Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 56 guests and 1 member online
EH-Net News Feeds
Latest Additions
 
Advertisement

You are here: Home arrow Forum
EH-Net
May 21, 2012, 03:04:56 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Advertise on EH-Net!! - Reasonable Rates, Highly Targeted Audience.
 
  Home Help Calendar Login Register  
  Show Posts
Pages: 1 ... 62 63 [64] 65 66
946  Resources / Tutorials / Re: Hacking (harvesting) email addresses tutorial please! on: September 05, 2009, 03:14:57 PM
Chris G's method would be great, I'll have to add it to my list.  Google + site's domain name would be another way. 1 search google for just the site, 2 search google for just the @domain_name.

I think the big question is though, why do want the email address?

From a pentest perspective, I could see collecting the different email addresses for trying to get possible log in names, or people in the company to try and impersonate for Social Engineering.

From a security standpoint to see if people are spoofing your comapny / found an open relay.

From a non-security related world, the only legal reason I could see doing this would be for an EECB (Executive Email Carpet Bomb). http://consumerist.com/259713/how-to-launch-an-executive-email-carpet-bomb

There are other methods, if I recall correctly, covered in Hacking for Dummies. But you really should only try to get email address for ETHICAL reasons. Spamming people is bad. Trying to get the information for just showing of is bad too.
947  Columns / Linn / Re: [Article]-Review: Penetration Testing with BackTrack by Offensive Security Part 1 on: September 05, 2009, 11:11:59 AM
Ryan,
Are you running backtrack as a virtual machine, or on a dedicated computer for this class?
948  Ethical Hacking Discussions and Related Certifications / Other / Re: Preferred SIEM on: September 04, 2009, 06:08:07 PM
After demoing the two products I like Loglogic the best.  We also demoed Cisco MARS and wasn't nearly as impressed as I was the Loglogic.


I use Cisco MARS at work, even have a few books on it at home, but have found the the web interface and the over all control of it kludgy. It was in place before I started, and it became mine shortly there after. It's better than nothing, but sometimes I wish it could do more. (or I knew how to make it sing and dance the way I want).
949  Ethical Hacking Discussions and Related Certifications / Forensics / Re: Forensics Tools - strap on your util belt on: September 04, 2009, 11:55:22 AM
We've used Helix 3 for a couple of issues at work. They were internal issues, that did go to legal. (It's also what started me down the path that has lead me here).

I'd love to get my hands on EnCase, and learn more, but I'd probably have to buy it myself. I don't know how well Helix works compared to EnCase, but it's worked for what we've needed so far.
950  Features / Book Reviews / Re: Hacking For Dummies 3rd edition? on: August 31, 2009, 11:03:43 PM
I used my Safari account and started reading the 2nd edition. I've only got a little way in, in the first part of the book (first 2 chapters down). Kind of wish I bought the second edition now. So far it's been an easy read. I expect that to change in part 2.

Really enjoying the book though. Even if I do finish it before 3rd comes out, I'll probably buy third and read that too.
951  Ethical Hacking Discussions and Related Certifications / Web Applications / Re: Web app attacks and using web shells on: August 31, 2009, 05:53:31 PM
And PDFs don't make you paranoid?  Wink

Don

Not as paranoid, I know about word macros and the easiness of having the word doc do other things. The pdf as an entry vector I don't know about. Doesn't mean it doesn't exist, just that I have more to learn.
952  Ethical Hacking Discussions and Related Certifications / Web Applications / Re: Web app attacks and using web shells on: August 31, 2009, 11:53:50 AM
Does he ever release in PDF format? Call me paranoid, but I don't like downloading .doc files from the interwebs. Smiley
953  Ethical Hacking Discussions and Related Certifications / General Certification / Re: Sec+ on: August 30, 2009, 08:53:44 PM
That review guide was one of the books I was looking at. I was looking at the deluxe study guide and another book that makes up the study pack (With the regular study guide). I checked my local library and they have very few books on the subject (read none on sec+).

