Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 25 guests and 1 member online
 
Free Business and Tech Magazines and eBooks

You are here: Home
EH-Net
May 25, 2013, 01:20:54 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
  Home Help Calendar Login Register  
  Show Posts
Pages: 1 ... 73 74 [75] 76 77 78
1111  Ethical Hacking Discussions and Related Certifications / General Certification / Decent Sec+ Study Guide for SY0-201 (aka 2008) exam? on: September 25, 2009, 12:18:17 PM
I kind of feel like this has been hashed over in different threads but after talking with Ryan Linn in IRC (you guys should come join us, the channel is lonely) he suggested starting this topic.

I'm looking for a good study guide for the Security+ 2008 / SY0-201 exam. I'm looking for something that will fill in the gaps in my knowledge while pre-paring me for the exam. I'm also not looking to just pass the exam and say I'm certified, I want to know more about security by the time I"m done.

So, what are your opinions on the current Security+ study guides out there? Are there ones you like more than others, which ones do you think are worth their salt?
1112  Ethical Hacking Discussions and Related Certifications / Wireless / Re: hacking wireless network at school...help! on: September 20, 2009, 07:11:20 PM
(going to jump on the bandwagon here)

This is Ethical Hacker, if you want to be one, maybe you should learn what a firewall is used for and why the owners would chose to block the sites they do.
1113  Ethical Hacking Discussions and Related Certifications / Other / Re: How you got into Hacking? on: September 20, 2009, 06:56:25 PM
My family always pushed me towards computers my whole life. Had one in 84 at the age of 7. When I was 19, I was lucky enough to be working for one of the "Original Six Backbone Providers". The part of securing the network interested me, especially after the network got hacked. Several years later, I was lucky enough to get a job where my duties involved using Network General's Sniffers and Infinistream, as well as doing wireless audits for rouge equipment on site.
1114  Ethical Hacking Discussions and Related Certifications / Other / What should one expect from a local Security group? on: September 16, 2009, 02:48:10 PM
I hope this is an easy question.

What is the type of things you'd expect to find at your local Security Group meeting? I looked for a local DC group, but DC734 recently changed to ArbSec. Partly because it wasn't what people were expecting.

To be fair, I've only been to one meeting so far, but all they did was sit around BSing and picking locks at a local bar. The bar didn't even have space set up for the group.

I've been told they are supposed to have a standing reservation and that the September meeting was a fluke. They also said they try to have a guest speaker but with end of the summer things got a little kerfuffled.

When I asked about the name change another person there said it was because people were traveling long distances but not finding what they thought a DC group should be doing. (He didn't say what that was though).

I've seen the posts by Good_4sh about some of the fun things they do there, and just wondering what should a person expect to see?

(edit: changed the topic slightly to better fit my question).
1115  Columns / Linn / Re: [Article]-Review: Penetration Testing with BackTrack by Offensive Security Part 2 on: September 14, 2009, 04:15:20 PM
Might be a silly question, but are these instructor led or video led? Is there someone there saying do this in this time frame etc, and available on the spot to answer questions?
1116  Ethical Hacking Discussions and Related Certifications / Web Applications / Re: Which chat (IM) app do you use? on: September 14, 2009, 01:18:22 PM
For work related IM, we're using google's talk, with pidgin and the encryption plug-in. It's only partly set up in the company though. Not everyone is using it. With our facility move (moving from one large location to 3 smaller ones) my department won't have the time to push for everyone to start using it.
1117  Ethical Hacking Discussions and Related Certifications / Other / Re: Recommendations for IRC servers/ channels wanted on: September 10, 2009, 12:56:07 PM
Well, lets try an experiment.   I just created an joined a channel #ehnet on EFNet.   Let's see if anyone pops up today.

