Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 37 guests and 2 members online
You are here:
Home
Ethical Hacking Discussions and Related Certifications
Network Pen Testing
OSCP - Offensive Security Certified Professional
OSCP Walkthrough
EH-Net
May 21, 2013, 09:42:43 PM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Ethical Hacking Discussions and Related Certifications
>
Network Pen Testing
>
OSCP - Offensive Security Certified Professional
(Moderator:
don
) >
OSCP Walkthrough
Pages:
1
2
3
[
4
]
5
6
...
10
Go Down
« previous
next »
Print
Author
Topic: OSCP Walkthrough (Read 80105 times)
0 Members and 1 Guest are viewing this topic.
Dutchie
Newbie
Offline
Posts: 33
Re: OSCP Walkthrough
«
Reply #45 on:
August 20, 2010, 12:49:34 PM »
Quote from: hayabusa on August 20, 2010, 12:21:22 PM
I think there'll be a bit more from him... hang tight.
Is the time-slot for the lab exercises that thight that there is no time left for a interim update, as promised!
Logged
RA, CISA, CISSP, C|EH, C|HFI, CWSP, LPIC-1
hayabusa
Hero Member
Offline
Posts: 1632
Re: OSCP Walkthrough
«
Reply #46 on:
August 20, 2010, 02:00:12 PM »
It's a rough class, and does take a lot of your time, especially if you're doing it around a full-time job, etc. So I'd venture he's been plenty busy, and thus, the delay in updating his thread / walkthrough.
It's hard telling where j0rdy's at (I don't know what he does with his non-course time - re: family, work, school, etc - and he could've extended his time, too, depending on what package he signed up for.) But I'm certain he'll be adding more, as he concludes his time and / or takes his exam (with what he can give you, within the course / exam NDA)
Logged
~ hayabusa ~
"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'
OSCE, OSCP , GPEN, C|EH
j0rDy
Hero Member
Offline
Posts: 590
Re: OSCP Walkthrough
«
Reply #47 on:
August 23, 2010, 01:58:16 AM »
Here i am
and hayabusa is right, this course has taken a lot of my spare time which i at the moment rarely have (new job, trying to keep my family/friends happy etc.). but here is a new update!
Quote
Hacking along and preparing for certification
Ok, my labtime is officially over. I managed to get into about 60% of the hosts which leaves me with an unsatisfying feeling. If i knew the lab was going to be this big and hard i would have stared way earlier then i did now. i spend the first half working through the material which i could combine with playing around in the lab, but didnt. i suggest to start immediately if you want to get into the other subnets and make sure you get at least the 60 day course. The skill level of the lab differs from click and hack to complete manual procedures which makes it a pleasant environment to play in for everyone. You are certain to find a challenge regarding of the skill level you have prior to the course.
this brings me to one of the most burning questions at the moment: how hard is OSCP and is it suitable for beginners? i would say NO. If you have no prior knowledge in pentesting/ethical hacking this will knock you down and leave you in the gutter. Unless you have aquired the techniques of hacking and know how to penetrate systems you will have a very difficult time to gain the knowledge required to do well in the labs. I'm not saying its wasted time, because you will learn (a lot!) and you have sufficient time, you probably will have a decent chance to pass. i found it hard to find time because of my new job which kept me pretty busy and i guess you will have occupations too, so keep that in mind. Compared to CEH, wait...what is there to compare? i thought about this a long time but i cant seem to find any similarities between the two courses. the only way to describe it is as followed: CEH: start talking it. OSCP. start doing it!
At this point i am working on my report that you will need to hand in once the exam is finished. I am describing all the hacks i made within the labs and the exercises i made during the course. Remember to make it as complete as possible to make it look just as a real pentest report. I planned my exam somewhere next month, this give me some time to go over the material again and to put in some work on some of the extra mile challenges to make sure i completely understand all the techniques mentioned. i have no idea what to expect, but i am preparing for hell! wish me luck!
Next up: Exam time!
[\quote]
Logged
ISC2 Associate, CEH, ECSA, OSCP, OSWP
earning my stripes appears to be a road i must travel alone...with a little help of EH.net
hayabusa
Hero Member
Offline
Posts: 1632
Re: OSCP Walkthrough
«
Reply #48 on:
August 23, 2010, 09:50:26 AM »
and there he is!
Congrats on getting through your lab time, j0rdy!
