Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 38 guests and 2 members online
Free Business and Tech Magazines and eBooks
You are here:
Home
Ethical Hacking Discussions and Related Certifications
Network Pen Testing
CEH - Certified Ethical Hacker
Exam version 4 help
EH-Net
May 24, 2013, 09:12:14 AM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Ethical Hacking Discussions and Related Certifications
>
Network Pen Testing
>
CEH - Certified Ethical Hacker
(Moderator:
don
) >
Exam version 4 help
Pages: [
1
]
Go Down
« previous
next »
Print
Author
Topic: Exam version 4 help (Read 9645 times)
0 Members and 1 Guest are viewing this topic.
skel
Jr. Member
Offline
Posts: 60
"Beam me up Scotty - Only hackers here"
Exam version 4 help
«
on:
August 30, 2006, 12:07:27 PM »
Hi
I came across this site when searching for hping info. This site is great. This is the only discussion site I found relating to CEH. So thanks for the owner
I am thinking of sitting for the CEH next week (if my office time permits). I have a genereic question from guys who have done the exam 4.
I have a general idea of what the ver 3 of exams looks like. But how about the version 4.? Is is similar to ver 3?
What are the most common tools the exam focussed in relation to parameters etc.
thanks
Logged
Skel
don
Editor-In-Chief
Administrator
Hero Member
Online
Posts: 4168
Editor-In-Chief
Re: Exam version 4 help
«
Reply #1 on:
August 30, 2006, 02:00:59 PM »
First of all, thanks for the compliment and welcome to EH-Net from the 'owner.' As always we look forward to your continued participation.
In your post you say that you're thinking of sitting for the exam next week. Have you put in the time to study and do you have experience in the field? Although not a hard exam, it is easy for those who are prepared.
I can't give away too much, as I have already taken the exam and don't want to be unethical. But be sure to know switches for Nmap and Netcat. Most of the other tools, you just need to know what it does, but not the switches.
There are also questions with Snort log dumps. You don't need to know Snort in depth, but it would help to know what the attack looks like.
Hope this helps,
Don
Logged
CISSP, MCSE, CSTA, Security+ SME
Oyle
Sr. Member
Offline
Posts: 264
"Man. Nature. Technology".
Re: Exam version 4 help
«
Reply #2 on:
August 30, 2006, 07:13:49 PM »
Welcome. I did the exam ver. 2.3, and there were questions on buffer overflows, DDoS, and many other goodies. I had a question on URL De-obfuscation that was not covered in my class. Make sure you know how to de-obfuscate.
Some programming knowledge would be nice, as well.
Hope you understand that once we pass an exam we could not take it again, even if we WANTED to throw the money away. Same as with Microsoft exams, once you PASS an exam, you are NOT ALLOWED to take it again.
Then again, why would you want to?
Like Don asked, Are you SURE you're ready for it?
Logged
MCP, MCP+I, MCSA, MCSE(NT4/W2K), CCNA, CCA, NWCCC, VH-PIRTS, CEH
--------------------
"hackers are like jedi, crackers are like the sith: do not fall prey to the dark side".
From 1337 h4x0r h4ndb00k: "the ten laws of geek", law x
-Tapeworm
LSOChris
Guest
Re: Exam version 4 help
«
Reply #3 on:
August 30, 2006, 11:52:32 PM »
welcome!
Logged
skel
Jr. Member
Offline
Posts: 60
"Beam me up Scotty - Only hackers here"
Re: Exam version 4 help
«
Reply #4 on:
August 31, 2006, 12:24:40 AM »
Hi guys
Thanks to Kev and Oyle for the replies and tips.
I went through my training last year and was planning to do the exams ever since. I have done through the Books and and played around with the Auditor CD and PHLAK CDs. And I am going through them again now.
Well our training was nothing like what Fenris wrote. This was a more relaxed (loose ?
) training and there was nothing called Lab classes. We didn’t even have Linux box. We got the internet connection to the training room only on the second or third day. But the guy who did the training really knew his stuff. So nothing much to hack we hacked in to the training institutes file server using a buffer overflow attack. I must say the institutes guys were surprised
. But it was harmless fun and the institute got a free penetration testing job for free. So u gus are lucky to go through such a thorough exam preparation boot camp.
Anyway I have decided to do the exam next week ( actually was planning to do it last weekend but was stuck with office work). And also my exam voucher will be expiring soon
I learned some thing new today . URL De-obfuscation !! first time I heard that word. But I now I realise this refers to decoding encoded URLs. Please correct me if I am wrong.
I thought only hex encoded URLs were tested at the exams. Even that, how do you decode a hex URL without a tool ? This I don’t know. What things would I be expected to know in URL De-obfuscation for the test ?
If I manage to do the exam and pass (So far I have never failed a exam but always a first time), I will definitely put comments at the forum
Thanks
Logged
Skel
jimbob
Guest
Re: Exam version 4 help
«
Reply #5 on:
August 31, 2006, 07:10:18 AM »
With character de-obfuscation, try writing a script in perl to do it for you. It's a good way of learning how it works. Try writing one to do URLs (%00), backslash escaped chars (\x00) and unicode (�).
There are several write ups on the web of real attempts to remove obfuscation. SANS have a nice list of some URL obfuscation techniques.
http://isc.sans.org/presentations/urlobfuscation.txt
Regards,
Jim
Logged
Oyle
Sr. Member
Offline
Posts: 264
"Man. Nature. Technology".
Re: Exam version 4 help
«
Reply #6 on:
August 31, 2006, 08:50:55 AM »
URL de-obfuscation is really quite easy, and all you need for it is the Windows Calculator, which I WAS allowed to use during the exam. There is a simple formula, well worth memorizing. This formula should be all you need to know. But in the exam I took, (passed it in Dec. 04) I only had ONE question on URL de-obfuscation.