I'll try to pop in tonight. I usually hang out on p2p-net though.
1118  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Hydra with Domain Controller on: September 07, 2009, 10:16:25 AM
impelse,

Sounds like a case of false positives to me. You could try to do the smb option, see if the results differ. You could try the same set up again, and see if it comes back with a different username and password.
1119  Ethical Hacking Discussions and Related Certifications / Physical Security / Re: Windows sever 2008 security expert needed URGENTLY. 911. Help please. on: September 06, 2009, 07:50:05 PM
Two things we've done in the past at work (xp and S2003), was use Trinity Rescue Kit (trk), and Knoppix 5.1. TRK might be easier, I've had it work on 64 bit and 32 bit systems.

TRK's user guide says how to use it to reset admin password. There are guides out there (google is good) on how to use a Linux Live CD to reset a window admin password.
1120  Resources / Tutorials / Re: New EH on: September 06, 2009, 02:45:27 PM
basic

you should be able to get the network card's drivers off the HP site. Does it work with a linux live cd?
1121  Resources / Tools / Re: Modem and phone pentesting tools? on: September 05, 2009, 07:30:05 PM
I'll probably not be much help on this one, down side to being a noob, but have you looked at:

ToneLoc or THC-Scan?

Kevin Beaver, in Hacking for Dummies, says he likes ToneLoc. Not having a phone line, I can't really test any. I'm not even sure the modem in my laptop works with my Debian Linux install.

(I'm waiting for someone to laugh at me now).  Smiley
1122  EH-Net / News Items and General Discussion About EH-Net / Re: Open Discussion: What Courses Should EH-Net Review and Who Should Do Them? on: September 05, 2009, 03:26:59 PM
While not exactly on topic, what I'd like to see, from a stand point of just starting out is a "easy challenge" section. Something less powerful than the monthly challenge and more like what SANs did the other week with the pcap file for Sec558.

When it was first posted, all I knew was how to load the pcap into wireshark and look for information, but between the 2 threads here, I was able to figure out how to go through all the other 6 steps (stopped before scripting it).

That way multiple people could post their solutions (written up as a howto for future users), find out what they did wrong, what they did right and we get to see other people's writing styles.

I could see a section like that getting mis-used / abused by script kiddies and black hats starting out, but as others have said (thinking Hacking for Dummies and Firewalls and Internet Security) the black hats have their communication channels. It's better to share with the white hats and get people better at security.

But this is just my view.
1123  Resources / Tutorials / Re: Hacking (harvesting) email addresses tutorial please! on: September 05, 2009, 03:14:57 PM
Chris G's method would be great, I'll have to add it to my list.  Google + site's domain name would be another way. 1 search google for just the site, 2 search google for just the @domain_name.

I think the big question is though, why do want the email address?

From a pentest perspective, I could see collecting the different email addresses for trying to get possible log in names, or people in the company to try and impersonate for Social Engineering.

From a security standpoint to see if people are spoofing your comapny / found an open relay.

From a non-security related world, the only legal reason I could see doing this would be for an EECB (Executive Email Carpet Bomb). http://consumerist.com/259713/how-to-launch-an-executive-email-carpet-bomb

There are other methods, if I recall correctly, covered in Hacking for Dummies. But you really should only try to get email address for ETHICAL reasons. Spamming people is bad. Trying to get the information for just showing of is bad too.
1124  Columns / Linn / Re: [Article]-Review: Penetration Testing with BackTrack by Offensive Security Part 1 on: September 05, 2009, 11:11:59 AM
Ryan,
Are you running backtrack as a virtual machine, or on a dedicated computer for this class?
1125  Ethical Hacking Discussions and Related Certifications / Other / Re: Preferred SIEM on: September 04, 2009, 06:08:07 PM
After demoing the two products I like Loglogic the best.  We also demoed Cisco MARS and wasn't nearly as impressed as I was the Loglogic.


I use Cisco MARS at work, even have a few books on it at home, but have found the the web interface and the over all control of it kludgy. It was in place before I started, and it became mine shortly there after. It's better than nothing, but sometimes I wish it could do more. (or I knew how to make it sing and dance the way I want).
Pages: 1 ... 73 74 [75] 76 77 78
Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.091 seconds with 21 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.