Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 56 guests and 1 member online
You are here:
Home
EH-Net
Special Events
Q&A for Pen Testing Perfect Storm Webcast Series: Part I
EH-Net
May 19, 2013, 08:13:53 PM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
EH-Net
>
Special Events
(Moderator:
don
) >
Q&A for Pen Testing Perfect Storm Webcast Series: Part I
Pages:
1
[
2
]
3
Go Down
« previous
next »
Print
Author
Topic: Q&A for Pen Testing Perfect Storm Webcast Series: Part I (Read 43534 times)
0 Members and 1 Guest are viewing this topic.
LinearNetworking
Newbie
Offline
Posts: 2
Re: Q&A for Pen Testing Perfect Storm Webcast Series: Part I
«
Reply #15 on:
October 16, 2008, 12:59:09 PM »
Awesome Present Guys! Cant wait for the next one.
My question is more toward the certification process of doing the trifecta of Network, Wireless and Application based Pen testing disciplines. I know that you guys have the SANS programs that you teach for. Is there any other certs that you would recommend for someone who is hard core dedicated to the EH and Pen Testing disciplines?
Also, Have any of you had good success using the techniques discribed yesterday using BeEF over a bluetooth access point that uses more of a PPPoE Model??? or is it more geared towards standard 802ABGX related?
Thanks again for the great presentation, Makes a pen test knowledge hungry person like me feel more in the loop.
Logged
edskoudis
Newbie
Offline
Posts: 10
Re: Q&A for Pen Testing Perfect Storm Webcast Series: Part I
«
Reply #16 on:
October 16, 2008, 04:12:32 PM »
This morning, a good friend of mine asked two questions based on our webcast yesterday. They were such good questions, I figured I’d address them here.
First off, he asked about how a pen tester could verify that the hooked browser near the start of our sample scenario is within the scope of the project. It’s a great question, and we plan on getting into details about how to do that in the second and third webcasts in the series. We’ll talk about different architectural approaches using client-side and web-server-side code to determine where on the network the browser is located to make sure it is kosher to include it in the pen test. So, stay tuned on that one. We’ve got a bunch of slides summarizing a variety of approaches.
His second question revolved around how to get customers who procure pen tests to include such combined work in their tests. I jokingly responded saying that you should do webcasts on the subject and hope your customers listen in and get the idea. But, more seriously, I explained that we do try to discuss combined tests up front during the initial scoping meetings with our clients to gauge their interest. Sometimes, they do sign up for a test that is a combination of the two or three vectors we discussed: network, web, and wireless. But, rather often, they tell us that they only have budget for one of those vectors, such as wireless. I told my friend that we then commence on the given test that the client has planned. Then, when we make some progress and get some form of access, we ask our client, “Do you want us to see how far we can go here?” They often do, thereby placing the more complex and powerful combined attack vectors in play. Customers often get excited by this, because they can see that we’ve scratched the surface and, with the increase in scope, will likely be able to help them make their case for security improvements. So, the short answer to my friend’s second question is to try to scope it in up front, and if that fails, consider running it by the client after a major discovery during a traditional non-combined pen test.
Logged
bugmenot
Newbie
Offline
Posts: 2
Re: Q&A for Pen Testing Perfect Storm Webcast Series: Part I
«
Reply #17 on:
October 16, 2008, 08:11:46 PM »
Any chance this series will be hosted offline somewhere (recorded).
Logged
LSOChris
Guest
Re: Q&A for Pen Testing Perfect Storm Webcast Series: Part I
«
Reply #18 on:
October 17, 2008, 05:15:56 AM »
i got an email that it was recorded and hosted on the sans site (webcast archives)
Logged
epyonx
Newbie
Offline
Posts: 1
Re: Q&A for Pen Testing Perfect Storm Webcast Series: Part I
«
Reply #19 on:
October 17, 2008, 08:08:25 AM »
This was a great webcast. Now I think about pentests in a different manner. Something that I found particularly helpful were slides 28-30. It had a list skills and knowledge needed for the different kinds of pentesting. It gave me a baseline for me to build on. I forgot all about beef; I am going to have to play with BEEF this weekend.
Ed => great seeing you at CSAW. I will get first place next time !
Logged
Thomas
Newbie
Offline
Posts: 4
Re: Q&A for Pen Testing Perfect Storm Webcast Series: Part I
«
Reply #20 on:
October 17, 2008, 07:18:50 PM »
I missed it live but I watched the archive yesterday. It was really good to see how different pen testers approach different customer scenarios.
I am looking forward to Part II and will spend some time with BeEF until then.
Logged
KevinInGuardians
Newbie
Offline
Posts: 15
Re: Q&A for Pen Testing Perfect Storm Webcast Series: Part I
«
Reply #21 on:
October 21, 2008, 11:37:13 AM »
Quote from: Thomas on October 17, 2008, 07:18:50 PM
I missed it live but I watched the archive yesterday. It was really good to see how different pen testers approach different customer scenarios.
Glad to hear you enjoyed it. I always love hearing tips and tricks from the perspective of other people also.
Quote from: Thomas on October 17, 2008, 07:18:50 PM
I am looking forward to Part II and will spend some time with BeEF until then.
As you can tell from the webcast, BEeF is one of my favorite tools. I recommend highly that you look into how to expand the system.
Kevin
Logged
joswr1ght
Newbie
Offline
Posts: 11
Re: Q&A for Pen Testing Perfect Storm Webcast Series: Part I
«
Reply #22 on:
October 21, 2008, 01:20:53 PM »
Quote from: LinearNetworking on October 16, 2008, 12:59:09 PM
Also, Have any of you had good success using the techniques discribed yesterday using BeEF over a bluetooth access point that uses more of a PPPoE Model??? or is it more geared towards standard 802ABGX related?
