Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 38 guests online
 
Advertisement

You are here: Home arrow Ethical Hacking Discussions and Related Certificationsarrow Network Pen Testingarrow OSCP - Offensive Security Certified Professionalarrow OSCP Strategy
EH-Net
May 19, 2013, 12:14:25 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: OSCP Strategy  (Read 8582 times)
0 Members and 1 Guest are viewing this topic.
cd1zz
Hero Member
*****
Offline Offline

Posts: 561


View Profile WWW
« on: October 04, 2010, 07:09:37 PM »

I'm currently 2 weeks into the OSCP. I heard that for the final exam you are only able to use Metasploit one time. Armed with that new information, I'm trying to ween myself off my favorite tool and go back to a manual process.

My question for the OSCP cert folks is about a strategy. If for example, you find a box that is vulnerable to ms08-067, instead of using metasploit, you'd have to search for the exploit and find a POC. Then, you'd have to understand the code to enough to be able to fix it for your own environment. Would you say this is correct?

If this is so, I'd say you've got to master fingerprinting and have ninja skills in finding exploit POCs.

Your thoughts?
Logged

xXxKrisxXx
Hero Member
*****
Offline Offline

Posts: 512



View Profile
« Reply #1 on: October 05, 2010, 12:10:16 AM »

Proof-of-Concepts, modifying existing exploits, etc - all of these concepts are covered in later on modules. Understanding the code enough to be able to fix it for the appropriate situation is what will play a huge part in any pen-test you do.

Quote
I'd say you've got to master fingerprinting and have ninja skills in finding exploit POCs.

This is a definite. No one taking the course is suppose to reveal any specific details about the exam itself, but whenever you do plan on taking the exam be prepared for anything. The OffSec guys have put together a great course and you truly have a lot in store for you. Be sure you grasp each attack vector and take advantage of the lab time you paid for.

-Kris
Logged

eCPPT, GCIH, OSCP, OSWP
H1t M0nk3y
Hero Member
*****
Offline Offline

Posts: 864



View Profile
« Reply #2 on: October 05, 2010, 06:48:16 AM »

@cd1zz: My best advice would be:

1) Go through the videos
2) Do all exercises, including the "Extra Mile" ones
3) Hack your way into many, many, many, many lab machines and find your way into the other networks (dev, IT and admin)
4) Then worry about what you are missing for the exam

The exam is very tough and it is too big to discuss learning strategies here. But if you follow these 4 steps, you should be fine!

Logged

OSCP, GPEN, GWAPT, GSEC, CEH, CISSP
mambru
Jr. Member
**
Offline Offline

Posts: 98


View Profile
« Reply #3 on: October 05, 2010, 09:56:35 AM »

I don't know what to say about the challenge without giving away important details about the contents and working, but xXxKrisxXx and H1t M0nk3y have made very important points. Remember, fingerprinting is crucial for a successful pen test.
Logged
linares189
Newbie
*
Offline Offline

Posts: 2


View Profile
« Reply #4 on: October 10, 2010, 07:47:43 PM »

Hey all. I'm also going through the course and spending a lot of hours in the lab banging away at things. I've had some problems getting nmap scans to work, which might hurt for time in the challenge maybe. (Nmap reports host is down though I can reach it through other means like netcat, etc. not sure if this is how it's "supposed" to work in the lab or not.) Doing things more manually sounds better but may push a 24 hour window, wouldn't it?

linares
Logged
COm_BOY
Full Member
***
Offline Offline

Posts: 129


LivinG DeaD


View Profile
« Reply #5 on: October 10, 2010, 07:52:17 PM »

Hey all. I'm also going through the course and spending a lot of hours in the lab banging away at things. I've had some problems getting nmap scans to work, which might hurt for time in the challenge maybe. (Nmap reports host is down though I can reach it through other means like netcat, etc. not sure if this is how it's "supposed" to work in the lab or not.) Doing things more manually sounds better but may push a 24 hour window, wouldn't it?

linares


Try -T2 or similar for nmap scans and it should be fine . I think its a problem with they VPN they used .
Logged

It has become appallingly obvious that our technology has exceeded our humanity.
linares189
Newbie
*
Offline Offline

Posts: 2


View Profile
« Reply #6 on: October 10, 2010, 07:58:32 PM »

Try -T2 or similar for nmap scans and it should be fine . I think its a problem with they VPN they used .

