Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 64 guests and 1 member online
 
Advertisement

You are here: Home
EH-Net
May 21, 2013, 09:14:40 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
  Home Help Calendar Login Register  
  Show Posts
Pages: 1 2 [3] 4 5 6
31  Ethical Hacking Discussions and Related Certifications / Wireless / Re: Question on wireless pen testing on: April 28, 2012, 12:38:59 PM
or he may have static IPs and have no DHCP what so ever
32  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: building a windows enterprise hacking lab suggestions? on: April 26, 2012, 07:25:02 PM
i have DHCP i was thinking of putting a fedora box running snort as that seems to be a common platform for snort i will add a kerberos box later if only there was a way to make virtual telephone networks (i don't mean voip) but that would be extremely difficult oh well but yeah i have a lot to keep me busy.
33  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: building a windows enterprise hacking lab suggestions? on: April 23, 2012, 12:58:47 PM
thanks i will add a exchange server and i may go the office communicator route for VOIP and have clients with softphones running traffic generation scripts and a MSSQL server i don't have much experience with sharepoint so it would make a good learning experience i may also add a VPN server as that is always a good way into a network.
34  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: building a windows enterprise hacking lab suggestions? on: April 22, 2012, 05:50:20 PM
no Sad
35  Ethical Hacking Discussions and Related Certifications / Wireless / Re: Alfa AWUS036NHR on: April 20, 2012, 11:04:17 PM
i would go with the AWUS036NHA it has a atheros card that works better with linux and can go into MASTER mode for AP attacks much easier something alot of other alfa and cards in general can't do in linux
36  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: building a windows enterprise hacking lab suggestions? on: April 20, 2012, 10:59:52 PM
based on the resources available to me and my goal to stick to M$ products i will go with MS SQL server may add fake spoils as entries in the database now that i think about it, i also will add a fedora Snort box because from what i understand that is a common IDS setup, and how could i forget? a Mail server?!!  i may add actual mail accounts and internal emails for lulz and realism sake maybe a sharepoint like you said any one else have any ideas?
37  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / building a windows enterprise hacking lab suggestions? on: April 20, 2012, 07:41:15 PM
Ok, so i have used linux based labs to practice network hacking for a while now. But now i want to build a virtual network that will emulate a windows enterprise network, i currently have set up a DC/DNS server a web server i intend to put vulnerable asp web apps on i also set up a SMB share server all in Windows 2003 R2 and i will add clients varying from XP SP3 to Windows 7 and vista (to simulate the ever changing landscape of a large network) i will add Cisco IOS gns3 vms and i may add a UC/VOIP system running traffic generation scripts. My question is what other services or network appliances should  i add to make this as realistic a lab as possible, keep in mind that while i can run VMs of alot of things i am on a student budget so alot of hardware components are not available to me. Thanks in advance for what ever advice you may give.
38  Resources / Links to cool sites. / my article on Wifi OSINT is up on the infosec institute on: April 13, 2012, 08:59:35 PM
i just finished writing another article on wifi OSINT and preperation for wifi pen tests on the infosec institute's resources section here is a link tell me what you think
http://resources.infosecinstitute.com/wlan-penetration-test/
39  Ethical Hacking Discussions and Related Certifications / Cyber Warfare / Re: wireless networks as a target for cyberwar? on: March 12, 2012, 08:02:36 PM
sil, to be honest that has little to do with the OP other then the fact that it makes more sense to go physical if there are NATs making external attacks more dificult and with the lack of static IPs some  networks use a client system's hostname as a sub domain i don't know why but it does happen so you can find targets that way and static IPed systems such as DNS servers or FTP servers are often vulnerable targets.

