Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 33 guests and 1 member online
You are here:
Home
Ethical Hacking Discussions and Related Certifications
Network Pen Testing
CEH - Certified Ethical Hacker
Beginning the CEH
EH-Net
May 20, 2013, 09:38:02 PM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Ethical Hacking Discussions and Related Certifications
>
Network Pen Testing
>
CEH - Certified Ethical Hacker
(Moderator:
don
) >
Beginning the CEH
Pages: [
1
]
2
Go Down
« previous
next »
Print
Author
Topic: Beginning the CEH (Read 8302 times)
0 Members and 1 Guest are viewing this topic.
SephStorm
Hero Member
Offline
Posts: 530
Beginning the CEH
«
on:
November 07, 2010, 02:34:35 AM »
Well, since i've decided to do what ive been putting off forever, i've finally decided to attack the ethical hacking part of my career (Bad pun intended.)
At this point I believe I will start with the CEH. ELS's student program will probable follow, we'll see what kind of timeframe I am looking at later. This thread will hopefully serve to chronicle my progress towards this exam, and hopefully keep me motivated and on track.
First and foremost, I am not looking at this point at ordering the official guide for financial reasons, and reviews of the material would seem to indicate that the money could go elsewhere.
So my first question is, what should be the first book that I should read? What kind of timeframe should I set for myself to master this exam material? I think I am firm on security knowledge at the Security+ level, and I have user level Linux knowledge, no programming knowledge.
Thanks in advance for your replies!
Logged
Support my hactivities.
http://www.cafepress.com/TRUEHacker
COm_BOY
Full Member
Offline
Posts: 129
LivinG DeaD
Re: Beginning the CEH
«
Reply #1 on:
November 07, 2010, 07:34:36 AM »
I dont think CEH requires to have knowledge of scripting or else . It focuses more on tools , You can get CEH book under 30 USD from amazon.com ( dont forget to read reviews of that before purchasing it ) . And as an starting point I think it would be a good idea , other then that do check out the tutorial section of EH which contains links to free logical security CEH videos .
Logged
It has become appallingly obvious that our technology has exceeded our humanity.
SephStorm
Hero Member
Offline
Posts: 530
Re: Beginning the CEH
«
Reply #2 on:
November 07, 2010, 03:53:17 PM »
Looking at that now. By the way, does anyone have a good lab setup for use in studying the CEH? I know the official kit comes with several DVDs.
Logged
Support my hactivities.
http://www.cafepress.com/TRUEHacker
MindOverMatter
Jr. Member
Offline
Posts: 62
Re: Beginning the CEH
«
Reply #3 on:
November 07, 2010, 04:52:25 PM »
Hi SephStorm, I read Kimberly Graves 2010 edition from Sybex, it's good, but doesn't seem to cover enough or go into depth, however the companion cd comes with a great test engine and flash cards.
The asbolute best resourse I've seen out there (which is very pricey) is Wayne Burke's video course, it's certified by the EC-Council, but like $1600 or so. I got to watch some that a friend of a friend had purchased and it's absolutely amazing. He goes so in depth way beyond just the CEH.
I do know that you need to know how to read and understand certain types of scripting, such as they show you a SQL Injection vulnerability or something similar that requires some programming knowledge to understand. Not in depth by any means, but you have to know what you'll get from that output. I'd check out eLearnSecurity's free SQL module.
I have the certificationflashcardsonline, by Shon Harris for $18 and they are 300 questions that are very very good. You can access from your mobile phone or wherever since it's web based login. The answers to the Q's go into a lot of depth as to whatever tool or subject they are talking about, that it seems like almost a book in itself...
The CEH Study Guide by Kimberly Graves cost me $60... Yes I do Amazon, but had a BnN gift card... I wanna get rid of, mint.. Let me know if you're interested, I can seel it back to Amazon for like $12...
If not breaking any laws/ rules I could give you access to my online certificationflashcards, so you can get a little taste if you like.
Logged
A+, Network+, Security+, CIW Associate, CCNA, C|EH
SephStorm
Hero Member
Offline
Posts: 530
Re: Beginning the CEH
«
Reply #4 on:
November 08, 2010, 03:42:05 AM »
very interesting... I have access to the graves book through books 24/7, so I I am good on the book, but the CD isn't included, but I am far from looking at testing at this point.
Is this the company selling the Burke video?
http://www.learninggate.com/about/meet_our_experts.php
hes on the page there, but I am concerned, as the claim to be affiliated with career academy, which has a IMO, horrid CEH video set (I believe the presenter is Kenneth Mayer, who is on that site as well. But I might be mistaken. Whoever it is, he was the most annoying habit of attempting to use his hands constantly... non stop, to illustrate the most basic of concepts. In addition to the series' other faults.
Anyway, I couldnt find a link to purchase the videos there, or elsewhere yet.
OH, I am however loving the logical security videos linked from here, great resource! (I still have yet to see Shon Harris in a video of any kind...)
