Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 64 guests online
 
Advertisement

You are here: Home
EH-Net
May 22, 2013, 10:23:08 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
  Home Help Calendar Login Register  
  Show Posts
Pages: 1 [2] 3 4 ... 9
16  Ethical Hacking Discussions and Related Certifications / Web Applications / Re: Web App Pen Testing training on: November 14, 2012, 12:43:56 AM
Just to reiterate what's already been said, I've told several people that the elearnsecurity course is the best entry level web security course out there.

It provides such a good foundation.  After taking the course, I started reading the WAHH, and I found the material in the book much easier to understand because of what I learned from the eCPPT.
17  Ethical Hacking Discussions and Related Certifications / Web Applications / Re: Mapping the Application on: November 06, 2012, 01:29:04 AM
I've only used Dirbuster once, I'll have to play around with it some more.

How accurate is nikto?  I've used it on 2 different servers and got a lot of false positives (PHP related issues on sites not running PHP!)
18  Ethical Hacking Discussions and Related Certifications / Web Applications / Mapping the Application on: November 05, 2012, 04:06:24 PM
I typically use Burp Spider and the BuiltWith Chrome Extension to map websites I'm testing.  Does anyone use anything else?  I'm always looking for new things to play around with.
19  Ethical Hacking Discussions and Related Certifications / General Certification / Re: Offensive Security's OSWE on: November 02, 2012, 04:54:22 PM
Did anyone take this course at Black Hat, or hear anything about it?  I haven't heard anything since it was announced.
20  Resources / Tools / Re: Nessus vs. OpenVAS on: October 19, 2012, 04:42:53 PM
Vuln scanners are a crutch. I still use them, but sometimes I find myself spending more time weeding out false positives and second guessing what I knew already.

I don't rely on vuln scanners too much, but I do like to use them to get a sense of the overall focus of security of a client.  If I run it and come up with 10 major issues, I know I might have to focus first on fixing simple things since it's most likely the case that the admin hasn't really viewed security as a priority.  Kind of like running an antivirus scan, if it comes up with 40 viruses, i know it's going to be a pain to clean, but if it comes up with none that doesn't necessarily mean things are ok.
21  Resources / Tools / Re: Nessus vs. OpenVAS on: October 18, 2012, 12:56:21 PM
Why don't you just pass the cost of the license on to your client(s)?

I obviously would if I need to, but if OpenVAS is just as good, then I'd rather pass the cost of something else on to them.
22  Resources / Tools / Re: Nessus vs. OpenVAS on: October 17, 2012, 04:34:57 PM
Yes, really excellent article m0wgli.  Just what I was looking for.  Thanks!
23  Resources / Tools / Nessus vs. OpenVAS on: October 17, 2012, 01:29:41 AM
So, I've been getting some paid pentesting jobs, and I need to decide between buying a Nessus license or using OpenVAS.  I'd prefer not to spend the extra money, but I don't have any experience with OpenVAS.  Is it just as good as Nessus or should I suck it up and just buy the license?  I primarily do web pentesting, and use Nessus to find configuration issues and software vulnerabilities on a web server before I begin testing the actual site.

Also there are a lot of OpenVAS tutorials out there.  If anyone has some favorites please post the links. 

Thanks.
24  Resources / Career Central / Re: Starting Your Own Company..... on: October 11, 2012, 12:59:40 PM

What are you doing to get your name out there? Are there any local ISSA, ISACA, OWASP, etc. meetings you could speak at? Focus on establishing a solid reputation; don't just knock on doors and ask for work.


'm not actually trying to be part of the security community.  I'm trying to go after small businesses and start-ups that have no idea they need security.  Sites that don't use HTTPS and send credit card numbers in plaintext for example.  There's definitely a market for that, but I'm trying to figure out how to market to people who don't have any idea of the security risks.
25  Resources / Career Central / Re: Starting Your Own Company..... on: October 11, 2012, 01:55:59 AM
I actually decided to start my own web pentesting company last month.  For the past 2 years, I've been doing consulting work for various start-ups while looking for a full-time job.  2 months ago I did a pentest on my friend's website and got a nice amount of money for it (despite the fact that I offered to do it for free).  As a result, I decided to try and see if I could make any money doing pentesting for other sites.  However, I'm having trouble finding that second client.

Besides using word-of-mouth with my friends, for the past 3 weeks I've been looking for sites that have obvious security holes (like a login system without HTTPS) and sending out e-mails.  I've gotten responses from 2 websites, both of which basically said, "We know and we don't care."

This past week, in addition to searching for those kinds of sites, I've been attempting to find freelance security jobs, but I haven't found anything useful.  If anyone has any advice, please let me know.

On the bright side, most of my interviews involve me going through 3-5 phone interviews, then flying out to the company before getting rejected.  So not finding clients is a lot less frustrating, and a lot less work, than not finding a job!
26  Ethical Hacking Discussions and Related Certifications / General Certification / Re: SANS Work-Study experience on: October 06, 2012, 12:15:23 PM
@Seen, would your employer foot the bill? If so, why not combine it with the opportunity to travel? ;-)

I'm unemployed, so no, he won't  Smiley
27  Ethical Hacking Discussions and Related Certifications / General Certification / Re: SANS Work-Study experience on: October 05, 2012, 05:21:46 PM
Looks like no GWAPT or even GPEN at my nearest conference this year, guess I won't have to try to be a volunteer until next year!
28  Ethical Hacking Discussions and Related Certifications / Other / Re: GoDADDY.com gets hacked. DoS for millions of websites. on: September 11, 2012, 12:28:03 PM
GoDaddy wouldn't even let me interview for a pentesting position because i didn't have enough experience, so is it ok that I take a little pleasure in this?
29  Ethical Hacking Discussions and Related Certifications / General Certification / Re: SANS Work-Study experience on: August 27, 2012, 12:42:01 AM
tturner (or anyone else), could you please elaborate on the type of work you have to do as a facilitator?  I'd like to be sure I can do the work before I try and sign up.

Thanks.
30  Ethical Hacking Discussions and Related Certifications / Other / Re: Hash Help on: August 07, 2012, 12:08:52 PM
There's no point in continuing to work with someone who is "an ass", does shoddy work and is unresponsive.  Get control of the site and hire someone else. 

I'm on it, that's why I'm doing this test.  Figuring out what works and what doesn't, what we can reuse and what we need to get rid of.  Once that's done, then we'll have a better understanding of what we need the new admin to be able to do.
Pages: 1 [2] 3 4 ... 9
Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.069 seconds with 21 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Free Business and Tech Magazines and eBooks

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.