|
Ethical Hacker Community Forums
|
|
December 01, 2008, 04:06:57 PM
|
Show Posts
|
|
Pages: 1 ... 13 14 [15] 16
|
|
212
|
Features / Opinions / Re: Linux vs Windows
|
on: August 15, 2006, 11:01:54 AM
|
|
I agree with you 100% that they both have their place, but the only reason I keep a windows system at home is for gaming. For the most part, I think a big reason for people using Linux is that its free and people either don't want to pay for Windows or are too lazy to pirate it. Either way I think people are underestimating the cost factor that goes into choosing an OS. There are some exceptions, like people choosing linux to get more experience on the platform, however rarely is it some ideal of open source over close source or its more secure, thats just a smoke screen for cheapskates who don't want to pay for an OS. If Vista was priced between 50-100 bucks for the various versions, I think you would see alot of people buying it, whereas people sick of the WGA just don't want the hassle, so they run ubuntu or debian. In a large scale professional environment, I would have to say maintenance of an open source linux distro(ie Not Redhat Enterprise or Novell SUSE) is much more difficult then windows. Microsoft provides a more structured upgrade path, better documentation, and better support. For a small shop linux makes sense, but when your talking 500-1000 servers, I think running an open source linux distro is a bit more difficult.
|
|
|
|
|
214
|
Ethical Hacking Discussions and Related Certifications / Malware / Re: Microsoft Braces for Worm Attack
|
on: August 15, 2006, 10:40:17 AM
|
|
Yeah, its really wierd, seeing tons of reports about, while certain vendors are saying it is a non-event. We've still only seen a few, that were non-managed systems. Old dats were detecting it as IRCbot or SDbot. Looks like it won't be that bad for most, but should serve to announce loudly which machines on your networks are unpatched/unmanaged.
|
|
|
|
|
221
|
Features / Opinions / Re: What is the worst vulnerability out there?
|
on: July 31, 2006, 03:08:20 PM
|
|
While wireless security is certainly lacking, I think Internet Explorer is the more important vulnerability. There still finding huge exploits in 6.0, wait till 7.0 goes mainstream it will be even worse. IE is the most ubiquitous portal that essentially serves as the gateway to spyware/adware/malware etc. I think that once companies start running a WPA2 wlan with AES encryption and a Radius server, hacking that network becomes extremely difficult and will rely more on trickery then an actual technical flaw.
|
|
|
|
|
222
|
Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: SYN Flooding DOS Attack - AFCEH Question
|
on: July 31, 2006, 02:14:17 PM
|
|
I would have to say the answer is 4.
The TCP connection process isn't cumbersome SYN/SYNACK/ACK, thats it. Yeah its not a simple as UDP, but really its not "cumbersome" for an enduser in anyway.
Question 4 states bandwidth, however doesn't specifically say network bandwidth. While not completely generic you could interpret that in several ways. In the broadest sense, a given computer only has enough bandwidth to support so many half open connections before it can't take anymore. I would also tend to believe that network bandwidth is directly relevant, as an attacking computer with huge pipe, will overwhelm a target machine with smaller pipe very easily, even though it doesn't take that many packets to create a SYN flood condition.
|
|
|
|
|
223
|
Ethical Hacking Discussions and Related Certifications / Certification / Forensics Certs
|
on: July 31, 2006, 09:52:55 AM
|
|
For anybody who is a long time forensics examiner, what certs are the most valued in forensics. I currently have the GCFA and may attempt the ENCE after I take the training, however I've never heard of the CCE that they are doing the giveaway for. Could some please give a ranking of which ones they feel are the best or most valuable.
Thx
|
|
|
|
|
225
|
Resources / Tools / Re: GFI LANguard Network Security Scanner
|
on: July 28, 2006, 09:26:27 AM
|
|
I'm a big fan of Languard as well, the scan for missing patches functionality is great, however I hate one thing, how it always pops up the yypasswd thing for everyhost.
As far as Nessus, one thing I never liked about Nessus is that you had to set up the server and then run a seperate client. I've only used it on linux, does this newer version on windows still require that?
|
|
|
|
|
Loading...
|