«
Last Edit: November 08, 2010, 03:44:39 AM by SephStorm
»
Logged
Support my hactivities.
http://www.cafepress.com/TRUEHacker
UNIX
Hero Member
Offline
Posts: 1234
Re: Beginning the CEH
«
Reply #5 on:
November 08, 2010, 08:52:49 AM »
Quote from: SephStorm on November 07, 2010, 03:53:17 PM
Looking at that now. By the way, does anyone have a good lab setup for use in studying the CEH? I know the official kit comes with several DVDs.
The DVDs, which are included in the official courseware, don't include any lab setup, iirc, just the tools, pdf's, etc.
Logged
SephStorm
Hero Member
Offline
Posts: 530
Re: Beginning the CEH
«
Reply #6 on:
November 08, 2010, 09:03:16 AM »
Thats too bad, I know many training programs use lab setups for classes. hence, why I hate self study...
After doing some research, I will have to reconsider the Career Academy program. I was correct with my info regarding Ken Mayer and CA, however, it appears that those videos may be dated. The videos referenced on the site appear to be the Burke videos. I will still have to do some research before I drop a grand on it, but the more I think about it, the more I like it...
I am wondering why Wayne didn't do a CPT video series with them, or anyone else...
Logged
Support my hactivities.
http://www.cafepress.com/TRUEHacker
MindOverMatter
Jr. Member
Offline
Posts: 62
Re: Beginning the CEH
«
Reply #7 on:
November 09, 2010, 01:01:31 AM »
Yeah, I had never heard of Wayne Burke before, but I must say his Career Academy stuff is pretty impressive in scope. I'll have to look up what else Burke has done..
Logged
A+, Network+, Security+, CIW Associate, CCNA, C|EH
chrisj
Hero Member
Offline
Posts: 1163
Re: Beginning the CEH
«
Reply #8 on:
November 09, 2010, 11:11:14 AM »
If you want ideas for labs, look in to chapter 4 of Practical Penetration Testing. You can find a link to the chapter in the book review section above. (Features).
The book over all, I'm not too far into it yet because other things taking have a higher priority, seems to be pretty good. I've already learned some things from it.
Logged
OSWP, Sec+
SephStorm
Hero Member
Offline
Posts: 530
Re: Beginning the CEH
«
Reply #9 on:
November 11, 2010, 10:16:34 PM »
Well, I did say I would chronicle my progress, so a rundown of this week.
I started studying this week, and one of my primary resourses is the Graves study guide. I read chapters 1 & 2, and started on chapter 3. As always, it is amazing reading information on the information gathering stage of hacking, as you can see just what information is out there about your orginization, and sometimes, you yourself.
I don't think I have any major problems with this section except that I really didnt have a hard target to test, while technicly I can use any company for this phase, and indeed I used ARIN and whois to lookup a few, I feel that ultimatly you are gathering this info to prepare an attack, and I have no intention of hacking any of these companies (unless they pay me for it. ; ). I also looked at Hacking Exposed vol6, the corresponding chapter, but it went, I think, overboard for my purposes. Excellent for use when actually using against a target, not so much I think for study?
Chapter 3 is the Scanning and enumeration section. I am only part way through this section, but I decided to throw up some practical excercise here. I used the Heorot.net De-ICE live cd 100.1. Now this "lab" has only limited usefulness because it is designed, I think, with a specific purpose in mind. on purpose, it is not "metasploitable" and certain things have been "broken" to add a touch of difficulty.
So after setting up my lab as decribed in the forum post on Heorot, I started my test. I am most familiar with NMAP, so I fired it up and took a swing. (FYI, I have done the scenario before, but I acted, for the most part as if I had not. Besides, I had forgotten many parts.) I attempted to practice the scenario with a touch of realisim, so first I preformed a scan to see if the host was online, followed by a scan, with the timing set to 3 as an attempt at staying a quiet as possible. I descoved several open ports, and preformed version detection on them. (again, I think the CD comes into account here, but I know its part of the methodology.)
At this point, I had my first real question, how does a beginner know where to go from here? From my previous experience, I knew what port to look at first. A year ago, I didnt. So how would I know what ports to look at and how to attack them?
An any case, I continued the 100.1 excercise up until the priviledge escalation portion, because I was using a different version of BT, that didnt have the needed password list to complete the excercise, and I sure as heck didn't remember it. But one thing I made sure to do was look at the tools presented for each purpose. NMAP and Hydra (cmd-line) were the ones I used. I was unfamiliar with Hydra, so I looked it up. I used the instructions given by the tool to perform the excersise, I did a YT search, but the video I looked at used the GUI option, which doesnt really help you learn much I dont think...
anyway, today I want to finish Chapter 3 and perhaps move on to Chapter 4. We'll see what the day brings... It is my birthday after all... Which begs a question... If youre born in the US, and you are aroundd the world on your birthday, should you celebrate it on the day in the timezone you are in, or when it is actually your brthday in the states? ....
