Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 34 guests and 1 member online
 
Advertisement

You are here: Home arrow Ethical Hacking Discussions and Related Certificationsarrow Network Pen Testingarrow CPT Practical - Feedback Please...
EH-Net
May 23, 2013, 05:37:44 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: 1 ... 5 6 [7] 8 9   Go Down
  Print  
Author Topic: CPT Practical - Feedback Please...  (Read 63504 times)
0 Members and 1 Guest are viewing this topic.
Joshsevo
Sr. Member
****
Offline Offline

Posts: 278


View Profile
« Reply #90 on: October 31, 2011, 08:58:09 AM »

Well using hydra the first try at breaking the password was unsuccesful.  It made it all the way through without finding it.  Either I need a larger wordlist or a new way to figure it out.
Logged

Security+, Network+, C|EH, CHFI, CPT
hayabusa
Hero Member
*****
Offline Offline

Posts: 1633



View Profile
« Reply #91 on: October 31, 2011, 09:47:49 AM »

I've never even seen/ taken the exam for CPT, so not breaking any rules by offering this advice (might be useful, might not, so take it at face value.)

Look for services, website scripts, or bash scripts, that might connect from the server you already got root for, to the other box.  Perhaps one or more of those will contain a noteworthy password.
Logged

~ hayabusa ~ 

"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'


OSCE, OSCP , GPEN, C|EH
Joshsevo
Sr. Member
****
Offline Offline

Posts: 278


View Profile
« Reply #92 on: October 31, 2011, 12:58:42 PM »

Any idea what tools I would use to search for that stuff?
Logged

Security+, Network+, C|EH, CHFI, CPT
Joshsevo
Sr. Member
****
Offline Offline

Posts: 278


View Profile
« Reply #93 on: October 31, 2011, 01:12:37 PM »

Called ICARB and asked about an extension on this as I technically have 2 days to get this last part and to look over my report and make any changes and get it turned in.

Thanfully they granted me an extension.  Whew....
Logged

Security+, Network+, C|EH, CHFI, CPT
hayabusa
Hero Member
*****
Offline Offline

Posts: 1633



View Profile
« Reply #94 on: October 31, 2011, 02:56:34 PM »

Nope, only because I've never seen the boxes or exam, so wouldn't have a clue.   If the IP's were dynamic, it's unlikely that this will work, or be the case.  If they are static, then, IMHO, the probability goes up.

Just depends on what's there.  Might be as easy as grep'ing through files, recursively, on server1, to try to spot server2's IP address...

Perhaps revisit the instructions, yet again, as SephStorm mentioned.  Maybe you're overlooking something painfully obvious (happens to the best of us, so don't think I'm picking on you, or giving you a hard time)
Logged

~ hayabusa ~ 

"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'


OSCE, OSCP , GPEN, C|EH
Joshsevo
Sr. Member
****
Offline Offline

Posts: 278


View Profile
« Reply #95 on: October 31, 2011, 04:12:04 PM »

No you guys have bene great and I try to not ask specifics about the exam but rather the tools.  Again no experience and I am at the limits of my knowledge but with Seph guiding me to read stuff over again, the youtube videos etc it's helped a lot.

So I am learning so much and I am really excited. So excited and want to get back at it that my mind has not been where it should be.  I've been thinking about what I need to do with JTR and hydra to get it to work and different combinations of the syntaxs that will get it to work faster.

Most of the tools I have are CMD and that's where I have a hard time understanding how the order of the CMD's.


In regards to the instructions, it says to do a MiTM attack and I did that but it didn't work SO maybe i am doing it wrong.  But they also said that can be used to only get one of the Root passwords, not both.  So I already got one and with some more hard work and determination I will get it.  I just want it now.  But making me earn it and work for it will make it that much sweeter once I crack the root psswd.
Logged

Security+, Network+, C|EH, CHFI, CPT
r2s
Newbie
*
Offline Offline

Posts: 49


The Artisan


View Profile
« Reply #96 on: October 31, 2011, 04:31:15 PM »

No you guys have bene great and I try to not ask specifics about the exam but rather the tools.  Again no experience and I am at the limits of my knowledge but with Seph guiding me to read stuff over again, the youtube videos etc it's helped a lot.

So I am learning so much and I am really excited. So excited and want to get back at it that my mind has not been where it should be.  I've been thinking about what I need to do with JTR and hydra to get it to work and different combinations of the syntaxs that will get it to work faster.

