Image
 
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 22 guests and 1 member online
EH-Net Donations

Enter Amount:
$

Google Ads
EH-Net News Feeds
Latest Additions
Book Recommendations





 
Advertisement

You are here: Home arrow Forum
Ethical Hacker Community Forums
November 22, 2008, 03:41:52 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: ChicagoCon 2-Day Ethical Hacking Conference with MS Blue Hats Oct 31 - Nov 1. Tickets Only $100! www.chicagocon.com/content/view/103/51/
 
  Home Help Calendar Login Register  
  Show Posts
Pages: [1] 2
1  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: What to use? on: July 26, 2007, 02:27:02 AM
Yeah, I'm not sure that this is a good idea... You should probably get written permission from the SysAdmin rather than accepting a 'bet'.
2  Ethical Hacking Discussions and Related Certifications / CEH - Certified Ethical Hacker / Re: CEH Test - Am I Screwed? on: July 06, 2007, 02:07:47 AM
Hi and welcome!

You sound like the sort of person who likes to learn. These people generally do very well in whatever they set their minds too.
I think you will be fine.

Get a few more books and read as much as you can from as many different sources as you can.
Very critical for this exam is hands-on practical. Get a copy of VM Ware and set a few virtual machines with different OS's and practice what you are reading about.
I would also advise you to setup Ubuntu on one of these virtual machines. Some of the test is Linux-based and this is the easiest flavour of Linux for newbie’s. Install some apps, configure various settings and see for yourself that it's not all that hard. Try to become familiar with the different commands and options available. Then format it and set it up again!

As for the exam itself, it is a little worrying that you haven’t done any certifications before. Tests can be stressful, especially if you are new to them. Study hard. Go into the exam confident and know your materials, then you'll be fine. As far as exams go, CEH is an intermediate level exam, so it will be hard but not too hard.

Hope this helps!
3  Features / Opinions / Re: Luke, remember the force! on: July 02, 2007, 03:26:58 AM
100% agree
4  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: thoughts on unsecured network printers on: May 25, 2007, 02:05:54 AM
Or what about a more traditional attack? (seems crude, I know!)

The attacker has gotten into the printer he can disable protocols, services, change the ports it operates on, hostname, etc...
Then you've either got a DOS scenario (imagine this printer is the only printer in a branch office, with no on-site IT staff - far from impossible to resolve remotely but could be a headache and will definitely result in 'downtime').
Maybe if the attacker changes the IP address of printer to that of a server or the router, we've got an IP conflict that could potentially result in a much more serious DOS attack...
5  Ethical Hacking Discussions and Related Certifications / CEH - Certified Ethical Hacker / Re: CEH Self Study 2 year IT Requirement. on: May 22, 2007, 03:45:07 AM
I also got my Boss to do the letter thing and had no problems
6  Ethical Hacking Discussions and Related Certifications / Forensics / Re: Hacked server but logs show a traceable IP. on: May 21, 2007, 09:05:04 AM
A WHOIS on the IP should tell you who the ISP is. The best advice I can give you is to complain to them. Especially as you've said you think the person that hacked you is in the US - they have pretty clear laws about breaking into computer systems. If he was in China or Russia you may get less sympathy  Smiley

Most ISP's have an 'abuse@domain-name' email address to deal with complaints like this. Take some screenshots and copy the logs then attach these to the email.
Be assertive - if it's a business server that's been hacked stress to the ISP that they need to deal with this criminal ASAP.
Chances are they will as they don't want to be sued and if you havae clear evidence then they may get the police/FBI involved.

