Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 42 guests and 2 members online
 
Advertisement

You are here: Home
EH-Net
May 23, 2013, 08:31:48 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
  Home Help Calendar Login Register  
  Show Posts
Pages: 1 2 [3] 4 5 ... 38
31  Ethical Hacking Discussions and Related Certifications / Cyber Warfare / Re: APT1: Exposing One of China's Cyber Espionage Units on: February 20, 2013, 04:08:17 PM
My only fear about all this is that we suck at defense. I'm not sure we (USA)  could withstand a serious attack...
32  Ethical Hacking Discussions and Related Certifications / Cyber Warfare / Re: APT1: Exposing One of China's Cyber Espionage Units on: February 20, 2013, 08:33:20 AM
That article you posted is interesting, they certainly have points. However, this report is based on a lot of data. The keyboard layouts that came across the RDP sessions didn't indicate Russian, they indicated Chinese. Just like in a court case, sometimes even if you don't have an actual video showing a person doing something, they can be convicted. IN this case, there is in fact a video to back it up, however we don't see the actual actor, which one could argue the video was fabricated. I for one, believe the data.

There is no doubt the US is doing similar activities, however, I don't believe they're stealing trade secrets unless its military secrets from other nations. I don't buy into the US using it for anything other than military purposes.
33  Ethical Hacking Discussions and Related Certifications / Cyber Warfare / Re: APT1: Exposing One of China's Cyber Espionage Units on: February 19, 2013, 09:07:17 AM
It's fascinating. The level of detail is unbelievable.
34  EH-Net / Special Events / Re: Corelan Plug on: February 19, 2013, 07:57:34 AM
That is a a GREAT deal. We paid significantly more. We had to bring Peter to us, which is probably why. I suspect with all the extra free press he gets being at a Con, and larger classes maybe, he can bring the price down.


***

oops, just realized you said euros.... that's still a little cheaper, but not as big of a break as I thought...
35  EH-Net / Special Events / Corelan Plug on: February 18, 2013, 06:02:17 PM
There have been a few posts lately about the Corelan live exploit dev training course. I thought this would help you make your decision if you're on the fence. The metasploit guys just took his course, and if they give it the thumbs up, you know its good. I'm just relieved to hear  that they also took 28 hours, not just our crew Smiley

https://community.rapid7.com/community/metasploit/blog/2013/02/15/weekly-update
36  Ethical Hacking Discussions and Related Certifications / Malware / Re: [guidance needed] Am I doing it wrong? on: February 12, 2013, 08:28:19 PM
Rumors are there is a real exploit floating around.

When I looked at this to see if exploitation was possible, I started with a 2 second packet capture of the RDP protocol, saw 10K packets in wireshark and said, well effff this bug. I'm out.
37  Ethical Hacking Discussions and Related Certifications / Malware / Re: Encoding parts of a payload on: February 12, 2013, 08:07:17 AM
There is a lot of overlap and in many cases they compliment each other. We had a thread on here somewhere where we got into the nitty gritty. For example, OSCE covers no ROP exploitation but Corelan does. Corelan is 110% exploit dev. OSCE is 90%. If possible, do them both!!

ajohnson just knocked out OSCE and recently did Corelan, he might have a fresher perspective...
38  Ethical Hacking Discussions and Related Certifications / Malware / Re: Joe McCray's Exploit Development Workshop on: February 11, 2013, 09:28:54 PM
I know, but on his blog he basically says he only used their VMs. http://strategicsec.com/blog/ - that's what I'm saying, his rebuttal doesn't make any sense.
39  Ethical Hacking Discussions and Related Certifications / Malware / Re: Joe McCray's Exploit Development Workshop on: February 11, 2013, 09:23:46 PM
He addressed it on his blog but still, why would he put his entire reputation at risk if all he did was use their VMs? Just seems like he must have done more, or, it was just an extremely stupid move. I just don't understand why you would jeopardize everything to save like a day or two of work.
40  Ethical Hacking Discussions and Related Certifications / Malware / Re: Encoding parts of a payload on: February 11, 2013, 08:43:16 PM
@ajohnson I've had it for so long, I completely forgot where it came from. This is it: http://www.redteamsecure.com/labs/post/18/build-your-own-ftp-fuzzer

Editing the post now to reflect that!

41  Ethical Hacking Discussions and Related Certifications / Malware / Re: Joe McCray's Exploit Development Workshop on: February 11, 2013, 06:48:43 PM
If you haven't heard, Mr. McCray is in a bit of hot water in regards to this course...Google full fu. (Damn dumbphone)
42  Ethical Hacking Discussions and Related Certifications / Malware / Re: Encoding parts of a payload on: February 11, 2013, 04:49:14 PM
I literally just had this last problem on the latest bug I posted. Just slapped together a blog post last night: http://www.pwnag3.com/2013/02/actfax-raw-server-exploit.html

Bottom line, you can cut up the payload easily. However, if you mess with the payload being sent sometimes the memory layout/registers will be completely different and show you something better or worse. In my case, 4 bytes literally changed the entire structure...
43  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: OSCE advice? on: February 07, 2013, 10:32:04 PM
@H1t M0nk3y

OSCE is hard. Best advice I can give looking back is to simply practice. I used to go to exploit db, pull down exploits, strip out all the stuff in the middle and start with a simple crash. From there, rebuild the exploit. If you do that 100 times, you're in good shape Smiley

The course material is merely supplemental to what's needed for the exam, assuming you have no experience prior. Go for it though, even if you fail, keep going because it's really really good stuff. You'll eventually get it.
44  Ethical Hacking Discussions and Related Certifications / General Certification / Re: nth topic on Career Advice on: February 05, 2013, 11:58:50 PM
When I say "get into the field" I mean try to get into a company that does some sort of infosec. Ideal situation would be to get  into one that does more than one thing...hopefully including pen testing so you could maybe get over to that part of the company.
45  Ethical Hacking Discussions and Related Certifications / General Certification / Re: nth topic on Career Advice on: February 04, 2013, 10:26:18 PM
While education and certs help you learn and help "check boxes" for HR, you should really try to get into the field as soon as possible. The hardest part about getting into pen testing, is getting into pen testing. If you can afford to get in as entry level/associate level, you should do so. You may come to find that no one wants to hire you, so you'll have to figure out a way to prove to a prospective company that #1 you love this stuff, #2 you have the drive and #3 you have a hunger to learn.

My advice, keep getting as much education as you can but also try to get into the field asap.
Pages: 1 2 [3] 4 5 ... 38
Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.082 seconds with 21 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Free Business and Tech Magazines and eBooks

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.