Image
 
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 25 guests and 1 member online
EH-Net Donations

Enter Amount:
$

Google Ads
EH-Net News Feeds
Latest Additions
Book Recommendations





 
Advertisement

You are here: Home arrow Forum arrow EH-Netarrow News Items and General Discussion About EH-Netarrow New Here
Ethical Hacker Community Forums
November 22, 2008, 07:54:04 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: ChicagoCon 2-Day Ethical Hacking Conference with MS Blue Hats Oct 31 - Nov 1. Tickets Only $100! www.chicagocon.com/content/view/103/51/
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: New Here  (Read 2493 times)
0 Members and 1 Guest are viewing this topic.
shawn
Newbie
*
Offline Offline

Posts: 15



View Profile
« on: January 08, 2007, 01:37:36 PM »

Wanted to let you all know how informative and educational your posts on this site are.  I have been browsing the forum for a few months and wanted to introduce myself.  I have been involved in pentesting for a few years, working with small to medium sized financial and medical firms.  Hope I can contribute to this forum in some way to help others with my experiences and knowledge gained along the way.  Keep up the good work and excellent job to all on this forum.
Logged

CEH, CCNA, Security+
don
Editor-In-Chief
Administrator
Hero Member
*****
Offline Offline

Posts: 2347


Editor-In-Chief


View Profile WWW
« Reply #1 on: January 08, 2007, 02:23:23 PM »

Welcome and we look forward to your participation. It's great to have someone with actual pen testing experience contributing to the conversation.

To start, how about sharing with us a little more detail (as much as you can) about what it is you do, the tools you use, wild experiences, etc.

Thanks for coming out of the shadows,
Don
Logged

CISSP, MCSE, CEH, Security+ SME
ChrisG
EH-Net Columnist
Hero Member
*****
Offline Offline

Posts: 1038


View Profile WWW
« Reply #2 on: January 08, 2007, 03:07:48 PM »

welcome!

i know i am always interested on how to land pen-testing type employment if you have time to go into that.

Chris
Logged

...tests i took go here...

http://carnal0wnage.blogspot.com/
Kev
Guest
« Reply #3 on: January 08, 2007, 03:28:22 PM »

Welcome aboard! Sounds like we are involved with similar clients.  It might be fun to compare notes.
Logged
shawn
Newbie
*
Offline Offline

Posts: 15



View Profile
« Reply #4 on: January 08, 2007, 05:19:12 PM »

Thank you all for your reply.  We do pen testing and IT auditing for Financial Institutions and Medical Firms for compliance to HIPPA and FFIEC regulations that recommend them to have internal and external penetration testing by a third party organization.  Most of our clients are small to medium sized community banks or credit unions.  We established or secuirty consulting roughly 2 or 3 years back as kind of a spin off of our normal core business.  We are lucky enough to offer other products to our customers which already gives us a foot in the door, and what I believe to be the biggest factor in selling consulting services to our customers which is trust.  Since we started we have found that the bulk of our work is now coming from word of mouth and repeat business from previous clients that we have done testing for which is the core to being sucessful in this industry.  As far as tools that we use:

Port Scanners - nmap, solarwinds (used for multiple purposes), hping
Firewall Testing - nmap, hping, firewalk
Scanners - Nessus, GFI Languard, Sara
Web Application Scanner - Web Inspect, Nikto
Password - Cain, John, Rainbow Tables, Sam Inside
Brute Force - Hydra, Brutus, tsgrinder, tscrack,
Sniffer - tcpdump, wireshark/ethereal, Network General Sniffer Pro
Wireless - Kismet, NetStumbler, Aircrack suite of tools for cracking WEP etc...
Exploit Tools - Metasploit, CANVAS, for bigger jobs we will buy a consulting license of Core but the majority of them we do not due to cost.
Bootable Linux - BackTrack

I am sure I missed some but the above is what I would call the core tools that we use.  Of course there are several others that we use in different situations as well as manual methods of compromising systems without running automated tools.

And the best tool of all "Google".  Just kidding but I have found in my researching that there is an unlimited amount of information out there and if someone looks hard enough they can normally find anything they want if they are patient. 

ChrisG -
We are always looking to hook up with other people to contract out services to.  Unfortunatley where we are located we lose out on alot of work due to travel expenses for us to get to the location.  We have tried to form partnerships with other companies that have consultants across the US but they all charge for the name, and alot of the smaller banks are tightly budgeted and wont spend the money to have a big consulting firm come in.

Kev -
I would be happy to share compare notes with you.  Always interested in learning more and from reading the forums there are alot of really talented people here.

Thanks
Logged

CEH, CCNA, Security+
slimjim100
EH-Net Columnist
Sr. Member
*****
Offline Offline

Posts: 363



View Profile WWW
« Reply #5 on: January 08, 2007, 08:25:55 PM »

Welcome aborad Shawn!

Brian
AKA Slimjim100
Logged

CISSP, CCSE, CCNA, CCAI, Network+, Security+, JNCIA, & MCP
shawn
Newbie
*
Offline Offline

Posts: 15



View Profile
« Reply #6 on: January 09, 2007, 07:54:33 AM »

Thanks slimjim
Logged

CEH, CCNA, Security+
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.7 | SMF © 2006-2008, Simple Machines LLC
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.887 seconds with 24 queries.
 
Sponsors

cwnp_moto__120x90.gif

Polls
During the most recent election, I:
 
Support EH-Net


Support EH-Net by
Buying all of your
Amazon items using
the search bar above.

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!
Recent Forum Topics
Vote For EH-Net

progenic.com
Click here to Vote!

Sadikhov.com
Top IT Cert Sites

binarica.com
Binarica Logo

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2008 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.