Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 31 guests online
Free Business and Tech Magazines and eBooks
You are here:
Home
Ethical Hacking Discussions and Related Certifications
Network Pen Testing
CPT Practical - Feedback Please...
EH-Net
May 23, 2013, 04:25:25 AM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Ethical Hacking Discussions and Related Certifications
>
Network Pen Testing
(Moderator:
don
) >
CPT Practical - Feedback Please...
Pages:
1
...
5
6
[
7
]
8
9
Go Down
« previous
next »
Print
Author
Topic: CPT Practical - Feedback Please... (Read 63486 times)
0 Members and 1 Guest are viewing this topic.
Joshsevo
Sr. Member
Offline
Posts: 278
Re: CPT Practical - Feedback Please...
«
Reply #90 on:
October 31, 2011, 08:58:09 AM »
Well using hydra the first try at breaking the password was unsuccesful. It made it all the way through without finding it. Either I need a larger wordlist or a new way to figure it out.
Logged
Security+, Network+, C|EH, CHFI, CPT
hayabusa
Hero Member
Offline
Posts: 1632
Re: CPT Practical - Feedback Please...
«
Reply #91 on:
October 31, 2011, 09:47:49 AM »
I've never even seen/ taken the exam for CPT, so not breaking any rules by offering this advice (might be useful, might not, so take it at face value.)
Look for services, website scripts, or bash scripts, that might connect from the server you already got root for, to the other box. Perhaps one or more of those will contain a noteworthy password.
Logged
~ hayabusa ~
"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'
OSCE, OSCP , GPEN, C|EH
Joshsevo
Sr. Member
Offline
Posts: 278
Re: CPT Practical - Feedback Please...
«
Reply #92 on:
October 31, 2011, 12:58:42 PM »
Any idea what tools I would use to search for that stuff?
Logged
Security+, Network+, C|EH, CHFI, CPT
Joshsevo
Sr. Member
Offline
Posts: 278
Re: CPT Practical - Feedback Please...
«
Reply #93 on:
October 31, 2011, 01:12:37 PM »
Called ICARB and asked about an extension on this as I technically have 2 days to get this last part and to look over my report and make any changes and get it turned in.
Thanfully they granted me an extension. Whew....
Logged
Security+, Network+, C|EH, CHFI, CPT
hayabusa
Hero Member
Offline
Posts: 1632
Re: CPT Practical - Feedback Please...
«
Reply #94 on:
October 31, 2011, 02:56:34 PM »
Nope, only because I've never seen the boxes or exam, so wouldn't have a clue. If the IP's were dynamic, it's unlikely that this will work, or be the case. If they are static, then, IMHO, the probability goes up.
Just depends on what's there. Might be as easy as grep'ing through files, recursively, on server1, to try to spot server2's IP address...
Perhaps revisit the instructions, yet again, as SephStorm mentioned. Maybe you're overlooking something painfully obvious (happens to the best of us, so don't think I'm picking on you, or giving you a hard time)
Logged
~ hayabusa ~
"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'
OSCE, OSCP , GPEN, C|EH
Joshsevo
Sr. Member
Offline
Posts: 278
Re: CPT Practical - Feedback Please...
«
Reply #95 on:
October 31, 2011, 04:12:04 PM »
No you guys have bene great and I try to not ask specifics about the exam but rather the tools. Again no experience and I am at the limits of my knowledge but with Seph guiding me to read stuff over again, the youtube videos etc it's helped a lot.
So I am learning so much and I am really excited. So excited and want to get back at it that my mind has not been where it should be. I've been thinking about what I need to do with JTR and hydra to get it to work and different combinations of the syntaxs that will get it to work faster.
Most of the tools I have are CMD and that's where I have a hard time understanding how the order of the CMD's.
In regards to the instructions, it says to do a MiTM attack and I did that but it didn't work SO maybe i am doing it wrong. But they also said that can be used to only get one of the Root passwords, not both. So I already got one and with some more hard work and determination I will get it. I just want it now. But making me earn it and work for it will make it that much sweeter once I crack the root psswd.
Logged
Security+, Network+, C|EH, CHFI, CPT
r2s
Newbie
Offline
Posts: 49
The Artisan
Re: CPT Practical - Feedback Please...
