<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0">
<channel>
<title>Ask a Pentester - Recent questions</title>
<link>http://www.ask-a-pentester.com/index.php/questions</link>
<description>Powered by Question2Answer</description>
<item>
<title>metasploit remote computer and network portforwarding</title>
<link>http://www.ask-a-pentester.com/index.php/177/metasploit-remote-computer-and-network-portforwarding</link>
<description>I am using metasploit and I tried to use hail mary with armitage to expose a remote computer on a different network than the one I am using with metasploit. I downgraded to metasploit 3.7 and tried the same thing with db_autopwn. It still did work. I was not getting any meterpreter sessions, however there where several exploits I could use. My question is do I need to portforward to exploit a remote computer with meterpreter or any other metasploit exploits. Also how do I do this. I know how to portforward.</description>
<category>Tools</category>
<guid isPermaLink="true">http://www.ask-a-pentester.com/index.php/177/metasploit-remote-computer-and-network-portforwarding</guid>
<pubDate>Sat, 19 May 2012 07:38:12 +0000</pubDate>
</item>
<item>
<title>Must sulley be run on a windows system?</title>
<link>http://www.ask-a-pentester.com/index.php/174/must-sulley-be-run-on-a-windows-system</link>
<description>Hi,&lt;br /&gt;
&lt;br /&gt;
so far I have only seen configurations with windows fuzzing-host and windows guest.&lt;br /&gt;
&lt;br /&gt;
Has anyone here had success with a linux fuzzing-host and windows fuzzing-target?</description>
<category>Frameworks</category>
<guid isPermaLink="true">http://www.ask-a-pentester.com/index.php/174/must-sulley-be-run-on-a-windows-system</guid>
<pubDate>Sat, 14 Apr 2012 15:39:40 +0000</pubDate>
</item>
<item>
<title>where to find Microsoft HTTPAPI httpd 2.0 exploits</title>
<link>http://www.ask-a-pentester.com/index.php/173/where-to-find-microsoft-httpapi-httpd-2-0-exploits</link>
<description>im using metasploit and i need to know what are the exploits related to HTTPAPI httpd 2.0 exploits</description>
<category>Exploit devel.</category>
<guid isPermaLink="true">http://www.ask-a-pentester.com/index.php/173/where-to-find-microsoft-httpapi-httpd-2-0-exploits</guid>
<pubDate>Wed, 04 Apr 2012 10:33:42 +0000</pubDate>
</item>
<item>
<title>What are some methods you can do to exploit a computer behind a router?</title>
<link>http://www.ask-a-pentester.com/index.php/172/what-are-some-methods-you-can-exploit-computer-behind-router</link>
<description>I have always practiced remotely exploiting computer over the lan but I have never reallly tried exploiting computers over the internet. What methods could you use to remotely exploit a computer over the internet and have the session connect back to you over the internet. Also is it even possible to attack from outside the router without pivoting from the inside?</description>
<guid isPermaLink="true">http://www.ask-a-pentester.com/index.php/172/what-are-some-methods-you-can-exploit-computer-behind-router</guid>
<pubDate>Mon, 02 Apr 2012 18:42:45 +0000</pubDate>
</item>
<item>
<title>Hi. We are looking or pentesters to writte to Pen Test Magazine. April issue.For more info. please contac: renata.polish@yahoo.com</title>
<link>http://www.ask-a-pentester.com/index.php/169/looking-pentesters-writte-magazine-please-renata-polish%40yahoo</link>
<description>I am editor of Pen Test Magazine. We are looking for specialists who are able to write articles for InfoSec Institiute on a behalf of Pen Test Magazine. Mentioned article must be written on advanced technical level as well as attractive and must give practical tips for readers. Note that the article should consist of at least 2000 words.&lt;br /&gt;
Apart from the material profit [the publisher pays 40 USD net (50 USD gross)], you are going to benefit from possibility to put your eg. business advertisement on world wild known Pen Test Magazine site. Moreover when cooperating with the Magazine you have privilege to title yourself “researcher at InfoSec institute”. Further, no doubt that gained experience is going to pay in your future careers.&lt;br /&gt;
Summarizing it is worth to write to the Pen Test Magazine, so do not hesitate to contact me directly for more details.</description>
<guid isPermaLink="true">http://www.ask-a-pentester.com/index.php/169/looking-pentesters-writte-magazine-please-renata-polish%40yahoo</guid>
