Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 42 guests online
 
Advertisement

You are here: Home
EH-Net
May 20, 2013, 07:49:08 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
  Home Help Calendar Login Register  
  Show Posts
Pages: 1 ... 25 26 [27] 28 29 30
391  Ethical Hacking Discussions and Related Certifications / Security / Re: Passed the CISSP on: April 18, 2011, 02:22:57 PM
Awesome!  Congrats, DrivinTin Grin
392  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Hacking DOJO on: April 18, 2011, 11:13:16 AM
I was looking at signing up for the classes, but not sure where I should start.  I have an intermediate knowledge of Linux, but my programming skills are basic.  I'm not sure of the languages taught in the Mukyu class, but I have intro knowledge of Perl and Python.  If possible, I'd like to subscribe into the Shodan classes to lock in the $95/month subscription fee, but I don't want to be in over my head.  Any thoughts would be greatly appreciated! Smiley
393  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: The Hacker Academy online subscription based training on: April 16, 2011, 11:45:22 PM
Hey tturner, any updates? Smiley
394  EH-Net / Ethical Hacktivism / Re: Counterattacking a hacker on: April 14, 2011, 04:59:28 PM
Good read.  It seems peoples belief that one can trace an IP back to an attacker is more common than it thought.  Or maybe I'm just lucky and have learned that early enough in my security training Huh
395  Resources / Mass Media / Re: "Breaking In" Pentest Sitcom on: April 13, 2011, 01:04:18 AM
Thanks ziggy.

Tip for others searching for ep2 on youtube, append the ep name to your search: karat caper.  The first ep should come up if you just search for the show name.
396  EH-Net / News Items and General Discussion About EH-Net / Re: [Article]-April 2011 Free Giveaway Sponsor - Rapid7 on: April 12, 2011, 04:51:58 PM
How does Don keep blackmailing these companies for these prizes and not get arrested?

lol Great way of putting it.

Totally agreed, great stuff Don.
397  Features / Book Reviews / Re: Anyone read your InfoSec books on Kindle? on: April 12, 2011, 04:24:44 PM
Ironic, books on technology fail miserably when viewed on the latest technology.

lol :-P

I was just listening to the Wireshark University certification video this morning and the issue with images, tables, etc is exactly why the Wireshark Network Analysis book wasn't made into an electronic version.

I've never used a handheld ebook reader, but I've always had issues reading PDF versions of tech books.  I just flip back and forth way too much for an ebook to work for me.  From the sounds of it, this is one of the issues with the handheld ebook readers too.
398  Resources / Mass Media / Re: "Breaking In" Pentest Sitcom on: April 12, 2011, 12:58:45 PM
Just watched ep1 of "Tiger Team" (full ep via TruTV - thanks hayabusa) and the clip of ep2 (thanks for the link BillV) - good stuff!  I wasn't able to find a full ep2, but I'm going to search a few other sites after I get off work.  Watching the recon, planning, and educating the client is just as good as the attack IMO Smiley

As for "Breaking In," I have yet to watch that yet, but I'll be watching it for the comedic value rather than accuracy/factuality.  It seems its more pleasurable that way :-P
399  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: How to be "Covert" on: April 12, 2011, 10:36:01 AM
Same thing with antivirus. Knowing which one is installed can probably help you craft your exploits accordingly (I am doing OSCE right now  Wink).

I just learned of that yesterday while listening to the ISD podcast, ep361! Smiley  They were talking about the Hartford breach and how the press release they sent out gave the vendor specific name of the virus rather than just the generic name.  Which in turn tells everybody which AV solution you're using.  That's good to know...

And those are some great tips, Sil - thanks!
400  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Password cracking on: April 08, 2011, 09:00:23 AM
Ah, good point regarding local vs remote.  I would think you'd need escalated privileges to access the SAM.  Checking my Win2k3 box, it only has permissions for administrators and system.  And I think if you have either admin or system privileges on a box, you wouldn't need to worry about the SysKey.  I think watching those week 1 Metasploit Unleashed vids from grmn00bs might of benefit to you.
401  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Password cracking on: April 08, 2011, 12:55:28 AM
I found the grmn00bs/Reversespace stuff after listening to her talk about her SMS botnet project also lol.  Heard her chat about it on PaulDotCom and Hak5 @ Shmoocon.  I've bookmarked that BrightTalk website, looks like some good videos there.

As for netcat, I don't have experience using it myself (yet), but IIRC from reading, netcat on the remote machine is the listener while you connect to the machine on the port netcat is listening on.

I did some reading on SysKey and it seems that being aware of it would be beneficial since it's an extra level of encryption on the SAM file.  From what I can gather from Irongeek's article on it though (http://www.irongeek.com/i.php?page=security/localsamcrack2), if you grab the SAM file while logged in as admin, then the SAM is unencrypted.  So then you only have to worry about cracking the hashes.  Otherwise, you're going to need the system key to bypass SysKey.  The article was last updated in 2007 though, so I'm not sure if there are other ways to bypass SysKey now.  I'll edit/post again if I find something else.
402  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Password cracking on: April 07, 2011, 03:12:14 PM
Thanks for posting this links, KillJ0y.  I've yet to watch the vids on the 2nd link, but the first video is great.  This is the first I've heard of masking for password cracking.  Is that something new or am I just behind the times?

As for Windows, just as KillJ0y said, you can use Metasploit to grab the hashes.  Reversespace has been doing Metasploit classes following Offensive Security's "Metasploit Unleashed."  During their week 1 class (can be found here: http://www.grmn00bs.com/), Georgia shows an example of exploiting MS08_067 using a payload that drops into meterpreter.  Once in meterpreter, you can issue a command that prints all the usernames and their respective hashes on the screen.  Then use whichever method you prefer to crack them.

I'm new to Metasploit, so if I've misworded something or understood something incorrectly, anybody please correct me Smiley
403  EH-Net / News Items and General Discussion About EH-Net / Re: [Article]-March 2011 Free Giveaway Winner - SANS vLive! on: April 07, 2011, 10:39:19 AM
Gratz SephStorm! Smiley
404  Resources / Tutorials / Re: Where to start? on: April 03, 2011, 04:14:48 PM
Awesome, thanks Jamie Smiley
405  Resources / Tutorials / Re: Where to start? on: April 02, 2011, 09:39:45 PM
So I've finally gotten around to setting up some VM's (using VMWare Player), went to download Metasploitable and I can't seem to find a link that works.  Initially started here and found that the "torrent" link doesn't work anymore.  I tried a few searches around metasploit.com with no luck either.  Anybody know of a good link to download from?
Pages: 1 ... 25 26 [27] 28 29 30
Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.076 seconds with 21 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Free Business and Tech Magazines and eBooks

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.