Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 42 guests online
 
Advertisement

You are here: Home
EH-Net
May 21, 2013, 06:49:03 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
  Home Help Calendar Login Register  
  Show Posts
Pages: 1 ... 4 5 [6]
76  Resources / Mass Media / Re: Metasploit Penetration Testers Book on: January 21, 2011, 09:01:51 AM
(and I get less grief from the missus for sitting reading a book, than sitting with a laptop on my knee 24/7 Wink )
^^^^^^^^^^^^^
THIS Smiley
77  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Security Assessment Inquiry on: January 18, 2011, 03:28:03 PM
The system has recently gone live so we are also looking at this as a ongoing security maintenance type thing...if that makes any sense.

As part of your lesson's learned, your vulnerability analysis and potential remediation steps should probably have been done prior to this step of going live.  If it is publicly live, I am sure lots of people have already performed the test for you Wink.
78  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Reliably determine the Operating System and Service Pack on: January 12, 2011, 01:54:56 PM
In a windows environment I occasionally get better results with the smb-os-discovery script in NMAP than simply using automated os detection.
79  Ethical Hacking Discussions and Related Certifications / Other / Re: Security Best Practices at Home on: December 22, 2010, 03:59:50 PM
Since rainbow tables are generated with SSIDs, I would suggest using a randomly generated SSID of sufficient length (depends on wireless vendor) and then a strong passphrase (randomly generated as well perhaps).  I would expect that to be good enough for home networks.
80  Ethical Hacking Discussions and Related Certifications / Networking / Re: Secure Network Design on: December 21, 2010, 08:49:16 AM
Personally, as long as you are using a "good" firewall (easy to administer, secure, works for you), then I would not go with a different vendor if the same group will be administering a lot of other equipment as well.  I do not think the overhead is worthwhile, and particularly not so if you use firewall management software from the same vendors (logging, configuration management, etc.).
81  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Highest possible Anonimization in internet by Ip spoofing and vpn chaining? on: December 20, 2010, 12:28:21 PM
1)  a-yes,b-maybe.  Most likely most protocols will work, but there are a lot of variables out there.

2)  Properly configured routers will only allow a source address they know, so it may kill the request right away.  Either way, if the packet does make it all the way to the internet with a spoofed source IP, the response (SA) will never make it back to you.  However, you can include a payload with a SYN packet, and with a specially constructed IP stack, you could use this for 1-way communication.

3)  If you really want "anonymous" traffic, rent a botnet and bombard them with packets.  It will be difficult to pick out the real traffic and if you use tech like VPN/Proxy/AnonEmail to work with the bot operators, it should be fairly difficult to track you down (at least until the bot operators are caught and start yapping).
82  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Detecting virtualization on servers located behind routers? on: November 19, 2010, 02:06:56 PM
You can actually specify the MAC in the vmx file in vmwware I believe.
83  Ethical Hacking Discussions and Related Certifications / Physical Security / Re: Learning lock picking on: November 12, 2010, 10:33:09 AM
Picks are like peckers....if you break it you are probably doing it wrong.  That being said, it is not hard to bend/break them while learning.
84  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Port Scan from random Source IP's on: October 22, 2010, 09:56:43 AM
tturner - why do you need access to the idle host?  I think you just need to have an open tcp port to use for the idle scan to increment the IP ID, but you don't need anything further.  Or did I misunderstand and you meant access as being such?
85  Ethical Hacking Discussions and Related Certifications / Security / Re: The value of GSE on: October 14, 2010, 08:40:29 AM
steven1664 - I think the problem with your thinking on GSE being Level III, is that there are only 29 GSEs worldwide.  They have to fill more than 29 positions, so they have to have a fallback.  Perhaps a combination of a couple of certs would be more to your thinking, though?
86  Ethical Hacking Discussions and Related Certifications / Forensics / Re: Starting off Pay on: October 14, 2010, 08:37:54 AM
In my previous life, I would have hired in a network technician with a couple of years experience around the 45k figure.  With no experience, but a great interview, I would probably go about 2 years of raises lower than that (~40k).  But, I must say our IT salaries in my part of the country are pretty low, but so is our cost of living.
87  Ethical Hacking Discussions and Related Certifications / Hardware / Re: Hardware Firewall Purchase on: September 29, 2010, 02:10:26 PM
Obviously you and Sil have had different experiences with the Fortinet products than have I.  We used quite a few (~50-60), mostly in the 60/60b/80c range with a few 300 as well.  We did not have much trouble out of them and often did not run bleeding edge code on them.  We did use IPSEC and SSLVPN without issue, and yes, the missing GUI for mac reservations was irritating, but not a show-stopper.

They also support routing, up to and including BGP (though I can say I never used BGP on one since ours were too small).  OSPF and RIP worked perfectly, though.  We used them for nearly all of our non-core routing without issue at our WAN sites.

All that being said, we also used a SA4500 SSLVPN from Juniper that was far ahead of Fortinet's SSLVPN offering.  That would stand to reason, though, since Fortinet's was  bolt-on to list a feature (though it was quite usable for small implementations).

Fortinet support was not so good, but to be honest, we rarely had reason to call them.  Support is definitely a weakness for them that they will have to work on in order to improve market share.  Additionally, I think QA in their software side is next in line to get spanked if they do not improve.

In my experience, for the products we were purchasing, Juniper could not compete on a bang-for-the-buck comparison.  When we demoed Fortinet initially, we compared them to the Pixs and the NetScreens (now Juniper) and chose them due to simplicity and cost (and I really do not like Cisco products outside of routers for the most part).  As I stated before, each to his/her own.
88  Ethical Hacking Discussions and Related Certifications / Hardware / Re: Hardware Firewall Purchase on: September 20, 2010, 01:01:01 PM
Each to their own re: Fortinet.  In my previous life we had > 50 of these units and the only issue we had out of any of them were early models CF cards going bad.  Otherwise they were rock solid.  Their support can be slow at times, but if it is an urgent ticket, calling will normally get things resolved more quickly than sending email.  However, I would have to agree that their support is a weakness, but stand by the statement that they are a solid product.

The Juniper SSGs are also a good product line, but they are not in the same price point.  It all depends on what you need and what your budget is.
89  Ethical Hacking Discussions and Related Certifications / Hardware / Re: Hardware Firewall Purchase on: September 17, 2010, 09:14:51 AM
Look at Fortinet.  They make a solid product at a competitive price.
90  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Masters Degree on: September 09, 2010, 03:59:48 PM
SANS.edu as well...
Pages: 1 ... 4 5 [6]
Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.084 seconds with 21 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.