Image
 
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 20 guests and 2 members online
EH-Net Donations

Enter Amount:
$

Google Ads
EH-Net News Feeds
Latest Additions
Book Recommendations





 
Advertisement

You are here: Home arrow Forum
Ethical Hacker Community Forums
December 02, 2008, 09:09:53 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: ChicagoCon 2-Day Ethical Hacking Conference with MS Blue Hats Oct 31 - Nov 1. Tickets Only $100! www.chicagocon.com/content/view/103/51/
 
  Home Help Calendar Login Register  
  Show Posts
Pages: [1]
1  Resources / Tools / Re: Nipper - Network configuration audit tool on: March 14, 2008, 12:49:49 PM
Kudos on a nice comparison writeup RR!
2  Resources / Tools / Re: Nipper - Network configuration audit tool on: March 14, 2008, 09:32:34 AM
Thanks for the update RoleReversal,

Iit would be curious to run both tools on the same config and compare the results. I tend to think of the CIS as sort of a "standard" or "best practices" for benchmarks... from their website:

Quote
How are the CIS Benchmarks created?
The CIS Benchmarks are created through a consensus based process involving dozens or hundred of experts from around the world and each of the three major sectors: government, private industry, and academic institutions.

These experts meet virtually through email lists and teleconferences facilitated by CIS to discuss security configuration recommendations that comprise a CIS Benchmark.  Because agreement doesn't always come easy, this process can take anywhere from weeks to months.

In the end, this unique process helps to create comprehensive security guidance that is applicable to a wide audience.

As far as your other question goes, you have to fill provide name, email and accept TOUA before download. Although email address or personal info is NOT verified (by confirmation email or otherwise). You get access to download right away.
3  Resources / Tools / Re: Nipper - Network configuration audit tool on: March 14, 2008, 08:34:15 AM
Quick disclaimer, I have not used the tool, I'm basing my observations on information that was on the website:

My concern was that I could not find any information on what the tool bases the audit results on? I always had great results using CIS RAT. Their benchmark guide is detailed and fairy well written. A person auditing an IOS/PIX device has access to details of the recommendation made by the tool, not just pass or fail.

pseud0, if you are concerned about this particular tool's impact on the audit device (as we all are with any audit tool) best option is to save config file and run audit on a file instead of pulling it directly from the device.
4  Resources / Tools / Re: Tools for auditing folder/file permissions on: February 29, 2008, 10:21:33 AM
I had pretty good results with DumpSec (formerly DumpACL), and its FREE

Quote
SomarSoft's DumpSec is a security auditing program for Microsoft Windows® NT/XP/200x. It dumps the permissions (DACLs) and audit settings (SACLs) for the file system, registry, printers and shares in a concise, readable format, so that holes in system security are readily apparent. DumpSec also dumps user, group and replication information.

http://www.somarsoft.com/
5  Resources / Tutorials / Re: Unfreeze The Deep Freeze - Step by Step tutorial to bypass Deep Freeze on: February 28, 2008, 01:50:27 PM
Version 6 may not be vulnerable. Remember, this issue came out in 2005.

http://www.securiteam.com/windowsntfocus/5XP0H1FG0S.html
6  Ethical Hacking Discussions and Related Certifications / Programming / Re: Help with some bash script on: January 31, 2008, 12:09:15 PM
Here is the quick and dirty that might work for you:

Code:
cat file1 |while read line; do grep ${line} file2 ; done
7  Resources / Tools / Re: Web Application Scanners on: January 09, 2008, 08:17:35 AM
I'm interested in opinions on commercial scanner applications, not managed services.
8  Resources / Tools / Web Application Scanners on: January 08, 2008, 02:06:30 PM
There has been a lot of talk about Web Application Scanners and their effectiveness. There are a lot of industry articles (Rolling Reviews, etc) blog posts and independent reviews (Larry Suto's paper) and the rebuttals from HP/IBM. I was wondering what the personal opinions of this forum's members are. Does anyone have a preferred WAS?

Cheers!
9  Ethical Hacking Discussions and Related Certifications / Certification / Re: FREE Juniper certifications for Cisco Certified peoples. on: December 07, 2007, 10:44:05 AM
Cool. Thanks for the info.
10  Resources / Links to cool sites. / Re: Security and hacking forums. on: October 31, 2007, 12:53:04 PM
My personal favorite, especially if you're using BackTrack to learn:

http://forums.remote-exploit.org

Chuck-full of tutorials, insightful threads and fun!

Forums @ http://www.learnsecurityonline.com are also good

Cheers!
11  Ethical Hacking Discussions and Related Certifications / Hardware / Re: How do I recognize a multi-function printing device on a network? on: October 31, 2007, 09:20:20 AM
If the device supports SNMP you can use it to pull relevant information from the device. (make sure to change the default community string or better yet if the device supports it use SNMPv3)
12  Ethical Hacking Discussions and Related Certifications / OSCP - Offensive Security Certified Professional / Re: OSCP (Offensive Security Certified Professional) Certification on: June 06, 2007, 08:33:27 AM
IMHO Only basic Linux knowledge is required for OS101. Especially if you're planning on using BT distro (as it is recommended by OS team). And if get lost and can't remember/not sure of some linux commands or options, you can use my favorite: Google!  Tongue

13  Ethical Hacking Discussions and Related Certifications / OSCP - Offensive Security Certified Professional / Re: OSCP (Offensive Security Certified Professional) Certification on: June 05, 2007, 01:25:17 PM
Woot! Just got my OSCP cert! If anyone is on the fence about getting this, I have three words for you:

FANTASTIC! FANTASTIC! and ...wait what's the word I'm looking for, oh yea
FANTASTIC!

Kudos to Offensive Security team on making the experience fresh, enjoyable and challenging!
14  Ethical Hacking Discussions and Related Certifications / OSCP - Offensive Security Certified Professional / Re: OSCP (Offensive Security Certified Professional) Certification on: April 24, 2007, 10:06:20 AM
Just signed up for class. Can't wait to start! Thanx for a wonderful course writeup blackazarro. Cool
Pages: [1]
Powered by MySQL Powered by PHP Powered by SMF 1.1.7 | SMF © 2006-2008, Simple Machines LLC
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.059 seconds with 22 queries.
 
Sponsors

cwnp_moto__120x90.gif

Polls
During the most recent election, I:
 
Support EH-Net


Support EH-Net by
Buying all of your
Amazon items using
the search bar above.

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!
Recent Forum Topics
Vote For EH-Net

progenic.com
Click here to Vote!

Sadikhov.com
Top IT Cert Sites

binarica.com
Binarica Logo

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2008 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.