Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
Jan 2009 Free Giveaway Sponsor - Black Hat DC
Scooby Doo and the Crypto Caper - Answers and Winners
Daemon - A Contest Revealed
Hacking: The Art of Exploitation 2nd Edition
Nov 2008 Free Giveaway - Winners
Dec 2008 Free Giveaway Sponsor - SANS
Santa Claus is Hacking to Town
Plug-N-Play Network Hacking
Nov 2008 Free Giveaway Sponsor - CWNP
Daemon - A Contest Begins Now
It Happened One Friday - Answers and Winners
Daemon - A Contest
Scooby Doo and the Crypto Caper
MS Blue Hat Hackers Headline Chicago Security Con
The Pen Testing Perfect Storm Webcast Series with Skoudis, Wright, Johnson
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 24 guests and 2 members online
EH-Net Donations
Enter Amount:
$
CAD
USD
GBP
AUD
JPY
EUR
Google Ads
EH-Net News Feeds
Latest Additions
Book Recommendations
You are here:
Home
Forum
EH-Net
Special Events
Q&A for Pen Testing Perfect Storm Webcast Series: Part I
Ethical Hacker Community Forums
January 08, 2009, 03:48:02 AM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: ChicagoCon 2-Day Ethical Hacking Conference with MS Blue Hats Oct 31 - Nov 1. Tickets Only $100!
www.chicagocon.com/content/view/103/51/
Home
Help
Calendar
Login
Register
Ethical Hacker Community Forums
>
EH-Net
>
Special Events
(Moderator:
don
) >
Q&A for Pen Testing Perfect Storm Webcast Series: Part I
Pages:
1
[
2
]
3
Go Down
« previous
next »
Print
Author
Topic: Q&A for Pen Testing Perfect Storm Webcast Series: Part I (Read 11296 times)
0 Members and 1 Guest are viewing this topic.
LinearNetworking
Newbie
Offline
Posts: 2
Re: Q&A for Pen Testing Perfect Storm Webcast Series: Part I
«
Reply #15 on:
October 16, 2008, 12:59:09 PM »
Awesome Present Guys! Cant wait for the next one.
My question is more toward the certification process of doing the trifecta of Network, Wireless and Application based Pen testing disciplines. I know that you guys have the SANS programs that you teach for. Is there any other certs that you would recommend for someone who is hard core dedicated to the EH and Pen Testing disciplines?
Also, Have any of you had good success using the techniques discribed yesterday using BeEF over a bluetooth access point that uses more of a PPPoE Model??? or is it more geared towards standard 802ABGX related?
Thanks again for the great presentation, Makes a pen test knowledge hungry person like me feel more in the loop.
Logged
edskoudis
Newbie
Offline
Posts: 5
Re: Q&A for Pen Testing Perfect Storm Webcast Series: Part I
«
Reply #16 on:
October 16, 2008, 04:12:32 PM »
This morning, a good friend of mine asked two questions based on our webcast yesterday. They were such good questions, I figured I’d address them here.
First off, he asked about how a pen tester could verify that the hooked browser near the start of our sample scenario is within the scope of the project. It’s a great question, and we plan on getting into details about how to do that in the second and third webcasts in the series. We’ll talk about different architectural approaches using client-side and web-server-side code to determine where on the network the browser is located to make sure it is kosher to include it in the pen test. So, stay tuned on that one. We’ve got a bunch of slides summarizing a variety of approaches.
His second question revolved around how to get customers who procure pen tests to include such combined work in their tests. I jokingly responded saying that you should do webcasts on the subject and hope your customers listen in and get the idea. But, more seriously, I explained that we do try to discuss combined tests up front during the initial scoping meetings with our clients to gauge their interest. Sometimes, they do sign up for a test that is a combination of the two or three vectors we discussed: network, web, and wireless. But, rather often, they tell us that they only have budget for one of those vectors, such as wireless. I told my friend that we then commence on the given test that the client has planned. Then, when we make some progress and get some form of access, we ask our client, “Do you want us to see how far we can go here?” They often do, thereby placing the more complex and powerful combined attack vectors in play. Customers often get excited by this, because they can see that we’ve scratched the surface and, with the increase in scope, will likely be able to help them make their case for security improvements. So, the short answer to my friend’s second question is to try to scope it in up front, and if that fails, consider running it by the client after a major discovery during a traditional non-combined pen test.
