of overflows in a really consistent manner plus a few others taken from the exploit DB that are not in the form of tutorials but I was able to adapt them to fit both Vivek and Stephen methodologies.
Sounds like you're ready. If you want more practice, search for buffer overflows at Exploit-DB. In some cases, the vulnerable software is included so you can download it and recreate the exploit.
|
|
|
|
|
24
|
Ethical Hacking Discussions and Related Certifications / Malware / Re: Joe McCray's Exploit Development Workshop
|
on: February 12, 2013, 10:22:37 AM
|
Uh, I think I'll take a pass on Mr. McCray's offerings... Wow, reads like an article in the enquirer. http://strategicsec.com/2013/02/12/the-final-statement-on-this-issue/At this point I didn’t care anymore, I was so angry with him for being such a cowardly bitch that I couldn’t stand it. I swore that the next time I see him there was gonna be some furniture moving. Yes ChrisJohnRiley THIS IS THE NEW BLACK I was 2 seconds away from whooping Saumil’s ass. I was ready to put my foot so far up his ass that his breath would smell like shoe polish!
I told him explicitly (yes that means I dropped a lot of F-Bombs) how I felt, and that I’m not paying him the remaining money because he and Hiren are both some bitches. After that – all of these notes I rewrote, scripts I ported from perl to python, lab manuals that I wrote – for him as a gift to show my appreciation that he mentions in his blog post, and yes his precious virtual machines – I used them in classes, webinars, and workshops I taught. I did it to spite him. I was pissed at him – immature I realize – but at least it’s the truth. I might as well try to make my money back after all of this mess.
Saumil and anybody else for that matter – you can write whatever you want about me. You can put me on what ever page you want, talk about me on twitter, but at the end of the day Saumil can have a hot steamy cup of FUCK YOU! At this point I flat out don’t care how many people you tell, how many people talk about this on twitter. I hope that every single human being on this earth learns how much of a whining wimpy little bitch you are, and knows that I can’t stand you and I would rather eat hot shit before I’d even acknowledge that you are a fucking human being let alone speak to you.
No I’m not paying you, and I sincerely feel bad for every single incident of a people loosing respect for me with regard to this issue, I know that I will never do it again because there is no HUMAN being that would ever be the way that he was to me, but I refuse to continue to talk to people like you are a good person when I know you are not.
So Saumil, and Hiren – I just want you to know what I think of you personally, and professionally.
From the bottom of my heart…
FUCK YOU!
Joe Daaayuuum...
|
|
|
|
|
28
|
Resources / Tutorials / Re: introduce me exploitation books
|
on: February 04, 2013, 05:13:45 PM
|
|
AoE is an introduction to exploitation, but doesn't cover trickier exploits. If you've never written an exploit before, this is a good book to start with. However - you'll find that to exploit certain programs you encounter in the wild, you may need to write bits of assembly to get execution flow to hop around memory and eventually hit your shellcode. To do this, you'll need to know assembly.
|
|
|
|
|
29
|
Resources / Tutorials / Re: introduce me exploitation books
|
on: February 02, 2013, 11:09:29 PM
|
|
If you're looking for a book, Hacking: The Art of Exploitation is an excellent one that covers exploitation of Linux programs in C. You'll also find numerous exploitation tutorials on Google.
|
|
|
|
|
30
|
Ethical Hacking Discussions and Related Certifications / Programming / Re: Complete newbie
|
on: January 31, 2013, 04:15:23 PM
|
Sorry, I have been busy since I made the post lol. But I have started working on the links in the first post. thank you very much for the replies. I do have one more question though, i am not "Terrible" at typing, but i never learned it from a program and want to get better and if any of you have advice on a free program i could use if any, i would appreciate it very much.
Never learned it from a program either. All you need to know are the home keys and which keys are controlled by which finger (see http://en.wikipedia.org/wiki/File:Touch_typing.svg). Anyway, you can google for online typing tutors. There are a few out there that are decent and should get the job done. Practice makes perfect.
|
|
|
|
|
Loading...
|
|
 |
|