<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Ec0-350 Certification Exam Training Materials&#38;Study Guide &#187; Briandumps</title>
	<atom:link href="http://www.ec0-350.com/category/briandumps/feed" rel="self" type="application/rss+xml" />
	<link>http://www.ec0-350.com</link>
	<description>Ec-council Ethical Hacking and Countermeasures: EC0-350 CEH 6.0  Exam</description>
	<lastBuildDate>Thu, 22 Apr 2010 08:35:27 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>ceh 6.0 questions</title>
		<link>http://www.ec0-350.com/ceh-6-0-questions.html</link>
		<comments>http://www.ec0-350.com/ceh-6-0-questions.html#comments</comments>
		<pubDate>Fri, 25 Sep 2009 04:41:23 +0000</pubDate>
		<dc:creator>Ec-council</dc:creator>
				<category><![CDATA[Briandumps]]></category>

		<guid isPermaLink="false">http://www.ec0-350.com/?p=41</guid>
		<description><![CDATA[ec-council ec0-350 ceh 6.0 QUESTION 1
http://rapidshare.com/files/284657518/CEH_Questions.pdf.html
http://www.4shared.com/file/135246368/d8cd55ed/ec0-council_ceh_ec0-350_Questions.html
220-701
Exhibit
Study the log given in the exhibit,
Precautionary measures to prevent this attack would include writing firewall rules. Of these firewall
rules, which among the following would be appropriate?
A. Disallow UDP 53 in from outside to DNS server
B. Allow UDP 53 in from DNS server to outside
C. Disallow TCP 53 in form [...]]]></description>
			<content:encoded><![CDATA[<p>ec-council ec0-350 ceh 6.0 QUESTION 1<br />
http://rapidshare.com/files/284657518/CEH_Questions.pdf.html<br />
http://www.4shared.com/file/135246368/d8cd55ed/ec0-council_ceh_ec0-350_Questions.html</p>
<p><a href="http://www.passguide.com/220-701.html">220-701</a><br />
Exhibit</p>
<p>Study the log given in the exhibit,<br />
Precautionary measures to prevent this attack would include writing firewall rules. Of these firewall<br />
rules, which among the following would be appropriate?<span id="more-41"></span></p>
<p>A. Disallow UDP 53 in from outside to DNS server<br />
B. Allow UDP 53 in from DNS server to outside<br />
C. Disallow TCP 53 in form secondaries or ISP server to DNS server<br />
D. Block all UDP traffic</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<br />
QUESTION 2<br />
You are attempting to map out the firewall policy for an organization. You discover your target system is<br />
one hop beyond the firewall. Using hping2, you send SYN packets with the exact TTL of the target system<br />
starting at port 1 and going up to port 1024. What is this process known as?</p>
<p>A. Footprinting<br />
B. Firewalking<br />
C. Enumeration<br />
D. Idle scanning</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<br />
QUESTION 3<br />
Once an intruder has gained access to a remote system with a valid username and password, the attacker<br />
will attempt to increase his privileges by escalating the used account to one that has increased privileges.<br />
such as that of an administrator. What would be the best countermeasure to protect against escalation of<br />
priveges?</p>
<p>A. Give users tokens<br />
B. Give user the least amount of privileges<br />
C. Give users two passwords<br />
D. Give users a strong policy document</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<br />
QUESTION 4<br />
Which one of the following attacks will pass through a network layer intrusion detection system<br />
undetected?</p>
<p>A. A teardrop attack<br />
B. A SYN flood attack<br />
C. A DNS spoofing attack<br />
D. A test.cgi attack</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<br />
QUESTION 5<br />
Why would an ethical hacker use the technique of firewalking?</p>
<p>A. It is a technique used to discover wireless network on foot.<br />
B. It is a technique used to map routers on a network link.<br />
C. It is a technique used to discover the nature of rules configured on a gateway.<br />
D. It is a technique used to discover interfaces in promiscuous mode.</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<br />
QUESTION 6<br />
What makes web application vulnerabilities so aggravating? (Choose two)</p>
<p>A. They can be launched through an authorized port.<br />
B. A firewall will not stop them.<br />
C. They exist only on the Linux platform.<br />
D. They are detectable by most leading antivirus software.</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<br />
QUESTION 7<br />
An employee wants to defeat detection by a network-based IDS application. He does not want to attack<br />
the system containing the IDS application.<br />
Which of the following strategies can be used to defeat detection by a network-based IDS application?<br />
(Choose the best answer)</p>
<p>A. Create a network tunnel.<br />
B. Create a multiple false positives.<br />
C. Create a SYN flood.<br />
D. Create a ping flood.</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<br />
QUESTION 8<br />
Carl has successfully compromised a web server from behind a firewall by exploiting a vulnerability in<br />
the web server program. He wants to proceed by installing a backdoor program. However, he is aware<br />
that not all inbound ports on the firewall are in the open state.<br />
From the list given below, identify the port that is most likely to be open and allowed to reach the server<br />
that Carl has just compromised.</p>
<p>A. 53<br />
B. 110<br />
C. 25<br />
D. 69</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<br />
QUESTION 9<br />
Neil monitors his firewall rules and log files closely on a regular basis. Some of the users have complained<br />
to Neil that there are a few employees who are visiting offensive web sites during work hours, without<br />
consideration for others. Neil knows that he has an updated content filtering system and that such access<br />
should not be authorized.<br />
What type of technique might be used by these offenders to access the Internet without restriction?</p>
<p>A. They are using UDP which is always authorized at the firewall.<br />
B. They are using tunneling software which allows them to communicate with protocols in a way it was not<br />
intended.<br />
C. They have been able to compromise the firewall, modify the rules, and give themselves proper access.<br />
D. They are using an older version of Internet Explorer that allows them to bypass the proxy server.</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<br />
QUESTION 10<br />
The programmers on your team are analyzing the free, open source software being used to run FTP<br />
services on a server in your organization. They notice that there is excessive number of functions in the<br />
source code that might lead to buffer overflow. These C++ functions do not check bounds. Identify the<br />
line the source code that might lead to buffer overflow.</p>
<p>A. Line number 31.<br />
B. Line number 15<br />
C. Line number 8<br />
D. Line number 14<br />
QUESTION 1<br />
Doug is conducting a port scan of a target network. He knows that his client target network has a web<br />
server and that there is a mail server also which is up and running. Doug has been sweeping the network<br />
but has not been able to elicit any response from the remote target. Which of the following could be the<br />
most likely cause behind this lack of response? Select 4.</p>
<p>A. UDP is filted by a gateway<br />
B. The packet TTL value is too low and cannot reach the target<br />
C. The host might be down<br />
D. The destination network might be down<br />
E. The TCP windows size does not match<br />
F. ICMP is filtered by a gateway</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<br />
QUESTION 2<br />
Exhibit</p>
<p>Joe Hacker runs the hping2 hacking tool to predict the target host&#8217;s sequence numbers in one of the<br />
hacking session.<br />
What does the first and second column mean? Select two.</p>
<p>A. The first column reports the sequence number<br />
B. The second column reports the difference between the current and last sequence number<br />
C. The second column reports the next sequence number<br />
D. The first column reports the difference between current and last sequence number<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<br />
QUESTION 3<br />
While performing a ping sweep of a subnet you receive an ICMP reply of Code 3/Type 13 for all the pings<br />
sent out.<br />
What is the most likely cause behind this response?</p>