Logged
bugmenot
Newbie
Offline
Posts: 2
Re: Q&A for Pen Testing Perfect Storm Webcast Series: Part I
«
Reply #17 on:
October 16, 2008, 08:11:46 PM »
Any chance this series will be hosted offline somewhere (recorded).
Logged
ChrisG
EH-Net Columnist
Hero Member
Offline
Posts: 1049
Re: Q&A for Pen Testing Perfect Storm Webcast Series: Part I
«
Reply #18 on:
October 17, 2008, 05:15:56 AM »
i got an email that it was recorded and hosted on the sans site (webcast archives)
Logged
...tests i took go here...
http://carnal0wnage.blogspot.com/
epyonx
Newbie
Offline
Posts: 1
Re: Q&A for Pen Testing Perfect Storm Webcast Series: Part I
«
Reply #19 on:
October 17, 2008, 08:08:25 AM »
This was a great webcast. Now I think about pentests in a different manner. Something that I found particularly helpful were slides 28-30. It had a list skills and knowledge needed for the different kinds of pentesting. It gave me a baseline for me to build on. I forgot all about beef; I am going to have to play with BEEF this weekend.
Ed => great seeing you at CSAW. I will get first place next time !
Logged
Thomas
Newbie
Offline
Posts: 4
Re: Q&A for Pen Testing Perfect Storm Webcast Series: Part I
«
Reply #20 on:
October 17, 2008, 07:18:50 PM »
I missed it live but I watched the archive yesterday. It was really good to see how different pen testers approach different customer scenarios.
I am looking forward to Part II and will spend some time with BeEF until then.
Logged
KevinInGuardians
Newbie
Offline
Posts: 9
Re: Q&A for Pen Testing Perfect Storm Webcast Series: Part I
«
Reply #21 on:
October 21, 2008, 11:37:13 AM »
Quote from: Thomas on October 17, 2008, 07:18:50 PM
I missed it live but I watched the archive yesterday. It was really good to see how different pen testers approach different customer scenarios.
Glad to hear you enjoyed it. I always love hearing tips and tricks from the perspective of other people also.
Quote from: Thomas on October 17, 2008, 07:18:50 PM
I am looking forward to Part II and will spend some time with BeEF until then.
As you can tell from the webcast, BEeF is one of my favorite tools. I recommend highly that you look into how to expand the system.
Kevin
Logged
joswr1ght
Newbie
Offline
Posts: 9
Re: Q&A for Pen Testing Perfect Storm Webcast Series: Part I
«
Reply #22 on:
October 21, 2008, 01:20:53 PM »
Quote from: LinearNetworking on October 16, 2008, 12:59:09 PM
Also, Have any of you had good success using the techniques discribed yesterday using BeEF over a bluetooth access point that uses more of a PPPoE Model??? or is it more geared towards standard 802ABGX related?
I seldom find Bluetooth AP's using the RFCOMM, PPP or Bluetooth Network Encapsulation Protocol (BNEP). Most of my experience with Bluetooth AP's has not been in manipulating clients using the device, but in leveraging it as a network access mechanism that escapes 802.11 rogue AP identification.
It's probably not common to find users leveraging a Bluetooth AP for wireless connectivity due to the greater cost associated with the hardware and the relative popularity of 802.11. However, that doesn't mean there aren't other uses for Bluetooth AP's...
Thanks,
-Josh
Logged
oleDB
Full Member
Offline
Posts: 231
Re: Q&A for Pen Testing Perfect Storm Webcast Series: Part I
«
Reply #23 on:
October 21, 2008, 02:38:54 PM »
I have a general question for all 3 guys. I'm sure its an infrequent occurrence that you find a network you cannot hack. However in that rare occasion, what are some of the things that present the biggest obstacles to your pen test?
