Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 36 guests and 1 member online
You are here:
Home
Ethical Hacking Discussions and Related Certifications
Network Pen Testing
CPT Practical - Feedback Please...
EH-Net
May 24, 2013, 09:11:26 AM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Ethical Hacking Discussions and Related Certifications
>
Network Pen Testing
(Moderator:
don
) >
CPT Practical - Feedback Please...
Pages:
1
...
3
4
[
5
]
6
7
...
9
Go Down
« previous
next »
Print
Author
Topic: CPT Practical - Feedback Please... (Read 63518 times)
0 Members and 1 Guest are viewing this topic.
Joshsevo
Sr. Member
Offline
Posts: 278
Re: CPT Practical - Feedback Please...
«
Reply #60 on:
October 19, 2011, 01:57:12 PM »
I feel I am over my head on this one. Sucks cause I wanted it. No luck on getting the two to be able to talk to each other.
I suppose I am still a bit confusedon which computer am I supposed to use to do the attacking. I first thought the cptvm1 was the attackeing and I was supposed to get info about it (IP ranges, users, username/passwords) then use that to attack cptvm1. But in order for me to attack the 2nd one I need the tools loaded onto cptvm1 to use them. If this is the case then I am having problems getting the programs to execute.
Or..
If I am supposed to use my host computer to attack the two VM's and get the info from there. This is a bit easier for me, but so far the things I have tried has not worked and I still can't talk to the VM's to begin the attack.
Tried calling the oraganization that offers this cert and they have yet to call me back.....3 weeks ago. tried calling my teacher from Infosec Institute and he has not picked up or called me back or emailed me back.
Logged
Security+, Network+, C|EH, CHFI, CPT
r2s
Newbie
Offline
Posts: 49
The Artisan
Re: CPT Practical - Feedback Please...
«
Reply #61 on:
October 19, 2011, 05:09:20 PM »
Quote from: Joshsevo on October 19, 2011, 01:57:12 PM
I feel I am over my head on this one. Sucks cause I wanted it. No luck on getting the two to be able to talk to each other.
I suppose I am still a bit confusedon which computer am I supposed to use to do the attacking. I first thought the cptvm1 was the attackeing and I was supposed to get info about it (IP ranges, users, username/passwords) then use that to attack cptvm1. But in order for me to attack the 2nd one I need the tools loaded onto cptvm1 to use them. If this is the case then I am having problems getting the programs to execute.
Or..
If I am supposed to use my host computer to attack the two VM's and get the info from there. This is a bit easier for me, but so far the things I have tried has not worked and I still can't talk to the VM's to begin the attack.
Tried calling the oraganization that offers this cert and they have yet to call me back.....3 weeks ago. tried calling my teacher from Infosec Institute and he has not picked up or called me back or emailed me back.
Without violating NDA (for the networking issue), all I can say is think back to your pentesting methodologies and how networks work in general. Think about how hosts get IPs and what that interaction looks like. Think about what tools you could use to see network interactions.
Your host machine (if bridged) or guest VM(s) is/are supposed to leverage the two VMs. If you happen to get root on CPTVM1 before CPTVM2 or vice versa then so be it.
The networking advice sounds extremely basic but if interpreted right you'll soon be on your way. In my experience with this exam, you will definitely find multiple sticking points where things just don't work as expected but the pain and anguish is well worth it and will be vastly beneficial in your overall development.
«
Last Edit: October 19, 2011, 05:13:43 PM by r2s
»
Logged
In progress:
OSCP & GXPN (June)
"Silence enables the sound to be"
- Eckhart Toll
Joshsevo
Sr. Member
Offline
Posts: 278
Re: CPT Practical - Feedback Please...
«
Reply #62 on:
October 19, 2011, 05:34:03 PM »
R2s,
Thanks for the response. I am a bit frustrated to say the least. If you have been keeping up with this thread since I brought it back from the dead you will see that I am a recent graduate and have never had a IT related job for the most part.
My knowledge of networks is very basic. IP's come from the ISP. No idea what they look like or how they are really generated. No experience in that. What do you mean leverage the VM's?? How can I get the root if I cannot even ping the VM to use certain brute force tools to crack the password. Fomr playing around with John the Ripper, it asks for a Target IP to begin. I don't know that target IP.