<p>A. The firewall is dropping the packets.<br />
B. An in-line IDS is dropping the packets.<br />
C. A router is blocking ICMP.<br />
D. The host does not respond to ICMP packets.</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<br />
QUESTION 4<br />
The following excerpt is taken from a honeyput log. The log captures activities across three days. There<br />
are several intrusion attempts; however, a few are successful. Study the log given below and answer the<br />
following question:<br />
(Note: The objective of this questions is to test whether the student has learnt about passive OS<br />
fingerprinting (which should tell them the OS from log captures): can they tell a SQL injection attack<br />
signature; can they infer if a user ID has been created by an attacker and whether they can read plain<br />
source &#8211; destination entries from log entries.)</p>
<p>What can you infer from the above log?</p>
<p>A. The system is a windows system which is being scanned unsuccessfully.<br />
B. The system is a web application server compromised through SQL injection.<br />
C. The system has been compromised and backdoored by the attacker.<br />
D. The actual IP of the successful attacker is 24.9.255.53.<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<br />
QUESTION 5<br />
Bob has been hired to perform a penetration test on Certkiller .com. He begins by looking at IP address<br />
ranges owned by the company and details of domain name registration. He then goes to News Groups<br />
and financial web sites to see if they are leaking any sensitive information of have any technical details<br />
online.<br />
Within the context of penetration testing methodology, what phase is Bob involved with?</p>
<p>A. Passive information gathering<br />
B. Active information gathering<br />
C. Attack phase<br />
D. Vulnerability Mapping<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<br />
QUESTION 6<br />
Which of the following would be the best reason for sending a single SMTP message to an address that<br />
does not exist within the target company?</p>
<p>A. To create a denial of service attack.<br />
B. To verify information about the mail administrator and his address.<br />
C. To gather information about internal hosts used in email treatment.<br />
D. To gather information about procedures that are in place to deal with such messages.</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<br />
QUESTION 7<br />
You are conducting a port scan on a subnet that has ICMP blocked. You have discovered 23 live systems<br />
and after scanning each of them you notice that they all show port 21 in closed state.<br />
What should be the next logical step that should be performed?</p>
<p>A. Connect to open ports to discover applications.<br />
B. Perform a ping sweep to identify any additional systems that might be up.<br />
C. Perform a SYN scan on port 21 to identify any additional systems that might be up.<br />
D. Rescan every computer to verify the results.</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<br />
QUESTION 8<br />
Ann would like to perform a reliable scan against a remote target. She is not concerned about being<br />
stealth at this point.<br />
Which of the following type of scans would be the most accurate and reliable option?</p>
<p>A. A half-scan<br />
B. A UDP scan<br />
C. A TCP Connect scan<br />
D. A FIN scan</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<br />
QUESTION 9<br />
What type of port scan is shown below?</p>
<p>A. Idle Scan<br />
B. Windows Scan<br />
C. XMAS Scan<br />
D. SYN Stealth Scan</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<br />
QUESTION 10<br />
War dialing is a very old attack and depicted in movies that were made years ago.<br />
Why would a modem security tester consider using such an old technique?</p>
<p>A. It is cool, and if it works in the movies it must work in real life.<br />
B. It allows circumvention of protection mechanisms by being on the internal network.<br />
C. It allows circumvention of the company PBX.<br />
D. A good security tester would not use such a derelict technique.</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<br />
QUESTION 11<br />
An attacker is attempting to telnet into a corporation&#8217;s system in the DMZ. The attacker doesn&#8217;t want to<br />
get caught and is spoofing his IP address. After numerous tries he remains unsuccessful in connecting to<br />
the system. The attacker rechecks that the target system is actually listening on Port 23 and he verifies it<br />
with both nmap and hping2. He is still unable to connect to the target system.<br />
What is the most probable reason?</p>
<p>A. The firewall is blocking port 23 to that system.<br />
B. He cannot spoof his IP and successfully use TCP.<br />
C. He needs to use an automated tool to telnet in.<br />
D. He is attacking an operating system that does not reply to telnet even when open.</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<br />
QUESTION 12<br />
You are scanning into the target network for the first time. You find very few conventional ports open.<br />
When you attempt to perform traditional service identification by connecting to the open ports, it yields<br />
either unreliable or no results. You are unsure of which protocols are being used. You need to discover as<br />
many different protocols as possible.<br />
Which kind of scan would you use to achieve this? (Choose the best answer)</p>
<p>A. Nessus scan with TCP based pings.<br />
B. Nmap scan with the -sP (Ping scan) switch.<br />
C. Netcat scan with the -u -e switches.<br />
D. Nmap with the -sO (Raw IP packets) switch.</p>
<p>QUESTION 1<br />
Bubba has just accessed he preferred ecommerce web site and has spotted an item that he would like to<br />
buy. Bubba considers the price a bit too steep. He looks at the source code of the webpage and decides to<br />
save the page locally, so that he can modify the page variables. In the context of web application security,<br />
what do you think Bubba has changes?</p>
<p>A. A hidden form field value.<br />
B. A hidden price value.<br />
C. An integer variable.<br />
D. A page cannot be changed locally, as it is served by a web server.</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<br />
QUESTION 2<br />
You want to carry out session hijacking on a remote server. The server and the client are communicating<br />
via TCP after a successful TCP three way handshake. The server has just received packet #120 from the<br />
client. The client has a receive window of 200 and the server has a receive window of 250.<br />
Within what range of sequence numbers should a packet, sent by the client fall in order to be accepted by<br />
the server?</p>
<p>A. 200-250<br />
B. 121-371<br />
C. 120-321<br />
D. 121-231<br />
E. 120-370</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<br />
QUESTION 3<br />
You have been called to investigate a sudden increase in network traffic at Certkiller . It seems that the<br />
traffic generated was too heavy that normal business functions could no longer be rendered to external<br />
employees and clients. After a quick investigation, you find that the computer has services running<br />
attached to TFN2k and Trinoo software. What do you think was the most likely cause behind this sudden<br />
increase in traffic?</p>
<p>A. A distributed denial of service attack.<br />
B. A network card that was jabbering.<br />
C. A bad route on the firewall.<br />
D. Invalid rules entry at the gateway.</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<br />
QUESTION 4<br />
SYN Flood is a DOS attack in which an attacker deliberately violates the three-way handshake and opens<br />
a large number of half-open TCP connections.<br />
The signature for SYN Flood attack is:</p>
<p>A. The source and destination address having the same value.<br />
B. The source and destination port numbers having the same value.<br />
C. A large number of SYN packets appearing on a network without the corresponding reply packets.<br />
D. A large number of SYN packets appearing on a network with the corresponding reply packets.</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<br />
QUESTION 5<br />
Which definition among those given below best describes a covert channel?</p>
<p>A. A server program using a port that is not well known.<br />
