<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>elamb &#187; CEH</title>
	<atom:link href="http://elamb.org/category/ceh/feed/" rel="self" type="application/rss+xml" />
	<link>http://elamb.org</link>
	<description>information system security, risk management, scam research</description>
	<lastBuildDate>Mon, 28 Nov 2011 02:27:55 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>The Value of a (Ethical Hacker) Certification</title>
		<link>http://elamb.org/the-value-of-a-ethical-hacker-certification/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=the-value-of-a-ethical-hacker-certification</link>
		<comments>http://elamb.org/the-value-of-a-ethical-hacker-certification/#comments</comments>
		<pubDate>Thu, 26 Jun 2008 05:30:47 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
				<category><![CDATA[CEH]]></category>
		<category><![CDATA[Certification]]></category>
		<category><![CDATA[Certification/CISSP]]></category>
		<category><![CDATA[Certification/Security+]]></category>
		<category><![CDATA[Main Digg]]></category>
		<category><![CDATA[hacker]]></category>

	<!-- AutoMeta Start -->
	<category>donâ ™t</category>
	<category>ceh</category>
	<category>certifications</category>
	<category>suppose</category>
	<category>havenâ ™t</category>
	<category>cissp</category>
	<category>consistent</category>
	<category>certification</category>
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/the-value-of-a-ethical-hacker-certification/</guid>
		<description><![CDATA[Ok, I admit it. I have totally slacked off on getting that CEH certification. Iâ€™ve had the boot camp, Iâ€™ve amassed lots of great books and resources, Iâ€™ve even talked to some people who have passed it, but I still &#8230; <a href="http://elamb.org/the-value-of-a-ethical-hacker-certification/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p> Ok, I admit it.  I have totally slacked off on getting that CEH certification.  Iâ€™ve had the boot camp, Iâ€™ve amassed lots of great books and resources, Iâ€™ve even talked to some people who have passed it, but I still havenâ€™t been consistent about studying.  For a while I was pretty consistent.  I read the Official Study Guide and started working on an Unofficial one. </p>
<p>Why donâ€™t I have that cert yet?  I suppose I just donâ€™t feel I have a reason to have it.  It would just be for show because I donâ€™t really do pen testing.  â€™d like to, but in my job, I donâ€™t usually have the opportunity to do it or reason to do it.  Iâ€™ve already got the CISSP so I donâ€™t need the CEH for some kind of prestige.  Many hackers piss on certifications they are not impressed with them and are willing hurt anyone who flashes the credentials.  The CISSP trumps most certification.  The only real benefit for me getting it is that it would force me to get more familiar with tools like netcat and Snort which I donâ€™t use enough.  I am interested in <em>cyber kung fu</em>.  Lately, I have been more drawn to the scientific and mathematical side of technology.. the side where the innovation are born, not just mastered.  Iâ€™ve been sharpening up my math skills and plan on getting into Computer Science, Electrical Engineering or physics.</p>
<p>I havenâ€™t decided whether I want to take the CEH because I want to do something that has more depth.  I suppose I could complete the CEH, go through Computer Science and specialize in security/crypto/info assurance and follow in the foot steps of Bruce Schneier and Steve Gibson.   In the beginning, certifications were definitely a step up, but Iâ€™m in a place now where they are just ornaments, flashy bobbles I could decorate my name with when  I need an ego boost.  If my wife and kids are giving me lip I can say, â€œdonâ€™t you know I am a CISSP, A+, B, C, D, E, F, G.  You MUST respect my awesome test taking ability!â€ </p>
<p>Iâ€™ve said it before, I think certifications can be of great value.  If you work for the Department of Defense in IT you pretty much MUST have one (per DoD 8570).  Certifications can give you that extra edge against competing employees in the private sector.  Problem arise when the IT certifications value is taken out of context.  Like the 8570 which makes it mandatory to have a certain certification regardless of your experience and/or degrees.  That is a bit much.  Not everyone who passes the CISSP can configure a firewall properly.   But perhaps thats the reason the DoD wants system specific certification.</p>
]]></content:encoded>
			<wfw:commentRss>http://elamb.org/the-value-of-a-ethical-hacker-certification/feed/</wfw:commentRss>
		<slash:comments>7</slash:comments>
		</item>
		<item>
		<title>Legal Hacking Cases</title>
		<link>http://elamb.org/legal-hacking-cases/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=legal-hacking-cases</link>
		<comments>http://elamb.org/legal-hacking-cases/#comments</comments>
		<pubDate>Thu, 09 Aug 2007 23:13:41 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
				<category><![CDATA[CEH]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[Main Digg]]></category>

	<!-- AutoMeta Start -->
	<category>cases</category>
	<category>btng</category>
	<category>legal</category>
	<category>search</category>
	<category>google</category>
	<category>source</category>
