Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 48 guests online
You are here:
Home
EH-Net
News Items and General Discussion About EH-Net
Advice for the beginner
EH-Net
May 25, 2013, 04:23:42 AM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
EH-Net
>
News Items and General Discussion About EH-Net
(Moderator:
don
) >
Advice for the beginner
Pages: [
1
]
Go Down
« previous
next »
Print
Author
Topic: Advice for the beginner (Read 6348 times)
0 Members and 1 Guest are viewing this topic.
Kev
Guest
Advice for the beginner
«
on:
July 27, 2006, 04:24:34 PM »
A long, long time ago in a far away galaxy script kiddies were people who couldn’t write their own programs and had to use other peoples programs. Now with the complexity of everything, I don’t know of a hacker that doesn’t use a program or exploit that someone else has written at least on some occasion. So I guess that makes us all script kiddies on some level. Today I believe that term is used more for people that use programs or exploits that they have no clue at all as to how it works. Go to the Defcon event in Vegas and you will run into a lot of teenagers that don’t know what a port is really. They know its something that should be open and that’s about it. That’s not to say there are some very knowledgeable people there, but they do have their fair share of script kiddies.
My advice to anyone just getting into all this is, learn TCP/IP. I mean really learn it very well. Don’t just memorize the stack protocols but see if you can actually visualize the entire process in your mind’s eye. Understand how the software works with the hardware to move a frame and how all this works together in a network. This will pay off dividends later when working with tools, etc... Even a book like TCP/IP for Dummies is really not a bad place to start, but dont let it end there. This would be my basic advice to a beginner and I promise they will not be disappointed later down the road.
«
Last Edit: July 27, 2006, 05:01:25 PM by Kev
»
Logged
don
Editor-In-Chief
Administrator
Hero Member
Offline
Posts: 4169
Editor-In-Chief
Re: Advice for the beginner
«
Reply #1 on:
July 28, 2006, 12:13:58 AM »
I agree and apparently so do the authors of books on the topic. Both Ed Skoudis' book
Counter Hack Reloaded
and Michael Gregg's book
CEH: Exam Prep
both have in depth coverage of TCP/IP. In fact, you can read that specific chapter of Gregg's book here on this site by clicking the title link.
Your suggestion of being able to visualize the packet flow is a great one. Did you get a chance to look at the animation video I posted on the travles of a packet named
Warriors of the Net
?
Whether it is looking at Snort or firewall logs to figure out what has happened, doing real time analysis using Wireshark or scanning using Nmap, a good understanding of TCP/IP is crucial.
Don
PS - Hey Kev, you're making a nice push for the Free Monthly Giveaway. Keep up the good work.
Logged
CISSP, MCSE, CSTA, Security+ SME
Kev
Guest
Re: Advice for the beginner
«
Reply #2 on:
July 28, 2006, 10:03:08 AM »
Hey thanks. Yes, a friend sent that to me a while back and that’s a great little animation. Everyone should take a few moments and watch it
Logged
LSOChris
Guest
Re: Advice for the beginner
«
Reply #3 on:
July 29, 2006, 12:13:18 PM »
being able to fix the broken exploit code (or code in genreal) people post on the net is good skill to have. if you are waiting for other people to create the .exe for you, you will be well behind the bad guys...
Logged
Kev
Guest
Re: Advice for the beginner
«
Reply #4 on:
July 29, 2006, 02:46:40 PM »
Yes being able to repair the exploit code posted on the net is an important skill. Some people post code with intentional errors to mess up script kiddies. Those errors are usually small ones like a missing } or something commented out that should not be.
Logged
nebu10uz
Sr. Member
Offline
Posts: 368
Re: Advice for the beginner
«
Reply #5 on:
August 16, 2006, 11:34:25 PM »
I always advice newbies to first read TCP/IP JumpStart: Internet Protocol Basics by Andrew G. Blank. This book explains the basic in an understandable writing which also includes illustration. It's easier for novice to grasp the concept after reading this book. From there, then you should read a book thats more comprehensive and deep in to details of the protocols, such as what we IT professional consider the bible of TCP/IP, The Protocols (TCP/IP Illustrated, Volume 1) by W. Richard Stevens. This book is a bit outdated and ones should also consider other resources with updated information, however this book explains the foundation of TCP/IP.
Logged
Security+, OSCP, CEH
jimbob
Guest
Re: Advice for the beginner
«
Reply #6 on:
August 17, 2006, 03:41:58 AM »
TCP and IP seem to go hand in hand in most literature, does anyone know if there are texts teaching SCTP/IP or SCTP/IPv6? You never know, in the future this could be the book that gets recommended to newbs if SCTP ever catches on. I know squat about SCTP so any recommendations would be welcomed.
Jim
Logged
Pages: [
1
]
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
News Items and General Discussion About EH-Net
: Change is Coming to EH-Net!!
(30) by
don
Tools
: Symbolic Exploit Assistant project is looking for collaborators
(0) by
galapag0
Greetings
: Hi from the UK
(5) by
prats84
GCIH - GIAC Certified Incident Handler
: Passed my GCIH
(9) by
prats84
Network Pen Testing
: Want a challenge? Want a GXPN practice exam?
(0) by
ajohnson
GCIH - GIAC Certified Incident Handler
: GCIH Free Practice test attempt
(1) by
prats84
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.