Most of the tools I have are CMD and that's where I have a hard time understanding how the order of the CMD's.


In regards to the instructions, it says to do a MiTM attack and I did that but it didn't work SO maybe i am doing it wrong.  But they also said that can be used to only get one of the Root passwords, not both.  So I already got one and with some more hard work and determination I will get it.  I just want it now.  But making me earn it and work for it will make it that much sweeter once I crack the root psswd.

Sorry I'm late in responding post my initial guidance (been a crazy week). Hayabusa and Sephstorm definitely make a strong point. A major key to passing this exam is to think simple and to just stick to what is right in front of you. From personal experience, I can say hitting the sticking points and being forced to wrack your brain will prove extremely beneficial in your long term progression through infosec.
Logged

In progress: OSCP & GXPN (June)
"Silence enables the sound to be" - Eckhart Toll
SephStorm
Hero Member
*****
Offline Offline

Posts: 530


View Profile WWW
« Reply #97 on: October 31, 2011, 07:56:58 PM »

I would remove the specifics above about the MITM attack, to keep from spoiling any1's fun.

if I am correct, you already got the password to the VM you were "given". The other one will require determination, and/or the right wordlist. one tool I found helpful was a relatively unknown one to me called hashcat.
Logged

UNIX
Hero Member
*****
Offline Offline

Posts: 1235


View Profile
« Reply #98 on: November 03, 2011, 02:14:22 AM »

Joshsevo, you really shouldn't post and publish such details about a certification exam.
Logged
SephStorm
Hero Member
*****
Offline Offline

Posts: 530


View Profile WWW
« Reply #99 on: November 04, 2011, 07:33:56 PM »

I understand the compulsion, but the above poster is correct. If you are having difficulty (I did too) Then I suggest reviewing everything you know (and dont know) about cracking passwords for that OS...
Logged

Joshsevo
Sr. Member
****
Offline Offline

Posts: 278


View Profile
« Reply #100 on: November 04, 2011, 09:45:25 PM »

As stated before I am not here to cheat but to pass and have my peers know that I did it on my own.

The only problem I have is the limited experience doing this as well as other tools restricts me.  So I get happy when I figure certain things out and get overzealous at times.  Sad for a 32 yr old. LOL.

Anyways see the next post.
Logged

Security+, Network+, C|EH, CHFI, CPT
Joshsevo
Sr. Member
****
Offline Offline

Posts: 278


View Profile
« Reply #101 on: November 04, 2011, 09:48:51 PM »

Question:  If I can change the root password does is that equal to gaining root access and then having full control of the system? 

Instructions don't say that I can't nor say I can.

Give me your opinions.
Logged

Security+, Network+, C|EH, CHFI, CPT
hayabusa
Hero Member
*****
Offline Offline

Posts: 1633



View Profile
« Reply #102 on: November 04, 2011, 10:02:16 PM »

I'd say if you can change root password, and PROVE you did it, then you've proven you root'ed the box (because if you change it, you can login as it.)  But I don't know their rules, so I have to yield to SephStorm, and those who have.
Logged

~ hayabusa ~ 

"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'


OSCE, OSCP , GPEN, C|EH
Joshsevo
Sr. Member
****
Offline Offline

Posts: 278


View Profile
« Reply #103 on: November 04, 2011, 10:37:09 PM »

That's my assumption.  If I can get the key to your front door and then change the locks, your locked out while I pillage your fridge.

Let's wait to see what others say and then I will try it from there.

Logged

Security+, Network+, C|EH, CHFI, CPT
r2s
Newbie
*
Offline Offline

Posts: 49


The Artisan


View Profile
« Reply #104 on: November 07, 2011, 09:05:48 AM »

Question:  If I can change the root password does is that equal to gaining root access and then having full control of the system? 

Instructions don't say that I can't nor say I can.

Give me your opinions.

I'm back! Getting "root" is very subjective but I would not change the pre-set root password as I believe cracking the password may be part of the objective set (<- does not violate NDA as per the instructions).

I can't go any further than that advice wise as any further information could eventually start to steer the direction of your executive post engagement report and potentially walk the NDA line (I have huge respect for IACRB).

Dig deep and you'll get this.

Logged

In progress: OSCP & GXPN (June)
"Silence enables the sound to be" - Eckhart Toll
Pages: 1 ... 5 6 [7] 8 9   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.068 seconds with 23 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.