Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 77 guests online
 
Free Business and Tech Magazines and eBooks

You are here: Home arrow Ethical Hacking Discussions and Related Certificationsarrow Network Pen Testingarrow An Ethical Hacker must have these skills...
EH-Net
May 19, 2013, 09:53:51 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: 1 2 [3] 4 5   Go Down
  Print  
Author Topic: An Ethical Hacker must have these skills...  (Read 97287 times)
0 Members and 2 Guests are viewing this topic.
dalepearson
Sr. Member
****
Offline Offline

Posts: 357


View Profile WWW
« Reply #30 on: August 04, 2008, 04:29:41 PM »

Welcome to the forum, I would say an Ethical Hacker / InfoSec Professional really needs to have passion.

By this I mean is a general interest for IT Security and all that it encompases. The Security field is very varied with so many subject domains, but dont worry about becoming the guru of everything security. Personally I feel its important to have a high level understanding of all of these domains, but by no means be the master of all.

As you start looking at InfoSec you will find what it is that floats your boat, these maybe technical or soft related skill sets, but as long as you enjoy it and you have passion you can succed.

All the best on the journey.
Logged

bruha666v
Newbie
*
Offline Offline

Posts: 7


View Profile
« Reply #31 on: August 07, 2008, 01:11:46 AM »

  Hi Guys!

  Im bruha666v from the philippines..im a computer science graduate and was exposed to "vb6" for four years. Embarrassed

  I decided to take this course because i wanted to learn how make viruses and stufss but later found out that its wrong. so here i am trying to learn how to hack.

  But im really confused where to start and what to do.  Then a guy i met in a chat room who is also from the philippines challenged me to hack his site and would give me 20k if i do so.
 
  What i need to do is login as admin and just get 20 customer accounts and passwords from his customers database and send it to his email. The site is using php and the URL is:tipidweb.com.

  I believe this could help me start out.Hope you guys could help me out. Im not in for the money, i just wanna learn.

  Thanks!


 
 
 
Logged
Andrew Waite
Hero Member
*****
Offline Offline

Posts: 928



View Profile WWW
« Reply #32 on: August 07, 2008, 03:22:23 AM »

But im really confused where to start and what to do.  Then a guy i met in a chat room who is also from the philippines challenged me to hack his site and would give me 20k if i do so.

You serious? Is that a closed offer or can anyone play? Wink

Any chance this guy is actually any way responsibl for the site in question?

First phase of any penentration engagement is to get a formal contract in place providing full authorisation for you to carry out the work, that way you don't get sued/imprisoned when someone changes their mind. Otherwise known as a CYA document.

I'd be very inclined to take this 'offer' with a pinch of salt...

(P.S. I've got $20million stuck in an offshore account, I could give you 10% if you help me transfer it into your country....)
Logged

dalepearson
Sr. Member
****
Offline Offline

Posts: 357


View Profile WWW
« Reply #33 on: August 07, 2008, 04:43:51 AM »

As RoleReversal says, I think you are buying into this to much.

One its in a chat room, and as on the Internet you can be anybody, I would ignore this guy.

If someone was to REALLY offer you work, it should be via more official means. Just because someone owns a website, its probably hosted by someone else and they would be responsible for authorising any Pen Testing, etc.

If you want to learn / practice pen testing, then have a search on this great forum for information on setting up a virtual lab, using live cds etc.
Logged

bruha666v
Newbie
*
Offline Offline

Posts: 7


View Profile
« Reply #34 on: August 07, 2008, 06:10:20 AM »

Thansk for the reply RR and DP..

Well the guy actually owns the site and he brags about it being "unhackable" and he is manila right now maintaining the site. So im pretty sure its not a scam or watever. Anyway ill try to contact him again and get the "letter" as you told me RR.
 
Anyway, its been nice knowing you guys are out here helping other pipol out.

Ill update you guys as soon as i get in touch with him again.

Bruha666v
Logged
bruha666v
Newbie
*
Offline Offline

Posts: 7


View Profile
« Reply #35 on: August 07, 2008, 06:11:53 AM »

Btw, have you guys checked the site?
Logged
sgt_mjc
Sr. Member
****
Offline Offline

Posts: 294


View Profile
« Reply #36 on: August 07, 2008, 08:28:36 AM »

I did a little research on the site and found that it is hosted by GoDaddy.com. Now that mean that you bruha would need not only authorization form the site owner, but also from GoDaddy. I did my research at dnsstuff.com. Further research shows that this is a Philippine web service provider. Chances are that you are getting in over your head. I would say stay away.

By the way, what was this chat room contacts name?
Logged

Mike Conway
CISSP
CompTia Security +
C|EH
oldgrue
Newbie
*
Offline Offline

Posts: 13


View Profile
« Reply #37 on: August 07, 2008, 03:08:33 PM »

Critical Reasoning Skills.
Developed sense of paranoia.
Logged
sgt_mjc
Sr. Member
****
Offline Offline

Posts: 294


View Profile
« Reply #38 on: August 07, 2008, 04:00:56 PM »

exactly
 
I find myself researching emails from people I don't know just to figure out if they are legit or not. the spammers are getting better by having names on the emails, but they don't often match the name on the email. It cracks me up.
Logged

Mike Conway
CISSP
CompTia Security +
C|EH
bruha666v
Newbie
*
Offline Offline

Posts: 7


View Profile
« Reply #39 on: August 07, 2008, 11:36:20 PM »

Thanks jm..

btw, he's in irc. Channel: bacolod | nick: panulay

anyway, this site has really opened me to new ideas and concepts that could help start.

