Some users have recently had their accounts hijacked. It seems that the now defunct EVGA forums might have compromised your password there and seems many are using the same PW here. We would suggest you UPDATE YOUR PASSWORD and TURN ON 2FA for your account here to further secure it. None of the compromised accounts had 2FA turned on.
Once you have enabled 2FA, your account will be updated soon to show a badge, letting other members know that you use 2FA to protect your account. This should be beneficial for everyone that uses FSFT.
Could someone post a thorough list of materials to study, to successfully pass this test?
All I can find is for the old version, it seems. It doesn't have all the new info for the new exam.
I don't think you're going to find much help around here as hacking of any type (even "Certified Ethical") doesn't seem to be tolerated. One of my huge letdowns about this forum...
What I will say though is that I'd encourage you to consider a Safari Books Online subscription. The latest CEH book added is the CEH® Certified Ethical Hacker Study Guide (ISBN 978-0-470-52520-3) which was published April 26, 2010. The full meal deal subscription is $46/month after tax but I think it is the single best investment you could (continue) to make in continuing education.
No I don't resell it or anything, but it really is that good.
Hey man, thanks for the response.
Will try to get a hold on a copy ASAP!
I'm also using Counter Hack Reloaded, Second Edition (amazing book, check the reviews at Amazon.com) and also, Hacking Exposed, sixth edition, a little less general knowledge, is basically a huge review of tools & types of attacks. A little hard to read, but I think it's very useful as a complement.
I'm also planning on beginning studies for the CEH certification soon, and I have done a crap ton of research on printed materials, and I'll second that the official CEH Study Guide is awesome. I can't wait to tear into it.
And I'd also like to take an opportunity to say that it is absolutely ridiculous that IT professionals can't discuss a critical aspect of their work here because some script kiddie might get wind of it and get the wrong ideas. As Space said, it's a huge letdown for me considering how valuable these forums are for other areas.
I'll go one step further and state that I firmly believe that any IT professional should BE a hacker.
Let's not misconstrue the definition of the word hacker however before making assumptions about the previous statement. I believe a hacker to be anyone who furthers their knowledge in the their field of expertise by unconventional means and without regard to the conventional wisdom and/or assumptions of what would be considered standard practice.
Popular usage of the term as we all know has turned into anyone that commits a crime with a computer. And the rules of this forum certainly do not help us in this regard.
By my definition, and that of what I think most people here think, practically everyone on this forum is a hacker. To me, you can't be [H]ard without being a hacker. Who here has overclocked their PC? You sir/madam are a hacker. Remember when you were a kid and took apart your favorite toy just to see how it worked? - Hacker. Macgyver - Grand Master Hacker.
So why all of the sudden, when what I believe where the founding principles of [H]ard|OCP, we apply this philosophy to security is it considered a ban-worthy offense? I understand that you don't want to be litigated against, but I wouldn't suspect any knowledge posted here wouldn't already be on other sites or even published in books such as the ones mentioned above. The fact that we can't even discuss 3/4 of what it takes to be a CEH here is more than just frustrating, it's downright disappointing. And by disappointing I mean that I actively avoid hardforum and hardocp.com at times because being [H]ard has turned into conforming.
I believe that in order to be a competent IT admin, you need to know how to "hack". And that means knowing how to break security, fuzz applications, social engineer, etc. If you don't - you have NO hopes of being able to secure and protect your organization.
Knowing how to kill does not a murderer make.
My boss today upon apparently re-looking over his job duties remembered that part of HIPAA compliance states that we must perform regular security audits. After he explained to the group what he thought constitutes an audit, I quickly interjected a few examples of gaping security issues that we were vulnerable to purely because of the lack of active knowledge of most of the department and further lack of funding to resolve the issues. The conversation was over within 30 seconds. That was very disturbing to me. And it's the same feeling that I get here when I'm outright dying to discuss these issues. Nobody in my department knew what a pen test was, and I'm willing to bet that neither Kyle, Steve or the rest of the crew here do either.
It's so frustrating to me that I just wish that subforum were renamed to Networking. Real security discussion is outright forbidden here. I hope that with the support of fellow members, this could become a plea to either rename the subforum or allow real security discussion.
Kyle and company - we truly appreciate the outlet that you have here that we all use to become more [H]ard. But the lack of understanding of why real security discussion should be permitted is a great detriment to the potential of all of us. We URGE you to reconsider your stance in this regard, and give us the chance to explain why this knowledge is essential to all of us - you included.