Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 37 guests and 2 members online
 
Advertisement

You are here: Home
EH-Net
May 24, 2013, 10:45:11 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
  Home Help Calendar Login Register  
  Show Posts
Pages: [1] 2 3 ... 9
1  Ethical Hacking Discussions and Related Certifications / Web Applications / Re: Nessus and Nikto on: May 18, 2013, 02:56:21 AM
i can't watch that movie IDK why anyway:

is network established between you and the target? can you ping it?
Can you scan the target with nmap?

Is your target on internet? if it is:
Are you behind any firewall? If you are, try this scan:
Code:
nmap --scanflags SYNFIN <Target IP address>
This may bypass the firewall.
Always scan the server using IP address because they may implemented network load balancing so you may scan different servers each and every time.

Is your target in a virtual lab? if it is:
Make sure that you attack system and server are using a same network adapter otherwise they can't connect to each other.
check your IP addresses for both systems

i hope this info can be helpful if not tell me i will watch the vidoe.

Huh?
2  Ethical Hacking Discussions and Related Certifications / Web Applications / Re: Nessus and Nikto on: May 15, 2013, 02:20:53 AM
Looking at the audit trail, I see the following message:

Nikto was not found in $PATH

When logged in as root or a normal user Nikto is in my path.  Is there anyway to view the path nessus is using?  Or is there a system path I can change?  Thoughts?
3  Ethical Hacking Discussions and Related Certifications / Web Applications / Nessus and Nikto on: May 14, 2013, 12:13:53 PM
I've been trying to integrate Nessus and Nikto.  I've followed all the instructions on this video:

http://www.youtube.com/watch?v=6kHyAhFv7xg

But when I run the scan nothing seems to happen.  Meaning no new vulnerabilities appear compared to a Nessus scan that doesn't have Nikto enabled.

The only information I was able to find in nessusd.messages was the following:

Code:
launching nikto.nasl against 192.168.0.125 [1251]
nikto.nasl (process 1251) finished its job in 0.010 seconds

This seems incredibly fast compared to running Nikto from the command line, which works fine.  Does anyone have any ideas on how to get this working, or where on my system I could check to find additional information on what is happening?

I'm running CentOS 6.4 x64 and Nessus 5.2.

Thanks.
4  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Elearnsecurity new Web App security course info on: May 01, 2013, 12:51:45 PM
Thanks for clearing that up Armando!
5  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Elearnsecurity new Web App security course info on: April 30, 2013, 02:42:24 PM
Does anyone know how the lab hours work?  I was planning on buying now, and then starting the course in a few months, but it says "90 days to activate Coliseum WAPT Lab?"  Does that mean I have to use 60 or 90 lab hours within 90 days, start using them within 90 days, or what?

I typically like to go through all the material before I do the labs, it helps me find out if I've retained the info.
6  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Elearnsecurity new Web App security course info on: April 23, 2013, 12:25:50 PM
I may do the course once gold is out the way tho as I got free upgrade since I don't want be in situation where I trying to do both at once.

My thoughts exactly Jamie.  I hope to start on Gold in July.
7  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Elearnsecurity new Web App security course info on: April 20, 2013, 01:42:32 AM
Looking at the syllabus, I kinda got the feeling that the labs were an integral part of the course, and not just supplemental.  In which case, I was assuming there would be unlimited access, but maybe that was just wishful thinking.
8  EH-Net / News Items and General Discussion About EH-Net / Re: Change is Coming to EH-Net!! on: April 13, 2013, 02:04:52 AM
I'm ok with making changes.

I don't use PM very much.

Unfortunately, right now I'm pretty busy so I don't have time to help test the site.

I don't use OpenID or Twitter.  As long as they aren't required, I'm fine.
9  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: eLearnSecurity: New Web Application Security Courses on: April 05, 2013, 01:59:22 AM
So now I have to finish eCPPTv2, eCPPT Gold, and then do this.  I can't wait for a course that adds more hours in the day Smiley
10  Ethical Hacking Discussions and Related Certifications / General Certification / Re: Hackingdojo on: February 28, 2013, 11:23:42 AM
I've done most of the Shodan course, however I failed at cracking some passwords. Despite that I tried idunno, 50-100'000 relevant variations of the mentioned topic, and 165 million random different passwords. Did any of them crack? Nope.

I failed at cracking some of the passwords as well MaXe.  I spent weeks after trying to crack them but couldn't get them.
11  Ethical Hacking Discussions and Related Certifications / General Certification / Re: SANS Work-Study experience on: February 16, 2013, 12:45:03 AM
Do you know that you can also volunteer for a SANS' online course?

And you get the same discount?  What exactly are your obligations?

I'd be interested in learning about this as well.
12  Ethical Hacking Discussions and Related Certifications / ECSA - EC-Council Certified Security Analyst / Re: Passed! on: February 02, 2013, 01:08:09 PM
Congratulations.   j0rDy do you recommend going after the ECSA?  Is the information you are required to learn useful?  Since I won the LearningGate training I was considering doing the ECSA after the CEH, but not a lot of jobs require the ECSA so I would only go after it if earning it would teach me something. 
13  Ethical Hacking Discussions and Related Certifications / General Certification / Re: Certification Advice on: January 09, 2013, 05:58:29 PM
I find that certs are the only way to force me to learn usefull but boring things. Without a goal/carrot in front of my, I either get lazy or study only what I like.

There have been many discussions on certs vs experience on this site and I think most people agree that experience is more important, while *some* certs open doors (get you through HR screening) and *other* certs/training programs make you a better pentester.

For example, CISSP vs OSCP are pretty much opposite to each others...

I completely agree.  I get callbacks on about 80% of the jobs I submit my resume for, but I have trouble passing some of the technical interview questions, so I'm more focused on things like eCPPT and OSCP which will give me knowledge.  On the other hand, someone who knows more than I do but doesn't get past HR screenings would probably do better to get a CEH or CISSP.
14  EH-Net / News Items and General Discussion About EH-Net / Re: [Article]-October 2012 Free Giveaway Winner of LearningGate Training on: December 27, 2012, 06:00:43 PM
Excellent!  Merry Christmas and Happy New Year to me!

Anyone have any thoughts on what certs I should start off with?  I'm thinking CEH.  While I don't think I'll necessarily learn much, it's good to have on the resume, I just never wanted to pay for the course needed to earn the cert.

If anyone has any other suggestions, let me know.

Thanks again Don and EH-NET!
15  Ethical Hacking Discussions and Related Certifications / Programming / Re: SecurityTube GNU Debugger Expert on: November 26, 2012, 05:57:49 PM
Has anyone taken this?  Any thoughts?
Pages: [1] 2 3 ... 9
Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.081 seconds with 21 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.