Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 45 guests and 1 member online
 
Advertisement

You are here: Home
EH-Net
May 18, 2013, 06:34:12 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
  Home Help Calendar Login Register  
  Show Posts
Pages: [1] 2 3
1  Ethical Hacking Discussions and Related Certifications / Web Applications / Ruby on Tails v PHP - Security on: April 25, 2013, 06:36:14 PM
I was wondering if anyone has an opinion on the merits of Ruby on Rails v PHP,  from a security standpoint. Is one more inherently secure than the other?

If you have any published references that you could point me in the direction that would also be fantastic.

Thanks!

2  Ethical Hacking Discussions and Related Certifications / Hardware / Re: OG150 Pentest Drop Box on: March 30, 2013, 10:50:58 AM
Just had a look at pwnpi. I think I'll order raspberry pi, instead! Thanks.
3  Ethical Hacking Discussions and Related Certifications / Hardware / OG150 Pentest Drop Box on: March 30, 2013, 10:12:29 AM
http://www.og150.com/

I was wondering if anyone here has any knowledge or experience of the OG150? They're currently out of stock but I intend to purchase one when available. They look like a very cheap alternative to Pwnie express.

Steve.
4  Ethical Hacking Discussions and Related Certifications / Mobile / Re: Mobile Phone Scanning on: March 16, 2013, 07:24:44 PM
Just to clarify, if the phone is switched off, it will still emit a RF signal and be detected by the scanner. SOP is to remove the phone's battery to prevent detection.
5  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Attack Vector for RDP on: March 16, 2013, 07:18:04 PM
OK, to be clear, this is purely hypothetical and only for lab testing.

If a Windows Server only has port 3389 open, given that no remote code exploit for MS12-020 has yet to manifest itself, what are the available attack vectors? Brute force?

Thanks. 
6  Resources / Career Central / Re: Am I too old for a career change into security? on: March 15, 2013, 05:56:25 PM
It's definately not too late. 28 is young! I was 30 when I took the transition from soldier in the British Army to IT Systems Admin - I didn't do IT in the army!

From the sounds of it your're on the right track. Most definitely concentrate on Web Application testing. Also, get signed up for the PWB/OSCP course too. It's worth the investment.

Take a look at this security organisation in Denmark:
https://www.csis.dk/da/csis/job/

Steve.
7  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Pen Test Scalability on: January 29, 2013, 08:10:18 AM
I understand every company, every network is not the same but how long would it take to pen test a company with 2000 PCs & 1000 servers? Naturally, the network is segmented into bite size chunks!

In terms of man hours, could one person conduct a pen test on a site this large and within a reasonable amount of time?  For sites this large, do pen test companies send in teams of testers?

I'd be interested to know what you all think.
8  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Evading Anti-virus Detection with Metasploit - Live Webcast on: January 24, 2013, 06:21:38 PM
I got the confirmation emails through fine but I messed up on my mental arithmetic! I put GMT ahead of EST by 6 hours instead of 5, so I only caught the Q&A session at the end of the webinar! To rub salt into the wound, one of the comments on chat was about how the presentation was the best from Rapid7 ever! Cheesy
9  Ethical Hacking Discussions and Related Certifications / Compliance, Regulations & Standards / Re: Approved Scanning Vendor - PCI on: January 14, 2013, 11:16:29 AM
Thanks for the replies, guys. All very helpful.
10  Ethical Hacking Discussions and Related Certifications / Compliance, Regulations & Standards / Approved Scanning Vendor - PCI on: January 13, 2013, 12:16:05 PM
Is it possible for an individual to perform a PCI scan or does that person have to be a member of an approved company (ASV)? Can somebody qualified to conduct PCI scans do this on a freelance basis?

Thanks in advance!
11  Ethical Hacking Discussions and Related Certifications / Other / Re: Where are you from? on: December 31, 2012, 09:58:37 AM
Worcestershire, Great Britain.
12  Ethical Hacking Discussions and Related Certifications / OSCP - Offensive Security Certified Professional / CHECK V OSCP? on: December 04, 2012, 06:40:06 AM
This may be a question for our UK members, but is there any comparison between The CESG Check certification and OSCP?

I know I'm not comparing apples with apples and CHECK status is to assure that the tester is qualified to test on HMG (Her Majesty's Government Infrastructure) but on a technical standpoint, how do they compare with each other?

http://www.cesg.gov.uk/servicecatalogue/CHECK/Pages/WhatisCHECK.aspx
 
13  Ethical Hacking Discussions and Related Certifications / Other / Re: Prince William IT Security Issue! on: November 22, 2012, 12:24:02 PM
Having used the UK Ministry of Defence DII systems I know just how unmanageable the whole thing is. I had to write down my password(s)  too - and I should know better!
14  Ethical Hacking Discussions and Related Certifications / Forensics / Cyber Incident - is a pentest enough? on: November 15, 2012, 12:22:58 PM
This is completely hypothetical but if a company knows they have been compromised in some fashion, maybe through information from their ISP or host, would a pentest be of any value; considering the company would want the current attacker removed and not told how other attackers could get!

Is Incident Handling/forensics the only way to go in this scenario? Following up with regular pentests.

15  Resources / News from the Outside World / Re: The guy suing companies for using SSL/TLS on: November 13, 2012, 07:42:51 AM
Echoes of British Telecom's frivolous Hyperlink Patent lawsuit from 2002! BT lost that one, not surprisingly!
Pages: [1] 2 3
Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.099 seconds with 21 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.