Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 22 guests and 1 member online
Free Business and Tech Magazines and eBooks
You are here:
Home
Ethical Hacking Discussions and Related Certifications
Network Pen Testing
Suggestions for security projects wanted
EH-Net
May 21, 2013, 01:26:47 AM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Ethical Hacking Discussions and Related Certifications
>
Network Pen Testing
(Moderator:
don
) >
Suggestions for security projects wanted
Pages: [
1
]
Go Down
« previous
next »
Print
Author
Topic: Suggestions for security projects wanted (Read 6624 times)
0 Members and 1 Guest are viewing this topic.
UNIX
Hero Member
Offline
Posts: 1234
Suggestions for security projects wanted
«
on:
July 10, 2009, 04:02:40 AM »
Hey,
although I am already working on some smaller projects and help out at others, I would like to start and work regulary on one big project.
Currently I have no specific project in mind, only some basic conditions I would like to follow:
It should be related with penetration testing (on the offensive site) or reverse code engineering, as those are the topics I have most knowledge of and personal interest in
Free, nothing to pay for others
Although not necessary, it may be good if such a project is not available yet or at least not "good", e.g. i see no particular reason for me to write another metasploit
It doesn't matter for me if it is something to program, automate, write, teach etc.
Some random thoughts and keywords I have in mind:
framework for pentesting report
setting up a lab environment
guides
vulnerable operating system, application, etc.
Some kind of CTF
some kind of training
Any suggestions or thoughts on this? Any help is much appreciated.
It is no problem if it is a bigger project.. i see this not only as a chance to help others in one way or another, but also to learn more myself, get "known", etc..so it doesn't matter for me if it takes a lot of time until it is finished.
Looking forward to comments on this.
«
Last Edit: July 10, 2009, 04:59:13 AM by awesec
»
Logged
dalepearson
Sr. Member
Offline
Posts: 357
Re: Suggestions for security projects wanted
«
Reply #1 on:
July 10, 2009, 10:08:01 AM »
Awesec,
I think this is admirable of you, I really struggle to find the time to do something indepth.
Nothing is springing to mind at the moment, but if I think of anything I will drop you a line.
All the best with it though.
Dale
Logged
:: Subliminal Hacking ::
/
:: Security Active Blog ::
Phyr3Ph0x
Newbie
Offline
Posts: 10
Re: Suggestions for security projects wanted
«
Reply #2 on:
July 10, 2009, 02:59:22 PM »
Hiya.
I don't know if you've ever seen the De-ICE lab disks?
http://de-ice.net/hackerpedia/index.php/De-ICE.net_PenTest_Disks#Level_1_2
They are a set of disks based on Slax that are configured to be user as pen-test targets.
You get very little info on what you need to do, and you hack them... Lot's of fun, and they're damned hard too! (Especially for a noob like me
)
Having looked around, there don't seem to be many things like them, so more would be nice...
Regards,
`ph0x
Logged
UNIX
Hero Member
Offline
Posts: 1234
Re: Suggestions for security projects wanted
«
Reply #3 on:
July 11, 2009, 02:11:52 AM »
Thanks dalepearson.
I really like the mentioned De-ICE discs and already completed them some time ago. There are some similar projects I know off but probably one can't have enough of such simulations. I may consider this, thanks for your suggestion, Phyr3Ph0x.
Any more suggestions are of course welcomed.
Logged
former33t
Full Member
Offline
Posts: 226
Re: Suggestions for security projects wanted
«
Reply #4 on:
July 11, 2009, 11:04:30 AM »
I've been toying with the idea of doing log cleaning tools for Solaris auditing logs in binary form. The logs themselves don't seem so hard to clean, the harder part seems to be automating the location of ALL of your log entries and getting rid of them. This is VERY time consuming in a manual fashion. Of course if you can just clean the really damning stuff nobody is likely to even detect that an attack occurred, so maybe that is good enough.
Another place that I was looking at going was reverse engineering AV/firewall log file formats to create cleaning tools for these. The big problem there is that most of these are locked open by the AV program (in windows) so you have to stop the service to clean, then restart (which invariably leaves a log message). Still better than leaving the details of your exploit behind though.
Logged
Certifications: CREA, MCSE: Security, CCNA, Security+, other junk
timmedin
Sr. Member
Offline
Posts: 469
Re: Suggestions for security projects wanted
«
Reply #5 on:
July 14, 2009, 06:53:38 PM »
I am working on setting up a CTF for our local DefCon Group (DC612). Our plan is to have multiple CTFs along the way until we get to the big one. Before each "mini" CTF we will have a few sessions/meetings where we explain the material they will need to pop a box. We will then add more information and tools before the next CTF. We plan on having at least two CTFs before the big one.
