Ethical Hacking and Penetration Testing

Discussion on ethical hacking and penetration testing subjects.

InfoSec Institute's most popular information security and hacking training goes in-depth into the techniques used by malicious, black hat hackers with attention getting lectures and hands-on lab exercises . While these hacking skills can be used for malicious purposes, this class teaches you how to use the same hacking techniques to perform a white-hat, ethical hack, on your organization. You leave with the ability to quantitatively assess and measure threats to information assets; and discover where your organization is most vulnerable to hacking in this network security training course.

Some of the instructor-led hands-on hacking lab exercises in this security training experience:

* Capture the Flag hacking exercises every night
* Abusing DNS for host identification
* Leaking system information from Unix and Windows
* Stealthy Recon
* Unix, Windows and Cisco password cracking
* Remote buffer overflow exploit lab I - Smashing the Stack
* Remote buffer overflow exploit lab II - Integer Overflows
* Remote heap overflow exploit lab III - Beyond the Stack
* Desktop exploitation
* Remote keylogging
* Data mining authentication information from clear-text protocols
* Remote sniffing
* Breaking wireless security
* Malicious event log editing
* Transferring files through firewalls
* Hacking into Cisco routers
* Harvesting web application data
* Data retrieval with SQL Injection Hacking
* Calculating the Return on Investment (ROI) for an ethical hack


Click here to learn more about the most hands-on Ethical Hacking course ever!

Wednesday, February 16, 2005

First Post

So, this is the first post in my blog. I feel it is only appropriate for me to talk about why I am doing this, what my intentions are, and my opinion on blogs in general.

I must be totally honest and confess to have never actually explicitly or intentionally viewed any persons blog. I may have landed on a few here and there searching for particular things on the internet, but I would have to say I would never regularly visit a blog to better inform myself about current events, security, or anything else I have an interest in. I guess I just don't trust them. All of this talk about the "blogosphere" (Am I the only one that thinks that is the silliest media-contrived slang term ever created?) replacing traditional media, I just don't buy into bloggers having the same journalistic integrity as, say, a journalist from The Wall Street Journal, The Washington Post, or even SecurityFocus. I don't think they ever will either, but I could see some exceptional bloggers being hired by a traditional media outlet. So, why am I doing this?

Well, two reasons, the first is that I am lucky enough to be relatively plugged-in to the information security/ethical hacking industry. I am also lucky in that I get to regularly teach hacking classes for InfoSec Institute, and students are always asking me for additional resources after the class. So this blog will serve as a place to find these resources if you are a previous student, or are simply looking for some interesting security information on the web.

The second reason is much more self-interested (selfish?). The marketing manager here at InfoSec has asked me to do this, as our website was hit by a recent google update (called Allegra, read more here if you care). It is high time we started adding original content to our web presence, so this is a good opportunity. I have also written two books, and consider myself to have average to above-average writing skills. I would like to improve my writing skills, and a blog looks like a good place to practice without having nasty editors hanging over my head. So here it is. Please leave comments, and if you like what you see, please link to this website.

~Jack

13 Comments:

  • At 11:00 PM, Anonymous said…

    Welcome to the 'blogosphere' and I look forward to another resource to turn to for security insight.

     
  • At 8:23 AM, Max said…

    Jack,
    Glad to see you are on the bandwagon. I am adding you to my bloglines and plan to read this regularly.

    This is Max, I was in your D.C. class last month. I hope to make the advanced class soon also, hopefully this summer.

     
  • At 10:23 AM, Anonymous said…

    ha ha i hack u!

     
  • At 4:41 PM, Anonymous said…

    Howdy Jack,

    Great to see your blog come alive, I think you have a few stories that you could most certainly share with the community. I look forward to your future posts.

    Clement
    The Security Lumberjack

    http://www.professionalsecuritytesters.org
    The Professional Tester Warehouse

     
  • At 4:38 PM, Anonymous said…

    cool

     
  • At 7:36 AM, Anonymous said…

    In my experience, editors improve my writing by pointing out incorrect facts, lame punctuation, spelling errors and a hundred other things that I should be thinking about when I write.

     
  • At 9:51 AM, Matt said…

    I agree with you Jack. I had a short blog back in the late 90s before it was cool and boy was I surprised when it caught on in the last couple years--it's not for me though, writing or reading. They're just spooky.

    I appreciate your work though. The tMobile article was cool. Oh and hey I might be moving out to your neck of the woods, shoot me an email.

    --Chewie

     
  • At 3:03 PM, Anonymous said…

    http://www.rootsecure.net/?p=reports/paris_hilton_phonebook_hacked

     
  • At 12:19 PM, vin_pi said…

    I like your stuff... Just stumbled on it today. Hope to take one of the classes at InfoSec. Please post again..

    Best Regards... VinPi

     
  • At 8:24 PM, zonker said…

    Well, if you're looking for related blog material as part of your regular reading, I'd hope you'd be reading Bruce Schneier's weblog. He's got some good stuff...

    Schneier on Security
    http://www.schneier.com/blog/

    Anyway, good luck to you. I look forward to seeing what you have to say here.

