Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 48 guests online
You are here:
Home
Ethical Hacking Discussions and Related Certifications
Network Pen Testing
CPT Practical - Feedback Please...
EH-Net
May 25, 2013, 04:23:35 AM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Ethical Hacking Discussions and Related Certifications
>
Network Pen Testing
(Moderator:
don
) >
CPT Practical - Feedback Please...
Pages:
1
2
[
3
]
4
5
...
9
Go Down
« previous
next »
Print
Author
Topic: CPT Practical - Feedback Please... (Read 63578 times)
0 Members and 1 Guest are viewing this topic.
Joshsevo
Sr. Member
Offline
Posts: 278
Re: CPT Practical - Feedback Please...
«
Reply #30 on:
September 30, 2011, 01:58:46 PM »
I need some help on this.
I am a newbie as some of you know. I passed the first part of the CPT test and now I am about to start the practical and am stuck.
Again I am a newbie and only played with VM player twice. I have the disc the techer form the InfoSec class gave us.
It loads fine. I see instructions and two other files named "target1 & Target2" or something like that. I'm at work and not sitting in front of the computer now so going off memeory here.
But I load them up and they start to load and it stays on a black screen and says " NO OS detected". Assuming I am understanding this coreectly I have to install my own OS into the VM that I got from class.
Any help? I have tried calling the teacher already to help me start and also tried calling Infosec.
Logged
Security+, Network+, C|EH, CHFI, CPT
lorddicranius
Sr. Member
Offline
Posts: 447
Re: CPT Practical - Feedback Please...
«
Reply #31 on:
September 30, 2011, 02:13:23 PM »
I haven't used VMWare Player in awhile, but when setting up a new VM in VirtualBox you have to make sure you load the CD/ISO in the virtual CD-ROM, then boot up the VM. It's like you're setting up the hardware (creating the VM to show up in your list), then installing the OS...if that makes sense.
Logged
GSEC, eCPPT, Sec+
Joshsevo
Sr. Member
Offline
Posts: 278
Re: CPT Practical - Feedback Please...
«
Reply #32 on:
September 30, 2011, 02:41:33 PM »
I think I understand. I will give that a shot when I get home.
Logged
Security+, Network+, C|EH, CHFI, CPT
hayabusa
Hero Member
Offline
Posts: 1633
Re: CPT Practical - Feedback Please...
«
Reply #33 on:
September 30, 2011, 05:57:01 PM »
Most class VM's SHOULD be good to go, already. If they gave you the vmdk files, and they're fairly sizeable, you shouldn't have to install an OS. You should just go to the file menu in VMWare, do an Open, and browse to the proper vmx config files, for each. The only other thing you might have to do (maybe) is edit the vmx to make sure paths are set to your local machine file paths.
Oh, and one more thing... If you copied the files from CD or DVD, make sure to take off the Read-Only flag on them... That might be contributing to your grief.
(edit - you can't run them from the CD /DVD unless they're just 'live dvd' images)
«
Last Edit: September 30, 2011, 05:58:34 PM by hayabusa
»
Logged
~ hayabusa ~
"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'
OSCE, OSCP , GPEN, C|EH
Joshsevo
Sr. Member
Offline
Posts: 278
Re: CPT Practical - Feedback Please...
«
Reply #34 on:
September 30, 2011, 08:47:20 PM »
Ok SO I'm home now and I here is what I have
CD from InfoSec
Instructions
When I click on Start, Computer and then go to the CD that is in my E Drive I have a folder named CPT.
Double click CPT folder
Opens to shows 6 files:
._CPT Instructions.htm.......can't open this one
CPT Instructions.htm...this opens to the instructions on the test
CPT.VM1.rar
CPT.VM2.rar
VM-player 3.1.2-301548.exe
wrar.393.exe
Double click the file VM.exe and it installs VW player
The CPT.VM1.rar files show them being as Itunes opened files. Meaning there is an iTunes logo on the file because I probably have the .rar files being auto opened by this. Don't think this is a big deal though as I can just click "open with VM"...right?
Logged
Security+, Network+, C|EH, CHFI, CPT
Joshsevo
Sr. Member
Offline
Posts: 278
Re: CPT Practical - Feedback Please...
«
Reply #35 on:
September 30, 2011, 08:59:36 PM »
Here are the instructions:
On the DVD provided to you, will be a folder named CPT Practical. In this folder you’ll find a copy of winrar, a copy of vmware player and two virtual machines. You’ll need to uncompress the .rar files using winrar, then start the virtual machines included in these two .rar files
(CPT VM1.rar and CPT VM2.rar). Once these are started you’ll need to perform a penetration test against these two virtual machines.
No IP addresses will be given. You must first discover the ip’s of the two virtual machines first. Once you’ve discovered them you will need to do recon on both machines. You’ll need to configure your network or computer appropriately to operate on the same network or in the same network range of the two VM’s. You are allowed to use the Linux Attack VM you were given in the Infosec Institute Ethical Hacking class. Discover if there’s any services running on them that might be vulnerable. You’ll need to document your network recon efforts.
It might be helpful to perform man in the middle per your instructions in class, against the two virtual mchines. From this MiTM you should get at least one of the two root passwords!
You must launch a network based penetration attack against the two machines and discover potential credentials. The only hint you have in that regard is the paragraph above. The end result should be that you obtain the root password to one of the virtual machines.
