Image
 
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 23 guests and 1 member online
EH-Net Donations

Enter Amount:
$

Google Ads
EH-Net News Feeds
Latest Additions
Book Recommendations





 
Advertisement

You are here: Home arrow Forum arrow Ethical Hacking Discussions and Related Certificationsarrow Certificationarrow The Charter Study Group - Pen Testarrow Charter Study Group - Pen Test - Don
Ethical Hacker Community Forums
December 01, 2008, 07:24:16 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: ChicagoCon 2-Day Ethical Hacking Conference with MS Blue Hats Oct 31 - Nov 1. Tickets Only $100! www.chicagocon.com/content/view/103/51/
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Charter Study Group - Pen Test - Don  (Read 7360 times)
0 Members and 1 Guest are viewing this topic.
don
Editor-In-Chief
Administrator
Hero Member
*****
Offline Offline

Posts: 2380


Editor-In-Chief


View Profile WWW
« on: May 18, 2006, 03:15:20 PM »

Hi. I'm Don... (crowd responds, "Hiiiii Doonnnnn."), and I am addicted to computers.

 Cheesy

OK... in all seriouness... I had recommended that all members of the Charter Study Group for Pen Testing introduce themselves and let the rest of the group know where we are and how we plan to accomplish passing the CEH exam by June / July.

I have been working in IT for over a decade and have been a computer enthusiast for over 2. Security holds my interest, but it is not my only function on a day to day basis for my full time job. I also work hard to maintain a couple sites dealing with security. As in my signature, I currently have my CISSP, MCSE 2003 and Security+. I am also a Subject Matter Expert for Security+.

In prep for the CEH exam (the cert that members of the Charter Group chose as our first pen test credential), I have so far:

1. Setup virtual and real lab with XP, Win Server 2003 and Fedora Core 5. I may add RHEL4. I also have numerous bootable CDs and the individual hacking tools for practice.
2. Read Hacking for Dummies.
3. Familiarized myself with EC-Council's Course Outline.
4. Watched CBT Nuggets CEH Videos.

Plan to:

1. Read Exam Prep CEH
2. Watch Career Academy Videos
3. If time allows, I have several other titles that interest me such as Counter Hack Reloaded & Cisco Press Pen Testing that I have skimmed but would like to read more thoroughly.
4. Attend The Training Camp's CEH Boot Camp. I have already received the EC-Council Official Courseware that comes with 3 books, several CDs, a t-shirt and a backpack to hold it all.

That should be plenty. Wink

Don't know if I'll get to them all, but I'd like to write an article on my experience in attaining the CEH credential and do a comparison of study materials for others to use as a reference. So the more I use the more comprehensive the article will be.

Now that you know about me and how I plan to pass the CEH, it's time to hear from the other members.

I'll update this post as I move through the material,
Don
Logged

CISSP, MCSE, CEH, Security+ SME
Sniganoo
Newbie
*
Offline Offline

Posts: 13


View Profile
« Reply #1 on: May 22, 2006, 05:47:43 AM »

Hi Don et al.

I have just joined the forums here with a view to gaining some assistance, advice and guidance with my career goals.

I am looking to move into the security arena of IT after a lengthy stint as an IT consultant working in the UK and the USA.  I have been in IT for over 10 years and worked my way from a PC support guy to a Lotus Notes Consultant.  I have been approved by EC Council to take the CEH exam but now I see the CNDA exam I may choose to take that instead.  I also wish to pursue the CPTS cert in the future.

It looks like the study and practice for the CEH (or CNDA) test will take some time and involve a lot of reading and working in a lab environment to get familiar with the tools and techniques that will be tested.

I would appreciate any suggestions as to the best course of action.  I normally don't spend long gearing up for tests but this one makes me a little nervous.  I will be viewing  a few DVD's on the CEH topics and perhaps will buy the EC Council courseware but that is very expensive.

An example test lab would be great too.  I will need a few laptops to get it going.

I hope to be a valuable member of this community and wish you all success in achieving your goals.

Thanks.

Steve
Logged
don
Editor-In-Chief
Administrator
Hero Member
*****
Offline Offline

Posts: 2380


Editor-In-Chief


View Profile WWW
« Reply #2 on: May 22, 2006, 09:44:12 AM »

Well, first of all Welcome to EH-Net. We also look forward to you being a valuable member of this community.

