Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 72 guests online
 
Free Business and Tech Magazines and eBooks

You are here: Home
EH-Net
May 18, 2013, 12:22:01 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
  Home Help Calendar Login Register  
  Show Posts
Pages: 1 ... 6 7 [8] 9 10 ... 12
106  EH-Net / News Items and General Discussion About EH-Net / Re: [Article]-September 2011 Free Giveaway Sponsor - Rapid7 on: September 01, 2011, 09:21:24 PM
HO-LY Crap!!   Grin
107  Resources / News from the Outside World / Re: DigiNotar Security Incident (Certificate) on: August 30, 2011, 08:11:43 PM
Its kind of a broken system. Moxie has great talks on this. If you allow just about anyone to be a CA or if you're a CA and have shitty security practices, then it ruins the integrity of the entire system. If we cant count on CAs to provide valid certs to legit companies then what good is it? At least the communication channel is encrypted.

I remember that especially when he released sslstrip.  I just knew it was only a matter of time after that.  I guess a broken system on its way to being crushed.  But it will be interesting to see alternatives implemented.  I remember being at a talk by Marcus Ranum and he wanted to change AV since that has been defeated, crushed and left for dead.  He had some good interesting ideas of changing the "already too late" paradigm.  But we will see.  I know we need to have something or more dark days ahead. 


Moxie introduced his alternative for the current CA structure this year at BlackHat/DEFCON:

http://convergence.io/index.html

Has anybody had a chance to check it out?

I just came across this via Twitter: http://codereview.chromium.org/7791032/diff/2001/net/base/x509_certificate.cc


I am checking that out now.  Thanks for the links!
108  Ethical Hacking Discussions and Related Certifications / Other / Re: Kevin Mitnick interview on TWiT on: August 30, 2011, 07:53:19 PM
I watch Hak5 on/off.  I try to watch everyone when I can.  "http://www.grmn00bs.com"  is another site to watch some good blog videos. Not sure if that link was posted on here.

I think they should release a movie on him since I look back on "Track Down" after reading most of his book and it seems like none of it was actually accurate.  I mean it kind of sucked if you were really interested in what happened. I guess it reminds you to go to the source.
109  Resources / News from the Outside World / DigiNotar Security Incident (Certificate) on: August 30, 2011, 01:24:32 PM

It looks like it is time to check your browsers for this cert.  Many are suggesting on your *nix boxes to use:

cd /etc/ssl/certs/
rm DigiNotar_Root_CA.pem

It seems like SSL is really getting hit these days.  And I do not think EV-SSL certs are going to save the day...


http://www.vasco.com/company/press_room/news_archive/2011/news_diginotar_reports_security_incident.aspx
110  Ethical Hacking Discussions and Related Certifications / Other / Re: Kevin Mitnick interview on TWiT on: August 30, 2011, 07:16:04 AM
Thanks for the link!
111  Ethical Hacking Discussions and Related Certifications / Other / Re: Kevin Mitnick interview on TWiT on: August 29, 2011, 10:35:47 AM
The book is pretty good.  I am almost done.  I truly cannot believe this is one man's life and not a movie. 
112  Ethical Hacking Discussions and Related Certifications / OSWP - Offensive Security Wireless Professional / Re: OSWP exam prep on: August 16, 2011, 06:37:35 AM
Thanks for the heads up.  Wasn't sure how that was handled.  Plus I know I will be installing BT5 R1 when it comes out tomorrow.   Grin
113  Ethical Hacking Discussions and Related Certifications / OSWP - Offensive Security Wireless Professional / Re: OSWP exam prep on: August 15, 2011, 02:36:56 PM
Would the wordlists in Backtrack 5 be just fine or does it matter? Huh
114  EH-Net / News Items and General Discussion About EH-Net / Re: [Article]-July 2011 Free Giveaway Winners - Sequrit on: August 15, 2011, 02:09:00 PM
Congrats fellas!
115  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Your First Pentest on: August 04, 2011, 07:10:50 AM
First, thanks for all the replies.  I was curious of the "lessons learned" during everyone's pentests.  I have watched some of Joe McCray's videos and he always has some crazy stories. I guess I should have asked not only for first pentests, but craziest/funniest also. From the stories, it seems like the customers make the situation more unusual than it has to be. I have never heard of a pentest with those kind of parameters. A moving target in a van.  Ouch. And tturner brings up a good point. "These are the kinds of situations that no certification program on the planet will prepare you for". Anyone would have to agree with that. I guess that is why Sil made the point about paper certificates. Experience with knowledge helps with most obstacles especially with the unusal scenarios. I guess that is what brought up the question. I definitely learned a thing or two just by reading these stories.

Client side and web app attacks seem to crack any perimeter for one. Thanks again for all the replies.  Oh yeah, I did want to say, CONGRATS on the new job Jamie.R! Time to update the 'ol SET to v2....
116  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Your First Pentest on: July 27, 2011, 10:29:00 PM
I know there are a lot of Professional Pentester here so I wanted to ask if anyone would share their story of their first pentest? Without breaking their NDA of course.  Was it a piece of cake or a train-wreck? What would you have done differently knowing what you know now? Did your customer's restrictions kind of ruin the fun for you or made it more challenging? Would you have added more tools to your arsenal or just focused more on the tools you already had? Meh, just thought I would ask. 
117  EH-Net / News Items and General Discussion About EH-Net / Re: [Article]-June 2011 Free Giveaway Winner - Hacking Dojo on: July 25, 2011, 03:15:46 PM
Congrats MaXe! You definitely deserve it! We expect a full report too.   Grin
118  Resources / Career Central / Re: Its all about Ports on: July 20, 2011, 07:02:23 AM
Congrats.  Good luck on the new job!
119  Resources / Tutorials / Snort Signature Evasion with Metasploit on: July 15, 2011, 09:01:59 AM
I did not see this video posted anywhere but if it was, my apologies.  It is a very cool video on hiding from snort. I glanced at the commands before while reading MetaSploit Unleashed but it is nice to see them in action. 

http://vimeo.com/24455465
by T0X1C

Info on the commands:
http://www.offensive-security.com/metasploit-unleashed/Msfconsole_Show_Command
120  EH-Net / Ethical Hacktivism / Re: So, whats your opinion about Lulzsec??? on: June 21, 2011, 09:06:45 AM
Maybe not j0rdy:

Twitter update: LulzSec The Lulz Boat
Seems the glorious leader of LulzSec got arrested, it's all over now... wait... we're all still here! Which poor b*stard did they take down?


Did seem a little too easy or fast.  But they do have every organization chasing them.  We will see I guess, who they really have.
Pages: 1 ... 6 7 [8] 9 10 ... 12
Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.064 seconds with 21 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.