Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 37 guests online
Free Business and Tech Magazines and eBooks
You are here:
Home
Ethical Hacking Discussions and Related Certifications
Network Pen Testing
CPT Practical - Feedback Please...
EH-Net
May 19, 2013, 12:14:33 AM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Ethical Hacking Discussions and Related Certifications
>
Network Pen Testing
(Moderator:
don
) >
CPT Practical - Feedback Please...
Pages:
1
2
3
[
4
]
5
6
...
9
Go Down
« previous
next »
Print
Author
Topic: CPT Practical - Feedback Please... (Read 63190 times)
0 Members and 1 Guest are viewing this topic.
Joshsevo
Sr. Member
Offline
Posts: 278
Re: CPT Practical - Feedback Please...
«
Reply #45 on:
October 04, 2011, 08:49:43 PM »
I kinda got lazy on this the last few days. I suppose I was happy I got the password and then didn't do a thing to it since.
Although the whole VM not being able to download all my tools is upsetting me.
Logged
Security+, Network+, C|EH, CHFI, CPT
Joshsevo
Sr. Member
Offline
Posts: 278
Re: CPT Practical - Feedback Please...
«
Reply #46 on:
October 04, 2011, 09:51:56 PM »
I am the shit..... I think I got it now. Now I need to see which folders can load up...so far none...LOL
Logged
Security+, Network+, C|EH, CHFI, CPT
SephStorm
Hero Member
Offline
Posts: 530
Re: CPT Practical - Feedback Please...
«
Reply #47 on:
October 05, 2011, 07:50:41 AM »
I think you are going about this the wrong way. i'll try to help without spoiling it. Your host machine is your attacking pc. Your tools should be accessible on that machine. You need to review the hacker methodology to see what your goals are. Gain information, exploit that information to gain access, elevate privileges, get your token and ensure you have a way back in if the "company" discovered the first vulnerability. (The last part isnt required, but I thought it pertinent.)
Logged
Support my hactivities.
http://www.cafepress.com/TRUEHacker
Joshsevo
Sr. Member
Offline
Posts: 278
Re: CPT Practical - Feedback Please...
«
Reply #48 on:
October 10, 2011, 09:17:08 AM »
I believe that you are correct. Shows ya how new I am to the VM stuff. This is like my 5th time using it and the most in-depth.
Slowly learning.
Logged
Security+, Network+, C|EH, CHFI, CPT
hayabusa
Hero Member
Offline
Posts: 1630
Re: CPT Practical - Feedback Please...
«
Reply #49 on:
October 10, 2011, 09:25:19 AM »
Security is ALWAYS a learning process. Just keep moving forward!
Logged
~ hayabusa ~
"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'
OSCE, OSCP , GPEN, C|EH
r2s
Newbie
Offline
Posts: 49
The Artisan
Re: CPT Practical - Feedback Please...
«
Reply #50 on:
October 12, 2011, 01:19:59 AM »
Quote from: hayabusa on October 10, 2011, 09:25:19 AM
Security is ALWAYS a learning process. Just keep moving forward!
+1.
In terms of the practical, make sure that you are documenting the steps you took to complete each phase of the pentest and the details involved. The final engagement report is a vital role in whether or not you pass in the end regardless of whether you get roots or not (actually rephrase; I don't think you can pass with no root pws).
My advice would be to take snap shots, title them according to what you were doing at the time, and maybe make a little notepad document correlating the events with the snapshots.
Logged
In progress:
OSCP & GXPN (June)
"Silence enables the sound to be"
- Eckhart Toll
Joshsevo
Sr. Member
Offline
Posts: 278
Re: CPT Practical - Feedback Please...
«
Reply #51 on:
October 14, 2011, 12:41:12 PM »
Oh I am. The teacher mentioned how important this was as it could get yourself into a lot of trouble if you don't and can save you if you can provide the documentation.
I have to get hot on this, this weekend.
Logged
Security+, Network+, C|EH, CHFI, CPT
Joshsevo
Sr. Member
Offline
Posts: 278
Re: CPT Practical - Feedback Please...
«
Reply #52 on:
October 15, 2011, 12:39:31 PM »
So I am trying to get hot on this and everything is up and running except I have no idea how to connect to the VM. I've tried playing with some settings like "host only" "bridged" "NAT" none of them seem to be working.
I've gone onto the VM and went into the console and tried typing "ifconfig" to see if that works to get the IP so I can then Ping it from the host. Nothing...any suggestions?
Logged
Security+, Network+, C|EH, CHFI, CPT
hayabusa
Hero Member
Offline
Posts: 1630
Re: CPT Practical - Feedback Please...
«
Reply #53 on:
October 15, 2011, 02:18:47 PM »
A couple of thoughts.
