Image
 
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 26 guests and 2 members online
EH-Net Donations

Enter Amount:
$

Google Ads
ChicagoCon 2008f
chicagocon2008f_125x200banner.jpg
ChicagoCon 2008f
EH-Net News Feeds
Latest Additions
Book Recommendations





 
Advertisement

You are here: Home arrow Forum
Ethical Hacker Community Forums
August 21, 2008, 03:16:36 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Registration Now Open for ChicagoCon 2008f Oct 27 - Nov 2! Visit www.chicagocon.com.
 
  Home Help Calendar Login Register  
  Show Posts
Pages: [1] 2 3 4
1  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Assistance please on: April 22, 2008, 08:41:25 AM
Quote
why not? its not like that dude is gonna come to your house and kick your butt.  you guys are quick to say "that's unethical" but not so quick to call some out for being a troll or an idiot.  wtf.

Well I don't know about that.  I mean, if he *is* a h4x0r, he *might* come to my house, what with those m4d rm -rf ski11z and all!
2  Resources / News from the Outside World / Re: Feel free to hack Microsoft sites on: April 21, 2008, 02:49:51 PM
Quote
Moussouris said she is pushing to get a provision added to a proposed standard that's making its way through the International Organization for Standardization that would protect ethical hackers who responsibly disclose vulnerabilities in other companies' websites.

That scares the living crap out of me.  I can't imagine the increase in attack traffic if the legal deterrent disappears.  We all become practice targets for the "ethical" hackers.  If your intentions were maliscious?  Just *say* you were ethically hacking, trying to be a good netizen.

That and kiss your IDP systems goodbye, or be prepared to hire a dozen full-timers to wade through the increased traffic.

Yeah... yuck.  Much yuck.
3  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Assistance please on: April 18, 2008, 03:59:37 PM
Rance I thought deltree was the command to do that?

I have experience from the CEH course and exam. The company said I did the best on the interview fo all the candidates.

deltree is a windows command, rm is a linux/unix command.  Lack of basic file manipulation command knowledge says you're out of your league.  And just because you can pass an exam doesn't necessarily mean you're qualified.  I mean, you admittedly executed a command you have *no* knowledge about... that's a huge no-no, even just in every-day computing.  That's how viruses start propagating, and rootkis get installed. 

I'm sorry, I don't want to be harsh, but I wouldn't plan on holding this job of yours for too long.  Doing something like this is going to show pretty blatant incompetence, and I'd bet a paycheck or two that your boss is going to quickly realize that you're not the best qualified candidate they interviewed.

Again, sorry to be so harsh, but reality is what it is.
4  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Assistance please on: April 18, 2008, 03:45:39 PM
Not to rehash anything that anyone has said, but I don't know if it's clearly been stated, but the command rm -rf / *will* attempt to erase every file on the server, without confirmation.

If you had the privlege to run the "rm" command, and it took, then chances are pretty high that you completely toasted their server.

And not to sound like a jerk, but if you're running around on servers (that you don't own or manage) executing commands you don't know about at will, you should probably take a step back from a penetration specialist role and get some more basic experience under your belt.
5  Ethical Hacking Discussions and Related Certifications / Malware / Microsoft Works 7 'WkImgSrv.dll' ActiveX Control Remote Denial of Service Vuln on: April 17, 2008, 03:49:46 PM
There's new exploit code floating around for what appears to be an unpublished zero-day for MS Works.  Looks like it just crashes Works, the code is pretty simple.

Code is available at milworm or packerstorm.
6  Resources / Tools / Re: what is bonjour? on: April 16, 2008, 08:21:41 PM
To add on to what apollo said...

Bonjour is Apple's version of UPnP for the network.  iTunes uses, as does iChat (which is nice if you're on a large LAN, you can see who else is on, without having to add people to a "buddy" list).  Other application use it as well, like subethaedit, which gives users a collaborative document writing, coding platform, and you can see live edits and such.

There's even a windows bonjour client, so you can see printers hanging off a Mac, and so forth.
7  Ethical Hacking Discussions and Related Certifications / Malware / Re: FYI: MS08-021 Exploits are formulating... on: April 14, 2008, 02:07:21 PM
`sploit code has been posted to milw0rm.

Also, SANS ISC has a matrix showing more and more `sploiting going on for the latest round of patches... including 021, 022, 023, and 025.  Info here: http://isc.sans.org/diary.html?storyid=4264
8  Resources / Links to cool sites. / Does the world need another security portal? on: April 14, 2008, 11:07:18 AM
I recently snagged a cool domain name, stormthe.net.  I wanted to do something computer security related with it, but didn't know exactly what.