Logged
Security+, Network+, C|EH, CHFI, CPT
lorddicranius
Sr. Member
Offline
Posts: 447
Re: CPT Practical - Feedback Please...
«
Reply #63 on:
October 19, 2011, 06:03:03 PM »
Quote from: Joshsevo on September 30, 2011, 08:59:36 PM
(CPT VM1.rar and CPT VM2.rar). Once these are started you’ll need to perform a penetration test against these two virtual machines.
No IP addresses will be given. You must first discover the ip’s of the two virtual machines first. Once you’ve discovered them you will need to do recon on both machines. You’ll need to configure your network or computer appropriately to operate on the same network or in the same network range of the two VM’s. You are allowed to use the Linux Attack VM you were given in the Infosec Institute Ethical Hacking class. Discover if there’s any services running on them that might be vulnerable. You’ll need to document your network recon efforts.
1) It looks like the CPT VM's are both target machines. Use either the Linux Attack VM you were given during class or another machine you've setup for attacking (BackTrack, Samurai WTF, etc).
2) As for the IP situation, go back to the networking settings for the VM's (e.g. bridged, internal, etc). Understand the different network settings used by the VM software you're using (VMWare Player, Virtualbox, etc). Once you understand that, you'll be able to configure the VM's to the proper network settings and move forward.
As for finding what IP's they've acquired, per the instructions it looks like that's part of the exam so I'm not sure how far I can go with helping...but given you aren't getting any feedback from the cert org or your instructor, I'll just throw some terms out there and see if you can sort it out
DHCP, ARP, Wireshark, nmap...
Logged
GSEC, eCPPT, Sec+
Joshsevo
Sr. Member
Offline
Posts: 278
Re: CPT Practical - Feedback Please...
«
Reply #64 on:
October 19, 2011, 08:11:36 PM »
There was not an attack machine or VM given to me. Just one disc with cptvm1 and cptvm2 on it and a good luck!
Logged
Security+, Network+, C|EH, CHFI, CPT
SephStorm
Hero Member
Offline
Posts: 530
Re: CPT Practical - Feedback Please...
«
Reply #65 on:
October 19, 2011, 08:53:39 PM »
There should have been another, but at this point, it doesnt matter (you can contact ISI if you cant find it in your packet). Actually, some of the videos go through all this, have you viewed the course videos?
okay, my suggestion:
Turn off your vms and boot up your pc. (Windows) Open up command prompt and insure you have an ip address. If you do, then boot up a new vm booting from CPTVM1. do a ping sweep using nmap from your windows PC. You should find a new device. (i.e the vm.) if that works, do the same with CPTVM2. If you have any problems going through this, PM me.
Logged
Support my hactivities.
http://www.cafepress.com/TRUEHacker
Joshsevo
Sr. Member
Offline
Posts: 278
Re: CPT Practical - Feedback Please...
«
Reply #66 on:
October 19, 2011, 11:11:40 PM »
OK answer this for me.
I log onto cptvm1 and I go onto the internet on the VM. I have wireshark up and catching packets. Why doesn't wireshark show the HTTP traffic. I've watched some tutorials about wireshark and they show HTTP traffic when using a regular computer. (the videos were done on a computer and not a VM).
This is what I am seeing so far.
Logged
Security+, Network+, C|EH, CHFI, CPT
SephStorm
Hero Member
Offline
Posts: 530
Re: CPT Practical - Feedback Please...
«
Reply #67 on:
October 19, 2011, 11:13:48 PM »
Couldnt tell you. You should never login to the VM's, except via shell, they are representing remote systems you dont have physical access to.
Logged
Support my hactivities.
http://www.cafepress.com/TRUEHacker
Joshsevo
Sr. Member
Offline
Posts: 278
Re: CPT Practical - Feedback Please...
«
Reply #68 on:
October 19, 2011, 11:20:21 PM »
Ok, I open the cmd on my computer. I type ipconfig and I get the following
Ethernet adapter local area connection:
blah blah blah
blah blah blah blah
IPV4 192.168.1.XXX This is my IP
blah blah blah
blah blah blah
Ethernet Adapter VMware Network Adapter VMnet1:
blah blah blah
blah blah blah
IPv4 192.168.213.1
Ethernet Adapter VMware Network Adapter VMnet8:
blah blah blah
blah blah blah
IPv4 192.168.191.1
I assume these are my VMware IP's? Why this didn't show the other day I don't know. Maybe because I had the VM on "host only" and tonight when I got home I changed it to Bridged.