<pubDate>Thu, 29 Mar 2012 08:42:38 +0000</pubDate>
</item>
<item>
<title>How do you determine which exploit to use in metasploit?</title>
<link>http://www.ask-a-pentester.com/index.php/166/how-do-you-determine-which-exploit-to-use-in-metasploit</link>
<description>I am about to go to college for computer/systems security and I have been studying computer security for a while now and I know a lot about the metasploit framework and how to use the different modules. Although I know how to utilize these tools and do a remote exploitation on programs I already know are vulnerable, like icecast, how do you determine which remote exploit to use in metasploit? Do you need to code one yourself for most computers? Also can you exploit programs not on a tcp/udp port remotely?&lt;br /&gt;
&lt;br /&gt;
p.s. I know how to use nmap and the standard scans like nmap -sSV -A -O x.x.x.x and the rest, so you dont have to explain how they work</description>
<guid isPermaLink="true">http://www.ask-a-pentester.com/index.php/166/how-do-you-determine-which-exploit-to-use-in-metasploit</guid>
<pubDate>Thu, 15 Mar 2012 16:33:57 +0000</pubDate>
</item>
<item>
<title>OSCP - omg can i pay this myself ?</title>
<link>http://www.ask-a-pentester.com/index.php/161/oscp---omg-can-i-pay-this-myself</link>
<description>I am addicted to IT, i work with computers all my life, in my last job i did technical support for a software company, plus administration of windows based domain. Currently I work as full-time admin.&lt;br /&gt;
&lt;br /&gt;
I have MSCE 2k, MCSA 2k3 and LPIC-1 certificate. My linux distrib at home is Ubuntu and BackTrack and i want to get serious training and certification as a pentester.&lt;br /&gt;
&lt;br /&gt;
&amp;nbsp;&lt;br /&gt;
&lt;br /&gt;
The online training+30 Days labs access+ certificate is a little bit to short i think. What is your optinion ? Is there a way to get more training ? Any online/offline courses, books you would suggest ?&lt;br /&gt;
&lt;br /&gt;
&amp;nbsp;&lt;br /&gt;
&lt;br /&gt;
I have to pay the 750$ by myself, so i better not fail on these tests/trainings.</description>
<category>Career, Certs, etc.</category>
<guid isPermaLink="true">http://www.ask-a-pentester.com/index.php/161/oscp---omg-can-i-pay-this-myself</guid>
<pubDate>Tue, 13 Mar 2012 10:52:06 +0000</pubDate>
</item>
<item>
<title>How to know which CVEs affect my application?</title>
<link>http://www.ask-a-pentester.com/index.php/158/how-to-know-which-cves-affect-my-application</link>
<description>Let's say I have an old version &amp;quot;V&amp;quot; of an application X.&lt;br /&gt;
&lt;br /&gt;
I would like to know if there's a *simple* way to know all CVEs that affect that application, that is, all CVEs concerning version &amp;gt;= V for the given application.&lt;br /&gt;
&lt;br /&gt;
&amp;nbsp;&lt;br /&gt;
&lt;br /&gt;
Thanks in advance! :)</description>
<guid isPermaLink="true">http://www.ask-a-pentester.com/index.php/158/how-to-know-which-cves-affect-my-application</guid>
<pubDate>Wed, 25 Jan 2012 13:42:26 +0000</pubDate>
</item>
<item>
<title>Do you have any classes online you could recommend? Also, is there any certain degree in college I should get if I want to be a pentester?</title>
<link>http://www.ask-a-pentester.com/index.php/152/classes-online-recommend-certain-degree-college-pentester</link>
<description>I'm sorry if this has been asked before but I am a high school student(sophomore) and am interested in becoming a pentester or something of the like. I live in a small rural town so there's not much of anything for computer courses here.</description>
<category>Career, Certs, etc.</category>
<guid isPermaLink="true">http://www.ask-a-pentester.com/index.php/152/classes-online-recommend-certain-degree-college-pentester</guid>
<pubDate>Thu, 10 Nov 2011 00:22:50 +0000</pubDate>
</item>
<item>
<title>Entry level to Pen tester help</title>
<link>http://www.ask-a-pentester.com/index.php/149/entry-level-to-pen-tester-help</link>
