Chercher :
Newsletter :  


Revues :
- Presse
- Presse FR
- Vidéos
- Twitter
- Secuobs





Sommaires :
- Tendances
- Failles
- Virus
- Concours
- Reportages
- Acteurs
- Outils
- Breves
- Infrastructures
- Livres
- Tutoriels
- Interviews
- Podcasts
- Communiques
- USBsploit
- Commentaires


Revue Presse:
- Tous
- Francophone
- Par mot clé
- Par site
- Le tagwall


Top bi-hebdo:
- Ensemble
- Articles
- Revue
- Videos
- Twitter
- Auteurs


Articles :
- Par mot clé
- Par auteur
- Par organisme
- Le tagwall


Videos :
- Toutes
- Par mot clé
- Par site
- Le tagwall


Twitter :
- Tous
- Par mot clé
- Par compte
- Le tagwall


Commentaires :
- Breves
- Virus
- Failles
- Outils
- Tutoriels
- Tendances
- Acteurs
- Reportages
- Infrastructures
- Interviews
- Concours
- Livres
- Communiques


RSS/XML :
- Articles
- Commentaires
- Revue
- Revue FR
- Videos
- Twitter


RSS SecuObs :
- sécurité
- exploit
- windows
- attaque
- outil
- microsoft


RSS Revue :
- security
- microsoft
- windows
- hacker
- attack
- network


RSS Videos :
- curit
- security
- biomet
- metasploit
- biometric
- cking


RSS Twitter :
- security
- linux
- botnet
- attack
- metasploit
- cisco


RSS Comments :
- Breves
- Virus
- Failles
- Outils
- Tutoriels
- Tendances
- Acteurs
- Reportages
- Infrastructures
- Interviews
- Concours
- Livres
- Communiques


RSS OPML :
- Français
- International











Revue de presse francophone :
- Fintech Paymium lève 1 million d'euros
- VMware présente vSphere Integrated Containers et Photon Platform
- Vigilance - TYPO3 Core six vulnérabilités, analysé le 02 07 2015
- Vigilance - Noyau Linux boucle infinie de perf_callchain_user_64, analysé le 18 08 2015
- Vigilance - Drupal Migrate Cross Site Scripting, analysé le 02 07 2015
- Vigilance - Drupal Views Bulk Operations élévation de privilèges, analysé le 02 07 2015
- Vigilance - Noyau Linux fuite de descripteur via VHOST_SET_LOG_FD, analysé le 18 08 2015
- Vigilance - Joomla swMenuFree permissions de dossiers incorectes, analysé le 01 07 2015
- Vigilance - WordPress Count Per Day injection SQL, analysé le 01 07 2015
- Vigilance - WordPress qTranslate Cross Site Scripting, analysé le 01 07 2015
- Vigilance - WordPress Paid Memberships Pro Cross Site Scripting, analysé le 01 07 2015
- Vigilance - Magento Cross Site Scripting de description, analysé le 01 07 2015
- Nouveau rapport McAfee Labs retour sur le deuxième trimestre 2015 et rétrospective de l'évolution des menaces informatiques entre 2010 et 2015
- Nouveaux disques Enterprise Capacity 3.5, Enterprise NAS et Kinetic HDDs de 8 To
- Seagate Technology plc lance un disque dur d'une capacité atteignant 2 To

Dernier articles de SecuObs :
- Renaud Bidou (Deny All): "L'innovation dans le domaine des WAFs s'oriente vers plus de bon sens et d'intelligence, plus de flexibilité et plus d'ergonomie"
- Mises à jour en perspective pour le système Vigik
- Les russes ont-ils pwn le système AEGIS ?
- Le ministère de l'intérieur censure une conférence au Canada
- Saut d'air gap, audit de firmware et (in)sécurité mobile au programme de Cansecwest 2014
- GCHQ: Le JTRIG torpille Anonymous qui torpille le JTRIG (ou pas)
- #FIC2014: Entrée en territoire inconnu
- Le Sénat investit dans les monnaies virtuelles
- #LPM2013: Un nouvel espoir ?
- L'ANSSI durcit le ton

Revue de presse internationale :
- Recycled Factory Recycles Soda Bottles
- Snoopers Charter will cause extreme rise in business costs
- Start of the Polyscopy Project
- Inside the police sting that netted one of the world's largest paedophile rings
- Allinchrome.com
- The Ashley Madison Hack A Timeline
- Whats burning up resources for IT pros during the summer
- Verizon and Splunk deliver actionable threat intelligence
- SSD Advisory IMail Cross Site Scripting
- Hackaday Prize Semifinalist Bendy Solar Bluetooth Tags
- VMworld2015 Business Mobility Made Easy with F5 and VMware feat. Venezia
- EEVblog 790 Lecroy Wavejet 354 Touch Oscilloscope Teardown
- Turkey Arrests Journalists For Using Encryption
- Nuclear Reactor Eye Candy From Around the World
- dnSpy a .NET assembly editor, decompiler and debugger forked from ILSpy

