Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 37 guests online
 
Advertisement

You are here: Home
EH-Net
May 23, 2013, 04:33:23 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
  Home Help Calendar Login Register  
  Show Posts
Pages: 1 2 3 [4] 5 6 ... 9
46  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Web Hackers Handbook labs? on: February 27, 2012, 11:32:12 AM
Thanks ajohnson, your post was very informative.  I'm planning on starting the labs after I finish the entire book.  I'm almost finished with chapter 5 so that might be a while.
47  Ethical Hacking Discussions and Related Certifications / Web Applications / Re: tools on: February 18, 2012, 01:05:39 AM
I've been thinking about playing around with Nessus and Nexpose, and this thread has been really informative.  Thanks guys!
48  Ethical Hacking Discussions and Related Certifications / Web Applications / Re: Some questions as usual ? on: February 04, 2012, 01:49:59 AM
If you can get a SQL error message that displays your input, then you might be able to provide a script tag as input to do XSS.  However, this would require that the output isn't sanitized.  More importantly, error messages tend to have a fixed length, so how much XSS you can inject would be limited.
49  Resources / Tools / Re: Combining Wordlists on: February 01, 2012, 05:58:18 PM
Thanks dynamik, I'll try different orderings of my list and see if it makes any difference.
50  Resources / Tools / Combining Wordlists on: February 01, 2012, 01:21:45 PM
What's the best way to combine wordlists?  Just cat them all, and then run sort/uniq?  I've noticed some wordlists have duplicate entries, is this because some password crackers (like Hydra) can miss words?  If I run uniq this would remove all the duplicates, would it be better to just add the lines that aren't in one file to another when combining them?  Sorry for the newbie questions, I've never made a custom wordlist before!
51  Resources / Tools / Re: John the Ripper Multi-Core Setup on: January 27, 2012, 06:20:10 PM
SephStorm, here's the link I ultimately ended up using:

http://blog.thireus.com/crack-passwords-using-john-the-ripper-with-multiple-cpu-cores-openmp

It was super easy to setup, but I'm not sure if all hash formats support multi-core, need to try a few more things
52  Resources / Tools / Re: John the Ripper Multi-Core Setup on: January 27, 2012, 08:42:45 AM
If I remember correctly, the /usr/bin/john file is actually just a softlink to the actual binary. You can install as many versions of John as you like and just point the softlink to the binary of the version you want.

Thanks ziggy, I'll try that.
53  Resources / Tools / Re: John the Ripper Multi-Core Setup on: January 27, 2012, 01:10:15 AM
Thanks guys, got it.

Now I have 2 versions of john on my system.  Can I just replace the john directory in the /pentest directory with the new one, and then overwrite the old /bin/john with the new one?  It's a bit confusing, if I type john instead of ./john it uses the old version.
54  Resources / Tools / John the Ripper Multi-Core Setup on: January 26, 2012, 01:02:06 AM
Does anyone know a good link that explains how to setup jtr to use multiple cores?  I found some links but they were a few years old.  Considering I have the latest version (1.7.9) I just wanted to make sure I didn't break jtr by using info for an older version.  Multiple cores are nice, but if I break it, 0 cores are bad Smiley

I'm running backtrack 5 r1 x64.

I tried using hashcat, and while it uses multiple cores and is very fast by default, it was only able to crack 1/3 hashes, whereas john was able to crack all 3 using the --rules option with its default rules.  So if anyone knows a good rules file for hashcat (and maybe a tutorial), that would be useful as well.

Thanks.
55  Ethical Hacking Discussions and Related Certifications / Hardware / Re: What Equipment Should I get For Hacking on: January 23, 2012, 06:14:05 PM
What sort of hacking are you interested in?  Network, web, system?

Web hacking really only requires a tool like Burp Proxy which is not too resource intensive.

Network hacking requires that you run a lot of VMs, unless you have the actual systems to hack, which would require a lot of memory.  Network and system hacking can also require password cracking, which means you'll need a relatively fast processor.

If you're not sure what kind of hacking you're interested in, you might want to try eCPPT to get exposed to different areas of security.
56  Ethical Hacking Discussions and Related Certifications / General Certification / Re: Offensive Security's OSEE on: January 19, 2012, 06:25:22 PM
Damn, I wish the web cert was a little cheaper than GWAPT.  Considering it looks to be the same price, I'd probably just go for GWAPT.
57  Ethical Hacking Discussions and Related Certifications / Web Applications / Re: Burp Suite Pro: Worth the Price? on: January 18, 2012, 06:11:38 PM
Ok, so I'll definitely buy Burp Suite Pro once I get a paying job.  (That and the GWAPT class).  Until then, I'll use the free version and try out ZAP. 
58  Ethical Hacking Discussions and Related Certifications / Web Applications / Burp Suite Pro: Worth the Price? on: January 17, 2012, 06:21:59 PM
I'm getting more serious about web security as I'm going through the WAHH v2, and I'm wondering if Burp Suite Pro is worth the price.  I definitely think it would be worth a one time price of $299, but $299 a year seems quite steep.  Is it updated enough to justify such a huge subscription price?  Just thought I'd get the opinions of people who have the pro version.

Thanks.
59  EH-Net / News Items and General Discussion About EH-Net / Re: [Article]-December 2011 Free Giveaway Winner - SANS on: January 13, 2012, 06:18:44 PM
Congratulations, this is a great prize!

By the way, has anyone taken DEV522/GWEB?  How does it differ from GWAPT?
60  Ethical Hacking Discussions and Related Certifications / Web Applications / Re: URL Encoder on: January 12, 2012, 12:56:34 AM
I like knowing how things works, so I appreciate the code  Smiley
Pages: 1 2 3 [4] 5 6 ... 9
Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.1 seconds with 21 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Free Business and Tech Magazines and eBooks

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.