<description>Which path to take , im very interested in security (the pentesting part) , never had a job thats IT related , but i do have some broad knowledge . im about to finish my comptia a+ course and i was planning to take netwok+ --&amp;gt; security+ --&amp;gt; CCNA --&amp;gt; CEH , but since i heard that CEH is pretty much all theory and useless i changed my plan to netwok+ --&amp;gt; security+ --&amp;gt; CCNA --&amp;gt; OSCP and maybe more advanced well see how it goes from there . Since im just an entry level student i was wondering if someone can give me gudience or help in which courses to take , since money is kinda an issue here , i mean does network+ and security+ worth it? , should i just skip to CCNA--&amp;gt;OSCP and take something networking related. i have some knowledge in linux,networking,wireless and some security (after playing around with backtrack). althought not advanced just basic. &amp;nbsp;and btw im a long way from uni so time is something that i have on my side. thx for all the help</description>
<category>Career, Certs, etc.</category>
<guid isPermaLink="true">http://www.ask-a-pentester.com/index.php/149/entry-level-to-pen-tester-help</guid>
<pubDate>Fri, 21 Oct 2011 09:47:14 +0000</pubDate>
</item>
<item>
<title>LFI exploration files</title>
<link>http://www.ask-a-pentester.com/index.php/148/lfi-exploration-files</link>
<description>Hi,&lt;br /&gt;
i'm studding LFI issue due to a pratical test for a job.&lt;br /&gt;
So i'm trying to find key files to inject my commands.&lt;br /&gt;
Until now, i can enumerate this:&lt;br /&gt;
&lt;br /&gt;
Files to inject:&lt;br /&gt;
- default webserver logs&lt;br /&gt;
- default daemons logs if world readable&lt;br /&gt;
- environ file at /proc&lt;br /&gt;
&lt;br /&gt;
Files to get helpfull information&lt;br /&gt;
- locatedb file (no slocate, no mlocate) to get vhost and more logs&lt;br /&gt;
- some proc files&lt;br /&gt;
&lt;br /&gt;
Some one could help me about more key files ? Injectable or not, maybe tricks to get vhost infos (without httpd.conf and localedb, course).&lt;br /&gt;
&lt;br /&gt;
thanks friends.</description>
<category>Web Hacking</category>
<guid isPermaLink="true">http://www.ask-a-pentester.com/index.php/148/lfi-exploration-files</guid>
<pubDate>Thu, 20 Oct 2011 11:57:47 +0000</pubDate>
</item>
<item>
<title>Could you recommend a ressource for images which have weak spots to learn more about Pentesting?</title>
<link>http://www.ask-a-pentester.com/index.php/145/recommend-ressource-images-which-spots-learn-about-pentesting</link>
<description>I am looking for prepared OSes (Linux, Windows, maybe Macintosh) which contains security holes to train my skills in pentesting. My plan is to start a VirtualBox instance, use the common tools (e.g. Nmap, Metasploit, Wireshark) and finally find out, which programs or components contain security holes or maladjusted services. Could you recommend a site which provides such preconfigured images?</description>
<guid isPermaLink="true">http://www.ask-a-pentester.com/index.php/145/recommend-ressource-images-which-spots-learn-about-pentesting</guid>
<pubDate>Tue, 06 Sep 2011 18:48:15 +0000</pubDate>
</item>
<item>
<title>What lab setup do you recommend real machines or virtual ones?</title>
<link>http://www.ask-a-pentester.com/index.php/143/what-lab-setup-do-you-recommend-real-machines-or-virtual-ones</link>
<description>Hi,&lt;br /&gt;
&lt;br /&gt;
I want to teach myself some skills the legal way by working in my own lab.&lt;br /&gt;
&lt;br /&gt;
However I am not sure what to use. Can you give me some first hand accounts&lt;br /&gt;
&lt;br /&gt;
about your lab environments?</description>
<category>Tools</category>
<guid isPermaLink="true">http://www.ask-a-pentester.com/index.php/143/what-lab-setup-do-you-recommend-real-machines-or-virtual-ones</guid>
<pubDate>Sun, 04 Sep 2011 10:08:15 +0000</pubDate>
</item>
<item>
<title>Does Scapy support the LDAP protocol?</title>
<link>http://www.ask-a-pentester.com/index.php/139/does-scapy-support-the-ldap-protocol</link>
<description>&lt;p&gt;
	I'm new to &lt;a rel=&quot;nofollow&quot; href=&quot;http://www.secdev.org/projects/scapy/&quot;&gt;Scapy&lt;/a&gt;&amp;nbsp;and I can't find support for the LDAP protocol on it. Does anybody know if it's supported?&lt;/p&gt;
&lt;p&gt;
	Maybe I need to install another package?&lt;/p&gt;
&lt;p&gt;
	&amp;nbsp;&lt;/p&gt;
&lt;p&gt;
	Thanks in advance!&lt;/p&gt;</description>
<category>Tools</category>
<guid isPermaLink="true">http://www.ask-a-pentester.com/index.php/139/does-scapy-support-the-ldap-protocol</guid>
<pubDate>Thu, 07 Jul 2011 14:42:30 +0000</pubDate>
</item>
<item>
<title>Do pentest tools slow down internet</title>
<link>http://www.ask-a-pentester.com/index.php/138/do-pentest-tools-slow-down-internet</link>