Annuaire des videos
- FUZZING ON LINE PART THREE
- Official Maltego tutorial 5 Writing your own transforms
- Official Maltego tutorial 6 Integrating with SQL DBs
- Official Maltego tutorial 3 Importing CSVs spreadsheets
- install zeus botnet
- Eloy Magalhaes
- Official Maltego tutorial 1 Google s websites
- Official Maltego tutorial 4 Social Networks
- Blind String SQL Injection
- backdoor linux root from r57 php shell VPS khg crew redc00de
- How To Attaque Pc With Back Track 5 In Arabique
- RSA Todd Schomburg talks about Roundup Ready lines available in 2013
- Nessus Diagnostics Troubleshooting
- Panda Security Vidcast Panda GateDefender Performa Parte 2 de 2
- MultiPyInjector Shellcode Injection

Revue Twitter
- RT @fpalumbo: Cisco consistently leading the way ? buys vCider to boost its distributed cloud vision #CiscoONE
- @mckeay Looks odd... not much to go on (prob some slideshow/vid app under Linux)
- [SuggestedReading] Using the HTML5 Fullscreen API for Phishing Attacks
- RT @BrianHonan: Our problems are not technical but cultural. OWASP top 10 has not changed over the years @joshcorman #RSAC
- RT @mikko: Wow. Apple kernels actually have a function called PE_i_can_has_debugger:
- [Blog Spam] Metasploit and PowerShell payloads
- PinkiePie Strikes Again, Compromises Google Chrome in Pwnium Contest at Hack in the Box: For the second time thi...
- @mikko @fslabs y'all wldn't happen to have lat/long data sets for other botnets, wld you? Doing some research (free/open info rls when done)
- RT @nickhacks: Want to crash a remote host running Snow Leopard? Just use: nmap -P0 -6 --script=targets-ipv6-multicast-mld #wishiwaskidding
- An inexpensive proxy service called is actually a front for #malware distribution -

Mini-Tagwall
Revue de presse : security, microsoft, windows, hacker, attack, network, vulnerability, google, exploit, malware, internet, remote, iphone

+ de mots clés pour la revue de presse

Annuaires des videos : curit, security, biomet, metasploit, biometric, cking, password, windows, botnet, defcon, tutorial, crypt, xploit

+ de mots clés pour les videos

Revue Twitter : security, linux, botnet, attack, metasploit, cisco, defcon, phish, exploit, google, inject, server, firewall

+ de mots clés pour la revue Twitter

Top bi-hebdo des articles de SecuObs
- [Sécurité et PHP - Partie 3] Les failles PHP
- Utiliser google comme un outil de pen-testing (Johnny Long - Blackhat 2005)
- Maltego un outil de cartographie d’informations
- Les avancées de DeDECTed pour l'écoute et l'enregistrement des appels effectués via les téléphones DECT
- EFIPW récupère automatiquement le mot de passe BIOS EFI des Macbook Pro avec processeurs Intel
- [IDS Snort Windows – Partie 2] Installation et configuration
- XMPPloit, un outil exploitant les vulnérabilités XMPP
- USBDumper 2 nouvelle version nouvelles fonctions !
- [Ettercap – Partie 2] Ettercap par l'exemple - Man In the Middle et SSL sniffing
- Mises à jour en perspective pour le système Vigik

Top bi-hebdo de la revue de presse
- FakeNet Windows Network Simulation Tool For Malware Analysis
- Titan Datacenter annonce la création d'un Datacentre de nouvelle génération
- Smart City le citoyen est devenu un acteur 2.0 de sa ville
- SCADA Siemens Simatic, une famille qui collectionne les trous
- Xerox, du DRM dans les cartouches d imprimante
- Hadopi décapitée
- Fuites Ashley Madison, le syndrome Pastebin
- 21 septembre Paris Lundi de l'IE - Cybercriminalité Prévention et réactivité
- Remote Server Administration Tools for Windows 10 Released
- Windows 10 tools MDT 2013 Update 1, Windows ADK for Windows 10, MDOP 2015, and RSAT

