Image
 
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 16 guests online
EH-Net Donations

Enter Amount:
$

Google Ads
ChicagoCon 2008s
chicagocon2008s_125x200.jpg
ChicagoCon 2008s
EH-Net News Feeds
Latest Additions
Book Recommendations





 
Advertisement

You are here: Home arrow Forum
Ethical Hacker Community Forums
May 12, 2008, 05:40:30 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: $100 Conference Only Tickets for ChicagoCon 2008s available NOW! Visit www.chicagocon.com.
 
  Home Help Calendar Login Register  
  Show Posts
Pages: [1] 2 3 ... 16
1  General Discussions and Related Certifications / Malware / how to find 'interesting' malware samples? on: Yesterday at 09:55:18 AM
Peoples,

I've recently put a Nepenthes server into production. There were several reasons for this, from trying to get a better view of what's out there, training resources and just 'for fun' (yes I'm a bit strange).

Unfortunately, the server is being too successful and is providing more samples than I can analyse in the timeframe available. Can anyone provide tips so that I can quickly identify and focus on the 'interesting' samples rather than spend time and resources investigating 'garden variety' malware?

Any advice appreciated, thanks in advance.
RR
2  Resources / News from the Outside World / Re: 8 Dirty Secrets of The Security Industry on: May 10, 2008, 10:43:32 AM
I understand that I work for a business, and that the business of business is business...but if you lose your customer base because you didn't do all you could to protect their info, you'll have no business being in business.

wow.... thats a lot of business Wink

couldn't agree more though, it seems that current business culture makes it difficult and rare to get full management buy-in for improving security beyond the minimum. Unfortunately the current climate allows the man (& women) at the top can earn as much (and sometimes more) for a golden boot as a golden handshake.
3  General Discussions and Related Certifications / Ethical Hacking / Re: Tracking MAC Address over internet on: May 10, 2008, 10:38:54 AM
idscore,

I think that on a diverse and distributed system like the Internet what you are proposing could be nearly impossible without physical authentication.

As has been said MAC/IP address isn't going to be the way forward even just due to people having access to multiple machines/public access/etc. before we even get into the realm of spoofing. Likewise multiple, unique individuals may try to access your system from the same IP or MAC address, a shared/public terminal for example.

As Shawal has suggested debit/credit card information should be unique, but a person can have more than one card legitimately (If I only had one my finances would look nicer Wink )

Even going to the extreme of requiring physical authentication (such as RSA keyfobs, swipe cards, etc) whilst each device is unique, again an individual could have access to more than one device, for example registering/recieving one from multiple addresses.

However, whilst it may/will be impossible to get a 100% perfect system it is important to remember that you only need to remove enough flaws to make the system usuable. Holes can and will be found in any non-simple system, online or otherwise, what is required is reducing the level of holes to an acceptable level depending on your context and requirements.

Hope this helps, good luck
4  General Discussions and Related Certifications / Ethical Hacking / Database attacks on: May 09, 2008, 03:35:21 AM
Guys,

I've just read this article on Dark reading regarding penetrating databases. Gave me food for thought and I'll be looking over my own sysems in response to make sure I haven't missed the obvious.

Is also a good example of ways to penetrate systems without requiring an exploit which was recently queried by Loic all methds mentioned rely on poor configuration, poor input validation or simple human error. No 'sploit required
5  Resources / News from the Outside World / Re: Fake MP3 attack hits 360,000 PCs on: May 08, 2008, 08:43:32 AM
I feel your pain. GF has a habit of infecting her (& my) machine on a semi regular basis.

Recently took the huff when I explained that you actually need to (god forbid) run your AV rather than just install it Smiley gotta love non-techies...
6  EH-Net / ChicagoCon 2008s / Re: Ethical Hacking Conference - Talk Details Released on: May 08, 2008, 06:31:25 AM
Sounds great, just wish I could make it Cry
Spare a thought for us poor unfortunates stuck at home...
7  General Discussions and Related Certifications / Ethical Hacking / Re: Industry Regs on: May 08, 2008, 03:14:57 AM
From my experience (BS7799/ISO27001 standards) pen testing isn't required for standards but it is the de factor standard for 'proving' your security posture is working. Basically if you don't do pen-testing you better have a good reason for not doing it and be able to explain to the auditors why you feel your systems are secure without standard testing.
8  Resources / Links to cool sites. / Re: Nice set of Rewrite Rules on: May 07, 2008, 10:49:42 AM
Thanks Vijay2,

I'm working on a new Apache installation now so I'll give them a once over and see if it adds anything to my usual bag of tricks, looks nice and compact at first glance though. Cheers for sharing Cheesy
9  EH-Net / News Items and General Discussion About EH-Net / Re: Will Ethical Hacker site be blocked by Websense or Bluecoat ? on: May 07, 2008, 08:22:35 AM
I remember back to when I didn't know what a proxy was yet, let alone how to use one, trying to figure out how to get around those darn school web filters Tongue