I wouldn't suggest trying to hack into his TS or FTP server. A simple port-scan can't do any harm, but actively attacking him could get you into trouble ("but he started it" is never going to fly in a court of law).
Also, if he's any good, he has probably just relayed his connection through another hacked box so you might be attempting to hack another legitmate company!
7  Ethical Hacking Discussions and Related Certifications / Forensics / Re: Hacked server but logs show a traceable IP. on: May 21, 2007, 08:40:22 AM
Dude - I don't think it's very ethical to post the IP address here... try to keep yuor questions generic and people will be more than happy to help out.
8  Ethical Hacking Discussions and Related Certifications / Other / Re: EC-Council (& ECSA/LPT) on: May 02, 2007, 01:53:08 AM
I agree - the new web site looks much more professional
9  Ethical Hacking Discussions and Related Certifications / Hardware / Re: Hard Firewall? on: April 30, 2007, 02:55:41 AM
And IPCOP! (http://ipcop.org/)
Why has no one mentioned this yet? I would have thought it was the most well known/popular...

But yeah, you have options  Smiley
10  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Finding Entire network activity on: April 20, 2007, 03:06:48 AM
Hi,

First of all - welcome!

In answer to your question, can I ask if why you don't have access to the router? If it's because it's ISP managed that's cool, but if it's because you are not the network admin and just want to see what people in your office are up to you probably won't get a lot of help here... (Ethical Hacking Forum).

If you are doing some sort of pen-test or are the onsite IT guru, then the easiest (and best) way to monitor/restrict HTTP traffic is via a proxy-server with content filtering. There are many examples of software you can implement to do this - SurfControl springs to mind as the one I've most recently configured, but MS ISA, Wingate, etc support this functionality.
Otherwise if you just want to view the traffic and not implement a solution than Wireshark/Ethereal with the appropriate filters should show    you what you want to know. The obvious rules related to sniffing (ie., same segment, harder in a switched LAN, etc) apply here of course.

I hope this helps answer your question and again, I apologise if I've misinterpreted your intentions!  Smiley   
11  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: VOIP Sniffing on: April 18, 2007, 10:02:23 AM
Where are you sitting on the network?
We probably need a better picture of the setup to help out more...

If you are on a LAN segment in the head office and are trying to sniff packets between the branch office and the head office it's probably not going to work very well. The router that connects the two sites will be configured to do something with that traffic (ie. forward, drop, etc), probably with ACLs telling it to do different things with different types of traffic, and you being on the other side of the router won't be able to see it unless it's configured to pass it onto your segment.
12  Ethical Hacking Discussions and Related Certifications / Other / Re: DMCA: Blizzard vs MDY on: April 12, 2007, 11:49:26 AM
Interesting read... there will certainly be repercussions if the courts agree with Blizzard!
13  EH-Net / News Items and General Discussion About EH-Net / Re: New Poll? on: February 05, 2007, 09:15:44 AM
I agree that ideally the poll should not be cert-related if possible.

I really like Negrita's number two idea about the programming/scripting requirements for a security professional.
I would very much like to see the results of such a poll!

If we are doing that, it would be great to see more articles or tutorials on this topic as well.

14  EH-Net / News Items and General Discussion About EH-Net / Re: New Poll? on: February 02, 2007, 09:12:55 AM
So those of us fortunate enough to not be in the US get either 'London' or 'Other'?  Grin


What about rephrasing the question to something like:

"What certificate/qualification do you regard as the best door-opener in the IT Security Industry?"

And then list a bunch of various certs like Cisco (CCNA/CCSP), Security+, CISSP/SSCP, GIAC, CEH, etc...?

That way (as the poll would be open to non-members too) people in the industry can state their experiences and those perhaps wanting to get into the industry can add their view from an outsiders perspective.
Could be good to compare the two?
15  Ethical Hacking Discussions and Related Certifications / Certification / Re: CompTIA Needs Your Linux Input on: January 16, 2007, 11:01:49 AM
Done
Pages: [1] 2
Powered by MySQL Powered by PHP Powered by SMF 1.1.7 | SMF © 2006-2008, Simple Machines LLC
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.055 seconds with 21 queries.
 
Sponsors

cwnp_moto__120x90.gif

Polls
During the most recent election, I:
 
Support EH-Net


Support EH-Net by
Buying all of your
Amazon items using
the search bar above.

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!
Recent Forum Topics
Vote For EH-Net

progenic.com
Click here to Vote!

Sadikhov.com
Top IT Cert Sites

binarica.com
Binarica Logo

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2008 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.