Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 47 guests and 1 member online
 
Advertisement

You are here: Home
EH-Net
May 24, 2013, 02:13:13 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
  Home Help Calendar Login Register  
  Show Posts
Pages: 1 [2] 3 4
16  EH-Net / News Items and General Discussion About EH-Net / Re: Change is Coming to EH-Net!! on: April 08, 2013, 08:04:20 PM
This is exciting news. To answer your questions:

1. Definitely. Looking forward to it.

2. Not very much at all.

3. Unsure.

4. I'd be willing to help test.

5. If it means less spam, then yes, I'd be willing to help moderate. I work full time but I'm on EH pretty much everyday, so sure.

6. Not me forte.

7. Doesn't matter to me.
17  Ethical Hacking Discussions and Related Certifications / OSCP - Offensive Security Certified Professional / Re: Failed my first attempt at the OSCP exam on: April 07, 2013, 04:25:32 PM
I feel my weaknesses are changing shell code in exploits, and Windows privilege escalation in systems that are somewhat secure. That being Windows hosts that don't allow use of AT, etc.

Sorry to hear you didn't pass. Do you feel that you did better this time round than the last time though? You should still submit your lab + exam report as others have reported getting the certificate even though they didn't get all the points in the exam.

With regards to privilege escalation on Windows, perhaps the following links will be helpful if you haven't yet seen them:

http://obscuresecurity.blogspot.ca/2011/11/old-privilege-escalation-techniques.html
http://travisaltman.com/windows-privilege-escalation-via-weak-service-permissions/
http://www.room362.com/blog/2012/8/25/post-exploitation-command-lists-request-to-edit.html

Enumeration is key, sometimes you just need to find a misconfiguration somewhere or an exploitable program that will give you SYSTEM privileges.

As for writing exploits, practice is the only way to really learn it. I recommend reading the Corelan guides. the first few should suffice:

https://www.corelan.be/index.php/2009/07/19/exploit-writing-tutorial-part-1-stack-based-overflows/
https://www.corelan.be/index.php/2009/07/19/exploit-writing-tutorial-part-1-stack-based-overflows/
https://www.corelan.be/index.php/2009/07/25/writing-buffer-overflow-exploits-a-quick-and-basic-tutorial-part-3-seh/
https://www.corelan.be/index.php/2009/07/28/seh-based-exploit-writing-tutorial-continued-just-another-example-part-3b/

It definitely helps if you have your own lab to practice on. VulnHub.com has several vulnerable virtual machines you can practice on, and I recommend trying out sites such as https://hack.me/ and other war game sites such as http://www.overthewire.org/wargames/ and http://smashthestack.org/
18  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Using Metasploit on Kali Linux, the Evolution of BackTrack - Live webcast on: March 22, 2013, 05:19:21 PM
Any interesting highlights?

I didn't think so. Most of it was just an intro to Metasploit and information about Kali that's already on the Kali docs and FAQ.
19  Ethical Hacking Discussions and Related Certifications / OSCP - Offensive Security Certified Professional / Re: Failed my first attempt at the OSCP exam on: March 13, 2013, 10:28:24 AM
I scheduled my exam for April 6. I was shooting for a week earlier, but to get an 8:00am Saturday time slot, I had to schedule it a week later. That gives me an extra week. I have made good progress since my last attempt and think I will be ready.

All the best Smiley
20  Ethical Hacking Discussions and Related Certifications / OSCP - Offensive Security Certified Professional / Re: OSCP - Module 6 Buffer Overflows Question on: March 13, 2013, 10:04:05 AM
Well regarding the material, I was able to get the windows sample on the module plus aditional excercises from Vivek (mini share, FreeSSH, Easy Chat - SEH Based) plus Stephen Bradshaw material on info sec institute. Right now I can do this type of overflows in a really consistent manner plus a few others taken from the exploit DB that are not in the form of tutorials but I was able to adapt them to fit both Vivek and Stephen methodologies.

Sounds like you're ready. If you want more practice,  search for buffer overflows at Exploit-DB. In some cases, the vulnerable software is included so you can download it and recreate the exploit.

Hey! I checked your website and you have awesome material! One question regarding your pivoting series. if I want to recreate your setup do I have to use a GNS3 setup or can I use, say a 2003 server with RRAS configured to act as a router? I think this tutorials are great to avoid using metasploit for pivoting on the exam, in case you need to pivot, and maybe save the opportunity to use it for a harder machine! Thanks again for your amazing website!

You can use whatever setup you want really. The main thing is your pivot point (in my case the web server) has access to both networks and your attacking machine only has access to the web server. Glad you found the articles useful. Smiley
21  Ethical Hacking Discussions and Related Certifications / OSCP - Offensive Security Certified Professional / Re: OSCP - Module 6 Buffer Overflows Question on: March 12, 2013, 11:33:31 PM
Well regarding the material, I was able to get the windows sample on the module plus aditional excercises from Vivek (mini share, FreeSSH, Easy Chat - SEH Based) plus Stephen Bradshaw material on info sec institute. Right now I can do this type of overflows in a really consistent manner plus a few others taken from the exploit DB that are not in the form of tutorials but I was able to adapt them to fit both Vivek and Stephen methodologies.