B. Making use of a protocol in a way it is not intended to be used.<br />
C. It is the multiplexing taking place on a communication link.<br />
D. It is one of the weak channels used by WEP which makes it insecure.</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<br />
QUESTION 6<br />
While probing an organization you discover that they have a wireless network. From your attempts to<br />
connect to the WLAN you determine that they have deployed MAC filtering by using ACL on the access<br />
points. What would be the easiest way to circumvent and communicate on the WLAN?</p>
<p>A. Attempt to crack the WEP key using Airsnort.<br />
B. Attempt to brute force the access point and update or delete the MAC ACL.<br />
C. Steel a client computer and use it to access the wireless network.<br />
D. Sniff traffic if the WLAN and spoof your MAC address to one that you captured.</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<br />
QUESTION 7<br />
Take a look at the following attack on a Web Server using obstructed URL:<br />
http://www.example.com/script.ext?template%2e%2e%2e%2e%2e%2f%2e%2f%65%74%6<br />
3%2f%70%61%73%73%77%64<br />
The request is made up of:<br />
%2e%2e%2f%2e%2e%2f%2e%2f% = ../../../<br />
%65%74%63 = etc<br />
%2f = /<br />
%70%61%73%73%77%64 = passwd<br />
How would you protect information systems from these attacks?</p>
<p>A. Configure Web Server to deny requests involving Unicode characters.<br />
B. Create rules in IDS to alert on strange Unicode requests.<br />
C. Use SSL authentication on Web Servers.<br />
D. Enable Active Scripts Detection at the firewall and routers.</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<br />
QUESTION 8<br />
Which of the following is NOT a valid NetWare access level?</p>
<p>A. Not Logged in<br />
B. Logged in<br />
C. Console Access<br />
D. Administrator</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<br />
QUESTION 9<br />
While examining audit logs, you discover that people are able to telnet into the SMTP server on port 25.<br />
You would like to block this, though you do not see any evidence of an attack or other wring doing.<br />
However, you are concerned about affecting the normal functionality of the email server. From the<br />
following options choose how best you can achieve this objective?</p>
<p>A. Block port 25 at the firewall.<br />
B. Shut off the SMTP service on the server.<br />
C. Force all connections to use a username and password.<br />
D. Switch from Windows Exchange to UNIX Sendmail.<br />
E. None of the above.</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<br />
QUESTION 10<br />
Access control is often implemented through the use of MAC address filtering on wireless Access Points.<br />
Why is this considered to be a very limited security measure?</p>
<p>A. Vendors MAC address assignment is published on the Internet.<br />
B. The MAC address is not a real random number.<br />
C. The MAC address is broadcasted and can be captured by a sniffer.<br />
D. The MAC address is used properly only on Macintosh computers.</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<br />
QUESTION 11<br />
While reviewing the result of scanning run against a target network you come across the following:</p>
<p>Which among the following can be used to get this output?</p>
<p>A. A Bo2k system query.<br />
B. nmap protocol scan<br />
C. A sniffer<br />
D. An SNMP walk</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<br />
QUESTION 12<br />
In order to attack a wireless network, you put up can access point and override the signal of the real<br />
access point. As users send authentication data, you are able to capture it. What kind of attack is this?</p>
<p>A. Rouge access point attack<br />
B. Unauthorized access point attack<br />
C. War Chalking<br />
D. WEP attack</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<br />
QUESTION 13<br />
Windows LAN Manager (LM) hashes are known to be weak. Which of the following are known<br />
weaknesses of LM? (Choose three)</p>
<p>A. Converts passwords to uppercase.<br />
B. Hashes are sent in clear text over the network.<br />
C. Makes use of only 32 bit encryption.<br />
D. Effective length is 7 characters.</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<br />
QUESTION 14<br />
You are manually conducting Idle Scanning using Hping2. During your scanning you notice that almost<br />
every query increments the IPID regardless of the port being queried. One or two of the queries cause the<br />
IPID to increment by more than one value. Why do you think this occurs?</p>
<p>A. The zombie you are using is not truly idle.<br />
B. A stateful inspection firewall is resetting your queries.<br />
C. Hping2 cannot be used for idle scanning.<br />
D. These ports are actually open on the target system.</p>
<p>Question: 1<br />
What is the name of the software tool used to crack a single account on Netware Servers using a dictionary attack? </p>
<p>A. NPWCrack<br />
B. NWPCrack<br />
C. NovCrack<br />
D. CrackNov<br />
E. GetCrack </p>
<p>Answer: B </p>
<p>Explanation:<br />
NWPCrack is the software tool used to crack single accounts on Netware servers. </p>
<p>Question: 2<br />
How can you determine if an LM hash you extracted contains a password that is less than 8 characters long? </p>
<p>A. There is no way to tell because a hash cannot be reversed<br />
B. The right most portion of the hash is always the same<br />
C. The hash always starts with AB923D<br />
D. The left most portion of the hash is always the same<br />
E. A portion of the hash will be all 0&#8217;s </p>
<p>Answer: B </p>
<p>Explanation:<br />
When loosheets at an extracted LM hash, you will sometimes observe that the right most portion is always the same. This is padding that has been added to a password that is less than 8 characters long. </p>
<p>Question: 3<br />
Several of your co-workers are having a discussion over the etc/passwd file. They are at odds over what types of encryption are used to secure Linux passwords.(Choose all that apply). </p>
<p>A. Linux passwords can be encrypted with MD5<br />
B. Linux passwords can be encrypted with SHA<br />
C. Linux passwords can be encrypted with DES<br />
D. Linux passwords can be encrypted with Blowfish<br />
E. Linux passwords are encrypted with asymmetric algrothims </p>
<p>Answer: A, C D </p>
<p>Explanation:<br />
Linux passwords can be encrypted with several types of hashing algorithms. These include SHQ, MD5, and Blowfish. </p>
<p>Question: 4<br />
What are the two basic types of attacks?(Choose two. </p>
<p>A. DoS<br />
B. Passive<br />
C. Sniffing<br />
D. Active<br />
E. Cracsheets </p>
<p>Answer: B, D </p>
<p>Explanation:<br />
Passive and active attacks are the two basic types of attacks. </p>
<p>Question: 5<br />
Sniffing is considered an active attack. </p>
<p>A. True<br />
B. False </p>
<p>Answer: B </p>
<p>Explanation:<br />
Sniffing is considered a passive attack. </p>
<p>Question: 6<br />
When discussing passwords, what is considered a brute force attack? </p>
<p>A. You attempt every single possibility until you exhaust all possible combinations or discover the<br />
password<br />
B. You threaten to use the rubber hose on someone unless they reveal their password<br />
C. You load a dictionary of words into your cracsheets program<br />
D. You create hashes of a large number of words and compare it with the encrypted passwords<br />
E. You wait until the password expires </p>
<p>Answer: A </p>
<p>Explanation:<br />
Brute force cracsheets is a time consuming process where you try every possible combination of letters, numbers, and characters until you discover a match.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ec0-350.com/ceh-6-0-questions.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ECCouncil CEHv5 EC0-350 &amp; 312-50 &#8211; Printable Version</title>
		<link>http://www.ec0-350.com/eccouncil-cehv5-ec0-350-312-50-printable-version.html</link>
		<comments>http://www.ec0-350.com/eccouncil-cehv5-ec0-350-312-50-printable-version.html#comments</comments>
		<pubDate>Fri, 25 Sep 2009 03:17:37 +0000</pubDate>
		<dc:creator>Ec-council</dc:creator>
				<category><![CDATA[Briandumps]]></category>

		<guid isPermaLink="false">http://www.ec0-350.com/?p=39</guid>
		<description><![CDATA[i convert this PDF to VCE, this is valid version, enjoy. 
