Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 40 guests online
 
Advertisement

You are here: Home
EH-Net
May 23, 2013, 10:51:21 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
  Home Help Calendar Login Register  
  Show Posts
Pages: 1 [2] 3
16  EH-Net / News Items and General Discussion About EH-Net / Re: [Article]-October 2012 Free Giveaway Sponsor - LearningGate on: October 03, 2012, 12:15:49 PM
Nice! They offer some really interesting classes   Cool
17  Resources / News from the Outside World / Re: Your BMW can be stolen by any idiot with a $30 hacking kit on: September 23, 2012, 04:42:14 PM
Time to buy a new one  Cheesy

Quote
"After extensive research we are clear that none of our latest models - new 1 Series Hatch, 3 Series, 5 Series, 6 Series and 7 Series - nor any other BMW built after September 2011 can be stolen using this method.
18  Features / Opinions / Re: Security research and Black hats where does the bourder line on: August 16, 2012, 01:50:37 PM
I think this really depends on how you "research" and how professional you report your findings.

If it sounds like you try to extort the website owner -> you'll get in trouble.

If you send a mail from your 1337haxxor@steal-your-cc.com mail account containing a responsible report, nobody would trust you -> you'll get in trouble.

If you provide the webmaster with his entire database -> you'll get in trouble.

I can say from my own experience that most webmasters are thankful for a responsible and professional reported vulnerability  Cool

Regards.
19  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Anonamizing on: July 27, 2012, 04:39:22 PM
...and there are quite a lot of providers where you can buy a vpn access or even servers in different countries anonymously.
20  Ethical Hacking Discussions and Related Certifications / Other / Re: Security vulnerabilities and a vendor offer on: July 27, 2012, 04:25:24 PM
Thanks for your answers guys.

Quote
If there's enough market saturation of their product, the bad guys will be motivated to produce their own exploit. And by releasing a patch, they pretty much have what they need to do so. Taking the company's logic one step forward, if the company feels that their user base isn't technically proficient enough to patch (as the original poster stated) AND the patch might provide enough detail for an attacker to develop their own exploit, should they have even release the patch?

And this is exactly the problem! Most of my found vulnerabilities might be easy to reproduce for an attacker, even if they only state the type of the vulnerability in their patch notes. So patching it silently might be the right way here. But the problem will still persist on the devices of the people who simply cannot update due to a missing technical understanding. If the devices would auto-update, this wouldn't probably be a problem, but this is not implemented for some reasons.

So the vendor doesn't like to see the vulnerability to be disclosed because of loosing reputation and of course to protect their customers in the obvious "security through obscurity" way.

@3xban:
I had a talk with the product manager again about the situation and he clearly stated that they appreciate all of my further findings too.

I finally agree with unicityd - if and how they report this issue to their customers is their descision/problem, so I decided to take their offer.

Regards.
21  Ethical Hacking Discussions and Related Certifications / Other / Security vulnerabilities and a vendor offer on: July 22, 2012, 07:04:13 AM
Hello community,

I'm currently in the following situation and need an advice for it:

I've found several security vulnerabilities in the whole product-line of a modem/router vendor. I've reported the vulnerabilities confidentially to the vendor. We got in contact, and they are currently working on updates for their products to be published - some updates are already out. In general I wait for the updates to be publically available before publishing
any information on the issues (responsible disclosure).

A few weeks ago the vendor called me and appreciated the way of dealing with the issues. Then they asked if I would agree with not publishing any information on these issues. Their problem: Most of their customers are not very technically experienced and since there isn't an automatic update-process, most of them just won't update to fix the security issues.
In return they would pay me an amount of money for my effort or sponsor a training like the OSCP.

What to do ? Take the money and shut up ? Give this story to the press ?

Thanks for your ideas!  Smiley
22  EH-Net / News Items and General Discussion About EH-Net / Re: [Article]-May 2012 Free Giveaway Winner of iSWAT Training by FishNet Security on: June 29, 2012, 04:38:54 AM
Congrats...I'm a little bit jealous Shocked
23  Ethical Hacking Discussions and Related Certifications / Other / Re: Hacking own router on: June 15, 2012, 05:52:46 AM
But if you try to bruteforce your - of course long and secure - password, this could probably take a while. It's definitively faster to ask your ISP for the details like chrisj said  Cool

Regards.
24  Ethical Hacking Discussions and Related Certifications / Other / Re: What are these wierd IP addresses? on: June 15, 2012, 05:48:58 AM
You can try "netstat -aon" and then use the PIDs to find out which application(s) is(are) establishing these connections.

Since I do not know IPredator (just the facts from their website)...the traffic is probably related to their network infrastructure ?

Regards.
25  Ethical Hacking Discussions and Related Certifications / Other / Re: Hacking own router on: June 14, 2012, 07:26:58 AM
What about asking your ISP only for the DSL/CABLE/Whatever account details, so you can setup your router by yourself after resetting to manufactory defaults ?

I think this is the easiest way.
26  EH-Net / News Items and General Discussion About EH-Net / Re: [Article]-June 2012 Free Giveaway Sponsor - Black Hat USA 2012 on: June 05, 2012, 04:02:35 PM
I think it also does have an impact on you personally - just by talking to the guys who belong to the "elite" which may lead to a lot of new ideas  Cool
27  EH-Net / Greetings / Re: Hello Everyone on: June 05, 2012, 11:09:46 AM
Welcome  Cool
28  EH-Net / News Items and General Discussion About EH-Net / Re: [Article]-April 2012 Free Giveaway Winners of eLearnSecurity Training on: May 12, 2012, 10:37:25 AM
Congrats! It's a valuable course  Cool
29  Resources / News from the Outside World / Re: Serious Remote PHP Bug Accidentally Disclosed on: May 05, 2012, 03:35:16 AM
And Facebook takes this with humor  Cool

https://www.facebook.com/?-s
30  Ethical Hacking Discussions and Related Certifications / Other / Re: Google Drive on: April 29, 2012, 04:33:07 PM
the interesting part is the integration into other google services....and...it's cheaper than DropBox  Smiley
Pages: 1 [2] 3
Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.065 seconds with 21 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.