Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 45 guests and 3 members online
 
Advertisement

You are here: Home
EH-Net
May 20, 2013, 02:46:20 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
  Home Help Calendar Login Register  
  Show Posts
Pages: [1]
1  Ethical Hacking Discussions and Related Certifications / Web Applications / Re: WebApp Vulnerability Scanner Comparison on: January 04, 2011, 05:04:08 AM
Here's the study "An analysis of Black-box web security scanners" (pdf)

It presents an evaluation of eleven black-box web vulnerability scanners.




2  Ethical Hacking Discussions and Related Certifications / Web Applications / Re: Web App pentesting: Code review on: January 04, 2011, 04:56:34 AM
Very good topic.

Here's a little bibliography:

- OWASP Code Review Guide (free)
- Code Complete (Microsoft Press)
- Hunting Security Bugs (Microsoft Press)
- Writing Secure Code (Microsoft Press)

3  Ethical Hacking Discussions and Related Certifications / Incident Response / Re: Computer Security Test Gone Wrong - Please Help on: January 04, 2011, 04:16:28 AM
One more question I have done security assessment basically all  I do is Vulnerability Scanning is that what general industry practise ?? or should i be doing more steps..anything i refer and Learn.

Hello,

Vulnerability scanning is only one "technical" part of the risk assesment process. The "business" part is equally important.

One method (not the best) to approacjh Risk Assesment is:

RISK = THREAT +  WAY OF ATTACK + VULNERABILITIE + ASSET + IMPACT

These 5 components have to be estimate into the organization specific context with the approval of the business.

Once this estimate is done, business, and only business, have to evaluate the risk and then decide to keep, avoid, reduce or transfer the risk.

You're only here to estimate the risk. Executives and business people are here to evaluate it and decide the way to treat it

At this point, it is possible to determine necessary and sufficient security objectives and requirements.

This approach is called "EBIOS" and is promoted by the DCSSI and recognized by the French administrations and, accordiang to me, has a some good pedagogic virtues

(more info)

Hope this helps Wink

(sorry for my bad english, you guess it... i'm french)
4  Ethical Hacking Discussions and Related Certifications / Forensics / Kon-boot : finding evidence on a domain workstation... on: May 31, 2010, 03:00:07 PM
Hello,

I need some help to find evidences of Kon-boot CD usage on an XP workstation into an Active Directory domain.

the usage of the CD is simple : it boots and starts the OS on the hard drive, shows all Windows user's profile(domain and local) and displays a menu. You can choose the user you want to open a session without destroy the password using the "cached credentials" feature. So you have access to the filesystem. If you try to access a share, then a small window bubble appears in the task bar, "Windows needs your current credentials. Please lock this computer, then unlock it using your most recent password or smart card. Please click the icon to see more information."

I'm looking for events on the worksation or the DC in order to find evidence.

Thanks for your help.
Pages: [1]
Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.092 seconds with 22 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.