Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 30 guests online
 
Advertisement

You are here: Home arrow Ethical Hacking Discussions and Related Certificationsarrow General Certificationarrow oscp challenge exam question
EH-Net
May 25, 2013, 01:30:23 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: oscp challenge exam question  (Read 10117 times)
0 Members and 1 Guest are viewing this topic.
bowerbird001
Newbie
*
Offline Offline

Posts: 3



View Profile
« on: May 18, 2009, 11:50:19 AM »

i am studying for my oscp.
i have my challenge exam coming up soon.
i have ran out of lab time.
to pass the challenge i feel i may need some more experience in sql injection and creation of exploits.

could anyone advise me where i can find a few tutorials for the creation of exploits.
i would like the tutorial to be with current or easy to find software that is freeware/shareware.
i say this as the example in the oscp used software that is superseded and also not freeware/shareware.

the main parts of the sql injection i would like to practice is command injection and gaining shell.
also could someone please tell me how i could practice sql injection.
my guess is i would have to create the database that allowed sql injection to be preformed on.
and then practice on that.
Logged
ethicalhack3r
Full Member
***
Offline Offline

Posts: 139


View Profile WWW
« Reply #1 on: May 18, 2009, 02:24:24 PM »

Hello,
Im not sure about exploit creation but for SQL injection you could use a tool that I developed last year. 'Damn Vulnerable Web App' is a deliberatly insecure web application that allows you to 'train' on. However id also like to point out that there are other apps out there that do the same and in some cases better.

Damn Vulnerable Web App:
http://www.ethicalhack3r.co.uk

Check out irongeeks tool:
http://www.irongeek.com/i.php?page=videos/mutillidae-1-setup

Logged
Orhan
Newbie
*
Offline Offline

Posts: 14

If at first you don't succeed, cheat!


View Profile
« Reply #2 on: May 20, 2009, 03:50:27 PM »

I believe you can download some extra software to exploit from the offsec forums. 

As for tutorials on exploits, the are several videos in this forum as well as on the offsec forum taking you through the process of exploit development and bypassing different issues (i.e. pop pop ret).

I hope his helps.  Good luck with the exam!
Logged

GPEN OSCP OSWP CCSE CCSA CHFI..etc
Bronze Swimming certificate..
ethicalhack3r
Full Member
***
Offline Offline

Posts: 139


View Profile WWW
« Reply #3 on: May 20, 2009, 04:06:44 PM »

Orhan: I couldnt help notice that your sig is wrong or is it purposely like that?

Away
Pizza
Sausage
Throw
Not
Do
Please
Logged
Orhan
Newbie
*
Offline Offline

Posts: 14

If at first you don't succeed, cheat!


View Profile
« Reply #4 on: May 20, 2009, 04:09:38 PM »

I just love sausage pizza....
Logged

GPEN OSCP OSWP CCSE CCSA CHFI..etc
Bronze Swimming certificate..
Orhan
Newbie
*
Offline Offline

Posts: 14

If at first you don't succeed, cheat!


View Profile
« Reply #5 on: May 20, 2009, 04:15:32 PM »

I have changed it to avoid any further confusion...(probably mine)  Embarrassed
Logged

GPEN OSCP OSWP CCSE CCSA CHFI..etc
Bronze Swimming certificate..
bowerbird001
Newbie
*
Offline Offline

Posts: 3



View Profile
« Reply #6 on: May 21, 2009, 05:37:41 AM »

thanks guys.

ethicalhack3r thanks for your advise. that helped.

Orhan: i had also lost access to the offsec forums, that's why i posted for help here and not there.

but anyway i added more time.
so now i have access. Smiley
Logged
agurrutiac15
Newbie
*
Offline Offline

Posts: 2


View Profile
« Reply #7 on: May 26, 2009, 04:09:32 PM »

I am taking the OSCP challenge this Friday May29, 2009. I did 6 out of the final 7 challenges (For those OSCP grads, you probably know which is the one I could not pwn). I am looking for any hints some could give me on what to focus my studies. I' appreciate any tips you can give me....

Andres Urrutia
CCNA, MCSA, Net+
Logged
Orhan
Newbie
*
Offline Offline

Posts: 14

If at first you don't succeed, cheat!


View Profile
« Reply #8 on: May 28, 2009, 12:07:47 PM »

agurrutiac15,

I think if you applied yourself during the course you should be fine.  Also, by doing the extra credit questions you will have some bonus points to go towards your exam (should you need it). There are plenty to be had throughout the course. 

The exam can be a full 24 hours so get plently of rest and happy hacking!!

Good luck and let us know how you get on.

Logged

GPEN OSCP OSWP CCSE CCSA CHFI..etc
Bronze Swimming certificate..
agurrutiac15
Newbie
*
Offline Offline

Posts: 2


View Profile
« Reply #9 on: June 16, 2009, 01:40:30 PM »

Orphan thank you for your response... I passeeeed! I am now an OSCP. The exam was tough but liked it. Once again thank you!

Andres Urrutia

CCNA, OSCP, MSCA, Net+
Logged
don
Editor-In-Chief
Administrator
Hero Member
*****
Offline Offline

Posts: 4169


Editor-In-Chief


View Profile WWW
« Reply #10 on: June 16, 2009, 02:22:46 PM »

w00t!!

As you grow into your career, hopefully you'll share your thoughts and experiences with the EH-Net Community.

Don
Logged

CISSP, MCSE, CSTA, Security+ SME
UNIX
Hero Member
*****
Offline Offline

Posts: 1235


View Profile
« Reply #11 on: June 17, 2009, 12:04:37 AM »

Congratulation for passing, agurrutiac15. Wink
Logged
Orhan
Newbie
*
Offline Offline

Posts: 14

If at first you don't succeed, cheat!


View Profile
« Reply #12 on: June 19, 2009, 04:49:11 AM »

Orhan thank you for your response... I passeeeed! I am now an OSCP. The exam was tough but liked it. Once again thank you!

Andres Urrutia

CCNA, OSCP, MSCA, Net+

Congrats agurrutiac15! Well done!
Logged

GPEN OSCP OSWP CCSE CCSA CHFI..etc
Bronze Swimming certificate..
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.148 seconds with 24 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Free Business and Tech Magazines and eBooks

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.