Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 48 guests and 3 members online
 
Advertisement

You are here: Home
EH-Net
May 22, 2013, 06:35:50 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
  Home Help Calendar Login Register  
  Show Posts
Pages: [1] 2 3
1  Ethical Hacking Discussions and Related Certifications / eCPPT - eLearnSecurity Certified Professional Penetration Tester / Re: NEW: Coliseum Web App Security Lab on: July 22, 2011, 02:49:18 PM
My observations about gains I feel I have made from dedicated time in the labs : http://rabray.wordpress.com/2011/07/22/coliseumlab-observations/
2  Ethical Hacking Discussions and Related Certifications / Other / Re: Books 24x7 on: June 13, 2011, 05:50:28 PM
Thanks.  Cheesy
3  Ethical Hacking Discussions and Related Certifications / Social Engineering / Re: Social Engineering: The Art of Human Hacking on: June 13, 2011, 04:45:58 PM
Apologies for got to come back with my view on this book. http://rabray.wordpress.com/2011/05/04/social-engineering-the-art-of-human-hacking-review/

Certainly enjoyed it. Gave me ideas for things to check out further.
4  Ethical Hacking Discussions and Related Certifications / Other / Re: Books 24x7 on: June 13, 2011, 04:41:47 PM
Thanks for the info. Come back to take another look. What about safari any views?
5  Features / Book Reviews / Re: Recomended book for Pen Tester on: June 12, 2011, 06:21:23 PM
Not finished reading ed skoudis counter hack reloaded yet but I would recommend this. A number of core principles discussed in easy to understand manner. Providing info on the important ethical nature of pen testers. Remediation/mitigation strategy, Hoping to see a new edition.

Social engineering the art of human hacking is also an interesting read.

Web app handbook and network security assessment. Both good resources in my view.

6  Ethical Hacking Discussions and Related Certifications / eCPPT - eLearnSecurity Certified Professional Penetration Tester / Re: Beginning in ethical Hacking / pentest on: June 12, 2011, 05:57:12 PM
Also happy to give more info about the benefits I have personally gained from taking part in a challenging and interesting course.

7  Ethical Hacking Discussions and Related Certifications / eCPPT - eLearnSecurity Certified Professional Penetration Tester / Re: eCPPT certification and programming skills on: June 12, 2011, 05:49:36 PM
From the point of view about the books. I would say that you also read these while you study, its what I did and found them useful for areas at the time I felt a bit weak on.

I also recommend using the forums, there is quite a bit of useful information and questions/reply that I also learned things from and really helped me to develop a better understanding.
8  Ethical Hacking Discussions and Related Certifications / Other / Re: Books 24x7 on: June 12, 2011, 05:41:19 PM
Anyone recommend this with a tablet or any other online book service with decent sec resources?
9  Ethical Hacking Discussions and Related Certifications / eCPPT - eLearnSecurity Certified Professional Penetration Tester / Elearnsecurity BETA testing New Labs on: March 30, 2011, 01:21:33 PM
Elearn Security Online Labs and Challenges BETA Review

I was lucky enough to be asked to join in with a small team of beta testers to experience firsthand the latest developments by Elearnsecurity. The new online labs that are dedicated sandboxed cloud based environment for each student, accessible from the main learning material interface/portal.

On the 29 March 2011 at 8PM GMT; I eagerly await access to get a look at the concepts and ideas that up to then had only read about in discussions and suggestions by Armando in the forums.

The whole process I should add came off the back of consultation with the existing student community, so good to see a provider listening to the demands of the customer.

Reading the text in the forums, I could tell that Armando was excited about this project as it would bring yet another perspective to the learning model on offer from Elearnsecurity and ultimately would enhance the learner’s experience.

My experience I would have to say lived up to anticipated hype!
Perhaps partly due to having another chance to log in with equal minded
folks keen to get their hands on the latest information and experience they could.

I need to mention, matugm who pretty much pwnd it before we really got off and running, last time I seen him posting he was trying to get a shell!

4 hours flashed passed in a blink of an eye.

Roughly about 30 mins after the agreed meet up time; we were off and running. The only real reason for this late start in my mind was due to getting some testers initial technical issues resolved and giving us group instruction via text based chat. (A head ache I would imagine if you’re on the supporting side)

The test itself involved what appeared to be at the outset a simple enough challenge for anyone who has experience in this field or perhaps has recently studied a course like ecppt.

Though as we attacked the challenge set out in front of us, I started to realise how this setup could give me an advantage to expand my inner working knowledge of both SQLi and of the popular tool sqlmap.
Most of what I have read or the guides I have seen up to now focus in on GET method via URL vulnerable parameters. I struggled to see many discussions around other input channels or POST method choices while studying for ecppt.

This challenge was exactly what I wanted to see, exactly what I wanted to try out and lucky for me gave me a chance to yet again apply what I had learnt up to know. Having developed new skills you are keen to try to keep them sharp, in hacking as we know only really achievable if you have labs if you want to stay on the side of the good.

As well as the actual objective of retrieving information from a database and inserting data into a database, I found I was starting to think “you know what I am going to try this from different angles from the point of view of learning more about the use of Sqlmap, from a burp log, from config file and straight off the CLI”.
Giving me a chance to work with the tool in the different ways I wanted, so I could feel I was making progress towards being comfortable with the options that up to now I had really only read from the manual.

I collected a whole bunch of data that I plan to look at from the tool and study/research a bit further to understand as much as I can from the SQL used and look to ways to refine  and focus my attacks.

