Image
 
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 26 guests and 2 members online
EH-Net Donations

Enter Amount:
$

Google Ads
ChicagoCon 2008f
chicagocon2008f_125x200banner.jpg
ChicagoCon 2008f
EH-Net News Feeds
Latest Additions
Book Recommendations





 
Advertisement

You are here: Home arrow Forum
Ethical Hacker Community Forums
October 06, 2008, 07:20:52 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Registration Now Open for ChicagoCon 2008f Oct 27 - Nov 2! Visit www.chicagocon.com.
 
  Home Help Calendar Login Register  
  Show Posts
Pages: 1 ... 12 13 [14] 15 16 ... 29
196  Ethical Hacking Discussions and Related Certifications / Other / Re: Free Firewall Aces PC Magazine Tests on: May 14, 2008, 03:10:49 AM
Blackazarro,

thanks for the info man. Guess I should have rtfm  Embarrassed
197  Resources / News from the Outside World / Re: Funny story of stupid criminals on: May 13, 2008, 09:37:14 AM
Can you say D'oh! ?

cheers for the link, put a smile on my face during a long day in the office.
198  Resources / News from the Outside World / Re: Air Force Colonel Wants to Build a Military Botnet on: May 13, 2008, 09:27:43 AM
I read this story earlier and so far I'm hoping that this is PR-type fluff.

In my opinion this could cause some real damage to 'non-combatants' if this were ever utilised. Even if the 'target' is a legitimate enemy (I'll leave the definition to the politicians as we usually disagree) the traffic required to cause the DDoS still needs to head of public/commercial links at some point to reach the destination. Even if service is unaffected by the overheads (unlikely due to reports of ISP's over-subscribing lines etc.) are the US military going to compensate service providers for the extra cost of carrying this traffic? (the US's enemies are often a large distance from their physical borders so this could be a lot of affected networks)

I need to think about it more, just hope the military are going to think about it some more too.
199  Ethical Hacking Discussions and Related Certifications / Other / Re: OQO on: May 13, 2008, 09:20:14 AM
BillV,

looks like a nice device, but I think the price is the main appeal for the EeePC. OQO price is a little out of my budget at the minute but I'll keep it bookmarked for when I win the lottery Wink ,cheers.
200  EH-Net / News Items and General Discussion About EH-Net / Re: New member introduction on: May 13, 2008, 09:18:03 AM
I'll second EnGarde as a good solution.
Good EH-Net review here (It's how I discovered EnGarde in the first place)
201  Resources / News from the Outside World / Re: Hactivism - Good or bad? on: May 13, 2008, 09:15:18 AM
Geekyone,

I agree with your point, but at some point people have to be responsible for the security of their machine. I'm growing tired of the 'not me guv, must be one of them 1337 haxz0r type people' excuses. If you have anything on your machine then you should know how it got there. Until this is a basic requirement prosecuting this kind of thing is going to continue being a joke.

/rant
202  Ethical Hacking Discussions and Related Certifications / Forensics / Re: Forensic test images on: May 13, 2008, 09:07:08 AM
Jimbob,

thanks for the links, I always like having challenges to practice and test my skills. Should keep me out of mischief for a while.
203  Ethical Hacking Discussions and Related Certifications / Other / Re: Free Firewall Aces PC Magazine Tests on: May 13, 2008, 07:11:17 AM
Make sure in >Settings>Default Actions> that you configure it to prompt you or  to alert you when something is detected.

Checked that section afterwards as I hadn't changed the defaults. Suspected and potentially unwanted detects were set to 'prompt me' and know malicious threats were set to 'quarantine and alert me'. Either the alert wasn't generated or I missed it, something to bear in mind either way

From further testing I've installed this app on an XP machine I've got lying around (hasn't been rebuilt in years) and threatfire gave it a clean bill of health. Either I know how to keep a machine in good health or it missed something. (I hate when AV-type programs find nothing, no machine can be that clean Wink )

I've also noticed a few stability/performance issues with my machines whilst threatfire has been running, but this could just be the usual Windows flakiness. If anyone else has had similiar issues can you let me know?

Finally after more playing I've seen that threatfire has a real-time report on the number of global events it has scanned an threats found globally. I haven't had time to investigate this myself yet, does anyone know how this information is reported back and/or what information is included?
204  Ethical Hacking Discussions and Related Certifications / Other / Re: Free Firewall Aces PC Magazine Tests on: May 12, 2008, 07:03:28 AM
Don,

thanks for the link I've just taken a look and run a scan of my system and it looks promising. As Blackazarro said, could be a good addition to AV.

After install I performed a full scan of my system, whilst this did take a while (~3hrs for ~80GB) it found several potential threats on my system. Whilst everything it found I knew about (components from Metasploit and archived binaries from previous incident handling) if I was unaware of the files on my systems I would definately want to know about them. At the same time the files were ignored by recent AV scans on my machine (using Sophos and AVG free).

