Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 37 guests and 1 member online
You are here:
Home
Ethical Hacking Discussions and Related Certifications
Network Pen Testing
CEH - Certified Ethical Hacker
How I passed the CEH(v5) exam
EH-Net
May 19, 2013, 09:57:19 PM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Ethical Hacking Discussions and Related Certifications
>
Network Pen Testing
>
CEH - Certified Ethical Hacker
(Moderator:
don
) >
How I passed the CEH(v5) exam
Pages: [
1
]
2
Go Down
« previous
next »
Print
Author
Topic: How I passed the CEH(v5) exam (Read 45425 times)
0 Members and 1 Guest are viewing this topic.
nebu10uz
Sr. Member
Offline
Posts: 368
How I passed the CEH(v5) exam
«
on:
May 27, 2007, 03:48:45 PM »
I remember last year as I began to search for information regarding the CEH certification, I stumbled upon this site. And I'm glad I did. The EH-NET community contributed information that I later use to help me pass the exam and I will try to summarize it here.
I'm a type of guy that likes to read books and study for a cert on my own pace, so that's why I prefer the via self-study approach as opposed to boot camps. First, because my current employer won't pay for it and I don't have the financial means for paying a full blown course. Second, I learn and retain information better if I study on my own.
So I went ahead and registered to this site. I began to read articles about the subject and also posted questions to the forum in which responses were immediately received. The following links will direct you to the CEH topic forums that helped me with my study:
http://www.ethicalhacker.net/component/option,com_smf/Itemid,54/topic,561.msg2731/#msg2731
http://www.ethicalhacker.net/component/option,com_smf/Itemid,54/topic,279.msg3574/#msg3574
http://www.ethicalhacker.net/component/option,com_smf/Itemid,49/topic,174.0/
http://www.ethicalhacker.net/component/option,com_smf/Itemid,49/topic,665.0/
http://www.ethicalhacker.net/component/option,com_smf/Itemid,54/topic,1148.msg4330/topicseen,1/#new
I started to study last September by reading the first book (Gray Hat Hacking : The Ethical Hacker's Handbook). This book is a little advance and it talks about vulnerability tools, advance port scanners, programming survival skills and buffer overflow. I began reading this book because I was fascinated with exploit coding, source code analysis and the like, and because I already had 2 years experience under my belt in the security field. If you lack the knowledge of hacking methodology, buffer overflows and pertinent tools then I suggest that you read this book last after reading the other books that I will now mention.
My second book (Counter Hack Reloaded by Ed Skoudis). Awesome book on step-by-step hacking and countermeasure. Ed illustrates and explains clearly on how to ethically hack systems and network in a methodical fashion. If you really want to learn on how to conduct a penetration test and how to defend your network, this is the book. It gives you a clear picture on the methodology that the hacker use to compromise your network.
The other two books that I will now list is mainly focus on the cert itself. After reading Ed Skoudis' book you should have a clear understanding of the hacking methodology, these books will focus the main objectives of the CEH to help you pass the exam. For a detail explaintions on CEH and it's objectives, I recommend (Certified Ethical Hacker Exam Prep (Exam Prep 2)). This is book is far way better compared to EC-Council official courseware. The book help grasps knowledge of network penetration testing skills. Please be advice though, there's lots of typo errors some misinformation. Just read carefully and if you find something that you don't understand or confused about, research your question or post your inquiries to the forums. I did purchase CEH(v5) courseware but I only read half of it because there was to many information to read and for you to remember. It did not help me accept for the lab manual and tools that came with the cd. However, in my exam there were only few tools that I was asked about. The courseware in my oppnion is only good for reference. If you have the money and would like to add it to your library then go ahead and buy it but other than that you can definitely pass the exam without it. The second book focusing on CEH which I highly recommend is the (CEH: Official Certified Ethical Hacker Review Guide: Exam 312-50). This book really narrows down what you need to know to pass the CEH exam. It's concise, covering all exam objectives and it's officially endorsed by EC-Council. This is book is a must have. Some of the practice questions that came with the review guide especially from the cd rom was ask in my exam.
