Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 54 guests and 3 members online
Free Business and Tech Magazines and eBooks
You are here:
Home
Ethical Hacking Discussions and Related Certifications
Wireless
OSWP - Offensive Security Wireless Professional
OSWP Walkthrough
EH-Net
May 22, 2013, 03:34:38 AM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Ethical Hacking Discussions and Related Certifications
>
Wireless
>
OSWP - Offensive Security Wireless Professional
(Moderator:
don
) >
OSWP Walkthrough
Pages: [
1
]
2
Go Down
« previous
next »
Print
Author
Topic: OSWP Walkthrough (Read 31276 times)
0 Members and 1 Guest are viewing this topic.
j0rDy
Hero Member
Offline
Posts: 590
OSWP Walkthrough
«
on:
February 22, 2011, 05:02:58 AM »
OK, since i got alot of positive feedback on my last "walkthrough" i made the descision to write another one for my OSWP certification. Again, if anyone got feedback/comments (Donald or the guys at Offensive Security) please let me know!
General info:
Quote
After passing the OSCP course i decided to take a well deserved break. After about a month something started itching
. I was so impressed by the learning method used by Offensive Security i just had to go for another one. Giving the fact i went through hell (got there, got lost, wandered around for a long long time, and finally got back) to pass for PWB i decided to go for WiFu. The main reason for this decision is that i feel i am not yet ready to pursue OSCE, cause of my previous experiences with PWB. Another reason is that even though how much i ould like to learn it, writing exploits, learning assembly etc., it is a little bit out of scope for the work i do, but WiFi becomes a more important factor for me. And last but not least, it is a bargain!
When i clicked the sign up now button i noticed a different registration process. I received a mail with additional information about the course, and a registration form. From what i remember this is new. It is good to see that the guys at OffSec are not only working on the course itself, but also everything else that counts to become a good, respectable learning institute.
The outline is pretty much equal to the other courses. You will receive a lab guide (which is in size equal to the OSCP one!) and ofcourse the video's, which will take about 2.5 hours to get through. They also specify the required skills needed to pass the course. This is a little bit more then the "basic linux commandline skills". I quote:
"You need to have basic Linux skills in order to complete this course- meaning you should be able to navigate through the Linux filesystem, run simple commands, edit files and be comfortable in the command line in general."
They also provide an estimated time for completing the course, which is according to OffSec 2 hours. Giving i have played with WiFi and the air-suite before i guess it will be a little less, but we will see.
The labs are hosted by the student. This means no VPN to connect to as with PWB, but set up your own wireless network. Besides the fact that this is also good to know, it provides a nice look on the other side of IT security, which is in this case not hacking it, but properly configuring it. They also provide some tips on hardware which should not be a problem, cause most of the wireless adapters have good support in the latest version of Backtrack.
Finally there is an exam (ofcourse). This one will take about 3 hours including the time to prepare your results and to send them by mail. There are no pre set dates, but you have to schedule the exam within 4 months from your starting date. My guess is this will be no problem.
right now i am waiting for further instructions, and i must say i am stoked to be starting another OffSec course again!
(First) Impressions:
Quote
OK, this was supposed to be a first impression update, but since i already covered all material i will rename it to just impressions. As i suspected the course is significally smaller than OSCP. I knew this before i started the course, because of the CPE points you get for both exams. Ofcourse getting through the course so fast is partly my fault, because i spend almost the entire weekend on the course. First lets start with the course guide.
The first couple of chapters contain some background information on the wireless protocol. Mostly is about the used protocols and operating modes. Even though none of this information is required for the exam, it is very useful to read through to get a deeper understandig of the wireless protocol. There is also a chapter that covers the hardware aspect. While this information can be considered a little bit oudated because of the current developments within Backtrack 4 and the upcoming 802.11n protocol it makes the choice of hardware a little bit easier if you dont want to go dig in technical specifications of wireless adapters. This is something i decided to do just because i think it is fun.
Like mosts hackers i like new toys and if possible, the best toys available. I got myself an Alfa Network AWUS036NH, which is not supported out of the box by BT4R2, but there are tutorials around to get it fully working. I bought this specific one with current and future developments in mind, because the n protocol becomes more and more mainstream. While i was at it, i also ordered a 9dbi high gain antenna to make the picture complete. OK, enough about the hardware.
