Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 40 guests online
 
Advertisement

You are here: Home
EH-Net
May 23, 2013, 01:13:08 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
  Home Help Calendar Login Register  
  Show Posts
Pages: 1 ... 3 4 [5] 6
61  Columns / Editor-In-Chief / Re: [Article]-CASP – The Evolution of Technical Security Certifications? on: December 02, 2011, 10:53:45 AM
I always ask about OSI model in the interview. It just seems like a good way to find a starting place. I don't even necessarily expect people to dig deep, just tell me 7 layers and name them. Once you start discussing TCP/IP and packet structure in depth that is more what I'm interested in than the theory.

tturner - I agree with you on the applicant fail, but it should be both ways. How did this person get the cert? Exactly how you described, paper mill studying got the rubber stamp and now his resume has every CompTIA cert on it.

3xban - I am still LOL about the 3 days per SOHO, you could take one apart, put it back together, and configure it in 2 hours!
62  EH-Net / News Items and General Discussion About EH-Net / Re: Help Promote EH-Net on: December 02, 2011, 10:37:16 AM
LAB COAT LAB COAT LAB COAT!

This sounds incredible
63  Ethical Hacking Discussions and Related Certifications / General Certification / Re: Experience vs Certifications on: December 02, 2011, 12:03:59 AM

Hang in there. I spent six years working my ass off trying to get into security; it didn't just happen. I started off by taking over the IT responsibilities of a company of five people (it wasn't my primary responsibility), moved to a company of about 30 people, and then went to a managed services provider before I finally got a full-time security position. You need to start wherever you can get your foot in the door and work your way into what you want from there. 

This is the best path to get into a full time security position. Take over, and the job will come ...
64  Columns / Editor-In-Chief / Re: [Article]-CASP – The Evolution of Technical Security Certifications? on: December 01, 2011, 11:45:58 PM
I've been a CompTIA cert holder since 1999 and have never been very impressed with their programs.

I hate to sound negative because it does look like they're exploring expansion of their current space, but I recently interviewed for a position on my team and two of the candidates who were brought in had A+, Sec+, and Network+, yet were extremely unqualified. Perhaps it's just a caveat emptor for certifications altogether, but if someone has those and can't explain the OSI model (as I always ask in interviews) then clearly a goal has been missed. Perhaps prereqs should be higher?
65  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Problematic Pen Testing situation on: December 01, 2011, 10:33:30 PM
This issue was finally resolved for anyone interested or not interested.

We ended up working w/ the client and mapped out a plan w/ similar objectives from our preferred pen test contractor and the client accepted this. The test completed today and surprisingly, no high or urgent vulnerabilities were found. I guess my paranoia probably got to me on this one, but at the end of the day, we found no issues, and this particular problem was what caused me to seek out advice from the crew at ethicalhacker.net and become a registered user. Thanks to everyone for commentary and input, it's a wonderful site.
66  Ethical Hacking Discussions and Related Certifications / Programming / Re: How to learn PERL! on: December 01, 2011, 10:22:44 PM
PowerShell is pretty sweet, the Stop-Process cmdlet is the first thing I've seen from MSFT that actually operates the way kill would in *nix.

 I guess I'd suggest just focusing on a few items that need to be scripted, plotting out the logic, then writing them in a different language until you find one you really feel comes naturally to you. Taking that first step into programming/scripting is scary if from a non-dev background but after a few months of doing it you'll look back and be like wtf took me so long  Tongue
67  Ethical Hacking Discussions and Related Certifications / Programming / Re: How to learn PERL! on: December 01, 2011, 02:57:52 PM
Have you thought about Ruby?

I am from a vbscript & perl background, then evolved into powershell & perl. I work mainly in Ruby know, it's pretty easy & powerful, and is generally agnostic about OS.
68  Ethical Hacking Discussions and Related Certifications / Programming / Re: Stanford offers free Cryptography course online on: December 01, 2011, 02:47:29 PM
W/o looking I know @ Stanford there were a couple others like game theory, analysis of algorithms, and other really Computer-sciency topics. Not bad for the price
69  Ethical Hacking Discussions and Related Certifications / Networking / Re: A slightly noob subnet mask question on: December 01, 2011, 02:32:55 PM
You can take a Class A/B network and subnet it down further to smaller networks.  for instance 10.0.0.0/24, the octets fall into a Class A network but the CIDR notation makes it look as if it is a Class C. 

What he said  Cheesy

This is the only way I can see the comments making sense is if it was served as a warning as opposed to a fact.
70  Ethical Hacking Discussions and Related Certifications / Networking / Re: A slightly noob subnet mask question on: December 01, 2011, 02:08:02 PM
Perhaps they mean don't just think that because something has a /24 that means it's a Class C?

Network classes & first octets (for classful networks)
A    0 - 127
B    128 - 191
C    192 - 223
71  Ethical Hacking Discussions and Related Certifications / Hardware / Re: Which OS are you running currently? on: December 01, 2011, 01:52:59 PM
Work is XP, Wife's home is Win7, the geek lab has Fedora, BT5, Ubuntu 11.04, and of course every flavor of VM you can download from vmplanet.net
72  Ethical Hacking Discussions and Related Certifications / Hardware / Re: Need suggestions buying a laptop for security testing on: December 01, 2011, 01:44:59 PM
Macbook Pro i7 w/ 8GB of RAM Cheesy  I am up to 3 VMs running at once as well as host based activity (web browsing and such).  Though a Dell Alienware should work out the same. 

Similar to what I would suggest, something where you can max the F out on RAM and get BackTrack VM, and 3-4 VMs running at once. I'd say to shop for deals on HP or Dell and find the best deal that has the most RAM.
73  Resources / Tutorials / Re: how to exploit iis 6 on: November 30, 2011, 10:14:32 PM
I think before you just start going through tools, you should map out your plan for the demonstration. As you're using Metasploit ...

Intelligence Gathering
Steps X,Y,Z
Threat model X,Y,Z
Known/Discovered Vulnerabilites X,Y,Z
Exploitation (your Proof of concept) QED

Showing your boss a detailed plan and how you obtained the results would be more beneficial than what has been listed so far. Also, I'd be very careful if this is on a production box. Work in non-prod regions of SDLC if possible.
74  EH-Net / News Items and General Discussion About EH-Net / Re: Help Promote EH-Net on: November 30, 2011, 10:00:47 PM
... stickers for laptops...

D'OH

 Tongue
75  Ethical Hacking Discussions and Related Certifications / Cyber Warfare / Re: WSJ Surveillance Catalog on: November 24, 2011, 06:15:24 PM
Yeah, good stuff right? I don't know if it's just because I'm "into" it or what but it does seem like InfoSec is in the news a lot more, hitting a wider audience can't be a bad thing. The SCADA attacks haven't hurt with recognition either.
Pages: 1 ... 3 4 [5] 6
Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.064 seconds with 21 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Free Business and Tech Magazines and eBooks

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.