Once you’ve gained root on one machine, you’ll need to crack some other user accounts on that compromised machine. Remember credentials and accounts MIGHT be used on both machines, so once you’ve cracked the accounts on the first machine, consider that possibility.
Once you gain some level of access on the second machine (it most likely won’t be root privileges), you’ll need to perform a local exploit or as it’s also called a privilege escalation exploit to gather the shadow file on the second machine. Once you have the shadow file, crack away until you have the second root password.
Be advised you won’t be considered for being awarded the IACRB Certified Penetration Tester certification if both root passwords are not obtained and/or you don’t document your penetration test.
Good Luck!
Logged
Security+, Network+, C|EH, CHFI, CPT
hayabusa
Hero Member
Offline
Posts: 1633
Re: CPT Practical - Feedback Please...
«
Reply #36 on:
September 30, 2011, 09:32:20 PM »
So you need to install winrar (wrar.393.exe,) use it to extract the vm's from the two RAR files, install VMPlayer, then point to the extracted VM's and go.
Logged
~ hayabusa ~
"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'
OSCE, OSCP , GPEN, C|EH
hayabusa
Hero Member
Offline
Posts: 1633
Re: CPT Practical - Feedback Please...
«
Reply #37 on:
September 30, 2011, 09:33:42 PM »
Oh... And Good Luck! :-D
Logged
~ hayabusa ~
"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'
OSCE, OSCP , GPEN, C|EH
Joshsevo
Sr. Member
Offline
Posts: 278
Re: CPT Practical - Feedback Please...
«
Reply #38 on:
September 30, 2011, 10:40:46 PM »
HA that was it. It;s working now.
LOL I swear I did this.
Cool Thanks.
Looks like I have to break the username and password just to get into the system.
Logged
Security+, Network+, C|EH, CHFI, CPT
Joshsevo
Sr. Member
Offline
Posts: 278
Re: CPT Practical - Feedback Please...
«
Reply #39 on:
October 01, 2011, 01:44:36 AM »
Ok, been working on this for like 4 hrs now. I have been trying a bunch of passwords to try and get into the first system.
How am I supposed to attack this machine with a brute force if the computer is VM. Can I attack it from my desktop? I guess I don't understand how I am supposed to attack VMware if I can't be physically be in the VM yet?
My goal right now is to get the username/password to get into the CPT VM1.
Logged
Security+, Network+, C|EH, CHFI, CPT
hayabusa
Hero Member
Offline
Posts: 1633
Re: CPT Practical - Feedback Please...
«
Reply #40 on:
October 01, 2011, 06:36:40 AM »
Hint - did you clearly read those instructions you posted? They almost 'give' you the key to getting your first root password. (Man-in-the-middle)
You'll need to work for this, and in the interest of "fair play," we can't help you much more, if this is actually your exam. But I will say, they pretty much handed you the keys to the kingdom in those directions that you posted...
Logged
~ hayabusa ~
"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'
OSCE, OSCP , GPEN, C|EH
Joshsevo
Sr. Member
Offline
Posts: 278
Re: CPT Practical - Feedback Please...
«
Reply #41 on:
October 01, 2011, 11:35:23 AM »
Ya I got the username/password shortly after posting this. That is common with me as I "jump the gun" on things sometimes.
Logged
Security+, Network+, C|EH, CHFI, CPT
hayabusa
Hero Member
Offline
Posts: 1633
Re: CPT Practical - Feedback Please...
«
Reply #42 on:
October 01, 2011, 12:26:02 PM »
Glad to see you're progressing. Good job.
Logged
~ hayabusa ~
"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'
OSCE, OSCP , GPEN, C|EH
Joshsevo
Sr. Member
Offline
Posts: 278
Re: CPT Practical - Feedback Please...
«
Reply #43 on:
October 01, 2011, 03:47:29 PM »
So let me ask this. There is no real way to get the files that Infosec gave me on a 2nd CD that has most of the tools I would use to do this onto the VM machine, correct? I am stuck here now.
Trying to download things like Jon the Ripper and it saves it at the Home but since i have virtually no experience with Linux I am up the river without a paddle.
So again my question is can I get files from my CD drive ontp the VM. As of right now I don't think so.
Logged
Security+, Network+, C|EH, CHFI, CPT
hayabusa
Hero Member
Offline
Posts: 1633
Re: CPT Practical - Feedback Please...
«
Reply #44 on:
October 01, 2011, 03:51:23 PM »
VMWare should allow you to mount your physical cd drive into the guest. My bet is that you need to do that. I don't have it in front of me to tell you the menu, but it's like Devices - CD/DVD drive - then choose, when you're in a particular VM guest.
Logged
~ hayabusa ~
"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'
OSCE, OSCP , GPEN, C|EH
Pages:
1
2
[
3
]
4
5
...
9
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
News Items and General Discussion About EH-Net
: Change is Coming to EH-Net!!
(30) by
don
Tools
: Symbolic Exploit Assistant project is looking for collaborators
(0) by
galapag0
Greetings
: Hi from the UK
(5) by
prats84
GCIH - GIAC Certified Incident Handler
: Passed my GCIH
(9) by
prats84
Network Pen Testing
: Want a challenge? Want a GXPN practice exam?
(0) by
ajohnson
GCIH - GIAC Certified Incident Handler
: GCIH Free Practice test attempt
(1) by
prats84
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.