Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 31 guests and 1 member online
You are here:
Home
Ethical Hacking Discussions and Related Certifications
Forensics
CHFI - Computer Hacking Forensic Investigator
CHFI EXAM
EH-Net
May 20, 2013, 09:36:28 PM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Ethical Hacking Discussions and Related Certifications
>
Forensics
>
CHFI - Computer Hacking Forensic Investigator
(Moderator:
don
) >
CHFI EXAM
Pages: [
1
]
Go Down
« previous
next »
Print
Author
Topic: CHFI EXAM (Read 15866 times)
0 Members and 1 Guest are viewing this topic.
kabila
Newbie
Offline
Posts: 2
CHFI EXAM
«
on:
August 30, 2010, 07:11:29 AM »
Greetings to all ,
did any just pass the CHFI EXAM. I want to know the best way and materials to read in preparation for the exam . And where to get good CHFI DUMPS.
Thanks ,
kabila
Logged
sil
Hero Member
Offline
Posts: 549
Re: CHFI EXAM
«
Reply #1 on:
August 30, 2010, 09:02:15 AM »
<intro>
While many are reading this, be advised, I need dumps too. See, I'm going to be a doctor and I'm going to place someone's life in my hands. I think I need to read and memorize some books for the sake of passing the exam therefore anyone who may have dumps on becoming a doctor, please post them. After memorizing the books and learning nothing, I think I will now go and place a life in my hands. Anyone want free surgery?
</intro>
If you have to pass an exam like this, why don't you move along to another field. Usually I don't post these kinds of responses but in a situation like this, it's unusually sickening to see how people view the industry and the profession of forensics. Forensics at its best will either convict or exonerate someone of a crime. I've seen personally the downsides of non-competent forensics investigators (
http://mobileforensics.wordpress.com/bio/
[see note below on this]
) - who often carry the weight of assisting in the conviction or exoneration of someone - not have a clue with *someone* in the end being affected in an adverse way.
If you're taking the exam for the sake of doing something other than taking forensics seriously, you're devaluing the certification for those of us who have passed the exam. Those of us who've taken the time to understand the field and respect OURSELVES enough to take pride in certain arenas.
I've dealt with many individuals in government, private industry, hobbyists and for those that I've seen and corresponded with when it comes to forensics are a prideful bunch. Nary a time I've seen anyone come out with "give me a dump" to make me an expert. I've had the opportunity to learn from some of the best in the industry throughout my years and have learned for the sake of understanding it. NOT for the sake of passing a cert.
A dump will not make you an expert period. Learn the material. You wanna pass the CHFI study what EC-Council would like you to understand.
http://www.ethicalhacker.net/component/option,com_smf/Itemid,54/topic,1802.msg9277/
Understand that in this test there are a lot of questions related to LAWS. You know, those things that can either convict or free someone.
Quote
Four years ago, while pregnant, Ms. Amero went to work one day as a substitute teacher and left with felony charges against her.
Her crime? Julie Amero was convicted of four felony counts, each count carrying a maximum of ten years, for exposing school children to pornography.
...
The substitute teacher didn't know what to do to make them stop, so she was led away in handcuffs and convicted of felony charges carrying a maximum sentence of forty years in prison.
...
A number of computer security experts, led by software developer and blogger, Alex Eckelberry noticed serious technical errors were made throughout her trial. Mr. Eckelberry brought together a group of forensic investigators who volunteered to analyze the computer hard drive she was using in the classroom that day and published a report on their findings.
The group's report ultimately caused Julie's conviction to be overturned. Judge Hillary Strackbein overturned the unjust verdict in 2007 and ordered a new trial because of erroneous and false information given during the initial trial.
http://www.huffingtonpost.com/kim-mance/teachers-pop-up-porn-nigh_b_145772.html
Thankfully there are GOOD forensics investigators out there. Those who've taken the time to learn to investigate. You know, that thing you do when you actually have to use your brain for a change
Mobile Forensics Link Note
(
http://mobileforensics.wordpress.com/bio/
)
I was reading this blog as recommended from a friend who works at EnCase. I was performing an analysis of a Blackberry using Oxygen Forensics. After reading the blog and analyzing the procedures used by this former Sergeant Detective and "forensics" expert, I was sad and shocked to see more or less the same. Someone who seemed to perhaps have "read and memorized" a book.
As a forensics expert, everything has to be repeatable, taint free, cross-correlated and stand up in a court of law. Remember, you may need to prove that something happened on a machine (your job is not to see John Smith did this - your role is to present what occurred). The fuse that lit the bomb?