<description>I use alot of tools such as nessus, nexpose, nmap, metasploit, sqlmap which all use internet. and my internet is weird. my phone runs of it my sky channels run off it so my dad isn't happy when its slow. he sais that when I use these tools it is screwing up the internet? am I the only person that has this problem?</description>
<category>Tools</category>
<guid isPermaLink="true">http://www.ask-a-pentester.com/index.php/138/do-pentest-tools-slow-down-internet</guid>
<pubDate>Thu, 07 Jul 2011 13:12:58 +0000</pubDate>
</item>
<item>
<title>what can we do with Local file download/ File download vuln. Windows ?</title>
<link>http://www.ask-a-pentester.com/index.php/137/what-can-with-local-file-download-file-download-vuln-windows</link>
<description>hi i want to know what are the security files which are imp. which lead it to hack the Server and get acess to CMD &amp;nbsp;its on Server=Apache-Coyote/1.1&lt;br /&gt;
&lt;br /&gt;
&amp;nbsp;&lt;br /&gt;
&lt;br /&gt;
and i am able to download all files but not admin locked files so can anybody help me ?</description>
<category>Web Hacking</category>
<guid isPermaLink="true">http://www.ask-a-pentester.com/index.php/137/what-can-with-local-file-download-file-download-vuln-windows</guid>
<pubDate>Sat, 02 Jul 2011 08:17:41 +0000</pubDate>
</item>
<item>
<title>Vulnerable Ports?</title>
<link>http://www.ask-a-pentester.com/index.php/131/vulnerable-ports</link>
<description>&lt;p&gt;
	&lt;strong&gt;Im reently getting into nmap and such. and i want to know can ports be hacked? or attacked? anyone have some articles for me to see about it? and if so anything wrong or vulnerable about these ones:&lt;/strong&gt;&lt;/p&gt;
&lt;p style=&quot;text-align: center;&quot;&gt;
	&lt;strong&gt;21/tcp&amp;nbsp;&amp;nbsp;&amp;nbsp; open&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ftp&lt;br /&gt;
	25/tcp&amp;nbsp;&amp;nbsp;&amp;nbsp; open&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; smtp&lt;br /&gt;
	53/tcp&amp;nbsp;&amp;nbsp;&amp;nbsp; open&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; domain&lt;br /&gt;
	80/tcp&amp;nbsp;&amp;nbsp;&amp;nbsp; open&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; http&lt;br /&gt;
	110/tcp&amp;nbsp;&amp;nbsp; open&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; pop3&lt;br /&gt;
	111/tcp&amp;nbsp;&amp;nbsp; open&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; rpcbind&lt;br /&gt;
	143/tcp&amp;nbsp;&amp;nbsp; open&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; imap&lt;br /&gt;
	443/tcp&amp;nbsp;&amp;nbsp; open&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; https&lt;br /&gt;
	587/tcp&amp;nbsp;&amp;nbsp; open&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; submission&lt;br /&gt;
	993/tcp&amp;nbsp;&amp;nbsp; open&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; imaps&lt;br /&gt;
	995/tcp&amp;nbsp;&amp;nbsp; open&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; pop3s&lt;br /&gt;
	2222/tcp&amp;nbsp; open&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; unknown&lt;br /&gt;
	3011/tcp&amp;nbsp; open&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; unknown&lt;br /&gt;
	3306/tcp&amp;nbsp; open&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; mysql&lt;br /&gt;
	8888/tcp&amp;nbsp; open&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; sun-answerbook&lt;br /&gt;
	12000/tcp open&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; cce4x&lt;/strong&gt;&lt;/p&gt;</description>
<guid isPermaLink="true">http://www.ask-a-pentester.com/index.php/131/vulnerable-ports</guid>
<pubDate>Sun, 26 Jun 2011 22:09:06 +0000</pubDate>
</item>
<item>
<title>What to learn first?</title>
<link>http://www.ask-a-pentester.com/index.php/130/what-to-learn-first</link>
<description>&lt;p&gt;
	&lt;strong&gt;first off im new so this may already have been answered before.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;
	&lt;strong&gt;Whats the best programming language to learn? I want to be a pentester with stuff like servers, web apps, websites and to code exploits.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;
	&lt;strong&gt;So what languages should i learn? and in what order?&lt;/strong&gt;&lt;/p&gt;</description>
<category>Programming</category>
<guid isPermaLink="true">http://www.ask-a-pentester.com/index.php/130/what-to-learn-first</guid>
<pubDate>Sun, 26 Jun 2011 21:44:27 +0000</pubDate>
</item>
<item>
<title>Can any one help me to how to exploit windows 7?</title>