Assuming they didn't hardcode the IP, then it should get a DHCP-assigned address from VMWare. Look at VMWare's config, see what subnet those adapters (host only, NAT, etc) are assigned to, then scan the subnet assigned to the adapter you've set the VM to use, from your host, to see what addresses are there / in use. (You SHOULD only see your machine and the Guest...)
You might also do an 'ifconfig eth0' up, or an 'ifup eth0', depending on the lunix variant of the guest, in the event the guest's NIC isn't even alive, yet.
Logged
~ hayabusa ~
"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'
OSCE, OSCP , GPEN, C|EH
SephStorm
Hero Member
Offline
Posts: 530
Re: CPT Practical - Feedback Please...
«
Reply #54 on:
October 16, 2011, 10:19:07 PM »
Agreed. If you are using the suggested setup, with Windows as your host machine, and no (unnecessary)extra devices, I can tell you that you should set all the machines as Bridged. Scan the network and you will find the VM's with ease. To be safe, I would make sure your internal network is setup under a traditional subnet (i.e 192.168.1.0). If this doesnt work tell us your exact setup.
Logged
Support my hactivities.
http://www.cafepress.com/TRUEHacker
Joshsevo
Sr. Member
Offline
Posts: 278
Re: CPT Practical - Feedback Please...
«
Reply #55 on:
October 17, 2011, 09:10:17 AM »
I will double check what I left the settings on. Since the begining I had it on Bridged as that is what it was defaulted too but then after doing some research I fooled around with it.
Using the terminal on the Linux box I can only run a few commands. Most of the commands are not working so maybe they have it locked down also. Life would be easier if I could just go in a do a "ifconfig" get the IP that way and then move from there. But such is life.
Logged
Security+, Network+, C|EH, CHFI, CPT
SephStorm
Hero Member
Offline
Posts: 530
Re: CPT Practical - Feedback Please...
«
Reply #56 on:
October 17, 2011, 10:03:25 AM »
Wait, are you logged into one of the practical VM's? i.e one of the Red Hat boxes or are you talking about the attack VM?
Logged
Support my hactivities.
http://www.cafepress.com/TRUEHacker
Joshsevo
Sr. Member
Offline
Posts: 278
Re: CPT Practical - Feedback Please...
«
Reply #57 on:
October 17, 2011, 01:13:06 PM »
Um I tried both. I was on the host which is my despktop and then tried to get the IP's from there doing certain CMD's IPconfig. Nothing showed.
Then I logged onto CPTVM1 and tried to get the IP's off it (ifconfig). Again getting nothing.
I have not done anything yet to the second one CPTVM2, should I?
Logged
Security+, Network+, C|EH, CHFI, CPT
SephStorm
Hero Member
Offline
Posts: 530
Re: CPT Practical - Feedback Please...
«
Reply #58 on:
October 17, 2011, 04:31:09 PM »
ok, you cannot get an IP from your actual PC?
Logged
Support my hactivities.
http://www.cafepress.com/TRUEHacker
Joshsevo
Sr. Member
Offline
Posts: 278
Re: CPT Practical - Feedback Please...
«
Reply #59 on:
October 17, 2011, 04:48:02 PM »
LOL ok, jeez I feel dumb. LOL so on the CPTVM1 how do I go about getting the IP ranges for CPTVM 1 & 2.
Logged
Security+, Network+, C|EH, CHFI, CPT
Pages:
1
2
3
[
4
]
5
6
...
9
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
General Certification
: CPT Practical Submission
(0) by
z28power4u
OSCP - Offensive Security Certified Professional
: Class Scheduled 6/8 - Linux n00b
(5) by
MrTuxracer
Career Central
: Starter cert?
(0) by
Alert
Web Applications
: Nessus and Nikto
(4) by
Seen
Tutorials
: Need guidance
(7) by
impelse
Malware
: EICAR?
(2) by
SephStorm
Network Pen Testing
: Cracking salted MD5 hash
(4) by
n37sh@rk
CEH - Certified Ethical Hacker
: Passed my C|EH
(3) by
n37sh@rk
Mass Media
: EC-council hacked, irony at his best?
(0) by
j0rDy
Web Applications
: SQL Injection into an INSERT statement.
(6) by
eyenit0
Network Pen Testing
: Solution for sipXtapi INVITE Message CSeq Field Header Remote Overflow
(1) by
m0wgli
Web Applications
: dns
(2) by
H1t M0nk3y
Other
: BSides Boston
(0) by
3xban
Career Central
: InfoSec in Central, FL
(2) by
tturner
Web Applications
: Web vulnerability scanner
(4) by
H1t M0nk3y
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
Free Business and Tech Magazines and eBooks
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.