     
  • At 7:16 PM, (MFS{Pat}) said…

    Just took CEH from Tim. He did a helluva good job. I hope you keep your blog going. I appreciate the info and the time you (pl.) put into informing us.

     
  • At 8:40 PM, Anonymous said…

    Wow some grat stuff I am totaly new to this thing but I bealeave I will be keeping my eye's on your site. good luck to you and mabey send me a how to do peace and love drmevil

     
  • At 10:58 PM, sweetpartner said…

    What`s your discussion and comments to that real facts, impacts and background reasons of filthy hacking with damages up to US§ 30K ???

    Security – internet/computer hacking - sabotage – real reports

    Links in Spanish, English, German and Mandarin about massive computer/Internet observation, blocking, hacking including PC/LAN shut downs in other operation nets.
    • http://www.microperforation.com/spanish.html - German Server
    • http://www.microperforation.com/hacking-english.html
    • http://www.microperforation.com/hacking-german.html
    • http://www.deguodaguan.com/ipmwg/ipm.files/hacking-german.html - Chinese Server
    • http://www.deguodaguan.com/ipmwg/ipm.files/hacking-english.html
    • http://www.qsl.net/dk3qv/hacking-english - US Server
    • removed because much trouble with Trojan threats and NO communication
    • http://www.dk3qv.de/hacking-english.html - German Server
    • http://www.dk3qv.de/hacking-german.html
    • http://www.dk3qv.de/spanish.html
    • http://www.dk3qv.de/internet-log-1.html
    exactly the same hacking/blocking experiences : http://www.vheadline.com/readnews.asp?id=47155
    http://www.williambowles.info/venezuela/2005/raging_bull.html
    plus hundred other information sources on the Links.

    Other background information
    • http://www.vheadline.com/readnews.asp?id=47155
    • http://www.williambowles.info/venezuela/2005/raging_bull.html
    • http://groups.google.de/group/soc.culture.chile/browse_thread/thread/26124f71d0044493/f92ccc3539d3cb5c%23f92ccc3539d3cb5c?sa=X&oi=groupsr&start=0&num=3
    • http://www.opendemocracy.net/forums/thread.jspa?forumID=87&threadID=46305&start=30&tstart=0
    • http://www.vheadline.com/readnews.asp?id=17529
    • http://lists.grok.org.uk/pipermail/full-disclosure/2003-January/003259.html
    • http://www.crime-research.org/news/2003/05/Mess0604.html

    Links with the same association
    • http://youwillanyway.blogspot.com/2004_06_13_youwillanyway_archive.html
    • http://web2news.ac-versailles.fr/tree.php?group_name=soc_culture_chile&begin=0
    • http://web2news.ac-versailles.fr/article.php?id_article=%3C1144668444.486487.320380%40e56g2000cwe.googlegroups.com%3E&group_name=soc_culture_chile&begin=0&PHPSESSID=4b42e785264d2e7142a434a3bec5bec9
    • http://mailgate.supereva.com/soc/soc.culture.chile/msg56328.html

    --------------------------------------------------------------------------------------------------------------------------------------------------------------------------

    Disclaimer – April 2006 :
    Links in Spanish, English, German and Mandarin about massive computer/Internet observation, blocking, hacking including PC/LAN shut downs in other operation nets.
    • http://www.microperforation.com/spanish.html - German Server
    • http://www.microperforation.com/hacking-english.html
    • http://www.microperforation.com/hacking-german.html
    • http://www.deguodaguan.com/ipmwg/ipm.files/hacking-german.html - Chinese Server
    • http://www.deguodaguan.com/ipmwg/ipm.files/hacking-english.html
    • http://www.qsl.net/dk3qv/hacking-english - US Server
    • removed because much trouble with Trojan threats and NO communication
    • http://www.dk3qv.de/hacking-english.html - German Server
    • http://www.dk3qv.de/hacking-german.html
    • http://www.dk3qv.de/spanish.html
    • http://www.dk3qv.de/internet-log-1.html
    exactly the same hacking/blocking experiences : http://www.vheadline.com/readnews.asp?id=47155
    http://www.williambowles.info/venezuela/2005/raging_bull.html
    plus hundred other information sources on the Links.

