Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 35 guests online
You are here:
Home
Ethical Hacking Discussions and Related Certifications
Network Pen Testing
OSCP - Offensive Security Certified Professional
OSCP, Beginner?
EH-Net
May 24, 2013, 08:09:50 AM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Ethical Hacking Discussions and Related Certifications
>
Network Pen Testing
>
OSCP - Offensive Security Certified Professional
(Moderator:
don
) >
OSCP, Beginner?
Pages: [
1
]
Go Down
« previous
next »
Print
Author
Topic: OSCP, Beginner? (Read 7702 times)
0 Members and 1 Guest are viewing this topic.
SephStorm
Hero Member
Offline
Posts: 530
OSCP, Beginner?
«
on:
July 23, 2010, 07:07:31 PM »
Hi all,
I am looking at getting into pentesting, and I have been throwing the choices around in my head for some time. As someone with no real pentesting experience, is OSCP recommended?
i am also considering CEH,CPT,CPTE,and any other T1 pentesting certs, if anyone thinks one of these would be more appropriate.
I want to mention my experience: A+N+/S+, Security5, CIW Associate
Thanks in advance.
Logged
Support my hactivities.
http://www.cafepress.com/TRUEHacker
Dark_Knight
Sr. Member
Offline
Posts: 292
Re: OSCP, Beginner?
«
Reply #1 on:
July 23, 2010, 08:36:00 PM »
Hi SS,
My first certification was the CEH and it served as a great introduction to the field of penetration testing. The material was just enough to get me started. The exercises/labs looking back at them now were pretty basic
So the 'exploits' were against a windows 2000 box and if I remember correctly the exploit was the good old rpc_dcom. Point is it was nothing fancy, but at the end of the course it got me thinking about security. So everything I did from that point on was done with security in mind.
The OSCP on the other hand was a different beast. This course took it to an entire new level. So, I remember 'reading' about buffer overflows in the CEH. Well I actually did it in the OSCP. A lot of the topics covered in the CEH came to life in the OSCP. Sql injection that I had read about in the CEH, I actually got the chance to do it on several occasions. Another is example is metasploit. During the CEH, someone in the class used msf to pwn the windows 2000 server. And let me tell you I was blown away by it. Fast forward to the OSCP and I was not only using the msf but I was actually editing some of the exploits. Really getting into the guts. And where as in the CEH I could identify exploits that were say in the C programming language, in the OSCP I was editing the code.
The OSCP is also ALL YOU. No lecturers to run to. Nobody to hold your hand and spoon feed you. It can be REALLY frustrating at times. Google and the oscp irc channel become your best friend. The exam is also another thing. You have 24hrs to pwn a set of boxes that you are seeing for the first time. No multiple choice exam. So the OSCP will take your skills to the next level.
So now that you have all this 'raw' skill it now needs to be refined. Enter the Sans GPEN. This course covers the business side of things. So it takes you through setting everything up on the business side. Things like rules of engagement, various laws, establishing scope etc are covered. Really important stuff. And it also further explains some of the concepts learned in the OSCP. Rainbow tables comes to mind.
So having said ALL that you could run with the CEH and then make your way up to the OSCP.
My .02
«
Last Edit: July 23, 2010, 08:43:18 PM by Dark_Knight
»
Logged
CEH, OSCP, GPEN, GWAPT, GCIA
http://sector876.blogspot.com
chrisj
Hero Member
Offline
Posts: 1163
Re: OSCP, Beginner?
«
Reply #2 on:
July 23, 2010, 08:37:31 PM »
I can't really answer if OSCP is a beginner course or not. There are a couple of reviews on the site to look at. Ryan Lynn (apollo I think) and J0rDy.
However, if you have no experience with it yet, I'd recommend a little reading. Professional Penetration Testing (I'm liking it so far, even if the book is falling a part on me), and Hacking for Dummies. Maybe Hacking Exposed.
Logged
OSWP, Sec+
xXxKrisxXx
Hero Member
Offline
Posts: 512
Re: OSCP, Beginner?
«
Reply #3 on:
July 23, 2010, 09:21:31 PM »
I wouldn't recommend OSCP for a beginner even if it was the first certification I opted for. What made me feel comfortable with taking the course is I've been using BackTrack For 3 years. This may be the first time anyone's seen me suggest this but since the CEH is something you plan on going for, I'd say consider that first. It has more popularity and the negative if any is that it's very tool / theory based. People taking the course can walk out of the class with the certification and not prove that they know how to hack.