So basically these are the books that I read for the exam. As I was reading these books I created a virtual lab at home and practice the tools mentioned in those books. This will really help for the exam as you will definintly remember the commands and switches when ask in the test. Now even though I created a virtual lab I was compel to enroll the Offensive Security 101 class because of the course price and earning an additional certification just by taking their hacking challenge exam and at the same time practice the tools and methodology for the CEH exam. Man, this couldn't have come in a better time. The Offensive course helped me apply my hacking skills that I learned from reading the aforemention books and from the course itself. I consider this to be the best hacking course out there for the money. For my complete OffSec 101 review please refer to the following link:
http://www.ethicalhacker.net/component/option,com_smf/Itemid,54/topic,1152.0/
As for practice test is concern, I purchased TestKing CEH practice test since I heard good things about it. The product came with 458 312-50 downloadable exam engine and a downloadable, printable exams (in Testking iPad format). This played a big part of me passing the exam as well as practicing the test questions that came with CEH focus exam prep books. The practice tests helped me evaluate my understanding of the material and enforce my preparation for the exam. Check the following for more info:
http://www.testking.com/312-50.htm
To sum it up, it took me 8 months of preparation for the CEH(v5) exam via self-study and compared to a boot-camp sessions I know that the majority of the people will choose this route instead. But let me tell you that it is all worth it and I can't tell you how much I learned during the course of my studies. At the end, I earned two certification and only spent less than $800 not counting the official courseware from EC-Council (which really did not help me in this case) and including Offensive Security 101 course. I think you can't go wrong with the strategy that I took. Anyways, I hope this information that I hand before you will help you earn the Certified Ethical Hacker certification and I would once again like to express my gratitute to EH-NET site creator Don and it's wonderful members for an excellente site. Thank you.
Additional info with regards to the CEH(v5) exam:
In the exam I had a lot of questions on snort, nmap, honeypot, firewall and tcpdump logs. Make sure you know how to interpret these. Know how to read code, for instance, C, ASP and bash scripts. There were multiple questions on buffer overflow, SQL injection and such. As for the hacking tools, in my exam there only a few such as nmap, hping, snort command line and ettercap. Just follow the (CEH: Official Certified Ethical Hacker Review Guide: Exam 312-50) and read about the tools described in this book. As a matter of fact, this book really hit the spot and informs you what you should expect from the test. Know your ports such as (21(ftp), 23(telnet), 389(ldap)).
Overall the test was diverse in its entirety in terms of the questions being ask. I considered the CEH(v5) to be a good test.
For all future candidates, good luck
«
Last Edit: May 28, 2007, 07:55:56 AM by blackazarro
»
Logged
Security+, OSCP, CEH
don
Editor-In-Chief
Administrator
Hero Member
Offline
Posts: 4165
Editor-In-Chief
Re: How I passed the CEH(v5) exam
«
Reply #1 on:
May 27, 2007, 06:02:17 PM »
Great recap. Although you thanked me in your post (much appreciated BTW), you also thanked the EH-Net community. That's where most of the praise should be directed. If anyone is new to this site, blackazarro is the perfect example of the type of members he himself mentions in his post. He basically gives you a blueprint to pass the CEH v5 exam.
Well done,
Don
Logged
CISSP, MCSE, CSTA, Security+ SME
vp75
Jr. Member
Offline
Posts: 78
Re: How I passed the CEH(v5) exam
«
Reply #2 on:
May 29, 2007, 08:18:10 AM »
Quote from: blackazarro on May 27, 2007, 03:48:45 PM
So basically these are the books that I read for the exam. As I was reading these books I created a virtual lab at home and practice the tools mentioned in those books. This will really help for the exam as you will definintly remember the commands and switches when ask in the test.