	<category>hacking</category>
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/legal-hacking-cases/</guid>
		<description><![CDATA[The official Certified Ethical Hacking course material identifies three types of hackers: Black Hats: criminal hackers Grey Hats: hackers that find exploits because they want to (not for good or bad intentions) White Hats: hired penetration testers The media and &#8230; <a href="http://elamb.org/legal-hacking-cases/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>The official Certified Ethical Hacking course material identifies three types of hackers:</p>
<blockquote><p><strong>Black Hats:</strong> criminal hackers</p>
<p><strong>Grey Hats:</strong> hackers that find exploits because they want to (not for good or bad intentions)</p>
<p><strong>White Hats:</strong> hired penetration testers</p></blockquote>
<p>The media and many parts of the information security profession lumps all &#8216;hackers&#8217; into one big box labeled &#8220;criminals&#8221;.Â  I used to think this way as well until I went to Defcon.Â  It was a real eye opener.Â  I saw hackers who want to do something good for the consumners.Â  I saw several government agencies attempting to hireÂ the best and brightest hackers andÂ of course, I saw hackers that may very well have been working on the darkside.Â  The point is that &#8220;hacking&#8221; itself is the just a technique to find, and exploit weakness in a given system.Â  It is not intrinsically evil.Â  Hacking is just a method, the intentÂ of the user determines whether or not there is a adverse effect on individuals, organizations or a given society.</p>
<p>Contrary to popular conservative/traditional beliefs the world is not black and white.Â  There are cases in which hacking is legal.Â  Just take a look at these legal hacking cases:</p>
<p>Ethical Hacking.Â  Involves getting formal permission from the &#8220;target&#8221; prior to hacking.</p>
<p>Hackthissite.Â  Hack this site is one of many sites that allow users to freely hack their way in.Â Â This is done for fun, for learning or just for the heck of it.Â  Typically, there are rulesÂ and guidelines that are create soÂ that the user and the host can benefit from the learning experience.Â </p>
<p><strong><a href="http://www.chillingeffects.org/reverse/faq.cgi#QID195">Reverse Engineering is Legal</a>.</strong>Â  Cases of reverse engineering have been deemed as legal in the U.S. in many other industries.Â  The legalities for reverse engineering softwareÂ are still beingÂ shaped by a new breed of cases.Â </p>
<blockquote><p>1999-2002: DVD Copy Control Association (DVD-CCA) vs. Bunner, et al.Â  The DVD-CCAÂ attempts to sue anyoneÂ distributing a descrambler softwareÂ that was created by reverse engineering their product.Â Â They even attempt to sue anyone linking to sites giving out the descrambler.Â  <a href="http://www.eff.org/IP/Video/DVDCCA_case/19991228-complaint.html">initial case</a> <a href="http://en.wikisource.org/wiki/DVD_CCA_v._McLaughlin,_et_al._PI_Order">2</a> | <a href="http://www.eff.org/IP/Video/DVDCCA_case/#bunner-press">eef involvement</a> | Â Bunner and other won the caseÂ Â *note: there were not even the ones who reverse engineered the product</p></blockquote>
<p><strong>The attempt to Legalize Intrusions for Corporations</strong>.Â  In 2002, Rep. Howard Berman (D-Calif) tried to pass a law called the <a title="Peer to Peer Prevention Act " href="http://thomas.loc.gov/cgi-bin/query/z?c107:h.r.5211:">Peer to Peer Privacy Prevention Act</a> (2002) which would have created section <a title="USC Title 17 514 " href="http://www.law.cornell.edu/uscode/html/uscode17/usc_sup_01_17_10_5.html">514 of U.S.C 17</a> Chapt 5 allowing companies to legally hack into computers to find pirated software and intellectual property and use that information in a court of law against the assailant.Â  Article on <a href="http://www.usatoday.com/tech/news/techpolicy/2002-09-25-hack_x.htm">Peer to Peer Prevention Act</a></p>
<p>Â </p>
<p><a href="http://www.google.com/search?source=ig&#038;hl=en&#038;q=legal+hacking+cases&#038;btnG=Google+Search" /></p>
<p>Â </p>
<p class="tags">Tags: <a href="http://technorati.com/tag/CEH" title="See the Technorati tag page for 'CEH'." rel="tag">CEH</a>, <a href="http://technorati.com/tag/legal" title="See the Technorati tag page for 'legal'." rel="tag">legal</a>, <a href="http://technorati.com/tag/hacking" title="See the Technorati tag page for 'hacking'." rel="tag">hacking</a>, <a href="http://technorati.com/tag/hack" title="See the Technorati tag page for 'hack'." rel="tag">hack</a>, <a href="http://technorati.com/tag/berman" title="See the Technorati tag page for 'berman'." rel="tag">berman</a>, <a href="http://technorati.com/tag/white" title="See the Technorati tag page for 'white'." rel="tag">white</a>, <a href="http://technorati.com/tag/black" title="See the Technorati tag page for 'black'." rel="tag">black</a>, <a href="http://technorati.com/tag/gray" title="See the Technorati tag page for 'gray'." rel="tag">gray</a>, <a href="http://technorati.com/tag/hat" title="See the Technorati tag page for 'hat'." rel="tag">hat</a></p>]]></content:encoded>
			<wfw:commentRss>http://elamb.org/legal-hacking-cases/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Ethical Hacking Official Course Material (Book)</title>