If your looking to go a cheaper route and want to get your hands dirty for a cheap price, Learn Security Online has a beginners course called
"So You Wanna Be A Pentester"
. For $300 and access to the LSO lab environment to test your skills, this one's a steal.
Heorot.NET's Shodan Certified Penetration Tester (
1DCPT
) course is currently discounted (and I think it's only going to be discounted for another 2 or 3 days) could be another option. The course is affordable and comes with the book chrisj recommended, "
Professional Penetration Testing
".
I'm currently going through
eLearnSecurity Online's Training Course
thanks to Don and I definitely see it as an option for a beginner too. Jason has reviewed the course
here
and has coined it, 'The CEH Killer'.
Goodluck and welcome to the forums.
Kris
«
Last Edit: July 23, 2010, 09:29:07 PM by xXxKrisxXx
»
Logged
eCPPT, GCIH, OSCP, OSWP
SephStorm
Hero Member
Offline
Posts: 530
Re: OSCP, Beginner?
«
Reply #4 on:
July 24, 2010, 02:17:16 AM »
Thank you all for your welcomes, and your input. This is obviously something I am going to think long and hard on.
thank you.
Logged
Support my hactivities.
http://www.cafepress.com/TRUEHacker
hayabusa
Hero Member
Offline
Posts: 1633
Re: OSCP, Beginner?
«
Reply #5 on:
July 24, 2010, 07:34:56 AM »
I'll keep it short and sweet,,, xxxKrisxxx and Dark_Knight echoed my sentiments, and experiences, almost exactly. Start with the CEH, or even the Professional Penetration Testing book, by Wilhelm, then see how you're feeling, from there.
Good luck, and keep us informed as you move forward. We're here to discuss and help!
Logged
~ hayabusa ~
"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'
OSCE, OSCP , GPEN, C|EH
SephStorm
Hero Member
Offline
Posts: 530
Re: OSCP, Beginner?
«
Reply #6 on:
July 25, 2010, 11:53:47 AM »
Thanks, Well, I already have the Pro Pentesting book, and I was working with it, but two things are standing in my way, One, lack of dedicated time. I just finished a six month job training course that had me covering everything from vista, server 08, to UNIX, and security+. Two: too many books! That book is one of about five or six I have been trying to read while studying for other certs. I am hoping that over the next month I can focus on one area at a time. In fact, i'm starting right now!
Logged
Support my hactivities.
http://www.cafepress.com/TRUEHacker
impelse
Hero Member
Offline
Posts: 565
Re: OSCP, Beginner?
«
Reply #7 on:
July 25, 2010, 12:06:58 PM »
Good, just focus in one area.
Logged
CCNA, Security+, 70-290, 70-291
CCNA Security
Taking Hackingdojo training
Website:
http://blog.thehost1.com/
hayabusa
Hero Member
Offline
Posts: 1633
Re: OSCP, Beginner?
«
Reply #8 on:
July 25, 2010, 04:53:51 PM »
Based on that, SephStorm, you definitely wouldn't want to start with OSCP. You'd quickly run yourself ragged, and I think you'd likely give up way too quickly (it's a LOT of dedicated time, especially if you're new to much of it.
Yeah do the book, and consider CEH, before trying to focus on a challenge like OSCP.
Good luck, and keep us posted on how you're coming along.
Logged
~ hayabusa ~
"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'
OSCE, OSCP , GPEN, C|EH
SephStorm
Hero Member
Offline
Posts: 530
Re: OSCP, Beginner?
«
Reply #9 on:
July 27, 2010, 06:54:13 PM »
I will, thanks.
Logged
Support my hactivities.
http://www.cafepress.com/TRUEHacker
Pages: [
1
]
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
Network Pen Testing
: Want a challenge? Want a GXPN practice exam?
(0) by
ajohnson
GCIH - GIAC Certified Incident Handler
: Passed my GCIH
(8) by
ajohnson
News Items and General Discussion About EH-Net
: Change is Coming to EH-Net!!
(29) by
ajohnson
GCIH - GIAC Certified Incident Handler
: GCIH Free Practice test attempt
(1) by
prats84
Greetings
: Hi from the UK
(4) by
MrTuxracer
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.