Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 50 guests and 2 members online
 
Advertisement

You are here: Home
EH-Net
May 22, 2013, 06:28:21 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
  Home Help Calendar Login Register  
  Show Posts
Pages: 1 ... 31 32 [33] 34 35 ... 38
481  Ethical Hacking Discussions and Related Certifications / OSCP - Offensive Security Certified Professional / Re: OSCE Review on: May 03, 2011, 08:25:55 PM
I've been putting off the CISSP but unfortunately I think its next for me. Nice work on getting through that.

For me, recreating exploits was key because I only knew basic assembly and had basic debugger skills. It forced me to become comfortable in a debugger and learn much more about assembly. For example, if the original author of an exploit wrote it as an EIP overwrite, I'd look for the SEH overwrite and rewrite it. If they didn't use an egghunter, I would add an egghunter. If the original author only wrote it for XP, I'd write it for Vista or 7. Using this method I managed to run into all kinds of issues I had to sort out.

My biggest weakness going into this course was on the web side. I wish I would have spent more time on this. I would recommend not only focusing on the exploit dev but understand exploiting all kinds of web apps.
482  Ethical Hacking Discussions and Related Certifications / OSCP - Offensive Security Certified Professional / Re: OSCE Review on: May 03, 2011, 03:01:19 PM
Go for it dude. As far as BT4 or 5, it wont matter. I actually spent most of my time in Windows VMs using Immunity because most of this is windows exploit dev and windows pwnage.
483  Ethical Hacking Discussions and Related Certifications / OSCP - Offensive Security Certified Professional / OSCE Review on: May 03, 2011, 02:06:43 PM
Well, it will be nice to have my life back. I managed to get through the OSCE challenge and got word today that I obtained the cert.

I documented my experience like I did with the OSCP:

http://www.networkadminsecrets.com/2011/05/offensive-security-certified-expert.html

484  Resources / Tools / Re: BackTrack 5 on: May 02, 2011, 09:21:29 AM
The anticipation is agonizing, here are some new ones:

http://www.backtrack-linux.org/screenshots/
485  Ethical Hacking Discussions and Related Certifications / Malware / Re: Help Needed - revers Trojan on: April 29, 2011, 09:03:08 AM
Look at the metasploit payload modules.
486  Ethical Hacking Discussions and Related Certifications / Incident Response / Re: Stolen Macbook Pro from College Campus on: April 25, 2011, 11:33:56 AM
I would go change all your passwords so that further damage cant be done. If you had any saved credentials in your browser you'd hate to have this person empty your checking account as well.

Second, its a long shot but a decent idea to ask the IT group to notify you if the MAC comes up on the network, but then it seems you'd need some cooperation with law enforcement to actually get your PC back. There are certainly ways to track this stuff down but it all requires the ability to subpoena provider records to start to geographically pinpoint the person who stole your pc. It might be worth looking at the bottom of your gmail account in the "Last account activity" section to see if anything looks fishy but again... you might be able to get an IP but its likely the campus NATS and that IP is shared by thousands of students.

Unless you're a state senator it might be tough to get the local PD to give a crap and help you out. Sorry to hear about your luck.....but one lesson on this....back your data up...somewhere else......
487  Ethical Hacking Discussions and Related Certifications / Other / Re: Issues updating metasploit. on: April 25, 2011, 10:40:36 AM
Can you ping metasploit.com? What happens when you run msfupdate?

You might just want to pull down a new copy with subversion.
488  Ethical Hacking Discussions and Related Certifications / OSCP - Offensive Security Certified Professional / Re: OSCP Walkthrough on: April 24, 2011, 09:30:05 PM
Are you asking what operating systems are targets on the exam?
489  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: pentest lab questions on: April 24, 2011, 09:52:11 AM
You can never have enough RAM. Get as much as you can afford or as much as your motherboard can handle. From a HD perspective, I dont actually use that much. My biggest HD is 2TB but that is only for backups.

Think about it this way, if all your VMs are just for pwning and testing, they're not going to use a lot of RAM nor are they going have big vmdk files. So, unless you want every flavor of every Operating System ever created, you dont really need that much. I think 150 GB is probably enough. Like I said above, I have about 5 VMs, they're all on a drive that is 128 GB, in addition to my OS and I still have plenty of space left.

However, Hayabusa brings up a good point about snapshots, if you're going to use them, then make sure you have enough space! I use snaps lightly so I dont need too much extra space for them.
490  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: pentest lab questions on: April 23, 2011, 11:09:17 PM
Vmware is your friend. So is RAM and in my opinion, a SSD if you can swing it.

My "lab" consists of my 4 year old PC running Ubuntu with Vmware Workstation, 4gb of ram and a shiny new SSD. I have various windows operating systems and a few Linux operating systems as guest OSs. I can run two or three at a time without any issues, this is mainly due to the SSD. I basically put my OS on the SSD and only my VMs, the rest of my data goes on slower drives.

If you've got a few extra bucks to spend, I'd get a PC with a 64 bit processor, lots of RAM and a SSD. Can you tell I'm excited about my new SSD?

PS - Just ran some benchmark tests and my old HD had averaged about 60 MB/s and the new one is about 270...

491  Resources / Tools / Re: BackTrack4 R2 VMware Tools update issue. on: April 22, 2011, 09:11:11 PM
I think "fixvesa" then doing a startx also fixes that....
492  Ethical Hacking Discussions and Related Certifications / OSCP - Offensive Security Certified Professional / Re: OSCP question on: April 22, 2011, 08:14:27 AM
The exam is over VPN as well as the practice lab.
493  Ethical Hacking Discussions and Related Certifications / Web Applications / Re: Defending against MITM attack on: April 21, 2011, 09:24:51 AM
I believe that plugin only works on certain sites. I think that plugin just does what you should be doing anyways, and that is typing https into the browser instead of http and dealing with a redirect to https.

Its a good start but there are still many other known vulns for sslv3 and tls. Also, pay attention to your browser warnings.
494  Ethical Hacking Discussions and Related Certifications / OSCP - Offensive Security Certified Professional / Re: OSCP question on: April 20, 2011, 10:04:24 PM
http://lmgtfy.com/?q=oscp

495  Columns / Editor-In-Chief / Re: Whats the deal with all the SPAM Postings? on: April 19, 2011, 08:47:16 PM
I dont think so and the only reason I say that is it is always idiots with 0 posts, so they're clearly not interested in the material here...
Pages: 1 ... 31 32 [33] 34 35 ... 38
Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.068 seconds with 21 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.