Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 41 guests and 2 members online
 
Advertisement

You are here: Home arrow Ethical Hacking Discussions and Related Certificationsarrow Web Applicationsarrow SANS Sec542 (GWAPT)
EH-Net
May 23, 2013, 08:25:25 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1] 2   Go Down
  Print  
Author Topic: SANS Sec542 (GWAPT)  (Read 15779 times)
0 Members and 1 Guest are viewing this topic.
rance
Full Member
***
Offline Offline

Posts: 212


<censored>


View Profile
« on: July 28, 2011, 11:23:12 AM »

Just took this class at SansFire last week.  How many "wow" and "awesome" words can I come up with to describe the class?  Here's what I gained:

-A more in-depth understanding of exploits I was familiar with (XSS, for example, which now terrifies me more than ever).

-An introduction to new attack vectors (SOAP, AJAX, Web Services)

-Deeper knowledge of tools I already use (learned some neat tricks with Burp Proxy, and other tools)

-Introduced to some new, very nifty tools

-Got to mingle with some fantastic geeky folks

-And of course, real-world exercises including a CTF event on the last day.

And what can I say about the instructor, Kevin Johnson... the guy is a card, but he's sharp, and an incredibly effective instructor (I'll be looking forward to 642 when it's ready).  

I'm making my first trip to DefCon mostly to see his talk on exploiting web services.  If you're a pen tester and going to be at DefCon, be absolutely certain to attend the "Don't Drop the SOAP: Real World Web Service Testing for Web Hackers" talk: https://www.defcon.org/html/defcon-19/dc-19-speakers.html#Eston  Judging by the discussion we had in class, they are going to release some great info on this attack vector, which currently isn't very well documented.

Aside from the 6-day cram turning my brain in to mush, I can't think of a single bad thing to say about the class.  If you're involved in web app pen testing, Sec542 is time very well spent!

Next step, GWAPT exam!

If anyone has questions on the class or materials, please don't hesitate to ask!
« Last Edit: July 29, 2011, 01:25:44 AM by rance » Logged

Poking at security since 1986.  +++ATH
tturner
Sr. Member
****
Offline Offline

Posts: 432


View Profile WWW
« Reply #1 on: July 28, 2011, 12:40:16 PM »

I think you mean GWAPT Wink

And I agree, Kevin is fantastic! I'm lucky that he is relatively local and comes to speak at our local ISSA chapter periodically. SEC542 + a copy of Web Application Hackers Handbook + a copy of Burp Pro is an amazing foundation for web app pentesting.
Logged

Certifications:
CISSP, CISA, GPEN, GWAPT, GAWN, GCIA, GCIH, GSEC, OPSE, CSWAE, CSTP, VCP

WIP: OSWP, GSSP-JAVA, GXPN

Udacity on hold, again. I suck.

http://sentinel24.com/blog  @tonylturner http://bsidesorlando.org
rance
Full Member
***
Offline Offline

Posts: 212


<censored>


View Profile
« Reply #2 on: July 28, 2011, 12:50:43 PM »

Too many acronyms, and my brain is still mush. Smiley

I'm eagerly awaiting WAHH v2.  I think october is the tentative release date for that...
Logged

Poking at security since 1986.  +++ATH
YuckTheFankees
Sr. Member
****
Offline Offline

Posts: 324


View Profile
« Reply #3 on: July 29, 2011, 12:51:38 AM »

great review. Im probably about 8-12 months away from taking any SANS classes but I cant wait. Everything I hear about them is always positive. I hope to take GPEN, GWAPT, and GCIH.

Did you feel that you could of taken the exam after the class, or would you need a little more time to study?


thanks
Logged

OSCP in progress
rance
Full Member
***
Offline Offline

Posts: 212


<censored>


View Profile
« Reply #4 on: July 29, 2011, 01:24:35 AM »

great review. Im probably about 8-12 months away from taking any SANS classes but I cant wait. Everything I hear about them is always positive. I hope to take GPEN, GWAPT, and GCIH.

Did you feel that you could of taken the exam after the class, or would you need a little more time to study?


thanks

To be honest, I haven't even seen a practice exam.  I should probably look in to that since I did get the exam bundle with the course, so I will be taking it.  I'll have to get back to you... Smiley
Logged

Poking at security since 1986.  +++ATH
tturner
Sr. Member
****
Offline Offline

Posts: 432


View Profile WWW
« Reply #5 on: July 29, 2011, 07:25:34 AM »

Currently GWAPT is one of the easiest GIAC exams. The exams are moving to a format with fewer but harder questions in the next few months. Basically there are a lot of questions that can be answered directly from the courseware. The newer questions will focus more on application of the knowledge in the courseware so you can't just lookup the switch to define a host in Nikto or know what WSDigger is used for. Questions will be more focused on the understanding of material in the courseware and utilizing that understanding in practical application of the knowledge. It's still multiple choice, but will require a bit more thought.
Logged

Certifications:
CISSP, CISA, GPEN, GWAPT, GAWN, GCIA, GCIH, GSEC, OPSE, CSWAE, CSTP, VCP

WIP: OSWP, GSSP-JAVA, GXPN

Udacity on hold, again. I suck.

http://sentinel24.com/blog  @tonylturner http://bsidesorlando.org
alucian
Full Member
***
Offline Offline

Posts: 225



View Profile
« Reply #6 on: July 29, 2011, 03:14:03 PM »

Nice topic.

