Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 68 guests and 2 members online
Free Business and Tech Magazines and eBooks
You are here:
Home
Ethical Hacking Discussions and Related Certifications
Network Pen Testing
Web Hackers Handbook labs?
EH-Net
May 19, 2013, 01:44:39 AM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Ethical Hacking Discussions and Related Certifications
>
Network Pen Testing
(Moderator:
don
) >
Web Hackers Handbook labs?
Pages: [
1
]
2
3
Go Down
« previous
next »
Print
Author
Topic: Web Hackers Handbook labs? (Read 20307 times)
0 Members and 1 Guest are viewing this topic.
Sinco98
Newbie
Offline
Posts: 5
Web Hackers Handbook labs?
«
on:
December 14, 2011, 02:54:00 AM »
I am wondering if anyone has used the web hackers handbook labs from mdsec.net
Logged
millwalll
Guest
Re: Web Hackers Handbook labs?
«
Reply #1 on:
December 14, 2011, 03:49:06 AM »
Hi
No I have the book but I think the labs are too expensive when there are ways to test for free like webgoat,DVWA so on..
If the labs were a one off payment for a certain amount of time like $50 for a month then I would be more tempted to use them.
Logged
Sinco98
Newbie
Offline
Posts: 5
Re: Web Hackers Handbook labs?
«
Reply #2 on:
December 14, 2011, 05:00:06 AM »
yes that was my thinking $7 an hour (£5) seems to bit expensive when like you stated DVWA is available.
Thanks,
Logged
millwalll
Guest
Re: Web Hackers Handbook labs?
«
Reply #3 on:
December 14, 2011, 05:57:41 AM »
yah don't get me wrong I sure there labs are amazing and I sure they making lots money from companies who can afford $7 an hour but for someone new to the industry trying to work you way in with no money it just crazy
Logged
alucian
Full Member
Offline
Posts: 225
Re: Web Hackers Handbook labs?
«
Reply #4 on:
December 14, 2011, 08:28:03 AM »
I plan to buy 10 hours of lab time. I know that thery are expensive compared to eLS or even OS*P. But, the best way of learning is by studying and doing.
In my opinion, if someone will go through the most of the labs he will be extremelly skilled. Also, consider the fact that the book is about 40$ plus 100 hours lab time is 740$. A lot, but a SANS course is more than 3000$.
I did SANS GWAPT, eLS and I have the book. Soon I will do a comparison between them.
I also think that paying by the hour will make you sweat more.
Consider the following analogy: having a girfriend (pay monthly access) and "renting" a wh*re by the hour. In which case will you "give your best" and want the best ROI??
Logged
CISSP ISSAP, CISM/A, GWAPT, GCIH, eCPPT, OSWP
hayabusa
Hero Member
Offline
Posts: 1630
Re: Web Hackers Handbook labs?
«
Reply #5 on:
December 14, 2011, 09:10:24 AM »
<grin> That's quite the analogy, alucian!
Logged
~ hayabusa ~
"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'
OSCE, OSCP , GPEN, C|EH
millwalll
Guest
Re: Web Hackers Handbook labs?
«
Reply #6 on:
December 14, 2011, 09:17:58 AM »
That is fair comment and yes compared to most courses run by sans its really good value. I personally would rather read the book use free alternatives and the money I save by not going into the labs spend on another course that would help me develop in another area.
I guess if you want to be amazing at web apps then spending the money on it like a course would be beneficial.
Logged
Sinco98
Newbie
Offline
Posts: 5
Re: Web Hackers Handbook labs?
«
Reply #7 on:
December 15, 2011, 02:54:22 AM »
I suppose there is one good thing about it. You can follow it through with the book and all the examples in the book are relevant to the prac on the website.
Logged
millwalll
Guest
Re: Web Hackers Handbook labs?
«
Reply #8 on:
December 15, 2011, 04:23:14 AM »
Yah I think if you just wanted to learn web apps then may you could do it as course buy the book spend rest on the labs but more pen tester have to be skilled in many area I personally would buy the book use the free apps then spend other money on networking security course.
Logged
alucian
Full Member
Offline
Posts: 225
Re: Web Hackers Handbook labs?
