Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 49 guests and 4 members online
 
Advertisement

You are here: Home arrow Ethical Hacking Discussions and Related Certificationsarrow Network Pen Testingarrow CPT Practical - Feedback Please...
EH-Net
May 22, 2013, 07:03:19 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: 1 ... 6 7 [8] 9   Go Down
  Print  
Author Topic: CPT Practical - Feedback Please...  (Read 63450 times)
0 Members and 1 Guest are viewing this topic.
Joshsevo
Sr. Member
****
Offline Offline

Posts: 278


View Profile
« Reply #105 on: November 07, 2011, 12:02:02 PM »

Cool,  Thanks.  I have not changed it yet as I saw it as a cheap way around it.  Sure in real life I would be golden but this is not what it was desgined for.
Logged

Security+, Network+, C|EH, CHFI, CPT
SephStorm
Hero Member
*****
Offline Offline

Posts: 530


View Profile WWW
« Reply #106 on: November 07, 2011, 01:36:56 PM »

Lol, its awesome, we both thought alike on so many things on this exam. No, I would not change the password. 1. If im not mistaken, there are instructions to recover both root passwords. Now, you can change the user passwords all you want, but i wouldnt. 2. Think of this as a live pentest, would you change their root passwords, or any for that matter? If you do, you lock out the user, causing a denial of service, especially if its theri only root account on that system. It will also (hopefully) trigger their incident response mechanisms.

i'd do some research on the type of password hash you have and see if there are any tools that can crack that hash, then google/ youtube/ ask the creators about how to use the tool.
Logged

Joshsevo
Sr. Member
****
Offline Offline

Posts: 278


View Profile
« Reply #107 on: November 23, 2011, 03:24:55 PM »

Any good sites to look up CVE's to see if I can use an exploit to gain root access on the server?
Logged

Security+, Network+, C|EH, CHFI, CPT
Joshsevo
Sr. Member
****
Offline Offline

Posts: 278


View Profile
« Reply #108 on: November 23, 2011, 03:29:39 PM »

Are there any expolits that I can run without having to do any scripting/coding?
Logged

Security+, Network+, C|EH, CHFI, CPT
SephStorm
Hero Member
*****
Offline Offline

Posts: 530


View Profile WWW
« Reply #109 on: December 09, 2011, 04:57:34 PM »

You are unlikely to find any remote exploits giving you root access. If anything, you may find some local privilege escalation exploits. But i wouldnt use CVE, I would look at well, things that are commonly used for privilege escalation....

As for modifying exploits, you may have to search for a working copy of an exploit. I came upon the same issue, you just have to find either another exploit, a working version of the one you are working on, or learn how to find the problem...
Logged

Joshsevo
Sr. Member
****
Offline Offline

Posts: 278


View Profile
« Reply #110 on: December 13, 2011, 01:56:39 PM »

I am pretty much at a stand still with this cert.  Researched everything I could.  Just stuck.  Have roughly two weeks to get root or it's a FAIL.
Logged

Security+, Network+, C|EH, CHFI, CPT
UNIX
Hero Member
*****
Offline Offline

Posts: 1235


View Profile
« Reply #111 on: December 13, 2011, 02:12:20 PM »

It's still enough time to search for an appropriate way to root your box, just don't give up. If they haven't changed the exam since when I took it, then there are quite a few exploits available which will lead to root.

Also, if you have learned something during the course or the process itself, you really shouldn't consider it as a simply fail.
Logged
Joshsevo
Sr. Member
****
Offline Offline

Posts: 278


View Profile
« Reply #112 on: December 13, 2011, 03:58:03 PM »

LOL I don't know how to run the exploits.  Sure I learned stuff in the course but it was mostly aimed at the CEH and not so much CPT and nowhere did we touch running expolits.

I've tried asking the right questions without trying to get inside hints or make it seem like I am cheating but I just have no idea how to run the expoloits.  Finding them is easy.  But how to input them and how to complie them isn't something that I know.  Never been taught.  Besides me and coding don't get along the greatest.

I've been looking and reading but most of this stuff goes way over my head.
Logged

Security+, Network+, C|EH, CHFI, CPT
tturner
Sr. Member
****
Offline Offline

Posts: 432


View Profile WWW
« Reply #113 on: December 13, 2011, 08:26:14 PM »

The best way to learn is to do.
Logged

Certifications:
CISSP, CISA, GPEN, GWAPT, GAWN, GCIA, GCIH, GSEC, OPSE, CSWAE, CSTP, VCP

WIP: OSWP, GSSP-JAVA, GXPN

Udacity on hold, again. I suck.

http://sentinel24.com/blog  @tonylturner http://bsidesorlando.org
Joshsevo
Sr. Member
****
Offline Offline

Posts: 278


View Profile
« Reply #114 on: December 14, 2011, 07:55:35 AM »

It is I agree.  I was able to get Metaspolit runining last night for the first time.  Nothing postive though came from it.  But just being able to get it to run is an accomplishment in itself.
Logged

Security+, Network+, C|EH, CHFI, CPT
Joshsevo
Sr. Member
****
Offline Offline

Posts: 278


View Profile
« Reply #115 on: December 30, 2011, 04:29:46 PM »

I did it, found the root password for the server.  I am done.  I was running a Hascat for 18 hrs doing a brute force attack and it finally had a hit.  Double checked it by trying to log into the server under root and it worked. 
I had one day to complete this as my extension ends on Jan 1, 2012.

Thanks for everyone's help.

Logged

Security+, Network+, C|EH, CHFI, CPT
hayabusa
Hero Member
*****
Offline Offline

Posts: 1632



View Profile
« Reply #116 on: December 30, 2011, 05:52:51 PM »

Congrats, Josh!  Well done, and way to stick with it!
Logged

~ hayabusa ~ 

"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'


OSCE, OSCP , GPEN, C|EH
SephStorm
Hero Member
*****
Offline Offline

Posts: 530


View Profile WWW
« Reply #117 on: January 02, 2012, 10:15:05 PM »

I knew you could do it! Now add that cert to your signature and sit back and have a beer! (Then get back to work! *cracks whip*)
Logged

Joshsevo
Sr. Member
****
Offline Offline

Posts: 278


View Profile
« Reply #118 on: January 03, 2012, 10:34:20 AM »

Well I haven't officailly passed per se.  I have yet to turn my results in but seeing as the instructions say that to pass I need to get full root access to both systems and then also document everything I should pass.

InfoSec's website to submit my results is not letting me. I am trying to contact them to see what the deal is but when I go to their link and hit submit after loading my either Doc/Docx, or a zip file it says "this option is not available"
Logged

Security+, Network+, C|EH, CHFI, CPT
UNIX
Hero Member
*****
Offline Offline

Posts: 1235


View Profile
« Reply #119 on: January 03, 2012, 05:27:39 PM »

You should send your results directly to IACRB, see here.
Logged
Pages: 1 ... 6 7 [8] 9   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.067 seconds with 23 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.