Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 41 guests online
You are here:
Home
Ethical Hacking Discussions and Related Certifications
Network Pen Testing
Security related projects
EH-Net
May 20, 2013, 10:58:40 AM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Ethical Hacking Discussions and Related Certifications
>
Network Pen Testing
(Moderator:
don
) >
Security related projects
Pages: [
1
]
Go Down
« previous
next »
Print
Author
Topic: Security related projects (Read 8075 times)
0 Members and 1 Guest are viewing this topic.
yatz
Full Member
Offline
Posts: 222
Security related projects
«
on:
July 13, 2010, 03:49:46 PM »
I need to come up with some projects for the 2010-2011 year. The projects should be something with a scope of a few months. I will research/deploy/test/etc. some kind of technology or process that benefits the company.
Anyone got any ideas??? Maybe something fun you have done in the past?
Logged
"Live as though you would die tomorrow, learn as though you would live forever."
CCNA, MCSA, MCTS, Sec+, Net+, Linux+, CEH
ziggy_567
Sr. Member
Offline
Posts: 361
Re: Security related projects
«
Reply #1 on:
July 13, 2010, 04:40:29 PM »
What type of projects? i.e. what is your role?
Logged
--
Ziggy
eCPPT - GSEC - GCIH - GCUX - RHCE - SCSecA - Security+ - Network+
partek
Newbie
Offline
Posts: 27
Re: Security related projects
«
Reply #2 on:
July 13, 2010, 11:00:22 PM »
Quote from: yatz on July 13, 2010, 03:49:46 PM
I need to come up with some projects for the 2010-2011 year. The projects should be something with a scope of a few months. I will research/deploy/test/etc. some kind of technology or process that benefits the company.
Anyone got any ideas??? Maybe something fun you have done in the past?
Unfortunately as fun as it may be you can't implement security for the sake of security. There needs to be a valid business need to for any sort of security project. You should look for a problem to solve, and find ways to solve it. Look around and ask around, chances are if you're like a normal company there are an embarassingly large number of problems that need to solved. Once you have the problems identified, then you can come up with the projects in order to solve them.
Logged
CISSP, CISM, CISA, CCNA Security, OSCP, CEH
ajohnson
Recruiters
Hero Member
Offline
Posts: 1057
aka dynamik
Re: Security related projects
«
Reply #3 on:
July 14, 2010, 08:49:26 AM »
It sounds like he's just looking for projects for personal study. It'll be difficult to recommend things without knowing your interests.
If you're bored, why don't you start a blog and see what direction that takes you in?
Logged
WIP: GCFA |
www.infosiege.net
| @infosiege
The day you stop learning is the day you start becoming obsolete.
yatz
Full Member
Offline
Posts: 222
Re: Enjoyable projects
«
Reply #4 on:
July 14, 2010, 08:59:42 AM »
Thanks for the replies, and yes I know it needs to be decided by business need. Thankfully I'm allowed some latitude in my choice of projects as long as I can show a business impact.
In this case, let me rephrase the question:
What do you do on a daily/weekly/monthly basis that you enjoy?
(Maybe I can use some of the ideas to see how they fit my environment, something that I hadn't yet know that needed to be done.)
Logged
"Live as though you would die tomorrow, learn as though you would live forever."
CCNA, MCSA, MCTS, Sec+, Net+, Linux+, CEH
yatz
Full Member
Offline
Posts: 222
Re: Security related projects
«
Reply #5 on:
July 14, 2010, 09:09:11 AM »
Quote from: ziggy_567 on July 13, 2010, 04:40:29 PM
What type of projects? i.e. what is your role?
My role is officially Network Technician, but I play more of a System Administrator role.
Quote from: dynamik on July 14, 2010, 08:49:26 AM
It'll be difficult to recommend things without knowing your interests.
My interests are all over the board. I enjoy programming/scripting, hardware, vulnerability research and exploitation, and so on. Maybe I sound like every other security enthusiast out there.
Quote from: dynamik on July 14, 2010, 08:49:26 AM
It sounds like he's just looking for projects for personal study.
The best projects are those you would do on your free time and get paid for.
I really get a great feeling when I'm learning a new tool and can see the practical uses of it. Just yesterday I was watching a webcast that demo'd a tool called SAPD that extracts passwords for accounts running services. Well, I ran into a problem not too long ago where I didn't have the password for a service documented and then needed it. If I'd have had this tool back then I wouldn't have had to reset the password and pray nothing else would be affected.
