Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 37 guests online
 
Advertisement

You are here: Home
EH-Net
May 19, 2013, 06:28:27 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
  Home Help Calendar Login Register  
  Show Posts
Pages: 1 ... 4 5 [6] 7 8 9
76  Ethical Hacking Discussions and Related Certifications / Programming / Re: Ruby and Python on: December 22, 2011, 12:12:19 AM
This is the book I swear by for Ruby. It is the primary language I use as it is very easy to learn and lauds itself as "natural".

http://www.amazon.com/Programming-Ruby-1-9-Pragmatic-Programmers/dp/1934356085/ref=pd_sim_b_6

I just ordered this book l33t5h@rk, hope it's good!
77  Ethical Hacking Discussions and Related Certifications / Web Applications / Re: GWAPT with Live & OnDemand - review on: December 21, 2011, 03:44:12 PM
Thanks, I guess I'll do OnDemand then if I ever get the money.
78  Ethical Hacking Discussions and Related Certifications / Web Applications / No GWAPT for me! on: December 21, 2011, 01:31:00 AM
I just found out I'm not going to be a volunteer for GWAPT at SANS in February Sad.  I didn't think I'd make it, but there's always hope.

Oh well, I just ordered the WAHH V2, maybe once I finish that I'll have enough money saved to do the OnDemand version of GWAPT.
79  Ethical Hacking Discussions and Related Certifications / Web Applications / Re: GWAPT with Live & OnDemand - review on: December 21, 2011, 01:24:05 AM
What if you just signed up for the OnDemand as opposed to the vLive or something like that?  Does the OnDemand leave out things that are in the live course?  I like to work at my own pace, so if I ever save up enough money for GWAPT, I would probably do the OnDemand.  I have an insane memory, but it only works if I have time to process the information.  Taking the live class I'd learn all the material so fast that I'd probably not retain it that well after the exam.
80  Ethical Hacking Discussions and Related Certifications / Web Applications / Re: Bypassing File Upload Restrictions on: December 21, 2011, 01:16:28 AM
I came across a lab on eLearnSecurity where you could bypass the restriction by just making sure ".jpg" was in the filename.  I though that was a pretty cool bypass.

So you could try naming the file something like "file.jpg.php" for example.
81  Ethical Hacking Discussions and Related Certifications / Mobile / Re: Using Mobile Devices For Pentesting on: December 21, 2011, 01:12:59 AM
You can also find apps like droidsheep and others that are fun to play with, but still, more fun than functional. 

Yeah, this is kinda the feeling I got when I looked this topic online.

you can do it but the keyboards on the tablets make things unfun to do anything serious.

I HATE typing on my phone, I can call and leave a voicemail faster than I can send a text!
82  Ethical Hacking Discussions and Related Certifications / Mobile / Using Mobile Devices For Pentesting on: December 19, 2011, 09:51:47 PM
My sister just got an iPad from her work (apparently you can't teach 2nd grade without one now--when I was in grade school I think there 10 Apple IIs for the whole school!), and although I personally don't see the appeal for tablets, it got me thinking: has anyone here found a use for mobile devices in pentesting? 

There are quite a number of articles about performing a pentest on mobile applications, but besides one or two interesting projects, I couldn't really find anyone using smartphones or tablets to help perform a pentest.  This is understandable given the limited processing power, but I was just wondering does anyone here have any thoughts or personal experience on this topic?
83  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Web Hackers Handbook labs? on: December 16, 2011, 01:20:53 PM
Never mind, I found a description on the website, looks to be a few new labs from when I did it.
84  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Web Hackers Handbook labs? on: December 16, 2011, 01:16:47 PM
I think there were 10-20 eLS labs when I went through it during my course, I was just wondering how many there are now if anyone knows.
85  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Web Hackers Handbook labs? on: December 16, 2011, 08:30:20 AM
Has anyone gone through all the Coliseum labs for elearnsecurity?  How do those compare?  Are there any other online labs that are perhaps a better value than the WAHH ones?
86  Ethical Hacking Discussions and Related Certifications / General Certification / Re: Certification vs. Internship/co-op on: December 15, 2011, 11:45:14 PM
Are you based in the USA or UK Seen ?

US
87  Ethical Hacking Discussions and Related Certifications / General Certification / Re: Certificate of Cloud Security Knowledge (CCSK) Review on: December 15, 2011, 12:00:10 PM
Cool Review first time I have heard of this course too. Was it expensive to take the course was there any fee involved ?

Nope the material is free, the test costs $295.  I think there is also a 2-day training course that costs money but I don't know why you'd take it.
88  Ethical Hacking Discussions and Related Certifications / General Certification / Re: Certification vs. Internship/co-op on: December 15, 2011, 08:43:35 AM
The key is to demonstrate your passion for the industry. This can bypass experience sometimes. You have to do things on your own time to demonstrate that you're obsessed with this stuff, get certs, write articles, find exploits......whatever it is, do it and keep doing it. You've got to go into interviews professional, but energized. For example, I had a network admin/engineer background (12 years) and was hired as a senior pen testing consultant because I convinced them I knew what I was talking about. It can be tricky but it can be done. A good company will recognize passion and know that the upside for someone with passion is far superior to someone who is just luke warm.

Most of the interviews I've had they've explicitly told me "I can tell you're very passionate" or "you're doing the right things (in order to try to get the experience)", but they still say we're looking for someone with more experience.  Guess I just haven't found the right company yet.

when I was breaking into the industry I offered to work for free and no one would take me on. So I ended up doing certificated to get some expierence.

I am doing unpaid work for a startup, I'm not getting a lot of experience, but it's better than nothing.
89  Resources / Mass Media / Re: IT Security Books on: December 15, 2011, 08:38:06 AM
I was checking the table of contents last day, I was really happy to see that there is a sub section of Attacks regarding every protocol, exactly 'mother of all the books'   Grin

Which book are you referring to?
90  Ethical Hacking Discussions and Related Certifications / General Certification / Re: Certification vs. Internship/co-op on: December 15, 2011, 12:35:56 AM
Joshsevo, you're lucky like you said.  I haven't been able to find any pentesting jobs that require less than 3 years experience, let alone an internship.  How to get that first job without the 3 years...
Pages: 1 ... 4 5 [6] 7 8 9
Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.096 seconds with 21 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.