Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 33 guests online
 
Advertisement

You are here: Home arrow Ethical Hacking Discussions and Related Certificationsarrow Network Pen Testingarrow need some help with BT5r1/2
EH-Net
May 21, 2013, 05:17:53 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: need some help with BT5r1/2  (Read 2008 times)
0 Members and 1 Guest are viewing this topic.
lahp
Newbie
*
Offline Offline

Posts: 3


View Profile
« on: March 30, 2012, 11:57:27 AM »

Hi all I need some help with some tools I am new to hacking and can hack WIFI but so far thats about it ... I wish to webhack and network hack (I have permission from companies to do so) and was wondering what tools from BT5 I should use and if there are any guides for using them Smiley ta!
Logged
BillV
Hero Member
*****
Offline Offline

Posts: 1892


View Profile WWW
« Reply #1 on: March 30, 2012, 12:02:59 PM »

Welcome to EH-Net.

BackTrack is pretty well organized in that you can look through the menu or sift through the directories to find both 'network' and 'web' attack tools.

We can help you once you have specific questions.

You may want to take a look at these two sites:
BackTrack Forums
BackTrack Wiki

You may also have an interest in this:
Samurai WTF (Web Testing Framework)
Logged
lahp
Newbie
*
Offline Offline

Posts: 3


View Profile
« Reply #2 on: March 30, 2012, 12:12:30 PM »

Welcome to EH-Net.

BackTrack is pretty well organized in that you can look through the menu or sift through the directories to find both 'network' and 'web' attack tools.

We can help you once you have specific questions.

You may want to take a look at these two sites:
BackTrack Forums
BackTrack Wiki

You may also have an interest in this:
Samurai WTF (Web Testing Framework)

Thank you for your reply,

I have previously looked through the tools but sadly I do not know how to use them, this was really the main question what one is most suggested and maybe a list of commands to go with it? or a video?
Logged
chrisj
Hero Member
*****
Offline Offline

Posts: 1163


View Profile WWW
« Reply #3 on: March 30, 2012, 12:20:34 PM »

get the book "the basics of hacking and penetration testing" it'll get you started. will give you an idea of not only what tools to use to do it, but a good way to go about it. at under 150 pages it shouldn't take you long.
Logged

OSWP, Sec+
unicityd
Full Member
***
Offline Offline

Posts: 156

Bored IT Manager, Crypto Nerd


View Profile WWW
« Reply #4 on: March 30, 2012, 12:36:29 PM »

You say that you have permission from others to hack/pen-test their sites yet you have no idea how to do so.  I strongly suggest setting up a home lab, reading some books/articles, playing with the tools and trying to figure out what you are doing before you play with someone else's network.  Without understanding what you are doing, you won't be able to produce anything of value for your target and you may inadvertently break something because you didn't understand the consequences of a tool (e.g. an exploit that kills the targeted service).  If you can practice/learn at home, read books, maybe take a training class or two, you may be able to work your way into a junior position where you can carry out actual penetration testing under the watchful eye of more senior people who can provide some guidance.  Are you working in IT now?  Does your company have a security department or security staff?

There is no specific tool that you use for hacking/pen-testing.  It's all about context.  You'll use different tools depending on whether the target is a specific system/web app or an enterprise network.  You'll probably have some favorite tools for various common tasks (e.g. nmap for port scanning), but you'll need to know which tools to use depending on what you find.  What services can you access?  What versions?  What is the underlying OS?  Can you connect directly to your target or do you have to gain a foothold on another system first?  The number of questions/variables that will come up is infinite.  The more you know and the more experience you have, the better prepared you will be to find the answers.

If you want a book on hacking, try Hacking Exposed, Counter Hack, or Professional Pen Testing Vol. I.  For web applications, the Web Application Hackers Handbook is very good.  I have the 2nd edition, but a new one came out recently.   Heck, read everything you can get your hands on. 

You should also check out this guide by Sil, another member of this site:

http://www.infiltrated.net/pentesting101.html

Do everything Sil says in his tutorial.  Plan to learn networking, programming, and how to manage Windows and one or more variants of Unix/Linux.

Learning a couple of tricks to hack into undefended sites is easy, but if you want to operate at a high level you need to understand networking, system administration, and some programming in addition to understanding a wide variety of security tools and the concepts behind them.  You'll have to move beyond using canned tools to building your own and, especially with web apps, learning to find new vulnerabilities and exploit them.
Logged

BS in IT, CISSP, MS in IS Management (in progress)
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.114 seconds with 23 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Free Business and Tech Magazines and eBooks

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.