Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 42 guests and 1 member online
EH-Net News Feeds
Latest Additions
 
Advertisement

You are here: Home arrow Forum
EH-Net
May 22, 2012, 08:31:57 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Advertise on EH-Net!! - Reasonable Rates, Highly Targeted Audience.
 
  Home Help Calendar Login Register  
  Show Posts
Pages: 1 ... 3 4 [5] 6 7 ... 20
61  Resources / News from the Outside World / Re: Microsoft release "secure" XP to the government on: May 11, 2009, 10:59:53 AM
Yup, That'll ruin your day Wink
62  Resources / News from the Outside World / Re: Microsoft release "secure" XP to the government on: May 11, 2009, 07:46:45 AM
And if you are on a .mil domain, you can get the full version. I just recomend against letting it do the remediation. If you let it at it, you will have a "secure version" of XP that you can't use. But you are right on there Bill, it does come up with some registry edits.
63  Ethical Hacking Discussions and Related Certifications / Other / Re: Windows 7 RC Released Today on: May 11, 2009, 07:44:36 AM
I like what I have seen of Win 7 so far. The code for the RC is even more refinded than with the beta and it runs smokin'  compaired to eith XP or Vista: At least according to my stop watch during boot up. Good luck.
64  Ethical Hacking Discussions and Related Certifications / Other / Re: What is the Best Version of Linux? on: May 11, 2009, 07:42:40 AM
If you really want to get into the nuts and bolts, then Gentoo may be the way to go. It is not too unfriendly, but is not nearly as friendly as Ubuntu. I run Ubuntu as my alternate desktop and am thrilled to no end that BT4 is debian/ubuntu based. Get a live CD of whatever distro and play around with it. Find what works right for you. There are so many choices it is unreal. Once you find the distro you like, than it comes down to what desktop, kde, gnome, xfc, etc, that you like. Again, you will find no clear consensus on that either. Good luck.
65  Resources / Tools / Re: embedded http server fingerprinting on: May 11, 2009, 07:35:55 AM
We see that all the time when we do C&A testing as well. More often than not, it is something from Cisco. Chances are that what you are logging into is a web management interface for whatever device. As Katchup said, nmap and nessus work great for figuring out what the web serveer belongs to. Good luck.
66  Resources / News from the Outside World / Re: Microsoft release "secure" XP to the government on: May 08, 2009, 07:34:26 AM
If you are looking for what they used to lock it down, look at teh DISA web site. You are looking for the STIGs. If you don't start from the get go with the STIGs you are in for a long haul trying to meet them.
67  Resources / Career Central / Re: In need of some advice [Continued...] on: May 07, 2009, 12:40:07 PM
I wasn't trying to suggest that you were a noob. I jusst did not know your background and I would give the same advice to pretty much any one out there. After all, we live in a MS domincated world. Back on topic though, we do pen testing where I work, but it is usually associated with doing certification and accreditation testing. We get contracted to do the vulnerability assesment and then often come back and then do a pen test on the system. What you are seeing is that there are few if any that do nothing but pen tests. My background includes a BS in Software Engineering and a Masters in InfoSec. BEing able to read and write code helps, but I wish that I had more sysadmin experience. So as former33t said, do some non-profit work. Programming will never go away. We are too wired these days. Good luck.
68  Resources / Career Central / Re: In need of some advice [Continued...] on: May 07, 2009, 10:02:03 AM
Hang in there. First off, you don't need the degree to get into the field. It helps, but is not the end all be all just as certifications are not. With that said, anything you do will help you out. Pen Testing is not something you just jump right into. Look at a few books out there like "Hacking: the Art of Exploitation" or others. We have all read this or a similar book at some point. Start looking for ways to gain exprience in the general IT world. There are a few good threads on here about the skills that we should have. I wish I had the link handy for you. You need to know a bit about a whole lot of stuff like networking, linux, windows, and some programming (scripting). Just to pick a few. I would suggest trying to find a tech support job with Best Buy or soemthing where you can get soem hands on with various different systems. I did soem part time consulting prior to getting the job I hold now. That let me get into some sys admin and networking experience. take your time and look at what is out there. As far a certs go, look at the net + and security + form CompTia. These are good entry level certs that will open your eyes. Look at using a Linux disto if you have not used linux before. There are live cds that you can use that will not affect your host system. And a last piece of advice, find a mentor that can help guide you. This could be one of your instructors or some one that has been in the IT field for a while. Good luck.
69  Ethical Hacking Discussions and Related Certifications / General Certification / Re: Help with security Clearance forms on: May 06, 2009, 12:32:23 PM
My experience with background checks would suggest that the more honest you are the more likely you are to be granted a clearance. I would be honest about where you liked. I live at where ever while at the university. I was also coutioned for possession. The thought process is that if they have to dig for information that you could easily have given, they may think you were trying to hide something and denie you your clearance. Just a thought though. Good luck.
70  Ethical Hacking Discussions and Related Certifications / Other / Re: Technical presentation advice on: May 06, 2009, 12:29:32 PM
My first presentation was to an auditorium full of E-8s and E-9s while I was a lowly E-5. Again, the best advice was already given, know what you know and what you don't. They will have far more respect for you if you are honest with them. Getting shnoockered before hand might help too Wink. Good luck.
71  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Nmap show a lot of ports on: April 28, 2009, 02:02:22 PM
And don't forget the swiss army knife, netcat. You can always try connectign to the suspected port with nc -v 192.168.1.1 x where x is the port you want to connect to. If its open, you'll know along with its banner. Good luck.
72  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Vuln Scanner on: April 27, 2009, 02:18:23 PM
I also noticed that I do get beeter results with Retina if I have credentials. Unfortunately(or furtunately), our cleint will not give us credientials. Happy scanning.
73  Ethical Hacking Discussions and Related Certifications / Incident Response / Re: Oops, I got us hacked on: April 27, 2009, 02:16:02 PM
You would be surprised. If you are part of the program, you have pretty much unlimited physical access. With that said, the place is wired out the whazoo with video and other physical security implementations. Yes, the insider is a great threat, but it would be hard to get away with anything there.
74  Ethical Hacking Discussions and Related Certifications / Incident Response / Re: Oops, I got us hacked on: April 17, 2009, 01:34:56 PM
On our big contract we regard the insider as the biggest threat to the system if for no other reason than the system is not connected to the internet. With that said, insiders are still a huge threat. Easily half the systems I looked at last week had a boot order that would allow a system to boot from some other media than the first HD. They could also be booted into the BIOS with PWs and had the order changed there. On top of all that, the insider has one thing the outsider doesn't, physical access. We'll see where this goes. Thanks for the news.
75  Resources / News from the Outside World / Re: DoD at its best on: April 17, 2009, 01:30:12 PM
They are supposed to preffer small businesses.....
Pages: 1 ... 3 4 [5] 6 7 ... 20
Powered by MySQL Powered by PHP Powered by SMF 1.1.16 | SMF © 2011, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.292 seconds with 21 queries.
 

gk_static-ad_feb2012.jpg
Global Knowledge: Build Security Skills to Protect & Defend

els_130x200fixed2.gif
eLearnSecurity Student Course Now Live!
5% Off with Code
ELS-EH-5

SANS Deals 4 EH-Netters
$150 OFF Any SANS Course in Any Format!
Coupon Code: EHN_Connect Including SANS Security West 2012 & SANSFIRE 2012
Recent Forum Topics

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!

Vote For EH-Net

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2012 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.