Im backed out already knowing that this could get me into trouble. Thanks guys!

Hope you could help me out. I really want to know how to "hack". Not because i want to get into other peoples files o computers but i want to learn how to protect myself too knowing the vulnerabilities.

Thanks for the replies guys!


Bruha666v

Logged
$w33p3R
Newbie
*
Offline Offline

Posts: 30


View Profile
« Reply #40 on: August 09, 2008, 12:42:36 AM »

Back to the original topic;

I agree with one of the other posters in this thread...You have to start with the basics and work up if you ever intend to be proficient in your profession, in this case, working as an Ethical Hacker (Network Security).

My recommendations would be:

A++, Network+ - You don't necessarily have to have these certs, but having the knowledge that these certs test you on is essential to even start understanding how to hack.

Linux Is Your Friend - A basic understanding of Linux is pretty much essential in my opinion.  How can you hack something you don't understand anything about.  At least know the basic commands: rm, ps, top, cd, ls, chown, su, sudo, etc.  Staring at a Telnet/SSH prompt and not knowing what to type is hell...(Been there done that)  Plus, several great tools are only available in Linux.

Programming - At least some type of basic programming understanding...I started out back in the QBasic days...telling my age now...Anybody else remember that or am I the oldest fart on the board?  lol  Unless you want to be labeled that dirty word, "script kiddie", you best be able to write some of your own stuff or at least be able to modify others to suit your purpose.

Social Engineering - Yes, I would label this as a requirement for the ethical hacker and even a black hat hacker. (I know some will disagree)  There will be times when you are just not going to get in...the IT Department has done their job and done it well.  You must be able to go to the weakest link, the employee, vendor, etc. and be able to get the information you need to compromise their security.  You can't be just an all geek and number cruncher..you must have some social skills too.

This is just my opinion and we all know what opinions are like.  But, I honestly couldn't see someone succeeding as a hacker without these basic skills.  You might be able to run a script against a web site or company with very poor security, but when you come up against a company/web site that has done their homework, that is where it will take skill and patience when the pre-written scripts fail.

In this high speed internet / fast food society we live in, we always want the quickest way and take all the shortcuts we can.  But we must remember we are only cheating ourselves if we skip the basics.  Take your time and build a good foundation, then the advanced skills come a lot easier.

Logged

MCP, CEH
bruha666v
Newbie
*
Offline Offline

Posts: 7


View Profile
« Reply #41 on: August 10, 2008, 05:13:47 AM »

Guys!

   Remember the guys i told you that owns the site > Tipidweb.com ?? well he told me that godaddy.com doesnt host his site...He has his own dedicated server in the us. and he's really bragging about it. He also told me that he uses the combination of different sql and php code and API combinations. I stopped messing with his site coz u guys told me to back off. Well thanks anyway...



 
Logged
Amat3ur
Newbie
*
Offline Offline

Posts: 2


View Profile
« Reply #42 on: August 11, 2008, 08:49:43 AM »

This is a great thread to look at, when you hit your first plateau.
Some great information Smiley
And unlike some of the others here, I wanna know how to get into others systems without a proggy(I dont buy the ole "I wanna learn to protect myself"  jazz!! lol.), I wanna know how to bounce off nodes to make detection that little more difficult, I wanna know how to mass inject a server, and tell Frank he'll be alright once he gives my favourite Milli Vanilli single back!! I wanna know what the heck Im talking about when Im talking it!! lol

Im not gonna try and mask what I want to learn, as it only hinders my own learning, and there's nothing better than learning something you wanna learn Wink
But I can say out of all honesty..  Its out of curiosity and fun that I have been interested.
I dont wanna be the next Phantom Menace online.
But would like to be able to know, what Im looking at, when its right infront of me.

Freedom of information, and Common sense, are 2 necessities greatly under utilised when starting off.
Understand these, and patience will be your virtue Wink

My 2 shillings worth Grin
Logged
gascoin
Newbie
*
Offline Offline

Posts: 1


View Profile
« Reply #43 on: October 31, 2008, 03:50:25 PM »

Why not start out reading a book on hacking, like Hacking for Dummies, Hacking Exposed, any Kevin Mitnick book?  This could give you an overview of the fundamentals of hacking, and the Mitnick books have good stories, and history on hacking.

There are too many elements to consider on where to start.

Welcome by the way.


I am a newbie in hacking. I want you to be my mentor. Though much depends on me, I will be glad if you can help me through.
 Smiley
Logged
Lancewang
Newbie
*
Offline Offline

Posts: 1


View Profile
« Reply #44 on: December 03, 2008, 01:15:09 AM »



The only thing worse than training good employees and losing them
is NOT training your employees and keeping them
                                                           - Zig Ziglar   
this make sense:P
Logged
Pages: 1 2 [3] 4 5   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.077 seconds with 23 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Free Business and Tech Magazines and eBooks

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.