Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 31 guests and 2 members online
 
Free Business and Tech Magazines and eBooks

You are here: Home
EH-Net
May 21, 2013, 03:03:23 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
  Home Help Calendar Login Register  
  Show Posts
Pages: [1] 2 3
1  Ethical Hacking Discussions and Related Certifications / eCPPT - eLearnSecurity Certified Professional Penetration Tester / Re: eCPPT Gold Certification on: April 04, 2013, 01:51:51 PM
Armando:

Hope this message finds you well! I was checking the gold cert and it says that the engagement will include web apps to be tested (I imagine both manually and with other tools or Nessus) - My question is Do you recommend getting back to Coliseum and Hack.me to practice or Hera will provide the full experience of what I should encounter during the test?

Thanks in advance,

Jose
2  Ethical Hacking Discussions and Related Certifications / OSCP - Offensive Security Certified Professional / Re: Failed my first attempt at the OSCP exam on: March 13, 2013, 01:01:06 PM
I scheduled my exam for April 6. I was shooting for a week earlier, but to get an 8:00am Saturday time slot, I had to schedule it a week later. That gives me an extra week. I have made good progress since my last attempt and think I will be ready.

Best of luck!!!!  Grin
3  Ethical Hacking Discussions and Related Certifications / OSCP - Offensive Security Certified Professional / Re: OSCP - Module 6 Buffer Overflows Question on: March 13, 2013, 12:11:54 PM
Really useful, I'm exploring your site since Monday!!!!! Thanks!!!!
4  Ethical Hacking Discussions and Related Certifications / OSCP - Offensive Security Certified Professional / Re: OSCP - Module 6 Buffer Overflows Question on: March 13, 2013, 05:35:20 AM
Well regarding the material, I was able to get the windows sample on the module plus aditional excercises from Vivek (mini share, FreeSSH, Easy Chat - SEH Based) plus Stephen Bradshaw material on info sec institute. Right now I can do this type of overflows in a really consistent manner plus a few others taken from the exploit DB that are not in the form of tutorials but I was able to adapt them to fit both Vivek and Stephen methodologies.

Sounds like you're ready. If you want more practice,  search for buffer overflows at Exploit-DB. In some cases, the vulnerable software is included so you can download it and recreate the exploit.

Hey! I checked your website and you have awesome material! One question regarding your pivoting series. if I want to recreate your setup do I have to use a GNS3 setup or can I use, say a 2003 server with RRAS configured to act as a router? I think this tutorials are great to avoid using metasploit for pivoting on the exam, in case you need to pivot, and maybe save the opportunity to use it for a harder machine! Thanks again for your amazing website!
5  Ethical Hacking Discussions and Related Certifications / OSCP - Offensive Security Certified Professional / Re: OSCP - Module 6 Buffer Overflows Question on: March 12, 2013, 07:19:09 PM
Try harder!  Wink

I will!!!!! Smiley
6  Ethical Hacking Discussions and Related Certifications / OSCP - Offensive Security Certified Professional / Re: OSCP - Module 6 Buffer Overflows Question on: March 12, 2013, 07:07:00 PM
Well regarding the material, I was able to get the windows sample on the module plus aditional excercises from Vivek (mini share, FreeSSH, Easy Chat - SEH Based) plus Stephen Bradshaw material on info sec institute. Right now I can do this type of overflows in a really consistent manner plus a few others taken from the exploit DB that are not in the form of tutorials but I was able to adapt them to fit both Vivek and Stephen methodologies.
7  Ethical Hacking Discussions and Related Certifications / OSCP - Offensive Security Certified Professional / OSCP - Module 6 Buffer Overflows Question on: March 12, 2013, 05:14:48 PM
Hi... can anyone help me out here? For the OSCP exam do you use only the regular overflow or do you need to know SEH stack based overflows???

Thanks in advance
8  Ethical Hacking Discussions and Related Certifications / General Certification / Re: Hacking Dojo Novice Access - No Confirmation email/link. on: March 05, 2013, 10:07:49 AM
Open a skype account and look for hackingdojo.com - it's the fastest way to get a hold of him, he's online as I'm typing this!
9  Ethical Hacking Discussions and Related Certifications / General Certification / Re: Hackingdojo on: February 27, 2013, 03:16:26 PM
Hi:

I'm currently studying with him. I finished the foundations class and it's really good. His videos have a relaxed tone and the supplemental material is good. I've checked eCPPT and the difference is that they are 80% reading 20% videos from an instructor guiding you. Tom is the oposite. Plus you have a 20+ live targets hacking lab for you to practice at no extra charge. He has a special going on right now with a 50% off the classes. If I were you I'll go for it... Just my 2 cents

His pentest book is also a great tool to have along with the course. He follows a clear methodology that helps you on the real world, it's not just hack this or that. It's: follow this procedure so you can finish your testing with a decent report based on a standard. Highly recommended
10  Ethical Hacking Discussions and Related Certifications / Other / Re: Worth 1 Yr subscription to Hakin9 ? on: November 23, 2012, 06:20:06 PM
Don't subscribe to them!!!! Like it was said before they are a joke and just a spam club. I remember when it was a physical mag with CD's and everything and they were really good. Those days are long gone and about 50% of what they publish is crap and out of the other 50% half of it is decent and half of it you can find on free resources. Stay away from them!!!!!