This is what I have so far. I'm goin to bed.
Logged
Security+, Network+, C|EH, CHFI, CPT
lorddicranius
Sr. Member
Offline
Posts: 447
Re: CPT Practical - Feedback Please...
«
Reply #69 on:
October 20, 2011, 12:03:26 AM »
Those interfaces you're seeing on your host computer (VMnet1, VMnet8) are interfaces created by the VMWare software that allow all the VM's to communicate. Picture a physical switched network all contained within your one host computer. The VM's need a switch to talk to each other. That's what these interfaces do.
http://www.vmware.com/support/ws55/doc/ws_net_component_vswitch.html
So what you can gather from that, is depending on the type of networking you configured for the VM's, you'll know which subnet they reside on.
There's some images in these links that may help you visualize it:
- NAT:
http://www.vmware.com/support/ws55/doc/ws_net_configurations_nat.html
- Host-only:
http://www.vmware.com/support/ws55/doc/ws_net_configurations_hostonly.html
«
Last Edit: October 20, 2011, 12:07:47 AM by lorddicranius
»
Logged
GSEC, eCPPT, Sec+
SephStorm
Hero Member
Offline
Posts: 530
Re: CPT Practical - Feedback Please...
«
Reply #70 on:
October 20, 2011, 11:04:39 AM »
ok, your computer is getting an IP address. I would ignore the VMNet ips. If you still cannot sweep the vms, I would check your router settings, and insure you are on DHCP and you have enough leases in your pool to give them IP's, and make sure you arent doing anything crazy like MAC filtering, ect. Failing that, PM me and we'll setup a call, i'll try to get you setup.
A very important question though, did you watch the videos?
Logged
Support my hactivities.
http://www.cafepress.com/TRUEHacker
Joshsevo
Sr. Member
Offline
Posts: 278
Re: CPT Practical - Feedback Please...
«
Reply #71 on:
October 20, 2011, 01:54:52 PM »
No not yet. I won't have time until late tonight or tomorrow and over the weekend. Going to my internship to night for a few hrs as he has a new case he wants my help on.
Logged
Security+, Network+, C|EH, CHFI, CPT
SephStorm
Hero Member
Offline
Posts: 530
Re: CPT Practical - Feedback Please...
«
Reply #72 on:
October 21, 2011, 01:41:31 AM »
Oh, my friend, you need to view the videos before you start the exam!!
I see you have the CEH... im a little confused...
Logged
Support my hactivities.
http://www.cafepress.com/TRUEHacker
Joshsevo
Sr. Member
Offline
Posts: 278
Re: CPT Practical - Feedback Please...
«
Reply #73 on:
October 21, 2011, 01:15:31 PM »
What are you confused on?
Logged
Security+, Network+, C|EH, CHFI, CPT
Full7i17
Newbie
Offline
Posts: 2
Re: CPT Practical - Feedback Please...
«
Reply #74 on:
October 21, 2011, 03:48:40 PM »
When I took that course, I received a disk with the attack machine from class. The instructor told us we were allowed to log into the boxes as we probably wouldn't be able to find remote exploits for the machines.
You may want to consider using a network discovery tool like autoscan. It will find host even if they aren't on the same subnet or network. That should help you.
Logged
A+, Network+, Security+, C|EH. CPT
Currently working on: CCNA
Pages:
1
...
3
4
[
5
]
6
7
...
9
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
Network Pen Testing
: Want a challenge? Want a GXPN practice exam?
(0) by
ajohnson
GCIH - GIAC Certified Incident Handler
: Passed my GCIH
(8) by
ajohnson
News Items and General Discussion About EH-Net
: Change is Coming to EH-Net!!
(29) by
ajohnson
GCIH - GIAC Certified Incident Handler
: GCIH Free Practice test attempt
(1) by
prats84
Greetings
: Hi from the UK
(4) by
MrTuxracer
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.