Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 57 guests and 3 members online
 
Advertisement

You are here: Home
EH-Net
May 23, 2013, 08:38:54 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
  Home Help Calendar Login Register  
  Show Posts
Pages: 1 ... 4 5 [6] 7 8 ... 58
76  Ethical Hacking Discussions and Related Certifications / Malware / Encoding parts of a payload on: February 11, 2013, 10:28:37 AM
Hi everyone,

When I use msfpayload to generate my payload (let's say, a Windows tcp bind shell), I always encode it with msfencode to remove null bytes (\x00) or any other characters (usually \x0a and \xff, sometimes more). I do this because these bytes would otherwise prevent the insertion of my payload in memory.

But what if my payload needs to be cut in two because I cannot put it all at the same memory location? For example, if my payload is 300 bytes long and I only have two spots of 200 bytes in memory? Should I carefully cut the payload (between two instructions) then encode each part separately, if they contain any invalid bytes? I would finally jump from the first part to the second one.

I haven't hit this problem yet, I was just "meditating" on the issue and couldn't get a good answer from Google.

Thanks
77  Resources / Career Central / Re: Question about penetration testing specialties on: February 11, 2013, 09:24:45 AM
Quote
Bottom line, in my opinion, you should learn from pleasure and if this learning activity can gets you some paper too then why not?
And for many of us, "pleasure" turned to "pain" before going back to "pleasure" again...  Cheesy

All jokes aside, Amidamaru is right: if you don't love it, you can't spend the required effort into it. You just need to go one bite at a time. You're interested in wifi? Have fun for a few weeks exploring that. Then switch your interest on whatever interests you at that time. I think it's a nice way of not getting overwelm by all the materials that needs to be learn...
78  Ethical Hacking Discussions and Related Certifications / Web Applications / Re: SANS GWAPT Exam? on: February 11, 2013, 06:57:06 AM
Quote
In the real-world, doing web app pentesting might practically require that you understand these areas much better, but SEC-542 is not what I'd consider a really advanced web app pentesting course.
+1

SEC542 is not an easy course, but it focuses on introducing all the concepts you need to become a web app penetration tester. There is simply way too much content on the topic for a 6 day course.

I haven't taken this one, but SEC642: Advanced Web App Penetration Testing and Ethical Hacking should help you become a more complete web app pentester after you have completed SEC542.
79  Ethical Hacking Discussions and Related Certifications / Web Applications / Re: SANS GWAPT Exam? on: February 08, 2013, 09:22:05 PM
Quote
You certainly don't need to be a developer to understand the material.
ajohnson is right. All you really need is to be able to read (not write) and understand basic HTML and Javascript. The course will teach you all this and the few other little things you need to know.

And by all means, if you are performing Vulnerability Assessments of web app, that's a great course/cert to get you started.
80  Ethical Hacking Discussions and Related Certifications / CEH - Certified Ethical Hacker / Re: Can I interview one of you who is a Certified Ethical Hacker on: February 08, 2013, 02:04:20 PM
Why do you need to interview one of us?
You have to give more details...
81  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: OSCE advice? on: February 08, 2013, 08:14:51 AM
Thank you all for these great advice.

I have a pretty good idea now about what to do for exploit development. But what about the web apps and the network sections? Any advice on these two topics?


82  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: OSCE advice? on: February 07, 2013, 10:36:48 AM
Quote
Great thanks UNIX! You too (and many more here) are a gold mine!!  Cheesy

I have also found this http://www.mydigitallife.info/how-to-convert-and-import-vhd-to-vmdk-vmware/ to convert these VHD to VMWare VMDK format.

Update: The last step: http://hacktolive.org/wiki/Using_VMware_images_%28.vmdk_files%29

83  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: OSCE advice? on: February 07, 2013, 09:30:12 AM
MaXe and ajohnson, you are both gold mines!!!

Now I have a ton of things to read and practice.  Smiley

BTW, do you guys know where I can get a WinXP VM that I can use in my lab? I am running a AMD64 Linux machine at home...

Thx
84  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: OSCE advice? on: February 06, 2013, 06:08:41 PM
Great, thanks for these great responses!

I get the point regarding exploit development: practice all the techniques often and in different conditions.

I will also have a good look at the book you proposed ajohnson!

But what about the other things (web app, router, etc). What do you guys recommend or wish you would have done before the exam? I know I need to practice fuzzing web apps more, that's for sure, and I was planning on playing with the DVWA and other things like that. But what else would you recommend?



85  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: OSCE advice? on: February 06, 2013, 01:11:57 PM
Quote
A good practice would also be to try to create exploits that utilize different exploitation techniques than the ones that are publicly available.
Thanks UNIX. But what do you mean by "utilize different exploitation techniques"?
86  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / OSCE advice? on: February 06, 2013, 12:37:05 PM
Hi,

For those who are already certified, what advice would give to someone like me who is starting the Cracking the Perimeter course in order to later challenge the OSCE certification?

I have read some stories here and on the internet, but I am curious on what you have done to succeed and what you would change if you were to do it again.

Thanks in advance for you help

87  Ethical Hacking Discussions and Related Certifications / Forensics / Re: Web site forensics on: February 06, 2013, 10:43:31 AM
Nice point Ketchup!

88  Ethical Hacking Discussions and Related Certifications / Web Applications / Re: Need some MYSQL practical Resources on: February 06, 2013, 10:38:37 AM
Quote
i am more interested in writing and learning queries for becoming a web-app pen tester
That's what I thought!  Wink

Here are some free videos about SQL Injection:
http://www.securitytube.net/tags/sql-injection

Good luck!
89  Ethical Hacking Discussions and Related Certifications / OSCP - Offensive Security Certified Professional / Re: I passed OSCP !! on: February 06, 2013, 07:08:37 AM
Thanks again for the great comments!  Smiley
90  Ethical Hacking Discussions and Related Certifications / Web Applications / Re: Need some MYSQL practical Resources on: February 05, 2013, 10:29:57 AM
Are you looking for MySQL training or more something like SQL training?

I have been a MySQL DBA for 4 years in the past, so I know it pretty well now. Most developers or hackers really want to know how to connect to MySQL and run SQL statements while DBAs want to know how to install, configure and administer the RDBMS.

So what is your real goal? We will be able to help you better once we understand what you are looking for.
Pages: 1 ... 4 5 [6] 7 8 ... 58
Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.067 seconds with 21 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.