Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 120 guests and 2 members online
EH-Net News Feeds
Latest Additions
 
Advertisement

You are here: Home arrow Forum
EH-Net
February 10, 2012, 05:44:36 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Advertise on EH-Net!! - Reasonable Rates, Highly Targeted Audience.
 
  Home Help Calendar Login Register  
  Show Posts
Pages: [1] 2 3 ... 28
1  Ethical Hacking Discussions and Related Certifications / Web Applications / Re: SQL injection string encoding on: August 20, 2011, 04:29:27 PM
Many encoding techniques won't work with SQLi since they will not be decoded and interpreted as SQL.

One advantage of using an intercepting proxy rather than just using a HTML form is that you capture a record of the HTTP request and response. This can be vey useful for going back and seeing what you did and tweaking requests. I've also seen sites that implement input sanitisation in JavaScript and avoing the web form also gets around this.

2  Ethical Hacking Discussions and Related Certifications / CEH - Certified Ethical Hacker / Re: CEH Exam Prepration on: April 05, 2011, 04:03:41 AM
The problem with not using official courseware is you may not cover all the material your need for the exam. If the official courseware seems bloated then perhaps the syllabus is equally bloated. I've not done the CEH exam but experience with other vendor exams teaches me that passing may involve learning all of the guff that's included that you are never likely to use.

You might look to getting a second hand copy since I doubt many people will want to keep what is essentially an exam study guide. Your hard earned cash might be better spent on some mock exams which I find very useful for exam preparation.

Regards,
Jim
3  Ethical Hacking Discussions and Related Certifications / Web Applications / Re: Bruteforcing Without Causing a DoS on: April 05, 2011, 03:58:45 AM
You might consider monitoring the site you are attacking. If you can control the rate at which your brute force tool hits the site you can tune it, check your monitor to see if the site is working and returning pages in a timely fashion and ramp up. If you get a situation where there is a significant impact on the site throttle back.

A simple script to gather a page and measure the time taken for the response might suffice or you could set up a more complex user experience monitor.

Regards,
Jimbob
4  Ethical Hacking Discussions and Related Certifications / Wireless / Re: Question On Sniffing MSN Conversation Using Wireshark on: August 02, 2010, 09:19:54 AM
If you right click on a TCP packet in wireshark there is an option to follow the TCP stream. Wireshark will filter all the packets from the given TCP connection and this might give you what you want.

Since this filters to a single TCP stream then you might want to make sure you haven't missed out some of the traffic. Take a look at the filter string and play around with it, perhaps filtering traffic on 1683 only. I've seen the tool Netwitness reconstruct chat sessions, there's a free version of that you can try.

As for tutorials for wireshark, <insert-name-of-search-engine-here> is your friend.

Jimbob
5  Ethical Hacking Discussions and Related Certifications / Forensics / Beware UK forensics practitioners on: July 27, 2010, 10:27:42 AM
Hi all,
I just had a call from a company offering to produce lovely documents promoting my company to law enforcement and government and the public sector. Apparently there is loads of money available to forensics companies from the government purse, despite the fact that budgets for fighting cyber crime are being slashed.

Funny, I don't promote my forensics business becauses it's pretty much non-existent. If someone calls me asking about it then they've found my details on google. They would not send me any details by email because the salesperson's PC is not Internet connecte (seriously?). So I asked for a URL to check out that they are selling.

http://www.publicsector.co.uk/

Guess what? A holding page.

That's pretty damn cheap. I may as well sign up to a Russian business directory. I know a good few people out there trying to make their way in information security and calls like this from snake oil saledroids really get my goat. Caveat emptor.

Jimbob
6  Ethical Hacking Discussions and Related Certifications / Wireless / Re: Tools for Wifi sniffing on: July 22, 2010, 02:49:54 PM
It's strange, I know, but Wireshark uses a tool called airpcap...which costs anywhere from $200+

libpcap is free and so is WireShark. It will run on both windows and Linux, and probably some other operating systems. Kismet is really great for monitoring and sniffing wireless networks, you might want to check that out.