We are also evaluating having two teirs of boxes so the n00bs can keep up the the 1337's have something to do. For example they would have to take three boxes. The less experienced players take on A, B, and C while the more experienced take on B, C, and D. The A box would also have some tips for taking other boxes.
I plan on writing this up as we define it, but it will be a while (few months). I'll post here when we are done.
Logged
twitter.com/timmedin |
http://blog.securitywhole.com
timmedin
Sr. Member
Offline
Posts: 469
Re: Suggestions for security projects wanted
«
Reply #6 on:
July 14, 2009, 07:12:31 PM »
•framework for pentesting report
Here is a good guide for understanding the type of things that are done during a test.
http://www.vulnerabilityassessment.co.uk/Penetration%20Test.html
This includes a template for a sample report
http://www.vulnerabilityassessment.co.uk/report%20template.html
I've seen a few other samples as well and I know one sample was posted here last week (or so), but I don't have the link and I'm too lazy to find it.
•setting up a lab environment
Setup a virtual infrastructure and setup a bunch of machines. I know there are multiple threads covering this topic here on EH.net. I would recommend getting a server class machine (used, it is cheaper) and installing ESXi. Throw on a bunch of OS'es and other software. I can't give you good specifics here since it will depend on what you want to test. I would say at a minimum you should have a Windows XP box, a Linux box, and a BSD box. If you want a good box to test against add Damn Vulnerable Linux.
If you want to test against some vulnerable software download some old software from
http://www.oldversion.com
You can also download some intentionally web apps grab Web Goat, Multildea (sp?) and Moth.
•guides
Not to be a jerk but google for what you want, if you need specific help ask and you shall receive. There are a lot of good guides out there for specific tools and apps. If you are looking for one is specific google for it and if you can't find it then ask.
•vulnerable operating system, application, etc.
(See Lab)
•Some kind of CTF
I’ll submit some details on the one I am working on and post it in a few months
•some kind of training
There are lots of sites that specialize in this. Lots of good videos on YouTube and Vimeo, but it can be a little harder to find. I suggest TheAcademyPro.com for some good videos.
Logged
twitter.com/timmedin |
http://blog.securitywhole.com
UNIX
Hero Member
Offline
Posts: 1234
Re: Suggestions for security projects wanted
«
Reply #7 on:
July 15, 2009, 01:25:07 AM »
Your CTF project sounds interesting, good lock. I also like that you will offer something to play with also for the unexperienced users.
I am not sure if you understood my initial posting correct or if I misunderstood you last post. I am not looking for specific guides/ videos etc. for myself but thought about offering such things to others. I have set up a few labs for security testing before and have some experience with other topics too which may help others.
I already got some ideas with this thread although nothing specific yet, still it helps me.
Another thought I had in mind when starting this thread was that maybe someone has a good idea but is for some reason not able to do it by herself, e.g. because of lacking time or knowledge.
@former33t: Thanks for your suggestions. The log cleaning thing sounds interesting but is not exactly what I am currently interested in. I will take a closer look into it when I have experience with Solaris.
Your second suggestion sounds interesting too, although the reboot would make it a little "unsexy". I will think about it though, so thanks.
«
Last Edit: July 15, 2009, 01:33:09 AM by awesec
»
Logged
Jhaddix
Sr. Member
Offline
Posts: 317
Re: Suggestions for security projects wanted
«
Reply #8 on:
July 15, 2009, 11:08:27 AM »
We're working on VM lab setup guides and videos at security aegis pretty soon. One for webapp and one for network.
Should be good stuff
Logged
GSEC, GPEN, GWAPT, ECPPT, WAHHlive, LSOAdvancedPenTester
http://www.securityaegis.com
http://www.pentesterscripting.com
http://code.google.com/p/pentest-bookmarks/
ethicalhack3r
Full Member
Offline
Posts: 139
Re: Suggestions for security projects wanted
«
Reply #9 on:
July 15, 2009, 12:52:41 PM »
You may be interested in helping out with a project I started in December last year.
Damn Vulnerable Web App (dvwa)
Quote
Damn Vulnerable Web App (DVWA) is a PHP/MySQL web application that is damn vulnerable. Its main goals are to be light weight, easy to use and full of vulnerabilities to exploit. Used to learn or teach the art of web application security.
At the moment theres me and a couple of other people working on it in our spare time. The current version is 1.0.4 however were working on a complete recode for the next version which is about 60% complete and can be accessed via SVN.
