Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 77 guests online
You are here:
Home
Ethical Hacking Discussions and Related Certifications
Web Applications
GWAPT passed...
EH-Net
May 20, 2013, 04:20:55 PM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Ethical Hacking Discussions and Related Certifications
>
Web Applications
(Moderator:
don
) >
GWAPT passed...
Pages: [
1
]
2
Go Down
« previous
next »
Print
Author
Topic: GWAPT passed... (Read 6270 times)
0 Members and 1 Guest are viewing this topic.
docrice
Newbie
Offline
Posts: 27
GWAPT passed...
«
on:
April 11, 2012, 12:22:03 AM »
I made it through my fifth GIAC exam today and barely made it over the 90% score line. I was stressing quite a bit before I sat down in front of the exam terminal and mentally cleared my mind for the inevitable fail. It was a good exam with some quality analysis questions (and a few really lame ones).
I'm not aspiring to be a pentester and I don't think 542 will help someone go from zero to pro overnight. It does provide good starting foundations though and there was broad coverage on different subject areas and lots of tools. I'd guess that doing PWB would be more "fun," but 542 was a good experience nonetheless. Kevin Johnson brought it all together quite well.
So that said, I have a spare GWAPT practice exam for someone who has never taken a GIAC practice (or real) exam before. I know SANS courses and GIAC certification attempts aren't cheap, so instead of passing it to someone in the SANS Advisory Board or another forum where I've given away practice tests before, I figure I'd give someone here a shot at it. So for a little fun, here are the rules:
You have never taken a GIAC exam before (I'm relying on your sense of honor here).
You must send your request to my email address encrypted with my GPG key.
Determine the OS and its version that my website is running on.
Determine the RFC1918 address space the server is sitting in.
I'm not inviting a pentest or simulated / real attack, just merely a casual scan and guess-work with your favorite interception proxy (if that's how you roll). No exploits allowed, thank you very much. I haven't patched in seven years (...just kidding). If you can't find the answers, just pat yourself on the back for trying (not as if I could do any better) and email me your encrypted request.
Logged
GSEC, GCFW, GCIA, GCIH, GWAPT, GAWN, OSWP, WCNA, CCNA, CCNA Security, [...and other resume filler]
Hopefully-useful stuff I've written:
http://kimiushida.com/bitsandpieces/articles/
unicityd
Full Member
Offline
Posts: 156
Bored IT Manager, Crypto Nerd
Re: GWAPT passed...
«
Reply #1 on:
April 11, 2012, 12:24:12 AM »
Congratulations on the pass. You say you're not aspiring to be a pentester, so...what is your goal? Just curious.
Logged
BS in IT, CISSP, MS in IS Management (in progress)
docrice
Newbie
Offline
Posts: 27
Re: GWAPT passed...
«
Reply #2 on:
April 11, 2012, 12:30:55 AM »
I work on the blue team side and my web app mindset was pretty much nonexistent before I took 542. At work I'm quite often faced with looking at web traffic and configuring various infrastructure devices, so I needed something that would help me get up to speed with how web-based attacks work. Before the course I had some vague notions of what SOAP was or what a Python script might have looked like. I have a slightly better idea now, and every little bit helps.
Logged
GSEC, GCFW, GCIA, GCIH, GWAPT, GAWN, OSWP, WCNA, CCNA, CCNA Security, [...and other resume filler]
Hopefully-useful stuff I've written:
http://kimiushida.com/bitsandpieces/articles/
millwalll
Guest
Re: GWAPT passed...
«
Reply #3 on:
April 11, 2012, 07:25:28 AM »
Congrats
Logged
ajohnson
Recruiters
Hero Member
Offline
Posts: 1057
aka dynamik
Re: GWAPT passed...
«
Reply #4 on:
April 11, 2012, 07:31:28 AM »
Congratulations, Kimi! When are you scheduling that GSE written exam?
Have you gone through the Web App Hackers Handbook (2nd)? If so, how did you feel it compared to the course? I'm thinking about challenging this one and would be interested in any recommendations for supplementary material outside of the course.
Logged
WIP: GCFA |
www.infosiege.net
| @infosiege
The day you stop learning is the day you start becoming obsolete.
sil
Hero Member
Offline
Posts: 549
Re: GWAPT passed...
«
Reply #5 on:
April 11, 2012, 07:58:36 AM »
Quote from: docrice on April 11, 2012, 12:30:55 AM
I work on the blue team side
Why don't you just knock GCED out of the way.
Logged
http://www.infiltrated.net/mgz/puppylecter.jpg
hayabusa
Hero Member
Offline
Posts: 1631
Re: GWAPT passed...
