Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 31 guests online
 
Advertisement

You are here: Home
EH-Net
May 24, 2013, 02:58:03 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
  Home Help Calendar Login Register  
  Show Posts
Pages: 1 ... 3 4 [5] 6 7 ... 25
61  Resources / Tools / Re: DVWA v1.0.5 on: September 03, 2009, 04:34:48 PM

As mentioned by Ketchup in

http://www.ethicalhacker.net/component/option,com_smf/Itemid,54/topic,4586.msg22191/topicseen,1,1/

websecurify has the ability to login to the web application before testing. I didn't see the login link underneath the URL input field.
62  Ethical Hacking Discussions and Related Certifications / General Certification / Re: Heorot.net Intermediate Penetration Testing Course Vs Offensive security on: September 03, 2009, 03:14:54 PM

I can only speak for OSCP and it kicks ass! I highly recommend it.
63  Resources / Tools / Re: DVWA v1.0.5 on: September 03, 2009, 03:05:10 PM

Hey! thanks for your speedy response. I will download the official version and hopefully in the future websecurify will work against dvwa.

Keep up the good work. DVWA is a nice piece of work. Thanks again.
64  Resources / Links to cool sites. / Morningstar Security News on: September 03, 2009, 02:13:44 PM

Morningstar Security News is a security news meta aggregator. Its pretty decent. However, I would like that they include the Diary from the Internet Storm Center (SANS) and even EH.net in order to have all my security news in one page.
65  Resources / Tools / WEBSECURIFY on: September 03, 2009, 02:08:31 PM

Quote
Websecurify is a web and web2.0 security initiative specializing in researching security issues and building the next generation of tools to defeat and protect web technologies.

A new web app security tool created by the people at gnucitizen.com. Check it out:

websecurify 0.3
66  Resources / Tools / Re: DVWA v1.0.5 on: September 03, 2009, 01:53:25 PM
Downloaded for the purpose to test websecurify. It looks nice and instrumental in learning web application security.

I'm not sure if the XSS reflected section was or was not intentionally left out since I know you are still working on this version but just in case I wanted to let you know.

And another thing, I saw it some where on the web that you have tested websecurify and I wanted to know if you used it against dvwa. I tried it but it appears that this tool needs to authenticate to dvwa to fully test it. There's no way to add login information to websecurify unless its possible to add it to the URL. Any tips you can provide? Thanks.
67  Features / July 2009 - Prison Break / Re: [Article]-Prison Break - Breaking, Entering and Decoding on: August 29, 2009, 05:05:35 PM

Jakinne, try a little bit harder, its easier than you think. I did the challenge, I just have to write out the answers and submit it. I had a fun time doing it.
68  Ethical Hacking Discussions and Related Certifications / Malware / Re: Don't drink the water. on: August 26, 2009, 11:08:54 PM

I would like a copy.
69  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Recreating files from packet capture on: August 26, 2009, 04:54:20 PM

Hey chrisj, check this perl script out for extracting Office 2007 Metadata:

read_open_xml.pl

The script works, I tried against the docx file from the evidence pcap and it gave me some info such as the name of the file creator, creation and modify timestamp. Thats some cool info that you can include in your network forensic report.

You don't need the script to get this info but its quicker.
70  Resources / Links to cool sites. / Re: Infosec Cheatsheets I use a lot - lets update regularly! on: August 26, 2009, 10:26:48 AM

More cheat sheets for security admins. I got this from BlackHat twitter feed:

What’s in Your Folder: Security Cheat Sheets
71  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Recreating files from packet capture on: August 25, 2009, 11:20:04 AM

Available tools on the Internet for the purpose of extracting files from packet dumps:

NetworkMiner

Xplico

TcpXtract

And to do it manually using WireShark and a Hex editor check out the following blog:

Pulling binaries from pcaps

Enjoy!
72  Resources / Mass Media / Re: Hacker News Network (HNN) on: August 23, 2009, 11:48:00 PM

Nice, thanks for the info.
73  Ethical Hacking Discussions and Related Certifications / Forensics / Re: AIM attachments, NetWitness question on: August 23, 2009, 06:42:09 PM
There's nothing wrong searching the magic number via Google. This is exactly what I did.

I was able to reconstruct the docx using wireshark and a Hex editor. My md5 hash matches with the one posted in SANS commentaries. The tool tcpxtract help me a lot because I was able to extract the recipe contents and made me realize that the files extracted were zipped XML. This enticed me to research on the docx office 2007 format and such.

It was a cool challenge, to bad that someone posted his answers to SANs. Overall a good learning experience.

Oh yeah, in tcpxtract there's a config file where you can add new signatures. I don't know if docx is included, got to check that out. If not, I'm going to try to create a signature and add it to the config file to see if it works.
74  Ethical Hacking Discussions and Related Certifications / Forensics / Re: AIM attachments, NetWitness question on: August 22, 2009, 07:12:45 PM

It worked for me as well, I was able to get the files, now I just need to properly assemble it to calculate the hash and so forth. Have you accomplish this?
75  Ethical Hacking Discussions and Related Certifications / Forensics / Re: AIM attachments, NetWitness question on: August 21, 2009, 04:49:38 PM

Hey, btw, are you doing the challenge that was posted in SANS?

Network Forensics Puzzle Contest

Because I am and basically I have answered almost all of their questions. The only thing I need is to reconstruct the doc file from the dump file.

I found this tool (tcpxtract) which is used for extracting files from network traffic based on file signatures including Word Documents. I haven't tried yet... I have to wait when I get home or over the weekend but try it and let me know if it works.

Hope this helps.
Pages: 1 ... 3 4 [5] 6 7 ... 25
Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.067 seconds with 21 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.