Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 44 guests online
 
Advertisement

You are here: Home
EH-Net
May 22, 2013, 08:23:33 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
  Home Help Calendar Login Register  
  Show Posts
Pages: [1] 2 3 ... 38
1  Ethical Hacking Discussions and Related Certifications / Web Applications / Re: Web vulnerability scanner on: May 08, 2013, 09:47:15 PM
This is kind of a tough situation because most of these products are crappy. Burp is the best, but only for one site at a time. It doesn't do well even with large, single sites.

The problem you're going to face is that the "right" product you find that can handle such a huge workload is probably going to give you the same marginal results, at best.

The only product that really comes to mind that you might want to consider is Nexpose. It does web app scanning, although I'm not sure how well, and it can get pricey but it's worth a look. You can schedule and it seems to perform well on larger engagements. I was also going to say appscan but you already don't like that product.
2  Ethical Hacking Discussions and Related Certifications / Web Applications / Re: Web vulnerability scanner on: May 08, 2013, 06:23:28 PM
Appscan is like 30K and up, is that an option?
3  Ethical Hacking Discussions and Related Certifications / OSCP - Offensive Security Certified Professional / Re: OSCP exam scheduled on: May 07, 2013, 08:42:55 PM
If you got every box, you should be good. No idea what this other challenge is you're talking about. My advice is to sleep well before and knock off the easy stuff first in the challenge.
4  Ethical Hacking Discussions and Related Certifications / OSCP - Offensive Security Certified Professional / Re: Passed OSCP - Review Inside on: May 01, 2013, 03:17:21 PM
Nice work!!
5  Ethical Hacking Discussions and Related Certifications / General Certification / Re: looking for a little guidance from professionals on: April 30, 2013, 07:58:03 AM
Your path will be unique, but as long as you achieve your milestones you can get there. To begin, those milestones should be certs. You certainly don't need a college degree to pentest, some of the best don't have a degree. My personal opinion is that if you can find a IA or IS degree that is a balance between "credibility" and cost, it cant hurt. Who knows, in 10 years you may need that college degree for some type of management gig.

To over simplify the process, and if money is no object here is how I would do it:

CCNA or MCSE -> GPEN -> OSCP ...

You will need to learn how to troubleshoot, that is probably the most important skill that does not come with a cert. As an electrician, you probably already have a knack for this. The ability to quickly analyze and fix issues is imperative.
6  Ethical Hacking Discussions and Related Certifications / General Certification / Re: looking for a little guidance from professionals on: April 29, 2013, 06:56:58 PM
This is probably the most common question here. Seems it comes up at least every week or two, search around and you'll find the same answers on each one.

Where are you located? Depending on your current salary, the strategy may be different.
7  Resources / Tutorials / Re: OWASP 2013 top 10 application security attacks using BackTrack 5 - Help Needed!! on: April 25, 2013, 08:34:42 AM
First of all, "Backtrack" has a million tools on it, you need to know which tool to use for the task at hand. Otherwise its like trying to screw in a bolt with a tool box.

For OWASP, the likely tool to begin with is Burp. The "wireless grid" has no impact on OWASP, that is simply the network medium.

You can start here: http://www.securityninja.co.uk/hacking/burp-suite-tutorial-the-intruder-tool/

You cant just "run commands" an expect magic to happen. Web apps are usually custom written, so you need to know what you're looking for and subsequently plan your next steps. Learn about what each of the top 10 really mean.

Go read this book cover to cover: http://www.amazon.com/The-Web-Application-Hackers-Handbook/dp/1118026470/ref=sr_1_1?ie=UTF8&qid=1366896847&sr=8-1&keywords=web+application+hackers+handbook

8  Ethical Hacking Discussions and Related Certifications / Other / Re: Managing Usernames & Pass-Phrases on: April 25, 2013, 08:02:28 AM
Keepass
9  Resources / Career Central / Re: Looking for advice... on: April 18, 2013, 11:03:37 AM
20% is a pretty big hit, but depending on where you are now, you could make it up. Feel free to PM me with specific numbers and I can give you a better idea (at least at US rates).

App security is exploding just like the rest of security. There are companies that will allow you to stay as a practitioner by doing something like this: associate -> consultant -> senior consultant -> principal or super senior, or whatever the term is.

It really depends on what you're trying to accomplish. If its for the love of the work, or if its to try and position your self for another position in 5 years, whatever, MY advice would depend on a number of other factors.
10  Resources / Tools / Re: Comparison between different tools with different goals and price ranges on: April 10, 2013, 08:31:31 AM
They're both awesome for pen testing.  Core impact has exploits in it that are not public and Meta Pro can help automate large pentests, it is a phishing platform and does some other stuff. Not sure about web app scanning, I doubt it. That would be be creeping into their other product, Nexpose. I always turn the Nexpose spidering/scanning option off. In my opinion, web app scanners are only as good as the guy using it. Burp is the only option + someone who knows what they're doing.

For network, you need a good vuln scanner. I like Nexpose. However, there are a billion vulns that dont show up in a vuln scanner either. Again, it depends on the person driving. I guess what I'm saying is that you need multiple tools. Meta pro and core are expensive, the rest are not. What you give up in the pro, you can make up with old school metasploit.
11  Resources / Tools / Re: Comparison between different tools with different goals and price ranges on: April 06, 2013, 06:19:16 PM
I completely disagree. Just gave Acunetix another shot this week on a client and hate it even more. Worst. Product. Ever.

If all you need are pretty reports with false positives, Acunetix is your tool.
12  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Noob needs some help! Getting started in CEH - hacking at work... on: April 03, 2013, 09:24:40 PM
I assume right click on the taskbar is dead too? Any right clickage?
13  Ethical Hacking Discussions and Related Certifications / Other / Re: FireSheep for 2013? on: April 03, 2013, 09:16:00 PM
Wireshark would do the trick. You just have to know what you're looking for Smiley
14  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Noob needs some help! Getting started in CEH - hacking at work... on: April 03, 2013, 09:13:51 PM
Can you use removable media or is there a CDROM either virtual or physical? If so, just drop a shell and try to escalate from there. Are there any other apps the regular user can access at all? Like in the system tray? Sometimes AV will still be accessible and within the AV you can escape the restricted desktop via the same methods....help menu etc.
15  Resources / Tools / Re: Comparison between different tools with different goals and price ranges on: March 31, 2013, 11:01:03 PM
I hate Acunetix, I use Burp Pro for everything now.
Pages: [1] 2 3 ... 38
Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.087 seconds with 21 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.