«
Reply #6 on:
April 11, 2012, 08:34:42 AM »
@docrice -
If you're looking to part with the pracice exam, I might be interested. One of these days, I figured on at least attempting the exam, so I wouldn't mind seeing what's in the practice exam.
Logged
~ hayabusa ~
"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'
OSCE, OSCP , GPEN, C|EH
alucian
Full Member
Offline
Posts: 225
Re: GWAPT passed...
«
Reply #7 on:
April 11, 2012, 11:59:03 AM »
Congrats!
And nice of you giving the practice exam!
Logged
CISSP ISSAP, CISM/A, GWAPT, GCIH, eCPPT, OSWP
knwminus
Full Member
Offline
Posts: 100
Re: GWAPT passed...
«
Reply #8 on:
April 11, 2012, 04:26:04 PM »
Congrats man! You certainly are destroying the GIAC exams. I am curious about your GSE date as well. You seem to have all of the required prereqs.
Also for those of us who would self study, do you a suggested book list?
Logged
A+ N+ CCNA CCNA:S CNSS 4011 Security+
Next Up: CCNP CCNP:S
docrice
Newbie
Offline
Posts: 27
Re: GWAPT passed...
«
Reply #9 on:
April 12, 2012, 12:03:59 AM »
Quote from: ajohnson on April 11, 2012, 07:31:28 AM
When are you scheduling that GSE written exam?
Maybe in a few years if I haven't gone insane from all this studying?
Quote from: ajohnson on April 11, 2012, 07:31:28 AM
Have you gone through the Web App Hackers Handbook (2nd)? If so, how did you feel it compared to the course? I'm thinking about challenging this one and would be interested in any recommendations for supplementary material outside of the course.
I actually just ordered WAHH and it's on my long back-logged to-read list. I figure I'll need additional reinforcement of the subject matter as well as a different perspective / author's voice.
Quote from: sil on April 11, 2012, 07:58:36 AM
Why don't you just knock GCED out of the way.
The GAWN and GPEN look more interesting, although I could certainly gain something from taking 501. The problem is that the latter looks very much like another generalist course, similar to 401 and getting the GSEC. I've always found the more specialized classes more interesting.
Quote from: hayabusa on April 11, 2012, 08:34:42 AM
If you're looking to part with the pracice exam, I might be interested.
I await your email message, per the rules above.
Quote from: knwminus on April 11, 2012, 04:26:04 PM
Also for those of us who would self study, do you a suggested book list?
After going through (I think) seven GIAC courses at this point, my general impression is that while one can certainly self-study the subjects and challenge GIAC exams directly, there are some things that the exams cover for which the information is well-noted in a specific SANS course.
Another way to put it is that since GIAC exams are pretty much based on the corresponding SANS material, you have a tactical home advantage with the SANS books in-hand. There's some "specialized knowledge" in those books which may not be directly available in the pages at the bookstore, although at the same time it's not proprietary stuff either. It's just that SANS packages a lot of things together and GIAC's coverage tends to be based on it.
I've never directly challenged GIAC exams without haven taken the relevant class first, although with some studying on the wireless side I could probably pass a GAWN attempt. I very much enjoy the challenge of scoring above 90% (which I've been lucky to accomplish on all my GIAC attempts so far) so taking the course fulfills a gap which I think is more important that attaining the title, although it also helps pad my resume with more somewhat-useless alphabet. That's a rant I'll save for another day.
We're fortunate enough to live in times where infosec books are a plenty. Instead of chasing more acronyms, I think I'd gain more right now by reading non-certification books and applying the knowledge into actual practice.
Logged
GSEC, GCFW, GCIA, GCIH, GWAPT, GAWN, OSWP, WCNA, CCNA, CCNA Security, [...and other resume filler]
Hopefully-useful stuff I've written:
http://kimiushida.com/bitsandpieces/articles/
hayabusa
Hero Member
Offline
Posts: 1631
Re: GWAPT passed...
«
Reply #10 on:
April 12, 2012, 07:20:29 AM »
LOL... Somehow, I skimmed right past the rules above.
I don't qualify, based on 'never having taken a GIAC exam.' Save it for another who needs it, and good of you to offer it up for someone.
Logged
~ hayabusa ~
"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'
OSCE, OSCP , GPEN, C|EH
ajohnson
Recruiters
Hero Member
Offline
Posts: 1057
aka dynamik
Re: GWAPT passed...
«
Reply #11 on:
April 12, 2012, 09:14:40 AM »
Quote from: docrice on April 12, 2012, 12:03:59 AM
Maybe in a few years if I haven't gone insane from all this studying?
