|
Ethical Hacker Community Forums
|
|
November 22, 2008, 04:33:11 AM
|
|
242
|
Ethical Hacking Discussions and Related Certifications / Forensics / Re: Forensic Exam Concludes No Breach at Colorado University
|
on: May 07, 2008, 06:31:50 AM
|
Cheers Don, it's nice to see a story where no evidence of foul play was found after investigation and that additional pre-emptive changes have been made to improve the environment anyway. If we could get more 'good news' stories like this it might make companies worry less about PR effects of a breach and not try to cover up any potential issues, which should improve security as a whole. Might even stop suits and beancounters from seeing security as a necessary cost/evil .... (pinch me, I'm dreaming  )
|
|
|
|
|
244
|
EH-Net / News Items and General Discussion About EH-Net / Re: Who needs it when I've got EH-Net?
|
on: May 07, 2008, 06:19:43 AM
|
|
I'll agree with the general consensus so far, I've found EH-Net to be a great source of information and debate (cheers Don, keep blushin').
I did take a look at HoH and it may have some potential if the top bloke (Petko Petkov, I think) can manage to keep in on track, however only time will tell if it manages to stay legal/professional/ethical for long or if it will attract any knowledgable top contributors.
As for why we need anything else with EH-Net around, if the only place you look for information is EH-Net then you may find yourself falling behind as no single resource can cover every topic to full depth, especially in such a diverse and rapidly evolving field. It never hurts to have a seperate source of information (or to keep an eye of the 'bad guys' if the site goes that way).
|
|
|
|
|
245
|
Resources / Mass Media / Re: Hackerteen - Class, Comic Promotes Ethical Hacking
|
on: May 06, 2008, 04:22:53 AM
|
|
I've just taken a closer look at the site and think it could be really useful for anyone starting out as a kid.
The section that really caught my attention was 'For Parents'. It could make a lot a people's lives easier if they had some way of explaining to on non-technical parent what it really means to be a hacker. From my perspective I was lucky, my mother read the first few chapters of 'A complete hacker's handbook' by Dr-K (at least until the binary and TCP/IP stuff confused her), after that I got no more complaints (and a few more books for christmas).
However, after I recently moved in with my girlfriend I still get od comments from friends/relatives when the read the titles on my bookshelf. This sort of information, if it gets wide exposure, could increase the number of talented individuals able to enter the profession and possibly increase the level of awareness and funding available from other parts of the business if the suits and beancounters can better understand what they are paying for.
|
|
|
|
|
246
|
Resources / Mass Media / Re: Hackerteen - Class, Comic Promotes Ethical Hacking
|
on: May 06, 2008, 04:15:41 AM
|
A kid may grow up wanting to be a hacker...but why would he grow up thinking "I want to be a security analyst!".
Easy, I can answer that one from personal experience. After watching Hackers and reading Mentor's Manifesto, I wanted to be a hacker. But I really didn't want to hear ' pass the soap' after doing something stupid, hence security professional. 
|
|
|
|
|
248
|
Ethical Hacking Discussions and Related Certifications / Other / Re: Encryption and regulations
|
on: May 03, 2008, 04:02:53 AM
|
In countries that don't allow encryption (or believe anything encrypted must be illegal; 'nothing to hide.....etc.). Then I would recommend leaving your data at home and accessing it remotely over a secure (ssh/vpn/etc.) channel once inside the countries borders. Obviously this only works depending on the size of the files you need and the performance of an available network pipe. Read this article earlier and it is worrying me as I need to travel stateside toward the end of the year. From these new changes they'll be a fresh OS installed on my laptop with no data. Two proposals that regularly turn up in commentaries to this is to either release your own 'music', then call in RIAA or place an 'interestingly' named folder on the desktop and fill it with every piece of malware you can find. But they would be unethical....... (or justified depending on your take on state sponsored corporate espionage....)
|
|
|
|
|
249
|
Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: is it possible?????
|
on: April 30, 2008, 10:46:50 AM
|
Dude forget that servercrasher man,you are heating me because of him,I just want to ask cookie can giv id or password or it is totally different???I am not asking how to crack id and passwords from cookie??I want the difference between cookie and id-passwprds!!!that's it!!!
