 |
| |
| |
|
Who's Online |
|
We have 27 guests online |
|
| |
|
|
 |
|
EH-Net
|
|
May 24, 2013, 05:11:20 PM
|
Show Posts
|
|
Pages: 1 [2] 3 4 ... 7
|
|
16
|
Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: pen test documentation
|
on: August 08, 2012, 06:59:00 PM
|
|
@jamie. i would ue the template or engine for more than just pen testing by the way. As a mechanical engineer, i will be writing reports probably weekly if not daily.
I think a reporting engine will be awesome for more than just pen test engineers
as for calaborating, google docs is good at that. there is also a program like google docs but can be ran privatly on a LAN for a business(thought that doesnt help you but still pretty cool)
@ datadwarf. dude, you didnt lead us astray, just gave some awesome info of what not to do. This forums totally reminds me of a thomas edison style forum. try and try again until you suceed. I have found it is very importatnt to take notes like mr edison as well. if you get a chnace to see some of his writings, you will be impressed. he wrote everything down and i mean everything.
|
|
|
|
|
18
|
Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: please shed some light
|
on: August 07, 2012, 01:45:15 PM
|
|
im hoping it will. haha. The rules you have to follow for adding acls to routers is tough but writing them is pretty cool. I remember during my CCNA, it took me 45 minutes for one of the sims because it was soooo wicked hard. advanced firewall config was the exercise. haha. got 100%on security though.
I want to start a new thread for a new question but i am not sure when i should. haha. I want to discuss two firewall programs(entangle vs smoothwall) and how to add them to my vmplayer network for a lab. but i dont want to start to many threads.. haha. I want to learn how firewalls work and be able to use namp against one and then read the logs and see what it is doing. Then i want to tighten security on the fire wall and see if i can get past it to see if i can get access to de-ice 1.100
thanks guys
|
|
|
|
|
21
|
Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: pen test documentation
|
on: August 07, 2012, 11:25:58 AM
|
|
Thanks for the info on the executive summery. My problem is i am a very detailed write so flashy is my type. Now to learn how not to be flashy in the right moments.
@jamie.
That would be awesome. I have downloaded so many pdf's on how to write a technical report, it aint funny. haha. It seems that apa style is the norm.
you could have a wiki page or google docs that only certain people can edit.
for standard sakes i think apa is great. but my biggest concern i have seen is un-organized screen shots of attacks and command line stuff.
In my mechanical engineering class, we were taught "that in order to make your ceo happy, show lots of organized pictures. big bosses in business love pictures. they are pretty and fun to look at. Makes you feel special" so i think there should be a standard of how a body of pictures should be placed in the report AND easy to understand. IE proper names of x and y axis on graphs. I have seen some pen test reports where the x axis was the percentage but the y axis was just numbers from 0 - 20 with no title so people had no idea what the 75% at 11 ment. Was it that 11 of the scans showed 75% high risk or was it that it found 11 high risk cases and that that made up 75% of the total?
The hardest part, every professional out there including you and i, think we are the best at writing a report. So colaberating and effectivly communicating our ideas without stepping on toes, thats the hard part... oh and my spelling sux. haha
|
|
|
|
|
22
|
Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: please shed some light
|
on: August 07, 2012, 10:12:59 AM
|
If you're new to this, you should expect to struggle for the first few attempts. As you progress you'll start to learn what to look for and things will become a little easier. There will always be some degree of trial and error, especially when you get to more challenging machines, but there's no substitute for experience and lots of practice.
True. it is completely new to . I went back and looked at my ccna and ccnp security and it was all packet filtering and port forwarding stuff. nothing on how to attack a system. haha. I want to learn to use nmap in an environment with routers and firewalls, but im not sure how to run those apps in a vmplayer, nor do i know what config settngs should be configured on the firewall a well. IE, how secure should i configure it or how open. Wish there was a router/firewall challenge disk ISO.