My advice to you, now:
Spend the next bit of time, as you said, cleaning up and preparing the final report. What I'd recommend (without giving any specifics) is to template the sections, like you did for each host you did in the labs, into your appendix or section you're going to use fot the exam machines. Then your format for those is already prepared, and you can simply add your notes, screenshots, POC code, etc, to those, one you've gotten done with your 24-hour exam. (Because, you have to remember, after the exam, you only have an additional 24 hours to submit the report.) The more you have prepared in advance, the easier it will be to organize and submit your data, after exam day.
Then, review a little, anything you had any questions on from the labs, and then relax until exam day, focusing your time on those other things that matter (job, family, etc) and let yourself wond down a bit. Then, when test day arrives, you'll be refreshed, and ready to settle in for your exam.
One more thing I can tell you. IF you approach the exam right, you can get your 'passing score' pretty quickly. I passed within about 7 hours. However, I went after the perfect score, since Ryan Lynn set such a high target. I didn't get it, but afterwards, found out I was extremely close to finishing, on the LAST machine in the exam. <sniff> Oh well, considering I was in physical pain throughout, I was pleased with my result!
Good luck, and let us know when you schedule it, etc.
Logged
~ hayabusa ~
"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'
OSCE, OSCP , GPEN, C|EH
Synquell
Full Member
Offline
Posts: 169
Re: OSCP Walkthrough
«
Reply #49 on:
August 23, 2010, 10:00:50 AM »
Thanks for taking the time to update j0rdy!
Great read as ever.
Good luck on the final run, kick some ass!
Logged
Twitter:
https://twitter.com/dietervds
Blog:
https://synquell.wordpress.com
(not much there yet)
The beginning of knowledge is the discovery of something we do not understand.
j0rDy
Hero Member
Offline
Posts: 590
Re: OSCP Walkthrough
«
Reply #50 on:
August 24, 2010, 02:10:11 AM »
thanks guys! i know i am not 100 points material, but i think i can give myself a fair opportunity, even with my (limited) background. i cant wait to start on the exam, but on the other hand i really want to play in the lab a little more because i have learned so much from it and i want to learn even more!
Logged
ISC2 Associate, CEH, ECSA, OSCP, OSWP
earning my stripes appears to be a road i must travel alone...with a little help of EH.net
j0rDy
Hero Member
Offline
Posts: 590
Re: OSCP Walkthrough
«
Reply #51 on:
September 16, 2010, 11:57:14 AM »
Last update before the exam!
Quote
This is my last update before i will take the exam this weekend. It will be less informative then the previous posts i made but i want to give you all a view on how i stand thowards the exam, mental wise. i cant stop thinking about the score hit monkey got on his first try. I believe we are skillwise pretty equal. Giving the fact i am only in security for about 1.5 years now, i almost cant believe how far i already came, but the big question is will it be enough? i really want to pass the exam just to prove i learned all these skills and that i can put them in use.
At this moment i feel pretty confident about the knowledge i have optained. The one thing that worries me most is the time window in which i have to operate. Because i am on almost the other side of the earth, none of the starting times are great. You have the option of choosing several starting times going from 4pm to about 22pm. This means you will have to pull an all-nighter, no matter how good you are. This gives the whole experience a nice ring to it though. Pulling an all nighter just like real hackers do in movies. Can you imagine the dark room, lighted by just a computer screen, and the only sound you hear is the soft thicking of the keyboard and the brain cracking of a hacker that is working his ass off to get that root-shell? just thinking about it makes me all hyped up to get stared! Luckily i took a day off (sort off) so i can prepare myself for this. i'm planning on getting plenty of food and drinks (caffeine is your friend is such situations) so i dont have to waste any time on less important things like if i have enough to fuel my body for this experience.
After practicing in the labs i found out that if i really put myself to it, i can hack most of the hosts without any real problem. The only thing is that when i do, i dont have a time limit in which i have to finish. Some of the hosts took me a really long time because of the extra knowledge required to make the actual hack. Luckily not everything is chewed out so you really have to think on your own to achieve the result wanted. Because of my slim pre-knowledge this takes me longer then with someone who has more experience. the best advice in these situation IS just to try harder. In the end i get there, but with significantly more time and effort. I think time will be my biggest enemy. Wish me luck and i will post my post exam experience when i'm ready to do something else besides sleeping.
Next up:
Logged
ISC2 Associate, CEH, ECSA, OSCP, OSWP
earning my stripes appears to be a road i must travel alone...with a little help of EH.net
ziggy_567
Sr. Member
Online
Posts: 361
Re: OSCP Walkthrough
«
Reply #52 on:
September 16, 2010, 12:03:28 PM »
Good luck! And keep that positive attitude. You've proven you can do it in the labs....