I seldom find Bluetooth AP's using the RFCOMM, PPP or Bluetooth Network Encapsulation Protocol (BNEP). Most of my experience with Bluetooth AP's has not been in manipulating clients using the device, but in leveraging it as a network access mechanism that escapes 802.11 rogue AP identification.
It's probably not common to find users leveraging a Bluetooth AP for wireless connectivity due to the greater cost associated with the hardware and the relative popularity of 802.11. However, that doesn't mean there aren't other uses for Bluetooth AP's...
Thanks,
-Josh
Logged
oleDB
Recruiters
Full Member
Offline
Posts: 236
Re: Q&A for Pen Testing Perfect Storm Webcast Series: Part I
«
Reply #23 on:
October 21, 2008, 02:38:54 PM »
I have a general question for all 3 guys. I'm sure its an infrequent occurrence that you find a network you cannot hack. However in that rare occasion, what are some of the things that present the biggest obstacles to your pen test?
I'm interested in learning about when companies get security right. And not necessarily even certain technologies like WIDS or RSA authentication, it could just be use of procedures like patching, centralized logging or investments in user security awareness training.
Cheers!
Logged
vijay2
Full Member
Offline
Posts: 220
Re: Q&A for Pen Testing Perfect Storm Webcast Series: Part I
«
Reply #24 on:
October 22, 2008, 07:34:45 AM »
Great webcast guys, finally got it it
. Now that I have listened to it, I have new tools to play around with.
Kevin - I was just browsing through the samurai CD and could not see BeEF on it. As there plans to put it there ?
Thanks
VJ
Logged
GPEN GCFA GCIH CISSP CISA GSEC OSCP C|EH Security+
KevinInGuardians
Newbie
Offline
Posts: 15
Re: Q&A for Pen Testing Perfect Storm Webcast Series: Part I
«
Reply #25 on:
October 22, 2008, 10:37:31 AM »
Quote from: vijay2 on October 22, 2008, 07:34:45 AM
Great webcast guys, finally got it it
. Now that I have listened to it, I have new tools to play around with.
Kevin - I was just browsing through the samurai CD and could not see BeEF on it. As there plans to put it there ?
Thanks
VJ
Glad to hear you are checking out Samurai. As to BEeF, it is installed. Since it is a web application, it is found in the bookmarks on Firefox. The controller and the hook are in the "Samurai Tools" bookmark folder.
Kevin
Logged
KevinInGuardians
Newbie
Offline
Posts: 15
Re: Q&A for Pen Testing Perfect Storm Webcast Series: Part I
«
Reply #26 on:
October 22, 2008, 10:42:14 AM »
In the next few posts, I am going to post some of the questions we received after the web cast was finished as well as answering them.
Kevin
Logged
KevinInGuardians
Newbie
Offline
Posts: 15
Re: Q&A for Pen Testing Perfect Storm Webcast Series: Part I
«
Reply #27 on:
October 22, 2008, 10:43:48 AM »
We received many questions about the Tokoso! tool and where to look into it.
Quote
Yokoso! Is the tool I mentioned. It is an infrastructure fingerprinting system delivered via XSS attacks. More information regarding it is available at
http://yokoso.inguardians.com
Logged
KevinInGuardians
Newbie
Offline
Posts: 15
Re: Q&A for Pen Testing Perfect Storm Webcast Series: Part I
«
Reply #28 on:
October 22, 2008, 10:44:47 AM »
Quote
How do you rate BeEF in comparison to metasploit? Similar? Better? Just another tool?
BEeF and metasploit actually fit into two different niches.
Metasploit is an framework for creating, building and delivering exploits.
BEeF is a framework for delivering browser payloads, but does not provide any means for creating or building them.
«
Last Edit: October 22, 2008, 10:49:08 AM by KevinInGuardians
»
Logged
KevinInGuardians
Newbie
Offline
Posts: 15
Re: Q&A for Pen Testing Perfect Storm Webcast Series: Part I
«
Reply #29 on:
October 22, 2008, 10:45:37 AM »
Quote
Does BeEf leave a signiture rthat can be searched?
The hook script does not. Currently it is not detected by any antivirus tools that I have tested. The controller application is detected by antivirus.
Logged
Pages:
1
[
2
]
3
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
OSCP - Offensive Security Certified Professional
: OSCP exam scheduled
(6) by
gbhat
Incident Response
: LinkedIn Forensics
(0) by
AFENTIS_Forensics
General Certification
: Red Team/Blue Team
(1) by
ajohnson
OSCP - Offensive Security Certified Professional
: Class Scheduled 6/8 - Linux n00b
(6) by
Grendel
Career Central
: Starter cert?
(3) by
Grendel
Network Pen Testing
: Beginner Ethical Hacker
(1) by
m0wgli
General Certification
: CPT Practical Submission
(0) by
z28power4u
Web Applications
: Nessus and Nikto
(4) by
Seen
Tutorials
: Need guidance
(7) by
impelse
Malware
: EICAR?
(2) by
SephStorm
Network Pen Testing
: Cracking salted MD5 hash
(4) by
n37sh@rk
CEH - Certified Ethical Hacker
: Passed my C|EH
(3) by
n37sh@rk
Mass Media
: EC-council hacked, irony at his best?
(0) by
j0rDy
Web Applications
: SQL Injection into an INSERT statement.
(6) by
eyenit0
Network Pen Testing
: Solution for sipXtapi INVITE Message CSeq Field Header Remote Overflow
(1) by
m0wgli
Web Applications
: dns
(2) by
H1t M0nk3y
Other
: BSides Boston
(0) by
3xban
Career Central
: InfoSec in Central, FL
(2) by
tturner
Web Applications
: Web vulnerability scanner
(4) by
H1t M0nk3y
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.