|
EH-Net
|
|
May 22, 2013, 06:15:33 AM
|
Show Posts
|
|
Pages: 1 ... 5 6 [7] 8 9 ... 40
|
|
91
|
Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: What might you do?
|
on: July 29, 2011, 07:42:40 AM
|
2. here some pointers, remember that access isnt always enough. the ultimate goals is root/admin rights, also known as rooting the box!
I'm sorry but this is just wrong. The ultimate goal is whatever the objective of the pentest is. That is almost never root. The CIO rarely cares that you got root. He cares what you can do with it, the data you can access/exfiltrate, records you can mangle, etc depending on the nature of the business and what has value for them or what can create significant negative impact for them. Sure, root access can help you get there, but that's not the end goal. Focus on the data and however you can get at the data. A lot of times you will never need root to succeed in your test. true, but giving the context where O_o is operating in (a virtual environment playing at home in a pentest lab) the ultimate goal is root, not whipping up a report for his CIO pointing out all the vulnerabilities. i agree that finding more vulnerabilities and pointing out what can be done with his data is more useful that focussing on just one and obtain root access. Sorry for the misunderstanding, i will try to be more specific next time.
|
|
|
|
|
94
|
Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: What might you do?
|
on: July 29, 2011, 03:03:27 AM
|
|
1. we are hackers, our mission is to manipulate a system in such a way it will do what we want it to do, which is in none of the case a DoS. DoSing wont help you get access to a computer, ever! so forget about DoS exploits, which are fine for disgruntled n00bs who have some sort of beef with a specific target.
2. here some pointers, remember that access isnt always enough. the ultimate goals is root/admin rights, also known as rooting the box! here a few things of the 1000s that can be done: with null session you mean you gained access to a windows share right? next i would see if i had write permissions and upload (malicious) code, preferably in the language of a service i could access through another way (see where i am going with this?) try to access the filesystem to, if an old box, download the sam backup file to brute force login credentials offline. be creative and see what you can find (perhaps batch scripts that contain login credentials?)
|
|
|
|
|
96
|
Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Your First Pentest
|
on: July 29, 2011, 02:54:01 AM
|
|
not my first (which was a complete fiasco because i was into security for about two weeks, firing random exploits and such) but a funny one:
i was doing a pentest on a web application that offered e-commerce functionality. it was possible to view the service after you purchased it. after providing your credentials it did around 2 or 3 authentication checks, but then you were redirected to an url that had the ordernr as an url parameter. changing this provided you with the order information of other customers. now the funny part was that all the information was provided in formfields, but were not editable. in the code there was a parameter like: CanModify=false. setting this to true lets you change the order and contact details of the person...
|
|
|
|
|
98
|
Ethical Hacking Discussions and Related Certifications / OSCP - Offensive Security Certified Professional / Re: OSCP - Time Commitment Required
|
on: July 29, 2011, 02:37:43 AM
|
|
hmm, if you can bring up the discipline to really study every day(!) for about 2 hours and put some more in during the weekend, it can be done. i probably did it the same way you will. remember that it will take a lot of time from you, and besides that, get ready to be exhausted after studying for that long in a row, i have days i am tired from just working, and i am sure i will not be able to study when i get home.
bottom line is only you can make that decision if you are able to pull it off, just dont underestimate it...
|
|
|
|
|
103
|
Ethical Hacking Discussions and Related Certifications / CEH - Certified Ethical Hacker / Re: still waiting...
|
on: July 12, 2011, 02:39:59 AM
|
I think there's much confusion, so let me try this to clear things up from my own experience and reading many other posts on the topic...
- The backpack only comes with certain packages of training materials. - The physical certificate takes anywhere from 1 week to 1 year and never includes a backpack. - EC-Council is notorious for not getting back to you.
If you know this going in, hopefully it will cause less stress coming out.
Don
Thank you, but dont get me wrong, i could not care less about the backpack  @bickmade: good to see you are getting somewhere, i received the training kit from the institute i took the course at, so i dont know how long it took them to receive it...
|
|
|
|
|
Loading...
|