Image
 
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 21 guests and 2 members online
EH-Net Donations

Enter Amount:
$

Google Ads
EH-Net News Feeds
Latest Additions
Book Recommendations





 
Advertisement

You are here: Home arrow Forum
Ethical Hacker Community Forums
November 22, 2008, 03:32:53 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: ChicagoCon 2-Day Ethical Hacking Conference with MS Blue Hats Oct 31 - Nov 1. Tickets Only $100! www.chicagocon.com/content/view/103/51/
 
  Home Help Calendar Login Register  
  Show Posts
Pages: [1]
1  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Penetration Testing Ninjitsu on: February 20, 2008, 07:12:58 PM
Bill,

You got that on the board quick.  I was just reading through the email message when the Ethical Hacker Forum notified me of this porting.  I would like to tell everyone that if you have never had a class with Ed Skoudis it truly is a pleasure.  In addition this webcast is FREE!  Ya can't beat free. 

-jack
2  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Advice for a newbie please on: February 20, 2008, 01:41:31 PM
Rance while you are correct in your explanations of HTML and SQL I think you missed the point.   I think the assertion is that with so many dynamic web sites pulling from back end databases SQL information is replacing flat HTML web page development.  If I got your point wrong Kabal let me know.
3  Ethical Hacking Discussions and Related Certifications / Other / Re: Legality of spy software on: February 07, 2008, 04:59:59 PM
At first looking at this I thought they might be breaking Federal Wire Tap laws.  But after further investigation  http://www.securityfocus.com/news/9978 I found that the wiretap law was thrown out by this judge in a keylogger ruling. 

So next would come down to ownership and who owned the system and provided access to it.  If it is a non-martial relationship and the girlfriend granted access to the computer that belonged to the boyfriend I believe that then there would be laws being broken.
4  Ethical Hacking Discussions and Related Certifications / Malware / Re: $20,000 Bounty for Windows Exploit - Ethical? on: February 06, 2008, 04:13:34 PM
Being new here I haven't chimed in much.  I think JimBob has hit the concept that should be followed on the head.  In a capitalistic environment people should be compensated for their effort. Ultimately there should be a granting mechanism utilized to support research into these areas.  The problem I believe is that if software vendors realize that this mechanism exists what is the incentive to insure the start reducing the vulnerabilities in their software?  There would be no economic reason for someone to halt the release of software because of a flaw.

Now if the government or some independent party could take this on and enforce some type of a fine system for incidents found that would help the funding system.  Additionally, this would stimulate a few more independents to report the exploits as there would be a financial stimulant behind it.

Of course this will NEVER happen.

-Jack
5  Ethical Hacking Discussions and Related Certifications / Malware / Re: Computer illiteracy on: February 06, 2008, 03:36:30 PM
Shoot if you think roommates are bad try a household of Teenagers (4).  Even with AV. anti-spyware, etc I reformat their machines almost quarterly.  Needless to say they are a completely separate network with an independent firewall from all I do.  They would be the complete opposite of a "Trusted Network".  LOL

-Jack
6  Ethical Hacking Discussions and Related Certifications / Malware / Re: question on: February 06, 2008, 03:33:13 PM
Another nice little paper to reference is at http://www.radarhack.com/dir/papers/MetaSploit_for_dummiesl.pdf

Best of luck to you.
-Jack
7  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: How to hack into Linux on: February 05, 2008, 07:14:29 PM
So what happens if you go in after you have logged on in this way and manually reset the password?  Can you replicate this?  I guess it is time to download a Mandriva ISO and set up a VM session.  Has anyone else tested this out?

-Jack
8  Ethical Hacking Discussions and Related Certifications / Certification / Re: CISSP -- Step by Step on: February 05, 2008, 05:36:35 PM
Hi Don,

The link for your CISSP write up seems to be a black hole now.  Can you resurrect that article on here?

