Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 49 guests and 2 members online
 
Advertisement

You are here: Home
EH-Net
May 22, 2013, 03:02:47 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
  Home Help Calendar Login Register  
  Show Posts
Pages: 1 ... 39 40 [41] 42 43 ... 45
601  Ethical Hacking Discussions and Related Certifications / OSCP - Offensive Security Certified Professional / Re: Why I failed OSCP... on: November 12, 2010, 10:28:19 AM
Sorry to hear that H1t M0nk3y, but did you read these?
The Penetration Testers Open Source Toolkit vol. 2
and NIST SP800-42 (it's outdated I know, but read it anyway. It will give you some good ideas you can use when you perform pentests.)

Also, about privilege escalation:
- On Windows, the Meterpreter shell has a lot of options including privilege escalation, is it not possible to use that only? (Code your own exploits, and use a meterpreter as a payload.)
 
- On Linux, did you search on Exploit-DB for privilege escalation exploits and checked what was running on the target machine as root with "ps faux"?

It's just a few ideas, to help you the next time you attempt OSCP because I actually believed you would pass  Wink

For now I would say that you could (or should) play with similar challenges and prepare for your last and final retake (where you will certainly pass).


Nothing is impossible, it just takes time!  Smiley

Anyway, good luck with whatever you choose to do now. I'm sure you will pass OSCP the next time if you study hard for a long time and prepare yourself even more, remember, expect the unexpected. Especially during OffSec exam challenges ;-)



Best regards,
MaXe
602  Ethical Hacking Discussions and Related Certifications / OSCP - Offensive Security Certified Professional / Re: OSCE Certified! on: November 12, 2010, 10:10:11 AM
Thanks a lot to all of you, it was a huge satisfaction to finally pass and become certified since it's one of my dreams to take all the best certifications and I believe Offensive Security is some of the very best courses + certifications  Smiley (Even though they're not easy, they're awesome imho.)
603  Ethical Hacking Discussions and Related Certifications / OSCP - Offensive Security Certified Professional / OSCE Certified! on: November 12, 2010, 08:14:01 AM
Dear community of The Ethical Hacker Network,



After many months of struggle I have finally been able to pass my OSCE examination and I am now Offensive Security Certified Expert. The course it self was hard but not impossible to learn, do and complete however the examination was not easy at all.

It isn't for fun you're certified as an "Expert" when you do the OSCE certification because it really is that hard in my opinion, but far from impossible as you can see since there are OSCE's in this world.

I don't think it would be appropriate by copy+pasting my process here through CTP (Cracking the Perimeter) and the OSCE examination, so here's the links to my 4 blog entries about the course and the final examination.

Links:
http://forum.intern0t.net/blogs/maxe/95-cracking-perimeter-part-1.html
http://forum.intern0t.net/blogs/maxe/101-cracking-perimeter-part-2.html
http://forum.intern0t.net/blogs/maxe/108-cracking-perimeter-part-3.html
http://forum.intern0t.net/blogs/maxe/111-cracking-perimeter-part-4.html

You can read about the certification here:
http://www.offensive-security.com/information-security-certifications/#OSCE



Best regards,
MaXe
604  Ethical Hacking Discussions and Related Certifications / OSCP - Offensive Security Certified Professional / Re: Exam soon! on: November 12, 2010, 08:00:40 AM
Good luck! Even though he's already doing the exam as far as I know  Smiley
605  Ethical Hacking Discussions and Related Certifications / Web Applications / Re: Just another guy asking suggestions for learning the basics os Web-Exploitation on: November 11, 2010, 03:19:53 PM
This is coming from someone without a Web Application background, plus many on the forum here have said that it is the strongest compared to other courses.

Looks like I have to do some serious work soon then  Grin Something for people already knowing Web App Sec  Wink

I'm confused by what you mean, I think I have MatterOverMind, due to some overdosage of morning Cinamon Toast Crunch...

Excuse me for being cryptic, what I meant was a course meant for pros at Web App Sec Smiley

I know it sounds cryptic, but hehe nevermind  Grin Forget what I said :-P
606  Ethical Hacking Discussions and Related Certifications / Web Applications / Re: Just another guy asking suggestions for learning the basics os Web-Exploitation on: November 11, 2010, 07:49:43 AM
This is coming from someone without a Web Application background, plus many on the forum here have said that it is the strongest compared to other courses.