Jimbob
7  Resources / News from the Outside World / Re: LIGATT Security International and Gregory Evans Sue Alleged Stock Bashers on: July 13, 2010, 01:56:46 AM
The lawsuit has been filed with Gwinnett Courts.

http://www.gwinnettcourts.com/#casedetail/case:10-a-06012-5/

Mr. Evans has John A. Moore acting as his lawyer in this matter.

http://www.moorelawllc.com/

More in google no doubt.

Jimbob
8  Resources / News from the Outside World / Re: LIGATT Security International and Gregory Evans Sue Alleged Stock Bashers on: July 12, 2010, 04:36:37 PM
And already the sock puppets are out.

Quote
This is great news! People should pay for detroying the lives of others.

I'm tired of hearing about this guy and his bullshit. Anyone else feel the same way?

Jimbob
9  Ethical Hacking Discussions and Related Certifications / Web Applications / Re: Job Email Scam? on: July 12, 2010, 02:18:29 PM
Most likely just random junk to try and evade spam filters.

Jimbob
10  Features / Book Reviews / Re: Cover Art for New Book - Ninja Hacking on: July 11, 2010, 11:45:53 AM
That's class! I've always wanted to be able to hack a ninja.

Jimbob

p.s. Nice avatar Jason :{D
11  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Hacking Oracle on: June 18, 2010, 11:11:13 AM
For tools to connect to Oracle check out SQLPlus, the command line tool that ships with oracle. A free GUI  called SQL Developer is available from Oracle if you want something more visual.

There are a few good oracle security tools out there and some modules in metasploit for Oracle scanning and enumeration. POET is a recently release tool for Oracle pen testing.

http://pentestit.com/2010/06/08/poet-padding-oracle-exploit-tool/

Cheers,
Jim
12  Ethical Hacking Discussions and Related Certifications / Other / Re: converting IP adresses on: June 18, 2010, 09:32:35 AM
But as this is a valid question from the exam, they're expecting that we know all the Hex-notations by head? Can't be true!

Isn't there another method?
This is still by far the easiest way to do it. If you have a good scientific calculator it should support hexadecimal, which makes converting to hex and back again easy.

Knowing how to do hex arithmetic is a useful skill. If you're only covering 8-bit numbers you only need work with numbers in the rannge of 0x00-0xFF or 0-255 in decimal. Don't beat yourself up over it though, it does not come naturally to most and taking a minute doing a simple sum in your head can be time well spent.

Jim
13  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Dropping tools and malware using DNS on: June 09, 2010, 09:34:47 AM
How do you suppose you would get the record on the DNS server?  Maybe something inside a trusted dynamic DNS update?
You could add the records to a domain you have own, or to a zone file on a compromised DNS server. I'm not sure about dynamic DNS but that would be a novel way of setting up the records.

Jim
14  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: I have a shell. Now what? on: June 09, 2010, 06:58:25 AM
Pwn and pivot. Use the box your rooted as a base to attack other assets in the organisation.

Jim
15  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Dropping tools and malware using DNS on: June 09, 2010, 06:27:49 AM
Hi,
I blogged about the notion of using DNS TXT records to delivery binary files to a compromised system. Here is the link...

http://jimhalfpenny.blogspot.com/2010/06/delivery-your-malware-by-dns-http-is.html

I hope it's interesting to the folks here.

Regards,
Jim
Pages: [1] 2 3 ... 28
Powered by MySQL Powered by PHP Powered by SMF 1.1.16 | SMF © 2011, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.208 seconds with 21 queries.
 

gk_static-ad_feb2012.jpg
Global Knowledge Training: Build Security Skills to Protect and Defend

offsec_130x200-2_jan-feb2012.png
Offensive Security
AWE Live in the Caribbean!
March 5 - 9, 2012

SANS Deals 4 EH-Netters
$150 OFF Any SANS Course in Any Format!
Coupon Code: Refer_EHN
Including SANS Phoenix 2012, SANS 2012
Recent Forum Topics

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!

Vote For EH-Net

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2012 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.