Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 28 guests online
You are here:
Home
Ethical Hacking Discussions and Related Certifications
Network Pen Testing
OSCP - Offensive Security Certified Professional
Anyone did OSCE (CTP) ?
EH-Net
May 20, 2013, 12:14:04 AM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Ethical Hacking Discussions and Related Certifications
>
Network Pen Testing
>
OSCP - Offensive Security Certified Professional
(Moderator:
don
) >
Anyone did OSCE (CTP) ?
Pages: [
1
]
2
Go Down
« previous
next »
Print
Author
Topic: Anyone did OSCE (CTP) ? (Read 13227 times)
0 Members and 1 Guest are viewing this topic.
H1t M0nk3y
Hero Member
Offline
Posts: 864
Anyone did OSCE (CTP) ?
«
on:
May 19, 2010, 07:59:03 AM »
Hey,
I am almost done doing OSCP and I love it. I would like to start OSCE in early fall. Did anyone on this forum completed the CTP course and passed the OSCE certification?
I am curious to hear some review/feedback.
Logged
OSCP, GPEN, GWAPT, GSEC, CEH, CISSP
MaXe
Hero Member
Offline
Posts: 669
I've just upgraded myself to a cyborg muahahaa!!1
Re: Anyone did OSCE (CTP) ?
«
Reply #1 on:
August 17, 2010, 09:58:13 AM »
I recently did the course and I can only say good things about it.
Cracking the Perimeter is a journey of practical hacking combined with imaginative thinking allowing you to perform complex hacks in order to, yes penetrate / crack the perimeter.
Even within the Web Application Security part I learned something new and during the rest of the course I learned a lot about shellcode, overflows, and everything else mentioned on their website which is a must to know (in hardcore depth) if you want to pass the certification.
I used many hours within the labs where I made sure to learn everything I could and more about the course material.
I don't think anyone will regret doing this course, cause it's probably one of the hardest if not the hardest certification to achieve at the moment
«
Last Edit: August 17, 2010, 10:04:28 AM by MaXe
»
Logged
I'm an InterN0T'er
ajohnson
Recruiters
Hero Member
Offline
Posts: 1057
aka dynamik
Re: Anyone did OSCE (CTP) ?
«
Reply #2 on:
August 17, 2010, 03:28:40 PM »
Welcome to the forums MaXe!
Can you give any required skills/recommended resources to fill in the gaps between the OSCP and OSCE. It was my impression that the OSCE was significantly more advanced, and it wasn't intended to simply be a natural continuation of the OSCP.
Logged
WIP: GCFA |
www.infosiege.net
| @infosiege
The day you stop learning is the day you start becoming obsolete.
former33t
Full Member
Offline
Posts: 226
Re: Anyone did OSCE (CTP) ?
«
Reply #3 on:
August 17, 2010, 05:32:28 PM »
I start on the 29th, so I'll be sure to try to fill in the blanks as I go. I haven't done OCSP, so taking on the OCSE was a little intimidating. I finally decided that I had enough interest in the topic to invest the time and enough background to not be wasting my money so I bit the bullet and went for it. I'll post back by mid September and let you know if I think it was a mistake.
If anyone can share some insight (besides what's in the syllabus), please do so. I've already paid, so I'm stuck, but I would like to know about others' experiences.
I made the decision after hearing the same thing as MaXe said echoed by everyone who had taken the course (I won't regret it).
Logged
Certifications: CREA, MCSE: Security, CCNA, Security+, other junk
hayabusa
Hero Member
Offline
Posts: 1630
Re: Anyone did OSCE (CTP) ?
«
Reply #4 on:
August 17, 2010, 07:03:32 PM »
While I've not paid for it, yet (and won't be until my medical situation is squared away and I'm off these darned meds,) this one is on my list, for one of my next certs to do. So by all means, let us know what you think of it, former33t (and any others who challenge the course.)
Logged
~ hayabusa ~
"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'
OSCE, OSCP , GPEN, C|EH
MaXe
Hero Member
Offline
Posts: 669
I've just upgraded myself to a cyborg muahahaa!!1
Re: Anyone did OSCE (CTP) ?
«
Reply #5 on:
August 20, 2010, 06:45:01 AM »
@dynamik: The syllabus gives an idea of what to expect:
http://www.offensive-security.com/documentation/cracking-the-perimiter-syllabus.pdf
and you should be able to complete
http://fc4.me/
as well. You can try out the FC4.me challenge without registering.
The skills I think that are required to do the course only would be:
- Web Application Security knowledge. (PHP, MySQL and Apache)
-- You should be able to understand how most if not all vulnerabilities within PHP works.
-- Here's a good "article" to read:
http://forum.intern0t.net/offensive-guides-information/1382-finding-vulnerabilities-php-sirgod.html
-- Have a good understanding of how the HTTP protocol works.
- Stack Buffer Overflows with and without SEH overwrites
-- You'll learn a lot about overflows in the PWB course but there are other resources available too.