Logged
Support my hactivities.
http://www.cafepress.com/TRUEHacker
MindOverMatter
Jr. Member
Offline
Posts: 62
Re: Beginning the CEH
«
Reply #10 on:
November 11, 2010, 11:58:19 PM »
Happy Birthday! I dunno, I suppose I'd celebrate it when I feel most full of energy.. We tend to celebrate a birthday on a whole day, in my case being born at 7am I could use that as a reference.. Or just celebrate twice!
I'm glad you're liking the Graves book. I'm going to start my second reading of it tomorrow as now that I've had other resources and some of eLearn's modules, going back makes what is more "vague" make more sense in a way..
I actually purchased Hacking Exposed 6 along with the Graves book, which I can see being much more beneficial in the long run, but I've only gotten through the first couple of chapters, so I plan to try and finish that up by the end of this week.
I feel like Grave's book is more like a good "guideline", then as you're doing, research on your own from there, expanding on each topic. After I re-read what you're talking about right now tomorrow, I'll give you my opinion as to what I think..
Check your mail, I have a b-day gift for you, I know will help alot to expand on what your're getting from the CEH material you have gone through so far.
I purchased my voucher today, will probably take the exam mid to end of next week, depending on when I actually get the voucher or voucher number..
Logged
A+, Network+, Security+, CIW Associate, CCNA, C|EH
SephStorm
Hero Member
Offline
Posts: 530
Re: Beginning the CEH
«
Reply #11 on:
November 12, 2010, 09:22:16 AM »
lol, if you have my address, youre a better hacker than I am
Logged
Support my hactivities.
http://www.cafepress.com/TRUEHacker
MindOverMatter
Jr. Member
Offline
Posts: 62
Re: Beginning the CEH
«
Reply #12 on:
November 12, 2010, 03:24:57 PM »
Darn, I just put the one you have listed on the site here.. lol
I'm supposing it's the wrong one.. ?
Logged
A+, Network+, Security+, CIW Associate, CCNA, C|EH
MindOverMatter
Jr. Member
Offline
Posts: 62
Re: Beginning the CEH
«
Reply #13 on:
November 12, 2010, 04:13:32 PM »
Hey and who says I'm not a better hacker than you, just cuz I don't post your SS # on forums... JK of of course
Logged
A+, Network+, Security+, CIW Associate, CCNA, C|EH
SephStorm
Hero Member
Offline
Posts: 530
Re: Beginning the CEH
«
Reply #14 on:
November 12, 2010, 06:52:45 PM »
theres one on the site here?
Oh, are you talking email address?
Logged
Support my hactivities.
http://www.cafepress.com/TRUEHacker
Pages: [
1
]
2
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
OSCP - Offensive Security Certified Professional
: Failed my first attempt at the OSCP exam
(94) by
azmatt
Programming
: Finished Python Course in Codecademy now what?
(11) by
securitian
Tools
: Social-Engineer Toolkit (SET) Version 5.0 “The Wild West” Released
(2) by
m0wgli
Malware
: EICAR?
(3) by
UKSecurityGuy
Advisories
: HTB23154: Multiple Vulnerabilities in Exponent CMS
(0) by
AndyP
Advisories
: HTB23153: Multiple Vulnerabilities in Jojo CMS
(0) by
AndyP
Advisories
: HTB23151: Cross-Site Request Forgery (CSRF) in UMI.CMS
(0) by
AndyP
Tutorials
: Need guidance
(8) by
r0ckm4n
OSCP - Offensive Security Certified Professional
: Class Scheduled 6/8 - Linux n00b
(7) by
Taemyks
OSCP - Offensive Security Certified Professional
: OSCP exam scheduled
(6) by
gbhat
Incident Response
: LinkedIn Forensics
(0) by
AFENTIS_Forensics
General Certification
: Red Team/Blue Team
(1) by
ajohnson
Career Central
: Starter cert?
(3) by
Grendel
Network Pen Testing
: Beginner Ethical Hacker
(1) by
m0wgli
General Certification
: CPT Practical Submission
(0) by
z28power4u
Web Applications
: Nessus and Nikto
(4) by
Seen
Network Pen Testing
: Cracking salted MD5 hash
(4) by
n37sh@rk
CEH - Certified Ethical Hacker
: Passed my C|EH
(3) by
n37sh@rk
Mass Media
: EC-council hacked, irony at his best?
(0) by
j0rDy
Web Applications
: SQL Injection into an INSERT statement.
(6) by
eyenit0
Network Pen Testing
: Solution for sipXtapi INVITE Message CSeq Field Header Remote Overflow
(1) by
m0wgli
Web Applications
: dns
(2) by
H1t M0nk3y
Other
: BSides Boston
(0) by
3xban
Career Central
: InfoSec in Central, FL
(2) by
tturner
Web Applications
: Web vulnerability scanner
(4) by
H1t M0nk3y
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
Free Business and Tech Magazines and eBooks
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.