Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 42 guests and 1 member online
You are here:
Home
Ethical Hacking Discussions and Related Certifications
Network Pen Testing
CPT Practical - Feedback Please...
EH-Net
May 21, 2013, 06:12:56 AM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Ethical Hacking Discussions and Related Certifications
>
Network Pen Testing
(Moderator:
don
) >
CPT Practical - Feedback Please...
Pages: [
1
]
2
3
...
9
Go Down
« previous
next »
Print
Author
Topic: CPT Practical - Feedback Please... (Read 63381 times)
0 Members and 1 Guest are viewing this topic.
bm5034
Newbie
Offline
Posts: 6
CPT Practical - Feedback Please...
«
on:
November 17, 2010, 06:28:59 AM »
Greetings all:
I am in the process of taking the practical portion of the IACRB CPT exam. As most of you well know, you've got 60 days to complete and submit. I'm on the final step of the exam, which requires cracking of the root password on a Linux host. For me, this step seems to be taking quite a long time (15+ days now). While I realize that real-world password cracking can take days, months, or even years (depending on complexity), I'm curious to see if others have had the same experience. Also, what are your general feelings on the CPT and the amount of weight it carries in the pen-testing field? I've passed the CEH (InfoSec training) and have been considering the OSCP. Thoughts on that?
My planned direction is to "break into" this field starting next year, and I'm looking for suggestions on a sound approach. Ideally, I'd like to work as an independent, providing services to small companies (in the long run), but I realize that true pen-testing is seldom a one-man show.
Thanks in advance!
Logged
SephStorm
Hero Member
Offline
Posts: 530
Re: CPT Practical - Feedback Please...
«
Reply #1 on:
November 17, 2010, 08:17:05 AM »
Hi, welcome to EthicalHacker.net! While I will leave your questions to others with knowledge of the subject, You say you took the InfoSec Institute training? I would be very interested in hearing your review of the company and its training. If you have time, please, let me know your thoughts in this thread, or by PM.
Logged
Support my hactivities.
http://www.cafepress.com/TRUEHacker
hayabusa
Hero Member
Offline
Posts: 1631
Re: CPT Practical - Feedback Please...
«
Reply #2 on:
November 17, 2010, 08:26:07 AM »
Welcome!
Logged
~ hayabusa ~
"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'
OSCE, OSCP , GPEN, C|EH
sil
Hero Member
Offline
Posts: 549
Re: CPT Practical - Feedback Please...
«
Reply #3 on:
November 17, 2010, 08:57:38 AM »
Quote from: bm5034 on November 17, 2010, 06:28:59 AM
Greetings all:
I am in the process of taking the practical portion of the IACRB CPT exam. As most of you well know, you've got 60 days to complete and submit. I'm on the final step of the exam, which requires cracking of the root password on a Linux host. For me, this step seems to be taking quite a long time (15+ days now). While I realize that real-world password cracking can take days, months, or even years (depending on complexity), I'm curious to see if others have had the same experience. Also, what are your general feelings on the CPT and the amount of weight it carries in the pen-testing field? I've passed the CEH (InfoSec training) and have been considering the OSCP. Thoughts on that?
My planned direction is to "break into" this field starting next year, and I'm looking for suggestions on a sound approach. Ideally, I'd like to work as an independent, providing services to small companies (in the long run), but I realize that true pen-testing is seldom a one-man show.
Thanks in advance!
You may want to find a better wordlist. I cracked IACRB's password in under 3 minutes. My method for cracking the password portion of the exam was to create a pseudo distributed system to do the cracking. I took 4 machines with about 2gigs of memory each, downloaded a couple of wordlists, made some voodoo regex's of the files, put them on different machines and fired them up. At best I think I was able to generate about 20 million attempts per minute,
The pw cracking portion was easy to me. It boils down to a few things when cracking passwords: 1) The PW cracker you're using 2) the wordlist(s) your using 3) the processor speed/memory of the machine doing the cracking. Here is a quick primer on password cracking:
http://geodsoft.com/howto/password/cracking_passwords.htm
without giving up the keys to the kingdom, this portion should not take you that long.
Did you manage to finish the second portion of the test or did you just start? There are always two ways to skin a cat you know
But that's all I will say on the exam.
As for the OSCP, points of view differ on this. Depending on what exam you receive for the CPT (I'm assuming here they have a few different deliverables), my technical exam was difficult as I had to work around my own exploit on a Bastille hardened version of Linux. Trust me when I tell you this, there was NO publicly available exploit for me to compromise the machine. I had to modify a few exploits with GDB in the background to get it working. Took me 3 days off and on to finish up the entire exam.
Logged
http://www.infiltrated.net/mgz/puppylecter.jpg
bm5034
Newbie
Offline
Posts: 6
Re: CPT Practical - Feedback Please...
«
Reply #4 on:
November 17, 2010, 10:49:17 AM »
Thanks for the information; it's much appreciated. I figured things were taking too long, but I couldn't be sure. I'm using JTR on the passwords, and I've got two machines working together. Best I can do, hardware-wise. Looks like I'll be searching for other wordlists. I've already obtained the root password for the first host; only need to get the second one at this point, then I'm ready to submit my results.
