Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 42 guests online
 
Advertisement

You are here: Home arrow EH-Netarrow News Items and General Discussion About EH-Netarrow [Article]-Pen Testing Perfect Storm Pt. III: Network Reconstructive Surgery
EH-Net
May 20, 2013, 07:49:34 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: [Article]-Pen Testing Perfect Storm Pt. III: Network Reconstructive Surgery  (Read 9750 times)
0 Members and 1 Guest are viewing this topic.
don
Editor-In-Chief
Administrator
Hero Member
*****
Offline Offline

Posts: 4165


Editor-In-Chief


View Profile WWW
« on: March 23, 2009, 09:24:19 AM »

Here's the info on tha last in this 3 part webcast series by SANS and sponsored by Core Security. As before, we will also host a post-webcast discussion with the 3 experts. Keep an eye out for the link at the top of the right column.

Permanent link: [Article]-Pen Testing Perfect Storm Pt. III: Network Reconstructive Surgery
Quote


EH-Net is pleased to announce the complimentary webcast, “Network Reconstructive Surgery,” Part III of the Pen Testing Perfect Storm webcast trilogy – featuring the return of SANS Pen Testing swashbucklers Ed Skoudis, Josh Wright and Kevin Johnson. The third and final installment of this popular webcast trilogy will focus on assessing the outside-in attack process, leveraging a seemingly innocuous website bug for full-scale control over the target network infrastructure. You'll learn how to take advantage of powerful tools including Ratproxy, the soon-to-be-released Yokoso! project and a recent browser exploit, as well as how a pentester can manipulate the not-so-helpful features in enterprise wireless networking systems. Combining concepts from web app, network, wireless and social-engineering attack techniques, this webcast will present practical tips for succeeding in a penetration test in ways that exceed that of independent analysis steps. In this finale webcast, you'll also gain insight into predictions by the pentest luminary team on the future of combined penetration tests, including the concept of "no holes barred" pentesting and the effect it will have on the future of enterprise security.

The third and final webcast in this series will take place Tues March 24, 2009 @ 1:00 PM EST. Following the webcast, attendees are invited to keep the conversation going with Kevin, Josh and Ed from InGuardians during discussions hosted by The Ethical Hacker Network (EH-Net), a free online magazine for security professionals. For at least one week after each webcast, the crew will make themselves available to answer your questions directly and candidly in EH-Net’s Community Forums. All discussions will remain freely available on EH-Net for your continued reference.


Don
« Last Edit: March 23, 2009, 12:26:22 PM by don » Logged

CISSP, MCSE, CSTA, Security+ SME
timmedin
Sr. Member
****
Offline Offline

Posts: 469



View Profile WWW
« Reply #1 on: March 23, 2009, 10:48:38 AM »

There are a fantastic series! If you haven't check them out do it. You can find the old ones here:

Part I - Combining Network, Web App and Wireless into the Ultimate Penetration Test
https://www.sans.org/webcasts/show.php?webcastid=91601

Part II - Anatomy of a Mutiny
https://www.sans.org/webcasts/show.php?webcastid=92109
Logged

twitter.com/timmedin | http://blog.securitywhole.com
former33t
Full Member
***
Offline Offline

Posts: 226


View Profile
« Reply #2 on: April 01, 2009, 09:39:00 PM »

Does anyone know where the third one was recorded at?  I have the first two and they are awesome, just missing the last one.

Thanks.
Logged

Certifications: CREA, MCSE: Security, CCNA, Security+, other junk
timmedin
Sr. Member
****
Offline Offline

Posts: 469



View Profile WWW
« Reply #3 on: April 02, 2009, 12:48:40 PM »

Part III
https://www.sans.org/webcasts/show.php?webcastid=92114
Logged

twitter.com/timmedin | http://blog.securitywhole.com
former33t
Full Member
***
Offline Offline

Posts: 226


View Profile
« Reply #4 on: April 02, 2009, 11:21:31 PM »

timmedin,

Maybe I'm missing something, but that's the same link I went to for registration last time looking for the archived session.  I missed it and got sent a registration email instead.  The registration email has links to download the original two webcasts, but not the third.  The only link for the third webcast is to actually attend in real time and it isn't functional.  Does anyone know if there is a recording of this posted somewhere?

Thanks.
Logged

Certifications: CREA, MCSE: Security, CCNA, Security+, other junk
Jhaddix
Sr. Member
****
Offline Offline

Posts: 317



View Profile WWW
« Reply #5 on: April 15, 2009, 02:31:44 PM »

These are the correct links:

•  Webcast recording:

https://coresecurity.webex.com/coresecurity/lsr.php?AT=pb&SP=EC&rID=7322987&rKey=1231C582ECF723AE

 

•  Slide presentation:

https://coresecurity.webex.com/coresecurity/lsr.php?AT=pb&SP=EC&rID=7325532&rKey=41C163EE4464BA8F
Logged

timmedin
Sr. Member
****
Offline Offline

Posts: 469



View Profile WWW
« Reply #6 on: April 27, 2009, 09:10:31 PM »

In the example here a reverse shell was established from the user to the attacker. Is there a tool to allow you to proxy requests through that shell? I don't mean uploading a proxy, but one that uses something like the telnet command to request pages.
Logged

twitter.com/timmedin | http://blog.securitywhole.com
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.055 seconds with 24 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Free Business and Tech Magazines and eBooks

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.