Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 47 guests and 2 members online
EH-Net News Feeds
Latest Additions
 
Advertisement

You are here: Home arrow Forum
EH-Net
May 21, 2012, 03:15:15 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Advertise on EH-Net!! - Reasonable Rates, Highly Targeted Audience.
 
  Home Help Calendar Login Register  
  Show Posts
Pages: 1 ... 6 7 [8] 9 10
106  Ethical Hacking Discussions and Related Certifications / Web Applications / Re: Web app attacks and using web shells on: January 20, 2011, 11:58:13 AM
Thanks!! Just doing some research on some web exploits.   I saw that Jhaddix provided some info but the link didn't work.  Thanks again. Hopefully it is something else I can use in the OSCP course.  =-)
107  Ethical Hacking Discussions and Related Certifications / Web Applications / Re: Web app attacks and using web shells on: January 20, 2011, 10:41:50 AM
Does anyone have a copy of that pdf?  The link is down: http://www.wtfchan.org/~evil1/Web-Shells-rev2.pdf
108  Ethical Hacking Discussions and Related Certifications / Mobile / Re: Mobile Devices Penetration Testing on: November 29, 2010, 02:07:40 PM
Hey guys,

I was just wondering, what are people here telling their customers after a pentest of mobile devices?  Should they disable bluetooth all together?  Create complicated 5 pin codes?  Encrypt them if applicable? Add antivirus where applicable?  It just seems like there are so many attack vectors with the mobile devices, it would be hard to nail down a secure way for all customers to use them 24-7.  Not to mention, the browser being vulnerable.  Just curious since I see so many companies now going to IPhones, Ipads, and Androids.  Thanks.
109  EH-Net / Calendar Of Events / Re: BSidesDelaware 2010 on: November 08, 2010, 09:12:40 PM
Unfortunately, I arrived late to the Security B-Sides Delaware conference, to my first conference no less. Long story.  Anyway, it was great to see so many smart people presenting information.  They had two conference rooms and a main auditorium.  Some of the presenters were Jason Ross, Marcus Carey, Dave Marcus, Scott Hazel, Michael “theprez98” Schearer and “Grecs”.  For those who could not attend, they have been posting video of the conference online.  I saw a couple of people tweet (hxxp://www.ustream.tv/channel/security-bsides-delaware-track-1), (hxxp://www.ustream.tv/channel/security-bsides-delaware-track2) and (hxxp://www.vimeo.com/16585113). 


The four talks I got to see were Lockpicking, Pwn an ISP in 10 Minutes, Intro to ShoNuff and Social Engineering for Non-Penetration Testers.   I have always thought about how important it is to have physical security and the lockpicking class proved it.  Dr. Robert Tran spoke on the basic locks such as tumblers and wafers and how to unlock them.  It should not be that simple to unlock these.  If you guys are curious, his group’s site is (hxxp://toool.us).  You can actually buy tool sets on their site.  Very cool.  He used rakers, half diamond, and hook tools.  You see it on TV all the time, but it was incredible to see it in person.  He explained it is all about light pressure.  Oh, and before I forget two rules: don’t try to pick a lock that you don’t own and don’t pick a lock that you rely on!  I am glad he said that, I was ready to try to lockpick my front door the minute I could.  It would really suck to have to replace my door lock because I got overzealous.  =-)


Next, SHODAN!! The speaker was “theprez98” and he talked about the Shodan Search Engine (hxxp://www.shodanhq.com).  It is not your Google search engine.   It gives info such as the IP address, hostname, port numbers, and OS versions of devices on the Internet.  It is very powerful.  He did a demonstration of how easily you can search for a Cisco device that has no protection and allows “level 15” permission over the device.  It was scary stuff and definitely worth a look of his video. 

 
Next up, ShoNuff!  We didn’t get to see a demonstration of ShoNuff due to some technical difficulties but Jason Ross still gave us the overview of it.   The site is (hxxp://whoisthemaster.org:8080/).  It basically does a super WHOIS of an organization.  It provides the network IP address range of the company and even ties to Shodan using the new API of Shodan.  It seems to me it is invaluable when you are doing passive recon work for a penetration test.  It is amazing that this started from curiosity and the scarcity of the IPv4 addresses available.


Lastly, I sat in on the social engineering demonstration by Scott Hazel.  He basically answered the question, “How do I practice social engineering when I am not doing a penetration test and I don’t want to get shot?”  It is a very good question.  I mean how do you get skills on social engineering so that you can be asked to do a penetration test?  He gave some answers I would not have thought of such as watching TV shows on mute just so you can read nonverbal communication.  It makes sense right and it is simple.  Also, try listening! Again, sounds simple but how many of us actually do it.  You can start by just listening to your wife, girlfriend, kids, friends and co-workers.  You will score points with the wife/gf at least. =-).   Finally, to get to that “layer 8” connection is to talk to people.  Just converse with strangers and see how much you can learn about people.  He gave some anecdotal examples when he described that you should be “the fail”.  It was hilarious.  Basically, you can get loads of information from people simple by stating things that are incorrect.  Someone will always be there to try to correct you with information that they should be give. 