Rok, apologises if you think I'm giving you grief due to an unrelated issue (think I may need to step away from the keyboard). I was merely suggesting that bumping your own topic due to a lack of response may not be advisable. From what I've seen from this site (haven't been a long-term member, possible someone of longer standing can be more exact) if people are able/willing to provide assistance they will. (as Vijay2 just has whilst I preview this, all is good with the world again  )
|
|
|
|
|
250
|
Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: is it possible?????
|
on: April 30, 2008, 10:25:18 AM
|
please do give my answers..
Rok, we did. If you aren't getting specific answers I'm guessing no one has an in depth knowledge of Orkut (never come across it myself) or is unable/willing to provide further info. As you are now looking at a specific target you are unlikely to get specifics from this site. If you have permission to test your thoery (access other people's session before cookie expires) then don't expect others to do your work for you. If assistance dries up you may have hit the wall for a particular topic. Begging and bugging for assistance is not going to help
|
|
|
|
|
251
|
Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Crashing a server
|
on: April 30, 2008, 09:51:42 AM
|
If, as you stated, this is for your dissertation, shouldn't you already have built a pretty solid foundation of knowledge on the subject? Especially if you're planning on testing your theories in an environment other than a lab?
Servercrash, I was going to make this suggestion but oneeyedcarmen beat me to it. I'm not sure of your level of study as I don't know where you are studying but if you have 2 days to get the initial proposal in and you are needing information like this you may want to look at a less technical area, where research material will be easier to find and readily available. As already stated when I completed my dissertation (UK BSc) my project was built on a technology that I had over one year's real world experience implementing, and still found it hard going. Therefore I would ask one final question, 'Why have you chosen this project over any other?' Either way, whatever your final topic as has been expressed by other posters you will get more respect, learn more information and ultimately complete a better project if you can fully understand and research the basics for yourself. Good Luck.
|
|
|
|
|
252
|
Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Crashing a server
|
on: April 30, 2008, 09:01:59 AM
|
man,whats the matter with u???
Servercrash, chill out. Vijay2 was trying to offer assistance, as he has said Google is your friend. But from my experience I know that Google can be daunting and unhelpful if you don't know what to search for, hence why I have given additional pointers. If you don't agree with/appreciate someones input that's fine, but don't flame them, this isn't that kind of place. Regardless, remember that Vijay2 did try to offer you assistance. That was on his time and his choice. I think you may have just stopped him (and possibly others) providing further assistance. RR
|
|
|
|
|
254
|
Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Crashing a server
|
on: April 30, 2008, 08:00:05 AM
|
"the listed attack vectors only make sense if the box you are trying to test is running the vulnerable service"
I wouldnt be knowing what vulnerablities,if any that the server wud be running.So I assume,that i wud have to scan for them first and then based on the search,launch attacks to exploit them...did i get that one right?
Makes sense to me  if you could link your tester to a nessus/nmap/etc. scan output then you're getting more automated  ...so in that case DoS isnt that easy to implement as some of the earlier posts suggest...
Not entirely true, DoS attacks can be the simplest form of assault on a system (other than SE  ). But if a system isn't running the service/application you are attacking it is just going to ignore you. More basically, if you are trying to DoS a system using the apache2 attack you mentioned for example. If the system isn't running apache2 to server web documents then there is no service for you to deny... Same way you don't need to bring a web server to it's knees to effectively stop it serving web content. Again, I'd recommend that you make sure that you have a well defined scope so that you can effectively prove you have achieved the targets of your project, thus getting the most marks for your project (which I'm assuming is your true goal  )
|
|
|
|
|
255
|
Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Crashing a server
|
on: April 30, 2008, 07:42:24 AM
|
My response to your new post/thread. ServerCrash,
the listed attack vectors only make sense if the box you are trying to test is running the vulnerable service. For example the Apache2 DoS requires an apach2 deamon to be running, syslogd requires syslogd etc.
At the same time if you are testing a specific server configuration and you find an attack vector that has no impact on the box then this will be as valuable to your university project as finding a vector that drops the server to it's knees. Therefore implementing the old exploits like Ping of Death may not be a waste of time provided you can explain why devices are no longer as vulnerable to once crippling attacks.
From my experience from University projects (specialised in monitoring systems) it can be more advantageous to explain why things don't work rather than have a state of the art technical solution. From your perspective I imagine that the methodology and techniques for testing systems may be more important than actual functionality.
Hope this helps. Why create a new post then continue the existing one with same content?
|
|
|
|
|
Loading...
|