Will do thanks. I was trying -PN and no game. As long as I know it's a bug and not a feature I'll just try em all.

linares
Logged
COm_BOY
Full Member
***
Offline Offline

Posts: 129


LivinG DeaD


View Profile
« Reply #7 on: October 10, 2010, 08:27:48 PM »

Try -T2 or similar for nmap scans and it should be fine . I think its a problem with they VPN they used .

Will do thanks. I was trying -PN and no game. As long as I know it's a bug and not a feature I'll just try em all.

linares

-PN or -P0 means to avoid ping request since there are lot of host computers out there ( web )  which will block icmp and I would recommend to use this option normally , other then that -Tx ( where x is 0-5 ) means timings templates , remember 0-1 is for IDS Smiley . Other then that if they are still using OpenVPN I think its a problem what that , other wise it should run fine on other VPNs in real world .


Best of Luck
Logged

It has become appallingly obvious that our technology has exceeded our humanity.
Saif
Newbie
*
Offline Offline

Posts: 16


View Profile
« Reply #8 on: October 19, 2010, 02:31:40 PM »

well since your taking OSCP then the answer for you question will be withing the course modules trust me Cheesy i know
Logged

OSCE, OSCP
cd1zz
Hero Member
*****
Offline Offline

Posts: 561


View Profile WWW
« Reply #9 on: December 16, 2010, 04:28:16 PM »

Here we are - 2 months later and I passed the exam. Now I see the light Smiley

I've documented the experience on my blog:
http://networkadminsecrets.blogspot.com/

Thanks for everyone's input.
Logged

Pookie
Newbie
*
Offline Offline

Posts: 47


View Profile
« Reply #10 on: December 16, 2010, 04:37:36 PM »

Congrats on passing!
Logged

Certifications: A+, Network+, Security+
impelse
Hero Member
*****
Offline Offline

Posts: 563


View Profile WWW
« Reply #11 on: December 16, 2010, 09:43:09 PM »

Congrats
Logged

CCNA, Security+, 70-290, 70-291
CCNA Security
Taking Hackingdojo training

Website: http://blog.thehost1.com/
Synquell
Full Member
***
Offline Offline

Posts: 169



View Profile
« Reply #12 on: December 17, 2010, 02:50:12 AM »

Nice review, congrats on passing!
Logged

Twitter: https://twitter.com/dietervds
Blog: https://synquell.wordpress.com (not much there yet)

The beginning of knowledge is the discovery of something we do not understand.
alucian
Full Member
***
Offline Offline

Posts: 225



View Profile
« Reply #13 on: December 17, 2010, 03:14:12 PM »

Congrats!
Nice review, it made me think again about doing the course.

I would like to go in the architecture / risk mgmt on the long run, but I still strongly believe that if don't know how the attacks are done you are not a good security specialist.
Doing a course like OSCP will help you more than enough understand how the things are working. Also, being a guy that works best under pressure I will full enjoy the rithm of the course. Being in Canada and having winter untill April, it will be a good way to enjoy.
The biggest problem will be my wife (and the kids) ...  Roll Eyes
Hmmmm
Logged

CISSP ISSAP, CISM/A, GWAPT, GCIH, eCPPT, OSWP
hayabusa
Hero Member
*****
Offline Offline

Posts: 1630



View Profile
« Reply #14 on: December 17, 2010, 03:48:45 PM »

As another who fully understands, I'd say you've got the right mindset (with the wife and kids,) but I'll tell you, you'll find a way to make it work, and it's worth it when you've done it.
Logged

~ hayabusa ~ 

"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'


OSCE, OSCP , GPEN, C|EH
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.072 seconds with 24 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.