the PDF:
http://www.4shared.com/file/41869181/d3c06fd5/ceh.html 
the VCE:
http://rapidshare.com/files/137060753/ECCouncil.CEHv5.EC0-350-_-312-50.288q.13-08-2008.by.commander.vce 
]]></description>
			<content:encoded><![CDATA[<p>i convert this PDF to VCE, this is valid version, enjoy. </p>
<p>the PDF:<br />
http://www.4shared.com/file/41869181/d3c06fd5/ceh.html </p>
<p>the VCE:<br />
http://rapidshare.com/files/137060753/ECCouncil.CEHv5.EC0-350-_-312-50.288q.13-08-2008.by.commander.vce </p>
]]></content:encoded>
			<wfw:commentRss>http://www.ec0-350.com/eccouncil-cehv5-ec0-350-312-50-printable-version.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ec-council ec0-350 test questions 1</title>
		<link>http://www.ec0-350.com/ec-council-ec0-350-test-questions-1.html</link>
		<comments>http://www.ec0-350.com/ec-council-ec0-350-test-questions-1.html#comments</comments>
		<pubDate>Thu, 24 Sep 2009 17:19:08 +0000</pubDate>
		<dc:creator>Ec-council</dc:creator>
				<category><![CDATA[Briandumps]]></category>

		<guid isPermaLink="false">http://www.ec0-350.com/?p=36</guid>
		<description><![CDATA[The mere name of ECCouncil EC0-350 can attract all organizations like a swarm of nectar-hungry bees. Having it under one&#8217;s belt opens new realms of opportunities hitherto unknown and unconquered. TK&#8217;s Ethical Hacking and Countermeasures is the dream certificate of many professionals. You can have this too. Give your career the bounce it needs by [...]]]></description>
			<content:encoded><![CDATA[<p>The mere name of<a href="http://www.ec0-350.com"> ECCouncil EC0-350 </a>can attract all organizations like a swarm of nectar-hungry bees. Having it under one&#8217;s belt opens new realms of opportunities hitherto unknown and unconquered. TK&#8217;s Ethical Hacking and Countermeasures is the dream certificate of many professionals. You can have this too. Give your career the bounce it needs by choosing EC0-350 of ECCouncil. Association with ECCouncil will ensure your success and growth no matter where you might pursue your career. Let TestKing-Exams.com take every worry off your mind and make this dream of an association a reality!<br />
Certification Provider: ECCouncil<br />
Exam Name: EC0-350 &#8211; passguide  <a href="http://www.passguide.com/EC0-350.html">Ethical Hacking and Countermeasures</a><br />
Associated Certifications: ECCouncil Certified Ethical Hacker<br />
Language:English<span id="more-36"></span><br />
You are footprinting an organization and gathering competitive intelligence. You visit the company<br />
website for contact information and telephone numbers but do not find them listed there. You<br />
know they had the entire staff directory listed on their website 12 months ago but now it is not<br />
there. Is there anyway you can retrieve information from a website that is outdated? </p>
<p>A. Visit google search engine and view the cached copy<br />
B. Crawl the entire website and store them into your computer<br />
C. Visit the company partners and customers website for this information<br />
D. Visit Archive.org web site to retrieve the Internet archive of the company website </p>
<p>Answer: D<br />
You have retrieved the raw hash values from a Windows 2000 Domain Controller. Using social<br />
engineering, you know that they are enforcing strong passwords. You understand that all users<br />
are required to use passwords that are at least 8 characters in length. All passwords must also<br />
use 3 of the 4 following categories: lower case letters, capital letters, numbers and special<br />
characters. With your given knowledge of users, likely user account names and the possibility<br />
that they will choose the easiest passwords possible, what would be the fastest type of password<br />
cracking attack you can run against these hash values to get results? </p>
<p>A. Hybrid Attack<br />
B. Dictionary Attack<br />
C. Encryption Attack<br />
D. Brute Force Attack </p>
<p>Answer: A<br />
You receive an e-mail with the below message:<br />
Hello Steve,<br />
We are having technical difficulty in restoring user database records after the recent blackout.<br />
Your account data is corrupted. Please logon on to SuperEmailServices.com and change your<br />
password.<br />
http://www.superemailservices.com%40c3405906949/support/logon.htm<br />
If you do not reset your password within 7 days, your account will be permanently disabled<br />
locking you out from using our e-mail services.<br />
Sincerely,<br />
Technical Support<br />
SuperEmailServices<br />
From this e-mail you suspect that some hacker sent this message since you have been using<br />
their e-mail services for the last 2 years and they never have sent out an e-mail such as this. You<br />
also observe the URL in the message and want to confirm your suspicion about 3405906949,<br />
which looks like a base10 number.<br />
You enter the following at the Windows 2003 command prompt:<br />
ping 3405906949<br />
You get a response with a valid IP address. What is the obstructed IP address in the e-mail URL? </p>
<p>A. 10.0.3.4<br />
B. 192.34.5.9<br />
C. 199.23.43.4<br />
D. 203.2.4.5 </p>
<p>Answer: D </p>
<p>Bob is acknowledged as a hacker of repute and is popular among visitors of &#8216;underground&#8217; sites.<br />
Bob is willing to share his knowledge to those who are willing to learn, and many have expressed<br />
their interest in learning from him. However, this knowledge has risks associated with it, as the<br />
same knowledge can be used for malevolent attacks as well. In this context, what would be the<br />
most effective method to bridge the knowledge gap between the &#8220;black&#8221; hats or crackers and the<br />
&#8220;white&#8221; hats or computer security professionals? </p>
<p>A. Hire more computer security monitoring personnel to monitor computer systems and networks<br />
B. Educate everyone with books, articles and training on risk analysis, vulnerabilities and<br />
safeguards<br />
C. Train more national guard and reservist in the art of computer security to help out in times of<br />
emergency or crises<br />
D. Make obtaining either a computer security certification or accreditation easier to achieve so<br />
more individuals feel that they are a part of something larger than life </p>
<p>Answer: B </p>
<p>Clive is conducting a pen-test and has just port scanned a system on the network. He has<br />
identified the operating system as Linux and been able to elicit responses from ports 23, 25 and<br />
53. He infers port 23 as running Telnet service, port 25 as running SMTP service and port 53 as<br />
running DNS service. The client confirms these findings and attests to the current availability of<br />
the services. When he tries to telnet to port 23 or 25, he gets a blank screen in response. On<br />
typing other commands, he sees only blank spaces or underscores symbols on the screen. What<br />
are you most likely to infer from this? </p>
<p>A. The services are protected by TCP wrappers<br />
B. There is a honeypot running on the scanned machine<br />
C. An attacker has replaced the services with trojaned ones<br />
D. This indicates that the telnet and SMTP server have crashed </p>
<p>Answer: A<br />
SSL has been seen as the solution to a lot of common security problems. Administrator will often<br />
time make use of SSL to encrypt communications from points A to point B. Why do you think this<br />
could be a bad idea if there is an Intrusion Detection System deployed to monitor the traffic<br />
between point A and B? </p>
<p>A. SSL is redundant if you already have IDS in place<br />
B. SSL will trigger rules at regular interval and force the administrator to turn them off<br />
C. SSL will mask the content of the packet and Intrusion Detection System are blinded<br />
D. SSL will slow down the IDS while it is breaking the encryption to see the packet content </p>
<p>Answer: C </p>
<p>Clive has been hired to perform a Black-Box test by one of his clients. How much information will<br />
Clive be able to get from the client before commencing his test? </p>
<p>A. Only the IP address range<br />
B. Nothing but corporate name<br />
C. All that is available from the client<br />
D. IP Range, OS, and patches installed </p>
<p>Answer: B </p>
]]></content:encoded>
			<wfw:commentRss>http://www.ec0-350.com/ec-council-ec0-350-test-questions-1.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PASSGUIDE EC0-350 BRAINDUMPS 1</title>
		<link>http://www.ec0-350.com/passguide-ec0-350-braindumps-1.html</link>
		<comments>http://www.ec0-350.com/passguide-ec0-350-braindumps-1.html#comments</comments>
		<pubDate>Thu, 24 Sep 2009 17:14:03 +0000</pubDate>
		<dc:creator>Ec-council</dc:creator>
				<category><![CDATA[Briandumps]]></category>

		<guid isPermaLink="false">http://www.ec0-350.com/?p=33</guid>
		<description><![CDATA[Exam Name:  ethical hacking and countermeasures
Exam Type  EC-Council
Exam Code:  EC0-350  Total Questions:  500
 An attacker runs netcat tool to transfer a secret file between two hosts. 