I've also considered taking InfoSec's Advanced Ethical Hacking course in the spring of next year. I understand that course focuses more on shellcoding, exploits, malware and the like. I've heard good reviews, so I may go for that one next.
Logged
UNIX
Hero Member
Offline
Posts: 1235
Re: CPT Practical - Feedback Please...
«
Reply #5 on:
November 17, 2010, 10:54:05 AM »
From the opinions I've heard of, InfoSec's Advanced Ethical Hacking course is excellent. Looking at the instructors, I have hardly a doubt on that. If you decide to take it, a review would be nice.
Logged
sil
Hero Member
Offline
Posts: 549
Re: CPT Practical - Feedback Please...
«
Reply #6 on:
November 17, 2010, 12:48:57 PM »
Quote from: bm5034 on November 17, 2010, 10:49:17 AM
I've also considered taking InfoSec's Advanced Ethical Hacking course in the spring of next year. I understand that course focuses more on shellcoding, exploits, malware and the like. I've heard good reviews, so I may go for that one next.
Here is a tip... As with real world penetrations, you should perhaps seek to obtain the password of
ANY
account not necessarily the root password. With a normal user account, you could then use a local exploit to escalate privileges. So, again, depending on how your performing password cracking, there is a likelihood you went overboard and could have obtained root access by other means. "just a thought"
Logged
http://www.infiltrated.net/mgz/puppylecter.jpg
jtb3125
Guest
Re: CPT Practical - Feedback Please...
«
Reply #7 on:
November 17, 2010, 12:52:22 PM »
bm5034: Your description sounds like my own experience with the CPT practical - first machine's root password was an easy crack, but the second one's still running, 2 weeks later... I'm also hardware limited, at least for now, so not much I can do to speed things up except perhaps a better wordlist.
My 2 cents' worth on InfoSec Institute - I thought their Ethical Hacking class was well-presented, and the materials seemed thorough and well-assembled. The instructor (Keatron Evans) was very good, kept things interesting. Passed the CEH, hoping to pass the CPT, then figuring out where to go next...
Logged
sil
Hero Member
Offline
Posts: 549
Re: CPT Practical - Feedback Please...
«
Reply #8 on:
November 17, 2010, 02:03:02 PM »
Quote from: jtb3125 on November 17, 2010, 12:52:22 PM
then figuring out where to go next...
*sigh* my biggest dilemna
Well I have GREM in Jan/Feb and I'm itching to take some training/testing again. Just don't know which way to go with this. I don't want to go the vendor route but I may be forced to do JNCIA + JNCIS soon because of the amount of Juniper crap I deal with nowadays... CCIE(s) reading + lab studies are still around but I do it more for perversion than anything else. (For those who don't know, I've actually spent about 10 years learning Cisco things...) Just too darned lazy to opt for taking the CCNA, then the CCSP route to get to the CCIE(S). I started studying immediately for the CCIE in 98-99 (see appendix @
http://www.ouah.org/protocol_level.htm
written 2000 imagine that!) and kept on studying at my own leisure...
Anyhow, my big fear with the CCIE is the lab. Failure = a lot of moolah. It's not a cheap exam. The written I don't believe I'd have a problem with. It's the lab because I don't have enough time to create scenarios, etc., I still have my lab, IPExperts audio, books, etc., its just not worth studying at the level to me anymore.
I like technical exams. I may do the OSCE soon, but I'm thinking... GREM first. Let me take a break for a month or two... Right after the GREM I may do, CREA, CCFE, EnCE one right after the other. I may follow up with other SANS classes depending on polit(r)ic(k)s. Unsure though. By next year if I was successful, I would be a bizarre professional
CPT, OSCP, CEH --> attacker
CHFI, EnCE CCFE --> analyst/forensic
GREM, CREA --> reverser
Not only that, would likely cost more to print my business cards. I was also looking at the NOP
Now that would be hardcore...
http://www.immunitysec.com/services-cnop.shtml
Logged
http://www.infiltrated.net/mgz/puppylecter.jpg
bm5034
Newbie
Offline
Posts: 6
Re: CPT Practical - Feedback Please...
«
Reply #9 on:
November 17, 2010, 02:48:08 PM »
Thinking about this more, my next step will likely be the Advanced CEH class. I personally have more interest in shell code, reversal, malware, exploits and the like, since I come from 12+ years in software/database development. I would enjoy working with software and data, as well as how products can be better designed to prevent these kinds of attacks. The pen-testing/ethical hacking profession will be a new endeavor for me, but I favor working with the software/data side of security, rather than the networking/admin side.
If I fare well after that, I'll need to determine what other certifications would be best to obtain with a focus on software/database exploits and security. I suppose that would be my next question...
(As a side note related to my original topic, I did successfully compromise the second host by logging in with a standard account, then performing a privilege escalation exploit. From there, I was able to obtain the root password hash, and here I sit waiting, two weeks later...)
Logged
SephStorm
Hero Member
Offline
Posts: 530
Re: CPT Practical - Feedback Please...