|
|
|
|
|
23
|
Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: please shed some light
|
on: August 07, 2012, 03:26:28 AM
|
I mention to students they should try to be like surgeons, and conduct surgical strikes... but they come in carpet bombing the targets.  But that comes with time. Feel free to hit me up with any other questions you might have. Enjoy! I can appreciate that since i am a pre med student. Thopugh i am not studying to be a surgeon, but rather the possibility to make surgical tools or biomenitic legs and arms for those who need them. OR posibly power generation. But my degree requires pre med. haha. I feel somewhat dumb in a way. i cant believe i struggle on levle one. haha. there is no way i could have figured it out by myself with out the movies. haha. I do have to say that the ISSAF is a funny ol thing. it gives you ideas of what to do without telling you how, not all the time though. haha. After this course i am doing. I will FINALLY get to my linuxcbt course i purchased 4 years ago. i got the security edition and the RHCT course as well. I took it in school and had to purchase the CBT. I completed the first course but not the other 2. so that is next. just need to build a lab for it though. thats the hard part. They sent me a picture of whathe VM environment should look like... holy crap its complicated. hahaha thanks for the info.
|
|
|
|
|
25
|
Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: please shed some light
|
on: August 06, 2012, 04:42:05 PM
|
|
Awesome. that makes sense now. Ok so i was not just hearing things then. There is actually a 1.101 but it is only for student use. ok cool. So sine i do not have access to that, will 1.110 suffice for 1.101?
I am trying to follow the dvd videos first then read the book. I plan on writing my technical report so i can turn it into my english professor as a grade. haha.
Thomas? do you give a little demo or tour of the new online lab you have besides whats on the youtube video?
it looks pretty cool what you are doing though. i wish when i was doing my ccna and ccnp, we had something like this to help us out. haha.
thanks for all the help. i like the book, but i need to read the issaf and follow the videos fist before i understnad the book. haha
thanks
|
|
|
|
|
26
|
Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: please shed some light
|
on: August 03, 2012, 11:54:18 AM
|
yeah the videos might be sligthly newer than the book or vice versa. The book goes along well with the labs and that's how I've been using them. I may fire that one up after I am done with my current read/lab combo.
so far i like it. I have found that i need to follow the videos first and the ISSAF before i read all of his book. Some of the concepts in the book are more advanced than what i am used to. I want to complete the de-ice lvl 1 first before i read the advanced material in his book. haha. What read/lab combo you doing now? thanks
|
|
|
|
|
27
|
Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: please shed some light
|
on: August 02, 2012, 10:20:15 PM
|
Yeha the ones that came with the book are 1.100 and 1.110 but in his videos he ays attack he 1.101 target as your individual pen test project. He has his back rack set to 1.10. Here are my open and closed ports. udp 53 is closed but book gives hint that it is actually open. haha. but netcat dont wanna connect to it using nc -u 192.168.1.100 53. any way, i assume the 1.101 is now 1.110 root@bt:~# nmap 192.168.1.100
Starting Nmap 5.61TEST4 ( http://nmap.org ) at 2012-08-02 23:14 EDT Nmap scan report for 192.168.1.100 Host is up (0.00023s latency). Not shown: 992 filtered ports PORT STATE SERVICE 20/tcp closed ftp-data 21/tcp open ftp 22/tcp open ssh 25/tcp closed smtp 80/tcp open http 110/tcp open pop3 143/tcp open imap 443/tcp closed https MAC Address: 00:0C:29:9A:56:D7 (VMware)
Nmap done: 1 IP address (1 host up) scanned in 17.37 seconds root@bt:~#
|
|
|
|
|
28
|
Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: please shed some light
|
on: August 02, 2012, 03:25:20 PM
|
If memory serves, there was a 101.1, I have the labs at home and can take a peak later on. There are some things that may no longer be valid since he has moved some of his material to HackingDojo.
awesome. yeah some things must have changed because in the video his nmap scan of 1.100 shows port 25 open. mine is closed. he creates a telnet session to port 25 to grab banners. haha. thanks
|
|
|
|
|
29
|
Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: pen test documentation
|
on: August 02, 2012, 11:45:22 AM
|
|
PERFECT. ok thats what i was thinking. The above was originally going to be from my hands on exp portion as i follow along the movie for my actual pen test.
But after reading my notes, i felt like it was a tutorial rather than an actual document.
I have actually never written a technical report for anything haha so this will be new to me.
However, i can use part of the notes i ahve for the final report i bet.
thansk guys
|
|
|
|
|
30
|
Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: pen test documentation
|
on: August 01, 2012, 11:18:00 PM
|
first one has a dead link in it and it looked like a good read. haha. I have read the other ones before but i did not find what i was looking for. I know the format using APA and what not. im just wondering if im supposed to explain what i did as if i was talking to a begineer in the networking world. ill read the second links agan and see if i an find some more info. thanks Matt
|
|
|
|
|
Loading...
|
|
 |
|