Machine A: netcat -l -p 1234 < secretfile
Machine B: netcat 192.168.3.4 > 1234 
He is worried about information being sniffed on the network. How [...]]]></description>
			<content:encoded><![CDATA[<p>Exam Name:  ethical hacking and countermeasures<br />
Exam Type  <a href="http://www.passguide.com/ec-council.html">EC-Council</a><br />
Exam Code:  EC0-350  Total Questions:  500<br />
 <span id="more-33"></span>An attacker runs netcat tool to transfer a secret file between two hosts. </p>
<p>Machine A: netcat -l -p 1234 < secretfile<br />
Machine B: netcat 192.168.3.4 > 1234 </p>
<p>He is worried about information being sniffed on the network. How would the attacker use netcat<br />
to encrypt the information before transmitting onto the wire? </p>
<p>A. Machine A: netcat -l -p -s password 1234 < testfile<br />
Machine B: netcat <machine A IP> 1234<br />
B. Machine A: netcat -l -e magickey -p 1234 < testfile<br />
Machine B: netcat <machine A IP> 1234<br />
C. Machine A: netcat -l -p 1234 < testfile -pw password<br />
Machine B: netcat <machine A IP> 1234 -pw password<br />
D. Use cryptcat instead of netcat </p>
<p>Answer: D<br />
Jess the hacker runs L0phtCrack&#8217;s built-in sniffer utility that grabs SMB password hashes and<br />
stores them for offline cracking. Once cracked, these passwords can provide easy access to<br />
whatever network resources the user account has access to. But Jess is not picking up hashes<br />
from the network. Why? </p>
<p>A. The physical network wire is on fibre optic cable<br />
B. The network protocol is configured to use IPSEC<br />
C. The network protocol is configured to use SMB Signing<br />
D. L0phtCrack SMB sniffing only works through Switches and not Hubs </p>
<p>Answer: C </p>
<p>Jack is conducting a port scan of a target network. He knows that his target network has a web<br />
server and that a mail server is up and running. Jack has been sweeping the network but has not<br />
been able to get any responses from the remote target. Check all of the following that could be a<br />
likely cause of the lack of response? </p>
<p>A. The host might be down<br />
B. UDP is filtered by a gateway<br />
C. ICMP is filtered by a gateway<br />
D. The TCP window size does not match<br />
E. The destination network might be down<br />
F. The packet TTL value is too low and cannot reach the target </p>
<p>Answer: A, C, E, F </p>
<p>You are attempting to map out the firewall policy for an organization. You discover your target<br />
system is one hop beyond the firewall. Using hping2, you send SYN packets with the exact TTL<br />
of the target system starting at port 1 and going up to port 1024. What is this process known as? </p>
<p>A. Firewalking<br />
B. Footprinting<br />
C. Enumeration<br />
D. Idle scanning </p>
<p>Answer: A<br />
Question: 11<br />
How would you prevent session hijacking attacks? </p>
<p>A. Using biometrics access tokens secures sessions against hijacking<br />
B. Using non-Internet protocols like http secures sessions against hijacking<br />
C. Using hardware-based authentication secures sessions against hijacking<br />
D. Using unpredictable sequence numbers secures sessions against hijacking </p>
<p>Answer: D </p>
<p>What does the term &#8216;Hacktivism&#8217; means? </p>
<p>A. Someone who is hacking for a cause<br />
B. Someone that has an urge to constantly hack<br />
C. Someone who subscribe to hacker&#8217;s magazine<br />
D. Someone who has at least 12 years of hacking experience </p>
<p>Answer: A<br />
During the intelligence-gathering phase of a penetration test, you discover a press release by a<br />
security products vendor stating that they have signed a multi-million dollar agreement with the<br />
company you are targeting. The contract was for vulnerability assessment tools and network<br />
based IDS systems.<br />
While researching on that particular brand of IDS you notice that its default installation allows it to<br />
perform sniffing and attack analysis on one NIC and is managed and sends reports via another<br />
NIC. The sniffing interface is completely unbound from the TCP/IP stack by default. Assuming the<br />
defaults were used, how can you detect these sniffing interfaces? </p>
<p>A. The sniffing interface cannot be detected<br />
B. Send attack traffic and look for it to be dropped by the IDS<br />
C. Use a ping flood against the IP of the sniffing NIC and look for latency in the responses<br />
D. Set your IP to that of the IDS and look for it to begin trying to knock your computer off the<br />
network </p>
<p>Answer: A<br />
Matthew re-injects a captured wireless packet back onto the network. He does this hundreds of<br />
times within a second. The packet is correctly encrypted and Matthew assumes it is an ARP<br />
request packet. The wireless host responds with a stream of responses, all individually encrypted<br />
with different IVs. What is this attack most appropriately called? </p>
<p>A. Spoof attack<br />
B. Replay attack<br />
C. Injection attack<br />
D. Rebound attack </p>
<p>Answer: B<br />
John is discussing security with Jane; she mentioned a few times to John that she suspects an<br />
LKM was installed on her server and this is why it has been acting so erratically lately. LKM<br />
stands for Loadable Kernel Module, what does it mean in the context of Linux Security? </p>
<p>A. Loadable Kernel Modules are a mechanism for adding functionality to a filesystem without<br />
requiring a kernel recompilation<br />
B. Loadable Kernel Modules are a mechanism for adding auditing to an operating-system kernel<br />
without requiring a kernel recompilation<br />
C. Loadable Kernel Modules are a mechanism for adding functionality to an operating-system<br />
kernel without requiring a kernel recompilation<br />
D. Loadable Kernel Modules are a mechanism for adding functionality to an operating-system<br />
kernel after it has been recompiled and the system rebooted </p>
<p>Answer: C<br />
Oregon Corp is fighting a litigation suit with Scamster Inc. Oregon has assigned a private<br />
investigative agency to go through garbage, recycled paper, and other rubbish at Scamster&#8217;s<br />
office site in order to find relevant information. What would you call this kind of activity? </p>
<p>A. Scanning<br />
B. CI Gathering<br />
C. Dumpster Diving<br />
D. Garbage Scooping </p>
<p>Answer: C </p>
<p>Jonathan being a keen administrator has followed all of the best practices he could find on<br />
securing his Windows Server. He renamed the Administrator account to a new name that cannot<br />
be easily guessed but there remain people who attempt to compromise his newly renamed<br />
administrator account. How can a remote attacker decipher the name of the administrator<br />
account if it has been renamed? </p>
<p>A. The attacker guessed the new name<br />
B. The attacker used the user2sid program<br />
C. The attacker used the sid2user program<br />
D. The attacker used NMAP with the V switch </p>
<p>Answer: C</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ec0-350.com/passguide-ec0-350-braindumps-1.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>E-council Ceh Ec0-350</title>
		<link>http://www.ec0-350.com/e-council-ceh-ec0-350.html</link>
		<comments>http://www.ec0-350.com/e-council-ceh-ec0-350.html#comments</comments>
		<pubDate>Tue, 31 Mar 2009 11:50:04 +0000</pubDate>
		<dc:creator>Ec-council</dc:creator>
				<category><![CDATA[Briandumps]]></category>

		<guid isPermaLink="false">http://www.ec0-350.com/?p=23</guid>
		<description><![CDATA[download it from my directory..