I will do the course in Ottawa (28 aug - 2 sept). Maybe there are other members that are taking it.

Do I need something special for the course??
Maybe Burp pro??
Logged

CISSP ISSAP, CISM/A, GWAPT, GCIH, eCPPT, OSWP
rance
Full Member
***
Offline Offline

Posts: 212


<censored>


View Profile
« Reply #7 on: July 29, 2011, 03:29:39 PM »

Nice topic.

I will do the course in Ottawa (28 aug - 2 sept). Maybe there are other members that are taking it.

Do I need something special for the course??
Maybe Burp pro??

For what they teach, you don't NEED pro, but you will work with the free version. Which of course means you lose the ability to save and run the scanner.  About the only place I'd see your license being useful is in the CTF exercise, but it's not necessary.

If you want to get familiar with the toolset you'll be using, grab SamuraiWTF.

I'm certain you'll enjoy the class, good luck!
Logged

Poking at security since 1986.  +++ATH
tturner
Sr. Member
****
Offline Offline

Posts: 432


View Profile WWW
« Reply #8 on: July 29, 2011, 03:39:36 PM »

I agree with Rance, but Burp pro is so cheap and its amazing how badly the free version is throttled. When I switched to pro and fired up Intruder I was floored. I used it in the CtF and while my group only placed in the middle of the pack it was not due to any slowness of tools. (except maybe Dirbuster) Just slowness of brains Smiley (I got SE'd by Kevin, spent hours attacking the wrong target. I shall say no more LOL!)
Logged

Certifications:
CISSP, CISA, GPEN, GWAPT, GAWN, GCIA, GCIH, GSEC, OPSE, CSWAE, CSTP, VCP

WIP: OSWP, GSSP-JAVA, GXPN

Udacity on hold, again. I suck.

http://sentinel24.com/blog  @tonylturner http://bsidesorlando.org
rance
Full Member
***
Offline Offline

Posts: 212


<censored>


View Profile
« Reply #9 on: July 29, 2011, 04:02:52 PM »

Just slowness of brains Smiley

Same thing happened to me.  I actually had a flag within the first oh 10 minutes or so, but I overlooked it.  Repeatedly.  My brain just wasn't processing information in my favor.  Kevin finally had to smack me upside the head. Smiley

I forgot about Burp intruder being throttled and limited to one field.  Still doesn't make Pro necessary for the course, though.

I was working through some of my exercises last night and ALMOST whipped out the CC for to purchase my own license.  It'll happen, just need to wait for payday.
Logged

Poking at security since 1986.  +++ATH
alucian
Full Member
***
Offline Offline

Posts: 225



View Profile
« Reply #10 on: July 31, 2011, 08:15:43 PM »

Thanks for the information.
If the company will pay for it before the course I will use it.

I am sure that I will enjoy the course.
Logged

CISSP ISSAP, CISM/A, GWAPT, GCIH, eCPPT, OSWP
lorddicranius
Sr. Member
****
Offline Offline

Posts: 447



View Profile WWW
« Reply #11 on: November 05, 2011, 12:55:33 AM »

(I'll be looking forward to 642 when it's ready).

According to the list here, looks like it'll be March 2012 Smiley

http://www.sans.org/security-training/advanced-web-app-penetration-testing-ethical-hacking-1641-mid
« Last Edit: November 05, 2011, 01:26:24 AM by lorddicranius » Logged

GSEC, eCPPT, Sec+
tturner
Sr. Member
****
Offline Offline

Posts: 432


View Profile WWW
« Reply #12 on: November 07, 2011, 08:39:18 AM »

As far as I know 642 did not make the cut for Orlando. If I'm not mistaken, May will be the first appearance but I'm not sure at which event. If you look at the AppSec 2012 event in April it's not listed there and you'd think it would be if it was ready. http://www.sans.org/appsec-2012/
Logged

Certifications:
CISSP, CISA, GPEN, GWAPT, GAWN, GCIA, GCIH, GSEC, OPSE, CSWAE, CSTP, VCP

WIP: OSWP, GSSP-JAVA, GXPN

Udacity on hold, again. I suck.

http://sentinel24.com/blog  @tonylturner http://bsidesorlando.org
alucian
Full Member
***
Offline Offline

Posts: 225



View Profile
« Reply #13 on: November 08, 2011, 02:05:33 PM »

Hi,

I have a question about the exam: how much are they covering the tools in the exam? I already read all the books, but I didn't made any index.

For me Day 4 (Client side discovery) was the most difficult to digest, and I think that I need to read some extra materials.

In the same time I don't want to spend too much time on this, so I want to pass the exam asap, and then to apply the knowledge.

Thanks!
Logged

CISSP ISSAP, CISM/A, GWAPT, GCIH, eCPPT, OSWP
rance
Full Member
***
Offline Offline

Posts: 212


<censored>


View Profile
« Reply #14 on: November 09, 2011, 04:00:32 PM »

I've been trying to get my books tagged before I jumped in to one of my practice exams.  Figured I'd tag first, take a practice test, then adjust as necessary... then hopefully use the second practice exam to make sure I get 100%! Smiley

don't know if you have access to the practice exams. I bundled my exam cost with my sec542 class, and the two practice exams showed up in my SANS portal... if you do have them available, you can run through one and see where the focus is.
Logged

Poking at security since 1986.  +++ATH
Pages: [1] 2   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.082 seconds with 22 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.