Tuesday, 30 July 2013

Bash sripts

So, all of this afternoon through to this evening I have been pulling my hair out trying to solve a bash script conundrum in the Pentesting With Backtack course. This problem was driving me crazy!

After installing Pure-ftp, you are required to use the supplied bash script to set up the user, password and directory for copying files into. However, like for many other OSCP's in training, the ruddy thing wouldn't work and the error '530 Login authentication failed' kept running.

If you happen to stumble across this or a similar issue, try the following:

>Stop Pure-ftp
>Remove Pure-ftp
>Reinstall Pure-ftp
>Recreate the bash script but change the user name first
>Chmod +x 'bash script name'
>Copy the nc.exe file as instructed
>Run ftp 127.0.0.1

Stay calm, think happy thoughts and keep trying.

Wednesday, 24 July 2013

Road to Ruin or Greatness?

On my path to achieving accreditations in the infosec arena, I have spent some time reading the below books.

Obviously, you must have a good understanding of the road ahead and although my knowledge of information gathering is strong, there are other areas which are weak in comparison.

If you are a newbie, you may also be interested in:

The Basics of Hacking and Penetration Testing - Patrick Engebretson

Google Hacking for Penetration Testers Volume 2 - Johnny Long

Backtrack 5 Cookbook - Willie Pritchett & David De Smet

TCP / IP For Dummies - Candace Leiden & Marshall Wilensky

I have also been learning Python on Codecademy.com to develop my programming/scripting skills. It's a great learning platform, give it a try.

Pentesting With Backtrack

So I recently signed up for the Pentesting With Backtrack course. I spent a number of evenings looking at the various courses available, summing up their pros & cons and their associated certifications.

If you are looking for a cert which is well recognised in the UK, you may consider CHECK or CREST. Personally I liked the look of Certified Ethical Hacker and Offensive Security's OSCP (Pentesting With Backtrack).

Certified Ethical Hacker seems to be more recognised in the US than the UK, but appears to be a good beginners course nonetheless and covers alot. I did look at completing this through Firebrand which is a week long intensive course at about £3k.

The reason for choosing PWB came down to three factors; ability to home study, hands on exam and cost.

The PWB course offers hands on home study for a period convenient to you, with access to their virtual lab environment.

Should you wish to take the inclusive exam at the end, you will need to complete a penetration test against a virtual network and write a full report on your findings. But having read various reviews, it's not for the faint hearted, at 24hrs long there is obviously alot of ground to cover. Other accreditations are multi choice exams, for me I know what I prefer.

And finally, cost. At less than £500 for 30 days of study followed by the exam, Offensive Security wins hands down. Unless you're a pro or well versed in pentesting, you may wish to study for longer like me. It's still a bargain though!

You can find out more from:

www.offensive-security.com
www.firebrandtraining.co.uk
www.crest-approved.org
www.tigerscheme.org

From Padawan to Jedi Master

Hi, my name is Dan. I'm from London and am an internet investigator. Over the last couple of years I have progressively become more interested in all things InfoSec. To that end, this year I started studying the art of Penetration Testing/Ethical Hacking.

The role of an internet investigator is very similar if not identical to the reconnaissance stage of pentesting. As well as researching your target across social networks, a skilled internet investigator will be obtaining whois data, employing social engineering techniques, studying email headers, capturing IP addresses, basic packet sniffing, steganography detection, advanced Google searching, scouring html source code... the list goes on.

Hopefully, with alot of effort, focused studying and hands on training, I'll master this fascinating area of infosec. I hope you'll join me on my journey from training Padawan to Jedi Master. It's going to be a long road.

You can also follow me on Twitter @101011101010101