Top bi-hebdo de l'annuaire des videos
- sniff password using Wireshark
- MaltegoCE Bugtraq Final t31m0
- Tutoriel Supprimer Cacaoweb Botnet
- Bugtraq 2 Blackwidow Botnets Crypters
- Avoir des donuts illimit s sur le jeu Simpsons Springfield
- kali linux Collecte d adresses Email avec Metasploit
- Comment Pirater Un Ordinateur Avec Ubuntu Metasploit
- configuration in gns3 dual wan setup and vmware pfsense 2 0 lusca cache
- Hacking Apache Tomcat 5 5 on Metasploitable ClubHACK Tutorials by Nishant Das Patnaik
- Official Maltego tutorial 4 Social Networks

Top bi-hebdo de la revue Twitter
- “@michaeldinn: @Wh1t3Rabbit as an #infosec enabled human, would you store e-voting data in the cloud?” You're going to gave to qualify
- UPDATE: Nessus 5.0.2!
- RT @PowerDNS_Bert: @kolkman Please don't say DNSSEC would've prevented the problem though ;-)
- RT @StopMalvertisin: MMPC | MSRT thwarts rogues with just one scan
- I think this months price for verified longest lifespan of a 0-day goes with 540 days to #SAP for DSECRG-12-036 ;(
- An inexpensive proxy service called is actually a front for #malware distribution -
- RT @curqq: I am a big fan of irony. Downloading a whitepaper on security from Huawei in PDF format. Worth getting pwned for
- Unnamed teenage #security researcher produces full exploit, sandbox escape included, of @Google's Chrome... again:
- Cisco Systems ends ZTE partnership
- RT @mdowd: Our iOS6 presentation slides are available on the HITB website:

Top des articles les plus commentés
- [Metasploit 2.x – Partie 1] Introduction et présentation
- Microsoft !Exploitable un nouvel outil gratuit pour aider les développeurs à évaluer automatiquement les risques
- Webshag, un outil d'audit de serveur web
- Les navigateurs internet, des mini-systèmes d’exploitation hors de contrôle ?
- Yellowsn0w un utilitaire de déblocage SIM pour le firmware 2.2 des Iphone 3G
- CAINE un Live[CD|USB] pour faciliter la recherche légale de preuves numériques de compromission
- Nessus 4.0 placé sous le signe de la performance, de l'unification et de la personnalisation
- [Renforcement des fonctions de sécurité du noyau Linux – Partie 1] Présentation
- [IDS Snort Windows – Partie 1] Introduction aux IDS et à SNORT
- Origami pour forger, analyser et manipuler des fichiers PDF malicieux

Passing the SANS SEC504 Hacker Techniques, Exploits Incident Handling Exam

Si vous voulez bloquer ce service sur vos fils RSS
Si vous voulez nous contacter ou nous proposer un fil RSS

Menu > Articles de la revue de presse : - l'ensemble [tous | francophone] - par mots clé [tous] - par site [tous] - le tagwall [voir] - Top bi-hebdo de la revue de presse [Voir]

