Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 23 guests and 1 member online
 
Advertisement

You are here: Home
EH-Net
May 21, 2013, 08:25:45 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
  Home Help Calendar Login Register  
  Show Posts
Pages: [1] 2 3 ... 7
1  Ethical Hacking Discussions and Related Certifications / Hardware / Re: device/system selection on: December 15, 2011, 10:11:40 AM
Have you tried a tap?

http://www.flukenetworks.com/enterprise-network/network-monitoring/Tap-Solutions

http://www.network-taps.eu/products/products_networktaps.php
2  Resources / Tutorials / Re: metasploit how to show exploits on: November 17, 2011, 10:38:47 AM
maybe you should take the time to do some research:

http://www.offensive-security.com/metasploit-unleashed/Msfconsole_Search_Command

There's a lot of good resources out there and a great site called Google
3  Ethical Hacking Discussions and Related Certifications / Web Applications / Re: secure methods for posting data from webpages on: November 17, 2011, 10:00:57 AM
Quote
What I am looking for is a pointer to best and secure methods for getting and sending data from the forms on the html pages to the web browser to the server, etc. I want any and all data that is visible in the address bar to be as discreet as possible. Of course, I would also like any sniffed data to also be discreet.

Then, just like cd1zz said, use SSL. Encryption will provide you all that.

Quote
I would assume that one practice is to make data values have obscure names

"security through obscurity" is not advisable at all.

Quote
Basically this impresses me because a lot of information seems hidden from the user and I want to learn how to do something similar in my own web-based data systems.

You not being able to see something doesn't mean that it isn't there and somebody can't reach it.
4  Resources / Tutorials / Re: apache pen test on: November 14, 2011, 02:09:54 PM
Quote
i dont know perl programming language but i can use perl apps and i know html

PenTesting is not about being able to run apps, you need to know how things work and what you're doing, then you can use tools.
5  Resources / Tutorials / Re: apache pen test on: November 14, 2011, 11:48:32 AM
Quote
i searched exploit-db.com and i found some perl exploit but its not runing on backtrack

If you don't manage to make the exploit run, I guess you don't even know how it works and what it does, it sounds like a very bad idea...
6  Ethical Hacking Discussions and Related Certifications / Programming / Re: Perl help need on: November 14, 2011, 10:33:44 AM
If you already have the list of URLs, then it's only matter of comparing your var against a pattern (your regular expression). In Perl the =~ operator is the one you'll use. You can use a capturing group (parentheses operators) to get your number into a var. I hope you're following me
7  Resources / Tutorials / Re: a question about metasploit on: November 11, 2011, 01:08:22 PM
The "best" payload to use will depend on you scenario.

http://www.offensive-security.com/metasploit-unleashed/Payload_Types
8  Ethical Hacking Discussions and Related Certifications / Programming / Re: Perl help need on: November 11, 2011, 11:44:25 AM
I'm not getting exactly what's the problem you're facing. Do you already have the list with URLs but you don't find one that contains the pattern you want?
9  Ethical Hacking Discussions and Related Certifications / Programming / Re: Perl help need on: November 11, 2011, 10:00:31 AM
Certainly you can. Perl is a very powerful language for text processing. If you have your list of URLs in a file, you can load all the contents into an array in a single operation an then traverse the array looking for an array that matches your RE, or you can can read your file line by line and compare it to the RE. You can even extract the specific part you are interested on (the number) from the string when you are comparing against your RE. Be careful how you use the ^ and $.
10  Ethical Hacking Discussions and Related Certifications / Programming / Re: Perl help need on: November 09, 2011, 12:37:08 PM
By "without download each page" you mean not writing to a file on disk the page and instead keep the contents in a variable? Yes you can, the same way you can with wget (you can dump the page to STDOUT). Check the LWP library, maybe there are many more, it's been a while since I used Perl.
11  Ethical Hacking Discussions and Related Certifications / Programming / Re: Reverse engineering non-executable files on: October 27, 2011, 10:25:33 AM
The tools you will use will depend on the type of files you're working with and what you want to achieve. The most basic tools are strings, file and hex editors. It's very common to find compressed data, so then you'll have to user some other tools. For a very good example read the next post:

http://www.devttys0.com/2011/05/reverse-engineering-firmware-linksys-wag120n/
12  Ethical Hacking Discussions and Related Certifications / Programming / Re: Reverse engineering non-executable files on: October 26, 2011, 04:18:00 PM
RE is a way to get some knowledge about the workings of something, so you can. There are good tools for both platforms.
13  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: nmap output interpretation? on: October 25, 2011, 10:31:13 AM
Quote
unless you come across something like this: 192.168.0.0/27  Angry

Then your broadcast is 192.168.0.31 and network is 192.168.0.1

This is usually true, there are some cases where the network address works as broadcast tough

http://www.whitehats.ca/main/members/Jeff/gcia_assign_2/gcia_assign_2.html

http://www.netbsd.org/docs/guide/en/chap-net-practice.html#chap-net-practice-kernel-options
14  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Question with SNMP Enumeration on: October 19, 2011, 10:24:01 AM
You should start learning how SNMP works and what MIBs and OIDs are
15  Ethical Hacking Discussions and Related Certifications / Other / Re: Xx Xploits xX on: October 18, 2011, 10:03:06 AM
Code:
Are there any good tutorials for writing web based exploits for beginners?

Saying you want to learn to write exploits is way too generic, even for web based ones. What do you want to focus on? SQLi, XSS, CSRF, RFI/LFI, auth bypass...? You should start by taking a look at OWASP.
Pages: [1] 2 3 ... 7
Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.071 seconds with 21 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.