Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 22 guests online
 
Advertisement

You are here: Home
EH-Net
May 25, 2013, 03:18:54 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
  Home Help Calendar Login Register  
  Show Posts
Pages: 1 ... 35 36 [37] 38 39 40
541  Resources / Links to cool sites. / Re: Zero Day Initiative on: March 09, 2010, 06:31:58 AM
I am not sure how I would feel about myself, when I would have to wash my hands off and forget the 0day I couldn't purchase, if I was Tipping Point.   I realize that this program has the potential to increase security and get some 0days out of the wild, but still.    It's a tough choice to make, when do I say I can just can't pay you that much and you I give you back your 0day.   

in theory this goes completely against the purpose (mission and vision) of the company, making the whole idea ridiculous.
542  Ethical Hacking Discussions and Related Certifications / Other / Re: best beginners programming language on: March 09, 2010, 06:29:04 AM
Personally, on my list right now: Relearn Shell Programming (used to be good, but haven't done it in forever). Followed by Perl (I've got tons of books, and it'll help at work), and then finally Python.

thanks for the links! this seems as a pretty good starting point. i picked up shell scripting first to get back in the game, after that i will get back into either perl or python.
543  Resources / Career Central / Re: moving to the states? on: March 09, 2010, 06:26:43 AM
to keep the discussion going, there is no influence of external factors like girlfriends, wife, family or other things. part of being happy is having the right job isnt it?

Also add that if you do not have Green Card/or Citizen you will not able to go inside of this profession in EEUU.

It is very hard to start here.

this is good to know!  so type of occupation has influence on the possibility of getting a greed card...interesting...keeping this in mind means that everybody is pretty stuck at the location there currently at Tongue
544  Ethical Hacking Discussions and Related Certifications / Other / best beginners programming language on: March 08, 2010, 03:26:28 AM
they always say know your strength, but know your weakness better. at this point i do, and i intent to do something about it.

i lack a pretty good foundation in programming and i'm willing to start with some basics. however, when i look at the programming languages used in the ethical hacker field i see mostly perl,python and c. i was wondering whats the best language to start with according to easiest learning curve and power. also, where do i find good documentation/tutorials to start?
545  Resources / Career Central / moving to the states? on: March 08, 2010, 03:22:32 AM
first of all, this is a threat intended for people living outside of the united states and having a hard time finding the proper job or career they would like to have, focussed on pentesting ofcourse.

even though i havent been working in this profession for a long time, at this point i'm (already) walking into some walls. i see that the demand for good ethical hackers / penetration testers is a lot lower then i would like to see. i think this has something to do with the characteristics of the typical dutch people, but thats a completely different story.

i think this profession is way more appriciated in for example the united states, and what i'd like to know is how does this affect job opportunities and if you are willing, is it wise to move to the united states to boost you carreer? any experience here?
546  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: hydra help on: March 08, 2010, 03:12:54 AM
did you set the parameters right? hydra can close the connection before he gets the result, so try to ajust the number of connections and the time it waits for response.

here's some reseach material:

http://www.enterprisenetworkingplanet.com/netsecur/article.php/3745276

i quote:
The Tuning tab is used for selecting the number of login attempts that are submitted simultaneously, and this number can be quite critical. Too high and the chances of being detected or locked out of the system are much higher, but too low and it could take days to work through your password list.
547  Resources / Links to cool sites. / Re: Zero Day Initiative on: March 08, 2010, 03:05:27 AM
there's no insurance for either the buyer or seller in this matter. its like a drugsdeal (which go bad almost all the time, if we believe hollywood). both have something they want, but is it legit? how does either of the both party's know there not getting crossed? like hayabusa said, its like making a deal with the devil, hoping he's a saint. i'd like to see this initiative to work, but there has to be extream caution in getting this bulletproof.
548  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: A cautionary tale for Penetration testers on live networks on: March 08, 2010, 02:50:16 AM
correct me if im wrong, but i see some flaws on either the CFO's side as the pentesters side. Dave acted correctly from the moment he discovered the "hack". The CFO should have never given permission to attack the availablity of the infrastructure, and the pentesters should have never kicked up that much dust to get detected. however, when compromising the availablity of the infrastructure, youre pretty sure you will be detected.
549  Ethical Hacking Discussions and Related Certifications / Hardware / Re: Full Disk Encryption - Which solution do you prefer? on: March 08, 2010, 02:43:06 AM
i'd say go for truecrypt, being an open source supporter and all. At work we use SafeBoot, which comes with McAfee i believe. i dont know if it supports mac and linux as well, but i'm pretty happy with it.
550  Resources / Tutorials / Re: Free Books! on: March 08, 2010, 02:41:22 AM
remember that free information is always welcome (one way or the other), but support the hacking community and BUY books you really like and use them often. it also looks good to have a full bookshelf, even if it is just to impress your (hacker)friends Cheesy
551  Ethical Hacking Discussions and Related Certifications / Web Applications / Re: What is possible in Webpage hacking? on: March 08, 2010, 02:37:00 AM

this is probably the best link for web application testing!

all the methods are explained and even how to test them yourself! just start with this document and try all the different vulnerabilities/attacks. make a chart of what worked, what didnt work, how it worked and how you will prevent them from happening in production. this is probably the best way to test it (atleast best practice)
552  Columns / Linn / Re: [Article]-Final Course and Exam Review: Pen Testing with BackTrack on: March 08, 2010, 02:33:32 AM
@ zeroflaw: break open that piggybank!

@ Ryan:

thanks for explaining the differences between the certificates. i must say according to my experience youre right about CEH, however it does cover some thinks like snort, so it isnt completely 100% offensive. i think CEH and GCIH will be pretty close information wise.

i really like the part you wrote about where to go next after CEH/GCIH. i believe web application will be hot in the next few years. the focus will be shifted from network/os to (web)application. maybe this is the best step after getting your basics.

you wrote you had prior knowledge about writing scripts for nmap and metasploit, and writing simple buffer overflows. how did this help in studying for OSCP? i'm trying to get a feel how technical you have to go for this cert. i have little knowledge of programming but understand the concepts of writing for example buffer overflows. i'm afraid my lack of (good) programming skills will slow me down during the training. what do you think?

last but not least: good luck with the CTP cert, although i think you will do just fine  Wink
553  EH-Net / News Items and General Discussion About EH-Net / Re: [Article]-March 2010 Free Giveaway Sponsor - Offensive Security on: March 07, 2010, 05:56:07 AM
Great work on the giveaways! you would almost think i signed up just for this! Wink good luck to all and keep up the good work!
554  EH-Net / News Items and General Discussion About EH-Net / Re: [Article]-Feb 2010 Free Giveaway Winners - Syngress Publishing on: March 05, 2010, 06:37:16 AM
Awesome.  I couldn't be happier.  I'll be sure to post book reviews as I get the books (and read them of course).

Thanks Don for a great site with great sponsors!

congrats! can't wait to see the reviews!

@hayabusa: just wait until you received the books, them the drooling will start for sure!
555  EH-Net / News Items and General Discussion About EH-Net / Re: [Article]-Feb 2010 Free Giveaway Winners - Syngress Publishing on: March 04, 2010, 02:27:22 PM
Congatulations! keep up the good work!
Pages: 1 ... 35 36 [37] 38 39 40
Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.095 seconds with 21 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Free Business and Tech Magazines and eBooks

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.