Logged
--
Ziggy
eCPPT - GSEC - GCIH - GCUX - RHCE - SCSecA - Security+ - Network+
H1t M0nk3y
Hero Member
Offline
Posts: 864
Re: OSCP Walkthrough
«
Reply #53 on:
September 17, 2010, 08:09:43 AM »
I wish you all the luck j0rDy!
My background is all about developing web applications. If yours is server administrator, it should help you in the exam.
Remember a few things. Each machine in the lab are worth different points, but for me, the "easiest" machines turn out to be the hardest... This is obviously due to a lack of experience on my part, but just don't be afraid to tackle the "big" ones.
That being said, you may get a totally different exam then mine was, but still...
Also, you will have a little bit less than 5 hours per machine. So take your time (yes, you will be awake all night!) and be careful not to do stupid mistakes toward the end. I mistyped an IP address after 22 hours into the exam and it took me almost 30 minutes figure it out... (yes, I was getting really tired!).
Finally, read your scan results properly. Something I didn't do for 2 machines!!
But hey, this can be done by humans!!!
Good luck, I will be looking at your result.
Logged
OSCP, GPEN, GWAPT, GSEC, CEH, CISSP
Synquell
Full Member
Offline
Posts: 169
Re: OSCP Walkthrough
«
Reply #54 on:
September 17, 2010, 08:19:54 AM »
You sound as prepared as you can be J0rdy, so just go for it
We'll be here cheering you on, let us know how it went afterwards!
Logged
Twitter:
https://twitter.com/dietervds
Blog:
https://synquell.wordpress.com
(not much there yet)
The beginning of knowledge is the discovery of something we do not understand.
impelse
Hero Member
Offline
Posts: 565
Re: OSCP Walkthrough
«
Reply #55 on:
September 17, 2010, 08:26:59 AM »
I like these tips. I am still studying for eLearnsecurity and sometimes I study the metasploit-unleashed from Offensiv-security to sharp my skill and when I pass those exams (yes CEH too) I will shoot OSCP
Logged
CCNA, Security+, 70-290, 70-291
CCNA Security
Taking Hackingdojo training
Website:
http://blog.thehost1.com/
MaXe
Hero Member
Offline
Posts: 669
I've just upgraded myself to a cyborg muahahaa!!1
Re: OSCP Walkthrough
«
Reply #56 on:
September 17, 2010, 08:57:23 AM »
Don't forget to take (short) breaks too
If you don't take a small break occasionally you will probably overheat your brain and you may end up in a deadlock. I know there is a big stress factor that you shouldn't eat, relax, or take long breaks while you're doing the exam because it's running and you need to get the right amount of points.
But if you're going in circles and you need fresh ideas, take a short break (perhaps a walk outside to the nearest store for refreshments you want and need) and think creatively about how you can solve the problem even though it may seem impossible it is not.
Logged
I'm an InterN0T'er
zeroflaw
Full Member
Offline
Posts: 208
Re: OSCP Walkthrough
«
Reply #57 on:
September 17, 2010, 10:29:03 AM »
Good luck j0rDy! r00t those boxes!
Logged
ZF
j0rDy
Hero Member
Offline
Posts: 590
Re: OSCP Walkthrough
«
Reply #58 on:
September 19, 2010, 09:20:46 AM »
I got Pwnd...
Quote
No seriously...like a script kiddie. I cant really figure out what happened. Maybe it was the long night, the fact i was more nervous then a bouncing toothpick, or perhaps just lack of skill? Anyway the mail was right on time, i logged in, started on the first host and bam! 5 hours gone. I was almost there but decided to let it go cause time was ticking. i went for the other hosts where i pretty quickly got a shell on one of them, but spend hours to make it a root one. No luck. The other hosts were just playing with me. I found several vulnerable services, but somehow i couldnt get that shell. And then, time's up. I got nothing! No shell, No exploit that worked for me. Perhaps this was where my lack of programming skills came in. I spend too much time figuring out how to make the exploits run, let alone if they worked. I feel defeated, almost humiliated. Even though somewhere i keep thinking wow, i cant believe how much i have learned in the past couple of months. At this point im having trouble to be entheusiastic about it, but thats just to blame on the exam results, and the 3h sleep i got.
I expected it to be hard. Heck, i was even sure i would need all the luck in the world to pass, but this result left me bedazzled. I guess this closes the ever ongoing CEH vs OSCP debate. Even if you can pass the CEH exam with two fingers up your nose, OSCP is a whole different ballgame. this certification truely separates the men from the boys.
the positive thing about this is that now i know where my weak points are. i will work on them first, expand my skills further, become more knowledgable and eventually i will succeed. i have never given up on anything in my life, and this will not become my first. I feel there is no point in taking the exam again any time soon, but when i feel i have progressed both skill and time wise, i will be ready for the biggest challenge of my life once more...I wish we could end this walkthrough with better news, but hey, guess i just have to: try harder...