From what I hear, the CEH courseware deals heavily with tool familiarity, so I'm looking forward to studying for that.
Anyway, if the question is still too vague, I understand. I will need to think of something and I wanted to do something fun that I have not done before.
«
Last Edit: July 14, 2010, 09:10:44 AM by yatz
»
Logged
"Live as though you would die tomorrow, learn as though you would live forever."
CCNA, MCSA, MCTS, Sec+, Net+, Linux+, CEH
ziggy_567
Sr. Member
Offline
Posts: 361
Re: Security related projects
«
Reply #6 on:
July 14, 2010, 09:28:33 AM »
From a Systems Administration standpoint two projects that I've worked on recently that were a lot of fun (and fairly inexpensive) were setting up OSSEC on our PCI segment and Splunk/Syslog-ng SIEM implementation.
If you're not doing log aggregation and monitoring, this can be a huge "quick win." Not only is log monitoring incredibly important for security, it will make misconfigurations glaringly obvious most of the time! Not only will the Security folks be happy, but Operations will get on-board with the project if you can show them how useful a tool it is...
Good luck!
Logged
--
Ziggy
eCPPT - GSEC - GCIH - GCUX - RHCE - SCSecA - Security+ - Network+
don
Editor-In-Chief
Administrator
Hero Member
Offline
Posts: 4165
Editor-In-Chief
Re: Security related projects
«
Reply #7 on:
July 14, 2010, 10:57:35 AM »
If you're a system admin & it's a MS shop, might be a great time to learn powershell.
Don
Logged
CISSP, MCSE, CSTA, Security+ SME
chrisj
Hero Member
Online
Posts: 1163
Re: Security related projects
«
Reply #8 on:
July 14, 2010, 11:41:14 AM »
I have to agree with Ziggy_567
Centralized syslog server or a dedicated syslog server per site based on inter-office interconnectivity (I have small pipes I don't want to flood with udp syslog traffic). I prefer syslog, rsyslog and syslog-ng.
Network monitoring tools, like Nagios (if you're not monitoring already).
I'm building new network monitoring boxes:
OS - Debian
Nagios
Bandwidthd
rsyslogd
ntop
wireshark (for packet monitoring)
Things I've done in the past.
Something else, depending on your firewall / network design a Proxy server would be nice. My ASA can use WCCC (I think that's the protocol) to check with Squid to allow traffic or not.
There is some fun scripting you can do with log files. I have one log file that's just for my firewall logs. I have a couple of nice scripts that check for policy violations.
You could also write a few scripts looking for multimedia (music and movies), on network drives, or peoples desktops if you have the right permissions.
Logged
OSWP, Sec+
chrisj
Hero Member
Online
Posts: 1163
Re: Security related projects
«
Reply #9 on:
July 14, 2010, 02:01:06 PM »
thought of something else. If those tool are in place already, audit them to make sure they're doing what everyone thinks they should be doing.
Logged
OSWP, Sec+
sil
Hero Member
Offline
Posts: 549
Re: Security related projects
«
Reply #10 on:
July 14, 2010, 09:04:37 PM »
I had to undergo a SIGv5 audit for AT&T recently so I took up a project on my own accord to keep us compliant well after the fact. The tasks consisted of a semi-automated pentesting platform to do two things... Perform a quarterly pentest from the outside scope, perform one from the inside scope, correlate all the data, then slap that data into OSSIM. The images were created from scratch using VMWare and a slew of tools. CANVAS, Metasploit, RRDTool (for graphing on my own), Acunetix and W3AF with a push/pull custom configuration I update daily. Horribly butchered in a shell script using expect. For applications we develop, Klockwork and beStorm ... Wish I had Codenomicon, but they won't let me purchase it.
The initial configuration and parameters for testing get tweaked, uploaded to a server and both the "outside scope" and "inside scope" server downloads the parameters and fires away the tests. Now be advised, all my parameters are usually set to cover/stealth/decoys so it is as real as an attack as I can perform. My network admins were not told the entire gist of this (management is aware) so we get to test incident response (whose gonna contact the security team of the issues). Initially I thought about vanilla Nessus for auditing, but metasploit using a modified (targeted) autopwn works wonders. CANVAS usually mops up the place for anything unique...
