Image
 
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 19 guests and 1 member online
EH-Net Donations

Enter Amount:
$

Google Ads
EH-Net News Feeds
Latest Additions
Book Recommendations





 
Advertisement

You are here: Home arrow Forum
Ethical Hacker Community Forums
November 22, 2008, 05:59:18 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: ChicagoCon 2-Day Ethical Hacking Conference with MS Blue Hats Oct 31 - Nov 1. Tickets Only $100! www.chicagocon.com/content/view/103/51/
 
  Home Help Calendar Login Register  
  Show Posts
Pages: 1 ... 24 25 [26] 27 28 ... 31
376  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Pentesting Kit on: March 18, 2008, 08:24:22 AM
I think if you search for it, you can find somewhere on the web to download it. I don't think it's maintained any longer (and hasn't been for a while if I remember). I couldn't even get the copy that came with my CEH to boot up.

Cheers BillV,

guess that might answer my question without finding the download
377  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Pentesting Kit on: March 18, 2008, 06:33:14 AM
i take it that since you have so much equipment, you are a pro pen tester, eth3real. Wink

From experience a pentest kit will be relatively similar to an emergency jump bag of anyone who deals with critical systems/networks. Only difference is the general level of calmness during kit's use Wink

My equipment hasn't really changed during the migration from administration to auditing.
378  Features / Opinions / Re: another nice game on: March 18, 2008, 06:28:04 AM
By the way, did I mentioned that this picture was taken 3 years ago.

I don't have time to spent on games like I use to before. Sad

now you're just showing off...... Wink
379  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Social Engineering on: March 18, 2008, 05:49:55 AM
Dean,

I agree with you that social engineering is a valid attack vector (and often the most effective).

However, I think the initial comments (at the very least my own, but I thought others felt the same way) was that SE was something that wasn't enjoyed. For myself this is largely a confidence issue, I'm not a 'people person' therefore trying to convince someone I'm something I'm not is something I don't relish.

I do enjoy the non-interactive, techinical social engineering techniques however and have used dummy sites and spear-phising as an alternative. Following this thread I'm looking forward to testing what happens when I 'lose' a USB stick, thanks for the advice you gave njemjy regarding msfpayload as this should come in useful in this regard.

From those that are skilled at/enjoy social engineering, do you have any advice on how to best introduce yourself into a client's environment? I can't imagine anyone believing my cover stories, would you trust a nervous sweating bloke with your server room? Wink
380  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Pentesting Kit on: March 18, 2008, 03:52:57 AM
eth3real,

pretty similar to my kit, only additions I have are:
  • Selection of tested Cat5 cables of varying lengths (Straight, cross- and roll-over)
  • Cable tester
  • RJ45 ends & crimping set
  • Plane ticket to Brazil for when the .... REALLY hits the fan Wink

I haven't passed the C|EH yet, is the BBC LNX any more useful than other pentest/audit distros?
381  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: hacking adware. on: March 17, 2008, 03:37:22 AM
A bit convoluted,

but quite evil Wink
382  Resources / Links to cool sites. / Re: VTC Learning Library Free One month subscription on: March 17, 2008, 03:34:30 AM
Cheers Manu,

guess I've got a lot of late nights ahead of me...
383  Features / Opinions / Re: another nice game on: March 17, 2008, 03:27:30 AM
will people please stop mentioning Uplink?

I've got work to do god damn it! Grin

(And judging from _Marshel_'s screendump some catching up to do)
384  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Social Engineering on: March 17, 2008, 03:22:09 AM
I am not good at being a “con” guy. 

I'll second that, if I was that good at lying to people I would have gone into management Wink
385  Columns / Wilson / Re: [Article]-Video: Man-in-the-Middle Attack on MySpace with Cain on: March 15, 2008, 09:27:05 AM

w00t!

Hows the site holding up under the legendary /. effect Don?
386  Columns / Gates / Re: Hacking Exposed Web 2.0 Book Review on: March 15, 2008, 09:25:10 AM
ChrisG,

I've actually just got back from a shopping trip where I saw this for the first time and considered a purchase. From reading your review I think you've just saved me from making a mistake, not much point in owning a book detailing a tool that I'll possibly never use.

I'll try to keep an eye out for it in the future bargain bins for the analysis of the samy worm though.

Thanks for the review.
387  Ethical Hacking Discussions and Related Certifications / Certification / Re: Just signed up on: March 15, 2008, 09:18:48 AM
ChrisG,

don't know about anyone else, but I just got the sense that I still have a loonnngggg way to go here. Still, it's always good to have something bring you back to earth to help refocus, thanks.
388  Columns / Wilson / Re: [Article]-Video: Man-in-the-Middle Attack with Cain on: March 14, 2008, 11:48:28 AM
Brian,

nice video, I've had Cain&Abel on my 'Must look at' list for a while. Think you've just jumped it to the top of the queue.

Thanks
389  Resources / Tools / Re: Nipper - Network configuration audit tool on: March 14, 2008, 11:07:24 AM
Sorry for replying to my own post, I managed to do a quick comparison sooner than expected. (Don't you love quite Fridays? Grin ).

I've just ran the CIS Router Audit Tool (RAT) using the same configuration I initially used with Nipper. Mostly both tools came back with the same set of potential weaknesses. So unless they both missed the same issue the coverage appears to be similar with each tool.

The report created by RAT is shorter and more concise than Nipper's although part of that is achieved by hiding some information on hyperlinked pages. (Config file your testing needs to be in the same directory as the rat binary or the links won't work).

As well as listing weaknesses RAT assigns each issue a priority and determines a % score based on which tests you pass or fail. I'm not sure I like having metrics like this as anything that isn't 100% secure is vulnerable to something, and despite what the value says nothing is 100% secure.

As I touch on the SNMP aspects of the report with Nipper I'll do the same for RAT. As with Nipper, RAT complained that I didn't have snmp disabled, and failed me on failed me on 4 tests because I had multiple lines with the string 'snmp-server' (snmp-server community foo; snmp-server location bar etc.).

A feature that RAT implements that isn't fully available with Nipper is that it generates a Cisco command file to run against the device that will 'fix' every security issue with the device. Whilst I'm sure this could be a time saver in many scenarios, if I had blindly run this file against my device I would have lost a lot of functionality that I actually need. Again using SNMP for an example, it is utilised for statistic gathering and most importantly monitoring the state of the device.

As I said with my review of Nipper, don't just follow the advice and fixes without understanding the impact they will have on your network, unless you fancy a world of hurt Wink

Overall, I quite like both tools and each has advantages over the other. Mostly it will come down to personal preference, which tool you know better and can better interpret the findings. Personally, I think I'll hang on to both for some cross checking.
390  Resources / Tools / Re: Nipper - Network configuration audit tool on: March 14, 2008, 10:18:14 AM
I would be curious to run both tools on the same config and compare the results.

Agreed, assuming nothing comes up in the meantime I intend to try CIS RAT at the weekend. I'll run through with the same config for each tool and try to get a comparison.

I'll update my findings as I get more
Pages: 1 ... 24 25 [26] 27 28 ... 31
Powered by MySQL Powered by PHP Powered by SMF 1.1.7 | SMF © 2006-2008, Simple Machines LLC
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.061 seconds with 21 queries.
 
Sponsors

cwnp_moto__120x90.gif

Polls
During the most recent election, I:
 
Support EH-Net


Support EH-Net by
Buying all of your
Amazon items using
the search bar above.

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!
Recent Forum Topics
Vote For EH-Net

progenic.com
Click here to Vote!

Sadikhov.com
Top IT Cert Sites

binarica.com
Binarica Logo

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2008 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.