As for help, look around the forums and the articles, if you have any specific question, feel free to start a new topic. I'm sure you'll get plenty of help from all of us.

Thanks for your words of encouragement,
Don
Logged

CISSP, MCSE, CEH, Security+ SME
Sniganoo
Newbie
*
Offline Offline

Posts: 13


View Profile
« Reply #3 on: May 23, 2006, 10:26:41 AM »

I have been working through CEH topics on DVD training by Mile2.  They seem pretty good but a little generalised at present.  They also say the training will enable you to take the CPTS test but I somehow doubt that.  DVD training is the next best thing to attending classes IMHO and better than just studying a book.  I will get familiar with the tools as they seem to focus heavily on those.

I will keep reading the posts here for useful tips for CEH study.

Thanks for the wlecome.

Steve
Logged
don
Editor-In-Chief
Administrator
Hero Member
*****
Offline Offline

Posts: 2380


Editor-In-Chief


View Profile WWW
« Reply #4 on: June 27, 2006, 12:56:57 PM »

Well... time for an update. It's Tues, and I just finished lunch at the site of the Training Camp CEH Boot Camp. All is going well so far. My best advice I can give to anyone looking into this process is to do 2 main things:

1. Pre-study. Read as much as you can and watch videos whether they be freebies online or retail CBTs of some sort. This way the boot camp seems like a review. This will help greatly in readying yourself for the exam.

2. Create a virtual lab using Windows 2000, WinXP and BackTrack. There are plenty others out there, but this will get you started. This way, you are not just reading about the tools, but you will have hands-on experience with them before class. If you never attend a class that sets up a lab computer for you, then this is your only option. If you do attend the class, still create your own virtual lab. As mentioned above, it allows the class to be more of a review. That way you can catch onto the subtle details and tricks as opposed to learning basics in class.

NOTE: When creating a virtual lab, especially in a classroom full of hackers, do not connect it to any network, wired or wireless. Install a MS Loopback  Adapter and make sure it is on the same subnet as the virtual machines.

Look for a more detailed tutorial on setting up a virtual lab from either Negrita or myself (and maybe both) in the coming weeks.

That's all for now. Class is starting again.

Stay tuned...

Don
Logged

CISSP, MCSE, CEH, Security+ SME
Negrita
Sr. Member
****
Offline Offline

Posts: 289



View Profile
« Reply #5 on: June 27, 2006, 02:13:08 PM »

Interesting post don. I agree that going to a class or boot camp should be used for revision and to ask the lecturer questions instead of learning the basics. Also once you know some stuff you can finally let it all loose on someone elses dedicated test lab.


Look for a more detailed tutorial on setting up a virtual lab from either Negrita or myself (and maybe both) in the coming weeks.


Well I started writing it up but got a bit side tracked. I'm not much of an expert but I don't mind sharing with others the way I set things up for myself, and hopefully some of you will find it interesting or even learn something new.  Wink
Logged

CEH, CCSA NG/AI, NNCSS, MCP, MCSA 2003

There are 10 kinds of people, those that understand binary, and those that don't.
jperkins
Newbie
*
Offline Offline

Posts: 1


View Profile
« Reply #6 on: June 28, 2006, 02:29:21 PM »

Don,

I didn't quite know where to post this.  I work with dengar13.  We are both attempting to pass the CPTS exam.  Do you if there is a list of topics published somewhere for the exam?

I would appreciate any help you could give on this.

Logged
don
Editor-In-Chief
Administrator
Hero Member
*****
Offline Offline

Posts: 2380


Editor-In-Chief


View Profile WWW
« Reply #7 on: June 29, 2006, 11:49:26 AM »

As for location of post, might be better suited as a new thread in the CPTS Forum:
http://www.ethicalhacker.net/component/option,com_smf/Itemid,35/board,3.0

Just to help, I'll answer.

