Forum Replies Created
-
AuthorPosts
-
-
November 29, 2012 at 3:24 am #51031
jinwald12
Participant@ajohnson wrote:
Why is everyone saying BackTrack is outdated? It’s based off an LTS version of Ubuntu and is still completely supported: https://wiki.ubuntu.com/LTS
it’s based off of 10.04 (lucid) which while in theory is still LTS but does not get nearly as much attention as other releases and BT uses different repos then normal lucid for most of it’s programs which have out dated versions (with the exception of firefox and a few others) and they slapped on a kernel version that is no where near what lucid was designed to work with.
-
November 28, 2012 at 1:34 am #51022
jinwald12
ParticipantAre you crazy? It’s never a good idea to run as root the hole point of sudo/levels of privilege is to allow for “security in layers” so that way if they compromise the signed in user an attacker does not have free reign of the system they have to find a way to escalate privileges. And it does not matter if it’s a forensics boot or not backtrack still is based off of an outdated platform.
-
November 27, 2012 at 10:41 pm #49362
jinwald12
Participantthis is probably the best progressive lock out there http://learnlockpicking.com/
-
November 27, 2012 at 10:40 pm #49361
jinwald12
ParticipantLike the guy above said the best way to get good really fast at lock picking is to get a progressive lock and practice. Lock your self in a room (no pun intended) for a day or so and do nothing but pick locks. And be sure to change up the configuration of the practice lock you are using, switch pins based on weight, size and type until you can pick anything that’s thrown at you.
-
November 27, 2012 at 10:34 pm #51020
jinwald12
ParticipantBut to be honest use specific VMs are better and more cost efficient. Assuming your virtualization software is up to date its really unlikely that malware will “jump the petri dish” as it where. Also Backtrack 5 runs as root on a outdated version of ubuntu with tons of after market modifications i would not use it to do banking under most circumstances
-
November 27, 2012 at 10:29 pm #51019
jinwald12
Participanthe forgot to mention the tin foil hats and vpn chaining
-
November 15, 2012 at 3:36 pm #50849
jinwald12
Participantfor practicing and learning SQL injection i reccomend this lab on a LAMP server: https://github.com/Audi-1/sqli-labs and if you get stuck the developer of these labs has video tutorials on Security Tube
-
November 12, 2012 at 9:56 pm #50813
jinwald12
ParticipantAgainst a modern IDS i am not so sure they would not notice and do you really want to risk ending a pen test during the recon phase, because you got caught? I would rather deal with a slightly slow stealthy scan then a fast loud and noticeable scan.
-
November 12, 2012 at 5:39 pm #50810
jinwald12
ParticipantI would have made it multi-threaded, but the thing with brute forcing DNS is it’s noisy-ish, not as noisy as a Zone-transfer but even a half-assed IDS would pick up multi-threaded DNS brute force. also in my Experience python does not do multi-threading well.
-
October 17, 2012 at 4:45 pm #50459
jinwald12
Participanti found a book on exploiting these systems:http://tinyurl.com/cq6r869
-
October 8, 2012 at 4:39 pm #44856
jinwald12
ParticipantDon’t get the H it does not support 802.11N or many advanced features that is why the Hakshop no longer sells it they now sell the NHA which is far superior DO NOT I REPEAT DO NOT GET the H
-
October 6, 2012 at 11:58 am #44851
jinwald12
Participantthe Alfa AWUS036H has the shitty reltek chipset and can not do 802.11N so go for the Alfa AWUS036NHA and the hakshop no longer sells the Alfa AWUS036H they sell the NHA so regardless of what vivek will tell you it is shit go for the NHA
-
September 15, 2012 at 5:31 pm #49869
jinwald12
ParticipantMdk3 will suit your needs if scripted, or you can look into http://openwips-ng.org/index.html however it is immature at this time.
-
September 15, 2012 at 5:22 pm #49883
jinwald12
ParticipantI wrote a article on this with a focus on wifi pen testing, it may be of help to you.
http://resources.infosecinstitute.com/wlan-penetration-test/ -
September 1, 2012 at 1:02 am #48830
jinwald12
ParticipantThere may be a few maverick networks out there, but generally you will be dealing with EAP and WPA2-PSK so focus on that and get a good GPU rig.
-
-
AuthorPosts