Project homepage:
http://sourceforge.net/projects/dvwa/
SVN:
https://dvwa.svn.sourceforge.net/svnroot/dvwa
Other info:
http://www.ethicalhack3r.co.uk
Email: dvwa<AT>ethicalhack3r.co.uk
Logged
Jhaddix
Sr. Member
Offline
Posts: 317
Re: Suggestions for security projects wanted
«
Reply #10 on:
July 15, 2009, 01:06:10 PM »
Hey ethicalhack3r,
We are featuring your project in our Webapp lab setup. It wont be out for a week or two (recording and uploading is most of time) but when it is finished our lab environment should have about 7 different targets one being yours. Thanks so much =)
Logged
GSEC, GPEN, GWAPT, ECPPT, WAHHlive, LSOAdvancedPenTester
http://www.securityaegis.com
http://www.pentesterscripting.com
http://code.google.com/p/pentest-bookmarks/
ethicalhack3r
Full Member
Offline
Posts: 139
Re: Suggestions for security projects wanted
«
Reply #11 on:
July 15, 2009, 01:32:38 PM »
Quote from: Jhaddix on July 15, 2009, 01:06:10 PM
Hey ethicalhack3r,
We are featuring your project in our Webapp lab setup. It wont be out for a week or two (recording and uploading is most of time) but when it is finished our lab environment should have about 7 different targets one being yours. Thanks so much =)
Awesome! Glad you find it useful. Where will it be uploaded to?
Keep an eye out for the next version, its in a completely different league to the current stable version.
Logged
Jhaddix
Sr. Member
Offline
Posts: 317
Re: Suggestions for security projects wanted
«
Reply #12 on:
July 15, 2009, 03:33:48 PM »
It'll be on our site and youtube, vimeo, etc. We are using Mutildae, Webgoat, Damn Vulnerable Web App, Foundstones Hacme bank, casino, shipping etc, moth, webmaven, and securibench. Our attack platform will be SamuraiWTF.
Logged
GSEC, GPEN, GWAPT, ECPPT, WAHHlive, LSOAdvancedPenTester
http://www.securityaegis.com
http://www.pentesterscripting.com
http://code.google.com/p/pentest-bookmarks/
UNIX
Hero Member
Offline
Posts: 1234
Re: Suggestions for security projects wanted
«
Reply #13 on:
July 16, 2009, 03:11:10 AM »
Thanks for all replies, also the few given privately. They are much appreciated.
The projectidea I will probably try to realize and work on:
Two
free
courses, including study materials, exercices/ "homework", videos and audio, toolboxes (only using freeware tools and maybe something like shareware etc., so that there is no need to pay money to follow everything).
While the first one will focus on penetration testing and related topics the second one focuses on reverse engineering, binary analysis and malware research.
I am currently settings up a concept on topics I would like to work on and include.
Probably this project will take quite a time until it is complete but I hope and think it will be worth the efforts.
Any thoughts on this?
«
Last Edit: July 17, 2009, 02:52:16 AM by awesec
»
Logged
Pages: [
1
]
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
OSCP - Offensive Security Certified Professional
: Failed my first attempt at the OSCP exam
(94) by
azmatt
Programming
: Finished Python Course in Codecademy now what?
(11) by
securitian
Tools
: Social-Engineer Toolkit (SET) Version 5.0 “The Wild West” Released
(2) by
m0wgli
Malware
: EICAR?
(3) by
UKSecurityGuy
Advisories
: HTB23154: Multiple Vulnerabilities in Exponent CMS
(0) by
AndyP
Advisories
: HTB23153: Multiple Vulnerabilities in Jojo CMS
(0) by
AndyP
Advisories
: HTB23151: Cross-Site Request Forgery (CSRF) in UMI.CMS
(0) by
AndyP
Tutorials
: Need guidance
(8) by
r0ckm4n
OSCP - Offensive Security Certified Professional
: Class Scheduled 6/8 - Linux n00b
(7) by
Taemyks
OSCP - Offensive Security Certified Professional
: OSCP exam scheduled
(6) by
gbhat
Incident Response
: LinkedIn Forensics
(0) by
AFENTIS_Forensics
General Certification
: Red Team/Blue Team
(1) by
ajohnson
Career Central
: Starter cert?
(3) by
Grendel
Network Pen Testing
: Beginner Ethical Hacker
(1) by
m0wgli
General Certification
: CPT Practical Submission
(0) by
z28power4u
Web Applications
: Nessus and Nikto
(4) by
Seen
Network Pen Testing
: Cracking salted MD5 hash
(4) by
n37sh@rk
CEH - Certified Ethical Hacker
: Passed my C|EH
(3) by
n37sh@rk
Mass Media
: EC-council hacked, irony at his best?
(0) by
j0rDy
Web Applications
: SQL Injection into an INSERT statement.
(6) by
eyenit0
Network Pen Testing
: Solution for sipXtapi INVITE Message CSeq Field Header Remote Overflow
(1) by
m0wgli
Web Applications
: dns
(2) by
H1t M0nk3y
Other
: BSides Boston
(0) by
3xban
Career Central
: InfoSec in Central, FL
(2) by
tturner
Web Applications
: Web vulnerability scanner
(4) by
H1t M0nk3y
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
Free Business and Tech Magazines and eBooks
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.