Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 21 guests and 2 members online
 
Advertisement

You are here: Home
EH-Net
May 19, 2013, 07:50:27 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
  Home Help Calendar Login Register  
  Show Posts
Pages: 1 2 [3] 4 5 ... 9
31  Ethical Hacking Discussions and Related Certifications / Other / Re: Hash Help on: August 06, 2012, 03:00:05 PM
I didn't take it as rude.  The guy who designed the site is an ass.  I found a way to bypass the login to the database a month ago, and it took him a month to fix it!  So he's not really good about getting back to my friend or me.  In his defense, he probably realizes once he gives us all this stuff, he's going to get fired!

So right now the plan is just to make a list of all the problems and things we need and hopefully get it eventually so someone else can handle the site.
32  Ethical Hacking Discussions and Related Certifications / Other / Re: Hash Help on: August 05, 2012, 12:29:43 PM
Why don't you just ask him what he's using? Is this supposed to be a custom algorithm? You shouldn't assume something's secure just because it's not recognized by a tool.

He doesn't know what algorithm he's using, someone else handled making the site.  And I'm not assuming it's secure, I'm just going to finish testing the rest of the site and THEN go back to the hash.
33  Ethical Hacking Discussions and Related Certifications / Other / Re: Hash Help on: August 04, 2012, 05:06:49 PM
Thanks, as long as you and I can't crack it easily, I'm going to tell him it's secure  Smiley  For now anyway.
34  Ethical Hacking Discussions and Related Certifications / Other / Hash Help on: August 04, 2012, 12:29:45 AM
Can anyone help me with this hash?  I was trying to check the strength of the hashing algorithm my friend uses on his site, and it must be amazing because JTR can't crack it Wink

This hash is supposed to be "password"

04c2bb68c40e147048aeaf319ff00c3a609bd50f

And here is the salt:

d5f58c19ade4233e3eb2478c489ebd171992f514

JTR recognizes it as raw-sha, but I went through all the formats and it couldn't crack it.

Can anyone else crack this?  Am I doing something wrong?

Thanks
35  Resources / Career Central / Re: Security engineer 2nd Technical Interview advice on: July 31, 2012, 07:17:53 PM
I had 5 1-hour phone interviews for a Security Engineering job with a large company that sells books before I flew to Seattle and interviewed with more people.  All the interviews were very technical.  The only stuff I didn't know was about routing.

Honestly, after going there, it didn't seem like that great a place to work.  Meaning even if I had gotten the job, I don't know if it would have been worth all the phone interviews and flying to Seattle for 3 days.  Plus it would have cost me more money to buy books because of tax if I worked there. Wink

That being said, study up on routing and good luck.
36  Ethical Hacking Discussions and Related Certifications / Web Applications / Re: Scanning Amazon EC2 Servers on: July 29, 2012, 05:29:48 PM
I have checked skip sensitive devices Smiley  And I have Nikto integrated into Nessus.  I also set the max TCP connections very low, so I don't think I'll have a problem.

We'll see though...

And I just ordered Burp Pro.
37  Ethical Hacking Discussions and Related Certifications / Web Applications / Re: Scanning Amazon EC2 Servers on: July 27, 2012, 12:49:01 PM
Thanks, I was planning on doing both.  Running a server scan without credentials (External IP Scan), and then a web app scan with credentials.  I will have safe scans enabled.  If I have all the plugins enabled, safe scan will ensure that the non-safe ones aren't run right?  The server is run through a PaaS provider, so my friend isn't sure about all the services running so I want to be thorough.

I've never run a scan on a live, external server before, so I'm just trying to be cautious.  I kind of wish I had an external server to test the scans on first, but oh well.

Thanks
38  Ethical Hacking Discussions and Related Certifications / Web Applications / Scanning Amazon EC2 Servers on: July 26, 2012, 12:57:38 AM
I'm testing a friend's website running on Amazon's EC2 servers.  He put in a request to allow me to test it next week.  The terms are pretty standard, don't DoS the servers.  I'm planning on running Nessus (regular server scan and web app scan), Nikto and BurpSuite Scanner on the site.  Is there anything I should know, settings I should change in the scans before I start?

Thanks.
39  Ethical Hacking Discussions and Related Certifications / GPEN - GIAC Certified Penetration Tester / Re: Quick SEC560 Review on: April 24, 2012, 07:25:26 PM
Thanks Agoonie, I was wondering how this prize worked out for you.
40  EH-Net / News Items and General Discussion About EH-Net / Re: [Article]-April 2012 Free Giveaway Sponsor - eLearnSecurity on: April 07, 2012, 12:20:39 PM
Already signed up, guess I'll have to wait for next month's giveaway!
41  Ethical Hacking Discussions and Related Certifications / eCPPT - eLearnSecurity Certified Professional Penetration Tester / Re: Professional v2 + Hera Lab released on: March 23, 2012, 02:20:26 AM
Excellent, the new stuff looks good, going to sign up this weekend!
42  Ethical Hacking Discussions and Related Certifications / Hardware / Re: Laptop Stand Recommendation on: March 21, 2012, 12:22:41 PM
That's what I've been doing for two years!  Unfortunately, no room for a desk given my current living situation.  Right now I just put my computer on a table with a towel under it to protect the table from heat/scratches.  Thought I'd try something different now.
43  Ethical Hacking Discussions and Related Certifications / Hardware / Laptop Stand Recommendation on: March 21, 2012, 09:50:59 AM
I know this is a bit off topic, but can anyone recommend a good laptop stand?  I primarily want it to provide a more ergonomic typing position, but I also want to prevent a desk/table from getting hot (and marking up my mom's kitchen table because of it--I'll only make that mistake once Smiley )

Thanks.

44  Resources / Tools / Re: Backtrack 5 R2 on: March 09, 2012, 12:22:25 AM
I don't have R2, but I had trouble installing it on R1.  I ran this script to update Backtrack, didn't expect it to fix Flash, and I just kind of assumed I couldn't get Flash to work on x64, then a couple of days later I noticed Flash was working.  I can't guarantee that this will fix it since I tried a whole bunch of things to fix Flash, but it's worth a shot.

http://sickness.tor.hu/wp-content/uploads/2011/06/backtrack5_update.py

I just did update all.

NOTE: I have not tried this on R2, nor have I tried to update R1 to R2 using this script.  I will at some point, I'm just busy now and can't afford to have things break Smiley
45  Ethical Hacking Discussions and Related Certifications / Programming / Re: Ruby and Python on: March 01, 2012, 08:41:12 AM
l33t5h@rk I just wanted to say thanks for the book recommendation.  I'm about 100 pages into it, and it's pretty good.  I can still write a C++ or Java program faster than I can script, but I'm learning.
Pages: 1 2 [3] 4 5 ... 9
Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.064 seconds with 21 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.