Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 52 guests online
 
Free Business and Tech Magazines and eBooks

You are here: Home
EH-Net
May 23, 2013, 03:37:25 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
  Home Help Calendar Login Register  
  Show Posts
Pages: 1 ... 10 11 [12]
166  Resources / News from the Outside World / Re: Pwnie Awards 2010 - Black Hat on: June 17, 2010, 01:29:47 PM
We would have to nominate the Google Hack this year right?  I mean it forced them to drop Micro$oft Windows.   Shocked
167  Ethical Hacking Discussions and Related Certifications / OSCP - Offensive Security Certified Professional / Re: OSCP certification challenge on: June 16, 2010, 07:39:34 AM
Did you get the 2 month or 1 month access to the labs when you signed up? 
168  Ethical Hacking Discussions and Related Certifications / General Certification / Re: CEH or eLearnsecurity wich one first on: June 15, 2010, 01:50:33 PM
I agree with COm_BOY.  It looks like eLearnsecurity will definitely get your hands dirty.  I have taken the CEH and it does provide good information but there is nothing like hands on experience.  I do like exams that cannot be simply brain-dumped, but requires at least some hands on work.  I guess that is what makes OSCP so appealing to me. 

To be fair, there is nothing preventing you from building a PenTest Lab to study for the C|EH.  I guess, you get, what you put into it.  But again, I think if take the eLearnsecurity first, you probably won't take the C|EH. 
169  Ethical Hacking Discussions and Related Certifications / Incident Response / Re: SIEM and incident response on: June 15, 2010, 10:30:20 AM
Has anyone ever used the SIEM (NitroView Enterprise Security Manager (ESM)) or QRadar?  It seems like SIEM can help get an organization SAS70 certified.  It was noted that "SIEM gives you a true picture of how your network is being used, and by whom. It independently monitors your network to verify security policies, to generate alerts for possible compliance breaches, and to analyze and report on network performance" but has it ever overwhelmed anyone here with false positives?
170  Resources / News from the Outside World / Even Faster Password Cracking on: March 12, 2010, 10:43:09 AM
Posting from TheRegister:

Quote
Password-cracking tools optimised to work with SSDs have achieved speeds up to 100 times quicker than previously possible.

After optimising its rainbow tables of password hashes to make use of SSDs Swiss security firm Objectif Sécurité was able to crack 14-digit WinXP passwords with special characters in just 5.3 seconds. Objectif Sécurité's Philippe Oechslin told Heise Security that the result was 100 times faster than possible with their old 8GB Rainbow Tables for XP hashes.

Quote
The exercise illustrated that the speed of hard discs rather than processor speeds was the main bottleneck in password cracking based on password hash lookups.

I did not see if they created a RAID 0 SSD setup which would have to make the process even faster with an increase in performance.  They said that it is even faster than the NVidia setup people are using.  Does anyone here have a SSD raid setup and can post about performances in your speed?

Entire Article:
http://www.theregister.co.uk/2010/03/12/password_cracking_on_crack/
171  Ethical Hacking Discussions and Related Certifications / Malware / Re: Microsoft warns of zero-day IE hole on Patch Tuesday on: March 11, 2010, 08:33:09 AM
Looks like it has already been added to Metasploit.  It is insane how fast the race is to patch systems.  I guess that is why InfoSec people get paid.  Grin


http://www.rec-sec.com/2010/03/10/internet-explorer-iepeers-use-after-free-exploit/
172  Ethical Hacking Discussions and Related Certifications / Malware / Microsoft warns of zero-day IE hole on Patch Tuesday on: March 10, 2010, 08:40:33 AM
Not sure if this has already been posted but just a heads-up:

http://news.cnet.com/8301-27080_3-10466199-245.html
173  Ethical Hacking Discussions and Related Certifications / Other / Re: Patch Management on: January 22, 2010, 07:47:18 AM
Thank you everyone for the replies.  I agree that patch management depends on the policies of the organization. I thought it was a good question to ask the community since it is such an important procedure for an organization with a security conscience. I know companies have different ways and applications of accomplishing it.  I have seen SMS, shavlik, WSUS, Altiris, BigFix, etc. I was wondering if anyone was partial to one of them and why? 

Also, I have seen people argue how often it should be done due to the testing required to install patches. Personally, I think once testing is done, you can install all tested patches.  You never know if a low priority patch can be used for a higher vulnerability. 

That is why I just wanted to see how other security minded people handled the task. Also, I think VMware is perfect for patch management because of snapshot.  It is faster than using Ghost or Clonezilla.

Again, I want to say thanks for the comments.
174  Ethical Hacking Discussions and Related Certifications / Other / Patch Management on: January 14, 2010, 11:29:58 AM
Hello All,

If you guys don't mind, I was wondering if people could share there advice and their experience on patch management.  How often they patch their systems, every day, week, quarter, etc?  What tools they use and their experiences with those tools?  Whether they concentrate on critical patches instead installing all patches?

Thanks in advance.
175  Ethical Hacking Discussions and Related Certifications / OSCP - Offensive Security Certified Professional / Re: Training Question on: December 11, 2009, 07:05:59 AM
Thanks for the replies.  I will be signing up at the end of January.  That should give me enough time to take care of the CISSP.  Oh yeah, I did want to say that was a great review for the OSCP.  Thanks again everyone.
176  Ethical Hacking Discussions and Related Certifications / OSCP - Offensive Security Certified Professional / Re: Training Question on: December 09, 2009, 12:41:43 PM
I also want to take the course but after, I complete the CISSP.  I was wondering if I have to be an Assembly GURU to pass the course.  I have the two books (Hacking: The Art of Exploitation  2nd Edition) and (Reversing: Secrets of Reverse Engineering).

I figured reading and understanding them would help me before I take the course.  But is it necessary? I am going to anyway since ultimately I wanted to become a researcher for discovering and breaking malware, especially the ones that create botnets.   Grin
Pages: 1 ... 10 11 [12]
Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.058 seconds with 21 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Free Business and Tech Magazines and eBooks

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.