		<link>http://elamb.org/ethical-hacking-official-course-material-book/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=ethical-hacking-official-course-material-book</link>
		<comments>http://elamb.org/ethical-hacking-official-course-material-book/#comments</comments>
		<pubDate>Sat, 28 Jul 2007 05:00:51 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
				<category><![CDATA[CEH]]></category>
		<category><![CDATA[Main Digg]]></category>

	<!-- AutoMeta Start -->
	<category>book</category>
	<category>notable</category>
	<category>poorly</category>
	<category>grammar</category>
	<category>amazon</category>
	<category>reviews</category>
	<category>quotes</category>
	<category>council</category>
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/ethical-hacking-official-course-material-book/</guid>
		<description><![CDATA[As of July 2007, the official course material book on Ethical Hacking is going for $5 on Amazon.Â  The cover price is $70 in the US and over $100 in Canada.Â  This should tell you a lot about what people &#8230; <a href="http://elamb.org/ethical-hacking-official-course-material-book/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>As of July 2007, the official course <a href="http://www.amazon.com/gp/product/customer-reviews/0972936211/sr=8-3/qid=1185597660/ref=cm_cr_dp_hist_1/105-4852714-4550030?ie=UTF8&#038;customer-reviews.sort%5Fby=byExactRating%5F1&#038;qid=1185597660&#038;sr=8-3#customerReviews">material book on Ethical Hacking</a> is going for $5 on Amazon.Â  The cover price is $70 in the US and over $100 in Canada.Â  This should tell you a lot about what people feel about this book.</p>
<p>The <em>hate</em> for this book is so profound that it makes me laugh.</p>
<p><strong>Here are a few comments:</strong></p>
<p>&#8220;I know this has been said but it really needs emphasis. This is perhaps the most poorly written and presented compilation of misinformation I have seen since the 5th grade.&#8221;</p>
<p>&#8220;If the author of this book isn&#8217;t going to take the time to correct the misspellings and grammar issues, that speaks volumes about the quality of the content.&#8221;</p>
<p>&#8221;  The EC-Council has a great CUT and Paste method of publishing a book, they don&#8217;t even list the Author.&#8221;</p>
<p>&#8220;I agree with all the negative comments. This book is poorly written.&#8221;</p>
<p>It touches on all of the modules of the test, its just that there are so many issues with the way it is put together.Â  Its almost as if the EC Council had a week to put something together so they gathered all there slides and copied and pasted them in this book then expanded on each slide.</p>
<p>One of the Amazon readers put it well:</p>
<p><strong>Here are a few notable indicators of the quality of the book: </strong></p>
<blockquote><p>* There is no reference section or bibliography and there are only a couple references made to outside works. Most of which is the legislation they quote and a couple quotes from notable manufacturers.<br />
* They do not cite any of their quotes correctly. The closest they get is, &#8220;A quote from the Internet says&#8230;&#8221; or &#8220;(Reference: Cryptography FAQs published on the World Wide Web)&#8221; No web site, date or proper credit is ever given. I&#8217;m suprised they actually listed the URLs for the tools they discuss.<br />
* The table of contents is very high level, there is no table of figures, or table of tables. There is also no index or list of terms.<br />
* They attempt to redefine established industry terms in their own style, often incorrectly or in contradiction to earlier statements.<br />
* As noted in previous reviews, grammar, spelling and typos are prevalent throughout the book. Most notably is the pres ence of sp aces in the midd le of wo rds.</p></blockquote>
<p>When course material is this bad, it is very hard to take the certification seriously.</p>
]]></content:encoded>
			<wfw:commentRss>http://elamb.org/ethical-hacking-official-course-material-book/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Certified Ethical Hacker Exam Prep (amazon review)</title>
		<link>http://elamb.org/certified-ethical-hacker-exam-prep-amazon-review/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=certified-ethical-hacker-exam-prep-amazon-review</link>
		<comments>http://elamb.org/certified-ethical-hacker-exam-prep-amazon-review/#comments</comments>
		<pubDate>Thu, 26 Jul 2007 19:33:59 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
				<category><![CDATA[CEH]]></category>
		<category><![CDATA[Certification]]></category>
		<category><![CDATA[Main Digg]]></category>

	<!-- AutoMeta Start -->
	<category>council</category>
	<category>book</category>
	<category>prep</category>
	<category>exam</category>
	<category>amazon</category>
	<category>sybex</category>
	<category>ceh</category>
	<category>test</category>
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/certified-ethical-hacker-exam-prep-amazon-review/</guid>
		<description><![CDATA[Found a good review of Mike Greggs book,Â Certified Ethical Hacker Exam Prep from Amazon reviewer, N. Rossino (NY)Â :Â  Â  Â Â Â  The previous poster did bring up a good point: this book will not teach you how to hack. It WILL &#8230; <a href="http://elamb.org/certified-ethical-hacker-exam-prep-amazon-review/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<table cellspacing="0" cellpadding="0" border="0">