I recommend making a working copy and a archive copy. Now reseal and store your exhibit.
Think about this for a moment. This shouldn't and ISN'T a recommendation. When you're acquiring evidence, you follow the rules and procedures. There is no "recommending" making any copies of archives. These are 1) mandates 2) common sense. See my gripe here?
Imagine if the woman mentioned in the article were your mother, your sister, your wife. How would you feel if their life were entrusted to some shmoe taking exam dumps?
Quote
And this is not even to mention that after her very public arrest,
the pregnant teacher suffered a miscarriage
. Subsequently,
Ms. Amero has been hospitalized because of declining health due to stress
.
In March 2008 a $2,400 ad appeared in the Hartford Courant which was signed by 28 computer science professors arguing that Ms. Amero could not have controlled the pornographic pop-ups.
Trial Detective Mark Lounsbury never checked for the presence of malware.
http://www.huffingtonpost.com/kim-mance/teachers-pop-up-porn-nigh_b_145772.html
Go read the books. Understand what you're doing or find another field. Don't degrade and or devalue this certification.
«
Last Edit: August 30, 2010, 09:04:18 AM by sil
»
Logged
http://www.infiltrated.net/mgz/puppylecter.jpg
smorgan
Newbie
Offline
Posts: 4
Re: CHFI EXAM
«
Reply #2 on:
August 31, 2010, 02:58:27 PM »
If you are looking for brain dumps, then I'm sorry I can't help you. But if you are serious about getting CHFI certified, then I can help you. I work for Firebrand Training and we provide
CHFI certification courses
. We have many EC-Council awards for our work.
if you are looking for the self-study option, then I recommend you the following books:
The Official CHFI Study Guide (Exam 312-49): For Computer Hacking Forensic Investigator (Taschenbuch)
ISBN: 9781597491976
Digital Evidence and Computer Crime: Forensic Science, Computers, and the Internet (Gebundene Ausgabe)
ISBN: 9780121631048
Hope this helps and good luck
Sarah
Logged
Ants
Newbie
Offline
Posts: 25
Re: CHFI EXAM
«
Reply #3 on:
August 31, 2010, 04:58:26 PM »
@sil
Quote from: sil on August 30, 2010, 09:02:15 AM
Those of us who've taken the time to understand the field and respect OURSELVES enough to take pride in certain arenas.
Excellent post - thanks
Logged
CEH, GPEN, GCFW
H1t M0nk3y
Hero Member
Offline
Posts: 864
Re: CHFI EXAM
«
Reply #4 on:
August 31, 2010, 07:29:38 PM »
I agree with you guys. This may be the hardest thing to do in IT security. I believe you need a lot of experience in order to, like sil mentioned, play with people's life.
But on the other hand, he did say:
Quote
I want to know the best way and materials to read in preparation for the exam
The key words are
"the best way"
. So thanks smorgan for helping him!
Like it's been debated on this forum many times, certifications doesn't you an expert (and I am the leaving proof of that!
). But I believe it is a step in the good direction. If this his goal to be a forensic investigator, then he has to start somewhere!
But:
Quote
And where to get good CHFI DUMPS
This wasn't exactly the best quote of the forum...
Logged
OSCP, GPEN, GWAPT, GSEC, CEH, CISSP
impelse
Hero Member
Offline
Posts: 565
Re: CHFI EXAM
«
Reply #5 on:
August 31, 2010, 09:17:59 PM »
I agree guys, It is amazing how I like this feel b ut sometimes I feel that I do not have some progress, like if I stuck in something until I get it well. But it is worth it
Logged
CCNA, Security+, 70-290, 70-291
CCNA Security
Taking Hackingdojo training
Website:
http://blog.thehost1.com/
kabila
Newbie
Offline
Posts: 2
Re: CHFI EXAM : I LIKE COORECTIONS
«
Reply #6 on:
September 01, 2010, 05:19:12 AM »
I thank you all for your time . We learn everyday . I am very sorry if I did sound lazy by asking for dumps but I stand to be corrected any day because I am ready to learn.
Now what materials should I read and which topics should I concentrate more .
Please help me guys .
Warm shout out to all.
Kabila
Logged
UNIX
Hero Member
Offline
Posts: 1234
Re: CHFI EXAM
«
Reply #7 on:
September 01, 2010, 05:32:02 AM »
smorgan already recommended two books to you, so you might take a look at those.
