Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 37 guests online
Free Business and Tech Magazines and eBooks
You are here:
Home
Ethical Hacking Discussions and Related Certifications
Network Pen Testing
OSCP - Offensive Security Certified Professional
OSCP Walkthrough
EH-Net
May 25, 2013, 10:32:47 PM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Ethical Hacking Discussions and Related Certifications
>
Network Pen Testing
>
OSCP - Offensive Security Certified Professional
(Moderator:
don
) >
OSCP Walkthrough
Pages:
1
[
2
]
3
4
...
10
Go Down
« previous
next »
Print
Author
Topic: OSCP Walkthrough (Read 80273 times)
0 Members and 1 Guest are viewing this topic.
xXxKrisxXx
Hero Member
Offline
Posts: 512
Re: OSCP Walkthrough
«
Reply #15 on:
July 07, 2010, 11:15:04 AM »
I"m backing BillV on this one. When I was in the course, I scheduled my exam about a week after my lab time expired. This gave me time to go back and finish the report, take the exam then add my exam findings into the report (which is very do-able in 24 hours).
Logged
eCPPT, GCIH, OSCP, OSWP
zeroflaw
Full Member
Offline
Posts: 208
Re: OSCP Walkthrough
«
Reply #16 on:
July 07, 2010, 12:25:17 PM »
At first I was kind of confused about the documentation and reporting. Seems like we have to document everything. And put all the results relating to the network itself in our pentest report.
Did you guys use leo or basket? I personally find basket easier. Also I'm planning to do all the extra mile exercises.
Logged
ZF
H1t M0nk3y
Hero Member
Offline
Posts: 865
Re: OSCP Walkthrough
«
Reply #17 on:
July 07, 2010, 02:19:47 PM »
Speaking of scheduling the exam, I was going to register for Saturday, July 24th but all sits were taken. Having my daughters every second weekend, I tried August 7 or 8 with no chance. I finally got a slot on August 21st!
I have to wait almost 2 months!
So zeroflaw, book your exam way in advance, especially if you are planning on doing it on a weekend...
Logged
OSCP, GPEN, GWAPT, GSEC, CEH, CISSP
BillV
Hero Member
Offline
Posts: 1892
Re: OSCP Walkthrough
«
Reply #18 on:
July 07, 2010, 09:56:17 PM »
Yeah, the better your documentation is during the lab, the easier it will be to put it into a report. Personally, I didn't spend much time in the lab and only compromised about 6 or 7 systems. I just didn't have the time to spend playing around. I didn't use leo or basket. I used an Excel spreadsheet to keep track of what I was doing, with one sheet giving me an overview and each system having its own sheet. Just my preference of doing things I guess.
And I agree on scheduling the exam. It's a pretty bad interface imho. I ended up sending an email out to those guys to ask them what times were available for the next couple Fridays/Saturdays, then from there I went back and selected one of those times. Each one I had tried before that I just got the message saying it was unavailable. I think I suggested they should do something similar to Prometric, with a calendar that shows available dates/times rather than playing a guessing game with the system.
Logged
j0rDy
Hero Member
Offline
Posts: 590
Re: OSCP Walkthrough
«
Reply #19 on:
July 09, 2010, 04:56:16 AM »
thanks for the replies and i will get to the 2x24h part as soon as i get my next chapter finished! also great advice on the exam planning, i will keep it in mind when i am getting close to my last lab days.
Logged
ISC2 Associate, CEH, ECSA, OSCP, OSWP
earning my stripes appears to be a road i must travel alone...with a little help of EH.net
BillV
Hero Member
Offline
Posts: 1892
Re: OSCP Walkthrough
«
Reply #20 on:
July 19, 2010, 10:33:05 AM »
How's your course going? Any updates?
Logged
j0rDy
Hero Member
Offline
Posts: 590
Re: OSCP Walkthrough
«
Reply #21 on:
July 19, 2010, 11:59:12 AM »
just hit rock bottom working on the lab machines
, more on this next friday!
Logged
ISC2 Associate, CEH, ECSA, OSCP, OSWP
earning my stripes appears to be a road i must travel alone...with a little help of EH.net
partek
Newbie
Offline
Posts: 27
Re: OSCP Walkthrough
«
Reply #22 on:
July 19, 2010, 01:05:55 PM »
OSCP is a tough course and really forces you to come up with some interesting and unorthodox solutions. I remember spending many a late night trying to break into the lab boxes. It's very frustrating, but is definitely the most rewarding course I've ever taken.
Logged
CISSP, CISM, CISA, CCNA Security, OSCP, CEH
hayabusa
Hero Member
Offline
Posts: 1633
Re: OSCP Walkthrough
«
Reply #23 on:
July 19, 2010, 03:46:50 PM »
I fully agree with partek. Just take your time, j0rdy, and take breaks and rest, if you feel like you're hitting a wall. (muts and company would agree, especially when you're taking the exam.) Always remember, on the boxes, to look for the: who, what, where, when, why and how - as a moderator on the IRC chat reminded me during my lab time, as I hit a wall at one point on one box in particular. I asked, not for an answer, but for some sense that I wasn't WAY off on the machine, and he gave me that advice (and I wasn't far off, after all, once I stepped back and rested, then reconsidered some things.)
Keep it up. It's worth it !
Logged
~ hayabusa ~
"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'
OSCE, OSCP , GPEN, C|EH
Synquell
Full Member
Offline
Posts: 169
Re: OSCP Walkthrough
«
Reply #24 on:
July 20, 2010, 03:10:32 AM »
This makes for a great read Jordy, and will be most useful for other people trying their hands at the course (hopefully including me).