-- You should be able to understand this perfectly:
http://forum.intern0t.net/cinema/video-21/
(Here's an article about this old exploit:
http://en.wikibooks.org/wiki/Metasploit/WritingWindowsExploit
)
- Shellcode and Assembly Instructions / Opcodes
-- You should be able to write simple shellcode or be ready to become dedicated to write your own shellcode.
-- If you're not a shellcode "writer" you should be ready to manually write it yourself.
(Metasploit can't always help you in cases where you must use advanced methods.)
- Generic knowledge about networks and other protocols
-- You should know how the TCP/IP (and UDP) protocols function though you don't have to be an engineer.
-- Have a basic understanding of spoofing and man-in-the-middle attacks.
Note: Knowing a scripting language such as Python, Perl or perhaps PHP (CLI) is a good idea too.
You should also have a lot of patience, the will to learn new topics (in-depth, don't avoid any of the exercises) and have a lot of time you can use in the labs to study the course material and the following exercises.
If you choose 30 days it may be some very intensive 30 days, and if you choose 60 days then you should be able to have spare time in between. (I did this course after work in case you wonder.)
About the examination, well I won't disclose too many details on that. But everything covered in the course is only the beginning and you should therefore dedicate a lot of time to learn Web Application Security and Software Exploitation / Security in-depth. (This includes self-written (custom) optimized shellcode and a lot more!)
One shouldn't be intimidated by these facts, because it is one of the greatest journeys I've ever taken and I believe it really is one of the toughest if not the toughest certification at this date. If you have this certification, then I know you're above average within IT-security / Hacking
@former33t: I haven't done the PWB Course neither the OSCP examination, but it is possible to do and understand the CTP course if you have a good understanding about IT-security / Hacking. You won't regret this course ;-)
Logged
I'm an InterN0T'er
H1t M0nk3y
Hero Member
Offline
Posts: 864
Re: Anyone did OSCE (CTP) ?
«
Reply #6 on:
August 20, 2010, 08:02:23 AM »
Great review MaXe!
I am challenging OSCP tomorrow morning and
IF
everything goes well, OSCE would probably be the next one.
Quote
The skills I think that are required to do the course only would be:
- Web Application Security knowledge. (PHP, MySQL and Apache)
-- You should be able to understand how most if not all vulnerabilities within PHP works.
-- Here's a good "article" to read:
http://forum.intern0t.net/offensive-guides-information/1382-finding-vulnerabilities-php-sirgod.html
-- Have a good understanding of how the HTTP protocol works.
I am also looking at a very good web app pentest course. Would you consider OSCE to cover web app exploit in depth?
Logged
OSCP, GPEN, GWAPT, GSEC, CEH, CISSP
impelse
Hero Member
Online
Posts: 565
Re: Anyone did OSCE (CTP) ?
«
Reply #7 on:
August 20, 2010, 08:38:11 AM »
Quote from: H1t M0nk3y on August 20, 2010, 08:02:23 AM
Great review MaXe!
I am challenging OSCP tomorrow morning and
IF
everything goes well, OSCE would probably be the next one.
You will be find tomorrow in your challenge.
Logged
CCNA, Security+, 70-290, 70-291
CCNA Security
Taking Hackingdojo training
Website:
http://blog.thehost1.com/
H1t M0nk3y
Hero Member
Offline
Posts: 864
Re: Anyone did OSCE (CTP) ?
«
Reply #8 on:
August 20, 2010, 08:40:32 AM »
Thanks impelse.
I am almost ready now. Just one or two things to read and practice and I relax until the exam.
Logged
OSCP, GPEN, GWAPT, GSEC, CEH, CISSP
hayabusa
Hero Member
Offline
Posts: 1630
Re: Anyone did OSCE (CTP) ?
«
Reply #9 on:
August 20, 2010, 09:29:51 AM »
Yep... relax!
Let us now how it goes. Excited for you. It's quite an experience!
Logged
~ hayabusa ~
"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'
OSCE, OSCP , GPEN, C|EH
ajohnson
Recruiters
Hero Member
Offline
Posts: 1057
aka dynamik
Re: Anyone did OSCE (CTP) ?
«
Reply #10 on:
August 20, 2010, 09:31:55 AM »
Thanks for the feedback, MaXe.
I got through their registration challenge quickly, but I really don't want to give me a false sense of where I stand in terms of the course content. I'm solid on the networking side of things, decent with the web stuff, but I am completely lacking on shellcoding/exploit development side of things.
Logged
WIP: GCFA |
www.infosiege.net
| @infosiege
The day you stop learning is the day you start becoming obsolete.
MaXe
Hero Member
Offline
Posts: 669
I've just upgraded myself to a cyborg muahahaa!!1
Re: Anyone did OSCE (CTP) ?
«
Reply #11 on:
August 20, 2010, 09:48:41 AM »
Quote from: H1t M0nk3y on August 20, 2010, 08:02:23 AM
Great review MaXe!
I am challenging OSCP tomorrow morning and
IF
everything goes well, OSCE would probably be the next one.