<tr>
<td valign="top">Found a good review of Mike Greggs book,Â Certified Ethical Hacker Exam Prep from Amazon reviewer, <a title="Book Review: Certified Ethical Hacker Exam Prep" href="http://www.amazon.com/gp/pdp/profile/ATJAWR2UAIZG8/ref=cm_cr_auth/104-0585998-9487941">N. Rossino</a> (NY)Â :Â </p>
<p>Â </td>
<td>Â Â Â </td>
</tr>
</table>
<p>The previous poster did bring up a good point: this book will not teach you how to hack. It WILL help you pass the CEH exam. It lays a very good foundation, and the only reason I give it 4 stars was because it was lacking the detail and depth to be fully comprehensive.</p>
<p>Keep in mind, that this book is meant for people who do have an administration background and who happen to be pretty familiar with Linux and Windows. The book is written for that group of people because without that experience, you probably won&#8217;t have the experience necessary to be a CEH.</p>
<p>I happen to read all 3 books for the CEH that are listed on Amazon. The Sybex book, the EC-council book, and this book. By far, this book was the best out of the 3. The Sybex book was a waste of money as it wasn&#8217;t as good as this book and it had even less depth. The EC-council book had a bit more detail in some topics, although it lacked cohesion and was poor at presenting the thought behind it. I think this book and the EC-council book compliment each other, and give you a pretty good idea of what you actually need to know. I would start with this book and finish up with the EC-council book and/or courseware. My reasoning is that you should set the foundation first and this book does that.</p>
<p>Also, as with hacking, google is an excellent resource. These two books won&#8217;t be enough to fill all the holes, but the internet is a damned good filler.</p>
<p>In conclusion this book provides for pretty good preparation for the actual test, and is a comfortable read.</p>
<p>ABOUT THE TEST:</p>
<p>150 questions, you have 4 hours. I took only 2 and scored an 86%. 70% is passing. I studied for only two weeks, but have extensive background in the subject area.</p>
<p>The test is very specific, and you are expected to know the material in detail &#8211; NOT just concepts. The test is geared towards people with security experience, and the test questions are true to that purpose. It will be very difficult to pass if you:<br />
1) Don&#8217;t know linux<br />
2) Don&#8217;t understand Microsoft&#8217;s OS and operations<br />
3) never actually used any of the hacking tools</p>
<p>Linux is not a MAJOR part of the test, but there are enough questions on linux command line operations to make a difference.</p>
<p>Keep in mind, just reading alone will not let you pass this test. It is very important that you try out the most popular and important tools (firsthand!). You will be asked about specific commands, and be expected to know them. Know nmap, snort, hping2, tracert and tcpdump down cold. Know the ICMP codes and types. The only way you learn this stuff is to actually practice it.</p>
<p class="tags">Tags: <a href="http://technorati.com/tag/ceh" title="See the Technorati tag page for 'ceh'." rel="tag">ceh</a>, <a href="http://technorati.com/tag/ethical" title="See the Technorati tag page for 'ethical'." rel="tag">ethical</a>, <a href="http://technorati.com/tag/hacker" title="See the Technorati tag page for 'hacker'." rel="tag">hacker</a>, <a href="http://technorati.com/tag/security" title="See the Technorati tag page for 'security'." rel="tag">security</a>, <a href="http://technorati.com/tag/book" title="See the Technorati tag page for 'book'." rel="tag">book</a></p>]]></content:encoded>
			<wfw:commentRss>http://elamb.org/certified-ethical-hacker-exam-prep-amazon-review/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SC Magazine Awards 2007: Training Camp listed</title>
		<link>http://elamb.org/sc-magazine-awards-2007-training-camp-listed/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=sc-magazine-awards-2007-training-camp-listed</link>
		<comments>http://elamb.org/sc-magazine-awards-2007-training-camp-listed/#comments</comments>
		<pubDate>Wed, 15 Nov 2006 17:49:06 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
				<category><![CDATA[CEH]]></category>
		<category><![CDATA[Certification]]></category>
		<category><![CDATA[Certification/CISSP]]></category>
		<category><![CDATA[Main Digg]]></category>

	<!-- AutoMeta Start -->
	<category>training</category>
	<category>sscp</category>
	<category>cism</category>
	<category>issep</category>
	<category>comptia</category>
	<category>cisa</category>
	<category>magazine</category>
	<category>isc</category>
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/sc-magazine-awards-2007-training-camp-listed/</guid>