«
Reply #9 on:
December 15, 2011, 08:14:46 AM »
@Jamie
I think that you are wrong. For example you have the chapter about session management and how to test the tokens. Then you have three labs where you can practice. Like this you'll apply what you've just read, and you'll better understand and remember.
I plan to do at least a lab from each category. If I a do OK I'll move on, otherwise I'll do another one.
If you'll read the book, and then read one about network secutiry, then wireless... you'll be cabbage. Honestly.
At the beggining I was upset about the fact that they only give hourly access (I still think that it is too expensive). But, for lazy guys like me this will be a motivation to really use that hour.
I think that they are loosing money by putting a price so high on the lab. It is like the horses you can find in the malls. I will not pay 1$ for my kids to play 2 minutes, but I will pay 50 cents (maybe I will have them play 3 times).
I will keep you informed about the quality of the labs.
Logged
CISSP ISSAP, CISM/A, GWAPT, GCIH, eCPPT, OSWP
millwalll
Guest
Re: Web Hackers Handbook labs?
«
Reply #10 on:
December 15, 2011, 10:28:22 AM »
I agree with you that the price and book make sense if you look at it as a course. However IMO I would not pay for the labs as I think there are lots of free alternatives where you can practice most if not all the vulnerabilities in the book.
And I think one best way to lean web security is to build your own web applications and then break them.
IMO I think the price is too high and I think they would make more if it was more affordable.
Logged
Seen
Full Member
Offline
Posts: 134
Re: Web Hackers Handbook labs?
«
Reply #11 on:
December 16, 2011, 08:30:20 AM »
Has anyone gone through all the Coliseum labs for elearnsecurity? How do those compare? Are there any other online labs that are perhaps a better value than the WAHH ones?
Logged
Sec+, eCPPT
lorddicranius
Sr. Member
Offline
Posts: 447
Re: Web Hackers Handbook labs?
«
Reply #12 on:
December 16, 2011, 09:22:20 AM »
I thought the eLS Coliseum Labs were great. They really helped me learn and remember the techniques that were taught during the course, and actually seeing what happens when you exploit a vuln helped a lot as well. The stories that went along with each battle made it fun too.
I haven't done the WAHH labs though, so I can't compare the two. But I can say that the eLS Labs are definitely worth it.
eLS = $99 for a month access
WAHH - At $7/hr, 2 hours a night, you'll get to $98 spent by the end of one week.
Logged
GSEC, eCPPT, Sec+
Seen
Full Member
Offline
Posts: 134
Re: Web Hackers Handbook labs?
«
Reply #13 on:
December 16, 2011, 01:16:47 PM »
I think there were 10-20 eLS labs when I went through it during my course, I was just wondering how many there are now if anyone knows.
Logged
Sec+, eCPPT
Seen
Full Member
Offline
Posts: 134
Re: Web Hackers Handbook labs?
«
Reply #14 on:
December 16, 2011, 01:20:53 PM »
Never mind, I found a description on the website, looks to be a few new labs from when I did it.
Logged
Sec+, eCPPT
Pages: [
1
]
2
3
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
General Certification
: CPT Practical Submission
(0) by
z28power4u
OSCP - Offensive Security Certified Professional
: Class Scheduled 6/8 - Linux n00b
(5) by
MrTuxracer
Career Central
: Starter cert?
(0) by
Alert
Web Applications
: Nessus and Nikto
(4) by
Seen
Tutorials
: Need guidance
(7) by
impelse
Malware
: EICAR?
(2) by
SephStorm
Network Pen Testing
: Cracking salted MD5 hash
(4) by
n37sh@rk
CEH - Certified Ethical Hacker
: Passed my C|EH
(3) by
n37sh@rk
Mass Media
: EC-council hacked, irony at his best?
(0) by
j0rDy
Web Applications
: SQL Injection into an INSERT statement.
(6) by
eyenit0
Network Pen Testing
: Solution for sipXtapi INVITE Message CSeq Field Header Remote Overflow
(1) by
m0wgli
Web Applications
: dns
(2) by
H1t M0nk3y
Other
: BSides Boston
(0) by
3xban
Career Central
: InfoSec in Central, FL
(2) by
tturner
Web Applications
: Web vulnerability scanner
(4) by
H1t M0nk3y
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.