Logged
don
Editor-In-Chief
Administrator
Hero Member
Offline
Posts: 4165
Editor-In-Chief
Re: CHFI EXAM
«
Reply #8 on:
September 01, 2010, 03:04:22 PM »
Hey kabila,
Welcome to EH-Net. The feelings of the community have been pretty clearly stated. But let me take this opportunity to thank you for taking it the right way. Many would simply yell back or leave. You were strong enough to take the advice and move forward in a positive manner.
That kind of attitude is welcomed and encouraged.
Let us know how you like the recommended books.
Don
Logged
CISSP, MCSE, CSTA, Security+ SME
sil
Hero Member
Offline
Posts: 549
Re: CHFI EXAM
«
Reply #9 on:
September 01, 2010, 04:15:38 PM »
And just as an FYI, again, my response was off-beat, but I'm hoping its enough to make some readers WANT to do things the right way. A dump makes you nothing more than a fraud at the end of the day. Remember, you're supposed to be an SME (Subject Matter Expert) and in the forensics field, you may (often will) be called to testify. You wouldn't want a fraud representing you if your life was on the line would you?
Anyhow, here is a quick list of books and my reasons for posting them:
1) Windows Forensic Analysis DVD Toolkit, Second Edition
http://www.amazon.com/Windows-Forensic-Analysis-Toolkit-Second/dp/1597494224/ref=pd_sim_b_3
A must have period. So I will quote someone to avoid re-writing a book-long response: "
the chapters on Registry Analysis, File Analysis, Executable Analysis, and Rootkit Detection provide and build upon basic concepts that go beyond what is taught in beginning and intermediate computer forensics courses
"
--------
2) File System Forensic Analysis
http://www.amazon.com/System-Forensic-Analysis-Brian-Carrier/dp/0321268172/ref=pd_cp_b_3
I suggest reading Jose Nazario's description of this book on the Amazon page. Nuff said
--------
3) Computer Forensics Library Boxed Set
http://www.amazon.com/Computer-Forensics-Library-Boxed-Set/dp/0321525647/ref=pd_sim_b_14
Bejtlich, Dan Farmer, Wietse, Carrier - If you don't recognize these names, you're in the wrong industry
--------
4) The Official CHFI Study Guide
http://www.amazon.com/Official-CHFI-Study-Guide-312-49/dp/1597491977
It's EC-Council's exam. If they say the sky is green, you better answer the sky is green. No matter how wrong they may be. This book will contain the majority of content they'll put on the exam. Take note... There is knowing to pass the exam... And there is knowing for the sake of being an expert and understanding forensics as best as possible. I suggest getting the top three books listed and learning as much as you can from them. This includes either downloading trial software to run it, or finding replacements to accomplish the tasks.
Right now (this week to be exact) I had to go back and forth through using Mandiant's Memoryze, First Response, "First on Scene", RPIER, Red Curtain and a bucketload of other IR/Forensics tools to prep me for January. Do I *need* to... No. I *want* to because I need to understand how things flow/work and alternatives in the event I don't have a specific tool at my disposal. Will I always be able to use foremost or FTK? I can never say yes, so I need to be aware of processes, procedures and how to perform them in as many different methods as I can think of. Remember, any evidence I were to put forward would need to be repeatable.
Some test takers may say something to the tune of: "no money for the books, etc." and it's understandable. If you're on this site or any other site that's similar, books like these are an investment when used properly. So invest in yourself because I can guarantee you, its rare that you will find someone else who will
Anyhow, time to go home
Logged
http://www.infiltrated.net/mgz/puppylecter.jpg
ajohnson
Recruiters
Hero Member
Offline
Posts: 1057
aka dynamik
Re: CHFI EXAM
«
Reply #10 on:
September 01, 2010, 05:37:35 PM »
Sil, quit it. I already have more books than I know what to do with
Logged
WIP: GCFA |
www.infosiege.net
| @infosiege
The day you stop learning is the day you start becoming obsolete.