For all future candidates, good luck
Hi Blackasarro,
Firstly congrats on your passing CEH,
Could you give details or setup on what type of virtual lab you set for your practice and workouts....
Iam also in the same learning rope of setting up virtual lab, it would be useful if you could let me know like what you used like Microsoft virtual product or vmware product and number of windows & linux on virtual lab...!
Cheers
Vp
Logged
eCPPT
nebu10uz
Sr. Member
Offline
Posts: 368
Re: How I passed the CEH(v5) exam
«
Reply #3 on:
May 29, 2007, 02:25:17 PM »
First of all, thank you for your comment vp75. I basically followed Negrita's "Virtual Lab with VMware" article. Just click on the following link:
http://www.ethicalhacker.net/content/view/63/2/
However, instead of using VMware to create the virtual machines I used VMX Builder, a free easy-to-use desktop tool for creating virtual machines. For additional info about this app please refer to the following link:
http://petruska.stardock.net/Software/VMware.html
http://www.linux.com/article.pl?sid=06/10/31/1822248
I also used irongeek's video
http://irongeek.com/i.php?page=videos/vmxbuilder
to learn how to use it in conjunction with VMware's player.
My virtual lab consist of 2 Windows Server (2000 and 2003), a linux server (Ubuntu 6.10) and my slax client (Backtrack final 2.0) for conducting attacks against these server as well as my Windows XP professional client.
«
Last Edit: May 29, 2007, 03:42:20 PM by blackazarro
»
Logged
Security+, OSCP, CEH
Kev
Guest
Re: How I passed the CEH(v5) exam
«
Reply #4 on:
May 30, 2007, 12:19:00 AM »
Thats a good line up for your lab and I am glad to see you included Xp pro. Some people make the mistake of having nothing but servers in their test lab and neglect the regular user client. While its true that the server is almost always the end target, sometimes the only way in is to attack a normal user in the network and then after owning that box, attack the server from there. I have known situations where the a workers home computer was first owned and from there the hacker was able to connect to the employees workplace computer. After that, the hacker had full access on the network to begin his attack on the server from the inside which is often easier.
Logged
vp75
Jr. Member
Offline
Posts: 78
Re: How I passed the CEH(v5) exam
«
Reply #5 on:
May 31, 2007, 06:58:11 PM »
Hi blackazarro
Thanks for your reply, I have started installing VMplayer and knoppix520 (5.2.0) version , it says that vmplayer doesnt support and need advanced player ...a bit literally confused and now trying to download vmplayer 2.0 and reinstall it, in the meantime
could you provide me with which version of linux flavours used in vmplayer....it could be helpful in setting up for me,
cheers
Vp
Logged
eCPPT
dalepearson
Sr. Member
Offline
Posts: 357
Re: How I passed the CEH(v5) exam
«
Reply #6 on:
June 01, 2007, 02:50:39 AM »
Well Done,
this is an excellent post, it helps to reasure me about my plans for certification.
May I ask how much time you spent each week on study?
Thanks
Dale
Logged
:: Subliminal Hacking ::
/
:: Security Active Blog ::
nebu10uz
Sr. Member
Offline
Posts: 368
Re: How I passed the CEH(v5) exam
«
Reply #7 on:
June 01, 2007, 10:49:37 AM »
When it comes to studying, I'm a bit lazy but I have a good reason for this. I usually work 50 hours a week (sometimes more) and getting to work takes a hour (sometimes 2 depending on traffic). So I don't have a lot of free time to on my hands. However, during the week I always manage to squeeze in 2 hours for studying. In the weekends I usually dedicate my time on other things but if I have some extra free time then I use it for studying.
Books or study guides that ranges from 400 to 600 pages takes me about a month to complete. So let say I have 4 books to read, it usually takes me 4 months to read it.
After reading all the books and doing lab work I devote my time in taking and studying practice tests. I always dedicate 2 weeks for this before taking the exam.
