|
fred
|
 |
« on: May 23, 2012, 03:25:08 PM » |
|
Hello my freinds i really love this forum becuase i alway got useful info here and thank you all.
frist of all, i wanna say im not new in hacking world i had some pentest experience i can use back track metasploit and many other tools and im familiar with many concepts and so on.
But as im addicted to hack!!!! i wanna start studying it so seriously and i know i must build a hacking lab so i bought VMware Workstation 8 (i know i can use Virtual box for free but i love Vmware its better) and i download Backtrack 5 R2 Gnome i installed to A VM and a windows Xp VM also so do i need anything more for my lab?
i need some hacking scenario for exercises i googled it but i couldnt find some efficient scenarios dose anybody has them?
Thanks again Take care!!
|
|
|
|
|
Logged
|
ICS Academy Network Security Certified
|
|
|
|
sil
|
 |
« Reply #1 on: May 23, 2012, 04:18:04 PM » |
|
|
|
|
|
|
Logged
|
|
|
|
|
fred
|
 |
« Reply #2 on: May 24, 2012, 07:52:03 AM » |
|
ok thankx and what about my hacking lab is it efficient?
|
|
|
|
|
Logged
|
ICS Academy Network Security Certified
|
|
|
|
magxtopher
|
 |
« Reply #3 on: May 24, 2012, 07:55:20 AM » |
|
Thanks.Great blog all newbies or serious security guru's shd read the link. Cool mate.
|
|
|
|
|
Logged
|
|
|
|
|
magxtopher
|
 |
« Reply #4 on: May 24, 2012, 08:07:34 AM » |
|
@ cyber.spirit, My candidy advise is read google hacking and pen test by Johnny Long, any security officer needs this book.You will found millions of hacking scenarios and above all you will be equip with billions of search codes.I was shocked how the guy come up with such book.After reading the book you will attempt to know how to hack with other search engines like msn,yahoo,bing etc.Give it a try u loose nothing. Good luck.
|
|
|
|
|
Logged
|
|
|
|
|
fred
|
 |
« Reply #5 on: May 24, 2012, 11:54:28 AM » |
|
thank you both Magxtopher and sil that blog is really greate iDK who creates that its pretty well.
magxtopher, google hacking and pen test? Really? But i thought hacking with search engines is useless coz you cant choose ur target u must select one of results anyway thanks again and i'll buy that book if its not free.
|
|
|
|
|
Logged
|
ICS Academy Network Security Certified
|
|
|
|
|
|
chrisj
|
 |
« Reply #7 on: May 24, 2012, 12:01:41 PM » |
|
thank you both Magxtopher and sil that blog is really greate iDK who creates that its pretty well.
magxtopher, google hacking and pen test? Really? But i thought hacking with search engines is useless coz you cant choose ur target u must select one of results anyway thanks again and i'll buy that book if its not free.
You can't hack if you don't have information. You can get information passively or actively.
|
|
|
|
|
Logged
|
OSWP, Sec+
|
|
|
|
fred
|
 |
« Reply #8 on: May 24, 2012, 12:36:15 PM » |
|
Yes chrisj i already know without Footprinting i cant hack, and i can find info passively and sometimes actively. But if u used google hacking i may know in this type of attack u must use some Google dorks and choose a vulnerable site from results and go further but my problem is i wanna choose the target by myself not useing the Google's results thats why i think its useless IDK maybe Im wrong.
and thank you for that book i guess its a greate book, and plese tell me is my lab efficient? do i need anything else for that? and which SP of windows XP is good for my lab
thanks again
|
|
|
|
« Last Edit: May 24, 2012, 12:40:04 PM by cyber.spirit »
|
Logged
|
ICS Academy Network Security Certified
|
|
|
|
chrisj
|
 |
« Reply #9 on: May 24, 2012, 01:06:16 PM » |
|
my problem is i wanna choose the target by myself not useing the Google's results thats why i think its useless IDK maybe Im wrong.
and thank you for that book i guess its a greate book, and plese tell me is my lab efficient? do i need anything else for that? and which SP of windows XP is good for my lab
thanks again
As for the google stuff, treat it as if it's out of scope.  I was reading Basics of Hacking and Penetration Testing, or was it in the elearn security documents, last week, I can't remember. Pretty sure that was where I came across, get the lowest SP version you can find. It'll have more stuff for you to exploit. Doesn't mean newer ones won't have stuff to exploit but you'll get more bang for your training doing the oldest. Of course, if your system will handle it, do all service packs and see how each do.
|
|
|
|
|
Logged
|
OSWP, Sec+
|
|
|
|
ziggy_567
|
 |
« Reply #10 on: May 24, 2012, 03:25:28 PM » |
|
But i thought hacking with search engines is useless coz you cant choose ur target u must select one of results Check out the "site:" or "inurl:" Google dorks...
|
|
|
|
|
Logged
|
-- Ziggy
eCPPT - GSEC - GCIH - GCUX - RHCE - SCSecA - Security+ - Network+
|
|
|
|
fred
|
 |
« Reply #11 on: May 25, 2012, 04:45:28 PM » |
|
Ok thank you all chrisj what do you think if i'll buy the complete package of Professional Penetration Testing Creating And Operating A Formal Hacking. i think its expensive but as i said im addicted to hack and i dont care !!!! so what is ur opinion???
|
|
|
|
|
Logged
|
ICS Academy Network Security Certified
|
|
|
|
fred
|
 |
« Reply #12 on: May 25, 2012, 04:46:54 PM » |
|
can you give me an example ZIGGY??
|
|
|
|
|
Logged
|
ICS Academy Network Security Certified
|
|
|
|
Grendel
|
 |
« Reply #13 on: May 25, 2012, 08:48:52 PM » |
|
chrisj what do you think if i'll buy the complete package of Professional Penetration Testing Creating And Operating A Formal Hacking.
As author of the aforementioned book, I strongly support your purchase it. 
|
|
|
|
|
Logged
|
- Thomas Wilhelm, MSCS MSM ISSMP CISSP SCSECA SCNA IEM Web Site: Author: - Professional Penetration Testing
- Ninja Hacking
- Penetration Tester's Open Source Toolkit
- Metasploit Toolkit for Penetration Testing
- Netcat Power Tools
|
|
|
|
ziggy_567
|
 |
« Reply #14 on: May 25, 2012, 10:59:53 PM » |
|
can you give me an example ZIGGY?? Sure. Say you're assessing a site for abc.com, and you want to look for sql dumps carelessly left on their webservers...go to Google and search for the following: filetype:"sql" site:abc.com As long as Google has indexed it, you're in business...
|
|
|
|
|
Logged
|
-- Ziggy
eCPPT - GSEC - GCIH - GCUX - RHCE - SCSecA - Security+ - Network+
|
|
|
|