Real places to go:

Security Aegis, Irongeek, Securitytube, and of course google. catonmat is really good for scripting as I found just yesterday while browsing for a sed tutorial for a lesson on Hacking Dojo.

So save your money for something worth reading!!!!!
11  Ethical Hacking Discussions and Related Certifications / Other / Re: Thomas Wilhelm - ISSUES WITH HACKING DOJO (SOLVED) on: November 21, 2012, 07:25:03 PM
just a question, shouldnt some of your statements be commented rather than echoed?

Yes you are right!!!! I'll fix the script to comment out the explanation
12  Ethical Hacking Discussions and Related Certifications / Other / Re: Thomas Wilhelm - ISSUES WITH HACKING DOJO (SOLVED) on: November 21, 2012, 06:17:04 PM
Yea, glad everything got sorted out. Nice start on the script.

If you want additional ideas, check out Lee Baird's discovery script: http://code.google.com/p/backtrack-scripts/

The Python Nmap library is pretty cool too: http://pypi.python.org/pypi/python-nmap

Nice!!!! Thanks for the links. I also did a search on Lee and found two great videos and one of them is a BASH lesson. Once again thanks for your help  Grin Grin Grin

http://www.irongeek.com/i.php?page=videos/hack3rcon3/09-bash-scripting-101-for-pen-testers-lee-baird
13  Ethical Hacking Discussions and Related Certifications / Other / Re: Thomas Wilhelm - ISSUES WITH HACKING DOJO (SOLVED) on: November 21, 2012, 02:44:57 PM
Well things are OK now, I started going through the Myoku videos and here's my first script to automate nslookup and nmap is based on a grep line Tom showed us to clean an nslookup command so you are left with just plain IP's. I thought that this can be saved and used to launch nmap.

With this you can have a folder for every client ant it will automatically save all your data for that client there. I will add new things to run later along the way.

Any opinions are welcome:

--------------------------------------------------------
#!/bin/bash

clear
echo
echo AUTOMATE NSLOOKUP AND NMAP
#++++++++++++++++++++++++++++++++++
# This is a very simple script that let you create a folder to save your scans,
# run a basic nslookup for any domain, grep it and pass it to nmap for a scan.
# All results are saved on text files inside the folder you created for future refrences...
#++++++++++++++++++++++++++++++++++
# Jose Ruiz
# Nov 2012
#++++++++++++++++++++++++++++++++++
echo
echo "++++++++++++++++++++++++++++++"
echo
echo Usage: domain.com
echo
echo "PLEASE CREATE A FOLDER:"
read folder
mkdir /root/$folder
echo
echo "WRITE YOUR DOMAIN:"
read domain
echo
echo "++++++++++++++++++++++++++++++"
echo
nslookup $domain
nslookup $domain | grep "Address" | cut -d":" -f2 | tail -n +2 > /root/$folder/nslookup.txt
echo
echo "++++++++++++++++++++++++++++++"
echo
echo "RUNNING NMAP AGAINST SCANNED IP's... PLEASE WAIT"
nmap -sS -sV -O -Pn -iL /root/$folder/nslookup.txt > /root/$folder/nmap.txt
echo "NMAP SCAN OF" $domain "COMPLETED"
echo "HERE's THE RESULTS OF YOUR SCAN"
cat /root/$folder/nmap.txt
echo
echo "+++++++++++++++++++++++++++++"
echo
echo "THANKS!"



14  Ethical Hacking Discussions and Related Certifications / Other / Re: Thomas Wilhelm - ISSUES WITH HACKING DOJO (IN PROGRESS) on: November 20, 2012, 06:40:41 AM
@prats84

You waited a year?!?!?! Wow, my respects to you. You are a very patient man. I think what you are asking is fair due to the fact of the waiting time - Refund in April is 8 months waiting time for a reply....

Once again thanks for posting. I'm supposed to contact Tom's assistant via email to get an update, I will do it today and post later on. Take care!!!!
15  Ethical Hacking Discussions and Related Certifications / Other / Re: Thomas Wilhelm - ISSUES WITH HACKING DOJO (IN PROGRESS) on: November 19, 2012, 07:50:23 PM
Just to let everyone know that Thomas responded me regarding my queries for refunds etc. He has requested me for some detail and he will check internally.



Great!! Thanks for posting Grin Grin Grin
Pages: [1] 2 3
Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.091 seconds with 21 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.