<link>http://www.ask-a-pentester.com/index.php/129/can-any-one-help-me-to-how-to-exploit-windows-7</link>
<description>hi cany any body help me how to exploit windows 7 ? i have tried it for last 3 months but no luck, i am new bee to metasploit pls help&lt;br /&gt;
&lt;br /&gt;
&amp;nbsp;&lt;br /&gt;
&lt;br /&gt;
&amp;nbsp;&lt;br /&gt;
&lt;br /&gt;
thanx in advance!!</description>
<category>Exploit devel.</category>
<guid isPermaLink="true">http://www.ask-a-pentester.com/index.php/129/can-any-one-help-me-to-how-to-exploit-windows-7</guid>
<pubDate>Tue, 21 Jun 2011 05:39:46 +0000</pubDate>
</item>
<item>
<title>Can u suggest good exploit for Windows 7, like &quot;ms08_067_netapi &quot; in xp?</title>
<link>http://www.ask-a-pentester.com/index.php/124/can-suggest-good-exploit-for-windows-like-ms08_067_netapi</link>
<description>hi, i am working on finding a good exploit for windows 7. i am new bee to metasploit but succeded to hack windows xp with &amp;quot;windows/smb/ms08_067_netapi&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;nbsp;&lt;br /&gt;
&lt;br /&gt;
now trying to do same in windows 7 in LAN.. pls help me on this..&lt;br /&gt;
&lt;br /&gt;
&amp;nbsp;&lt;br /&gt;
&lt;br /&gt;
&amp;nbsp;&lt;br /&gt;
&lt;br /&gt;
thanx in advance!!</description>
<category>Exploit devel.</category>
<guid isPermaLink="true">http://www.ask-a-pentester.com/index.php/124/can-suggest-good-exploit-for-windows-like-ms08_067_netapi</guid>
<pubDate>Fri, 10 Jun 2011 08:51:48 +0000</pubDate>
</item>
<item>
<title>What if you pentest someone who unkowingly to you lies that they have authority?</title>
<link>http://www.ask-a-pentester.com/index.php/123/what-pentest-someone-unkowingly-lies-that-they-have-authority</link>
<description>&lt;p&gt;
	Client A signs a contract stating that he owns or is authorized to represent the owner of a Network. &amp;nbsp;He asks a penetration testing company to crack it. After they crack it, recover the pass, tell him how to make it more secure; they find out it's not actually his network and now he has the password. Who is liable?&lt;/p&gt;
&lt;div&gt;
	&amp;nbsp;&lt;/div&gt;
&lt;div&gt;
	The contract they signed, says , among other things:&lt;/div&gt;
&lt;div&gt;
	&amp;nbsp;&lt;/div&gt;
&lt;div&gt;
	&lt;p style=&quot;margin-bottom: 0.2in; text-align: JUSTIFY;&quot;&gt;
		&lt;span style=&quot;color: #000000;&quot;&gt;&lt;span style=&quot;font-family: Arial;&quot;&gt;&lt;span style=&quot;font-size: small;&quot;&gt;The client does hereby retain the provider for the purpose of providing Penetration Testing services on the client’s computers and/or Networks.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
	&lt;p style=&quot;margin-bottom: 0.2in; text-align: JUSTIFY;&quot;&gt;
		&lt;span style=&quot;color: #000000;&quot;&gt;&lt;span style=&quot;font-family: Arial;&quot;&gt;&lt;span style=&quot;font-size: small;&quot;&gt;&lt;span style=&quot;color: #000000;&quot;&gt;&lt;span style=&quot;font-family: Arial;&quot;&gt;&lt;span style=&quot;font-size: small;&quot;&gt;The client has provided the provider with certain required information regarding the scope and range of the tests and the client hereby warrants that all information provided is true and accurate and that the client &lt;b&gt;owns or is authorized&lt;/b&gt; to represent the owners of the &lt;b&gt;computers systems and networks&lt;/b&gt; described in Form A. The client further warrants and represents that he/she is &lt;b&gt;authorized&lt;/b&gt; to enter into binding legal agreements.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
	&lt;p&gt;
		&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;</description>
<guid isPermaLink="true">http://www.ask-a-pentester.com/index.php/123/what-pentest-someone-unkowingly-lies-that-they-have-authority</guid>
<pubDate>Sun, 22 May 2011 23:34:17 +0000</pubDate>
</item>
<item>
<title>Defensive Programming--Second Steps?</title>
<link>http://www.ask-a-pentester.com/index.php/117/defensive-programming--second-steps</link>
<description>My company is paying for me to get the GSSP-J certification as it aligns with where I see myself going in the long run. &amp;nbsp;(Just started my master's in CS.)&lt;br /&gt;
&lt;br /&gt;
I'm already aware of OWASP top 10, and SANS top-25, and I wanted to know after I learn mitigation techniques for those, would it be advisable to seek training in pentesting in order to deepen offensive knowledge, or should I look down a different path??&lt;br /&gt;
