Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 48 guests and 2 members online
You are here:
Home
Ethical Hacking Discussions and Related Certifications
Network Pen Testing
Noob!!!
EH-Net
May 21, 2013, 08:43:57 AM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Ethical Hacking Discussions and Related Certifications
>
Network Pen Testing
(Moderator:
don
) >
Noob!!!
Pages:
1
[
2
]
3
4
Go Down
« previous
next »
Print
Author
Topic: Noob!!! (Read 31755 times)
0 Members and 1 Guest are viewing this topic.
sedated
Newbie
Offline
Posts: 37
Re: Noob!!!
«
Reply #15 on:
November 22, 2007, 07:20:31 PM »
To me hacking is more about the pursuit of knowledge.While i am not in the information security field yet i am pretty sure employers when they hire someone to pen test them they expect that person to be knowledgeable
about protocols and many other aspects of computing.While maybe tcp/ip
mite not be the best route to start it is absolutely needed in my opinion.Maybe the best thing to recommend to newcomers is books on computer ethics thats what everyone needs before they start playing with tools they do not understand.
.
«
Last Edit: November 22, 2007, 07:22:36 PM by sedated
»
Logged
EmanoN
Newbie
Offline
Posts: 41
Re: Noob!!!
«
Reply #16 on:
November 23, 2007, 07:58:04 PM »
Quote from: dean on November 22, 2007, 09:18:21 AM
I've said this before but it apparently requires repeating,
pentesting is about gaining access to critical data, not dropping a shell on a box
And so spoke the god of hacking! Actually you don’t need to repeat it again and in fact you would do everyone a favor not to because it’s not true. How much bad information can one person give in a single thread? Accessing critical data might be the end result of a pentest, but not always. Many times just gaining a foothold on the network and planting a flag is all a company may allow in a blackbox test. That alone should have not happened and its enough to display vulnerability. If doing a pentest from inside the network, collecting critical data might be part of the information gathering process before the hack like sniffing out a password, that is if you consider a password sensitive or critical data. But neither are the hack itself. Not even in a BlackHat hack is it always the objective. Sometimes the hack is done just to snoop around out of curiosity. Sometimes the hack is done to do something malicious like wipe out a hard drive. With your narrow definition I could say anytime I turn on my computer and access critical data I just hacked it! If I go in and put a gun to the head of the Admin and force him to turn on his box and access data , I guess I just hacked it? Hacking as defined by the majority is gaining unauthorized access to a computer or network via another computer.
«
Last Edit: November 23, 2007, 08:08:16 PM by EmanoN
»
Logged
don
Editor-In-Chief
Administrator
Hero Member
Offline
Posts: 4165
Editor-In-Chief
Re: Noob!!!
«
Reply #17 on:
November 23, 2007, 09:46:56 PM »
The most telling part of this thread is that Cerberus has never posted again. Maybe that should be the lesson here.
Cerberus,
Is there anything I can do to help answer your question or anything else that you feel you maybe didn't get thus far?
Don
Logged
CISSP, MCSE, CSTA, Security+ SME
pseud0
Recruiters
Full Member
Offline
Posts: 208
Re: Noob!!!
«
Reply #18 on:
November 24, 2007, 08:14:17 AM »
You have got to be kidding me. This thread has turned into the geek version of "tastes great! Less filling!" and Ginger versus Mary Ann. Cerberus, the straight answer is that the information security field is still really young, and there is no standard way that folks tend to get involved. Some people are going to start from the OSI model approach and move into the tools, some folks are going to start from the tools and move into the OSI model. To be worthwhile you are going to have to be able to do both. If you get stuck on the OSI side of the house then you are probably not going to understand how to actually carry out or defend against an attack. If you get stuck using just the tools then you are a scriptkiddie who is completely dependent on other people to make your tools, and if you can't find the perfect tool for a situation then you're stuck. Try this approach: If you are already in the OSI mindset (like most students, sys admins, etc) then go on bugtraq and lookup the most common attacks against the systems you are familiar with. Since you are already familiar with your systems then you should be able to understand what the exploit is doing to break your stuff. The next step is to research the tools that use that exploit in order to attack your system. Keep doing that and you'll start to pickup a good understanding of the exploits and the tools. If you are already on the tools side of the house, then just go the opposite direction. If you're using nessus, take the time to actually read the reports, follow the links, and understand what the vulnerabilities are that it is finding. If you're throwing around nmap then read the man page and every time you see a networking/protocol term that you're not familiar with, go research it. If you're into metasploit then take 10 minutes to bring up the code of the exploit you are about to fire off. You're probably not going to be able to make heads or tails of it, so take a couple of days to familiarize yourself with some coding. You'll eventually have to get to this point if you are going to want to write some of your own toys, which is starting to become necessary to avoid mature IDS/IPS systems. By the time you work through these steps you'll start to be able to figure out where you want to go next. Before long you'll realize that each of these areas is an enormous field of study by itself, which is why most "super hackers" actually focus in one area at a time.