With URL de-obfuscation, you can represent URLs as a DWORD value, or as HEX, DECIMAL, OCTAL, or ANY COMBINATION OF THOSE. You can insert text into certain areas of a URL that the browser will ignore. It's really pretty cool. There is a 10 page website that does an excellent job of explaining it; it's what I used. It's all explained here:
Click HERE.
Have fun!
Also good to memorize:
%20 is the Unicode equivalent of Space (pressing the space bar)
%40 is the Unicode equivalent of @ (the AT sign)
Note: the web page hyperlinked above is only one page of a larger site. Remove the trailing "obscure.htm", and there's lots more good info, there, too.
Good luck on the exam!! You'll have a long wait for your certificate, be warned.
«
Last Edit: August 31, 2006, 09:37:43 AM by Oyle
»
Logged
MCP, MCP+I, MCSA, MCSE(NT4/W2K), CCNA, CCA, NWCCC, VH-PIRTS, CEH
--------------------
"hackers are like jedi, crackers are like the sith: do not fall prey to the dark side".
From 1337 h4x0r h4ndb00k: "the ten laws of geek", law x
-Tapeworm
jimbob
Guest
Re: Exam version 4 help
«
Reply #7 on:
August 31, 2006, 09:08:03 AM »
I just dug out the emails I got when playing this game. The best clue I can give without giving the game away is to suggest you install the LiveHTTPHeaders plugin for Firefox. It will make your life a little easier!
Jim
Logged
skel
Jr. Member
Offline
Posts: 60
"Beam me up Scotty - Only hackers here"
Re: Exam version 4 help
«
Reply #8 on:
August 31, 2006, 10:14:39 AM »
thanks for the info. The URLs really helped me. I think I have pretty good idea of decoding URLs now.
But I think I will skip the perl script as I am not much of a linux guy
.
Does anybody know a good site that has a some tutorial on analysing snort logs for attacks ?
I found this prtty good article at
http://www.securityfocus.com/infocus/1676
Does anybody know any other articles on this subject ?
Thanks and regards
Logged
Skel
Negrita
Sr. Member
Offline
Posts: 299
Re: Exam version 4 help
«
Reply #9 on:
August 31, 2006, 03:29:23 PM »
I just passed this exam 3 hour ago and I can confirm that Don and Oyle are spot on. You may want to do some revision on SQL injection and on buffer overflows; I found there were quite a few questions about them.
Logged
CEH, CCSA NG/AI, NNCSS, MCP, MCSA 2003
There are 10 kinds of people, those that understand binary, and those that don't.
Kev
Guest
Re: Exam version 4 help
«
Reply #10 on:
August 31, 2006, 04:16:41 PM »
If I remember correctly, the CEH examine datebase consists of something like 500 questions. Each time the test is given, 125 questions are pulled out of this database at random. This makes everyone's experience a little different.
My experience with the test consisted of at least 5 questions on reading snort logs. Several questions asking to identify Ethereal logs and some questions concerning Nmap and Netcat switches. Also, many questions that had nothing to do with tools. Have you heard terms like “piggy backing, black box testing, hacktivism,etc..”?
Good luck with the test and let us know how it goes.
«
Last Edit: August 31, 2006, 06:00:44 PM by Kev
»
Logged
skel
Jr. Member
Offline
Posts: 60
"Beam me up Scotty - Only hackers here"
Re: Exam version 4 help
«
Reply #11 on:
August 31, 2006, 10:19:40 PM »
Quote from: Negrita on August 31, 2006, 03:29:23 PM
I just passed this exam 3 hour ago and I can confirm that Don and Oyle are spot on. You may want to do some revision on SQL injection and on buffer overflows; I found there were quite a few questions about them.
Hi Negrita
Congradulations !!!!!
I shall take your advice
Logged
Skel
skel
Jr. Member
Offline
Posts: 60
"Beam me up Scotty - Only hackers here"
Re: Exam version 4 help
«
Reply #12 on:
August 31, 2006, 10:28:17 PM »
Quote from: Kev on August 31, 2006, 04:16:41 PM
My experience with the test consisted of at least 5 questions on reading snort logs. Several questions asking to identify Ethereal logs and some questions concerning Nmap and Netcat switches. Also, many questions that had nothing to do with tools. Have you heard terms like “piggy backing, black box testing, hacktivism,etc..”?
Good luck with the test and let us know how it goes.
Hi Kev
Ethereal logs are something I have not looked at. I will do it today. Thanks for the tip. I think I can get through the non tool questions.
Regards
Logged
Skel
Negrita
Sr. Member
Offline
Posts: 299
Re: Exam version 4 help
«
Reply #13 on:
September 01, 2006, 03:14:14 AM »
Quote from: skel on August 31, 2006, 10:19:40 PM
Hi Negrita
Congradulations !!!!!
I shall take your advice
Thank you skel.
You may find in the exam that some questions combine topics, for example you might be shown a snort log of a buffer overflow or some other exploit, or even a nmap scan, and be asked questions about that.
Logged
CEH, CCSA NG/AI, NNCSS, MCP, MCSA 2003
There are 10 kinds of people, those that understand binary, and those that don't.
Pages: [
1
]
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
Network Pen Testing
: Want a challenge? Want a GXPN practice exam?
(0) by
ajohnson
GCIH - GIAC Certified Incident Handler
: Passed my GCIH
(8) by
ajohnson
News Items and General Discussion About EH-Net
: Change is Coming to EH-Net!!
(29) by
ajohnson
GCIH - GIAC Certified Incident Handler
: GCIH Free Practice test attempt
(1) by
prats84
Greetings
: Hi from the UK
(4) by
MrTuxracer
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.