&lt;br /&gt;
The implicit argument is of course, that I will learn better defense by learning better offense. &lt;br /&gt;
&lt;br /&gt;
There is little chance I will be able to find work in the Red Team at work, but at least the company I'm in recognizes the value I'll have by learning defensive programming. &amp;nbsp;The core of my long-term plans is this: &amp;nbsp;I don't want to be a PenTester. &amp;nbsp;I want to be a developer. &amp;nbsp;Any advice on straddling that line would also be appreciated.</description>
<category>Career, Certs, etc.</category>
<guid isPermaLink="true">http://www.ask-a-pentester.com/index.php/117/defensive-programming--second-steps</guid>
<pubDate>Sat, 30 Apr 2011 17:59:02 +0000</pubDate>
</item>
<item>
<title>Identify HTTP or SSL running on non-standard ports</title>
<link>http://www.ask-a-pentester.com/index.php/106/identify-http-or-ssl-running-on-non-standard-ports</link>
<description>Let's say I'm scanning both IPv4 (4 /8 e.g. all of RFC1918, plus 1 more) and IPv6 (a few /48) networks.&lt;br /&gt;
&lt;br /&gt;
How do I come up with a list of HTTP and SSL ports that I can connect to when they are running on non-standard ports quickly and easily?&lt;br /&gt;
&lt;br /&gt;
What if I also want to grab their banners? What if I wanted to partially customize the URI, HTTP methods, or HTTP headers? What if I wanted to send a follow-up request depending on the HTTP response from the first request?&lt;br /&gt;
&lt;br /&gt;
What is the most optimized way to do this?</description>
<category>Web Hacking</category>
<guid isPermaLink="true">http://www.ask-a-pentester.com/index.php/106/identify-http-or-ssl-running-on-non-standard-ports</guid>
<pubDate>Tue, 05 Apr 2011 21:17:35 +0000</pubDate>
</item>
<item>
<title>Wget download ONLY PHP file</title>
<link>http://www.ask-a-pentester.com/index.php/78/wget-download-only-php-file</link>
<description>&lt;p&gt;
	Hi everyone,&lt;/p&gt;
&lt;p&gt;
	&amp;nbsp;&lt;/p&gt;
&lt;p&gt;
	this is a lame-ass question but I couldn't find an answer easily just googling around.&lt;/p&gt;
&lt;p&gt;
	I want to download a .PHP file from a webserver but the original file, not the file once interpreted by the web browser.&lt;/p&gt;
&lt;p&gt;
	What happens when I just do&lt;/p&gt;
&lt;blockquote&gt;
	&lt;p&gt;
		&lt;span style=&quot;font-family: Courier New,Courier,monospace;&quot;&gt;wget http://the.webserver.com/file.php&lt;/span&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;
	is that the server &lt;strong&gt;processes the PHP code&lt;/strong&gt; and I end up with the result &lt;strong&gt;instead of the original code.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;
	Is there even a way to do this?&lt;/p&gt;
&lt;p&gt;
	&amp;nbsp;&lt;/p&gt;
&lt;p&gt;
	Thanks in advance!&lt;/p&gt;
&lt;p&gt;
	Greg&lt;/p&gt;</description>
<category>Tools</category>
<guid isPermaLink="true">http://www.ask-a-pentester.com/index.php/78/wget-download-only-php-file</guid>
<pubDate>Mon, 07 Mar 2011 14:41:10 +0000</pubDate>
</item>
<item>
<title>THE question: CEH or OSCP?</title>
<link>http://www.ask-a-pentester.com/index.php/71/the-question-ceh-or-oscp</link>
<description>Hi guys,&lt;br /&gt;
&lt;br /&gt;
&amp;nbsp;&lt;br /&gt;
&lt;br /&gt;
I want to make a career in offensive security/pentesting (name it as you want). I know that apart from real experience it's important to be certified, but I can't make up my mind between those two (CEH or OSCP).&lt;br /&gt;
&lt;br /&gt;
Any suggestions?&lt;br /&gt;
&lt;br /&gt;
&amp;nbsp;&lt;br /&gt;
&lt;br /&gt;
Thanks in advance!</description>
<category>Career, Certs, etc.</category>
<guid isPermaLink="true">http://www.ask-a-pentester.com/index.php/71/the-question-ceh-or-oscp</guid>
<pubDate>Sat, 19 Feb 2011 09:34:22 +0000</pubDate>
</item>
<item>
<title>What methodology you use in a pentest?</title>
<link>http://www.ask-a-pentester.com/index.php/70/what-methodology-you-use-in-a-pentest</link>
<description>I mean, do you follow some standard (like OSSTMM, to mention one) or do you just do like me in the hospital, that is, whathever the fuck I want? ;)&lt;br /&gt;
&lt;br /&gt;
&amp;nbsp;&lt;br /&gt;
&lt;br /&gt;
Thanks in advance!&lt;br /&gt;
&lt;br /&gt;
Greg</description>
<category>Frameworks</category>
<guid isPermaLink="true">http://www.ask-a-pentester.com/index.php/70/what-methodology-you-use-in-a-pentest</guid>
