Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 45 guests and 1 member online
 
Free Business and Tech Magazines and eBooks

You are here: Home
EH-Net
May 18, 2013, 06:35:05 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
  Home Help Calendar Login Register  
  Show Posts
Pages: [1]
1  Resources / Looking For Work / Re: Looking for security opportunity on: March 01, 2013, 05:57:28 PM
Thanks guys! Experience: I have managed network penetration test and network assessment projects. Analyzed several IDS/IPS logs and investigated incidents.
Vuln assessment with nessus, nmap experience.

I have also installed, configured, and managed firewall, switches, vlan.

Thanks H1t M0nk3y but I am not considering moving to Ottawa at this moment.

This is not to brag but just sharing excitement with you guys like a kid would when he has some good news/goodies. So last Wednesday, I received an email from ISC2 informing me that I am now a cissp holder.
2  Resources / Looking For Work / Looking for security opportunity on: February 26, 2013, 11:38:20 PM
Any one know of some one in Calgary, Alberta, Canada that's hiring, please let me know.

I have more than 12 years in the I.T and 5 years spent in the security field. GPEN, GAWN, GISP and passed CISSP exam, just awaiting endorsement.

Thanks,

Bushman
3  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: certifications dilema on: June 18, 2012, 02:57:58 PM
A thank you to though who have responded so far.

However, I should add that I am not really interested in the HR or job hunt certs. I must say that even though all of us would like the pay but I am more into a REALY STUFF! I am interested in skills development, personal challenge and self satistifaction.
4  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / certifications dilema on: June 18, 2012, 01:18:51 AM
Hi guys,

Here are a few certs that I can find with their respective training institutions. They all look sexy and self proclaimed as being the best cert.

CPTC - Certified Penetration Testing Consultant     25421
CPTE - Certified Penetration Testing Engineer     34894
CSTA - Certified Security Testing Associate             3614
GPEN - GIAC Certified Penetration Tester             33170
OSCP - Offensive Security Certified Professional     36097
CEH - Certified Ethical Hacker                             90494
ECSA - EC-Council Certified Security Analyst     29890
CEPT - Certified Expert Penetration Tester            26267

However, the question I have been wrestling with is which one of these ethical hacking or pentesting certifications and trainings truly and genuinely offer the best material in the world? Categorizing them in the best being 1, how would you rank them in term of quality, depth, practicality and maturity?
I have only taken SANS training but have read a lot about the other ones' testimonies, reviews and talk to a few friends who have taken for example OSCP and CEH.

Could any one of you guys attempt to answer this question if you have taken a few of these courses and certs. Please provide some comparisons if you wish on tools covered, instructors' experience, labs setup and etc.

I am excited to hear from you and would like to thank you in advanced.
5  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Attending SANS617 Ethical Hacking, Penetration Test and Defenses by Josh on: September 13, 2011, 02:45:12 PM
Hello everyone,

I am excited that I am attending the above mentioned course in Las Vegas, starting Sept. 19-24/11. It will be taught by Mr. Wright, the author of this course and after attending the SANS560 last year taught by Ed and knowing the quality of SNAS instructors, I thought some of you might be interested in asking Mr. Wright some pointed questions.

This is your chance if you had some doubts in regard to certain parts, tools, methods or you are unable to attend this course for whatever reasons but had wanted to ask, please just reply to this post and I will take a bag full of your questions to Josh.

I have read Don's review of this course but it has been a while since that review and I am excited take a critical look if there has been some inclusion of what Don mentioned.

I promise to share his responses/answers with you when I get back. I am looking forward to your responses or suggestions for those of you who have taken this course.


Thanks,

Bushman
6  Ethical Hacking Discussions and Related Certifications / GPEN - GIAC Certified Penetration Tester / Passed GPEN, next ? on: May 03, 2011, 05:44:43 PM
Belated news but still worth mentioning.

How I prepared for it.
First, I attended SANS live training last year in Vegas and then bought the bundle for 4 months which gave me a vpn access to their systems to practice/hacking.
Also SANS provides their "ondemand" access for the 4 months which is a recorded training for the course and of course Ed Skoudis is amazing.

GIAC provides two practice test exams as a prep for the real thing. It is a representative of the real exam but not the real exam.
I listened to all the recordings, practiced all the lab and capture the flag, reread all the five text books provided and prepared indexes for the exams since it is an open book.

Then launched for the exam which I managed to pass for the first time.

