Image
 
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 21 guests and 2 members online
EH-Net Donations

Enter Amount:
$

Google Ads
EH-Net News Feeds
Latest Additions
Book Recommendations





 
Advertisement

You are here: Home arrow Forum
Ethical Hacker Community Forums
December 02, 2008, 08:58:55 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: ChicagoCon 2-Day Ethical Hacking Conference with MS Blue Hats Oct 31 - Nov 1. Tickets Only $100! www.chicagocon.com/content/view/103/51/
 
  Home Help Calendar Login Register  
  Show Posts
Pages: [1] 2 3 ... 5
1  Ethical Hacking Discussions and Related Certifications / Other / Re: OpenVPN on Windows on: February 16, 2007, 03:57:58 AM
Quote
bah, restarting works wonders Tongue

M$ problem solving: Minor problems - reboot, major problems - reinstall ...

2  Ethical Hacking Discussions and Related Certifications / Other / Re: OpenVPN on Windows on: February 15, 2007, 11:22:04 AM
It seems that you are mixing routing and bridging.

Did you create the bridge in windows ? You'll have to do that manually outside of openvpn.

Do you really want to bridge ? (it's not advisable if you're connecting via the internet, a lot of unnecessary traffic will go over the wire...)

If you decide to use routing (that's what I would do) remember that you'll have to activate routing (IP-forwarding) in windows either via MMC-SnapIn "Routing and RAS" or via setting the registry key manually.

BTW, if you don't specify "pull" in the client config no setting will be pushed from the server, so have a look at that too.

3  Ethical Hacking Discussions and Related Certifications / Other / Re: OpenVPN on Windows on: February 15, 2007, 06:54:56 AM
Never had any problems.

Post your config if you need help.

4  Columns / Editor-In-Chief / Re: To DMZ or not to DMZ? on: February 05, 2007, 12:20:15 PM
A DMZ is another layer of security and you never can have too much layers when you are about to secure your network.

If you need to make a system accessible from the Internet I can't think of any reason to put such a system directly in a internal network - that would be the worst possible solution.

5  Ethical Hacking Discussions and Related Certifications / Forensics / Re: Forensic images of USB devices in Windows on: January 02, 2007, 05:35:42 AM
No matter what tool you are using you need a hardware write blocker to be absolutely sure to get a forensically sound image when doing it in windows.

There is a registry key to prevent write access to USB devices but I would not rely on that...
6  Ethical Hacking Discussions and Related Certifications / Hardware / Re: Securing Your Network from Scratch on: January 01, 2007, 11:30:37 AM
That is not a question of money. What you need is a concept - and the very same idea can be set up with $10.000,- or $100.000,-, the difference is reliability and the real level of security.

You can set up a system with a DMZ, an IDS, an IPS, firewall, proxy, mailserver etc. using just one Linux-Box - or a bunch of high-end servers, routers and appliances.

All depends on the needed level of security. As negrita pointed out you'll certainly not choose the option with one Linux-Box if you need to secure top secret information, the more applications runs on one system the more vulnerable it will be.

But for the scenario Don has described I would definitely go for the one Box solution to start with, it is easy to extend such a system as needed. I think the biggest problem in that scenario is who would be the person to do the job. A startup with 5 people will rarely hire a skilled admin ...
7  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Skype Network Scanning on: January 01, 2007, 11:11:19 AM
If you are in need of security you would not allow any encrypted traffic into your network - be it skype or any other app.

Terminate any encrypted channel at your perimeter if you really need security, otherwise you'll always be in big trouble....
8  Ethical Hacking Discussions and Related Certifications / Certification / Re: Poll on certifications on: January 01, 2007, 11:06:16 AM
It depends what cert you are talking about.

Certs which require a practical cannot be done only by studying braindumps, but there are not that many that require a practical (Red Hat, EnCE).

All of the mainstream certs (M$, Cisco, EC-Council etc) can be done just studying braindumps, but those who take them that way are easily spotted when they face the first real world problem (most of the certs have nothing to do with real world scenarios, thats one of the biggest downsides of these certs).


 
9  Features / Opinions / Re: Thoughts on Hamachi as a VPN on: December 09, 2006, 10:47:46 AM
It depends on your needs...

If it's for gaming or just sharing some MP3s - go for it, it's easy to use.

If you need a secure VPN solution to transfer sensible data - don't even think to touch it. How a VPN going through a server which is completely out of your control can be secure ? I would never trust it, but perhaps I'm paranoid.

10  EH-Net / News Items and General Discussion About EH-Net / Re: Need Everyone's Feedback!! on: October 21, 2006, 03:28:38 AM
I mostly agree with Negrita and Kev and I'd like to add another reason to use those kind of "study guides":

I've taken a number of different kind of tests so far (M$, Comptia, Mile2, Guidance) and found that the content - what was asked for - is somewhat questionable in a lot of these tests.