«
Reply #96 on:
October 31, 2011, 04:31:15 PM »
Quote from: Joshsevo on October 31, 2011, 04:12:04 PM
No you guys have bene great and I try to not ask specifics about the exam but rather the tools. Again no experience and I am at the limits of my knowledge but with Seph guiding me to read stuff over again, the youtube videos etc it's helped a lot.
So I am learning so much and I am really excited. So excited and want to get back at it that my mind has not been where it should be. I've been thinking about what I need to do with JTR and hydra to get it to work and different combinations of the syntaxs that will get it to work faster.
Most of the tools I have are CMD and that's where I have a hard time understanding how the order of the CMD's.
In regards to the instructions, it says to do a MiTM attack and I did that but it didn't work SO maybe i am doing it wrong. But they also said that can be used to only get one of the Root passwords, not both. So I already got one and with some more hard work and determination I will get it. I just want it now. But making me earn it and work for it will make it that much sweeter once I crack the root psswd.
Sorry I'm late in responding post my initial guidance (been a crazy week). Hayabusa and Sephstorm definitely make a strong point. A major key to passing this exam is to think simple and to just stick to what is right in front of you. From personal experience, I can say hitting the sticking points and being forced to wrack your brain will prove extremely beneficial in your long term progression through infosec.
Logged
In progress:
OSCP & GXPN (June)
"Silence enables the sound to be"
- Eckhart Toll
SephStorm
Hero Member
Offline
Posts: 530
Re: CPT Practical - Feedback Please...
«
Reply #97 on:
October 31, 2011, 07:56:58 PM »
I would remove the specifics above about the MITM attack, to keep from spoiling any1's fun.
if I am correct, you already got the password to the VM you were "given". The other one will require determination, and/or the right wordlist. one tool I found helpful was a relatively unknown one to me called hashcat.
Logged
Support my hactivities.
http://www.cafepress.com/TRUEHacker
UNIX
Hero Member
Offline
Posts: 1235
Re: CPT Practical - Feedback Please...
«
Reply #98 on:
November 03, 2011, 02:14:22 AM »
Joshsevo, you really shouldn't post and publish such details about a certification exam.
Logged
SephStorm
Hero Member
Offline
Posts: 530
Re: CPT Practical - Feedback Please...
«
Reply #99 on:
November 04, 2011, 07:33:56 PM »
I understand the compulsion, but the above poster is correct. If you are having difficulty (I did too) Then I suggest reviewing everything you know (and dont know) about cracking passwords for that OS...
Logged
Support my hactivities.
http://www.cafepress.com/TRUEHacker
Joshsevo
Sr. Member
Offline
Posts: 278
Re: CPT Practical - Feedback Please...
«
Reply #100 on:
November 04, 2011, 09:45:25 PM »
As stated before I am not here to cheat but to pass and have my peers know that I did it on my own.
The only problem I have is the limited experience doing this as well as other tools restricts me. So I get happy when I figure certain things out and get overzealous at times. Sad for a 32 yr old. LOL.
Anyways see the next post.
Logged
Security+, Network+, C|EH, CHFI, CPT
Joshsevo
Sr. Member
Offline
Posts: 278
Re: CPT Practical - Feedback Please...
«
Reply #101 on:
November 04, 2011, 09:48:51 PM »
Question: If I can change the root password does is that equal to gaining root access and then having full control of the system?
Instructions don't say that I can't nor say I can.
Give me your opinions.
Logged
Security+, Network+, C|EH, CHFI, CPT
hayabusa
Hero Member
Offline
Posts: 1632
Re: CPT Practical - Feedback Please...
«
Reply #102 on:
November 04, 2011, 10:02:16 PM »
I'd say if you can change root password, and PROVE you did it, then you've proven you root'ed the box (because if you change it, you can login as it.) But I don't know their rules, so I have to yield to SephStorm, and those who have.
Logged
~ hayabusa ~
"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'
OSCE, OSCP , GPEN, C|EH
Joshsevo
Sr. Member
Offline
Posts: 278
Re: CPT Practical - Feedback Please...
«
Reply #103 on:
November 04, 2011, 10:37:09 PM »
That's my assumption. If I can get the key to your front door and then change the locks, your locked out while I pillage your fridge.
Let's wait to see what others say and then I will try it from there.