Last week, however, I found myself trying to scour up web sites that i hadn't visited for a while, from bookmarks across several computers, and having to search for some completely from scratch.

So, I was thinking about a portal of links, sorted by categories, such as Tools, Advisories, Blogs, Exploit Code, News, etc...

User submitted content, ranked links, etc...

Wondering if people would be interested in such a thing before I started writing code.  Please, let me know your thoughts.  Thanks!
9  Ethical Hacking Discussions and Related Certifications / Other / Re: Macbook air on: April 13, 2008, 11:52:47 PM
look here, i'm getting a dell xps m1530 laptop this week... speak up if your puny little macbook air can beat that.

I didn't know it was a competition.  In a manner of speaking, you're comparing apples to oranges.  The Air is an ultra-portable, where the XPS is, well, not.  My main criteria for a laptop at this point is compact and lightweight, with sufficient performance to do work related tasks; which the Air definitely meets.

On top of that, the XPS comes with Windows.  Yuck! Smiley
10  Ethical Hacking Discussions and Related Certifications / Other / Re: Password Protected Word Document on: April 11, 2008, 01:25:13 PM
I'd manually try the obvious things first; password, document, 12345, qwerty, etc.

Failing that, you'll probably have to look at a commercial brute forcer.
11  EH-Net / News Items and General Discussion About EH-Net / Re: 10,000 Posts!! on: April 11, 2008, 11:27:20 AM
I think Don's gone in and modified his post count, what with being 20% of that 10,000 posts and all.  Cheesy

(Congrats on the milestone!)
12  Ethical Hacking Discussions and Related Certifications / Malware / MS08-023 Exploit in the wild on: April 11, 2008, 11:10:04 AM
The SANS ISC reports that PoC code for the MS08-023 vulnerability has been posted publicly (although, I've yet to find it).
13  Ethical Hacking Discussions and Related Certifications / Malware / Re: FYI: MS08-021 Exploits are formulating... on: April 10, 2008, 05:18:58 PM
Also, just checked the milw0rm and packerstorm exploit code databases, and it doesn't appear that this code has reached full disclosure... yet.

Update: The Full Disclosure list also has nothing at this point.
14  Ethical Hacking Discussions and Related Certifications / Malware / FYI: MS08-021 Exploits are formulating... on: April 10, 2008, 05:09:19 PM
It doesn't appear succesful, yet, but give it time.

Quote
The DeepSight honeynet has observed in-the-wild exploit attempts targeting a GDI vulnerability patched by Microsoft on April 8, 2008. The malicious image appears to target the Microsoft Windows GDI Stack Overflow Vulnerability (BID 28570). At least three different sites are hosting the images; two different malicious binaries are associated with the attacks. Analysis of the images has shown that although they appear to be malicious, they do not contain enough data in the associated image property to sufficiently trigger the vulnerability.

Read more:  http://www.symantec.com/security_response/threatcon/index.jsp
15  Ethical Hacking Discussions and Related Certifications / Other / Re: Macbook air on: April 10, 2008, 04:26:54 PM
Rance,

sounds like a nice piece of kit if you use it for the right jobs. The aspect of the Air that has worried me so far is the durability factor. Although I'm yet to get my hands on one to see for myself.

From your experience so far is it likely to survive 'traversing airports'?

I totally think so.  I'd be more worried with a Macbook (plastic enclosure) as opposed to the aluminum enclosure of the Air.  Despite it's small footprint and light-weightedness, I don't notice any flimsyness in the device at all.  I think, overall, it should hold up quite well.
Pages: [1] 2 3 4
Powered by MySQL Powered by PHP Powered by SMF 1.1.5 | SMF © 2006-2008, Simple Machines LLC
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.063 seconds with 21 queries.
 

EH-Net's
2nd Annual
Tweener Party
 

Thanks all. Click HERE for details.

Polls
Best for daily desktop use:
 
Support EH-Net
chicagocon2008f_125x200banner.jpg
ChicagoCon 2008f


Support EH-Net by
Buying all of your
Amazon items using
the search bar above.

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!
Recent Forum Topics
Vote For EH-Net

progenic.com
Click here to Vote!

Sadikhov.com
Top IT Cert Sites

binarica.com
Binarica Logo

Add to Technorati Favorites
technorati fave

chicagocon2008f_125x200banner.jpg
ChicagoCon 2008f
 
         
Advertisement

© 2008 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.