Logged
CISSP, CISM, CISA, GCIH, GREM, CEH, HMFIC, KTHXBIROFLCOPTER
Kev
Sr. Member
Offline
Posts: 428
Re: Noob!!!
«
Reply #19 on:
November 24, 2007, 09:29:12 AM »
Well said Sedated and Pseud0! Does seem like much to do about nothing. One person says you should go right into tools and later if you want to go deeper and write your own tools and exploits you should know TCP/IP. Others here seem to feel you should have a good understanding of TCP/IP before working with tools. At least that is what I gathered from the discussion. Really not that big a deal and not worth arguing and certainly not worth lowering a thread with name calling someone an “idiot”.
I would recommend that whens someone asks where to start in computer security, they give a little background information about themselves and also state what their objectives are. For instance, if someone were to come on this board and state they have a Masters in computer science and would just like to learn a few basic tools to evaluate their network, they will get a different response from me than from someone that says they have just a little knowledge of even their own favorite OS, but one day they desire to be one of the hacking greats. As far as anyone knows in this thread, Cerberusugh may already have an awesome background in networking, programming and TCP/IP. If that were the case it would have made this thread take a different direction.
Cerberusugh, if you are still reading this thread, please feel free to post a comment and we can get back on track to better help you!
«
Last Edit: November 24, 2007, 09:33:03 AM by Kev
»
Logged
matthiasfan
Newbie
Offline
Posts: 25
Re: Noob!!!
«
Reply #20 on:
November 24, 2007, 09:32:32 AM »
Gotta throw in my two cents. If you want to learn how to be the best at something, start with the BASICS. If you want to know how to drive a car, you need to know how to start it first. This is not to say that you need to know every detail at first, but to actually drive the car, you need to know some basic things. When you start learning about how cars drive and how the engine works and all, you can actually drive better because you have studied it. This is with ANY FIELD!
If you don't start with the basics, you won't be very good in the long run.
My suggestion, take a networking class at a local community college. Read about how to make virtual machines so that you can practice.
Logged
dean
Guest
Re: Noob!!!
«
Reply #21 on:
November 24, 2007, 10:03:15 AM »
Fine, the thread did take a turn for the worse but at least EmanoN took an apposing viewpoint and was willing to defend it instead of just going along with the previous posts. As much as I disagree with his viewpoint I have to respect that.
EmanoN, if you really want to continue this discussion, you can find me in LSO's IRC.
pseud0, Kev, all really good points those, perhaps posting them earlier would have helped keep the thread on track.
dean
Logged
pseud0
Recruiters
Full Member
Offline
Posts: 208
Re: Noob!!!
«
Reply #22 on:
November 24, 2007, 10:23:54 AM »
I thought the proper use of all threads was to troll and flame. On that note:
You all suck. If it was physically possible you would suck and blow at the same time.
I'm pretty cool. In fact, one time I got two gold stars on my drawing of Elmo.
Since don has the power to kill my account, he's tolerable... but just barely I guess.
Logged
CISSP, CISM, CISA, GCIH, GREM, CEH, HMFIC, KTHXBIROFLCOPTER
LSOChris
Guest
Re: Noob!!!
«
Reply #23 on:
November 24, 2007, 06:32:41 PM »
those of you that just decided, obviously without actually reading the posts, that it was a "great taste vs. less filling debate" really ought to be ashamed of yourself. especially mr badass big 4 pentester, you especially should know better.
Logged
Kev
Sr. Member
Offline
Posts: 428
Re: Noob!!!
«
Reply #24 on:
November 24, 2007, 06:54:06 PM »
Quote from: ChrisG on November 24, 2007, 06:32:41 PM
especially mr badass big 4 pentester, you especially should know better.