Looks like I have to do some serious work soon then  Grin Something for people already knowing Web App Sec  Wink
607  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Ethical Hackers Wanted for Global Cyber Warfare Simulation on: November 09, 2010, 09:44:31 AM
This was also posted in the "Information Security" group on LinkedIn.

As someone posted on LinkedIn, we'd like more information about who is hosting this event and preferably more details.  Smiley
608  Ethical Hacking Discussions and Related Certifications / General Certification / Re: Report for eLearnsecurity on: November 06, 2010, 04:39:37 PM
Yes, by the way your site game a good ideas. In this casr l allow to penetrate


Thanks, check out Hacking Lab too! They hot a challenge going on at the moment  Grin
http://www.hacking-lab.com/events/swiss-cyber-storm-3-cargame-challenge.html
609  Ethical Hacking Discussions and Related Certifications / General Certification / Re: Report for eLearnsecurity on: November 06, 2010, 06:11:47 AM
By the way you learn a lot doing the report, because you have to read and make sure that the vulnerability or attack vector that you are putting there, match with your prove, so in other words you validate your own exploit.

Nice, glad to hear you enjoy their courses  Smiley

However, I always validate the exploits I use and perform. Else you can't really confirm it exists nor that the target is vulnerable. There are of course some scenarios with IRL vulnerability assessments where you're not allowed to test exploits on critical infrastructure, but if you're allowed then it's a good idea to check if the target really is unpatched / insecure.
610  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: which sans course i should take first? sans660 or sans706! on: November 06, 2010, 06:09:47 AM
Neither  Grin

If you're into really advanced penetration testing, Cracking the Perimeter by Offensive Security is the way to go. They got live and online courses.

If you want to write advanced exploits on Windows, then sign up for their AWE class.

It's most likely also a lot cheaper and you'll also, most likely gain a lot more knowledge.
611  EH-Net / News Items and General Discussion About EH-Net / Re: [Article]-November 2010 Free Giveaway Sponsor - InfoSec Institute on: November 03, 2010, 02:47:34 PM
Awesome, good luck to anyone participating and of course the winner when that time comes  Smiley
612  Ethical Hacking Discussions and Related Certifications / OSCP - Offensive Security Certified Professional / Re: Exam soon! on: November 03, 2010, 09:30:24 AM
Good luck! OSCE was extremely challenging.  Knowing what you do now, I'm sure it will help a lot on the next attempt.  Let us know how you do! 

Thanks, did you do OSCE yet?  Grin (I know this topic is about OSCP, but I am doing OSCE currently.)  Wink

Anyway I'll make a thread if I am successful  Smiley
613  Ethical Hacking Discussions and Related Certifications / OSCP - Offensive Security Certified Professional / Re: OSCP Walkthrough on: November 03, 2010, 09:24:45 AM
*just a post to hijack the threat back...

Im still working on this, and i will not let it go until i pass. Currently im starting to go over the course material again and see if i can reflect it to the steps i took during the exam. I will post a real update when i find the time to do so. I will keep you guys updated!

Check out these books from Syngress too:
- The Metasploit Toolkit (may seem a bit outdated)
- The Penetration Testers Open Source Toolkit vol. 2 (highly recommendable)

Also if you don't know a scripting language, learn Python or Perl, or perhaps Ruby and then a Web Application language like PHP as well. That will help you a lot  Smiley

The most important thing you need to do, is to find out why you possibly failed if you did, and then know what you need to improve on accurately and then take your time to learn this area a lot more, even if you already know it.

Anyway, good luck :-)
614  EH-Net / News Items and General Discussion About EH-Net / Re: The True Power a Hacker Possesses on: November 02, 2010, 06:02:02 PM
Welcome TeknoGod,


If you're in for a bit more detailed and technical content, check out http://InterN0T.net too which has some nice videos too you might want to check out. Stay away from the script kiddie communities and hopefully stay ethical too  Grin (Exploit-DB has a nice blog section with some very nice entries as well imho)



Best regards,
MaXe
615  Ethical Hacking Discussions and Related Certifications / Web Applications / Re: exploiting vulnerable http methods and ./ directory traversal ? on: November 02, 2010, 02:28:21 PM
Thanks MaXe, I just subscribed to your YouTube Channel.

I am looking forward to your demo...

Awesome!  Grin You'll like it, after all it's free and realistic  Smiley
Pages: 1 ... 39 40 [41] 42 43 ... 45
Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.063 seconds with 21 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Free Business and Tech Magazines and eBooks

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.