I'm interested in learning about when companies get security right. And not necessarily even certain technologies like WIDS or RSA authentication, it could just be use of procedures like patching, centralized logging or investments in user security awareness training.
Cheers!
Logged
vijay2
Full Member
Offline
Posts: 134
Re: Q&A for Pen Testing Perfect Storm Webcast Series: Part I
«
Reply #24 on:
October 22, 2008, 07:34:45 AM »
Great webcast guys, finally got it it
. Now that I have listened to it, I have new tools to play around with.
Kevin - I was just browsing through the samurai CD and could not see BeEF on it. As there plans to put it there ?
Thanks
VJ
Logged
GPEN GCIH CISSP CISA GSEC OSCP C|EH Security+
KevinInGuardians
Newbie
Offline
Posts: 9
Re: Q&A for Pen Testing Perfect Storm Webcast Series: Part I
«
Reply #25 on:
October 22, 2008, 10:37:31 AM »
Quote from: vijay2 on October 22, 2008, 07:34:45 AM
Great webcast guys, finally got it it
. Now that I have listened to it, I have new tools to play around with.
Kevin - I was just browsing through the samurai CD and could not see BeEF on it. As there plans to put it there ?
Thanks
VJ
Glad to hear you are checking out Samurai. As to BEeF, it is installed. Since it is a web application, it is found in the bookmarks on Firefox. The controller and the hook are in the "Samurai Tools" bookmark folder.
Kevin
Logged
KevinInGuardians
Newbie
Offline
Posts: 9
Re: Q&A for Pen Testing Perfect Storm Webcast Series: Part I
«
Reply #26 on:
October 22, 2008, 10:42:14 AM »
In the next few posts, I am going to post some of the questions we received after the web cast was finished as well as answering them.
Kevin
Logged
KevinInGuardians
Newbie
Offline
Posts: 9
Re: Q&A for Pen Testing Perfect Storm Webcast Series: Part I
«
Reply #27 on:
October 22, 2008, 10:43:48 AM »
We received many questions about the Tokoso! tool and where to look into it.
Quote
Yokoso! Is the tool I mentioned. It is an infrastructure fingerprinting system delivered via XSS attacks. More information regarding it is available at
http://yokoso.inguardians.com
Logged
KevinInGuardians
Newbie
Offline
Posts: 9
Re: Q&A for Pen Testing Perfect Storm Webcast Series: Part I
«
Reply #28 on:
October 22, 2008, 10:44:47 AM »
Quote
How do you rate BeEF in comparison to metasploit? Similar? Better? Just another tool?
BEeF and metasploit actually fit into two different niches.
Metasploit is an framework for creating, building and delivering exploits.
BEeF is a framework for delivering browser payloads, but does not provide any means for creating or building them.
«
Last Edit: October 22, 2008, 10:49:08 AM by KevinInGuardians
»
Logged
KevinInGuardians
Newbie
Offline
Posts: 9
Re: Q&A for Pen Testing Perfect Storm Webcast Series: Part I
«
Reply #29 on:
October 22, 2008, 10:45:37 AM »
Quote
Does BeEf leave a signiture rthat can be searched?
The hook script does not. Currently it is not detected by any antivirus tools that I have tested. The controller application is detected by antivirus.
Logged
Pages:
1
[
2
]
3
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Special Events
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009
=> News Items and General Discussion About EH-Net
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> Certification
===> The Charter Study Group - Pen Test
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
=====> CEH - Official Course Modules v4
=====> CEH - Official Course Modules v5
=====> CEH - Official Course Modules v6
===> CPTS - Certified Pen Testing Specialist
=====> CPTS - Official Course Modules v5
===> CPTE - Certified Pen Testing Expert
=====> CPTE - Official Course Modules v1
===> ECSA - EC-Council Certified Security Analyst
=====> ECSA - Official Course Modules v1.2
=====> ECSA / LPT - Official Course Modules v3
===> OSCP - Offensive Security Certified Professional
===> GPEN - GIAC Certified Penetration Tester
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
=====> CHFI - Official Course Modules v2
===> EnCE - EnCase® Certified Examiner
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Hardware
=> Malware
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Gates
=> Heffner
=> Hoffman
=> RichM
=> Murray
=> J. Peltier
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
Loading...