«
Reply #10 on:
November 18, 2010, 02:29:22 AM »
So, I admit myself confused, the CEH/CPT by ISI does not require the shell-coding/programming knowledge?
Logged
Support my hactivities.
http://www.cafepress.com/TRUEHacker
bm5034
Newbie
Offline
Posts: 6
Re: CPT Practical - Feedback Please...
«
Reply #11 on:
November 18, 2010, 06:27:36 AM »
In the CEH/CPT, you learn the concepts of programming exploits using shellcode, but you don't actually do any coding. The exploits you use are already prepared for you in the labs. In the advanced CEH course, you actually write the exploits, so it's *strongly* recommended that you have knowledge of assembler or C beforehand.
My instructor in the CEH class suggested that I get a copy of the Shellcoder's Handbook (J. Koziol) to do some advance reading in preparation for the advanced class.
Logged
SephStorm
Hero Member
Offline
Posts: 530
Re: CPT Practical - Feedback Please...
«
Reply #12 on:
November 18, 2010, 06:56:02 AM »
Okay, that explained it. What books did you guys use during the course? Did they provide any?
Logged
Support my hactivities.
http://www.cafepress.com/TRUEHacker
bm5034
Newbie
Offline
Posts: 6
Re: CPT Practical - Feedback Please...
«
Reply #13 on:
November 18, 2010, 08:25:23 AM »
Two books were used: a textbook and lab manual. You had the option of having the textbook sent to you in advance, when InfoSec received your course payment in full. This is what I did, and it really helped me to prepare, as I had read through the textbook twice before the week of class.
The lab manual was given out in class. You were also given two DVDs to keep: one was a linux attack server VM, and the other was a collection of tools used in the class.
«
Last Edit: November 18, 2010, 08:27:11 AM by bm5034
»
Logged
edygert
Newbie
Offline
Posts: 1
Re: CPT Practical - Feedback Please...
«
Reply #14 on:
November 18, 2010, 02:59:56 PM »
I just passed the CPT exam last month and the CEH this morning after taking the online version of the InfoSec Institute Ethical Hacking course. I found the course materials to be excellent. However, for the CEH test, I also recommend studying the Michael Gregg book before taking the CEH. The CPT multiple choice was very easy but the practical took me several days to finish. Escalating privileges on the two machines was fairly challenging.
I am currently taking their Advanced Ethical Hacking course and am about 1/2 done. I don't recommend it if you are not a programmer. I have been programming for over 30 years so I am really enjoying the course.
I am taking the GIAC GPEN test on Monday. I took one of GIAC's GPEN practice tests and did really well on it. Just have a few things to brush up on. There is a lot of overlap between CEH/CPT and GPEN.
Logged
Pages: [
1
]
2
3
...
9
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
GAWN - GIAC Assessing Wireless Networks
: Karen Millen Dresses Things did improve as the decade gone on
(0) by
dtree70fx
General Certification
: CPT Practical Submission
(1) by
UNIX
OSCP - Offensive Security Certified Professional
: Failed my first attempt at the OSCP exam
(94) by
azmatt
Programming
: Finished Python Course in Codecademy now what?
(11) by
securitian
Tools
: Social-Engineer Toolkit (SET) Version 5.0 “The Wild West” Released
(2) by
m0wgli
Malware
: EICAR?
(3) by
UKSecurityGuy
Advisories
: HTB23154: Multiple Vulnerabilities in Exponent CMS
(0) by
AndyP
Advisories
: HTB23153: Multiple Vulnerabilities in Jojo CMS
(0) by
AndyP
Advisories
: HTB23151: Cross-Site Request Forgery (CSRF) in UMI.CMS
(0) by
AndyP
Tutorials
: Need guidance
(8) by
r0ckm4n
OSCP - Offensive Security Certified Professional
: Class Scheduled 6/8 - Linux n00b
(7) by
Taemyks
OSCP - Offensive Security Certified Professional
: OSCP exam scheduled
(6) by
gbhat
Incident Response
: LinkedIn Forensics
(0) by
AFENTIS_Forensics
General Certification
: Red Team/Blue Team
(1) by
ajohnson
Career Central
: Starter cert?
(3) by
Grendel
Network Pen Testing
: Beginner Ethical Hacker
(1) by
m0wgli
Web Applications
: Nessus and Nikto
(4) by
Seen
Network Pen Testing
: Cracking salted MD5 hash
(4) by
n37sh@rk
CEH - Certified Ethical Hacker
: Passed my C|EH
(3) by
n37sh@rk
Mass Media
: EC-council hacked, irony at his best?
(0) by
j0rDy
Web Applications
: SQL Injection into an INSERT statement.
(6) by
eyenit0
Network Pen Testing
: Solution for sipXtapi INVITE Message CSeq Field Header Remote Overflow
(1) by
m0wgli
Web Applications
: dns
(2) by
H1t M0nk3y
Other
: BSides Boston
(0) by
3xban
Career Central
: InfoSec in Central, FL
(2) by
tturner
Web Applications
: Web vulnerability scanner
(4) by
H1t M0nk3y
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.