Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 40 guests online
EH-Net News Feeds
Latest Additions
 
Advertisement

You are here: Home arrow Forum
EH-Net
February 09, 2012, 01:24:57 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Advertise on EH-Net!! - Reasonable Rates, Highly Targeted Audience.
 
  Home Help Calendar Login Register  
  Show Posts
Pages: [1] 2 3 ... 20
1  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: How to convince your boss to allow linux in the workplace on: December 19, 2011, 09:10:32 AM
As 3xban pointed out, a VM might be your best bet of getting a Linux box.  If you do go that route though, pick the hyper-visor that will work best with both the host and the guest.  And don't forget that backtrack was not built to be a secure OS but a pentest OS. 
2  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Questionnaire for Pen Test. on: June 04, 2011, 10:38:32 PM
Find out what the overall objective is.  Do they have a specific objective in mind or is it a free for all and just see what you can get? Oh and ask for a "Get out of jail free card".
3  Features / Opinions / Loaded Question on: June 04, 2011, 10:34:54 PM
I know this will be a loaded question in a site devoted to white hat hackers, so here it goes.

I'm doing research for class on getting the best ROI on a pentest. In your experience how receptive have your organizations/targets been to conducting pentests?

Have you seen value to the pentest?

I know loaded.  Have fun and thanks for the input.

4  Ethical Hacking Discussions and Related Certifications / Security / Re: Passed the CISSP on: June 04, 2011, 10:30:41 PM
I got my approved email last week.  I was relieved. so Now I need to go change my certs.
5  Ethical Hacking Discussions and Related Certifications / Security / Re: Passed the CISSP on: May 04, 2011, 04:21:11 PM
There are no new certs on the horizon for me as its back to school again.
6  Ethical Hacking Discussions and Related Certifications / Security / Re: Passed the CISSP on: April 26, 2011, 02:14:53 PM
Sorry, I have been out for a while now.  Been kinda busy here.  Any way, I also just got my "Congratulations" email from (ISC)2.  It was definitely a relief to get that email instead of the "Thank you" email.  I felt drained when I got done and was not real sure on how I did. 
7  Ethical Hacking Discussions and Related Certifications / General Certification / Re: Noob Question on: December 30, 2010, 08:21:55 AM
What industry are you looking to get into?  The DoD recognizes a few certifications as meeting training requirements.  CEH, CISSP, and CompTIA Security + are just a few. This is not an all inclusive list but it may help. However, any Ethical Hacking cert will help you gain more knowledge.  The Offsec cert is a great cert and is very hands on.  It is not for some one new to Linux or ethical hacking. Before going straight to the hacking certs, look at the Security+ and the Network+ certs.  Then build from there.
8  Ethical Hacking Discussions and Related Certifications / Incident Response / Re: Computer Security Test Gone Wrong - Please Help on: December 30, 2010, 08:15:08 AM
Crossover,

A vulnerability scan is a good start but can give you an incomplete picture. If you look at it from a Risk perspective, there is more you need to look at.  A vulnerability scan like that performed by Nessus, will give network facing vulnerabilities like FTP server listening.  It will not tell you necessarily if the system is vulnerable to a local privilege escalation.  For that you need other tools or methods. You also need to look at the configuration of the network, disaster plans, user agreements, etc.  The list goes on.  In the Federal space, they are migrating to NIST SP800-37 Guide for Applying the Risk Management Framework to Federal Information Systems and using NIST SP800-53a Guide for Assessing the Security Controls in Federal Information Systems and Organizations.  This process is very similar to the DoD process call DIACAP. Both are risk management activities designed to minimize risks to C-I-A (Confidentiality, Integrity, Availability). They take in the whole picture, nut just a vulnerability scan.
9  Ethical Hacking Discussions and Related Certifications / Incident Response / Re: Computer Security Test Gone Wrong - Please Help on: December 21, 2010, 09:09:44 AM
For locking down the system in a meaningful way after doing a risk analysis, you could also look at the guides published by DISA at http://iase.disa.mil/stigs/stig/index.html. These are a little more current that what is published at the NSA site. The key though, is to determine what you have that needs protected and how much protection does it need. Sil's analogy of a house is great and spot on. Hang in there.  We all made mistakes when we started.
10  Ethical Hacking Discussions and Related Certifications / Incident Response / Re: Computer Security Test Gone Wrong - Please Help on: December 15, 2010, 08:43:56 AM
Well taking the HD out is the easiest route since the data may or "probably not" be encrypted.  Since that is not an option and you are using Windows, I would suggest that you look at several of the Microsoft Security Bulletins as they may point you at a flaw in one of the executables already on the system like with Word or Excel.  One question though, can the user save files or make use of a USB drive or other peripheral?  I ask only because you say the C: drive is locked down and they cannot write to it.  Is the system boot password protected or just the BIOS? Can the 1st boot device be changed? What is the boot order?
11  Resources / Tools / Re: SQL Server password cracking on: December 06, 2010, 08:23:40 PM
Thanks, I'll try 'em
12  Resources / Mass Media / Re: TRON: Legacy on: December 06, 2010, 09:09:31 AM
I just let my kids, 8 and 4, watch Tron this weekend and they loved it.  Of course they also love the original Star Wars and like making Cat5 so I'm not really surprised.  I'm going to have to sweet talk my wife into letting me go out to see it when it comes out.  May be as my anniversary present......hhmmm
13  Resources / Tools / SQL Server password cracking on: December 06, 2010, 09:03:40 AM
Hey gang,

I know it has been a while since I had anything meaningful to say, and I'm sorry that is not about to change today.  I'm looking for a tool that will crack SQL Server passwords.  I have the wireshark capture so I have both the salt and the hashed value to go with a user name.  I just need to find a way to crack it.  I know, With the user name and the hash, I already have the keys to the kingdom, but I would like the plain text for use on other systems that might use the same password.

Thanks,
Mike


On a side note, I already know the password but that is not really the point.
14  Ethical Hacking Discussions and Related Certifications / Other / Re: Computer Science or Information Assurace? on: April 02, 2010, 10:07:17 PM
Chris, that's key.  I took just about every language offered when I was in college.  I learned absolutely nothing.   When I finally found a few projects I was interested in years later, I re-learned just about everything.   It is only an opinion, but I believe that programming skills aren't taught, they are acquired over time.   The trick is to find something to write that will motivate you.  I often forget to eat, sleep, bathe, etc when I write code.

I had a problem this week with getting out of the office on time because I was writing a frickin batch script of all things.  When you enjoy what you do, time just flies.
15  Ethical Hacking Discussions and Related Certifications / Other / Re: IIS Problems on: March 30, 2010, 09:58:13 PM
Bill,

Check user rights.  I found that on my box, IUSR was a member of the guest group and guests where denied access to the system both locally and over the network.
Pages: [1] 2 3 ... 20
Powered by MySQL Powered by PHP Powered by SMF 1.1.16 | SMF © 2011, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.226 seconds with 21 queries.
 

gk_static-ad_feb2012.jpg
Global Knowledge Training: Build Security Skills to Protect and Defend

offsec_130x200-2_jan-feb2012.png
Offensive Security
AWE Live in the Caribbean!
March 5 - 9, 2012

SANS Deals 4 EH-Netters
$150 OFF Any SANS Course in Any Format!
Coupon Code: Refer_EHN
Including SANS Phoenix 2012, SANS 2012
Recent Forum Topics

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!

Vote For EH-Net

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2012 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.