I think the conference was a success.  It was informative, exciting and inspiring.  I would definitely recommend looking at their videos if you could not attend.  I am hoping this is the start of more great conferences to come. 
110  EH-Net / Calendar Of Events / Re: BSidesDelaware 2010 on: November 06, 2010, 06:35:06 PM
Just came back from it.  It was very cool, loved the info on Shodan, ShoNuff and Lockpicking. 
111  Ethical Hacking Discussions and Related Certifications / Other / Re: Convincing upper management on: November 04, 2010, 03:04:32 PM
I agree H1t M0nk3y.  Also, I know information security standards like PCI-DSS are usually for financial institutions but FISMA and SOX has to influence a government agency, right.  That would have to put some pressure on management to do their due diligence and due care.  I would research some laws that show that not only can it be a hit to reputation and profits but it could possibly lead to charges being brought if any. 
112  Resources / Links to cool sites. / Hack3rcon 2010 Videos on: November 02, 2010, 09:13:15 AM
I did not see it posted but I saw some great videos on IronGeek and figured other people might want to check them out. 

http://www.irongeek.com/i.php?page=videos/hack3rcon-videos
113  Ethical Hacking Discussions and Related Certifications / OSCP - Offensive Security Certified Professional / Re: Exam soon! on: October 30, 2010, 05:23:09 PM
Good luck!!!! I hope all the studying and training can help you thru it.  I will finally be able to take the OSCP training next month.  Finally!  Please tell us how you think you did when you are done.  Again, good luck ZF!!
114  Features / Skillz / Re: Anymore Challenges this year? on: August 20, 2010, 10:01:51 PM
Thanks COm_BOY.  I took a look and went through some of the challenges.  I do like some of the programming ones and the Exploit challenge.  As far as the quality, it was a complete range of 1 - 10.  Some challenges were just looking through Google and some had you test your Assembly/Debugging skills.  It is definitely worth a quick look. I have been trying to look for as many challenges as possible to prepare for the OSCP course.  If anyone else is looking, here are some I have seen:

http://www.dvwa.co.uk/download.php
http://forums.heorot.net/viewtopic.php?f=21&t=149
http://forums.heorot.net/viewforum.php?f=16
http://forums.heorot.net/viewforum.php?f=18
http://www.crackmes.de/
http://www.hackthissite.org/
http://www.astalavista.com/
http://www.mavensecurity.com/WebMaven/
   http://dojo.mavensecurity.com
http://www.foundstone.com/us/resources/proddesc/hacmeshipping.htm
http://www.foundstone.com/us/resources/proddesc/hacmebank.htm
115  Ethical Hacking Discussions and Related Certifications / OSCP - Offensive Security Certified Professional / Re: OSCP exam in 1 week - Advice? on: August 13, 2010, 12:09:33 PM
I have not taken it so I cannot give any helpful hints.  But I still wanted to wish you good luck.  And like you said, relax.  I did find these links for inspiration and recommendations:

http://www.chris-mohan.com/2010/02/how-to-fail-the-offensive-security-101-exam/

http://xyberpix.blogspot.com/2007/08/oscp-certification-challenge-most.html

http://www.elwood.net/post/39599202/offensive-security-oscp

http://blogs.securiteam.com/index.php/archives/989
116  Features / Skillz / Anymore Challenges this year? on: August 06, 2010, 10:50:15 AM
I apologize if this was answered already.  Are there going to be anymore Skillz challenges this year?  I really like the Prison Break challenge.  There has been a lot of security topics for the year that may be cool to include:

-Mobile Phone Security
-Adobe (of course)
-Social Engineering

I guess it would be hard to include them in a challenge I suppose.  But it is something to work with. 
117  EH-Net / News Items and General Discussion About EH-Net / Re: Ethical Hacking Swag on: August 06, 2010, 10:37:16 AM
"At my job I wear many hats.  My favorite is white ...."
     -EH.net

"You should have more than just an antivirus to protect you..."
      -EH.net

All I have so far. 
118  Resources / Career Central / Re: What sort of questions are asked during an Infosec Interview? on: August 05, 2010, 08:20:48 AM
I know this is late, but I did find someone speak on this topic also.  Figured it could other people too.

http://danielmiessler.com/blog/25-questions-to-ask-during-an-information-security-interview
119  Features / Book Reviews / Re: Cover Art for New Book - Ninja Hacking on: August 05, 2010, 06:58:57 AM
Well, I guess not next week.  At least it will be ordered when it comes out. 
120  Features / Book Reviews / Re: Cover Art for New Book - Ninja Hacking on: August 05, 2010, 06:58:02 AM
Congrates guys.  I also added the book to my wishlist.  I should have it by next week hopefully.  What inspired you guys to write the book?  It just needed to be done or the love of InfoSec? Also, do you think Ninja skills increase your ability for Social Engineering? 
Pages: 1 ... 6 7 [8] 9 10
Powered by MySQL Powered by PHP Powered by SMF 1.1.16 | SMF © 2011, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.333 seconds with 21 queries.
 

gk_static-ad_feb2012.jpg
Global Knowledge: Build Security Skills to Protect & Defend

els_130x200fixed2.gif
eLearnSecurity Student Course Now Live!
5% Off with Code
ELS-EH-5

SANS Deals 4 EH-Netters
$150 OFF Any SANS Course in Any Format!
Coupon Code: EHN_Connect Including SANS Security West 2012 & SANSFIRE 2012
Recent Forum Topics

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!

Vote For EH-Net

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2012 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.