On one hand there are a lot of questions where the whole content (the question and the proposed answers) has nothing to do with real world or at least comprehensible  scenarios, on the other hand on some of these exams there are outdated and poor worded questions where even the meaning is hard to understand (not only on these study guides, I've seen this kind of questions on live exams too).

Even if you really know your business sometimes it's really hard to guess what answer they want to see - and that can make it sometimes hard to pass an exam without having the possibility to prepare yourself by the means of these "Study Guides".

The point is that the questions in these guides are often worded as bad as they are in the real exams - so without posting a question exactly as it is printed sometimes it is not possible to find the wanted (not necessarily the right) answer...
11  Ethical Hacking Discussions and Related Certifications / CEH - Certified Ethical Hacker / Re: CEH question on Snortlogs (form Testking) on: September 25, 2006, 07:35:14 AM
I agree that the Answer would be C.

But sorry Negrita, I somewhat disagree with your explanation because:

1) though it is still possible it's not very likely that somebody still has valid accounts/passwords in the dummy passwd file used by most ftp-servers
2) why an attacker would wait more than 36 hours to login after retrieving a valid account ? (sure it could have happened that way, but I don't think so.)

Look at these entries:
Quote
Apr 25 02:08:07 [5875]: IDS277/DNS-version-query: 63.226.81.13:4499 -> 172.16.1.107:80
Apr 26 06:43:05 [6283]: IDS181/nops-x86: 63.226.81.13:1351 -> 172.16.1.107:53
Apr 26 06:44:25 victim7 PAM_pwdb[12509]: (login) session opened for user simple by (uid=0)
Apr 26 06:44:36 victim7 PAM_pwdb[12521]: (su) session opened for user simon by simple(uid=506)

It looks like an attacker has first discovered a certain version of DNS-server-software (most likely some vulnerable version of bind), then exploited a buffer overflow (NOPs are often part of the payload to exploit buffer overflows) and then logged in first with an unprivileged account and then su'ed to a privileged account...

BTW, I found that log somewhat familiar - if you are interested in the whole story have a look here


12  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Test your Hacking Skills on: September 22, 2006, 12:27:46 AM
Quote
I was trying to send the following to the server as the username:
' or 1=1; --

That query works, but you have to add a space after the double dash to get it working.

Quote from: mysql reference:
In MySQL, the ‘-- ’ (double-dash) comment style requires the second dash to be followed by at least one whitespace or control character (such as a space, tab, newline, and so on)
13  Ethical Hacking Discussions and Related Certifications / Forensics / Re: OS Detection from a RAM dump on: September 16, 2006, 10:48:08 AM
Harlan does a lot of great work - but why should somebody need to determine the OS from a RAM dump ? When you're in front of computer doing a RAM dump in general you know what operating system is running on that box.

What do you think about, perhaps I'm missing something?
14  Resources / News from the Outside World / Re: A Wireless Hacking Computer That Can't Be Hacked on: September 11, 2006, 11:14:19 AM
Of course, but you don't need a wireless card to crack the key, you'll use it just to capture data.

Multiple wireless cards won't give you the ability to do multiprocessing as opposed to have multiple processors.
15  Resources / News from the Outside World / Re: A Wireless Hacking Computer That Can't Be Hacked on: September 10, 2006, 04:49:30 AM
Quote
In addition to scanning for wireless traffic, Williams says the computer can break most WEP keys very quickly by focusing all eight wireless cards on the access point. Using a combination of common utilities like airreplay, airdump and aircrack, Willams said, "When I use all 8 radios to focus in on a single access point, [the WEP key] lasts less than five minutes." However, he added that some retail wireless access points will "just die" after being hit with so much traffic.

I canot see the reason why WEP would be cracked more quickly using 8 cards instead of one.

In most cases you'll just capture traffic sent by the access point - so one card will do it. In case that you're running a replay attack with ARP packets  you'll flood the access point with packets at the speed it supports, so where's the advantage of using multiple cards ?

If you are trying to crack multiple access points you'll benefit from that box, but I doubt that you'll get it done quicker when just targeting a single access point.

Pages: [1] 2 3 ... 5
Powered by MySQL Powered by PHP Powered by SMF 1.1.7 | SMF © 2006-2008, Simple Machines LLC
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.049 seconds with 21 queries.
 
Sponsors

cwnp_moto__120x90.gif

Polls
During the most recent election, I:
 
Support EH-Net


Support EH-Net by
Buying all of your
Amazon items using
the search bar above.

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!
Recent Forum Topics
Vote For EH-Net

progenic.com
Click here to Vote!

Sadikhov.com
Top IT Cert Sites

binarica.com
Binarica Logo

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2008 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.