Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 37 guests online
 
Free Business and Tech Magazines and eBooks

You are here: Home arrow Ethical Hacking Discussions and Related Certificationsarrow Network Pen Testingarrow CPT Practical - Feedback Please...
EH-Net
May 19, 2013, 12:14:33 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: 1 2 3 [4] 5 6 ... 9   Go Down
  Print  
Author Topic: CPT Practical - Feedback Please...  (Read 63190 times)
0 Members and 1 Guest are viewing this topic.
Joshsevo
Sr. Member
****
Offline Offline

Posts: 278


View Profile
« Reply #45 on: October 04, 2011, 08:49:43 PM »

I kinda got lazy on this the last few days.  I suppose I was happy I got the password and then didn't do a thing to it since.

Although the whole VM not being able to download all my tools is upsetting me.
Logged

Security+, Network+, C|EH, CHFI, CPT
Joshsevo
Sr. Member
****
Offline Offline

Posts: 278


View Profile
« Reply #46 on: October 04, 2011, 09:51:56 PM »

I am the shit..... I think I got it now.  Now I need to see which folders can load up...so far none...LOL
Logged

Security+, Network+, C|EH, CHFI, CPT
SephStorm
Hero Member
*****
Offline Offline

Posts: 530


View Profile WWW
« Reply #47 on: October 05, 2011, 07:50:41 AM »

I think you are going about this the wrong way. i'll try to help without spoiling it. Your host machine is your attacking pc. Your tools should be accessible on that machine. You need to review the hacker methodology to see what your goals are. Gain information, exploit that information to gain access, elevate privileges, get your token and ensure you have a way back in if the "company" discovered the first vulnerability. (The last part isnt required, but I thought it pertinent.)
Logged

Joshsevo
Sr. Member
****
Offline Offline

Posts: 278


View Profile
« Reply #48 on: October 10, 2011, 09:17:08 AM »

I believe that you are correct.  Shows ya how new I am to the VM stuff.  This is like my 5th time using it and the most in-depth.

Slowly learning.
Logged

Security+, Network+, C|EH, CHFI, CPT
hayabusa
Hero Member
*****
Offline Offline

Posts: 1630



View Profile
« Reply #49 on: October 10, 2011, 09:25:19 AM »

Security is ALWAYS a learning process.  Just keep moving forward!
Logged

~ hayabusa ~ 

"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'


OSCE, OSCP , GPEN, C|EH
r2s
Newbie
*
Offline Offline

Posts: 49


The Artisan


View Profile
« Reply #50 on: October 12, 2011, 01:19:59 AM »

Security is ALWAYS a learning process.  Just keep moving forward!

+1.

In terms of the practical, make sure that you are documenting the steps you took to complete each phase of the pentest and the details involved. The final engagement report is a vital role in whether or not you pass in the end regardless of whether you get roots or not (actually rephrase; I don't think you can pass with no root pws).

My advice would be to take snap shots, title them according to what you were doing at the time, and maybe make a little notepad document correlating the events with the snapshots.
Logged

In progress: OSCP & GXPN (June)
"Silence enables the sound to be" - Eckhart Toll
Joshsevo
Sr. Member
****
Offline Offline

Posts: 278


View Profile
« Reply #51 on: October 14, 2011, 12:41:12 PM »

Oh I am.  The teacher mentioned how important this was as it could get yourself into a lot of trouble if you don't and can save you if you can provide the documentation.

I have to get hot on this, this weekend. 
Logged

Security+, Network+, C|EH, CHFI, CPT
Joshsevo
Sr. Member
****
Offline Offline

Posts: 278


View Profile
« Reply #52 on: October 15, 2011, 12:39:31 PM »

So I am trying to get hot on this and everything is up and running except I have no idea how to connect to the VM.  I've tried playing with some settings like "host only" "bridged" "NAT" none of them seem to be working.

I've gone onto the VM and went into the console and tried typing "ifconfig" to see if that works to get the IP so I can then Ping it from the host.  Nothing...any suggestions?
Logged

Security+, Network+, C|EH, CHFI, CPT
hayabusa
Hero Member
*****
Offline Offline

Posts: 1630



View Profile
« Reply #53 on: October 15, 2011, 02:18:47 PM »

A couple of thoughts.

Assuming they didn't hardcode the IP, then it should get a DHCP-assigned address from VMWare.  Look at VMWare's config, see what subnet those adapters (host only, NAT, etc) are assigned to, then scan the subnet assigned to the adapter you've set the VM to use, from your host, to see what addresses are there / in use.  (You SHOULD only see your machine and the Guest...)

You might also do an 'ifconfig eth0' up, or an 'ifup eth0', depending on the lunix variant of the guest, in the event the guest's NIC isn't even alive, yet.
Logged

~ hayabusa ~ 

"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'


OSCE, OSCP , GPEN, C|EH
SephStorm
Hero Member
*****
Offline Offline

Posts: 530


View Profile WWW
« Reply #54 on: October 16, 2011, 10:19:07 PM »

Agreed. If you are using the suggested setup, with Windows as your host machine, and no (unnecessary)extra devices, I can tell you that you should set all the machines as Bridged. Scan the network and you will find the VM's with ease. To be safe, I would make sure your internal network is setup under a traditional subnet (i.e 192.168.1.0). If this doesnt work tell us your exact setup.
Logged

Joshsevo
Sr. Member
****
Offline Offline

Posts: 278


View Profile
« Reply #55 on: October 17, 2011, 09:10:17 AM »

I will double check what I left the settings on.  Since the begining I had it on Bridged as that is what it was defaulted too but then after doing some research I fooled around with it.

Using the terminal on the Linux box I can only run a few commands.  Most of the commands are not working so maybe they have it locked down also.  Life would be easier if I could just go in a do a "ifconfig" get the IP that way and then move from there.  But such is life.
Logged

Security+, Network+, C|EH, CHFI, CPT
SephStorm
Hero Member
*****
Offline Offline

Posts: 530


View Profile WWW
« Reply #56 on: October 17, 2011, 10:03:25 AM »

Wait, are you logged into one of the practical VM's? i.e one of the Red Hat boxes or are you talking about the attack VM?
Logged

Joshsevo
Sr. Member
****
Offline Offline

Posts: 278


View Profile
« Reply #57 on: October 17, 2011, 01:13:06 PM »

Um I tried both.  I was on the host which is my despktop and then tried to get the IP's from there doing certain CMD's IPconfig.  Nothing showed. 

Then I logged onto CPTVM1 and tried to get the IP's off it (ifconfig). Again getting nothing.

I have not done anything yet to the second one CPTVM2, should I?
Logged

Security+, Network+, C|EH, CHFI, CPT
SephStorm
Hero Member
*****
Offline Offline

Posts: 530


View Profile WWW
« Reply #58 on: October 17, 2011, 04:31:09 PM »

ok, you cannot get an IP from your actual PC?
Logged

Joshsevo
Sr. Member
****
Offline Offline

Posts: 278


View Profile
« Reply #59 on: October 17, 2011, 04:48:02 PM »

LOL ok, jeez I feel dumb. LOL so on the CPTVM1 how do I go about getting the IP ranges for CPTVM 1 & 2.
Logged

Security+, Network+, C|EH, CHFI, CPT
Pages: 1 2 3 [4] 5 6 ... 9   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.072 seconds with 23 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Free Business and Tech Magazines and eBooks

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.