Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 19 guests and 1 member online
 
Free Business and Tech Magazines and eBooks

You are here: Home arrow Ethical Hacking Discussions and Related Certificationsarrow Wirelessarrow OSWP - VPN Connection Question
EH-Net
May 25, 2013, 02:30:26 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1] 2   Go Down
  Print  
Author Topic: OSWP - VPN Connection Question  (Read 7192 times)
0 Members and 1 Guest are viewing this topic.
esojzuir
Newbie
*
Offline Offline

Posts: 36


View Profile
« on: March 01, 2012, 04:25:03 PM »

Hello Everyone!

I have a question regarding the Offensive Security Wireless Test. You are supposed to connect remotely to the test site and use a terminal to attack the routers. I've never done anything like this before (used to the multiple selection tests) and I wanted to see if anyone that has taken the test can clear some doubts:

When you log in do you actually open a terminal and see a BT machine and work from that or do you log in and open a putty terminal and work from that?

Any help will be appreciated

Thanks in advance!
Logged
UNIX
Hero Member
*****
Offline Offline

Posts: 1235


View Profile
« Reply #1 on: March 01, 2012, 04:53:22 PM »

You will receive an email from offsec with instructions on how to connect to the exam machine through SSH, which will be your attacking machine.
Logged
esojzuir
Newbie
*
Offline Offline

Posts: 36


View Profile
« Reply #2 on: March 01, 2012, 05:43:02 PM »

Thanks for the response. So it will be correct to assume that I will connect to an instance of the BT machine with GUI and from then open a konsole and fire away???
Logged
cd1zz
Hero Member
*****
Offline Offline

Posts: 561


View Profile WWW
« Reply #3 on: March 01, 2012, 07:59:33 PM »

No GUI, just console sessions. You can open more than one, I think I had 4 going during my test.
Logged

TheXero
Full Member
***
Offline Offline

Posts: 112


Try Harder!


View Profile WWW
« Reply #4 on: March 02, 2012, 03:44:18 AM »

 esojzuir, I used 'screen' in my exam and I would recommend it Smiley
Logged

ajohnson
Recruiters
Hero Member
*
Offline Offline

Posts: 1060


aka dynamik


View Profile WWW
« Reply #5 on: March 02, 2012, 08:40:32 AM »

esojzuir, I used 'screen' in my exam and I would recommend it Smiley

Good advice; I love screen. There's also the added benefit of being able to retrieve your session if you get disconnected.
Logged

WIP: GCFA | www.infosiege.net | @infosiege

The day you stop learning is the day you start becoming obsolete.
esojzuir
Newbie
*
Offline Offline

Posts: 36


View Profile
« Reply #6 on: March 02, 2012, 08:46:44 AM »

Thanks for the help everyone! How can I get screen??? Is there a link you can post???
Logged
ajohnson
Recruiters
Hero Member
*
Offline Offline

Posts: 1060


aka dynamik


View Profile WWW
« Reply #7 on: March 02, 2012, 08:52:20 AM »

I believe it's installed by default in BT5, which is what you'll be connecting to.

Otherwise, apt-get install screen (or whatever the equivalent is on non-Debian systems)

It's pretty simple, but you should still experiment with it a bit in advance to get used to the key commands, etc. Just check out the man page.
Logged

WIP: GCFA | www.infosiege.net | @infosiege

The day you stop learning is the day you start becoming obsolete.
BillV
Hero Member
*****
Offline Offline

Posts: 1892


View Profile WWW
« Reply #8 on: March 02, 2012, 09:15:49 AM »

Well I'm glad these guys remembered because I sure didn't. Tongue I just remember it being very quick.

Good luck on your test!
Logged
esojzuir
Newbie
*
Offline Offline

Posts: 36


View Profile
« Reply #9 on: March 27, 2012, 08:37:10 AM »

I passed the OSWP!!!!! It's a really cool and fun way to get introduced to the world of practical examinations, as I was used to the typical questions type exam.