For initial info, look at our CPTS Info Page under the Certs>Ethical Hacking Category:
http://www.ethicalhacker.net/content/view/37/3/

For specific modules to study, look at the CPTS - Official Course Modules v5 Board:
http://www.ethicalhacker.net/component/option,com_smf/Itemid,35/board,36.0

Hope that helps getting you going in the right direction,
Don
Logged

CISSP, MCSE, CEH, Security+ SME
don
Editor-In-Chief
Administrator
Hero Member
*****
Offline Offline

Posts: 2380


Editor-In-Chief


View Profile WWW
« Reply #8 on: June 30, 2006, 02:45:59 PM »

I passed my CEH exam!  Cool

I'm exhausted and a little under the weather, so look for more in a day or two. Also, I plan to do a full article for the site over the next few weeks.

Night night...

Don
Logged

CISSP, MCSE, CEH, Security+ SME
Negrita
Sr. Member
****
Offline Offline

Posts: 289



View Profile
« Reply #9 on: June 30, 2006, 03:25:22 PM »

Congrats Don.  Grin

I'm looking forward to reading about your experience. Have a good sleep and I hope you feel better.
Logged

CEH, CCSA NG/AI, NNCSS, MCP, MCSA 2003

There are 10 kinds of people, those that understand binary, and those that don't.
Oyle
Sr. Member
****
Offline Offline

Posts: 264


"Man. Nature. Technology".


View Profile WWW
« Reply #10 on: June 30, 2006, 07:31:14 PM »

Congrats, Don!!  Grin Grin Grin

Now you can look forward to getting your certificate...in about 3 MONTHS!! Eeeyow! That's really the hard part of the whole CEH exam experience. This AIN'T no Microsoft Exam, this is EC-Council!

 Cheesy Cheesy
Logged

MCP, MCP+I, MCSA, MCSE(NT4/W2K), CCNA, CCA, NWCCC, VH-PIRTS, CEH
--------------------
"hackers are like jedi, crackers are like the sith: do not fall prey to the dark side".

From 1337 h4x0r h4ndb00k: "the ten laws of geek", law x
                  -Tapeworm
Dengar13
Moderator
Full Member
*****
Offline Offline

Posts: 224



View Profile
« Reply #11 on: July 04, 2006, 11:29:53 PM »

Congrats Don!  Is there anything that you feel the boot camp didn't cover for the exam? 
Logged

A+, Net+, MCP, CEH
MCSE: Security/Messaging
MCSA: Security/Messaging
Former U.S. Marine and damn proud of it!
don
Editor-In-Chief
Administrator
Hero Member
*****
Offline Offline

Posts: 2380


Editor-In-Chief


View Profile WWW
« Reply #12 on: July 05, 2006, 12:03:18 AM »

In short - No. That doesn't mean that the exam itself covered every topic known to the field of pen testing. But the instructor did cover all topics more than adequately for exam success, and that was your question.

This is one of the areas on which I'll touch in the upcoming article on my quest for CEH. The Training Camp (TTC), being an official training partner with several cert organizations, seems to catch on to the organizations 'way' of doing things. Just as there is the Microsoft Way when taking a MS exam, there is also a way of thinking and certain topics that deserve greater focus for every exam. TTC seems to grasp those subtleties and pass them onto their students. I'm not saying they give you exact questions and answers like a brain dump. They do instruct using the official course work of the given organization, but they also make slight changes in an attempt to convey the info better. So I guess it's more like a mindset dump.

I hope that's not too vague, but at midnight after spending the entire day in the sun, it's the best I can do.  Cheesy

Don
Logged

CISSP, MCSE, CEH, Security+ SME
Dengar13
Moderator
Full Member
*****
Offline Offline

Posts: 224



View Profile
« Reply #13 on: July 05, 2006, 12:05:46 AM »

Thanks Don.  Now you will get to log onto their (EC-Council's) portal which is pretty cool.  Are they still on version 4 of the exam?

Day in the sun?  Lucky you, I am working, but at least I am working from home.   Grin
Logged

A+, Net+, MCP, CEH
MCSE: Security/Messaging
MCSA: Security/Messaging
Former U.S. Marine and damn proud of it!
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.7 | SMF © 2006-2008, Simple Machines LLC
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.058 seconds with 24 queries.
 
Sponsors

cwnp_moto__120x90.gif

Polls
During the most recent election, I:
 
Support EH-Net


Support EH-Net by
Buying all of your
Amazon items using
the search bar above.

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!
Recent Forum Topics
Vote For EH-Net

progenic.com
Click here to Vote!

Sadikhov.com
Top IT Cert Sites

binarica.com
Binarica Logo

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2008 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.