Sponsors
Polls
How many security events including conferences and training do you attend a year:
1 - 2
3 - 4
5 - 6
7+
None - But want to
None - Choose not to
Support EH-Net
Support EH-Net by
Buying all of your
Amazon items using
the search bar above.
Try CBT Nuggets Free!
Recent Forum Topics
CEH - Certified Ethical Hacker
: Helow... help some tutorials...
(7) by
K3lV1n
CEH - Certified Ethical Hacker
: CEH is a scam
(20) by
K3lV1n
Malware
: uninstall trend mciro officescan clients
(0) by
Hack_80
Mass Media
: Daniel Suarez Interview
(9) by
blackazarro
Malware
: Security Forecast for 2009
(5) by
jason
News from the Outside World
: Is this acceptable?
(9) by
jason
Wireless
: Wireless Pen Testing Cards
(6) by
jason
Oct 2008 - Scooby Doo and the Crypto Caper
: Skillz October 08 Winning Entry - Technical
(1) by
jason
Gates
: Oracle version module for metasploit
(2) by
BillV
Book Reviews
: [Article]-Mitnick - The Art Of Intrusion: Ch 1 - Hacking The Casinos For A Million Bu...
(5) by
jason
Links to cool sites.
: Free Computer Engineering Classes From Stanford
(3) by
jason
Oct 2008 - Scooby Doo and the Crypto Caper
: Skillz October 08 Winning Entry - Creative
(1) by
jason
Oct 2008 - Scooby Doo and the Crypto Caper
: [Article]-Scooby Doo and the Crypto Caper - Answers and Winners
(2) by
jason
News Items and General Discussion About EH-Net
: [Article]-Jan 2009 Free Giveaway Sponsor - Black Hat DC
(1) by
jason
Book Reviews
: Need a book suggestion!
(2) by
jason
News Items and General Discussion About EH-Net
: EH-Net Milestone - 2 Articles Cross 1 Million Page Views
(3) by
BillV
Other
: What kind of lab, machines you have for your security testing?
(12) by
charlottebandit
Malware
: Network Virus Problem
(9) by
RoleReversal
Wireless
: WUSB600N good usb ?
(2) by
nap191
Other
: FBI code cracking challenge
(3) by
jimbob
Calendar Of Events
: RSA 2009
(0) by
don
Forensics
: Network Forensic tools/practice/techniques
(2) by
jimbob
Malware
: Autoplay when i try to open the drive.
(4) by
jimbob
Physical Security
: Magnetic stripe card spoofing
(4) by
jimbob
Malware
: THe website is Evil but what to do??
(1) by
jimbob
Other
: Insanity?
(3) by
jason
CEH - Certified Ethical Hacker
: Any Practice Environment for learning tool for CEH?
(15) by
don
Wireless
: a petri-dish bridge
(2) by
don
CEH - Certified Ethical Hacker
: TFTP Tranfer time out
(5) by
jason
Tools
: tool to trace users
(8) by
pseud0
Malware
: Malware Challenge 2008 Analysis
(0) by
blackazarro
Programming
: Python 3.0 Released
(0) by
don
Forensics
: SANS SIFT Forensic toolkit
(1) by
don
Links to cool sites.
: Omgili Hacking - Another Search Engine dedicated to Hacking Related Forums
(2) by
RoleReversal
Tools
: Insecure.org's 2006 Top 100 Security Tools List Released
(10) by
shednik
Other
: Happy New Year!
(8) by
vijay2
CEH - Official Course Modules v6
: Community-built CEH Wiki
(2) by
yehg
Vote For EH-Net
progenic.com
binarica.com
technorati fave
Privacy Notice
for TDCC & All Properties
© 2009 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.