Quote
The skills I think that are required to do the course only would be:
- Web Application Security knowledge. (PHP, MySQL and Apache)
-- You should be able to understand how most if not all vulnerabilities within PHP works.
-- Here's a good "article" to read:
http://forum.intern0t.net/offensive-guides-information/1382-finding-vulnerabilities-php-sirgod.html
-- Have a good understanding of how the HTTP protocol works.
I am also looking at a very good web app pentest course. Would you consider OSCE to cover web app exploit in depth?
Thanks and good luck!
The CTP course will give you some ideas about Web Application Security in-depth and the examination will prove that point, but it does not cover everything there is and you should have a very good base either from another certification or by self-study.
I don't know of any certifications within Web App Sec that are worth doing but I'll be glad to hear of any
Quote from: dynamik on August 20, 2010, 09:31:55 AM
Thanks for the feedback, MaXe.
I got through their registration challenge quickly, but I really don't want to give me a false sense of where I stand in terms of the course content. I'm solid on the networking side of things, decent with the web stuff, but I am completely lacking on shellcoding/exploit development side of things.
Sounds good, but you should focus on learning more about Exploit Development then and of course Shellcoding even though most of this is covered within the course quite well (don't forget to use the forums too). I can't say that you'll know everything about exploit development after the CTP course, cause you won't but you'll have a better understanding especially if you've played with a few simple Stack Overflows in the past
Note: Nothing within the CTP course and the OSCE examination is impossible to do, but it is quite hard. (Especially the exam.)
«
Last Edit: August 20, 2010, 09:55:19 AM by MaXe
»
Logged
I'm an InterN0T'er
ajohnson
Recruiters
Hero Member
Offline
Posts: 1057
aka dynamik
Re: Anyone did OSCE (CTP) ?
«
Reply #12 on:
August 20, 2010, 10:02:19 AM »
Oh yea, I've got Gray Hat Hacking, The Shellcoder's Handbook, and Hacking: The Art of Exploitation on my reading list. I fully intend on being prepared.
Thanks again for the feedback
Logged
WIP: GCFA |
www.infosiege.net
| @infosiege
The day you stop learning is the day you start becoming obsolete.
Equix3n-
Sr. Member
Offline
Posts: 386
Re: Anyone did OSCE (CTP) ?
«
Reply #13 on:
August 20, 2010, 10:36:11 AM »
@dynamik
Nothing related to this thread, but just wanted to tell you that if you ever start learning from shellcoder's handbook use an old distro for the first 4-5 chapters. Preferably Redhat Linux 8 and above.
The examples used in these chapters assume that you've absolutely no protection enabled in your system- NX bits, ASLR... Even Redhat Linux 9 uses ASLR, built in the kernel and can't be disabled, and so you won't be able to use it for a LOT of exploits.
Majority of these protections can be disabled in the current distributions but there are still hidden elements which prevent your code from working properly. I learned all of this the hard way
It's still fun to first test your code in an old distro and then try to make it work in the newer ones
Logged
ajohnson
Recruiters
Hero Member
Offline
Posts: 1057
aka dynamik
Re: Anyone did OSCE (CTP) ?
«
Reply #14 on:
August 20, 2010, 11:02:30 AM »
I think I saw you make note of that before, but thanks for the reminder
Logged
WIP: GCFA |
www.infosiege.net
| @infosiege
The day you stop learning is the day you start becoming obsolete.
Pages: [
1
]
2
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
OSCP - Offensive Security Certified Professional
: Failed my first attempt at the OSCP exam
(86) by
impelse
Tutorials
: Need guidance
(8) by
r0ckm4n
OSCP - Offensive Security Certified Professional
: Class Scheduled 6/8 - Linux n00b
(7) by
Taemyks
OSCP - Offensive Security Certified Professional
: OSCP exam scheduled
(6) by
gbhat
Incident Response
: LinkedIn Forensics
(0) by
AFENTIS_Forensics
General Certification
: Red Team/Blue Team
(1) by
ajohnson
Career Central
: Starter cert?
(3) by
Grendel
Network Pen Testing
: Beginner Ethical Hacker
(1) by
m0wgli
General Certification
: CPT Practical Submission
(0) by
z28power4u
Web Applications
: Nessus and Nikto
(4) by
Seen
Malware
: EICAR?
(2) by
SephStorm
Network Pen Testing
: Cracking salted MD5 hash
(4) by
n37sh@rk
CEH - Certified Ethical Hacker
: Passed my C|EH
(3) by
n37sh@rk
Mass Media
: EC-council hacked, irony at his best?
(0) by
j0rDy
Web Applications
: SQL Injection into an INSERT statement.
(6) by
eyenit0
Network Pen Testing
: Solution for sipXtapi INVITE Message CSeq Field Header Remote Overflow
(1) by
m0wgli
Web Applications
: dns
(2) by
H1t M0nk3y
Other
: BSides Boston
(0) by
3xban
Career Central
: InfoSec in Central, FL
(2) by
tturner
Web Applications
: Web vulnerability scanner
(4) by
H1t M0nk3y
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.