I used this exact methods mentioned above for my Security+ and CEH certs and I had no problems passing the exams on my first try.
Hope this helps.
«
Last Edit: June 01, 2007, 04:29:33 PM by blackazarro
»
Logged
Security+, OSCP, CEH
nebu10uz
Sr. Member
Offline
Posts: 368
Re: How I passed the CEH(v5) exam
«
Reply #8 on:
June 01, 2007, 11:09:01 AM »
Hey vp75, sorry I didn't see your post until now. As mentioned in Negrita's article on creating your virtual lab, go to
http://www.vmware.com/vmtn/appliances/directory/
to look for virtual appliances. There's different variety of linux flavor to choose from so I suggest you check this website and download the distro you're interested in.
As stated in
http://www.vmware.com/vmtn/appliances/index.html
,
Quote
A virtual appliance is a pre-built, pre-configured and ready-to-run software application packaged with the operating system inside a virtual machine
You should have no problem running these virtual appliances using VMware Player.
Another thing, what Operating System you are using? That's probably why you need to install the new VMware Player. The new version supports Windows Vista.
http://blogs.vmware.com/news/2007/05/vmware_player_2.html
Logged
Security+, OSCP, CEH
Negrita
Sr. Member
Offline
Posts: 299
Re: How I passed the CEH(v5) exam
«
Reply #9 on:
June 01, 2007, 03:01:06 PM »
Nice post blackazzaro. It's full of excellent info, just what a lot of people here are looking for.
BTW, thanks for using my tutorial. I'm glad that someone here got more out of it than just a good read.
Logged
CEH, CCSA NG/AI, NNCSS, MCP, MCSA 2003
There are 10 kinds of people, those that understand binary, and those that don't.
don
Editor-In-Chief
Administrator
Hero Member
Offline
Posts: 4165
Editor-In-Chief
Re: How I passed the CEH(v5) exam
«
Reply #10 on:
June 01, 2007, 03:08:10 PM »
Seeing as though it has gotten almost 12,000 hits, I think it has done more good than you think.
Don
Logged
CISSP, MCSE, CSTA, Security+ SME
nebu10uz
Sr. Member
Offline
Posts: 368
Re: How I passed the CEH(v5) exam
«
Reply #11 on:
June 01, 2007, 04:39:13 PM »
No, thank you Negrita for writing a good article that is useful. I'm hope that this forum can help someone achieve their goal in earning the CEH.
Wow, almost 12,000 hits, that awesome
Logged
Security+, OSCP, CEH
vp75
Jr. Member
Offline
Posts: 78
Re: How I passed the CEH(v5) exam
«
Reply #12 on:
June 01, 2007, 05:07:48 PM »
Quote from: blackazarro on June 01, 2007, 11:09:01 AM
Hey vp75, sorry I didn't see your post until now. As mentioned in Negrita's article on creating your virtual lab, go to
http://www.vmware.com/vmtn/appliances/directory/
to look for virtual appliances. There's different variety of linux flavor to choose from so I suggest you check this website and download the distro you're interested in.
As stated in
http://www.vmware.com/vmtn/appliances/index.html
,
Quote
A virtual appliance is a pre-built, pre-configured and ready-to-run software application packaged with the operating system inside a virtual machine
You should have no problem running these virtual appliances using VMware Player.
Another thing, what Operating System you are using? That's probably why you need to install the new VMware Player. The new version supports Windows Vista.
http://blogs.vmware.com/news/2007/05/vmware_player_2.html
Hi blackazarro
Thanks for your reply and explanation.
I got installed VMPlayer ver 2 and tried knoppix and got error as it didnt come with .iso image file, now downloading it, hope would take another 1hr approx to download 697MB.
Regarding virtual appliance i saw one of the link got Hacking and networking security usage & training tool, but OS it says is Suse linux, does it mean it cant be used in Knoppix environment....? (sorry for this dumb question)
Again the scripts whatever we write in linux can it be saved into virtual machine & compile and run it...?