Logged
Security+, Network+, C|EH, CHFI, CPT
r2s
Newbie
Offline
Posts: 49
The Artisan
Re: CPT Practical - Feedback Please...
«
Reply #104 on:
November 07, 2011, 09:05:48 AM »
Quote from: Joshsevo on November 04, 2011, 09:48:51 PM
Question: If I can change the root password does is that equal to gaining root access and then having full control of the system?
Instructions don't say that I can't nor say I can.
Give me your opinions.
I'm back! Getting "root" is very subjective but I would not change the pre-set root password as I believe cracking the password may be part of the objective set (<- does not violate NDA as per the instructions).
I can't go any further than that advice wise as any further information could eventually start to steer the direction of your executive post engagement report and potentially walk the NDA line (I have huge respect for IACRB).
Dig deep and you'll get this.
Logged
In progress:
OSCP & GXPN (June)
"Silence enables the sound to be"
- Eckhart Toll
Pages:
1
...
5
6
[
7
]
8
9
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
Editor-In-Chief
: Special Xmas Deal: 10% Off eLearnSecurity Courses
(3) by
hekvvddtest
Greetings
: Hello
(6) by
hekvvddtest
Greetings
: Obtain The Scoop On mulberry bags Before You Are Too Late
(13) by
hekvvddtest
Calendar Of Events
: HITBSecConf2013 – Amsterdam
(9) by
hekvvddtest
Special Events
: [Article]-Webcast: Deep Dive into Red Teaming with the Metasploit Framework
(19) by
hekvvddtest
Network Pen Testing
: HackaServer - Anyone tried it?
(4) by
hekvvddtest
Greetings
: Good day ...
(7) by
hekvvddtest
Gates
: Chris Gates' Blog RSA Finalist
(5) by
hekvvddtest
Network Pen Testing
: Ruby on Rails Vulnerabilities / Attacks in BackTrack 5 r3
(1) by
hekvvddtest
General Certification
: nth topic on Career Advice
(9) by
hekvvddtest
General Certification
: Direction
(5) by
hekvvddtest
Hardware
: Discreet Hacking Devices
(8) by
hekvvddtest
Calendar Of Events
: CanSecWest 2013
(5) by
hekvvddtest
Forensics
: Burn Note
(5) by
hekvvddtest
Calendar Of Events
: Cyber Readiness Challenge - Rome
(1) by
hekvvddtest
GCIH - GIAC Certified Incident Handler
: GCIH Free Practice test attempt
(0) by
prats84
GCIH - GIAC Certified Incident Handler
: Passed my GCIH
(0) by
prats84
News Items and General Discussion About EH-Net
: Change is Coming to EH-Net!!
(27) by
don
Greetings
: Hi from the UK
(2) by
n37sh@rk
Network Pen Testing
: AIX Vulnerability Assessments
(2) by
ras76
Tutorials
: Need guidance
(9) by
hanyhasan
Programming
: Finished Python Course in Codecademy now what?
(15) by
hanyhasan
Network Pen Testing
: De-ICE 1.140 released!
(2) by
superkojiman
General Certification
: CPT Practical Submission
(1) by
UNIX
OSCP - Offensive Security Certified Professional
: Failed my first attempt at the OSCP exam
(94) by
azmatt
Tools
: Social-Engineer Toolkit (SET) Version 5.0 “The Wild West” Released
(2) by
m0wgli
Malware
: EICAR?
(3) by
UKSecurityGuy
Advisories
: HTB23154: Multiple Vulnerabilities in Exponent CMS
(0) by
AndyP
Advisories
: HTB23153: Multiple Vulnerabilities in Jojo CMS
(0) by
AndyP
Advisories
: HTB23151: Cross-Site Request Forgery (CSRF) in UMI.CMS
(0) by
AndyP
OSCP - Offensive Security Certified Professional
: Class Scheduled 6/8 - Linux n00b
(7) by
Taemyks
OSCP - Offensive Security Certified Professional
: OSCP exam scheduled
(6) by
gbhat
Incident Response
: LinkedIn Forensics
(0) by
AFENTIS_Forensics
General Certification
: Red Team/Blue Team
(1) by
ajohnson
Career Central
: Starter cert?
(3) by
Grendel
Network Pen Testing
: Beginner Ethical Hacker
(1) by
m0wgli
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.