40  Ethical Hacking Discussions and Related Certifications / Cyber Warfare / Re: wireless networks as a target for cyberwar? on: March 07, 2012, 07:49:40 PM
about EAP-TTLS and EP-TLS yes they are more secure but PEAP is much more common becuase it uses already available credentials and infrastructure most companies already have RADIUS servers and not as many AP vendors sell devices that support or are optimized for  TLS or TTLS so PEAP is the de facto standard for WPA enterprise and the most common implementation of 802.11X and about the recon aspects if you read the wikipedia article on APTs it reads
Quote
Advanced persistent threat (APT) usually refers to a group, such as a foreign government, with both the capability and the intent to persistently and effectively target a specific entity. The term is commonly used to refer to cyber threats, in particular that of Internet-enabled espionage, but applies equally to other threats such as that of traditional espionage or attack
and i bet the FSB, PLA or Iranian Revolutionary Guard could easily and have gotten people into the U.S. or Europe to do B&E so this is just taking it a step forward (or in some cases a step back) and a lot of that recon can be done with OSINT sources, a lot not all. and NACing or DMZing is not a 100% fix all they have to do is pop a computer connected to the wifi but also has a Ethernet connection to pivot and if they use PEAP (which most of the companies where i live do) they already have a set of credentials for the other machine on the network not just the wifi, remember most PEAP implementations use the same RADIUS servers as windows login and even if they don't there is password re-use and derivable attacks. also most APTs have access to HUMINT resources so paying a janitor to re-arrange a few cables to create a bridge into the internal network would not be to hard albeit risky and i don't think they would trust a janitor perhaps a crooked IT person, that is another thing APTs could recruit insiders to do the B&E work as 3xban mentioned and for the being stealthy part some one sitting in a van  down the street is pretty common place where i live and most cities. also most IDS and IPS excluding WIDS/WIPS solutions focus on connections inbound from external sources and in  some government and intelligence agencies i would imagine they could not sniff or log traffic for sensitive departments or projects making a physical access or wireless attack even more stealthy. one of the main problems i have with the infosec and physical security departments in most organizations is they don't work together when they should what good is a strong network based camera and door swipe card system if its control computer can be found via shodan (http://www.shodanhq.com/search?q=GoAhead+Webs+login.asp+no+cache%2C+must+revalidate) and uses ancient software? whats the point of having a multi thousand dollar IDS/IPS solution if its host box's power source can be cut from outside the building? we need to start working with the physical security people more then we do right now, the navy and the army have the marines for a reason.
41  Ethical Hacking Discussions and Related Certifications / Cyber Warfare / wireless networks as a target for cyberwar? on: March 06, 2012, 10:34:32 PM
so i have had an idea recently, so in my experience wifi security is one of the easiest ways into a network just ask Albert Gonzalez and TJ Max so if a nation state or another APT has the resources to get operatives into the target's city wouldn't their Wifi network be a easy way in. i mean all they would have to do is if they have WEP crack it WPA/WPA2 personal crack it or if they have PEAP do what i call a kick-and-call: figure out which client on the network has which phone number deuath them or deauth the network wholesale  repeatability and then call them up and ask if they  are having network trouble and get them to connect to a honey pot, crack the MS-CHAPv2 hash and you are in, i digress but wifi security in many ways is the poor relations of computer security so what is there to stop APTs from exploiting it?  in my opinion this is something governments and other high risk targets need to take into consideration: beef up your wifi security and get a WIDS!!!
42  Ethical Hacking Discussions and Related Certifications / Social Engineering / Re: Email engineering on: March 06, 2012, 10:15:57 PM
http://emkei.cz/

my personal favorite
43  Ethical Hacking Discussions and Related Certifications / Web Applications / Re: Good resources for testing Java applications on: March 06, 2012, 10:13:31 PM
OWASP is your friend
https://www.owasp.org/index.php/Preventing_SQL_Injection_in_Java
https://www.owasp.org/index.php/Preventing_LDAP_Injection_in_Java
https://www.owasp.org/index.php/OWASP_Java_Project
44  Ethical Hacking Discussions and Related Certifications / Web Applications / Re: tools on: March 06, 2012, 10:12:04 PM
i am personally against web vulnerability scanners  they are noisy, blocked/detected by most WAFs/IDS/IPSes and often generate false positives or miss things  for a vulnerability assessment they are ok but for a pen test they are stupid and sometimes a game ender i personally do all my assessments by hand with firefox, tamper data and firebug, my logic behind that is i get a better idea how the application works and an attacker is going to use a setup that maximizes his or her anonymity and also its easier to look like a legitimate user if i am using a web browser then if i am sending huge numbers of packets with a automated tool and hoping the WAF only checks user agents. if i where doing a whitebox/vulnerability assessment type thing i use nikto/W3af community tools generally have more frequent updates in my experience. but for a pen test i suggest you all do your tests by hand, they are paying you not the tool :-p
45  Ethical Hacking Discussions and Related Certifications / Web Applications / Re: hacme bank prebuilt vmware image by (Ninja-Sec.com) on: March 06, 2012, 10:03:13 PM
i use linux as a base and the linux 7zip client could not open it and the ability to open a archive does not mean you can hack a web app or a windows 2003 box both of which i can do
Pages: 1 2 [3] 4 5 6
Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.068 seconds with 21 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.