The aspect that could really be of interest is the behaviour based detection. I tested this with using netcat to set up a port listener, ThreatFire both closed the port and quarantined the nc.exe binary. My only complaint is that I did not recieve an alert starting that the quarentine had taken placing, leaving me to search for a few minutes to figure out why an executable I had just used had vanished  Embarrassed

Overall I'll keep it around and will install it in my malware analysis environment to see how well it performs with behaviour from the 'wild'. Thanks for the heads up.
205  Ethical Hacking Discussions and Related Certifications / Malware / how to find 'interesting' malware samples? on: May 11, 2008, 09:55:18 AM
Peoples,

I've recently put a Nepenthes server into production. There were several reasons for this, from trying to get a better view of what's out there, training resources and just 'for fun' (yes I'm a bit strange).

Unfortunately, the server is being too successful and is providing more samples than I can analyse in the timeframe available. Can anyone provide tips so that I can quickly identify and focus on the 'interesting' samples rather than spend time and resources investigating 'garden variety' malware?

Any advice appreciated, thanks in advance.
RR
206  Resources / News from the Outside World / Re: 8 Dirty Secrets of The Security Industry on: May 10, 2008, 10:43:32 AM
I understand that I work for a business, and that the business of business is business...but if you lose your customer base because you didn't do all you could to protect their info, you'll have no business being in business.

wow.... thats a lot of business Wink

couldn't agree more though, it seems that current business culture makes it difficult and rare to get full management buy-in for improving security beyond the minimum. Unfortunately the current climate allows the man (& women) at the top can earn as much (and sometimes more) for a golden boot as a golden handshake.
207  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Tracking MAC Address over internet on: May 10, 2008, 10:38:54 AM
idscore,

I think that on a diverse and distributed system like the Internet what you are proposing could be nearly impossible without physical authentication.

As has been said MAC/IP address isn't going to be the way forward even just due to people having access to multiple machines/public access/etc. before we even get into the realm of spoofing. Likewise multiple, unique individuals may try to access your system from the same IP or MAC address, a shared/public terminal for example.

As Shawal has suggested debit/credit card information should be unique, but a person can have more than one card legitimately (If I only had one my finances would look nicer Wink )

Even going to the extreme of requiring physical authentication (such as RSA keyfobs, swipe cards, etc) whilst each device is unique, again an individual could have access to more than one device, for example registering/recieving one from multiple addresses.

However, whilst it may/will be impossible to get a 100% perfect system it is important to remember that you only need to remove enough flaws to make the system usuable. Holes can and will be found in any non-simple system, online or otherwise, what is required is reducing the level of holes to an acceptable level depending on your context and requirements.

Hope this helps, good luck
208  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Database attacks on: May 09, 2008, 03:35:21 AM
Guys,

I've just read this article on Dark reading regarding penetrating databases. Gave me food for thought and I'll be looking over my own sysems in response to make sure I haven't missed the obvious.

Is also a good example of ways to penetrate systems without requiring an exploit which was recently queried by Loic all methds mentioned rely on poor configuration, poor input validation or simple human error. No 'sploit required
209  Resources / News from the Outside World / Re: Fake MP3 attack hits 360,000 PCs on: May 08, 2008, 08:43:32 AM
I feel your pain. GF has a habit of infecting her (& my) machine on a semi regular basis.

Recently took the huff when I explained that you actually need to (god forbid) run your AV rather than just install it Smiley gotta love non-techies...
210  EH-Net / ChicagoCon 2008s / Re: Ethical Hacking Conference - Talk Details Released on: May 08, 2008, 06:31:25 AM
Sounds great, just wish I could make it Cry
Spare a thought for us poor unfortunates stuck at home...
Pages: 1 ... 12 13 [14] 15 16 ... 29
Powered by MySQL Powered by PHP Powered by SMF 1.1.5 | SMF © 2006-2008, Simple Machines LLC
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.122 seconds with 21 queries.
 

Microsoft Blue Hat Hackers Headline ChicagoCon
Ethical Hacking Conference Oct 31 - Nov 2

Help spread the word!

Polls
Why a Career in Ethical Hacking:
 
Support EH-Net
chicagocon2008f_125x200banner.jpg
ChicagoCon 2008f


Support EH-Net by
Buying all of your
Amazon items using
the search bar above.

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!
Recent Forum Topics
Vote For EH-Net

progenic.com
Click here to Vote!

Sadikhov.com
Top IT Cert Sites

binarica.com
Binarica Logo

Add to Technorati Favorites
technorati fave

chicagocon2008f_125x200banner.jpg
ChicagoCon 2008f
 
         
Advertisement

© 2008 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.