All of this from a single login page, I could hardly believe it, now I was wishing I had more time and energy left in me to keep chatting and testing with some very experienced specialists in the field. Alas work beckoned in the morning and the lure of sleep forced me to concede, well at least to go to bed and leave my laptop cracking the hashes I had obtained from the dump (not actually an objective but fun none the less, there was talk of removing this as I don’t think it was intended but I suggest leave it in)
As far as other enhancements are concerned; my understanding is there is a plan to have more exercises with step by step walkthrough examples to get those needing extra assistance off the ground, which in turn will help them pass the cert/gain skills.

More challenges are to be released to keep the more experienced students coming back for more; this in turn should in my view build on what is already showing signs of growing as a community.
The challenges do come with hints, but I know from chat with Armando and the team that these hints will affect the participants scores and plans of giving away goodies for challenge winners will probably keep the hardcore away from these but still give others at least a good learning tool until they build up their skills and experience.

Details of the goodies and prices for access have yet to be disclosed.

In my humble view a good addition to give us who are interested in researching security the hands on approach that is needed to close in on a sector that needs more good guys/gals on side.
 



10  Ethical Hacking Discussions and Related Certifications / eCPPT - eLearnSecurity Certified Professional Penetration Tester / Re: Awaiting my eCPPT result ... fingers crossed on: March 24, 2011, 02:33:49 PM
Hi,

I am pleased to be able to report back a proud holder of eCPPT.

From my own background and perspective the course and exam was a very enjoyable experience.

I had done CEH prior to this course and personally found CEH useful in giving me a foundation to approach this course. My day to day working life is not at the moment centred on security.

From my initial contact with eLearn security, I was impressed by the way I was handled as a potential customer and supported in terms of believing that I could achieve. I did ponder long and hard before I parted with my own hard earned cash.

After making my decision to join the course, I initially did feel a bit unsure in what I had bought into, mainly due to my concerns that perhaps I could not do this on my own in a distance learning fashion. But my fears where quickly put to rest, once I seen responses to my questions and I had read every post in the forums to make sure I was not adding posts already answered and just creating a nuisance of myself.

The responses I received gave me matters to think about and pointers as to where to head to next, which is useful when you’re learning; building on my understanding was a combination of taking in the good advice and information in the slides/videos and asking appropriate questions. I never felt at any time that if I had tried on my own and had to request for more info that I would not be given some sort of support, be it from someone experienced on the course or Armando the creator himself.

I would also say that network+ and CCNA came in useful, as did some of my previous studies in relation to web technology including HTML, CSS (limited PHP and SQL), a basic understanding of Linux is also helpful.

The challenge of the exam really does focus on expecting you to apply what you learn; I believe this to be an excellent approach. No exam cram sessions on this one I am afraid, if you’re really only looking for another CV filler.

I had good fun and I believe that Armando is building on its success and looking to provide new and interesting experiences for current and potential new students.

If like me you wondered if you had what it took to perform a manual web application penetration test, then this is the one for you!



11  Ethical Hacking Discussions and Related Certifications / eCPPT - eLearnSecurity Certified Professional Penetration Tester / Re: Awaiting my eCPPT result ... fingers crossed on: March 23, 2011, 05:55:36 PM
Thanks folks. I hope to hear soon and will come back to you all.

It's all part of the process.
12  Ethical Hacking Discussions and Related Certifications / eCPPT - eLearnSecurity Certified Professional Penetration Tester / Re: Awaiting my eCPPT result ... fingers crossed on: March 19, 2011, 07:03:34 AM
Quick update. First attempt : FAIL

Not to worry you get a 2nd attempt and very useful feedback.

Armed with the helpful feedback and the various resources from both the course materials and the discussion forums I set about putting matters right (hopefully)

Got my report completed yesterday after a few hours and is back in the digital drop box awaiting review. Once again my fingers are crossed.

13  Ethical Hacking Discussions and Related Certifications / eCPPT - eLearnSecurity Certified Professional Penetration Tester / Re: Awaiting my eCPPT result ... fingers crossed on: March 11, 2011, 05:43:49 AM
I would recommend the course.

For the cost personally I found it to be of good value. As the assessment is a practical exam then it is a bit more of a challenge I think than typical certs, Depending on your current pen test skills will determine the level of the challenge.

The forums are the main support mechanism and if your engaged with the course regular you will find these useful as you try to bridge any gaps in your understanding. Ofc you need to be patient as you wait for a response, the response times are usually quite good.

I would suggest to anyone thinking about doing it, make sure you can dedicate time!

Doing the actual reporting takes longer than you expect. Lesson learned here!
14  Ethical Hacking Discussions and Related Certifications / eCPPT - eLearnSecurity Certified Professional Penetration Tester / Re: eLearnSecurity opinions? on: March 10, 2011, 04:13:37 PM
I am not sure about the price of the student version. I believe that this is to be set and will be public fairly soon.

Content wise this has not been made public yet but I believe it is to lead up to the Pro version so more introducing concepts and skills that you need to get you up to speed for Pro.

15  Ethical Hacking Discussions and Related Certifications / eCPPT - eLearnSecurity Certified Professional Penetration Tester / Awaiting my eCPPT result ... fingers crossed on: March 10, 2011, 03:51:09 PM
Awaiting news about eCPPT :-)

Checking the email now at shocking rates!

I can honestly say that no matter what, I have enjoyed the course!
Pages: [1] 2 3
Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.061 seconds with 21 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.