-
timmedin replied to the topic Metasploit Question in the forum Network Pen Testing 11 years, 1 month ago
@d3l0n wrote:
jonas, unless you managed to run it as a scheduled task which runs with system privileges you won’t be able to dump the hash.
d3l0n is right, you have to have admin or system level privileges in order to dump the hashes.
-
timmedin replied to the topic would this be ethical? in the forum Network Pen Testing 11 years, 1 month ago
It all depends on the “rules of engagement”.
From practical experience, I haven’t seen an intentional DoS against productions systems be allowed.
-
timmedin replied to the topic C|EH vs. GPEN? in the forum General Certification 11 years, 1 month ago
I’ll second BillV’s response.
CEH is more well known, but from what I have been hearing it isn’t keeping up in the certification market. GPEN is great. Not only does it give you good training on the tools it teaches the business side of things which is very important. You can be the best pen tester out there, but if you can’t communicate findings…[Read more]
-
timmedin replied to the topic Pass-the-hash on other system is it possible? in the forum Network Pen Testing 11 years, 1 month ago
@d3l0n wrote:
Thanks timmedin
Pash-the-hash works because the hash is reused without modification and it is the sole piece used for authentication. This is the same reason that cookie and session hijacking work in web apps.
How can you get transparent access to network without storing users’ credentials somewhere?And without asking users to…
-
timmedin replied to the topic Pass-the-hash on other system is it possible? in the forum Network Pen Testing 11 years, 1 month ago
Pash-the-hash works because the hash is reused without modification and it is the sole piece used for authentication. This is the same reason that cookie and session hijacking work in web apps.
The attack is specific to the protocol and its authentication mechanism, NTLMv1 authentication. You won’t be able to authenticate to a *nix ssh server or…[Read more]
-
timmedin replied to the topic cain and abel in the forum Other 11 years, 1 month ago
Where did you download it from? It should be http://www.oxid.it/cain.html
-
timmedin replied to the topic What are all the parameters that your wireless router logs ? in the forum Wireless 11 years, 1 month ago
Depends on the router, but the router would also need to keep the dhcp request timestamp
-
timmedin replied to the topic Footprinting Vs Fingerprinting – Difference? in the forum Network Pen Testing 11 years, 1 month ago
I have always heard that…
-fingerprinting is seeing what the machine or service is
-footprinting is seeing what machines and services are out there -
timmedin replied to the topic How much a Penetration cost? in the forum Network Pen Testing 11 years, 1 month ago
@don wrote:
It’s also similar to finding a lawyer. You get very different results going with the more expensive ones. “You get what you pay for” seems to fit in with pen testing as well.
This can’t be emphasized more. The quality of your test is directly proportional to the quality of the tester.
-
timmedin replied to the topic Detecting Exploits! in the forum Network Pen Testing 11 years, 1 month ago
What is your goal here?
– If it is to write snort rules then look at the metasploit exploits (not payloads)
– If you just want the rules then check out http://wwww.bleedingsnort.com (free) or even better look at http://www.sourcefire.com/products/snort/rules (paid)
-
timmedin replied to the topic GIAC PENETRATION TESTER (GPEN) Certification Trainning in the forum GPEN – GIAC Certified Penetration Tester 11 years, 1 month ago
I would recommend the online training with vLive, taught by Ed Skoudis and John Strand, both of whom are fantastic. Here is the link.
-
timmedin replied to the topic IRONKEY gets my KICK AZZ award ! in the forum Hardware 11 years, 1 month ago
I have an older one and I got one from EH.net/IronKey. I love it. It is so rugged. Normally I am afraid of breaking them in my bag and I wouldn’t trust them to be carried with my keys, but this thing is solid.
I like all the cool features and the cross platform support too.
-
timmedin replied to the topic Kodu by Microsoft Research in the forum Programming 11 years, 1 month ago
Sweet! What is the recommended age on this thing?
-
timmedin replied to the topic How much a Penetration cost? in the forum Network Pen Testing 11 years, 2 months ago
I’ve seen the hourly rate from $150-$250 and I would guess that this would take 20-40 hrs depending on the services and the size of the website. That would put the range between $3,000-$10,000.
-
timmedin replied to the topic Does use on NMAP and other port scanners illigal ..? in the forum Tools 11 years, 2 months ago
If you are scanning your internal systems, GET WRITTEN PERMISSION!
The tool isn’t illegal, except maybe in Germany. Anyone know the details of the German law?
-
timmedin replied to the topic Lost WPA2 Password Help in the forum Wireless 11 years, 2 months ago
Cain & Abel allows you to “read” the password boxes and retrieve the key even if it is blanked out by ******.
-
timmedin replied to the topic Internal Network Vulnerability Assessment Help in the forum Network Pen Testing 11 years, 2 months ago
It has been a while but if I remember correctly Paul Asadoorian (from PaulDotCom Security Weekly) did a webcast that gives some good justification.
-
timmedin replied to the topic GCIH (SANS 504) and GPEN (SANS 560) in the forum General Certification 11 years, 2 months ago
I have taken and passed both tests, and I would say that the overlap is a maximum of 40%. Not having the course material will make it much tougher to pass the test. I have Counter Hack Reloaded, but I haven’t read it yet so I an’t tell you how helpful it would be. Good luck.
-
timmedin replied to the topic Cracking/Opening a right protected email in the forum Other 11 years, 3 months ago
I’m still confused, but…
If you can export the message I would think you could open it. Try it (with permission of course).
-
timmedin replied to the topic Bypassing Safeboot Security System 4.2 in the forum Network Pen Testing 11 years, 3 months ago
I don’t know if Kon-Boot would work but it might. I would suggest trying it. All it does is load its code then calls the normal boot loader.
- Load More