The goal... Give my company a realistic view of the low to mid level hanging fruit and lock it down. Provide reporting on a quarterly basis for the powers that be, backup and log all information across syslog for future parsing. Backup and copy over tcpdump output for Netwitness analysis. Since we're trying to be on point, my goal was super simple... "I will hack my own company on a quarterly basis... I know what we use, I know the strengths and weaknesses... I could create a super focused attack..." As it stands... I could "social engineer" individuals in my company from time to time, but that's severly flawed... Most people are paranoid about the things I do with my testing let alone what someone else sends. OSSIM? Gathers up the aftermath of the testing, stores event data in which I can go back and clean up the false positives and false negatives.
Lastly, every week or two I try to create a new "By the way..." notice on security to send to colleagues in order to make them aware of attacks. Why people attack and what are they after. Many of my colleagues now get it, but that's because I've found so many analogies outside of technology to correlate attack situations to. It's also helped that media now reports anything and its mother so to my colleagues (especially in this economy) the last thing anyone wants to think about it "getting owned"
Anyhow, my project was a large undertaking, but think about it for a minute. If you work in a company that needs to meet certain compliance levels, its a mechanism to implement a "red team" on demand. One would seriously have to keep in tune with what's going on in order to update the scripts, tools used, etc., and vigilance is ALWAYS key. My other project I still tinker with is a VoIP based IPS made from scratch. I can randomly assign it to push people into a honeypot, etc...
Logged
http://www.infiltrated.net/mgz/puppylecter.jpg
yatz
Full Member
Offline
Posts: 222
Re: Security related projects
«
Reply #11 on:
July 16, 2010, 09:51:04 AM »
I appreciate the input everyone!
Log file management, automated pentesting and reporting, network monitoring box, really good!!! I have looked into powershell and used it for a few things, though to make it a project for next year I'd have to find out some purpose to it.
Any more ideas are appreciated, but these definitely are a good start. Typically I'll have to come up with 4-5 things for a given year, which consist of a combination of my ideas and those of my supervisor. The more I come up with the better.
Logged
"Live as though you would die tomorrow, learn as though you would live forever."
CCNA, MCSA, MCTS, Sec+, Net+, Linux+, CEH
Pages: [
1
]
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
OSCP - Offensive Security Certified Professional
: Failed my first attempt at the OSCP exam
(91) by
r0ckm4n
Tools
: Social-Engineer Toolkit (SET) Version 5.0 “The Wild West” Released
(2) by
m0wgli
Malware
: EICAR?
(3) by
UKSecurityGuy
Advisories
: HTB23154: Multiple Vulnerabilities in Exponent CMS
(0) by
AndyP
Advisories
: HTB23153: Multiple Vulnerabilities in Jojo CMS
(0) by
AndyP
Advisories
: HTB23151: Cross-Site Request Forgery (CSRF) in UMI.CMS
(0) by
AndyP
Tutorials
: Need guidance
(8) by
r0ckm4n
OSCP - Offensive Security Certified Professional
: Class Scheduled 6/8 - Linux n00b
(7) by
Taemyks
OSCP - Offensive Security Certified Professional
: OSCP exam scheduled
(6) by
gbhat
Incident Response
: LinkedIn Forensics
(0) by
AFENTIS_Forensics
General Certification
: Red Team/Blue Team
(1) by
ajohnson
Career Central
: Starter cert?
(3) by
Grendel
Network Pen Testing
: Beginner Ethical Hacker
(1) by
m0wgli
General Certification
: CPT Practical Submission
(0) by
z28power4u
Web Applications
: Nessus and Nikto
(4) by
Seen
Network Pen Testing
: Cracking salted MD5 hash
(4) by
n37sh@rk
CEH - Certified Ethical Hacker
: Passed my C|EH
(3) by
n37sh@rk
Mass Media
: EC-council hacked, irony at his best?
(0) by
j0rDy
Web Applications
: SQL Injection into an INSERT statement.
(6) by
eyenit0
Network Pen Testing
: Solution for sipXtapi INVITE Message CSeq Field Header Remote Overflow
(1) by
m0wgli
Web Applications
: dns
(2) by
H1t M0nk3y
Other
: BSides Boston
(0) by
3xban
Career Central
: InfoSec in Central, FL
(2) by
tturner
Web Applications
: Web vulnerability scanner
(4) by
H1t M0nk3y
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.