The next project is elearnsecurity pro and then PWB!!!!
Logged
Agoonie
Full Member
***
Offline Offline

Posts: 177



View Profile WWW
« Reply #10 on: March 27, 2012, 09:23:35 AM »

Congrats! What version did you take, 3.0? If v3, how did you like the Rogue Access Points and coWPAtty modules?
Logged

OSCE, OSCP, OSWP, CISSP, GPEN

www.agoonie.com
ajohnson
Recruiters
Hero Member
*
Offline Offline

Posts: 1060


aka dynamik


View Profile WWW
« Reply #11 on: March 27, 2012, 09:50:46 AM »

Congrats esojzuir!

I passed mine a couple weeks ago as well. I've been meaning to write a review.

Agoonie, the v3 additions were a nice improvement. v2 was always good for WEP, but it has felt dated for a long time. I thought the GPU RT generation with Pyrit was pretty slick. I have a decent GPU because I'm a bit of gamer, and it was interesting to see how that fared against the i7.

The actual exam is still v2, and I think there is still room for growth there (i.e. client attacks with karmetasploit, etc.).
« Last Edit: March 27, 2012, 09:57:48 AM by ajohnson » Logged

WIP: GCFA | www.infosiege.net | @infosiege

The day you stop learning is the day you start becoming obsolete.
Agoonie
Full Member
***
Offline Offline

Posts: 177



View Profile WWW
« Reply #12 on: March 27, 2012, 11:07:08 AM »

Congrats esojzuir!

I passed mine a couple weeks ago as well. I've been meaning to write a review.

Agoonie, the v3 additions were a nice improvement. v2 was always good for WEP, but it has felt dated for a long time. I thought the GPU RT generation with Pyrit was pretty slick. I have a decent GPU because I'm a bit of gamer, and it was interesting to see how that fared against the i7.

The actual exam is still v2, and I think there is still room for growth there (i.e. client attacks with karmetasploit, etc.).

Thanks for the heads up.  I figured I would take it later this year to see what they improved on.  It sounds cool so I am sure I will find the time at some point.  Did they have anything on attacking WPA2 Enterprise?  I found some people talking about it but I do not remember if the OffSec guys had anything. Meh, either way, I am going to take the new course.   Grin
Logged

OSCE, OSCP, OSWP, CISSP, GPEN

www.agoonie.com
esojzuir
Newbie
*
Offline Offline

Posts: 36


View Profile
« Reply #13 on: March 27, 2012, 11:42:11 AM »

Thanks everyone!!!! I took version 3 and both the cowpatty and rogue access point modules were really good, both on video and the text. You can set up and use both topics really fast. Unfortunately none were used on the test.

I tried cowpatty for the WPA but it wasn't even installed on the attack machine, so yes it's still a v2 exam, but lots of fun. I started the exam and for those weird reasons after 1/2 hour I was no able to crack my first target!!!!!!!!!!

I decided to move to the other 2 and I was done with those in about 25 minutes with all the documentation and everything. Then I took a breather and cracked the first one in 15 minutes, so in all I spent 1 hour and 40 minutes cracking, writing and getting screenshots and 2 hours setting the report.

I agree that later on they should add rogue access point and karmetasploit attacks to the exam. Maybe have 5 targets to attack and make it 6-8 hours to do the test. I really recommend this class to anyone!!!!!
Logged
ajohnson
Recruiters
Hero Member
*
Offline Offline

Posts: 1060


aka dynamik


View Profile WWW
« Reply #14 on: March 27, 2012, 12:29:45 PM »

Did they have anything on attacking WPA2 Enterprise?  I found some people talking about it but I do not remember if the OffSec guys had anything.

No, just PSK.

I thought the upgrade was worth it. I found the rainbow tables generation, airserv/airtun, and GPS portions to be particularly interesting.

They have the v3 Syllabus online if you haven't reviewed it yet: http://www.offensive-security.com/documentation/wifu-syllabus.pdf
Logged

WIP: GCFA | www.infosiege.net | @infosiege

The day you stop learning is the day you start becoming obsolete.
Pages: [1] 2   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.068 seconds with 23 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Free Business and Tech Magazines and eBooks

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.