The course is mainly focussed on the aircrack suite. The last chapters cover some other tools briefly, but almost not noteworthy. I like the layout of the course, because the different attack techniques are explained before you start the actual attack. This gives a better understanding of what goes on while aircrack is doing what it does best. While doing some extended research on the tool (after getting some vague errors which somehow dissapeared after a reboot, so actually not noteworthy) i saw that most of the material is also covered on the aircrack site. This makes the course a little bit obsolete if you just want to learn WiFu and do not want to pursue the certification. Still the additional video's provide a good addition to the course guide.
Again, Mati does a great job explaining the different attack techniques and makes it all very understandable. I always say that if you have the power to make something difficult look easy, you truly master the skills. Even though some subjects may need some updates, (for example, why is still BT3 recommended with the madwifi drivers?) it is still a great course to follow. Since there are no real exercises in the course (except for trying everything yourself) i will skip this part and move right on to the exam, so stay tuned for the next update: Exam time!
Exam time!
Quote
The exam exists of multiple WEP and WPA wireless networks that need to be hacked. There is a wordlist present for the WPA network(s), so do not worry about failing the exam because of a bad wordlist. The exam is more about how you got the result instead of the actual result. You have 4 hours to complete the exam and a total of 24 hours to send in the acquired results. They specifically ask for a workout of the steps taken and commands used which got you to your result. After this you will receive a reply with your results within a few workdays.
Different from the other courses, you will login using a SSH connection on a Backtrack3 box where the wireless setup has been prepared. The host has two wireless devices hooked up, which gives you the decision to choose your favourite driverset (Atheros or Alfa). Since i practised at home with the alfa my choice was obvious.
Saying this, there is really nothing more to tell about this course. I like the introduction chapters that give a better theoretical understanding of the wifi protocol. The big advantage of this course is that you will learn different attack methods to obtain the key which can be different depending on the state of the network (client/clientless, OPN/SKA etc.).
I received a reply on my submitted documentation within 24 hours, which was extremely fast! since i owned all the networks i figured i would most certainly pass, but there is always that little piece of doubt. Still when i got the results i was stoked i passed the course. Thank you again for all the feedback i received and for taking the time to join me once again in this walkthrough. I hope you had as much fun reading it as i had writing it. Thanks again to everyone for this great experience and the opportunity to tell others about my experiences within the security field. Until next time.
[\quote]
«
Last Edit: March 28, 2011, 02:21:02 AM by j0rDy
»
Logged
ISC2 Associate, CEH, ECSA, OSCP, OSWP
earning my stripes appears to be a road i must travel alone...with a little help of EH.net
H1t M0nk3y
Hero Member
Offline
Posts: 864
Re: OSWP Walkthrough
«
Reply #1 on:
February 22, 2011, 09:20:10 AM »
Hey j0rDy,
We really can't stop, isn't?
Thanks for your walkthrough. I was thinking on taking it eventually. You write nice reviews. You should talk to Don about writing an "official" review!
Logged
OSCP, GPEN, GWAPT, GSEC, CEH, CISSP
j0rDy
Hero Member
Offline
Posts: 590
Re: OSWP Walkthrough
«
Reply #2 on:
February 22, 2011, 09:47:42 AM »
Quote from: H1t M0nk3y on February 22, 2011, 09:20:10 AM
Hey j0rDy,
We really can't stop, isn't?
Thanks for your walkthrough. I was thinking on taking it eventually. You write nice reviews. You should talk to Don about writing an "official" review!
i guess we can't
Thanks and if Don wants me to save it for the front page, no problem, but then you guys have to play the waiting game...
Logged
ISC2 Associate, CEH, ECSA, OSCP, OSWP
earning my stripes appears to be a road i must travel alone...with a little help of EH.net
don
Editor-In-Chief
Administrator
Hero Member
Offline
Posts: 4165
Editor-In-Chief
Re: OSWP Walkthrough
«
Reply #3 on:
February 22, 2011, 11:06:28 PM »
I like the walkthrough format, but I'm always willing to look for new articles. PM me.
Don
Logged
CISSP, MCSE, CSTA, Security+ SME
j0rDy
Hero Member
Offline
Posts: 590
Re: OSWP Walkthrough
«
Reply #4 on:
March 03, 2011, 09:32:57 AM »
(First) Impressions:
Quote
OK, this was supposed to be a first impression update, but since i already covered all material i will rename it to just impressions. As i suspected the course is significally smaller than OSCP. I knew this before i started the course, because of the CPE points you get for both exams. Ofcourse getting through the course so fast is partly my fault, because i spend almost the entire weekend on the course. First lets start with the course guide.