Logged
LSOChris
Guest
Re: Noob!!!
«
Reply #25 on:
November 24, 2007, 06:58:28 PM »
http://www.ethicalhacker.net/component/option,com_smf/Itemid,54/topic,1812.msg7124/#msg7124
Logged
Kev
Sr. Member
Offline
Posts: 428
Re: Noob!!!
«
Reply #26 on:
November 24, 2007, 07:15:38 PM »
Quote from: dean on November 24, 2007, 10:03:15 AM
pseud0, Kev, all really good points those, perhaps posting them earlier would have helped keep the thread on track.
Thanks. Hey but dont blame me for how this thread went,LOL! Just kidding.
Eh-net is a small community or family if you like, of contributors. Just like in any family there is going to be some butting of heads now and again. Not really a bad thing once in a while to stir up some passionate debate. Hey, its all good.
Logged
pseud0
Recruiters
Full Member
Offline
Posts: 208
Re: Noob!!!
«
Reply #27 on:
November 24, 2007, 07:28:41 PM »
Did I miss something? I thought it was pretty clear my last post was a joke?
Logged
CISSP, CISM, CISA, GCIH, GREM, CEH, HMFIC, KTHXBIROFLCOPTER
pseud0
Recruiters
Full Member
Offline
Posts: 208
Re: Noob!!!
«
Reply #28 on:
November 24, 2007, 07:33:01 PM »
Ok, I'm trying to figure out where this thread went off the rails, and I just can't. From my point of view I saw people getting very heated over the "OSI to tools" versus "tools to OSI" model, and both are perfectly valid paths to take. That is why I made my "tastes great, less filling" comment. Did I touch a nerve somewhere?
Logged
CISSP, CISM, CISA, GCIH, GREM, CEH, HMFIC, KTHXBIROFLCOPTER
nebu10uz
Sr. Member
Offline
Posts: 368
Re: Noob!!!
«
Reply #29 on:
November 24, 2007, 07:41:40 PM »
This has been an interesting thread, I guess we can stop here and just respect other members opinions and not have a big fuss about it. Agreed?
Logged
Security+, OSCP, CEH
Pages:
1
[
2
]
3
4
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
General Certification
: CPT Practical Submission
(1) by
UNIX
OSCP - Offensive Security Certified Professional
: Failed my first attempt at the OSCP exam
(94) by
azmatt
Programming
: Finished Python Course in Codecademy now what?
(11) by
securitian
Tools
: Social-Engineer Toolkit (SET) Version 5.0 “The Wild West” Released
(2) by
m0wgli
Malware
: EICAR?
(3) by
UKSecurityGuy
Advisories
: HTB23154: Multiple Vulnerabilities in Exponent CMS
(0) by
AndyP
Advisories
: HTB23153: Multiple Vulnerabilities in Jojo CMS
(0) by
AndyP
Advisories
: HTB23151: Cross-Site Request Forgery (CSRF) in UMI.CMS
(0) by
AndyP
Tutorials
: Need guidance
(8) by
r0ckm4n
OSCP - Offensive Security Certified Professional
: Class Scheduled 6/8 - Linux n00b
(7) by
Taemyks
OSCP - Offensive Security Certified Professional
: OSCP exam scheduled
(6) by
gbhat
Incident Response
: LinkedIn Forensics
(0) by
AFENTIS_Forensics
General Certification
: Red Team/Blue Team
(1) by
ajohnson
Career Central
: Starter cert?
(3) by
Grendel
Network Pen Testing
: Beginner Ethical Hacker
(1) by
m0wgli
Web Applications
: Nessus and Nikto
(4) by
Seen
Network Pen Testing
: Cracking salted MD5 hash
(4) by
n37sh@rk
CEH - Certified Ethical Hacker
: Passed my C|EH
(3) by
n37sh@rk
Mass Media
: EC-council hacked, irony at his best?
(0) by
j0rDy
Web Applications
: SQL Injection into an INSERT statement.
(6) by
eyenit0
Network Pen Testing
: Solution for sipXtapi INVITE Message CSeq Field Header Remote Overflow
(1) by
m0wgli
Web Applications
: dns
(2) by
H1t M0nk3y
Other
: BSides Boston
(0) by
3xban
Career Central
: InfoSec in Central, FL
(2) by
tturner
Web Applications
: Web vulnerability scanner
(4) by
H1t M0nk3y
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.