		<description><![CDATA[Training Camp has been named a finalist in the SC Magazine Awards 2007 for the Best Professional Training Program category. According to SC Magazine, programs in this category are defined as those geared toward strengthening the expertise of IT security &#8230; <a href="http://elamb.org/sc-magazine-awards-2007-training-camp-listed/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p><span style="font-size: 10pt; font-family: Arial">Training Camp has been named a finalist in the <strong><a title="http://account-17405.clkserv.com/clicktracker.php?ld=77&#038;cd=735&#038;md=129&#038;ud=2546af02bdcd7627233d465ae34ae9e7&#038;url=http://www.scawards.com/" href="http://account-17405.clkserv.com/clicktracker.php?ld=77&#038;cd=735&#038;md=129&#038;ud=2546af02bdcd7627233d465ae34ae9e7&#038;url=http://www.scawards.com/">SC Magazine Awards 2007</a></strong> for the <strong>Best Professional Training Program</strong> category. According to SC Magazine, programs in this category are defined as those geared toward strengthening the expertise of IT security professionals, that provide educational programs, continued learning and certifications.</span><span style="font-size: 10pt; font-family: Arial">Â </span></p>
<p><span style="font-size: 10pt; font-family: Arial" /><span style="font-size: 10pt; font-family: Arial">Contact me to find out more about our award-nominated IT security Training Camps and why theyâ€™re the best of the best. Our IT security camps include:</span><span style="font-size: 10pt; font-family: Arial"> </span></p>
<p><span style="font-size: 10pt; font-family: Arial">-<a title="http://account-17405.clkserv.com/clicktracker.php?ld=77&#038;cd=735&#038;md=129&#038;ud=2546af02bdcd7627233d465ae34ae9e7&#038;url=http://www.trainingcamp.com/usa/training/isc2/cissp/overview.aspx" href="http://account-17405.clkserv.com/clicktracker.php?ld=77&#038;cd=735&#038;md=129&#038;ud=2546af02bdcd7627233d465ae34ae9e7&#038;url=http://www.trainingcamp.com/usa/training/isc2/cissp/overview.aspx">Official (ISC)<sup title="http://account-17405.clkserv.com/clicktracker.php?ld=77&#038;cd=735&#038;md=129&#038;ud=2546af02bdcd7627233d465ae34ae9e7&#038;url=http://www.trainingcamp.com/usa/training/isc2/cissp/overview.aspx">2</sup> CISSP</a></span><span style="font-size: 10pt; font-family: Arial"><br />
</span><span style="font-size: 10pt; font-family: Arial">-<a title="http://account-17405.clkserv.com/clicktracker.php?ld=77&#038;cd=735&#038;md=129&#038;ud=2546af02bdcd7627233d465ae34ae9e7&#038;url=http://www.trainingcamp.com/usa/training/isc2/issep/overview.aspx" href="http://account-17405.clkserv.com/clicktracker.php?ld=77&#038;cd=735&#038;md=129&#038;ud=2546af02bdcd7627233d465ae34ae9e7&#038;url=http://www.trainingcamp.com/usa/training/isc2/issep/overview.aspx">Official (ISC)<sup title="http://account-17405.clkserv.com/clicktracker.php?ld=77&#038;cd=735&#038;md=129&#038;ud=2546af02bdcd7627233d465ae34ae9e7&#038;url=http://www.trainingcamp.com/usa/training/isc2/issep/overview.aspx">2</sup> ISSEP</a></span><span style="font-size: 10pt; font-family: Arial"><br />
</span><span style="font-size: 10pt; color: navy; font-family: Arial">-<a title="http://account-17405.clkserv.com/clicktracker.php?ld=77&#038;cd=735&#038;md=129&#038;ud=2546af02bdcd7627233d465ae34ae9e7&#038;url=http://www.trainingcamp.com/usa/training/isc2/sscp/overview.aspx" href="http://account-17405.clkserv.com/clicktracker.php?ld=77&#038;cd=735&#038;md=129&#038;ud=2546af02bdcd7627233d465ae34ae9e7&#038;url=http://www.trainingcamp.com/usa/training/isc2/sscp/overview.aspx">Official (ISC)<sup title="http://account-17405.clkserv.com/clicktracker.php?ld=77&#038;cd=735&#038;md=129&#038;ud=2546af02bdcd7627233d465ae34ae9e7&#038;url=http://www.trainingcamp.com/usa/training/isc2/sscp/overview.aspx">2</sup> SSCP</a></span><span style="font-size: 10pt; color: navy; font-family: Arial"><br />
</span><span style="font-size: 10pt; font-family: Arial">-<a title="http://account-17405.clkserv.com/clicktracker.php?ld=77&#038;cd=735&#038;md=129&#038;ud=2546af02bdcd7627233d465ae34ae9e7&#038;url=http://www.trainingcamp.com/usa/training/eccouncil/ceh/overview.aspx" href="http://account-17405.clkserv.com/clicktracker.php?ld=77&#038;cd=735&#038;md=129&#038;ud=2546af02bdcd7627233d465ae34ae9e7&#038;url=http://www.trainingcamp.com/usa/training/eccouncil/ceh/overview.aspx">Certified Ethical Hacker</a></span><span style="font-size: 10pt; font-family: Arial"><br />
</span><span style="font-size: 10pt; font-family: Arial">-<a title="http://account-17405.clkserv.com/clicktracker.php?ld=77&#038;cd=735&#038;md=129&#038;ud=2546af02bdcd7627233d465ae34ae9e7&#038;url=http://www.trainingcamp.com/usa/training/eccouncil/chfi/overview.aspx" href="http://account-17405.clkserv.com/clicktracker.php?ld=77&#038;cd=735&#038;md=129&#038;ud=2546af02bdcd7627233d465ae34ae9e7&#038;url=http://www.trainingcamp.com/usa/training/eccouncil/chfi/overview.aspx">Forensics</a></span><span style="font-size: 10pt; font-family: Arial"><br />
</span><span style="font-size: 10pt; font-family: Arial">-<a title="http://account-17405.clkserv.com/clicktracker.php?ld=77&#038;cd=735&#038;md=129&#038;ud=2546af02bdcd7627233d465ae34ae9e7&#038;url=http://www.trainingcamp.com/usa/training/eccouncil/ecsalpt/overview.aspx" href="http://account-17405.clkserv.com/clicktracker.php?ld=77&#038;cd=735&#038;md=129&#038;ud=2546af02bdcd7627233d465ae34ae9e7&#038;url=http://www.trainingcamp.com/usa/training/eccouncil/ecsalpt/overview.aspx">Licensed Penetration Tester</a></span><span style="font-size: 10pt; font-family: Arial"><br />