<pubDate>Wed, 16 Feb 2011 18:56:52 +0000</pubDate>
</item>
<item>
<title>SVN update via a web proxy?</title>
<link>http://www.ask-a-pentester.com/index.php/66/svn-update-via-a-web-proxy</link>
<description>Hello.&lt;br /&gt;
&lt;br /&gt;
When on site pen testing you often have to use a web proxy to get internet access.&lt;br /&gt;
&lt;br /&gt;
If you have forgotten to 'sharpen your tools' before arriving on site is there a way to 'svn update' using a web proxy?&lt;br /&gt;
&lt;br /&gt;
I have tried edditing the '/Users/username/.subversion/servers' file however this didn't seem to do anything.&lt;br /&gt;
&lt;br /&gt;
Thanks,&lt;br /&gt;
&lt;br /&gt;
Ryan</description>
<category>Tools</category>
<guid isPermaLink="true">http://www.ask-a-pentester.com/index.php/66/svn-update-via-a-web-proxy</guid>
<pubDate>Wed, 09 Feb 2011 09:57:54 +0000</pubDate>
</item>
<item>
<title>hey guys....is their any documentation on XSSF for metasploit?</title>
<link>http://www.ask-a-pentester.com/index.php/59/hey-guys-is-their-any-documentation-on-xssf-for-metasploit</link>
<description></description>
<category>Frameworks</category>
<guid isPermaLink="true">http://www.ask-a-pentester.com/index.php/59/hey-guys-is-their-any-documentation-on-xssf-for-metasploit</guid>
<pubDate>Thu, 20 Jan 2011 15:54:25 +0000</pubDate>
</item>
<item>
<title>SAP security research, first steps?</title>
<link>http://www.ask-a-pentester.com/index.php/53/sap-security-research-first-steps</link>
<description>Hi everyone,&lt;br /&gt;
&lt;br /&gt;
I would like to start learning and experimenting with SAP security because... well, because one can do a lot of money in the field, I've heard ;)&lt;br /&gt;
&lt;br /&gt;
Unfortunately I find it quite difficult to get either SAP software or documentation.&lt;br /&gt;
&lt;br /&gt;
Could anyone please give me some advice?&lt;br /&gt;
&lt;br /&gt;
&amp;nbsp;&lt;br /&gt;
&lt;br /&gt;
I would appreciate it very much!&lt;br /&gt;
&lt;br /&gt;
Rey Misterio</description>
<category>Web Hacking</category>
<guid isPermaLink="true">http://www.ask-a-pentester.com/index.php/53/sap-security-research-first-steps</guid>
<pubDate>Tue, 18 Jan 2011 08:17:46 +0000</pubDate>
</item>
<item>
<title>Which guide would you recommend to understand Backtrack</title>
<link>http://www.ask-a-pentester.com/index.php/39/which-guide-would-you-recommend-to-understand-backtrack</link>
<description>Should i take a general guide about linux and specific ones for the different applications&lt;br /&gt;
&lt;br /&gt;
or a general guide about backtrack ?</description>
<category>Distros</category>
<guid isPermaLink="true">http://www.ask-a-pentester.com/index.php/39/which-guide-would-you-recommend-to-understand-backtrack</guid>
<pubDate>Fri, 14 Jan 2011 10:56:31 +0000</pubDate>
</item>
<item>
<title>Club Mate or Jolt Cola for Pen Testing?</title>
<link>http://www.ask-a-pentester.com/index.php/35/club-mate-or-jolt-cola-for-pen-testing</link>
<description></description>
<guid isPermaLink="true">http://www.ask-a-pentester.com/index.php/35/club-mate-or-jolt-cola-for-pen-testing</guid>
<pubDate>Fri, 14 Jan 2011 06:23:09 +0000</pubDate>
</item>
<item>
<title>Tool / Method for unknown network binary protocol analysis?</title>
<link>http://www.ask-a-pentester.com/index.php/30/tool-method-for-unknown-network-binary-protocol-analysis</link>
<description>Hi everyone,&lt;br /&gt;
&lt;br /&gt;
&amp;nbsp;&lt;br /&gt;
&lt;br /&gt;
I want to perform some analysis on a propietary network protocol in order to identify *some* structure. The purpose behind this is to fuzz the packets and... well you know, pwn it ;)&lt;br /&gt;
&lt;br /&gt;
Is there any tool /script which I could feed with different packet captures and identify constant fields, etc. ?&lt;br /&gt;
&lt;br /&gt;
Or do I need to put this coding fingers to work?&lt;br /&gt;
&lt;br /&gt;
&amp;nbsp;&lt;br /&gt;
&lt;br /&gt;
Thanks in advance!</description>
<category>Reverse Eng.</category>
<guid isPermaLink="true">http://www.ask-a-pentester.com/index.php/30/tool-method-for-unknown-network-binary-protocol-analysis</guid>
<pubDate>Thu, 13 Jan 2011 10:53:14 +0000</pubDate>
</item>
<item>
<title>Best (and updated) fuzzing tools?</title>
<link>http://www.ask-a-pentester.com/index.php/25/best-and-updated-fuzzing-tools</link>
<description>&lt;p&gt;
	Hi everyone,&lt;/p&gt;
&lt;p&gt;
	&amp;nbsp;&lt;/p&gt;
&lt;p&gt;