Logged
ISC2 Associate, CEH, ECSA, OSCP, OSWP
earning my stripes appears to be a road i must travel alone...with a little help of EH.net
hayabusa
Hero Member
Offline
Posts: 1632
Re: OSCP Walkthrough
«
Reply #59 on:
September 19, 2010, 10:34:39 AM »
Here's a tip for you, j0rDy...
If you got even semi-detailed scan results from the exam, or have versions of specific software you came across on the targets, see if you can't setup some of those in a lab, on your own, and spend some time on them. While you may not have found many / all, you can grow, simply by setting up what you DID see, and working to figure out how to nail those programs / services.
I'm sorry to hear you had a rough go of it. I've been talking to several folks who didn't pass on first attempt, and it seems this latest version of OSCP is challenging for 'almost' everyone I've chatted with. I'm glad, though, that you're looking at the bright side, and realizing what you HAVE learned and taken away from it, so far.
Remember, too, that IT security / pentesting is a never-ending learning experience. You'll see folks like me, sil, Ketchup, former33t, don and others regularly posting about what we're working on or learning, currently. It never ceases to amaze me, how much new and fun stuff there is to achieve in IT. That's what drew me to the field, to begin with. And the security aspects are literally the 'icing on the cake,' for geeks like me.
Just keep studying, attempt some things on your own, similar to what you saw in the labs, and grow. Either way, you take a lot from the experience. (Although, I'm sure you'll keep with it until you pass, and I commend you for your hard work and dedication to it, moving forward.)
Take care, and keep us posted, as to how you proceed, and feel free to ask questions. That's what we're all here for!
Logged
~ hayabusa ~
"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'
OSCE, OSCP , GPEN, C|EH
Pages:
1
2
3
[
4
]
5
6
...
10
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
Programming
: Finished Python Course in Codecademy now what?
(14) by
3xban
Network Pen Testing
: Ruby on Rails Vulnerabilities/Attacks in BackTrack 5 r3
(0) by
SUdoctstudent
Network Pen Testing
: De-ICE 1.140 released!
(2) by
superkojiman
Network Pen Testing
: AIX Vulnerability Assessments
(1) by
3xban
General Certification
: CPT Practical Submission
(1) by
UNIX
OSCP - Offensive Security Certified Professional
: Failed my first attempt at the OSCP exam
(94) by
azmatt
Tools
: Social-Engineer Toolkit (SET) Version 5.0 “The Wild West” Released
(2) by
m0wgli
Malware
: EICAR?
(3) by
UKSecurityGuy
Advisories
: HTB23154: Multiple Vulnerabilities in Exponent CMS
(0) by
AndyP
Advisories
: HTB23153: Multiple Vulnerabilities in Jojo CMS
(0) by
AndyP
Advisories
: HTB23151: Cross-Site Request Forgery (CSRF) in UMI.CMS
(0) by
AndyP
Tutorials
: Need guidance
(8) by
r0ckm4n
OSCP - Offensive Security Certified Professional
: Class Scheduled 6/8 - Linux n00b
(7) by
Taemyks
OSCP - Offensive Security Certified Professional
: OSCP exam scheduled
(6) by
gbhat
Incident Response
: LinkedIn Forensics
(0) by
AFENTIS_Forensics
General Certification
: Red Team/Blue Team
(1) by
ajohnson
Career Central
: Starter cert?
(3) by
Grendel
Network Pen Testing
: Beginner Ethical Hacker
(1) by
m0wgli
Web Applications
: Nessus and Nikto
(4) by
Seen
Network Pen Testing
: Cracking salted MD5 hash
(4) by
n37sh@rk
CEH - Certified Ethical Hacker
: Passed my C|EH
(3) by
n37sh@rk
Mass Media
: EC-council hacked, irony at his best?
(0) by
j0rDy
Web Applications
: SQL Injection into an INSERT statement.
(6) by
eyenit0
Network Pen Testing
: Solution for sipXtapi INVITE Message CSeq Field Header Remote Overflow
(1) by
m0wgli
Web Applications
: dns
(2) by
H1t M0nk3y
Other
: BSides Boston
(0) by
3xban
Career Central
: InfoSec in Central, FL
(2) by
tturner
Web Applications
: Web vulnerability scanner
(4) by
H1t M0nk3y
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
Free Business and Tech Magazines and eBooks
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.