</span><span style="font-size: 10pt; font-family: Arial">-<a title="http://account-17405.clkserv.com/clicktracker.php?ld=77&#038;cd=735&#038;md=129&#038;ud=2546af02bdcd7627233d465ae34ae9e7&#038;url=http://www.trainingcamp.com/usa/training/comptia/secplus/overview.aspx" href="http://account-17405.clkserv.com/clicktracker.php?ld=77&#038;cd=735&#038;md=129&#038;ud=2546af02bdcd7627233d465ae34ae9e7&#038;url=http://www.trainingcamp.com/usa/training/comptia/secplus/overview.aspx">CompTIA Security+</a></span><span style="font-size: 10pt; font-family: Arial"><br />
</span><span style="font-size: 10pt; font-family: Arial">-<a title="http://account-17405.clkserv.com/clicktracker.php?ld=77&#038;cd=735&#038;md=129&#038;ud=2546af02bdcd7627233d465ae34ae9e7&#038;url=http://www.trainingcamp.com/usa/training/isaca/cisa/overview.aspx" href="http://account-17405.clkserv.com/clicktracker.php?ld=77&#038;cd=735&#038;md=129&#038;ud=2546af02bdcd7627233d465ae34ae9e7&#038;url=http://www.trainingcamp.com/usa/training/isaca/cisa/overview.aspx">CISA</a></span><span style="font-size: 10pt; font-family: Arial"><br />
</span><span style="font-size: 10pt; font-family: Arial">-<a title="http://account-17405.clkserv.com/clicktracker.php?ld=77&#038;cd=735&#038;md=129&#038;ud=2546af02bdcd7627233d465ae34ae9e7&#038;url=http://www.trainingcamp.com/usa/training/isaca/cism/overview.aspx" href="http://account-17405.clkserv.com/clicktracker.php?ld=77&#038;cd=735&#038;md=129&#038;ud=2546af02bdcd7627233d465ae34ae9e7&#038;url=http://www.trainingcamp.com/usa/training/isaca/cism/overview.aspx">CISM</a></span><span style="font-size: 10pt; font-family: Arial"> </span></p>
<p class="tags">Tags: <a href="http://technorati.com/tag/ceh" title="See the Technorati tag page for 'ceh'." rel="tag">ceh</a>, <a href="http://technorati.com/tag/cissp" title="See the Technorati tag page for 'cissp'." rel="tag">cissp</a>, <a href="http://technorati.com/tag/certification" title="See the Technorati tag page for 'certification'." rel="tag">certification</a></p>]]></content:encoded>
			<wfw:commentRss>http://elamb.org/sc-magazine-awards-2007-training-camp-listed/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is a Hacker?</title>
		<link>http://elamb.org/what-is-a-hacker/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=what-is-a-hacker</link>
		<comments>http://elamb.org/what-is-a-hacker/#comments</comments>
		<pubDate>Thu, 14 Sep 2006 13:52:55 +0000</pubDate>
		<dc:creator>elamb</dc:creator>
		<br />
<b>Warning</b>:  Invalid argument supplied for foreach() in <b>/home/elamb_security/elamb.org/wp-content/plugins/autometa/autometa.php</b> on line <b>300</b><br />
		<category><![CDATA[CEH]]></category>
		<category><![CDATA[Computer Security]]></category>
		<category><![CDATA[Defcon]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[Internet and Information Technology Security]]></category>
		<category><![CDATA[Main Digg]]></category>

	<!-- AutoMeta Start -->
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/what-is-a-hacker/</guid>
		<description><![CDATA[&#8220;A hacker is someone who thinks outside the box. It&#8217;s someone who discards conventional wisdom, and does something else instead. It&#8217;s someone who looks at the edge and wonders what&#8217;s beyond. It&#8217;s someone who sees a set of rules and &#8230; <a href="http://elamb.org/what-is-a-hacker/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>&#8220;A hacker is someone who thinks outside the box. It&#8217;s someone who discards conventional wisdom, and does something else instead. It&#8217;s someone who looks at the edge and wonders what&#8217;s beyond. It&#8217;s someone who sees a set of rules and wonders what happens if you don&#8217;t follow them. A hacker is someone who experiments with the limitations of systems for intellectual curiosity.&#8221;<br />
The above is a quote from crypto living legend Bruce Shneier&#8217;s book, Beyond Fear.Â  This is exactly howÂ I feel about hacking.Â Â HackingÂ is a major asset to Information System Security&#8230; if fact isÂ THEE only real asset.Â  I&#8217;ve had arguements with some of my peers about this.Â  <a href="http://www.mckeay.net/secure/2005/05/well_duh.html">Information Security Pro vs. Hacker</a>.Â  If the typical information system security pro doesn&#8217;t get smart on hacking (security/programming)Â techniques, security will continue to be a losing battle.Â  Cyber criminals have no problem learning the latest exploits, they have no boundaries and this gives them a &#8220;superpower&#8221; against security professionals.Â  Some Information security professionals, on the otherhand, restrict themselves by categorizing hacking as bad.Â  They see it as unethical and not responsible.Â </p>
<p>It is unethical and not responsible to NOT know hacking techniques that might exploit a customers system.</p>
<p>Thanks for theÂ post Bruce.Â  I hope you willÂ make another appearance at the <a href="http://www.defcon.org/html/defcon-6/defcon-6.html">Defcon</a>.Â <br />
<a href="http://www.schneier.com/blog/archives/2006/09/what_is_a_hacke.html">read more</a>Â |Â <a href="http://digg.com/security/What_is_a_Hacker_2">digg story</a></p>
]]></content:encoded>