Yup the advantage of having more technical know-how than the teachers, I help set the filters up Cheesy (and no, I didn't shoulder-surf whilst the teachers pecked the admin password at 1 character a minute, allowing me to add what I wanted. That would have been unethical Wink )
10  EH-Net / News Items and General Discussion About EH-Net / Re: Who needs it when I've got EH-Net? on: May 07, 2008, 08:19:32 AM
I had a current and a potential employer both grill me about my dealings on THIS site...and it clearly states "Ethical" in the name!  Google be damned!   Wink

Interesting, I would have thought that active participation in the security community (of any form) would have been a plus for potential employers. It's got to be an advantage over someone who took a bootcamp two use ago and hasn't updated their skills/knowledge-set since.

Any one else had similar issues? (or should I hide my online dealings behind aliases and ToR Huh )
11  Columns / Hoffman / Re: [Article]-Step by Step Guide to the Advanced Mobile Hacks Video on: May 07, 2008, 06:36:29 AM
There are several white papers and videos available from Fiberlink.

Hadn't come across those yet, should stop me from being bored tonight, cheers.
12  General Discussions and Related Certifications / Forensics / Re: Forensic Exam Concludes No Breach at Colorado University on: May 07, 2008, 06:31:50 AM
Cheers Don,

it's nice to see a story where no evidence of foul play was found after investigation and that additional pre-emptive changes have been made to improve the environment anyway.

If we could get more 'good news' stories like this it might make companies worry less about PR effects of a breach and not try to cover up any potential issues, which should improve security as a whole. Might even stop suits and beancounters from seeing security as a necessary cost/evil .... (pinch me, I'm dreaming Wink )
13  General Discussions and Related Certifications / Ethical Hacking / Re: Black hats to become full blooded thieves? on: May 07, 2008, 06:24:09 AM
HonorTech,

I agree with the theory, however I don't imagine that this will become too common. As it stands there are easier ways to remain anonymous (unsecured/poorly secured wireless) without commiting a real-world offence and leaving physical evidence.

14  EH-Net / News Items and General Discussion About EH-Net / Re: Who needs it when I've got EH-Net? on: May 07, 2008, 06:19:43 AM
I'll agree with the general consensus so far, I've found EH-Net to be a great source of information and debate (cheers Don, keep blushin').

I did take a look at HoH and it may have some potential if the top bloke (Petko Petkov, I think) can manage to keep in on track, however only time will tell if it manages to stay legal/professional/ethical for long or if it will attract any knowledgable top contributors.

As for why we need anything else with EH-Net around, if the only place you look for information is EH-Net then you may find yourself falling behind as no single resource can cover every topic to full depth, especially in such a diverse and rapidly evolving field. It never hurts to have a seperate source of information (or to keep an eye of the 'bad guys' if the site goes that way).
15  Resources / Mass Media / Re: Hackerteen - Class, Comic Promotes Ethical Hacking on: May 06, 2008, 04:22:53 AM
I've just taken a closer look at the site and think it could be really useful for anyone starting out as a kid.

The section that really caught my attention was 'For Parents'. It could make a lot a people's lives easier if they had some way of explaining to on non-technical parent what it really means to be a hacker. From my perspective I was lucky, my mother read the first few chapters of 'A complete hacker's handbook' by Dr-K (at least until the binary and TCP/IP stuff confused her), after that I got no more complaints (and a few more books for christmas).

However, after I recently moved in with my girlfriend I still get od comments from friends/relatives when the read the titles on my bookshelf. This sort of information, if it gets wide exposure, could increase the number of talented individuals able to enter the profession and possibly increase the level of awareness and funding available from other parts of the business if the suits and beancounters can better understand what they are paying for.
Pages: [1] 2 3 ... 16
Powered by MySQL Powered by PHP Powered by SMF 1.1.4 | SMF © 2006-2007, Simple Machines LLC
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.061 seconds with 21 queries.
 
BackTrack2 VM w/ MSF3

Get it here NOW!

Polls
My next certification will be from:
 
Support EH-Net
chicagocon2008s_125x200.jpg
ChicagoCon 2008s


Support EH-Net by
Buying all of your
Amazon items using
the search bar above.

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!
Recent Forum Topics
Vote For EH-Net

progenic.com
Click here to Vote!

Sadikhov.com
Top IT Cert Sites

binarica.com
Binarica Logo

Add to Technorati Favorites
technorati fave

chicagocon2008s_125x200.jpg
ChicagoCon 2008s
 
         
Advertisement

© 2008 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.