Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 44 guests online
 
Free Business and Tech Magazines and eBooks

You are here: Home
EH-Net
May 20, 2013, 06:55:14 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
  Home Help Calendar Login Register  
  Show Posts
Pages: [1] 2 3 ... 58
1  Ethical Hacking Discussions and Related Certifications / Web Applications / Re: dns on: May 15, 2013, 07:31:44 AM
Another one:
http://www.securitytube.net/video/375
2  Ethical Hacking Discussions and Related Certifications / Web Applications / Re: SQL Injection into an INSERT statement. on: May 15, 2013, 07:27:41 AM
You know what eyenit0, I suggest you start MySQL Workbench (free!) and try to directly write SQL code there first (without going through PHP code). This way, you will be able to test SQL without the PHP layer.

For example, start with something like this:
Code:
INSERT INTO txtcomment (id,comment) VALUES (10, '<A comment>');

Then replace the <A comment> (but leave the single quotes there) with what you would normally use for SQL injection. For example:
Code:
-- Deleting the row containing the username 'bob' from the user table
-- Code to do this is: DELETE FROM user WHERE username='bob'
-- So the injection code would be: comment'); DELETE FROM user WHERE username='bob'; --
-- Note: There is a space at the very end of the SQL injection code!!!
INSERT INTO txtcomment (id,comment) VALUES (10, 'comment'); DELETE FROM user WHERE username='bob'; -- ');

As you can see:
Code:
comment'); DELETE FROM user WHERE username='bob'; --
Would be your SQLi code (including the space at the end)

Then, once it works in SQL Workbench, try to do the same thing through PHP. MySQL will often give you more meaningful error messages and you don't have to worry about PHP...

Does this make sense?
3  Ethical Hacking Discussions and Related Certifications / Web Applications / Re: SQL Injection into an INSERT statement. on: May 13, 2013, 07:10:44 AM
Hi eyenit0,

Is your 'id' column of type Integer? If it's the case, your problem is your single quotes.

Change from (having single quotes around the 'id' column)
Code:
INSERT INTO txtcomment (id,comment) VALUES ('" . $_POST['id'] . "','" . $_POST['comment']. "')

to (no single quotes)
Code:
INSERT INTO txtcomment (id,comment) VALUES (" . $_POST['id'] . ",'" . $_POST['comment']. "')

You only put single quotes around CHAR, VARCHAR and DATE data types...
Let me know if it works!
4  Ethical Hacking Discussions and Related Certifications / Web Applications / Re: Web vulnerability scanner on: May 13, 2013, 07:06:14 AM
Have you look at this site?
http://sectooladdict.blogspot.ca/2012/07/2012-web-application-scanner-benchmark.html

Very good information can be found there about web application vulnerability scanners!!
5  Ethical Hacking Discussions and Related Certifications / OSCP - Offensive Security Certified Professional / Re: OSCP Preparation on: May 09, 2013, 09:14:25 AM
The python lessons on codeacademy.com will be enough. Worse case, you will see what you're missing once you are in the PWB course and you can easily find examples on the web.

Good luck!
6  Ethical Hacking Discussions and Related Certifications / OSCP - Offensive Security Certified Professional / Re: OSCP exam scheduled on: May 08, 2013, 10:49:58 AM
You're gonna work 3 days in one, so like cd1zz and superkojiman said, sleep well before, eat properly and take many breaks. Try to sleep a few hours too.

Good luck and keep us posted!
7  EH-Net / Greetings / Re: hi on: May 07, 2013, 08:12:48 AM
Welcome nighturchin!

Feel free to post your questions here. What exactly are you interested in? Do you work in IT? Are you still at school?

8  Ethical Hacking Discussions and Related Certifications / GPEN - GIAC Certified Penetration Tester / Re: Attempting GPEN This Week on: May 07, 2013, 08:09:09 AM
For me, I self-studied by taking the Offensive-Security course "Penetration Testing with Backtrack". It was the best preparation. All I had to study after was some Windows based tools and read about laws and ethics. I barely used my notes in the exam and with no prior experience, I passed with a good score.

Honestly, I realized that playing with the tools covered in the exam is by far the best way of learning. You don't have to go too deep with each tool, but knowing how they works is key to being successful with this exam.

But since you were pretty close on your first attempt, you'll be good next time! Wink
9  Ethical Hacking Discussions and Related Certifications / OSCP - Offensive Security Certified Professional / Re: OSCP submission prior to exam on: April 17, 2013, 01:05:39 PM
Quote
The few I'd heard from, who benefited from the lab report, said they had shown, through their exam report, too, that they were VERY close to getting a final box, which would've passed them, so their report details kind of 'proved' that they had the proper knowledge and just weren't able to finish things off.
That is true. The EXAM report needs to be done properly. Like you said, if you are very close, they may give you some points for your efforts and knowledge.

However, if we talk about the STUDENT LAB report, you don't need it to pass the OSCP certification. Offensive-Security mentioned that if you fail the exam but you have give them you student lab report, you will still be able to claim 40 CPE.
10  Ethical Hacking Discussions and Related Certifications / OSCP - Offensive Security Certified Professional / Re: OSCP submission prior to exam on: April 17, 2013, 11:55:00 AM
Yes I know about this. But when I tried this on my first failed attempt, the lab report didn't me at all (and I scored 60 points in the exam)...

So although it helped some people pass, I wouldn't count on it...
11  Ethical Hacking Discussions and Related Certifications / OSCP - Offensive Security Certified Professional / Re: OSCP submission prior to exam on: April 17, 2013, 09:51:18 AM
By the way, you only have to send a report about the servers you hacked in the exam. You don't have to send a report about machines you hacked in the lab... (I asked them and I didn't...)
12  Ethical Hacking Discussions and Related Certifications / General Certification / Re: CEH on: April 16, 2013, 07:43:51 AM
For me, CEH help me study the main high level areas of information security. It was more a goal for me than anything else.

Also, we have to be careful here about the advice we give on any given certification. Some seems quite easy to achieve when you have lots of experience, but in my case, it was the first certification I studied for. And since I was totally new to this field, I found it quite difficult (btw, I self studied for it). But today, I would pass it with any study... So maybe that's why many people here think it's kind of a "low" cert. Too many people on this forum are very good...  Grin

So bottom line for me, this cert didn't help me get a job at all and now with the other certifications I have, I really don't need it anymore. But that being said, it was my first achievement in this field and I worked very hard for it, so I am still happy I did it.

Last thing, almost everyone in this field knows about it, even these "CISSP" guys. I believe it is known more than OSCP...
13  Ethical Hacking Discussions and Related Certifications / OSCP - Offensive Security Certified Professional / Re: Failed my first attempt at the OSCP exam on: April 16, 2013, 07:34:34 AM
@r0ckm4n:

Good to see you're already back at it and that you're making good progress!
But I have a question for you: What do you think you're still missing to pass the OSCP exam with confidence?

Maybe we can help you a bit here...  Wink
14  Ethical Hacking Discussions and Related Certifications / OSCP - Offensive Security Certified Professional / Re: Passed OSCP! on: April 11, 2013, 11:17:27 AM
Good job!
15  EH-Net / News Items and General Discussion About EH-Net / Re: Change is Coming to EH-Net!! on: April 09, 2013, 05:57:22 AM
Quote
4. Who's willing to help test?
Don, if you are talking about Vulnerability Assessments and Penetration Tests, I think you will get a lot of cheap labor form us!  Grin
Pages: [1] 2 3 ... 58
Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.057 seconds with 21 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.