Thanks,
Jack
9  Ethical Hacking Discussions and Related Certifications / GCIH - GIAC Certified Incident Handler / Re: SANS GCIH @home method? on: February 05, 2008, 05:21:50 PM
Hi Galaril,

I took the on demand course which was ran by Ed Skoduis and it was great.  Very informative and it was nice to have the lectures as MP3 files.  I loaded these onto my iPod and listened to them during my daily commute.

cheers
-Jack
10  Ethical Hacking Discussions and Related Certifications / CPTS - Certified Pen Testing Specialist / Re: How useful is this for a real world penetration tester? on: February 05, 2008, 02:16:47 PM
Hi,

I would strongly recommend the GCIH exam and class structure over the CEH.  With limited study you can complete the CEH after the GCIH class you couldn't pass the GCIH after a CEH. At least not with limited effort.

-Jack
11  Ethical Hacking Discussions and Related Certifications / Certification / Re: CEH exam woes on: February 05, 2008, 02:08:38 PM
Hi sgt_mjc,

Well don't be discouraged by not passing the CEH it has such a wide breadth of information to cover that it is hard to ensure that you know everything.  I just passed the exam last week and I would strongly recommend the following books for some self study though:

CEH: Official Certified Ethical Hacker Review Guide: Exam 312-50  (kimberly graves)
If you only buy one book this is a great nutshell of what is covered.  It was the only book I read cover to cover.  It is short.

Certified Ethical Hacker Exam Prep (Exam Prep 2 (Que Publishing))
This book is very good for filling in the cracks on areas you really need more information on.

I also though the TestKing practice test are good.  I used them as a guide to see what I needed to read up on more.  They do a very good job of grading you on individual areas.  So when I bombed a section on the practice exam I would go to the Exam Prep book and read up on that area.

I hope that this helps. Remember you can't know NMAP, TCPdump and your Snort logs to well.

Cheers,
Jack
12  Ethical Hacking Discussions and Related Certifications / Certification / Re: Have GCIH taking CEH on: February 05, 2008, 12:23:28 AM
Hi All,

Well I passed the CEH exam with an 82% not great but I spent about 8 hours studying for the test after passing my GCIH.  It is funny though the previous write up on the forum with the CEH study guide made it sound like I had the same exam.  THOUGHTS:

About 1/4 of the test was log reviews. Snort/tcpdump/etc.
NMAP and all the associated switches was huge maybe 15 questions
I used the CEH exam study guide (condensed book) and Testking practice tests and about 25 questions were exact duplicates on the test.

Over all I felt cheated some what by the test.  It has a sense of almost being something valuable, it has a good breadth of knowledge but it is such a patchwork that it doesn't really seem to accomplish anything.  Pretty much what most have said here on the forum.  Since I had already scheduled the test before finding this forum, I didn't put much effort into studying for the test.

Now onto completing my paper for the GCIH gold and trying to run through the GCFA material.

Cheers,
Jack

13  Ethical Hacking Discussions and Related Certifications / Certification / Re: Have GCIH taking CEH on: January 29, 2008, 01:46:38 AM
Thanks alot for the post.  I have the NMAP flags down, I am having a hard time memorizing all the freakin' ports associated with the various trojans and DOS tools.

I have to say I really enjoy the way that SANS lays their testing out.  If you don't know the material you won't make it through the exams cold with just the books.  Very similar to a real world event happening.  I am constantly going back to other resources that I know about to help during an incident.

Thanks Again,
Jack
14  Ethical Hacking Discussions and Related Certifications / Certification / Have GCIH taking CEH on: January 28, 2008, 01:31:40 AM
Hi All,

This is my first post on here and I am getting ready to schedule the CEH exam.  I have my GCIH from SANS and I was wondering if anyone could compare the two exams for me and how much more I might need to study for the CEH?

Cheers,
Jack
Pages: [1]
Powered by MySQL Powered by PHP Powered by SMF 1.1.7 | SMF © 2006-2008, Simple Machines LLC
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.055 seconds with 22 queries.
 
Sponsors

cwnp_moto__120x90.gif

Polls
During the most recent election, I:
 
Support EH-Net


Support EH-Net by
Buying all of your
Amazon items using
the search bar above.

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!
Recent Forum Topics
Vote For EH-Net

progenic.com
Click here to Vote!

Sadikhov.com
Top IT Cert Sites

binarica.com
Binarica Logo

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2008 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.