Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 33 guests and 3 members online
 
Free Business and Tech Magazines and eBooks

You are here: Home
EH-Net
May 22, 2013, 03:55:47 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
  Home Help Calendar Login Register  
  Show Posts
Pages: 1 [2]
16  Ethical Hacking Discussions and Related Certifications / Other / Re: Vulnerabiltiy Found... Need Advice on: May 05, 2010, 02:38:27 PM
Yeah. That's what I was the most afraid of. I don't have anything to hide, but I also don't want that kind of hassle. I also know the security policiy of the place I work at, and I wouldn't want to be me microscoped end.

Doesn't stop me from thinking about how much it would suck if the wrong person were to find this as well, but oh well.
17  Ethical Hacking Discussions and Related Certifications / Other / Re: Vulnerabiltiy Found... Need Advice on: May 05, 2010, 12:58:31 PM
I guess not...  Grin
Just kinda feel bad if I know that this is open and someone completely FUBAR's their DB. I do however see how it's not my responsiblity to notify them if I don't want to. It's their responsibility to secure their stuff...

Thanks for the advice Dengar13 and Equix3n-

Just got a little excited because it is the first thing I've actually seen and not just read about; or simulated in my lab.
18  Ethical Hacking Discussions and Related Certifications / Other / Vulnerabiltiy Found... Need Advice on: May 05, 2010, 09:43:36 AM
Fellow EH's I need some advice. I was doing some GoogleFoo and found a site that had public access to a directory that held some shell scripts. I noticed one of them was named in a way that led me to believe that it may have some 'login' info in it. Sure enough it had the SA credentials for their MYSQL database. What is a good way to notify the site admin? I know the easy way is just to email them, but I know that some admins get a little upset when you discover a flaw in their system. I guess I really want to know:
1) Legally I didn't do anything wrong; am I correct? I didn't download any data and found it with a "simple" google search...
2) How do I approach the Admin in a way to let him/her know that I am trying to help them?
3) Do any of you have any experience with something like this?

Thanks in advance for any advice. I crawl around these forums often and appreciate all of the information that everyone provides. It has really helped me get from, "Yeah, I think security would be a cool thing to get into," to "Wow! I've come a long way in a few months! This stuff is awesome!!!"

-inf3KT1d
19  Ethical Hacking Discussions and Related Certifications / Compliance, Regulations & Standards / Re: DoDI 8500.2 and DISA STIG on: March 13, 2010, 09:18:19 PM
Could've helped you, but then our Contract got cut... Cry
20  Ethical Hacking Discussions and Related Certifications / Malware / Favorite Exploit Repository on: March 03, 2010, 07:36:24 AM
I've mainly used milw0rm and exploit-db for exploit lookup. I've found a couple of others that seem to be reposting/copycat sites. Do any of you have a favorite that you check when you are doing exploit research?
Pages: 1 [2]
Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.073 seconds with 21 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Free Business and Tech Magazines and eBooks

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.