Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 30 guests online
 
Advertisement

You are here: Home arrow Ethical Hacking Discussions and Related Certificationsarrow Network Pen Testingarrow OSCP - Offensive Security Certified Professionalarrow OSCP, Beginner?
EH-Net
May 25, 2013, 10:11:41 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: OSCP, Beginner?  (Read 7711 times)
0 Members and 1 Guest are viewing this topic.
SephStorm
Hero Member
*****
Offline Offline

Posts: 530


View Profile WWW
« on: July 23, 2010, 07:07:31 PM »

Hi all,

I am looking at getting into pentesting, and I have been throwing the choices around in my head for some time. As someone with no real pentesting experience, is OSCP recommended?

i am also considering CEH,CPT,CPTE,and any other T1 pentesting certs, if anyone thinks one of these would be more appropriate.

I want to mention my experience: A+N+/S+, Security5, CIW Associate

Thanks in advance.
Logged

Dark_Knight
Sr. Member
****
Offline Offline

Posts: 292


View Profile WWW
« Reply #1 on: July 23, 2010, 08:36:00 PM »

Hi SS,
My first certification was the CEH and it served as a great introduction to the field of penetration testing. The material was just enough to get me started. The exercises/labs looking back at them now were pretty basic Smiley So the 'exploits' were against a windows 2000 box and if I remember correctly the exploit was the good old rpc_dcom. Point is it was nothing fancy, but at the end of the course it got me thinking about security. So everything I did from that point on was done with security in mind.

The OSCP on the other hand was a different beast. This course took it to an entire new level. So, I remember 'reading' about buffer overflows in the CEH. Well I actually did it in the OSCP. A lot of the topics covered in the CEH came to life in the OSCP. Sql injection that I had read about in the CEH, I actually got the chance to do it on several occasions. Another is example is metasploit. During the CEH, someone in the class used msf to pwn the windows 2000 server. And let me tell you I was blown away by it. Fast forward to the OSCP and I was not only using the msf but I was actually editing some of the exploits. Really getting into the guts. And where as in the CEH I could identify exploits that were say in the C programming language, in the OSCP I was editing the code.

The OSCP is also ALL YOU. No lecturers to run to. Nobody to hold your hand and spoon feed you. It can be REALLY frustrating at times. Google and the oscp irc channel become your best friend. The exam is also another thing. You have 24hrs to pwn a set of boxes that you are seeing for the first time. No multiple choice exam. So the OSCP will take your skills to the next level.

So now that you have all this 'raw' skill it now needs to be refined. Enter the Sans GPEN. This course covers the business side of things. So it takes you through setting everything up on the business side. Things like rules of engagement, various laws, establishing scope etc are covered. Really important stuff. And it also further explains some of the concepts learned in the OSCP. Rainbow tables comes to mind.

So having said ALL that you could run with the CEH and then make your way up to the OSCP.

My .02
« Last Edit: July 23, 2010, 08:43:18 PM by Dark_Knight » Logged

CEH, OSCP, GPEN, GWAPT, GCIA
http://sector876.blogspot.com
chrisj
Hero Member
*****
Offline Offline

Posts: 1163


View Profile WWW
« Reply #2 on: July 23, 2010, 08:37:31 PM »

I can't really answer if OSCP is a beginner course or not. There are a couple of reviews on the site to look at. Ryan Lynn (apollo I think) and J0rDy.

However, if you have no experience with it yet, I'd recommend a little reading. Professional Penetration Testing (I'm liking it so far, even if the book is falling a part on me), and Hacking for Dummies. Maybe Hacking Exposed.



Logged

OSWP, Sec+
xXxKrisxXx
Hero Member
*****
Offline Offline

Posts: 512



View Profile
« Reply #3 on: July 23, 2010, 09:21:31 PM »

I wouldn't recommend OSCP for a beginner even if it was the first certification I opted for. What made me feel comfortable with taking the course is I've been using BackTrack For 3 years. This may be the first time anyone's seen me suggest this but since the CEH is something you plan on going for, I'd say consider that first. It has more popularity and the negative if any is that it's very tool / theory based. People taking the course can walk out of the class with the certification and not prove that they know how to hack.

If your looking to go a cheaper route and want to get your hands dirty for a cheap price, Learn Security Online has a beginners course called "So You Wanna Be A Pentester". For $300 and access to the LSO lab environment to test your skills, this one's a steal.

Heorot.NET's Shodan Certified Penetration Tester (1DCPT) course is currently discounted (and I think it's only going to be discounted for another 2 or 3 days) could be another option. The course is affordable and comes with the book chrisj recommended, "Professional Penetration Testing".

I'm currently going through eLearnSecurity Online's Training Course thanks to Don and I definitely see it as an option for a beginner too. Jason has reviewed the course here and has coined it, 'The CEH Killer'.

Goodluck and welcome to the forums.

Kris
« Last Edit: July 23, 2010, 09:29:07 PM by xXxKrisxXx » Logged

eCPPT, GCIH, OSCP, OSWP
SephStorm
Hero Member
*****
Offline Offline

Posts: 530


View Profile WWW
« Reply #4 on: July 24, 2010, 02:17:16 AM »

Thank you all for your welcomes, and your input. This is obviously something I am going to think long and hard on.

thank you.
Logged

hayabusa
Hero Member
*****
Offline Offline

Posts: 1633



View Profile
« Reply #5 on: July 24, 2010, 07:34:56 AM »

I'll keep it short and sweet,,,  xxxKrisxxx and Dark_Knight echoed my sentiments, and experiences, almost exactly.  Start with the CEH, or even the Professional Penetration Testing book, by Wilhelm, then see how you're feeling, from there.

Good luck, and keep us informed as you move forward.  We're here to discuss and help!

Logged

~ hayabusa ~ 

"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'


OSCE, OSCP , GPEN, C|EH
SephStorm
Hero Member
*****
Offline Offline

Posts: 530


View Profile WWW
« Reply #6 on: July 25, 2010, 11:53:47 AM »

Thanks, Well, I already have the Pro Pentesting book, and I was working with it, but two things are standing in my way, One, lack of dedicated time. I just finished a six month job training course that had me covering everything from vista, server 08, to UNIX, and security+. Two: too many books! That book is one of about five or six I have been trying to read while studying for other certs. I am hoping that over the next month I can focus on one area at a time. In fact, i'm starting right now!
Logged

impelse
Hero Member
*****
Offline Offline

Posts: 565


View Profile WWW
« Reply #7 on: July 25, 2010, 12:06:58 PM »

Good, just focus in one area.
Logged

CCNA, Security+, 70-290, 70-291
CCNA Security
Taking Hackingdojo training

Website: http://blog.thehost1.com/
hayabusa
Hero Member
*****
Offline Offline

Posts: 1633



View Profile
« Reply #8 on: July 25, 2010, 04:53:51 PM »

Based on that, SephStorm, you definitely wouldn't want to start with OSCP.  You'd quickly run yourself ragged, and I think you'd likely give up way too quickly (it's a LOT of dedicated time, especially if you're new to much of it.

Yeah do the book, and consider CEH, before trying to focus on a challenge like OSCP.

Good luck, and keep us posted on how you're coming along.
Logged

~ hayabusa ~ 

"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'


OSCE, OSCP , GPEN, C|EH
SephStorm
Hero Member
*****
Offline Offline

Posts: 530


View Profile WWW
« Reply #9 on: July 27, 2010, 06:54:13 PM »

I will, thanks.
Logged

Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.059 seconds with 24 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.