Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 44 guests and 1 member online
 
Advertisement

You are here: Home arrow Ethical Hacking Discussions and Related Certificationsarrow Network Pen Testingarrow OSCP - Offensive Security Certified Professionalarrow OSCP - Two weeks in.
EH-Net
May 22, 2013, 09:20:40 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1] 2 3   Go Down
  Print  
Author Topic: OSCP - Two weeks in.  (Read 14104 times)
0 Members and 1 Guest are viewing this topic.
Catalyst256
Newbie
*
Offline Offline

Posts: 23



View Profile WWW
« on: August 06, 2012, 10:15:50 AM »

Hi guys, I started my OSCP journey a couple of weeks ago. I'm really enjoying it and still working out the best way to approach it. I've watched some of the videos and read a lot of the PDF but spent more time working on the lab machines.

I've managed to "pop" a few of the student lab boxes but struggle with privilege escalation and re-compiling the exploits.

Nothing worth getting stressed about, it all's part of the learning curve and I'm having an awesome time..  Grin
Logged

@catalyst256

Security+ OSCP VCP CCA
Jamie.R
Sr. Member
****
Offline Offline

Posts: 429


View Profile
« Reply #1 on: August 06, 2012, 10:33:59 AM »

It sounds like you doing fine there are a few good blogs on privilege escalation.

Might want look at
g0tmi1k blog
pentestermonkey
Logged

OSWP | Hackingdojo Nidan | eCPPT
Catalyst256
Newbie
*
Offline Offline

Posts: 23



View Profile WWW
« Reply #2 on: August 06, 2012, 10:36:00 AM »

Cool thanks I will check them out..
Logged

@catalyst256

Security+ OSCP VCP CCA
ajohnson
Recruiters
Hero Member
*
Offline Offline

Posts: 1057


aka dynamik


View Profile WWW
« Reply #3 on: August 06, 2012, 12:44:09 PM »

You'll often need to look at the exploit and try to figure out what it's specifically trying to do. You may find your kernel version falls within the range of a lot of public exploits, but there may be other conditions or subtleties that need to be analyzed in order to determine if a given exploit will compile and execute successfully.

Be sure to review other privilege services and pillage the system to the extent you're able to as well.
Logged

WIP: GCFA | www.infosiege.net | @infosiege

The day you stop learning is the day you start becoming obsolete.
Catalyst256
Newbie
*
Offline Offline

Posts: 23



View Profile WWW
« Reply #4 on: September 27, 2012, 07:00:19 AM »

Rather than posting on here all the time (yes I know its a forum and that's the point), I've been updating my blog on my progress.

Check it out if you are interested:

http://itgeekchronicles.co.uk
Logged

@catalyst256

Security+ OSCP VCP CCA
hayabusa
Hero Member
*****
Offline Offline

Posts: 1632



View Profile
« Reply #5 on: September 27, 2012, 07:41:42 AM »

Looks good, and I'm sure others will benefit from reading your experiences.  Thanks for the share.
Logged

~ hayabusa ~ 

"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'


OSCE, OSCP , GPEN, C|EH
tturner
Sr. Member
****
Offline Offline

Posts: 432


View Profile WWW
« Reply #6 on: September 27, 2012, 08:38:45 AM »

Rather than posting on here all the time (yes I know its a forum and that's the point), I've been updating my blog on my progress.

Check it out if you are interested:

http://itgeekchronicles.co.uk

I checked out your blog and found your Scapy guide. I haven't read the whole thing yet but so far I like! Great resource for folks trying to learn Scapy.
Logged

Certifications:
CISSP, CISA, GPEN, GWAPT, GAWN, GCIA, GCIH, GSEC, OPSE, CSWAE, CSTP, VCP

WIP: OSWP, GSSP-JAVA, GXPN

Udacity on hold, again. I suck.

http://sentinel24.com/blog  @tonylturner http://bsidesorlando.org
Catalyst256
Newbie
*
Offline Offline

Posts: 23



View Profile WWW
« Reply #7 on: September 27, 2012, 08:43:55 AM »

Glad you like it (so far) tturner. There will be more content added after my OSCP course is done and a special B-Sides London 2013 edition is in the works as well.
Logged

@catalyst256

Security+ OSCP VCP CCA
superkojiman
Jr. Member
**
Offline Offline

Posts: 60



View Profile WWW
« Reply #8 on: September 27, 2012, 09:17:18 AM »

Rather than posting on here all the time (yes I know its a forum and that's the point), I've been updating my blog on my progress.

Check it out if you are interested:

http://itgeekchronicles.co.uk

Looks good. I like reading about others' experiences in the course. You're correct about time flying by really quickly. I also took 90 days and finished with two weeks to spare for finishing up the report.

Good luck!
Logged

OSCP, GSEC
m0wgli
Full Member
***
Offline Offline

Posts: 248


View Profile
« Reply #9 on: September 27, 2012, 04:05:41 PM »

I've been following your blog for a while, and have been enjoying your OSCP updates. I've also read your Scapy guide and found it really useful, looking forward to the special B-Sides London 2013 edition.

Good luck!

@catalyst256 & @superkojiman: I'd be interested to hear a guestimate as to how many hours you invested over the 90 day's (@catalyst256 I appreciate you still have 30 to go) and a rough idea of how this broke down.

@superkojiman: I took a look at your blog too, you should update your profile to include it. Some good posts on there!
Logged

Security + | OSWP | eCPPT | CSTA
SecurityMonkey
Jr. Member
**
Offline Offline

Posts: 89



View Profile WWW
« Reply #10 on: September 27, 2012, 04:59:18 PM »

Awesome blog dude! Love your work.

Keep it up and good luck with the exam!
Logged

superkojiman
Jr. Member
**
Offline Offline

Posts: 60



View Profile WWW
« Reply #11 on: September 27, 2012, 08:02:55 PM »

@superkojiman: I took a look at your blog too, you should update your profile to include it. Some good posts on there!

Thanks Smiley

Regarding the number of hours I spent over the 90 day period, I would say about 8 hours on weekdays, and more on weekends. I work full time so I couldn't devote as much time as I wanted to the course. I took notes as I went through, and finished everything with two weeks to spare. Spent that time finalizing the report and going back to take screenshots or any other info that I may have missed. Overall, I still managed to have a bit of a life while taking the course.
Logged

OSCP, GSEC
Catalyst256
Newbie
*
Offline Offline

Posts: 23



View Profile WWW
« Reply #12 on: September 28, 2012, 01:02:34 AM »

Hey m0wgli,

I spend on average between 2-4 hours a day in the labs during the week and probably about 6-7 at the weekend. I will probably be pulling a few late nights during the last few weeks.

I have taken a few days off work and spent 12 hours each day in the lab which helped.

I tend to do research and mess around with VM's at work (just don't tell my boss). It's not as much time as I would like but that's life.
Logged

@catalyst256

Security+ OSCP VCP CCA
Jamie.R
Sr. Member
****
Offline Offline

Posts: 429


View Profile
« Reply #13 on: September 28, 2012, 04:07:22 AM »

Cool sounds like you are having a lot of fun. This course is on my list to do so any tips or feedback from you would be nice.
Logged

OSWP | Hackingdojo Nidan | eCPPT
m0wgli
Full Member
***
Offline Offline

Posts: 248


View Profile
« Reply #14 on: September 28, 2012, 04:32:06 AM »

@catalyst256 & @superkojiman: Thanks for the replies.
Logged

Security + | OSWP | eCPPT | CSTA
Pages: [1] 2 3   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.088 seconds with 24 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Free Business and Tech Magazines and eBooks

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.