Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 35 guests and 1 member online
 
Advertisement

You are here: Home arrow Ethical Hacking Discussions and Related Certificationsarrow Network Pen Testingarrow CPT Practical - Feedback Please...
EH-Net
May 19, 2013, 10:05:19 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: 1 2 [3] 4 5 ... 9   Go Down
  Print  
Author Topic: CPT Practical - Feedback Please...  (Read 63202 times)
0 Members and 1 Guest are viewing this topic.
Joshsevo
Sr. Member
****
Offline Offline

Posts: 278


View Profile
« Reply #30 on: September 30, 2011, 01:58:46 PM »

I need some help on this. 

I am a newbie as some of you know.  I passed the first part of the CPT test and now I am about to start the practical and am stuck. 

Again I am a newbie and only played with VM player twice.  I have the disc the techer form the InfoSec class gave us.

It loads fine.  I see instructions and two other files named "target1 & Target2" or something like that.  I'm at work and not sitting in front of the computer now so going off memeory here.

But I load them up and they start to load and it stays on a black screen and says " NO OS detected".  Assuming I am understanding this coreectly I have to install my own OS into the VM that I got from class.

Any help?  I have tried calling the teacher already to help me start and also tried calling Infosec. 
Logged

Security+, Network+, C|EH, CHFI, CPT
lorddicranius
Sr. Member
****
Offline Offline

Posts: 447



View Profile WWW
« Reply #31 on: September 30, 2011, 02:13:23 PM »

I haven't used VMWare Player in awhile, but when setting up a new VM in VirtualBox you have to make sure you load the CD/ISO in the virtual CD-ROM, then boot up the VM.  It's like you're setting up the hardware (creating the VM to show up in your list), then installing the OS...if that makes sense.
Logged

GSEC, eCPPT, Sec+
Joshsevo
Sr. Member
****
Offline Offline

Posts: 278


View Profile
« Reply #32 on: September 30, 2011, 02:41:33 PM »

I think I understand.  I will give that a shot when I get home.
Logged

Security+, Network+, C|EH, CHFI, CPT
hayabusa
Hero Member
*****
Offline Offline

Posts: 1630



View Profile
« Reply #33 on: September 30, 2011, 05:57:01 PM »

Most class VM's SHOULD be good to go, already.  If they gave you the vmdk files, and they're fairly sizeable, you shouldn't have to install an OS.  You should just go to the file menu in VMWare, do an Open, and browse to the proper vmx config files, for each.  The only other thing you might have to do (maybe) is edit the vmx to make sure paths are set to your local machine file paths.

Oh, and one more thing...  If you copied the files from CD or DVD, make sure to take off the Read-Only flag on them...  That might be contributing to your grief.

(edit - you can't run them from the CD /DVD unless they're just 'live dvd' images)
« Last Edit: September 30, 2011, 05:58:34 PM by hayabusa » Logged

~ hayabusa ~ 

"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'


OSCE, OSCP , GPEN, C|EH
Joshsevo
Sr. Member
****
Offline Offline

Posts: 278


View Profile
« Reply #34 on: September 30, 2011, 08:47:20 PM »

Ok SO I'm home now and I here is what I have

CD from InfoSec
Instructions

When I click on Start, Computer and then go to the CD that is in my E Drive I have a folder named CPT. 
Double click CPT folder
Opens to shows 6 files:
._CPT Instructions.htm.......can't open this one
CPT Instructions.htm...this opens to the instructions on the test
CPT.VM1.rar
CPT.VM2.rar
VM-player 3.1.2-301548.exe
wrar.393.exe

Double click the file VM.exe and it installs VW player
The CPT.VM1.rar files show them being as Itunes opened files.  Meaning there is an iTunes logo on the file because I probably have the .rar files being auto opened by this.  Don't think this is a big deal though as I can just click "open with VM"...right?

Logged

Security+, Network+, C|EH, CHFI, CPT
Joshsevo
Sr. Member
****
Offline Offline

Posts: 278


View Profile
« Reply #35 on: September 30, 2011, 08:59:36 PM »

Here are the instructions:

On the DVD provided to you, will be a folder named CPT Practical.  In this folder you’ll find a copy of winrar, a copy of vmware player and two virtual machines.  You’ll need to uncompress the .rar files using winrar, then start the virtual machines included in these two .rar files

(CPT VM1.rar and CPT VM2.rar).  Once these are started you’ll need to perform a penetration test against these two virtual machines.

No IP addresses will be given.  You must first discover the ip’s of the two virtual machines first.  Once you’ve discovered them you will need to do recon on both machines. You’ll need to configure your network or computer appropriately to operate on the same network or in the same network range of the two VM’s.   You are allowed to use the Linux Attack VM you were given in the Infosec Institute Ethical Hacking class.  Discover if there’s any services running on them that might be vulnerable.  You’ll need to document your network recon efforts.

It might be helpful to perform man in the middle per your instructions in class, against the two virtual mchines.  From this MiTM you should get at least one of the two root passwords!