			<wfw:commentRss>http://elamb.org/what-is-a-hacker/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Intricate Steps of How to Hack Into a Computer</title>
		<link>http://elamb.org/intricate-steps-of-how-to-hack-into-a-computer/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=intricate-steps-of-how-to-hack-into-a-computer</link>
		<comments>http://elamb.org/intricate-steps-of-how-to-hack-into-a-computer/#comments</comments>
		<pubDate>Thu, 20 Jul 2006 21:16:13 +0000</pubDate>
		<dc:creator>elamb</dc:creator>
				<category><![CDATA[CEH]]></category>
		<category><![CDATA[Certification]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[Howto]]></category>
		<category><![CDATA[Main Digg]]></category>

	<!-- AutoMeta Start -->
	<category></category>
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/intricate-steps-of-how-to-hack-into-a-computer/</guid>
		<description><![CDATA[Here is a huge map that pretty much shows you all possible ways to gain entrance into a system. From finding exploits and scanning ports to password cracking. It shows all the likely paths you can take to hack into &#8230; <a href="http://elamb.org/intricate-steps-of-how-to-hack-into-a-computer/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>Here is a huge map that pretty much shows you all possible ways to gain entrance into a system. From finding exploits and scanning ports to password cracking. It shows all the likely paths you can take to hack into a computer and/or test out it&#8217;s security.</p>
<p><a href="http://www.vulnerabilityassessment.co.uk/Penetration%20Test.html">read more</a>Â |Â <a href="http://digg.com/security/Intricate_Steps_of_How_to_Hack_Into_a_Computer">digg story</a></p>
]]></content:encoded>
			<wfw:commentRss>http://elamb.org/intricate-steps-of-how-to-hack-into-a-computer/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Former Pentester of FBI, hacks the FBI</title>
		<link>http://elamb.org/former-pentester-of-fbi-hacks-the-fbi/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=former-pentester-of-fbi-hacks-the-fbi</link>
		<comments>http://elamb.org/former-pentester-of-fbi-hacks-the-fbi/#comments</comments>
		<pubDate>Thu, 06 Jul 2006 23:45:51 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
		<br />
<b>Warning</b>:  Invalid argument supplied for foreach() in <b>/home/elamb_security/elamb.org/wp-content/plugins/autometa/autometa.php</b> on line <b>300</b><br />
		<category><![CDATA[CEH]]></category>
		<category><![CDATA[Computer Security]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[Passwords]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[security testing]]></category>
		<category><![CDATA[vulnerabilities]]></category>

	<!-- AutoMeta Start -->
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/?p=647</guid>
		<description><![CDATA[This case is not the same as the Department of Veteran Affairs loss of records or the Department of Agricultures security failures.&#160; In this case, a contracting consultant&#160;conducted a penetration test with out getting formal approval.&#160; He expoited the&#160;FBI&#39;s vulnerabilities &#8230; <a href="http://elamb.org/former-pentester-of-fbi-hacks-the-fbi/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>This case is not the same as the Department of Veteran Affairs loss of records or the Department of Agricultures security failures.&nbsp; In this case, a contracting consultant&nbsp;conducted a penetration test with out getting formal approval.&nbsp; He expoited the&nbsp;<a href="http://www.washingtonpost.com/wp-dyn/content/article/2006/07/05/AR2006070501489.html">FBI&#39;s vulnerabilities to gain elevated privledges</a>.</p>
<p>Joseph Thomas Colon, 28,&nbsp;is a former&nbsp;employee of BAE Systems.&nbsp;&nbsp;His&nbsp;pentest allowed&nbsp;him to obtain the passwords of 38,000 employees, including that of FBI Director Robert S. Mueller III.&nbsp; According to&nbsp;Colon, the FBI field office in Springfield, Ill., he was attached to&nbsp;gave him approval.</p>
<p>However,&nbsp;every professional&nbsp;pentester and/or&nbsp;ethical hackers knows that you have to get formal approval from&nbsp;an authority.&nbsp; </p>
<blockquote>
<p>Colon&#39;s lawyer said in a court filing that his client was hired to work on the FBI&#39;s &#8220;Trilogy&#8221; computer system but became frustrated over &#8220;bureaucratic&#8221; obstacles, such as obtaining written authorization from the FBI&#39;s Washington headquarters for &#8220;routine&#8221; matters such as adding a printer or moving a new computer onto the system.&nbsp;</p>
</blockquote>
<p>As a result, Mr. Colon will likely serve about 18 months in prison. <img src='http://elamb.org/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' /> &#8230;</p>
<p>Pentesting and ethical hacking tools and techniques must be dealt with responsibly.&nbsp; The bureacracies that might allow pentesting must be respected at all costs.&nbsp; The first thing in Pentesting and ethical hacking that is taught is to ALWAYs, ALWAYS, ALWAYS get writen consent to procede from the owners of the system.</p>
<p><a href="http://www.washingtonpost.com/wp-dyn/content/article/2006/07/05/AR2006070501489.html"></a>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://elamb.org/former-pentester-of-fbi-hacks-the-fbi/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Review: Certified Ethical Hacker (CEH) via Self Study</title>