    --------------------------------------------------------------------------------------------------------------------------------------------------------------------------
    By publishing and website visits on Latin, South American online medias, magazines and forums from Venezuela and Argentina as well by Internet connections with our and other computer systems certain persons and IT institutions had blocked, interrupted, hacked, penetrated an shut-down LAN/PC systems in Germany, Thailand, Malaysia and China between August 2005 up to February 2006.
    Thousands of dirty events as few examples are listed on the below IP data table.
    The immense blocking/hacker attacks began in 08-2005 - JUST after the publication of truth facts about the chancellor from Venezuela http://www.dk3qv.de/spanish.html - which includes penetrates of lock in, spy, snoop, key logger, remote control programs for Email exchanges, browser activities and as well Trojan threats during website services.
    Since 6-1-2006 our computer systems are clean and full protect against all hacking and observation attacks.
    All IP´s log are continuously recorded, government abuse sections and net operation companies are informed.
    It confirms that certain persons and institutions have an immense interest to blocking information publishing, based of opinion freedoms and real facts in order of international law/rules.
    We do not send messages without any identification, no spam, no unsolicited Emails, no untrue information, no personal insults, all texts are documented with evidences, no international political promotions, no political or social registered propaganda, no rubbish texts, no data abuse, no other promotions or banner, non virus infected Mails, etc.
    We as a honest company and my selves with a well reputation and honorary in China informing all the time there net operators and others that they can contact us in a normal/professional way by Email, phone or fax, to request what they really want from us.
    They observe, blocking and hacking our and other computer systems how and when they want.
    My publishing about a VIP politic persons in Venezuela is NOT the FIRST CASE which rise that bullshit of filthy communication sabotages what`s exactly described in the same way e.g. from a Canadian Journalist what link is added.
    We DO NOT accept that condition further, finished the investigation of all IP senders, Firewall logs, data events and others with Chinese IT specialists.
    We have the SOLID evidences and know the persons, institutions, locations and their background that international actions are being filed and qualified publications are initiated in Mandarin, Spanish, Bahasa, English and German.
    Since January 2006 the data abuse and security departments of the Chinese, Malaysian, Thai and German Governments are involved with their own investigation who has the fully responsibility for that underground actions.
    --------------------------------------------------------------------------------------------------------------------------------------------------------------------------
    Examples of firewall recorded IP addresses - thousands with the same IP-Address
    • 66.35.229.209 – 2005/10/14 - 17:56:07 Pings – IPNOC
    • 213.244.183.210 – 2005/10/22 - 17:56:31 - Amsterdam – NL – Broomfied Col. – USA – firewall blocked !
    • 213.244.183.210 - 2005/11/04 - 12:04:31 - Pings – Amsterdam – NL
    • 203.147.56.231 (232) – Dec. 2005/Jan. 2006 - eur.a1.yimg.com/us.i1.yimg.com – known IP
    • 169.254.146.146 - 2005-12-25 10:50:45 - 2005-12-25 10:51:59 - 2005-12-25 10:53:32 - 2005-12-25 10:53:38 – firewall attacks/blocking - FTP blocking – Trojan threats
    • 61.19.15.213 - 2005-12-25 10:53:15 - firewall attacks and blocking – CAT Thailand - Flag Telecom
    • 139.130.97.62 - 2005-12-25 10:53:32 - 2005-12-25 10:53:38 - firewall attacks and blocking – Telstra.net
    • 68.86.119.34 - 2006-01-04 10:35:15 - 2006-01-04 16:19:05 - 2006-01-06 12:12:08 - 2006-01-06 12:13:55 2006-01-07 15:55:31 - 2006-01-08 17:50:30 – firewall attacks and blocking – Comcast.net - Valparaiso Chicago
    • 68.86.119.34 – 31-1-2006 - USA - Firewall alert and blocked !
    • level3, non-level3 – several times - 30-1-2006
    • 203.147.56.231 (232) - eur.a1.yimg.com - us.i1. NL, DL - 1-2-2006 - 9.08.01 – POP3/SMTP !
    • 203.147.56.232 – eur.a1.yimg.com - us.i1. NL, DL - 8-2-2006 - 14.26.03 – POP3/SMTP !
    • unknown.level3 – 10-2-2006 - 14.43.15
    • 210.147.56.231 (232) – eur.a1.yimg.com - us.i1.yimg.com - 22-2-2006 - 9.14.23 – POP3/SMTP !
    • 210.147.56.231 (232) - eur.a1.yimg.com - us.i1. – 1-2-2006 - 9.08.01 – POP3/SMTP !
    • 203.147.56.232 – 25-2-2006 - 9.13.55 – POP3/SMTP !
    • 203.147.56.232 – 28-2-2006 - 16.56.05 – POP3/SMTP !
    • 203.147.56.231 (232) - 2-2-2006 at 10.08.23 – POP3/SMTP !
    • 203.147.56.230 – 10-3-2006 – 11.18.53 and 19.29.32 – PORT 3232/3151
    • 203.147.56.231 - 13-3-2006 – 12.39.01 – eur.a1.yimg.com - us.i1.yimg.com – 50 times blocked !
    • further as 203.147.230 (231), (232) with observations and blockings !
    • 203.147.56.230 - 2-4-2006 – 9.57.36 – blocked !
    • 100 times and further more…………………
    • 203.147.56.230 – 11-4-2006 – 17.15.22 - blocked
    Follow during observing, hacking and others. Time stamps UTC plus 7 hours.
    --------------------------------------------------------------------------------------------------------------------------------------------------------------------------
    This e-mail message and its attachments are intended solely for the use of the addressee and may contain legally privileged and confidential information. If the reader of this message is not the intended recipient, nor an employee or agent responsible for delivering this message to the intended recipient, please note that any dissemination, distribution, copying, or other use of this message or its attachments is strictly prohibited. If you have received this message in error, please notify the sender immediately and delete this message.
    --------------------------------------------------------------------------------------------------------------------------------------------------------------------------

     

Post a Comment

<< Home