hxxp://rapidshare.com/files/90499411/ec0-3502.73.rar
Also some of guys they like TK&#8230; So also i am going to provide you link for latest TK
hxxp://rapidshare.com/files/90501234/EC0-350.zip
It does have 4 part .Each part contains 150 question. Preparing for this exam.. But its too difficult.. But i will clear it soon..Need to spend alot time.
Anyway was looking for this version [...]]]></description>
			<content:encoded><![CDATA[<p>download it from my directory..</p>
<p>hxxp://rapidshare.com/files/90499411/ec0-3502.73.rar<br />
Also some of guys they like TK&#8230; So also i am going to provide you link for latest TK</p>
<p>hxxp://rapidshare.com/files/90501234/EC0-350.zip</p>
<p>It does have 4 part .Each part contains 150 question. Preparing for this exam.. But its too difficult.. But i will clear it soon..Need to spend alot time.</p>
<p>Anyway was looking for this version from last 2 months but finally today got it.</p>
<p>Tell me if you guys like my post</p>
<p>Don&#8217;t forget to use [req] or [offer] in the topic title </p>
<p>Hey.. thanks for the post but i think theres a newer version with 900 questions.. the 2.73 only has 600 questions.. if you go to pass4sure website you&#8217;ll see it clearly says 900 questions..updated august 2007 &#8230;.im also in search for the newer one .. let me know if u get any luck in finding it ! n good luck on your exam   </p>
<p>thanks for the share </p>
<p>(chaltikanaamgaadi @ Feb 10 2008, 02:53 AM)<br />
Hi Guys</p>
<p>Finally i got it.. yeah</p>
<p>download it from my directory..</p>
<p>hxxp://rapidshare.com/files/90499411/ec0-3502.73.rar<br />
Also some of guys they like TK&#8230; So also i am going to provide you link for latest TK</p>
<p>hxxp://rapidshare.com/files/90501234/EC0-350.zip</p>
<p>It does have 4 part .Each part contains 150 question. Preparing for this exam.. But its too difficult.. But i will clear it soon..Need to spend alot time.</p>
<p>Anyway was looking for this version from last 2 months but finally today got it.</p>
<p>Tell me if you guys like my post</p>
<p>Thanks very much man i was having version 2.29&#8230; but with ur gr8 help i found this new version but can u pls help in finding the latest version which is 2.93 which contains 900 Q &#038; A </p>
<p>thankc once again!!!!!!!!god blesh you </p>
]]></content:encoded>
			<wfw:commentRss>http://www.ec0-350.com/e-council-ceh-ec0-350.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Newest Testinside Ec0-350 V3.29.vce</title>
		<link>http://www.ec0-350.com/newest-testinside-ec0-350-v329vce.html</link>
		<comments>http://www.ec0-350.com/newest-testinside-ec0-350-v329vce.html#comments</comments>
		<pubDate>Tue, 31 Mar 2009 11:47:41 +0000</pubDate>
		<dc:creator>Ec-council</dc:creator>
				<category><![CDATA[Briandumps]]></category>

		<guid isPermaLink="false">http://www.ec0-350.com/?p=21</guid>
		<description><![CDATA[Description
Hello Guys, Newest TestInside EC0-350 v3.29.vce for you, 220 Q&#038;A.
Grab it here:
Download:
http://rapidshare.com/files/119539066/TestInside_EC0-350_v3.29.vce.html
http://www.testinside.com/EC0-350.htm
Have fun!
CONAN  
(conan69 @ Jun 2 2008, 06:22 PM)
Hello Guys, Newest TestInside EC0-350 v3.29.vce for you, 220 Q&#038;A.
Grab it here:
Download:
http://rapidshare.com/files/119539066/TestInside_EC0-350_v3.29.vce.html
http://www.testinside.com/EC0-350.htm
Have fun!
CONAN 
Does you have lastest Pass4sure CEH version 2.93 with 900 Questions?
Thanks
(conifer @ Jun 2 2008, 04:47 PM)
(conan69 @ Jun 2 2008, 06:22 [...]]]></description>
			<content:encoded><![CDATA[<p>Description</p>
<p>Hello Guys, Newest TestInside EC0-350 v3.29.vce for you, 220 Q&#038;A.</p>
<p>Grab it here:</p>
<p>Download:<br />
http://rapidshare.com/files/119539066/TestInside_EC0-350_v3.29.vce.html</p>
<p>http://www.testinside.com/EC0-350.htm</p>
<p>Have fun!</p>
<p>CONAN  </p>
<p>(conan69 @ Jun 2 2008, 06:22 PM)<br />
Hello Guys, Newest TestInside EC0-350 v3.29.vce for you, 220 Q&#038;A.</p>
<p>Grab it here:</p>
<p>Download:<br />
http://rapidshare.com/files/119539066/TestInside_EC0-350_v3.29.vce.html</p>
<p>http://www.testinside.com/EC0-350.htm</p>
<p>Have fun!</p>
<p>CONAN </p>
<p>Does you have lastest Pass4sure CEH version 2.93 with 900 Questions?</p>
<p>Thanks</p>
<p>(conifer @ Jun 2 2008, 04:47 PM)<br />
(conan69 @ Jun 2 2008, 06:22 PM)<br />
Hello Guys, Newest TestInside EC0-350 v3.29.vce for you, 220 Q&#038;A.</p>
<p>Grab it here:</p>
<p>Download:<br />
http://rapidshare.com/files/119539066/TestInside_EC0-350_v3.29.vce.html</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ec0-350.com/newest-testinside-ec0-350-v329vce.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>pass4sure ec-council ceh ec0-350</title>
		<link>http://www.ec0-350.com/pass4sure-ec-council-ceh-ec0-350.html</link>
		<comments>http://www.ec0-350.com/pass4sure-ec-council-ceh-ec0-350.html#comments</comments>
		<pubDate>Tue, 31 Mar 2009 11:42:07 +0000</pubDate>
		<dc:creator>Ec-council</dc:creator>
				<category><![CDATA[Briandumps]]></category>

		<guid isPermaLink="false">http://www.ec0-350.com/?p=19</guid>
		<description><![CDATA[ethical hacking and countermeasures : ec0-350 Exam
Exam Number/Code: ec0-350
Exam Name: ethical hacking and countermeasures
&#8220;ethical hacking and countermeasures&#8221;, also known as ec0-350 exam, is a ec-council certification.