The first couple of chapters contain some background information on the wireless protocol. Mostly is about the used protocols and operating modes. Even though none of this information is required for the exam, it is very useful to read through to get a deeper understandig of the wireless protocol. There is also a chapter that covers the hardware aspect. While this information can be considered a little bit oudated because of the current developments within Backtrack 4 and the upcoming 802.11n protocol it makes the choice of hardware a little bit easier if you dont want to go dig in technical specifications of wireless adapters. This is something i decided to do just because i think it is fun.
Like mosts hackers i like new toys and if possible, the best toys available. I got myself an Alfa Network AWUS036NH, which is not supported out of the box by BT4R2, but there are tutorials around to get it fully working. I bought this specific one with current and future developments in mind, because the n protocol becomes more and more mainstream. While i was at it, i also ordered a 9dbi high gain antenna to make the picture complete. OK, enough about the hardware.
The course is mainly focussed on the aircrack suite. The last chapters cover some other tools briefly, but almost not noteworthy. I like the layout of the course, because the different attack techniques are explained before you start the actual attack. This gives a better understanding of what goes on while aircrack is doing what it does best. While doing some extended research on the tool (after getting some vague errors which somehow dissapeared after a reboot, so actually not noteworthy) i saw that most of the material is also covered on the aircrack site. This makes the course a little bit obsolete if you just want to learn WiFu and do not want to pursue the certification. Still the additional video's provide a good addition to the course guide.
Again, Mati does a great job explaining the different attack techniques and makes it all very understandable. I always say that if you have the power to make something difficult look easy, you truly master the skills. Even though some subjects may need some updates, (for example, why is still BT3 recommended with the madwifi drivers?) it is still a great course to follow. Since there are no real exercises in the course (except for trying everything yourself) i will skip this part and move right on to the exam, so stay tuned for the next update: Exam time!
Logged
ISC2 Associate, CEH, ECSA, OSCP, OSWP
earning my stripes appears to be a road i must travel alone...with a little help of EH.net
AndyB
Full Member
Offline
Posts: 100
Re: OSWP Walkthrough
«
Reply #5 on:
March 10, 2011, 03:28:37 PM »
j0rDy,
Hope you can clarify something on this?
Have got the hardware and am playing with that and Aircrack suit atm with a view to doing the course and exam sometime after easter once I finally get my CCNA out of the way.
Been reading up on the Offensive Sec site about the course and note that the exam is only about 4 hrs. Do they expect you to crack passwords within that time, if so what the hell with?
Depending on which txt or lst file I use, I can be looking at 20hrs+ for aircrack to 'crack' a cap file
Logged
Net+ Sec+ More to come
j0rDy
Hero Member
Offline
Posts: 590
Re: OSWP Walkthrough
«
Reply #6 on:
March 11, 2011, 02:16:47 AM »
I am not sure about that one. I think they require you to crack several networks, probably a WEP and a WPA one. WEP should be no problem if they use a simple password, which should be done within several seconds/minutes. For the WPA i see your concern. I guess since BT comes with a standard WPA password list i figure the password will be in there, otherwise it will be shooting mosquito's with a bazooka. Once i have done the exam i will give clarification on this. Wish me luck
Logged
ISC2 Associate, CEH, ECSA, OSCP, OSWP
earning my stripes appears to be a road i must travel alone...with a little help of EH.net
chrisj
Hero Member
Offline
Posts: 1163
Re: OSWP Walkthrough
«
Reply #7 on:
March 11, 2011, 10:50:01 AM »
Quote from: AndyB on March 10, 2011, 03:28:37 PM
Have got the hardware and am playing with that and Aircrack suit atm with a view to doing the course and exam sometime after easter once I finally get my CCNA out of the way.
Been reading up on the Offensive Sec site about the course and note that the exam is only about 4 hrs. Do they expect you to crack passwords within that time, if so what the hell with?
Depending on which txt or lst file I use, I can be looking at 20hrs+ for aircrack to 'crack' a cap file
4 hours was more than enough time to do it. I finished in under 2, including the write up. I had to do both WEP and WPA, but more than that I will not say.
You're not cracking the passwords, you're cracking / recovering the wifi keys. There is a difference.
If you want to really get some side study done, besides just reading the Aircrack-NG site and howto, pick up Hacking Exposed Wireless Hacking.
Logged
OSWP, Sec+
AndyB
Full Member
Offline
Posts: 100
Re: OSWP Walkthrough
«
Reply #8 on:
March 11, 2011, 05:51:57 PM »
Best of luck j0rDy
chrisj, i'm ordering it very soon! Only question I have is, I've seen that there is edition 2 of the hacking exposed wireless. Looking at the blurb with the books online, the edition 2 looks like it's bang up to date but should I be looking at the edition 1 book to help with the exam?