sil
Hero Member
Offline
Posts: 549
Re: CHFI EXAM
«
Reply #11 on:
September 01, 2010, 09:34:32 PM »
Quote from: dynamik on September 01, 2010, 05:37:35 PM
Sil, quit it. I already have more books than I know what to do with
The first three are seriously must have books... I may or may not have posted it here before. I buy a lot of books from BestBargainBooks.com I have zero affiliation with them other than the fact I'm a customer. I've bough Cisco Press books as low as .01 (seriously) so I can vouch for them being on point:
Computer Forensics : Computer Crime Scene Investigation - Vacca ... Another good book $6.63 ... Come on now, I spend more than that on coffee in a day
http://www.bestbargainbook.com/index.php?file=productdtl&iitemid=342948
Encase Computer Forensics The Official EnCE - If you use EnCase... $5.14
http://www.bestbargainbook.com/index.php?file=productdtl&iitemid=69185
Worth spending even $20 on some of the security books they have there
http://www.bestbargainbook.com/index.php?file=listproduct&icatid=259
Logged
http://www.infiltrated.net/mgz/puppylecter.jpg
ajohnson
Recruiters
Hero Member
Offline
Posts: 1057
aka dynamik
Re: CHFI EXAM
«
Reply #12 on:
September 01, 2010, 09:53:06 PM »
I'm just kidding. Those are already on my wish-list at Amazon.
I do shop the bargain sites, such as what you listed, half.com, Amazon's used selection. I often spend more on shipping ($3.99) than the book itself. That's why I have more books than what I know what to do with. Those are up next. I'm hitting up assembly and then moving on to Hacking: The Art of Exploitation and The Shellcoder's Handbook. I need to de-noob myself
Logged
WIP: GCFA |
www.infosiege.net
| @infosiege
The day you stop learning is the day you start becoming obsolete.
Silver535d
Newbie
Offline
Posts: 2
Re: CHFI EXAM
«
Reply #13 on:
October 13, 2010, 06:00:46 PM »
Hey,
I need some help/advice,
I am a System admin with a MCSE 2003,
I am looking for a new direction in my career and was interested in the IT security area.
I am thinking of doing ECSA/LPT (CEH combined) or CHFI courses.
Can any one answer my questions below?
1) Is the ECSA/LPT, CEH ,CHFI recognised by the industry?
2) Are they sort after qualifications?
3) Once certified will find jobs for these skills?
4) Will I need to have any knowledge in any programming languages?
5) Am I going down the right path?
6) Can any one explain what a Penetration Tester does (other than the basics)
7) Will being a certified Hacker have any negativity?
I appreciate it if any one has any real world expertise in theses area’s to give me a heads up please.
Thanks
Silver-535d
Logged
Pages: [
1
]
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
OSCP - Offensive Security Certified Professional
: Failed my first attempt at the OSCP exam
(94) by
azmatt
Programming
: Finished Python Course in Codecademy now what?
(11) by
securitian
Tools
: Social-Engineer Toolkit (SET) Version 5.0 “The Wild West” Released
(2) by
m0wgli
Malware
: EICAR?
(3) by
UKSecurityGuy
Advisories
: HTB23154: Multiple Vulnerabilities in Exponent CMS
(0) by
AndyP
Advisories
: HTB23153: Multiple Vulnerabilities in Jojo CMS
(0) by
AndyP
Advisories
: HTB23151: Cross-Site Request Forgery (CSRF) in UMI.CMS
(0) by
AndyP
Tutorials
: Need guidance
(8) by
r0ckm4n
OSCP - Offensive Security Certified Professional
: Class Scheduled 6/8 - Linux n00b
(7) by
Taemyks
OSCP - Offensive Security Certified Professional
: OSCP exam scheduled
(6) by
gbhat
Incident Response
: LinkedIn Forensics
(0) by
AFENTIS_Forensics
General Certification
: Red Team/Blue Team
(1) by
ajohnson
Career Central
: Starter cert?
(3) by
Grendel
Network Pen Testing
: Beginner Ethical Hacker
(1) by
m0wgli
General Certification
: CPT Practical Submission
(0) by
z28power4u
Web Applications
: Nessus and Nikto
(4) by
Seen
Network Pen Testing
: Cracking salted MD5 hash
(4) by
n37sh@rk
CEH - Certified Ethical Hacker
: Passed my C|EH
(3) by
n37sh@rk
Mass Media
: EC-council hacked, irony at his best?
(0) by
j0rDy
Web Applications
: SQL Injection into an INSERT statement.
(6) by
eyenit0
Network Pen Testing
: Solution for sipXtapi INVITE Message CSeq Field Header Remote Overflow
(1) by
m0wgli
Web Applications
: dns
(2) by
H1t M0nk3y
Other
: BSides Boston
(0) by
3xban
Career Central
: InfoSec in Central, FL
(2) by
tturner
Web Applications
: Web vulnerability scanner
(4) by
H1t M0nk3y
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.