As for scheduling the test for a month out and forcing the study, that didn't work with my CCNA the last time I took it. I kept pushing it out. Didn't study well either, and never had anything hands on (it had been 4 years since I touched a switch or router at the time). I even had a job depending on me getting my CCNA and still managed to fail because I didn't take my study seriously.

When I'm serious about studying, I can do even the boring parts, just takes forever to read.
954  Ethical Hacking Discussions and Related Certifications / Other / Re: vista + linux help on: August 29, 2009, 09:04:15 PM
Kevin,

With all the free virtualization software out there, I don't think there is really much reason to dual boot anymore.

Just my 2cents.
955  Ethical Hacking Discussions and Related Certifications / General Certification / Re: Sec+ on: August 28, 2009, 04:53:48 PM
I've been thinking Sec+ might be the right place to start for me, for my first security cert.

Curious what materials did you like, and which ones did you think were not worth the price when studying?

*edit: and of course being excited about picking someone's brain on learning materials, I forgot to to say congratulations.
956  Ethical Hacking Discussions and Related Certifications / Physical Security / Re: How ATM Card Skimming and PIN Capturing Scams Work on: August 27, 2009, 10:11:21 AM
thats awesome, too bad they didnt do it before DEFCON Tongue

Actually, that's from a couple of months ago. The slide share link is new, but The Consumerist had a link to the PDF in April. I vaguely remember seeing it last year too, but I could be wrong on that.
957  Ethical Hacking Discussions and Related Certifications / Malware / Re: Don't drink the water. on: August 26, 2009, 06:50:18 PM
4sh

I wouldn't want to be responsible for it getting out and causing problems elsewhere either. I think what I'm interested in is:

1) what is making it so hard to clear
2) what kind of things to look for on a network that indicates it's there (original detection, in general)
3) What this bad boy is using as an entry vector
4) what your test environment is like

If I was setting this up, which I lack the hardware for at this time, I'd do a chrooted virtual window's box on a system I don't mind destroying the hard drive out of afterward. Although that seems a little expensive when I think about it (constantly going through hard drives).

What's the best way to get involved with a local DC group? I tried to join a local Perl Monger's group once, but they hardly ever met, and when they did, they wanted to focus on showing off what they (the host's company) was working at the time. (*edit: turns out the local DC is no longer DC, it's now ArbSec...)

I'll also remember to shop smart, shop S-Mart. Smiley
958  Resources / Tutorials / Re: New *looking for a point in a direction to get started* on: August 26, 2009, 06:18:47 PM
Some of the stickies are pretty good for where to start.

I think the big question is what are you looking for? For example, my interest is in making my networks stronger than doing pentesting. From what I've read here, I'm leaning toward reading hacking for dummies, follow up with Sec+ for an intro-cert and then follow up with C|EH and OffSec.

(note I've got a lot of the same stuff you do skill wise, just lack any current certs, but doing IT for 13 years).
959  Ethical Hacking Discussions and Related Certifications / Malware / Re: Don't drink the water. on: August 26, 2009, 06:08:46 PM
Not going to ask for a copy, because I fall under the new clause. I wouldn't know what to do with it if I had it anyway.

I'm just wondering if it would be possible to make some kind of training document from what you do with it?

I know, I'm asking a lot. Just looking for good ways to learn things, from people who would know what they're doing.
960  Ethical Hacking Discussions and Related Certifications / Other / Re: Online conversations - anyone interested? on: August 26, 2009, 12:35:39 PM
awesec, what's your native tongue?
Pages: 1 ... 62 63 [64] 65 66
Powered by MySQL Powered by PHP Powered by SMF 1.1.16 | SMF © 2011, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.098 seconds with 21 queries.
 

gk_static-ad_feb2012.jpg
Global Knowledge: Build Security Skills to Protect & Defend

els_130x200fixed2.gif
eLearnSecurity Student Course Now Live!
5% Off with Code
ELS-EH-5

SANS Deals 4 EH-Netters
$150 OFF Any SANS Course in Any Format!
Coupon Code: EHN_Connect Including SANS Security West 2012 & SANSFIRE 2012
Recent Forum Topics

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!

Vote For EH-Net

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2012 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.