Logged
Net+ Sec+ More to come
chrisj
Hero Member
Offline
Posts: 1163
Re: OSWP Walkthrough
«
Reply #9 on:
March 11, 2011, 08:26:31 PM »
That's actually a good question, and I don't know. I was suggesting the second edition to learn beyond what you'll need for the exam.
Logged
OSWP, Sec+
j0rDy
Hero Member
Offline
Posts: 590
Re: OSWP Walkthrough
«
Reply #10 on:
March 27, 2011, 10:42:27 AM »
Update: I passed!
I will write the final update in a few days...
Logged
ISC2 Associate, CEH, ECSA, OSCP, OSWP
earning my stripes appears to be a road i must travel alone...with a little help of EH.net
lorddicranius
Sr. Member
Offline
Posts: 447
Re: OSWP Walkthrough
«
Reply #11 on:
March 27, 2011, 01:41:29 PM »
Gratz j0rDy! Some more knowledge to build upon
Logged
GSEC, eCPPT, Sec+
hayabusa
Hero Member
Offline
Posts: 1632
Re: OSWP Walkthrough
«
Reply #12 on:
March 27, 2011, 01:53:33 PM »
Congrats on passing, j0rdy! Always nice to hear you're progressing. Keep it up, and continued good luck!
Logged
~ hayabusa ~
"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'
OSCE, OSCP , GPEN, C|EH
AndyB
Full Member
Offline
Posts: 100
Re: OSWP Walkthrough
«
Reply #13 on:
March 27, 2011, 02:50:53 PM »
Congrats and I look forward to reading you final installment
Logged
Net+ Sec+ More to come
millwalll
Guest
Re: OSWP Walkthrough
«
Reply #14 on:
March 27, 2011, 03:47:47 PM »
I just passed this too. and 4 hours is more than enough I didn't find that exam that hard once i got my head around it first security certificate so was all very new.
Logged
Pages: [
1
]
2
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
Network Pen Testing
: AIX Vulnerability Assessments
(2) by
ras76
Tutorials
: Need guidance
(9) by
hanyhasan
Programming
: Finished Python Course in Codecademy now what?
(15) by
hanyhasan
Network Pen Testing
: Ruby on Rails Vulnerabilities / Attacks in BackTrack 5 r3
(0) by
SUdoctstudent
Network Pen Testing
: De-ICE 1.140 released!
(2) by
superkojiman
General Certification
: CPT Practical Submission
(1) by
UNIX
OSCP - Offensive Security Certified Professional
: Failed my first attempt at the OSCP exam
(94) by
azmatt
Tools
: Social-Engineer Toolkit (SET) Version 5.0 “The Wild West” Released
(2) by
m0wgli
Malware
: EICAR?
(3) by
UKSecurityGuy
Advisories
: HTB23154: Multiple Vulnerabilities in Exponent CMS
(0) by
AndyP
Advisories
: HTB23153: Multiple Vulnerabilities in Jojo CMS
(0) by
AndyP
Advisories
: HTB23151: Cross-Site Request Forgery (CSRF) in UMI.CMS
(0) by
AndyP
OSCP - Offensive Security Certified Professional
: Class Scheduled 6/8 - Linux n00b
(7) by
Taemyks
OSCP - Offensive Security Certified Professional
: OSCP exam scheduled
(6) by
gbhat
Incident Response
: LinkedIn Forensics
(0) by
AFENTIS_Forensics
General Certification
: Red Team/Blue Team
(1) by
ajohnson
Career Central
: Starter cert?
(3) by
Grendel
Network Pen Testing
: Beginner Ethical Hacker
(1) by
m0wgli
Web Applications
: Nessus and Nikto
(4) by
Seen
Network Pen Testing
: Cracking salted MD5 hash
(4) by
n37sh@rk
CEH - Certified Ethical Hacker
: Passed my C|EH
(3) by
n37sh@rk
Mass Media
: EC-council hacked, irony at his best?
(0) by
j0rDy
Web Applications
: SQL Injection into an INSERT statement.
(6) by
eyenit0
Network Pen Testing
: Solution for sipXtapi INVITE Message CSeq Field Header Remote Overflow
(1) by
m0wgli
Web Applications
: dns
(2) by
H1t M0nk3y
Other
: BSides Boston
(0) by
3xban
Career Central
: InfoSec in Central, FL
(2) by
tturner
Web Applications
: Web vulnerability scanner
(4) by
H1t M0nk3y
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.