RE: delving deeper

From: David Taylor (David.Taylor_at_austrac.gov.au)
Date: 12/15/04

  • Next message: Erik Pace Birkholz: "Re: Penetration Testing Methodologies"
    Date: Wed, 15 Dec 2004 11:16:54 +1100
    To: "xyberpix" <xyberpix@xyberpix.com>, "Chris Benedict" <chrisb@daemonnews.org>
    
    

    My favourite is whoppix, another knoppix variant that has a large body
    of exploits included.

    www.whoppix.net And the site even has some nice demos to get you going
    :)

    Regards
    David Taylor

    -----Original Message-----
    From: xyberpix [mailto:xyberpix@xyberpix.com]
    Sent: Wednesday, 15 December 2004 4:00 AM
    To: Chris Benedict
    Cc: pen-test@securityfocus.com
    Subject: Re: delving deeper

    Hi Chris,

    Go and download a copy of PHLAK(http://www.phlak.org), there's a load of
    good docs on the disc, and some really good tools to get you going.
    Above
    it all it's Linux, so it should run on your machines.
    Aside from that scour the net for anything pertaining to pen testing and
    security, and read as much as you can possibly tollerate, it'll be worth
    it in the end.

    xyberpix

    On Mon, 13 December, 2004 10:34 pm, Chris Benedict said:
    > Hi, I've been looking at security and penetration-testing for some
    > time now and would like to get further into it. I'd like to learn
    > more about penetration-testing, forensics, techniques for network
    > exploration/mapping, web application security and incedent handling.
    > However I'm not really sure where to start, I looked at the OSSTMM and
    > it was above my head.
    >
    > At the moment I have a very limited budget and only a few spare
    > low-end computers. If it matters, I'm mainly running OpenBSD. Are
    > there any particular books or other media that I should take a look
    at?
    >
    > Any thoughts or recommendations are welcomed and greatly appreciated.
    >
    > -Chris Benedict
    >

    -- 
    For security and Opensource news check out:
    http://www.xyberpix.com
    **********************************************************************
    Please  note  that  your  email address  is known to  AUSTRAC  for the
    purposes  of  communicating with you.  The information  transmitted in
    this  e-mail is  for the  use of  the intended  recipient only and may
    contain confidential and/or legally  privileged  material. If you have
    received  this information  in error you must not disseminate, copy or
    take  any  action on  it and we  request that you delete all copies of
    this transmission together with attachments and notify the sender.
    This footnote also confirms that this email message has been swept for
    the presence of computer viruses.
    **********************************************************************
    

  • Next message: Erik Pace Birkholz: "Re: Penetration Testing Methodologies"

    Relevant Pages

    • [NT] Questionable Security Policies in Outlook 2002
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... A number of questionable security policies in Outlook 2002 which allow the ... The download happens when the email message is ... email message plus a second copy of the link in an attached .URL file. ...
      (Securiteam)
    • "BabySenSible" email prompting for password
      ... I just received an email message using Outlook with subject ... references site 217.37.152.185. ... software on my system (virus software, ... this thing executing without triggering a security alert of some sort. ...
      (microsoft.public.security)
    • Re: Email merge with Word
      ... We are not using an Exchange Server, so I guess I am stuck with the security ... > Not if you use HTML format for the email message merge. ... you can use a security policy to remove the prompts from ...
      (microsoft.public.outlook)
    • RE: Is it bad enough to resign?
      ... If you are in a situation where you do not have a security policy in place ... Any situation where you have hostile upper management and no policies is ... Everything expressed within this email message is the personal opinion of ...
      (Security-Basics)
    • delving deeper
      ... I've been looking at security and penetration-testing for some ... web application security and incedent handling. ... If it matters, I'm mainly running OpenBSD. ... there any particular books or other media that I should take a look at? ...
      (Pen-Test)