Preparing for the ec0-350 exam? Searching ec0-350 Test Questions, ec0-350 Practice Exam,  ec0-350 dumps]]></description>
			<content:encoded><![CDATA[<p>ethical hacking and countermeasures : ec0-350 Exam<br />
Exam Number/Code: ec0-350<br />
Exam Name: ethical hacking and countermeasures</p>
<p>&#8220;ethical hacking and countermeasures&#8221;, also known as ec0-350 exam, is a ec-council certification.<br />
Preparing for the ec0-350 exam? Searching ec0-350 Test Questions, ec0-350 Practice Exam,  ec0-350 dumps<</p>
<p>Free pass4sure ec0-350 Braindumps Demo Download  </p>
<p>The ec0-350 certificates give you possibility to work in any country of the world because they are acknowledged in all countries equally. This pass4sure ec0-350 torrent certificate helps not only to improve your knowledge and skills, but it also helps your career, gives a possibility for qualified usage of pass4sure ec0-350 training materials market  products under different conditions. The majority of companies in the sphere of information technologies require the presence of ec0-350 exam for the work in the company, and that makes obtaining this ec0-350 certificate necessary. Many IT specialists were not able to obtain the ec0-350 certificate from the first attempt, which was the result of poor preparation for the examination, using preparatory ec0-350 study guide of poor quality. </p>
<p>pass4sure ec0-350 Downloadable, Printable Exams (in pass4sure ePad pdf vce format):<br />
We are all well aware that a major problem in the IT industry is that there is a lack of quality study materials. Our Exam ec0-350 Preparation Material provides you everything you will need to take a certification examination. Details are researched and produced by Certification Experts who are constantly using industry experience to produce precise, and logical. You may get questions from different web sites or books, but logic is the key.</p>
<p><a href="http://www.pass4suredumps.org">pass4suredumps.org</a> ec0-350 Preparation from pass4sure include: </p>
<p>ec-council ec0-350 Q &#038; A with Explanations<br />
ec-council ec0-350 Audio Exam<br />
ec-council ec0-350 Preparation Lab<br />
ec-council ec0-350 rapidshare 4shared books</p>
<p><a href="http://http://www.pass4suredumps.org/category/ec-council/">pass4sure ec-council</a>  ec0-350 Tutorial, ec0-350 Exam Questions with Answers, ec0-350 Trainings, ec0-350 Online Course and free PDF</p>
<p>Our ec0-350 practice exams and study questions are composed by current and active Information Technology experts, who use their experience in preparing you for your future in IT.</p>
<p>100% Guarantee to Pass Your ec0-350 ExamIf you do not pass the  ec0-350 exam (ethical hacking and countermeasures) on your first attempt using our pass4sure testing engine, we will give you a FULL REFUND of your purchasing fee. </p>
<p>Your success in your coming ec0-350 ethical hacking and countermeasures Certification Exams is guaranteed using our ec-council ec0-350 Preparation Lab because our Preparation Labs are always updated in line with the changing ec-council ec0-350 Certification Exam Objectives. You can download our ec-council ec0-350 Preparation Labs anywhere anytime for a fast paced preparation of ec-council ec0-350 Certification Exam. You never have to attend any ec-council ec0-350 Training Class or ec-council ec0-350 Boot camp to pass in ec-council ec0-350 Certification Exam. We offer the latest and most accurate ec-council ec0-350 ethical hacking and countermeasures Preparation Lab with complete coverage of ec-council ec0-350 Exam Objectives and loads of professional experience.</p>
<p>pass4sure ec0-350 </p>
<p>Questions and Answers : 900 Q&#038;AsUpdated: February 11th , 2009<br />
http://rapidshare.com/files/215704122/www.pass4sure.cc_p4s_ec0-350_2.73_2.93.zip.html<br />
http://uploading.com/files/AVJ8FDFN/www.pass4sure.cc_p4s_ec0-350_2.73_2.93.zip.html<br />
http://rapidshare.de/files/46448698/www.pass4sure.cc_p4s_ec0-350_2.73_2.93.zip.html<br />
more info:<a href="http://www.examguard.net/download/braindumps/freetestking/ec-council">testking ec0-350</a><br />
more info:<a href="http://www.examguard.net/download/braindumps/freepass4sure/ec-council">pass4sure ec0-350</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.ec0-350.com/pass4sure-ec-council-ceh-ec0-350.html/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>ec0-council ec0-350 vce</title>
		<link>http://www.ec0-350.com/ec0-council-ec0-350-vce.html</link>
		<comments>http://www.ec0-350.com/ec0-council-ec0-350-vce.html#comments</comments>
		<pubDate>Tue, 31 Mar 2009 11:15:56 +0000</pubDate>
		<dc:creator>Ec-council</dc:creator>
				<category><![CDATA[Briandumps]]></category>

		<guid isPermaLink="false">http://www.ec0-350.com/?p=17</guid>
		<description><![CDATA[ EC0-350 Tests
Practice exams in VCE format:
File	Size	Date
ECCouncil ActualTests EC0-350 v2008-03-31 458q.vce	816.49 KB	18-Feb-2009
ECCouncil ActualTests EC0-350 v2008-03-31 by CONAN 458q.vce	3.99 MB	04-Jun-2008
ECCouncil TestInside EC0-350 v2008-04-21 by CONAN 220q.vce	10.92 MB	03-Jun-2008
ECCouncil ActualTest EC0-350 v 04 24 06 by SSB.vce	1.28 MB	21-Sep-2006
ECcouncil Actualtests EC0-350 v12.16.05 314q.zip	1.1 MB	26-Jul-2006
http://rapidshare.com/files/215696448/ec-council_ec0-350_vce_version.rar.html
http://rapidshare.de/files/46448289/ec-council_ec0-350_vce_version.rar.html
http://uploading.com/files/Y9O66H9U/ec-council_ec0-350_vce_version.rar.html
]]></description>
			<content:encoded><![CDATA[<p> EC0-350 Tests</p>
<p>Practice exams in VCE format:<br />
File	Size	Date<br />
ECCouncil ActualTests EC0-350 v2008-03-31 458q.vce	816.49 KB	18-Feb-2009<br />
ECCouncil ActualTests EC0-350 v2008-03-31 by CONAN 458q.vce	3.99 MB	04-Jun-2008<br />
ECCouncil TestInside EC0-350 v2008-04-21 by CONAN 220q.vce	10.92 MB	03-Jun-2008<br />
ECCouncil ActualTest EC0-350 v 04 24 06 by SSB.vce	1.28 MB	21-Sep-2006<br />
ECcouncil Actualtests EC0-350 v12.16.05 314q.zip	1.1 MB	26-Jul-2006<br />
http://rapidshare.com/files/215696448/ec-council_ec0-350_vce_version.rar.html<br />
http://rapidshare.de/files/46448289/ec-council_ec0-350_vce_version.rar.html<br />
http://uploading.com/files/Y9O66H9U/ec-council_ec0-350_vce_version.rar.html</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ec0-350.com/ec0-council-ec0-350-vce.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>actualtest ec-council ec0-350  2009</title>
		<link>http://www.ec0-350.com/actualtest-ec-council-ec0-350.html</link>
		<comments>http://www.ec0-350.com/actualtest-ec-council-ec0-350.html#comments</comments>
		<pubDate>Tue, 31 Mar 2009 10:40:07 +0000</pubDate>
		<dc:creator>Ec-council</dc:creator>
				<category><![CDATA[Briandumps]]></category>

		<guid isPermaLink="false">http://www.ec0-350.com/?p=13</guid>
		<description><![CDATA[QUESTION 1: 
What is the essential difference between an &#8216;Ethical Hacker&#8217; and a &#8216;Cracker&#8217;? 