Sounds like you're ready. If you want more practice,  search for buffer overflows at Exploit-DB. In some cases, the vulnerable software is included so you can download it and recreate the exploit.
22  Ethical Hacking Discussions and Related Certifications / OSCP - Offensive Security Certified Professional / Re: Failed my first attempt at the OSCP exam on: March 06, 2013, 10:23:29 AM
I have been on the bench since the end of December and I have a pentest next week and it will last three weeks. My over abundance of study time will be reduced, but I look forward to using what I have learned in the upcoming pentest. PWB has been very educational and I have improved a lot since I started my job as a pentester last April.

Hey as long as you keep learning, it's not a total loss Smiley I assume you'll be tackling the exam again?
23  Ethical Hacking Discussions and Related Certifications / OSCP - Offensive Security Certified Professional / Re: Failed my first attempt at the OSCP exam on: February 17, 2013, 11:51:06 PM
When I was doing the lab, I had pretty good luck with the RockYou wordlist found here: http://www.skullsecurity.org/wiki/index.php/Passwords

However, it is a huge list and it's unlikely you'll be able to use it all in the limited time you have for the exam. Better to start off with a smaller list - like the one you created as you were going through the machines in the lab.
24  Ethical Hacking Discussions and Related Certifications / Malware / Re: Joe McCray's Exploit Development Workshop on: February 12, 2013, 10:22:37 AM
Uh, I think I'll take a pass on Mr. McCray's offerings...

Wow, reads like an article in the enquirer.
http://strategicsec.com/2013/02/12/the-final-statement-on-this-issue/
Quote
At this point I didn’t care anymore, I was so angry with him for being such a cowardly bitch that I couldn’t stand it. I swore that the next time I see him there was gonna be some furniture moving. Yes ChrisJohnRiley THIS IS THE NEW BLACK I was 2 seconds away from whooping  Saumil’s ass. I was ready to put my foot so far up his ass that his breath would smell like shoe polish!

I told him explicitly (yes that means I dropped a lot of F-Bombs) how I felt, and that I’m not paying him the remaining money because he and Hiren are both some bitches.  After that – all of these notes I rewrote, scripts I ported from perl to python, lab manuals that I wrote – for him as a gift to show my appreciation that he mentions in his blog post, and yes his precious virtual machines – I used them in classes, webinars, and workshops I taught. I did it to spite him. I was pissed at him – immature I realize – but at least it’s the truth. I might as well try to make my money back after all of this mess.

Saumil and anybody else for that matter – you can write whatever you want about me. You can put me on what ever page you want, talk about me on twitter, but at the end of the day Saumil can have a hot steamy cup of FUCK YOU! At this point I flat out don’t care how many people you tell, how many people talk about this on twitter. I hope that every single human being on this earth learns how much of a whining wimpy little bitch you are, and knows that I can’t stand you and I would rather eat hot shit before I’d even acknowledge that you are a fucking human being let alone speak to you.

No I’m not paying you, and I sincerely feel bad for every single incident of a people loosing respect for me with regard to this issue, I know that I will never do it again because there is no HUMAN being that would ever be the way that he was to me, but I refuse to continue to talk to people like you are a good person when I know you are not.

So Saumil, and Hiren – I just want you to know what I think of you personally, and professionally.

From the bottom of my heart…

FUCK YOU!

Joe

Daaayuuum...
25  Ethical Hacking Discussions and Related Certifications / Malware / Re: Joe McCray's Exploit Development Workshop on: February 11, 2013, 09:16:41 PM
If you haven't heard, Mr. McCray is in a bit of hot water in regards to this course...Google full fu. (Damn dumbphone)

Just read the blog posts on it. Bit disappointing. Still, I hope he comes up with his own material and starts over.
26  Ethical Hacking Discussions and Related Certifications / Programming / Re: List of free programming books on: February 07, 2013, 07:09:14 AM
Haven't seen that one before. Thanks for sharing.
27  Ethical Hacking Discussions and Related Certifications / OSCP - Offensive Security Certified Professional / Re: I passed OSCP !! on: February 04, 2013, 05:14:47 PM
Congratulations Smiley
28  Resources / Tutorials / Re: introduce me exploitation books on: February 04, 2013, 05:13:45 PM
AoE is an introduction to exploitation, but doesn't cover trickier exploits. If you've never written an exploit before, this is a good book to start with. However - you'll find that to exploit certain programs you encounter in the wild, you may need to write bits of assembly to get execution flow to hop around memory and eventually hit your shellcode. To do this, you'll need to know assembly.
29  Resources / Tutorials / Re: introduce me exploitation books on: February 02, 2013, 11:09:29 PM
If you're looking for a book, Hacking: The Art of Exploitation is an excellent one that covers exploitation of Linux programs in C. You'll also find numerous exploitation tutorials on Google.
30  Ethical Hacking Discussions and Related Certifications / Programming / Re: Complete newbie on: January 31, 2013, 04:15:23 PM
Sorry, I have been busy since I made the post lol. But I have started working on the links in the first post. thank you very much for the replies. I do have one more question though, i am not "Terrible" at typing, but i never learned it from a program and want to get better and if any of you have advice on a free program i could use if any, i would appreciate it very much.

Never learned it from a program either. All you need to know are the home keys and which keys are controlled by which finger (see http://en.wikipedia.org/wiki/File:Touch_typing.svg). Anyway, you can google for online typing tutors. There are a few out there that are decent and should get the job done. Practice makes perfect.
Pages: 1 [2] 3 4
Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.075 seconds with 21 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.