Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 38 guests and 1 member online
EH-Net News Feeds
Latest Additions
 
Advertisement

You are here: Home arrow Forum
EH-Net
May 22, 2012, 07:41:22 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Advertise on EH-Net!! - Reasonable Rates, Highly Targeted Audience.
 
  Home Help Calendar Login Register  
  Show Posts
Pages: 1 ... 12 13 [14]
196  Ethical Hacking Discussions and Related Certifications / Forensics / Re: Dodging Search Warrants on: November 20, 2007, 08:52:13 AM
That will always be a catch for investigators, but it is offset a bit if those parts of your hard drive are still mounted when the system is taken into custody.  If you can secure the suspect before they unmount those areas or power off the system, then the encryption is worthless.  If they do manage to get it locked you can often make your case based on the network traffic you've been monitoring and the bits and pieces left over in the host OS that will indicate what they've been doing.  Remember, if the feds are kicking down your door they've probably already got a pretty good load of evidence against you. If you get a court order allowing you to rootkit their system before you take them into custody, you'll probably already have the password plus a log of the activities.  That naughty traffic also has to go somewhere and do something, which they probably already have observed and recorded.  Unless you are just hacking stuff for fun you are going to have to do something with the data you've collected. (use the credit card numbers, sell the data, control your bots, etc)  All of that activity leaves evidence scattered all over other networks, not just your home systems. If all else fails, I've seen situations where the suspect is subpoenaed and order to produce the password.  If they don't, they are held in contempt until they do.  That puts some heat on them to comply since they can sit in jail as long as the judge can allow.
197  Ethical Hacking Discussions and Related Certifications / Forensics / Re: Dodging Search Warrants on: November 20, 2007, 06:41:16 AM
I've served my share of warrants, and I think there are some problems with your scenario:
1)Assume that everything is just the way you've laid it out.  You are still in trouble.  If you've done something on the level that would cause me to come kick in your door, that means I've probably been monitoring your traffic for awhile.  When then traffic goes dead the second I come through your door, we tend to cal that a “clue”.  Even if your server isn't right there with you, it will take 15 minutes to call the judge and get an expanded warrant.  In the mean time I'll be reminding you that destroying evidence is a felony, you're buddy is probably going to screw up the whipe, I'll pull everything off with EnCase, but by then I'll be tired and pissed off.
2)To be a bit more realistic, your above scenario isn't going to happen.  If I'm interested enough in you to kick in your door that means I'll be monitoring you, not just your traffic.  If you are working with someone else then you are probably going to meet with them at some point, which means I start watching them.  Trust me, it won't take more than a couple of days to figure out that when you, him, or both of you are at home then the naughty traffic is occurring.  That means I get two search warrants, and when your door is being kicked down, so is his.
3)To be even more realistic, the above scenario is also a bit unlikely.  If I think there is a chance that you'll destroy the evidence, why am I going to give you a chance?  There is this place called “outside” that people go to in order to get food/alcohol/smokes/paychecks/transvestite hookers/etc.  It is usually a lot easier and a lot more fun to wait for you to go get a slurpee, arrest you in the parking lot, and then watch you piss your pants when I tell you that we just served a search warrant on your place 15 minutes ago.  I'll probably even drink your slurpee for you.
4)If you've really done something bad then the above scenario isn't going to happen either.  Almost every agency that would be doing this kind of investigation is going to have access to their own keyloggers, trojans, backdoors, etc.  (Read up on the FBI's Magic Lantern)  Again, if you are doing something that is going to get your door kicked in then you are probably worth having someone install one of these little toys on your system.  That means I've captures all of the keystrokes for your putty sessions which negates your “but its a remote system and you can't see me” argument.
5) Unless you are doing this hacking just for shits and giggles, at some point you probably expect to make a profit off of it.  Most hackers get busted by investigators following their money trail rather than their network trail. 
6) Once all of this goes to trial then your remote setup is going to work against you.  It just goes to show the judge and jury that you were very aware that you were involved in something illegal.  It will probably add an extra year or so onto your sentence in Federal Pound-Me-In-The-Ass prison where your only joy will be reading my smart ass forum submissions.
198  EH-Net / News Items and General Discussion About EH-Net / Re: ethicalhacker.net IRC channel? on: November 19, 2007, 12:23:36 PM
The most I've seen is a couple of dozen channels.  At any point in time about 5 or so have 20+ people.  The main channel seems to be 50+ most of the time.