		<link>http://elamb.org/review-certified-ethical-hacker-ceh-via-self-study/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=review-certified-ethical-hacker-ceh-via-self-study</link>
		<comments>http://elamb.org/review-certified-ethical-hacker-ceh-via-self-study/#comments</comments>
		<pubDate>Wed, 31 May 2006 23:02:08 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
		<br />
<b>Warning</b>:  Invalid argument supplied for foreach() in <b>/home/elamb_security/elamb.org/wp-content/plugins/autometa/autometa.php</b> on line <b>300</b><br />
		<category><![CDATA[CEH]]></category>
		<category><![CDATA[Certification]]></category>
		<category><![CDATA[DIGG]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[security testing]]></category>

	<!-- AutoMeta Start -->
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/?p=530</guid>
		<description><![CDATA[In his latest column for EH-Net, wireless hacking guru, Dan Hoffman, offers up his experience of attaining the CEH credential. Great read with fantastic advice for all you budding ethical hackers out there. read more&#160;&#124;&#160;digg story]]></description>
			<content:encoded><![CDATA[<p>In his latest column for EH-Net, wireless hacking guru, Dan Hoffman, offers up his experience of attaining the CEH credential. Great read with fantastic advice for all you budding ethical hackers out there.</p>
<p><a href="http://www.ethicalhacker.net/content/view/54/24/">read more</a>&nbsp;|&nbsp;<a href="http://digg.com/security/Review:_Certified_Ethical_Hacker_(CEH)_via_Self_Study">digg story</a></p>
]]></content:encoded>
			<wfw:commentRss>http://elamb.org/review-certified-ethical-hacker-ceh-via-self-study/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Certified Ethical Hacker Cert and Certified Pen Testing Expert</title>
		<link>http://elamb.org/certified-ethical-hacker-cert-and-certified-pen-testing-expert/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=certified-ethical-hacker-cert-and-certified-pen-testing-expert</link>
		<comments>http://elamb.org/certified-ethical-hacker-cert-and-certified-pen-testing-expert/#comments</comments>
		<pubDate>Wed, 31 May 2006 07:27:29 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
		<br />
<b>Warning</b>:  Invalid argument supplied for foreach() in <b>/home/elamb_security/elamb.org/wp-content/plugins/autometa/autometa.php</b> on line <b>300</b><br />
		<category><![CDATA[CEH]]></category>
		<category><![CDATA[Certification]]></category>
		<category><![CDATA[Certification/CISSP]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[ISSEP]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[security testing]]></category>

	<!-- AutoMeta Start -->
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/?p=527</guid>
		<description><![CDATA[I&#39;m going to go for the Certified Ethical Hacker Cert and eventually the Certified Pen Testing Expert Certification.&#160; That is the direction that I&#39;d like to go with my Information Security Career.&#160; As of right now, I have a CISSP.&#160; &#8230; <a href="http://elamb.org/certified-ethical-hacker-cert-and-certified-pen-testing-expert/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>I&#39;m going to go for the <a href="http://www.eccouncil.org/CEH.htm">Certified Ethical Hacker</a> Cert and eventually the Certified Pen Testing Expert Certification.&nbsp; That is the direction that I&#39;d like to go with my Information Security Career.&nbsp; </p>
<p>As of right now, I have a CISSP.&nbsp; I do a lot of Security Testing Evaluations and Authorization Agreement, Security Policy type work.&nbsp; It pays well but I think Pen Testing would be more fun.&nbsp; After getting the CISSP, I seriously considered going after the ISSEP, Information System Security Engineering Professional cert, which I heard was harder than the CISSP&#8230; I don&#39;t see how that is possible.</p>
<p>The CEH is a 125 question test that I&#39;ve heard mixed reviews about.&nbsp; I&#39;ve taken the bootcamp and I love the material.&nbsp; Its all hardcore hacking.&nbsp; Not simply how to use Cane &amp; Abel or NMap but how to code malware with notepad, methods of SQL injection, and firewall attacks.&nbsp; I learned a lot.&nbsp; It also scared the piss out of me.&nbsp; If your already a hacker or hardcore pent tester than the class would be nothing more than a refresher.&nbsp; Intermediates with pentesting will have a real treat.&nbsp; Beginers will be decapitated. </p>
<p>I guess CPTE, Certified Pen Testing Expert is the lastest one.&nbsp; From what I&#39;ve read, it looks like it is a step up from the CEH.&nbsp; Here is some <a href="http://www.ethicalhacker.net/component/option,com_smf/Itemid,35/board,4.0">more info on the CPTE</a>.&nbsp; From what I&#39;ve read the CPTE is INSANE.&nbsp;&nbsp;It looks like a practical exam&nbsp;completed in the presents of&nbsp;a pentesting expert.&nbsp; It&nbsp;includes&nbsp;SQL injections,&nbsp;gathering data, compiling&nbsp;hacker applications, and FRICKING Lockpicking&#8230; I AM NOT&nbsp;READY.&nbsp; </p>
]]></content:encoded>
			<wfw:commentRss>http://elamb.org/certified-ethical-hacker-cert-and-certified-pen-testing-expert/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