Being on learning rope i hope you guys understand what i am pointing at...
your help is appreciated.
Cheers
Vp
Logged
eCPPT
nebu10uz
Sr. Member
Offline
Posts: 368
Re: How I passed the CEH(v5) exam
«
Reply #13 on:
June 01, 2007, 05:45:30 PM »
Vp75, it appears that you're a bit confuse and that's ok. I was also confuse when I started to learn about VMware and virtual machines. I encourage you to reread Negrita's article carefully. What ever linux distro you download, you have to use a virtualization software in order to convert it to a virtual machines. Then use the VMware Player to boot-up the linux OS or whatever OS you interested in.
As for the knoppix distro, download the iso image and burned this to a cd. In your burning cd software, make sure to choose the option for burning iso image to a cd. Then use VMware Server or VMX Builder as I mentioned before, to create the virtual machine. This step here is similar to installing a OS on your system but you are doing it virtually. I haven't used knoppix for while but I think this distro does have an option to install it on a hard drive.
After successfully installing knoppix virtually you can add scripts, download applications and configure settings in your virtual machine and this will be saved.
Suse and Knoppix are two different linux distribution, for complete info refer to the following links:
http://en.wikipedia.org/wiki/SUSE_Linux
http://en.wikipedia.org/wiki/Knoppix
Vp75, if you still having problems in creating and playing virtual machines, I recommend that you check EH-NET forums for any information that will help you on the subject or create a new forum topic so we can address your problems there. I would like to keep this forum topic CEH related
,thanks.
Logged
Security+, OSCP, CEH
Negrita
Sr. Member
Offline
Posts: 299
Re: How I passed the CEH(v5) exam
«
Reply #14 on:
June 02, 2007, 03:54:18 AM »
To install Knoppix you should boot from the live CD and then open a shell and then type:
Code:
sudo knoppix-installer
After that just follow the wizard. For more info check here;
http://www.knoppix.net/wiki/Knoppix_Installer
.
Logged
CEH, CCSA NG/AI, NNCSS, MCP, MCSA 2003
There are 10 kinds of people, those that understand binary, and those that don't.
Pages: [
1
]
2
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
OSCP - Offensive Security Certified Professional
: Failed my first attempt at the OSCP exam
(84) by
impelse
OSCP - Offensive Security Certified Professional
: OSCP exam scheduled
(6) by
gbhat
Incident Response
: LinkedIn Forensics
(0) by
AFENTIS_Forensics
General Certification
: Red Team/Blue Team
(1) by
ajohnson
OSCP - Offensive Security Certified Professional
: Class Scheduled 6/8 - Linux n00b
(6) by
Grendel
Career Central
: Starter cert?
(3) by
Grendel
Network Pen Testing
: Beginner Ethical Hacker
(1) by
m0wgli
General Certification
: CPT Practical Submission
(0) by
z28power4u
Web Applications
: Nessus and Nikto
(4) by
Seen
Tutorials
: Need guidance
(7) by
impelse
Malware
: EICAR?
(2) by
SephStorm
Network Pen Testing
: Cracking salted MD5 hash
(4) by
n37sh@rk
CEH - Certified Ethical Hacker
: Passed my C|EH
(3) by
n37sh@rk
Mass Media
: EC-council hacked, irony at his best?
(0) by
j0rDy
Web Applications
: SQL Injection into an INSERT statement.
(6) by
eyenit0
Network Pen Testing
: Solution for sipXtapi INVITE Message CSeq Field Header Remote Overflow
(1) by
m0wgli
Web Applications
: dns
(2) by
H1t M0nk3y
Other
: BSides Boston
(0) by
3xban
Career Central
: InfoSec in Central, FL
(2) by
tturner
Web Applications
: Web vulnerability scanner
(4) by
H1t M0nk3y
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.