You must launch a network based penetration attack against the two machines and discover potential credentials.  The only hint you have in that regard is the paragraph above.  The end result should be that you obtain the root password to one of the virtual machines.

Once you’ve gained root on one machine, you’ll need to crack some other user accounts on that compromised machine.  Remember credentials and accounts MIGHT be used on both machines, so once you’ve cracked the accounts on the first machine, consider that possibility.

Once you gain some level of access on the second machine (it most likely won’t be root privileges), you’ll need to perform a local exploit or as it’s also called a privilege escalation exploit to gather the shadow file on the second machine.  Once you have the shadow file, crack away until you have the second root password.

Be advised you won’t be considered for being awarded the IACRB Certified Penetration Tester certification if both root passwords are not obtained and/or you don’t document your penetration test.

Good Luck!
Logged

Security+, Network+, C|EH, CHFI, CPT
hayabusa
Hero Member
*****
Offline Offline

Posts: 1630



View Profile
« Reply #36 on: September 30, 2011, 09:32:20 PM »

So you need to install winrar (wrar.393.exe,) use it to extract the vm's from the two RAR files, install VMPlayer, then point to the extracted VM's and go.
Logged

~ hayabusa ~ 

"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'


OSCE, OSCP , GPEN, C|EH
hayabusa
Hero Member
*****
Offline Offline

Posts: 1630



View Profile
« Reply #37 on: September 30, 2011, 09:33:42 PM »

Oh...  And Good Luck!  :-D
Logged

~ hayabusa ~ 

"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'


OSCE, OSCP , GPEN, C|EH
Joshsevo
Sr. Member
****
Offline Offline

Posts: 278


View Profile
« Reply #38 on: September 30, 2011, 10:40:46 PM »

HA that was it.  It;s working now.

LOL I swear I did this.

Cool Thanks.

Looks like I have to break the username and password just to get into the system.
Logged

Security+, Network+, C|EH, CHFI, CPT
Joshsevo
Sr. Member
****
Offline Offline

Posts: 278


View Profile
« Reply #39 on: October 01, 2011, 01:44:36 AM »

Ok, been working on this for like 4 hrs now.  I have been trying a bunch of passwords to try and get into the first system.

How am I supposed to attack this machine with a brute force if the computer is VM.  Can I attack it from my desktop?  I guess I don't understand how I am supposed to attack VMware if I can't be physically be in the VM yet?

My goal right now is to get the username/password to get into the CPT VM1.
Logged

Security+, Network+, C|EH, CHFI, CPT
hayabusa
Hero Member
*****
Offline Offline

Posts: 1630



View Profile
« Reply #40 on: October 01, 2011, 06:36:40 AM »

Hint - did you clearly read those instructions you posted?  They almost 'give' you the key to getting your first root password.  (Man-in-the-middle)

You'll need to work for this, and in the interest of "fair play," we can't help you much more, if this is actually your exam.  But I will say, they pretty much handed you the keys to the kingdom in those directions that you posted...
Logged

~ hayabusa ~ 

"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'


OSCE, OSCP , GPEN, C|EH
Joshsevo
Sr. Member
****
Offline Offline

Posts: 278


View Profile
« Reply #41 on: October 01, 2011, 11:35:23 AM »

Ya I got the username/password shortly after posting this.  That is common with me as I "jump the gun" on things sometimes.

Logged

Security+, Network+, C|EH, CHFI, CPT
hayabusa
Hero Member
*****
Offline Offline

Posts: 1630



View Profile
« Reply #42 on: October 01, 2011, 12:26:02 PM »

Glad to see you're progressing.  Good job.
Logged

~ hayabusa ~ 

"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'


OSCE, OSCP , GPEN, C|EH
Joshsevo
Sr. Member
****
Offline Offline

Posts: 278


View Profile
« Reply #43 on: October 01, 2011, 03:47:29 PM »

So let me ask this.  There is no real way to get the files that Infosec gave me on a 2nd CD that has most of the tools I would use to do this onto the VM machine, correct?  I am stuck here now.

Trying to download things like Jon the Ripper and it saves it at the Home but since i have virtually no experience with Linux I am up the river without a paddle.

So again my question is can I get files from my CD drive ontp the VM.  As of right now I don't think so.
Logged

Security+, Network+, C|EH, CHFI, CPT
hayabusa
Hero Member
*****
Offline Offline

Posts: 1630



View Profile
« Reply #44 on: October 01, 2011, 03:51:23 PM »

VMWare should allow you to mount your physical cd drive into the guest.  My bet is that you need to do that.  I don't have it in front of me to tell you the menu, but it's like Devices - CD/DVD drive - then choose, when you're in a particular VM guest.
Logged

~ hayabusa ~ 

"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'


OSCE, OSCP , GPEN, C|EH
Pages: 1 2 [3] 4 5 ... 9   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.073 seconds with 23 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Free Business and Tech Magazines and eBooks

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.