199  EH-Net / News Items and General Discussion About EH-Net / Re: ethicalhacker.net IRC channel? on: November 19, 2007, 07:49:25 AM
I'm lurking on cyberarmy's servers for now.
200  EH-Net / News Items and General Discussion About EH-Net / Re: ethicalhacker.net IRC channel? on: November 18, 2007, 06:29:45 PM
Was there ever an IRC chatroom setup?
201  Resources / Career Central / Re: Questions asked in my interview on: November 18, 2007, 01:52:17 PM
Bill,
  I've been a reader of the site for awhile, just never made an account.  Hopefully I'll bring something to the table other than comic relief.
202  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Virtual Networking on: November 17, 2007, 10:05:31 PM
I haven't used virtualbox since VMWare made VM Server free.  Most linux distros will have package that will let you install it without too much pain.  It will definitely allow you to stand up virtual networks as you need them.  Basically you can just assign virtual NICs to each machine that you create, and then you can use the command console to descibe how the NICs relate to each other.  For example, if you wanted to simulate an external penetration test you could create a VM with your testing system (or use your host OS), create another VM and use it to make a firewall, then create a third VM for your target system.  You'd give the firewall VM two NICs, and then use the main console to set one NIC as the external connection which will connect to your testing VM, and then set up the second NIC as the internal connection and connect it to your target OS.  This would let you try out various firewall configurations to see how they would affect your penetration testing.
203  Resources / Career Central / Re: Questions asked in my interview on: November 17, 2007, 09:54:53 PM
(First of all, Congrats on the hire)
This post caught my eye because I end up doing most of the technical interviews for my firm.  For the rest of the folks out there that might be interviewing in the near future, make sure to try and get a specific job description in addition to the title of the position.  Most of the people I interview are sent to me by the HR/Recruiters, and all they've been given are a generic job title and description (ie "IT Security Consultant").  The problem is that we are usually trying to fill several positions at once, and since the recruiters don't have the background to understand most of the technical aspects of the job they just throw all of the "security guys" together and send them to us.  We are expected to figure out during the interview what position, if any, the person would fall into.  So, as a bit of advice, try to find out before hand the specifics of the actual position for which you will be interviewing.  Most of the time the position will fall into one of three slots: auditors, vulnerability assessment, and pen testing.  If you see audit key words (controls, regulations, etc) you'll be expected to speak to stuff like SOX, HIPPA, FISMA, and so on.  If you see general security words (common tools, scanners,etc) then expect to be able to speak to the general OSI model, the scanners, types of exploits, stuff along the lines of the original poster's questions.  If you see anything about doing manual exploits then you'd better be comfortable speaking to application hacking, zero day exploits, client side attacks, and so on.  There is nothing more uncomfortable for the interviewer and person being interviewed than when the person being interviewed is completely in over their head.  Just my two cents...
204  Resources / Looking For Work / Experienced Consultant looking for side work on: November 17, 2007, 08:49:49 PM
Hello EHN community,
   I am an experienced penetration tester and computer forensics examiner looking for hourly or contract work.  I am physically located in the Midwest region of the US, but I can work remotely for any global region or time zone.  In addition to my technical skill set I have extensive experience producing professional formal reports, managing large scale engagements, and I regularly present to C level executives.  Currently I am a consultant for one of the Big-4 advisory firms where I manage their penetration testing and vulnerability assessment teams.  My full resume is available upon request.
EDUCATION:
-Bachelor's & Master's in Computer Science
-CISSP, CISM
TECHNICAL:
-BackTrack Suite, Metasploit, Paros, AppScan, Nessus, etc.
-EnCase, Helix, Autopsy, FTK
-C, C++, Ada, LISP, HTML/XML, Java, JavaScript
EXPERIENCE:
-(Present) Security Consultant
   --Multiple Fortune 100, State/Federal Government customers
        --Several international customers
-Manager of DoD SOC
-Air Intelligence Agency
-Air Force Office of Special Investigations
   --Computer Crimes Investigations
Pages: 1 ... 12 13 [14]
Powered by MySQL Powered by PHP Powered by SMF 1.1.16 | SMF © 2011, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.099 seconds with 21 queries.
 

gk_static-ad_feb2012.jpg
Global Knowledge: Build Security Skills to Protect & Defend

els_130x200fixed2.gif
eLearnSecurity Student Course Now Live!
5% Off with Code
ELS-EH-5

SANS Deals 4 EH-Netters
$150 OFF Any SANS Course in Any Format!
Coupon Code: EHN_Connect Including SANS Security West 2012 & SANSFIRE 2012
Recent Forum Topics

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!

Vote For EH-Net

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2012 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.