Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 40 guests and 1 member online
You are here:
Home
Ethical Hacking Discussions and Related Certifications
Network Pen Testing
OSCP - Offensive Security Certified Professional
PWB/OSCP course related question
EH-Net
May 24, 2013, 12:08:52 AM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Ethical Hacking Discussions and Related Certifications
>
Network Pen Testing
>
OSCP - Offensive Security Certified Professional
(Moderator:
don
) >
PWB/OSCP course related question
Pages: [
1
]
Go Down
« previous
next »
Print
Author
Topic: PWB/OSCP course related question (Read 6015 times)
0 Members and 1 Guest are viewing this topic.
blueaxis
Newbie
Offline
Posts: 44
PWB/OSCP course related question
«
on:
April 23, 2012, 01:50:20 PM »
PWB course discourages using tools like Nessus and Metasploit for exploting the lab machines. I am fine with it. My question is what should be the approach to find the vulnerabilities. Do you follow any pattern or just go through each service and test them manually? I appreciate if someone can give insights on how much time to spend on each host. The course examples use ftp fuzzing but I am not sure how to apply that technique to other services/ports that are open. Please share your thoughts.
Logged
ajohnson
Recruiters
Hero Member
Offline
Posts: 1057
aka dynamik
Re: PWB/OSCP course related question
«
Reply #1 on:
April 23, 2012, 03:00:04 PM »
Nmap version scanning would give you the most info the quickest. Then just research on exploit-db or the other vuln sites. If you run into problems with the results, you may need to dig a little deeper manually. For example, maybe the banner was changed and that's all nmap reviewed. In the case of a web server, try HTTPrint in addition to nmap.
Also, see if you can find another service that discloses information (i.e. snmp may show ports / processes).
Some may require manual review. Instead of there being a vuln with the web server, maybe you have to explore the web app (view source, etc.) to find the version of the app and see if it has any associated vulnerabilities with that.
I don't think you need to do any fuzzing unless you do the Extra Mile exercises in the exploitation module.
Logged
WIP: GCFA |
www.infosiege.net
| @infosiege
The day you stop learning is the day you start becoming obsolete.
blueaxis
Newbie
Offline
Posts: 44
Re: PWB/OSCP course related question
«
Reply #2 on:
April 23, 2012, 06:04:38 PM »
Thanks for posting your inputs. I like your views on the port 80 stuff.
Logged
impelse
Hero Member
Offline
Posts: 565
Re: PWB/OSCP course related question
«
Reply #3 on:
April 23, 2012, 06:34:09 PM »
I did to arrive to the lab yet, but I think the fuzzing is good. I am doing the extra mile and you begin to understand how to manage the exploit and modify it. This is showing me a good understanding how to attack machines no just copy and paste tools.
Logged
CCNA, Security+, 70-290, 70-291
CCNA Security
Taking Hackingdojo training
Website:
http://blog.thehost1.com/
TheXero
Full Member
Offline
Posts: 112
Try Harder!
Re: PWB/OSCP course related question
«
Reply #4 on:
April 24, 2012, 03:59:56 AM »
An important lesson I learnt was to make sure you check UDP ports as well as TCP.
Only checking the TCP could mean that you miss a critical vulnerability
Logged
OSCP | OSWP
www.thexero.co.uk
j0rDy
Hero Member
Offline
Posts: 590
Re: PWB/OSCP course related question
«
Reply #5 on:
April 24, 2012, 07:07:35 AM »
Quote from: TheXero on April 24, 2012, 03:59:56 AM
An important lesson I learnt was to make sure you check UDP ports as well as TCP.
Only checking the TCP could mean that you miss a critical vulnerability
if you only check TCP you are doing a half penetration test. ALWAYS check UDP!
Logged
ISC2 Associate, CEH, ECSA, OSCP, OSWP
earning my stripes appears to be a road i must travel alone...with a little help of EH.net
MaXe
Hero Member
Offline
Posts: 669
I've just upgraded myself to a cyborg muahahaa!!1
Re: PWB/OSCP course related question
«
Reply #6 on:
April 24, 2012, 02:19:29 PM »
Hint: TFTP and especially SNMP can be quite big sinners on any network.
Quote from: j0rDy on April 24, 2012, 07:07:35 AM
Quote from: TheXero on April 24, 2012, 03:59:56 AM
An important lesson I learnt was to make sure you check UDP ports as well as TCP.
Only checking the TCP could mean that you miss a critical vulnerability
if you only check TCP you are doing a half penetration test. ALWAYS check UDP!
I agree
Logged
I'm an InterN0T'er
blueaxis
Newbie
Offline
Posts: 44
Re: PWB/OSCP course related question
«
Reply #7 on:
April 24, 2012, 04:31:38 PM »
Thanks for sharing your views. I have seen people using the term "Low Hanging Fruit". Any tips how to identify these?
Logged
ajohnson
Recruiters
Hero Member
Offline
Posts: 1057
aka dynamik
Re: PWB/OSCP course related question
«
Reply #8 on:
April 24, 2012, 08:43:03 PM »
Quote from: blueaxis on April 24, 2012, 04:31:38 PM
Thanks for sharing your views. I have seen people using the term "Low Hanging Fruit". Any tips how to identify these?
You're going to have to rely on your intuition and experience here. Think about what *obvious* problems could be present with a given service. Does it require authentication? Maybe blank, default, or easily-guessable credentials are being used. Does the it disclose it's name and version? Check Exploit DB, maybe you can get a root shell by simply providing a script with the target IP address.
Logged
WIP: GCFA |
www.infosiege.net
| @infosiege
The day you stop learning is the day you start becoming obsolete.
blueaxis
Newbie
Offline
Posts: 44
Re: PWB/OSCP course related question
«
Reply #9 on:
April 24, 2012, 09:01:56 PM »
Thanks very much!
Logged
j0rDy
Hero Member
Offline
Posts: 590
Re: PWB/OSCP course related question
«
Reply #10 on:
April 25, 2012, 03:08:54 AM »
low hanging fruit refers to easily hackable hosts. Often these hosts can be hacked using automated attacks like DBautopwn or simple password guessing (root/toor) for example. Other hosts that require more skills are considered harder. My advice is look for the low hanging fruit in the labs first, do not worry about skipping a few hosts because they seem too hard, go for the hosts that seem fun/challenging and have a crack at those.
Logged
ISC2 Associate, CEH, ECSA, OSCP, OSWP
earning my stripes appears to be a road i must travel alone...with a little help of EH.net
amol_d
Newbie
Offline
Posts: 12
Re: PWB/OSCP course related question
«
Reply #11 on:
April 28, 2012, 09:24:08 AM »
WHen i was stuck and did not know how to proceed, I found it useful to look at videos on youtube and securitytube.net to see how others had approached similar problems. g0tmi1k.blogspot.com has a lot of videos as well, although the machines being hacked are totally different, when you see the videos you understand the approach that is taken from info gathering to validating possible vulnerabilities to getting a shell and the final privilege escalation. Once you understand the approach, it should help you progress faster
Logged
OSCP CISSP CSSLP CISA
Pages: [
1
]
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
News Items and General Discussion About EH-Net
: Change is Coming to EH-Net!!
(28) by
don
GCIH - GIAC Certified Incident Handler
: Passed my GCIH
(6) by
azmatt
Greetings
: Hi from the UK
(4) by
MrTuxracer
GCIH - GIAC Certified Incident Handler
: GCIH Free Practice test attempt
(0) by
prats84
Network Pen Testing
: AIX Vulnerability Assessments
(2) by
ras76
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.