|
EH-Net
|
|
May 23, 2013, 08:31:48 PM
|
Show Posts
|
|
Pages: 1 2 [3] 4 5 ... 38
|
|
32
|
Ethical Hacking Discussions and Related Certifications / Cyber Warfare / Re: APT1: Exposing One of China's Cyber Espionage Units
|
on: February 20, 2013, 08:33:20 AM
|
|
That article you posted is interesting, they certainly have points. However, this report is based on a lot of data. The keyboard layouts that came across the RDP sessions didn't indicate Russian, they indicated Chinese. Just like in a court case, sometimes even if you don't have an actual video showing a person doing something, they can be convicted. IN this case, there is in fact a video to back it up, however we don't see the actual actor, which one could argue the video was fabricated. I for one, believe the data.
There is no doubt the US is doing similar activities, however, I don't believe they're stealing trade secrets unless its military secrets from other nations. I don't buy into the US using it for anything other than military purposes.
|
|
|
|
|
34
|
EH-Net / Special Events / Re: Corelan Plug
|
on: February 19, 2013, 07:57:34 AM
|
|
That is a a GREAT deal. We paid significantly more. We had to bring Peter to us, which is probably why. I suspect with all the extra free press he gets being at a Con, and larger classes maybe, he can bring the price down.
***
oops, just realized you said euros.... that's still a little cheaper, but not as big of a break as I thought...
|
|
|
|
|
37
|
Ethical Hacking Discussions and Related Certifications / Malware / Re: Encoding parts of a payload
|
on: February 12, 2013, 08:07:17 AM
|
|
There is a lot of overlap and in many cases they compliment each other. We had a thread on here somewhere where we got into the nitty gritty. For example, OSCE covers no ROP exploitation but Corelan does. Corelan is 110% exploit dev. OSCE is 90%. If possible, do them both!!
ajohnson just knocked out OSCE and recently did Corelan, he might have a fresher perspective...
|
|
|
|
|
43
|
Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: OSCE advice?
|
on: February 07, 2013, 10:32:04 PM
|
@H1t M0nk3y OSCE is hard. Best advice I can give looking back is to simply practice. I used to go to exploit db, pull down exploits, strip out all the stuff in the middle and start with a simple crash. From there, rebuild the exploit. If you do that 100 times, you're in good shape  The course material is merely supplemental to what's needed for the exam, assuming you have no experience prior. Go for it though, even if you fail, keep going because it's really really good stuff. You'll eventually get it.
|
|
|
|
|
45
|
Ethical Hacking Discussions and Related Certifications / General Certification / Re: nth topic on Career Advice
|
on: February 04, 2013, 10:26:18 PM
|
|
While education and certs help you learn and help "check boxes" for HR, you should really try to get into the field as soon as possible. The hardest part about getting into pen testing, is getting into pen testing. If you can afford to get in as entry level/associate level, you should do so. You may come to find that no one wants to hire you, so you'll have to figure out a way to prove to a prospective company that #1 you love this stuff, #2 you have the drive and #3 you have a hunger to learn.
My advice, keep getting as much education as you can but also try to get into the field asap.
|
|
|
|
|
Loading...
|