My next goal is to take the OSCP training and test but according to the reading I have done so far, it sounds like this is more challenging than the GPEN.
For those who have taken the OSCP and GPEN, what is your feel? Do I have a chance or no? I have no programming knowledge but the rest of the requirments, I can get well along.

I am currently working with BT4 and practicing all the tutorial provided by the offensive sec on the metasploit unleashed in my lab.

Bushman
7  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: How to discover traces of a compromised system on: February 14, 2011, 12:24:27 PM
Thanks to everyone who has responded to this and your links to other sites.
However, I am thinking here purely on the prospective of a pentester doing his job without any knowledge of a breached on the network.

Also, when looking around after he compromised the target system, he is looking to further escalate privileges, delve deeper into the system but before doing all of these, he wanted to make sure that he is not contaminating any previous compromised by the real bad guy.

Is there any commands for him to run to verify previous breach? If rules of engagment allow, what tools could he utilize to determine any previous compromised?

Does this little explanation help in understanding what I am saying?

Any idea/suggestions would be appreciated.
8  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / How to discover traces of a compromised system on: February 11, 2011, 05:27:42 PM
He folks,

I was wondering about this scenario. You are hired to do pentest and while doing your pentest, you have to successfully compromise the target system (Windows or Linux). You started to look around for Windows, you run sc or sc query commands, net and etc sommands.
How would you know that the target system(s) had been compromised so that you can turn the pentest into investigation/forensic phase, given that fact that you are a pentester pro. not incident handler or forensic invetigator?
Are there specific skills that you need to have being a pentester in order to find traces of a compromised systems?

Your turn, any idea/suggestions?
9  Resources / Looking For Work / Rules of engagement sample for internal pen test on: January 28, 2011, 11:01:13 PM
Pentesters,

I am looking for a samples rules of engagement and liability agreement for our internal pen test. Just something to get me started since this is my first time doing pen test for our internal systems. I would be grateful for any pointers.

Please email it to me or send me a link if you have one.

Thank you all for your help.

Bushman
10  Ethical Hacking Discussions and Related Certifications / Cyber Warfare / Re: Please guys, I really need your help on: December 06, 2010, 05:35:55 PM
Besides all other recommendations by others, I would suggest that you hire professional pentester(s) who can figure out things for you - why this is happening, which vuln. is exploited and how to fix it for you legally.

It may cause you some $$ but it is the final blow to them and relief for you.

But for any person to start attacking/hacking this site withour proper procedures, will be liable to breaking the law and risk going to prison.

Hope this help
11  Ethical Hacking Discussions and Related Certifications / Cyber Warfare / Re: Wikileaks & the Security Community on: December 06, 2010, 05:19:05 PM
Here is my little 2 cent contribution! If any security pro. is really in doubt about this issue, you should be attending the SANS 560 that will put every issues raised here to rest. I am not ad. SANS here nor am I working for SANS. I am not even associate with them.
Qoute "hack and pivote mercilessly but within the rules of engagement". From whom did this guy get his permissions to hack/obtain this info? Which systems were he limited to hack?

Unless you are the bad hacker/guy who breaks cyber laws, then you can fear but if you are a real security pro., you fear not.

Judge for yourself.
12  Ethical Hacking Discussions and Related Certifications / GPEN - GIAC Certified Penetration Tester / Re: SEC560 on: December 03, 2010, 01:55:04 PM
Thank you!!

Just wanted to drop this thank you email for those of you who have taken their time to answer my concern and I do appreciate your humble advise.

I am gearing up for this and becuase of you honest encouragement, I feel better.

I will keep you updated.

Bushman
13  Ethical Hacking Discussions and Related Certifications / GPEN - GIAC Certified Penetration Tester / SEC560 on: October 01, 2010, 06:29:28 PM
Need help and couching on how to pass this exam. I just attended the live training in Vegas and have registered for the exam and the OnDemand Bundle which gives me access to the same training material and mp3s for 4 months.
But I am still nervous about this cert and would appreciate any help/tips on how to be well prepared to pass this exam. If you would like to share your indexes, tips, cautions, etc, please feel free to email me at yuguwani@hotmail.com

Thank you in advance.
14  Ethical Hacking Discussions and Related Certifications / GPEN - GIAC Certified Penetration Tester / Re: Reminder: Free GSEC and GPEN practice exams on: August 10, 2010, 11:33:19 AM
Hi,

Not sure if your GPEN still valid but I am taking the SEC560 course with Ed in Vegas. If it is still valid, I would appreciate if you could award this to me.

I am more of a Windows guy:)

Let me knw, please.
Thanks
Pages: [1]
Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.085 seconds with 23 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.