Lame
Quote from: docrice on April 12, 2012, 12:03:59 AM
The GAWN and GPEN look more interesting, although I could certainly gain something from taking 501. The problem is that the latter looks very much like another generalist course, similar to 401 and getting the GSEC. I've always found the more specialized classes more interesting.
I've actually seen the majority of the material because I've written some questions for the exam, and GCED is pretty serious. They actually don't even allow it to be challenged because they feel there's too much detailed information in the course material. I asked for an exception because I can't take it for two years after writing questions for it, but no dice...
Quote from: hayabusa on April 12, 2012, 07:20:29 AM
LOL... Somehow, I skimmed right past the rules above.
I was thinking about calling you out on that, but I figured it was just OSCE brain-fry
Logged
WIP: GCFA |
www.infosiege.net
| @infosiege
The day you stop learning is the day you start becoming obsolete.
hayabusa
Hero Member
Offline
Posts: 1631
Re: GWAPT passed...
«
Reply #12 on:
April 13, 2012, 08:02:35 AM »
Quote from: ajohnson on April 12, 2012, 09:14:40 AM
I was thinking about calling you out on that, but I figured it was just OSCE brain-fry
<nod> Yep, it was. (That AND the added stress, now, of prepping to move, in 7 weeks, from Ohio to Texas...) But it's all good!
Logged
~ hayabusa ~
"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'
OSCE, OSCP , GPEN, C|EH
Xorcist
Newbie
Offline
Posts: 2
Re: GWAPT passed...
«
Reply #13 on:
April 15, 2012, 12:32:01 AM »
Congrats dude..
Me too cleared GWAPT last month and was very happy about it.
i felt i have shelled out a bomb to SANS for sec542.. I now wanted to take GPEN. Can anyone suggest me the right course to take for taking this certification. plzz do not point me to SANS again.
Logged
DWH
Newbie
Offline
Posts: 1
Re: GWAPT passed...
«
Reply #14 on:
August 15, 2012, 05:15:41 AM »
Hi All,
I am willing to go for Giac GWAPT exam and I am searching about free practice exams, Can anyone help?
If there are no fee exams, can anyone help about test king or something like that to practice?
Appreciate your response.
Logged
Pages: [
1
]
2
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
Programming
: Finished Python Course in Codecademy now what?
(11) by
securitian
OSCP - Offensive Security Certified Professional
: Failed my first attempt at the OSCP exam
(91) by
r0ckm4n
Tools
: Social-Engineer Toolkit (SET) Version 5.0 “The Wild West” Released
(2) by
m0wgli
Malware
: EICAR?
(3) by
UKSecurityGuy
Advisories
: HTB23154: Multiple Vulnerabilities in Exponent CMS
(0) by
AndyP
Advisories
: HTB23153: Multiple Vulnerabilities in Jojo CMS
(0) by
AndyP
Advisories
: HTB23151: Cross-Site Request Forgery (CSRF) in UMI.CMS
(0) by
AndyP
Tutorials
: Need guidance
(8) by
r0ckm4n
OSCP - Offensive Security Certified Professional
: Class Scheduled 6/8 - Linux n00b
(7) by
Taemyks
OSCP - Offensive Security Certified Professional
: OSCP exam scheduled
(6) by
gbhat
Incident Response
: LinkedIn Forensics
(0) by
AFENTIS_Forensics
General Certification
: Red Team/Blue Team
(1) by
ajohnson
Career Central
: Starter cert?
(3) by
Grendel
Network Pen Testing
: Beginner Ethical Hacker
(1) by
m0wgli
General Certification
: CPT Practical Submission
(0) by
z28power4u
Web Applications
: Nessus and Nikto
(4) by
Seen
Network Pen Testing
: Cracking salted MD5 hash
(4) by
n37sh@rk
CEH - Certified Ethical Hacker
: Passed my C|EH
(3) by
n37sh@rk
Mass Media
: EC-council hacked, irony at his best?
(0) by
j0rDy
Web Applications
: SQL Injection into an INSERT statement.
(6) by
eyenit0
Network Pen Testing
: Solution for sipXtapi INVITE Message CSeq Field Header Remote Overflow
(1) by
m0wgli
Web Applications
: dns
(2) by
H1t M0nk3y
Other
: BSides Boston
(0) by
3xban
Career Central
: InfoSec in Central, FL
(2) by
tturner
Web Applications
: Web vulnerability scanner
(4) by
H1t M0nk3y
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
Free Business and Tech Magazines and eBooks
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.