S'abonner au fil RSS global de la revue de presse



Passing the SANS SEC504 Hacker Techniques, Exploits Incident Handling Exam

Par Security Bloggers Network
Le [2012-12-23] à 00:58:50



Présentation : I recently attended a SANS class a few months back, SEC504 Hacker Techniques, Exploits Incident Handling , and I must say, it was awesome. The course goes into detail on the techniques exploits hackers use in today s threat landscape and ways for incident handlers prevent, detect and eradicate threats. The cost of the training and the exam was expensive, but it was worth every dollar being able to spend 6 days with like-minded professionals all hacking the day away. Leaving the course I felt a renewed confidence in my skills and learned a few new tools that I wasn t familiar with before, than I began studying for the exam. Let me preface this by saying, exams and certifications don t make you a better security pro, all they do is show others that you have the knowledge to pass the certification. In many cases this means that people have diluted both the exam and the certification by dumping for the test and just end up collecting credentials without knowledge or experience. This hurts both the people that have worked very hard to pass the exam and the cheater themselves by falsifying their knowledge. Anyway, I digress. Now having said this I m not going to give away any questions or topics that are on the exam, that would defeat the purpose of this blog post, but I do want to give a few helpful hints regarding studying for the exam. During our class our instructor gave us a heads up on a few ways to prepare for the test and I have a few that helped me tremendously as well. First, lets lay down the rules of the exam and what to expect The exam is completely open book. Yeah, I know easy right. Not. The proctor looked at me weird when I told her it was an open test and made me prove to her that it was. This is your first tip, bring your confirmation proving that it's open book. She than went on to say that open book tests are normally much harder, this time she was right. You re allowed to bring in arms full of books to the exam that you fell will help you in your attempt. If you ve taken the course you ve been given the adequate material to pass the exam and don t need additional material, unless you want it, but you have what s needed to assist you with the exam. If you didn t take the course I would highly recommend reading Counter Hack Reloaded A Step-by-Step Guide to Computer Attacks and Effective Defenses by Ed Skoudis. Not only is this book awesome and fits right into the course material, but Ed Skoudis founded this course and teaches it. So pick it up if you re not able to attend the training, it will surely help with the exam and your knowledge in general. There are right out of the book answers , but material that will jog your memory. If you don't know the course work the books will be useless. For the exam you get 4 hours to complete 150 questions. That might seem like a lot of time, but when you re flipping through books for a question you re unsure of the time flies by quickly. You also get a 15-minute break that stops the clock to stretch and clear your mind. I highly suggest you use it when you hit question 75 to give your brain a break. The course is also multiple choices, but that doesn t always make it easier, and many times I found it more difficult to pick only one answer. During the test you ll have the score displayed every 15 questions as a meter of how you re doing. This can be either very reassuring if you re doing well, or a way to set you into a panic if you re not cutting the mustard. The passing grade for the exam is a 72, so knowing where you stand during the exam can be a two edged sword. Now for the studying tips If you ve attended the course or you re self studying I would highly recommend pouring over the material before taking the exam. Prepare yourself with the materials you have, otherwise you ll be in for a long test. Tab your books with sticky notes so that you ll be able to quickly find topics as they come up. This is one of the most important areas of preparation during the exam that I couldn t emphasis enough. If you re unable to answer the question without research you need to quickly find where the topic might be in your books. Having sticky notes lined on the side of it is a quick way to do this, especially if you re using five or more books. Read through all your material and keep notes. You re also allowed to bring in notes to the exam that you ve written or printed out. Find areas that you might be weak in that will help jog your memory. I used the course books and kept a spreadsheet of all the tools mentioned, the book they were in the page within that book so I could quickly divert to page in a book if there were specifics about a tool I wanted to verify during the exam. If you ve taken the course you ll get a few things on your SANS account that I wasn t aware of until I logged into the site. Within my account I was given two practice tests that were similar to the experience of the actual test just with different questions and mp3 s of the same course by Ed Skoudis. I can t tell you how valuable those mp3s were and after reading the books again, I listed to the mp3 s by Ed on my way to work, lunch, etc. to prepare for the exam. I read a review about Ed Skoudis s teaching and it went like this, Ed is able to harness the English language like a weapon and I couldn t agree more. He s a wonderful teacher and really helped me grasp many topics. Also, if you're not going to use the practice exams you're able to give them away to someone else during their studies. So that being said, please try to take a SANS course if you re able to, they re terrific. The SEC504 Hacker Techniques, Exploits Incident Handling in particular was a great learning experience that will help me professionally for years to come.

Les mots clés de la revue de presse pour cet article : hacker
Les videos sur SecuObs pour les mots clés : hacker
Les éléments de la revue Twitter pour les mots clé : hacker



AddThis Social Bookmark Widget



Les derniers articles du site "Security Bloggers Network" :

- The Ashley Madison Hack A Timeline
- SSD Advisory IMail Cross Site Scripting
- VMworld2015 Business Mobility Made Easy with F5 and VMware feat. Venezia
- VMworld 2015 Keynote Day 2 Microsoft and VMware Team up for Windows 10 Management and VMware Releases NSX 6.2
- VMworld 2015 Breifings Nutanix Leverages Hyper-Convergence to Simply Infrastructure Management
- Making Threat Intelligence Actionable through Unparalleled Visibility and Analytics
- SC Magazine Invincea Advanced Endpoint Protection AEP
- Microsoft to Retire the Intune Portal, Merge it into Office 365
- How Startups Are Transforming the Smart City Movement
- Cyveillance Weekly Threat Intelligence Brief September 1, 2015




S'abonner au fil RSS global de la revue de presse

Menu > Articles de la revue de presse : - l'ensemble [tous | francophone] - par mots clé [tous] - par site [tous] - le tagwall [voir] - Top bi-hebdo de la revue de presse [Voir]



Si vous voulez bloquer ce service sur vos fils RSS :
- avec iptables "iptables -A INPUT -s 88.190.17.190 --dport 80 -j DROP"
- avec ipfw et wipfw "ipfw add deny from 88.190.17.190 to any 80"
- Nous contacter par mail




SecuToolBox :

Mini-Tagwall des articles publiés sur SecuObs :

Mini-Tagwall de l'annuaire video :

Mini-Tagwall des articles de la revue de presse :

Mini-Tagwall des Tweets de la revue Twitter :