As a possible suggestion: maybe you can add the newly written parts in the first post? It's easier to then read the whole thing in one post, instead of having to scroll through, what I imagine, will become a very long thread
Thanks a bunch for taking the effort to write it all down m8, looking forward to more of your experiences with PWB!
Logged
Twitter:
https://twitter.com/dietervds
Blog:
https://synquell.wordpress.com
(not much there yet)
The beginning of knowledge is the discovery of something we do not understand.
j0rDy
Hero Member
Offline
Posts: 590
Re: OSCP Walkthrough
«
Reply #25 on:
July 22, 2010, 03:52:39 AM »
Great idea Anquilas! let me get on it straight away! remember to stay tuned for the next update coming this Friday!
Logged
ISC2 Associate, CEH, ECSA, OSCP, OSWP
earning my stripes appears to be a road i must travel alone...with a little help of EH.net
j0rDy
Hero Member
Offline
Posts: 590
Re: OSCP Walkthrough
«
Reply #26 on:
July 24, 2010, 06:46:16 AM »
as promised:
Quote
I finished all the modules that are covered in the videos and skipped in a fast pace through the last ones in the lab guide. Some topics were complete new for me like ARP spoofing, buffer overflows and client side attacks. Thanks to the good and simple explanation that takes you step by step through the process i managed to get through them with succes. The further i got in the course, the more i was amazed of the knowledge that the course comprehends (and i lack).ou I want to give massive kudo's to the Offensive Security team for this course. You know you are watching/learning from true professionals when they master the difficulty of the art, but make it look easy. This is exactly what they do.
After finishing the modules i started to review the information gathered about the labs you collect through the exercises. The reconnaissance part gives you heaps of info about the targets in the labs, but found out quick enough that i had to start documenting properly. I started with putting all the important information i gathered in the sample test report you receive at the start of the course. This helps in getting that overview of the target and lets you set that aim for your first targets. I tried to spend a full day in the week on this course doing exercises and practicing, and an hour a day to read/watch the material. At this point i am halfway through the 60 days i have, so i recommend everybody to take the 60 day course.
Now we got that out of the way it is time for the interesting part: The lab machines! At this point i only spend a few hours in the lab, which comes to about the 24h you need for the exam. At this point i targeted about three machines. results? Nothing! Remember that feeling i talked about earlier that you can hack the planet? This gets shot into a thousand pieces when you actually start on the lab. At first this got (and still does a little) me really frustrated and insecure about my freshly aquired knowledge, but then again, if it would be a walk in the park everybody would be OSCP certified.
At this point i can identify most of the vulnerabilities that the machines have, and theoretically explain how to exploit them, but when i try the exploits that are discussed in the material in practice i always seem to find a little twist that makes it not work the way it supposed to. The frustration feeling i got with this experience quickly turned into motivation to try harder and get as far as possible in the labs. I got this feeling that once you have hacked your first one, the next few will come within no time, and guess what: i was right! After spending another few hours in the lab i managed to get into a few machines! I see that the difficulty of the machines varies from 1 click hacks to almost impossible. All i can think of now is that this is more challenging and most important, more fun then i could imagine! This is like playing around in the biggest playground there is, and get certified at the same time. Once you have experienced this you will never want to take a normal certification course again!
Logged
ISC2 Associate, CEH, ECSA, OSCP, OSWP
earning my stripes appears to be a road i must travel alone...with a little help of EH.net
hayabusa
Hero Member
Offline
Posts: 1633
Re: OSCP Walkthrough
«
Reply #27 on:
July 24, 2010, 07:42:28 AM »
Great job, j0rdy, and glad you're progressing. You'll continue to have even more fun in the labs. Something to be aware of, as you progress... There are a few, whose IP's and names I won't disclose (both because 'we can't' and because that would take the fun and learning out of it for you,) that you'll need multiple steps / exploits to truly beat. Your challenge will be thinking of not only how to get that first access into the box, but how to move deeper on it, and root it / get SYSTEM.
Be patient, think things through, and when in doubt, 'talk it out.' Sometimes that inner monologue, in your head, if you walk away from it for a bit, is the best thing for the situation.
What I can say it this, having already passed the course and exam, I'm enjoying reading your take on it, and your descriptions of it all make this an interesting read. Keep it up!
Logged
~ hayabusa ~
"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'
OSCE, OSCP , GPEN, C|EH
Equix3n-
Sr. Member
Offline
Posts: 386
Re: OSCP Walkthrough
«
Reply #28 on:
July 24, 2010, 08:52:38 AM »
Nice post, j0rdy. Looks like you're finally getting your rhythm.
Logged
Synquell
Full Member
Offline
Posts: 169
Re: OSCP Walkthrough
«
Reply #29 on:
July 26, 2010, 04:00:02 AM »
I'm following your adventures in OSCP with great interest m8, keep it up and kick ass in the next 30 days!
Logged
Twitter:
https://twitter.com/dietervds
Blog:
https://synquell.wordpress.com
(not much there yet)
The beginning of knowledge is the discovery of something we do not understand.
Pages:
1
[
2
]
3
4
...
10
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
News Items and General Discussion About EH-Net
: Change is Coming to EH-Net!!
(30) by
don
Tools
: Symbolic Exploit Assistant project is looking for collaborators
(0) by
galapag0
Greetings
: Hi from the UK
(5) by
prats84
GCIH - GIAC Certified Incident Handler
: Passed my GCIH
(9) by
prats84
Network Pen Testing
: Want a challenge? Want a GXPN practice exam?
(0) by
ajohnson
GCIH - GIAC Certified Incident Handler
: GCIH Free Practice test attempt
(1) by
prats84
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.