	what are the best &lt;strong&gt;&lt;em&gt;file format&lt;/em&gt; fuzzing tools&lt;/strong&gt; out there?&lt;/p&gt;
&lt;p&gt;
	I've checked for example &lt;em&gt;FileFuzz &lt;/em&gt;but it's bit simple and outdated.&lt;/p&gt;
&lt;p&gt;
	What do you use?&lt;/p&gt;
&lt;p&gt;
	&amp;nbsp;&lt;/p&gt;
&lt;p&gt;
	Thanks in advance!&lt;/p&gt;
&lt;p&gt;
	Rey Misterio&lt;/p&gt;</description>
<category>Tools</category>
<guid isPermaLink="true">http://www.ask-a-pentester.com/index.php/25/best-and-updated-fuzzing-tools</guid>
<pubDate>Fri, 07 Jan 2011 07:45:28 +0000</pubDate>
</item>
<item>
<title>Could anybody explain me how does a &quot;bit flipping&quot; attack work?</title>
<link>http://www.ask-a-pentester.com/index.php/22/could-anybody-explain-me-how-does-a-bit-flipping-attack-work</link>
<description>Hi,&lt;br /&gt;
&lt;br /&gt;
I'm auditing a custom web application for a customer, concretely the crypto part of it. I've managed to get some encrypted data in transit from a client browser to the webserver. Since I know the format of the cleartext (it's documented) a colleague suggested that we could try a &amp;quot;bit flipping&amp;quot; attack.&lt;br /&gt;
&lt;br /&gt;
I've read about it online but I don't quite grasp it.&lt;br /&gt;
&lt;br /&gt;
Could anybody please explain it to me (with as little algebra as possible? ;))&lt;br /&gt;
&lt;br /&gt;
&amp;nbsp;&lt;br /&gt;
&lt;br /&gt;
Thanks in advance!&lt;br /&gt;
&lt;br /&gt;
Rey Misterio</description>
<category>Programming</category>
<guid isPermaLink="true">http://www.ask-a-pentester.com/index.php/22/could-anybody-explain-me-how-does-a-bit-flipping-attack-work</guid>
<pubDate>Wed, 05 Jan 2011 12:29:11 +0000</pubDate>
</item>
<item>
<title>has anyone ever done some sort of &quot;Active Directory&quot; forensics?</title>
<link>http://www.ask-a-pentester.com/index.php/14/has-anyone-ever-done-some-sort-of-active-directory-forensics</link>
<description>Does it make sense to think about Active Directory forensics? For example if i change a password,will there be a timestamp?</description>
<guid isPermaLink="true">http://www.ask-a-pentester.com/index.php/14/has-anyone-ever-done-some-sort-of-active-directory-forensics</guid>
<pubDate>Mon, 13 Dec 2010 18:17:00 +0000</pubDate>
</item>
<item>
<title>About &quot;NOP&quot; slides in JS Heap Overflows</title>
<link>http://www.ask-a-pentester.com/index.php/9/about-nop-slides-in-js-heap-overflows</link>
<description>I don't understand how 0x0c0c can be used as a &amp;quot;NOP&amp;quot; slide in Javascript's Heap Overflows. Can anybody please explain it to me?&lt;br /&gt;
&lt;br /&gt;
Thanks in advance! :)</description>
<category>Exploit devel.</category>
<guid isPermaLink="true">http://www.ask-a-pentester.com/index.php/9/about-nop-slides-in-js-heap-overflows</guid>
<pubDate>Sun, 12 Dec 2010 13:55:06 +0000</pubDate>
</item>
<item>
<title>How can I protect myself against Firesheep?</title>
<link>http://www.ask-a-pentester.com/index.php/6/how-can-i-protect-myself-against-firesheep</link>
<description>I have read about Firesheep and it scared the hell out of me ;)&lt;br /&gt;
&lt;br /&gt;
Is there anything I can do to protect myself?&lt;br /&gt;
&lt;br /&gt;
&amp;nbsp;&lt;br /&gt;
&lt;br /&gt;
Thanks!</description>
<category>Web Hacking</category>
<guid isPermaLink="true">http://www.ask-a-pentester.com/index.php/6/how-can-i-protect-myself-against-firesheep</guid>
<pubDate>Thu, 25 Nov 2010 12:02:26 +0000</pubDate>
</item>
<item>
<title>What is the best book for learning Malware RE?</title>
<link>http://www.ask-a-pentester.com/index.php/3/what-is-the-best-book-for-learning-malware-re</link>
<description>I mean, is there something like &amp;quot;The Shellcoder's Handbook&amp;quot;, that is, a bible of...?</description>
<category>Reverse Eng.</category>
<guid isPermaLink="true">http://www.ask-a-pentester.com/index.php/3/what-is-the-best-book-for-learning-malware-re</guid>
<pubDate>Mon, 15 Nov 2010 12:24:17 +0000</pubDate>
</item>
<item>
<title>Can I scan for vulnerabilities with nmap?</title>
<link>http://www.ask-a-pentester.com/index.php/1/can-i-scan-for-vulnerabilities-with-nmap</link>
<description>Is there any integrated support for automatic vulnerability finding?&lt;br /&gt;
&lt;br /&gt;
Thanks!</description>
<guid isPermaLink="true">http://www.ask-a-pentester.com/index.php/1/can-i-scan-for-vulnerabilities-with-nmap</guid>
<pubDate>Sat, 13 Nov 2010 12:43:11 +0000</pubDate>
</item>
</channel>
</rss>
