Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 47 guests and 1 member online
 
Free Business and Tech Magazines and eBooks

You are here: Home
EH-Net
May 25, 2013, 07:57:46 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
  Home Help Calendar Login Register  
  Show Posts
Pages: 1 2 [3] 4 5 6
31  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Cloud Computing - Formulating an EH Methodology for Cloud Computing on: February 04, 2010, 01:58:21 PM
Muss gave a great presentation at Kiwicon about the state of security of most shared web hosting providers and it didn't paint a pretty picture.
So when I read hayabusa's example of defaced websites I could almost visualise what exactly happened.
32  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Cloud Computing - Formulating an EH Methodology for Cloud Computing on: February 03, 2010, 07:29:35 PM
I don't work in the security industry but I do work in sys admin with a heavy focus towards virtualisation and cloud computing.

This sort of topic is something I face very much every day from my management and my clients.

I don't have anything specific to add to the discussion but I do want to bring up that going to the cloud you are essentially outsourcing your IT. Or at least part of the infrastructure.
Is that acceptable to your organisation?

In relation to your question, I don't see cloud computing to be much different to any other computing system. If your cloud apps are web applications, for instance a business I look after uses Xero a web based accounting software package, then you are just pen testing a web app. If your definition of cloud computing revolves around virtualisation then the only added component I would say would be that you need to also test the hypervisor layer.

Just some things to think about.
33  Ethical Hacking Discussions and Related Certifications / CEH - Certified Ethical Hacker / Re: CEH Cert on: January 27, 2010, 09:11:13 PM
One of the big things IMO that separates a pen tester, who just knows how to run a tool and use automated scans vs a great pen tester is the ability to write your own exploits.

One of the best frameworks for developing exploits currently is metasploit and if you want to write modules for metasploit you must be able to write code in ruby.

Advanced hacking courses like OCSE and CEPT etc devote a large amount of their curriculum to coding. Not simply writing the exploit code but things like fuzzing and learning the nuances of x86 assembly.
34  Ethical Hacking Discussions and Related Certifications / CEH - Certified Ethical Hacker / Re: CEH Cert on: January 27, 2010, 03:20:51 PM
I think you need to at least be able to code in python/ruby in order to be a good pen tester. I just can't see how you can be a good pentester without being able to write your own exploits.
35  Ethical Hacking Discussions and Related Certifications / CEH - Certified Ethical Hacker / Re: Is CEH Right for me? on: January 20, 2010, 03:15:08 PM
Do you want to do management stuff in information security or do you want to do penetration testing.

I think that really sums it up. Also once you complete your CEH, I think it really only starts you on a path, it doesn't really mean you can do a complete pen test.

So what do you want to do, INFOSEC management or penetration testing?
36  Resources / Tools / Re: BackTrack 4 Final Release is out on: January 19, 2010, 02:40:34 PM
Everything about backtrack 3 was designed to run on low spec hardware. It uses older versions of kde (old even for those days) to reduce memory footprint for instance.

I've found bt4 to be more memory and processor intensive. One of their goals was to transition the distro from a live cd to more installed friendly and they are clearly taking advantage of increased hardware specs.

I think you are going to struggle running the vmware version on your machine, I would suggest installing it instead.
37  Resources / Tools / Re: BackTrack 4 Final Release is out on: January 12, 2010, 05:19:43 PM
Will try installing it in VMware, looks good so far.

One of the best things about backtrack is that they provide a pre-formatted vmdk.

Sometimes with extra goodies in it as well.

Downloading now, should be done when I get home.
38  Ethical Hacking Discussions and Related Certifications / General Certification / Re: Top 10 Certifications for 2010 on: January 10, 2010, 03:12:14 PM
I'm frankly not suprised by CISSP and CISM. Having either one usually makes one's CV stand out to the HR department.
39  Ethical Hacking Discussions and Related Certifications / General Certification / Re: CEH or GPEN more attractive to employers? on: January 10, 2010, 03:09:19 PM
I decided to do the CEH/ECSA/LPT route as it was vastly more affordable than GIAC certs.

I think I could probably do the GPEN without attending the course as long as I had access to the study books. Once I am done with CEPT I think I might give that a go.

(Shameless plug, if anyone would like to sell me their recent GIAC study materials, please send me a PM.)

However the GIAC GWAPT course looks interesting. Not many options out there which focuses on web apps.
40  Ethical Hacking Discussions and Related Certifications / General Certification / CPT/CEH Infosec Institute on: December 21, 2009, 06:09:54 PM
I received an email from Jack at infosec earlier in the month. They have a new training portal up.
Logging onto it it seems to be a totally updated and refreshed version of their CPT/CEH Ethical Hacking course.

Not very useful for me since I have already done the certs but I'll be perusing through the update material and will let you guys know what I think of it compared to the previous version.

At the beginning it already looks much more polished.
41  Ethical Hacking Discussions and Related Certifications / CPTC - Certified Penetration Testing Consultant / Re: Why CEPT cert is not know? on: December 17, 2009, 04:23:53 PM
The course is good. The CEPT cert is more like a test at the end of the course to verify that you have learnt the course material.
It would be awesome if it had more clout but at the moment I don't see an isue that it isn't as widely known as CEH or ECSA etc.

IMO just get those too. Hell even infosec says you should achieve them.
42  Ethical Hacking Discussions and Related Certifications / CPTC - Certified Penetration Testing Consultant / Re: Why CEPT cert is not know? on: December 15, 2009, 08:41:23 PM
I'm doing it. Nothing wrong with the course.
43  Ethical Hacking Discussions and Related Certifications / Other / Re: Kiwicon 2009 on: November 26, 2009, 07:56:06 PM
Well Kiwicon is almost here.

Looking forward to the line up some of the presentations look very cool.

I'll post anything interesting here, when I get home to my computer of course!
44  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Advice on switching to a security focused career on: November 25, 2009, 03:21:35 PM
I truly believe that pentesting as a career is one of the few IT specialties (if you can call it a specialty) where knowing about everything is as synergistic as specialising in one thing.

Because so much of security in IT requires a healthy dose of creativity, insight and experience you never know when that little tidbit of knowledge will come in handy.

I trained to become a network engineer. Did that for a little while and then moved into system administration.
I have plans in the near future to focus on a programming language or two.

So I've come from a different perspective but in the end I will hopefully end up with a strong skillset in networking, system administration and programming.
45  Ethical Hacking Discussions and Related Certifications / CEH - Certified Ethical Hacker / Re: windows penetration testing on: November 24, 2009, 08:34:49 PM
Get thomas wilhelm's book Professional Penetration Testing. I just received my copy yesterday and while the first couple of chapters haven't taught me anything yet I think the book would of been awesome when I first started out.
Pages: 1 2 [3] 4 5 6
Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.073 seconds with 21 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Free Business and Tech Magazines and eBooks

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.