A. The ethical hacker does not use the same techniques or skills as a cracker.
B. The ethical hacker does it strictly for financial motives unlike a cracker.
C. The ethical hacker has authorization from the owner of the target.
D. The ethical hacker [...]]]></description>
			<content:encoded><![CDATA[<p>QUESTION 1: </p>
<p>What is the essential difference between an &#8216;Ethical Hacker&#8217; and a &#8216;Cracker&#8217;? </p>
<p>A. The ethical hacker does not use the same techniques or skills as a cracker.<br />
B. The ethical hacker does it strictly for financial motives unlike a cracker.<br />
C. The ethical hacker has authorization from the owner of the target.<br />
D. The ethical hacker is just a cracker who is getting paid. </p>
<p>Answer: C </p>
<p>Explanation: The ethical hacker uses the same techniques and skills as a cracker<br />
and the motive is to find the security breaches before a cracker does. There is<br />
nothing that says that a cracker does not get paid for the work he does, a ethical<br />
hacker has the owners authorization and will get paid even if he does not succeed to<br />
penetrate the target.<br />
QUESTION 2: </p>
<p>What does the term &#8220;Ethical Hacking&#8221; mean? </p>
<p>A. Someone who is hacking for ethical reasons.<br />
B. Someone who is using his/her skills for ethical reasons.<br />
C. Someone who is using his/her skills for defensive purposes.<br />
D. Someone who is using his/her skills for offensive purposes. </p>
<p>Answer: C </p>
<p>Explanation: Ethical hacking is only about defending your self or your employer<br />
against malicious persons by using the same techniques and skills.<br />
QUESTION 3: </p>
<p>Who is an Ethical Hacker? </p>
<p>A. A person whohacksfor ethical reasons<br />
B. A person whohacksfor an ethical cause<br />
C. A person whohacksfor defensive purposes<br />
D. A person whohacksfor offensive purposes </p>
<p>Answer: C </p>
<p>Explanation: The Ethical hacker is a security professional who applies his hacking<br />
skills for defensive purposes. </p>
<p>QUESTION 4: </p>
<p>What is &#8220;Hacktivism&#8221;? </p>
<p>A. Hacking for a cause<br />
B. Hacking ruthlessly<br />
C. An association which groups activists<br />
D. None of the above </p>
<p>Answer: A </p>
<p>Explanation: The term was coined by author/critic Jason Logan Bill Sack in an<br />
article about media artist Shu Lea Cheang. Acts of hacktivism are carried out in the<br />
belief that proper use of code will have leveraged effects similar to regular activism<br />
or civil disobedience. </p>
<p>QUESTION 5: </p>
<p>Where should a security tester be looking for information that could be used by an<br />
attacker against an organization? (Select all that apply) </p>
<p>A. CHAT rooms<br />
B. WHOIS database<br />
C. News groups<br />
D. Web sites<br />
E. Search engines<br />
F. Organization&#8217;s own web site </p>
<p>Answer: A, B, C, D, E, F </p>
<p>Explanation: A Security tester should search for information everywhere that<br />
he/she can access. You never know where you find that small piece of information<br />
that could penetrate a strong defense. </p>
<p>QUESTION 7: </p>
<p>You are footprinting Acme.com to gather competitive intelligence. You visit the<br />
acme.com websire for contact information and telephone number numbers but do<br />
not find it listed there. You know that they had the entire staff directory listed on<br />
their website 12 months ago but now it is not there. How would it be possible for you<br />
to retrieve information from the website that is outdated? </p>
<p>A. Visit google search engine and view the cached copy.<br />
B. Visit Archive.org site to retrieve the Internet archive of the acme website.<br />
C. Crawl the entire website and store them into your computer.<br />
D. Visit the company&#8217;s partners and customers website for this information. </p>
<p>Answer: B </p>
<p>Explanation: The Internet Archive (<br />
IA) is a non-profit organization dedicated to maintaining an archive of Web and<br />
multimedia resources. Located at the Presidio in San Francisco, California, this<br />
archive includes &#8220;snapshots of the World Wide Web&#8221; (archived copies of pages,<br />
taken at various points in time), software, movies, books, and audio recordings<br />
(including recordings of live concerts from bands that allow it). This site is found at<br />
www.archive.org. </p>
<p>The actualtest ec-council ec0-350 certificates give you possibility to work in any country of the world because they are acknowledged in all countries equally. This  actualtest ec-council ec0-350 torrent certificate helps<br />
not only to improve your knowledge and skills, but it also helps your career, gives a possibility for qualified usage of  actualtest ec-council ec0-350 exam products under different conditions. The<br />
majority of companies in the sphere of information technologies require the presence of actualtest ec-council ec0-350 exams for the work in the company, and that makes obtaining this actualtest ec-council ec0-350<br />
certificate necessary. Many IT specialists were not able to obtain the real actualtest ec-council ec0-350 certificate from the first attempt, which was the result of poor preparation for the<br />
examination, using preparatory actualtest ec-council ec0-350 study guide of poor quality. </p>
<p>The leader among the providers of actualtest ec-council ec0-350 preparatory materials is  products such as actualtest ec-council ec0-350 vce pdf Braindumps, actualtest ec-council ec0-350 Tutorial, actualtest ec-council ec0-350 Exam Questions with Answers, actualtest ec-council ec0-350<br />
Trainings, actualtest ec-council ec0-350 Test Online Simulations Course and free PDF. It obtained its leadership and trust of the users from the very beginning of its work on the  actualtest ec-council ec0-350 training<br />
materials market. All the actualtest ec-council ec0-350 value pack aids have been created by people who are personally familiar with actualtests actualtest ec-council ec0-350 Preparation Labs and who know all the<br />
difficulties and popular mistakes made by those who take a actualtest ec-council ec0-350 . The entire material is logically composed in such a way that everything becomes easy to understand for<br />
anyone. full download Many actualtest ec-council ec0-350 guides include audio and video material. It is really easy to acquire  actualtest ec-council ec0-350 exams because of great variety of methods of payment.</p>
<p>pass4sure testking actualtest ec-council ec0-350 rapidshare 4shared links</p>
<p>http://rapidshare.de/files/46447891/www.ec0-350.com_new_actualtest_ceh.rar.html</p>
<p>http://rapidshare.com/files/215688520/www.ec0-350.com_new_actualtest_ceh.rar.html<br />
http://uploading.com/files/NBHQ3LRR/www.ec0-350.com_new_actualtest_ceh.rar.html</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ec0-350.com/actualtest-ec-council-ec0-350.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
