Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 31 guests and 1 member online
You are here:
Home
Ethical Hacking Discussions and Related Certifications
Network Pen Testing
OSCP - Offensive Security Certified Professional
My OSCP journey...
EH-Net
May 26, 2013, 12:55:11 AM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Ethical Hacking Discussions and Related Certifications
>
Network Pen Testing
>
OSCP - Offensive Security Certified Professional
(Moderator:
don
) >
My OSCP journey...
Pages:
1
...
5
6
[
7
]
8
9
10
Go Down
« previous
next »
Print
Author
Topic: My OSCP journey... (Read 35117 times)
0 Members and 1 Guest are viewing this topic.
SecurityMonkey
Jr. Member
Offline
Posts: 89
Re: My OSCP journey...
«
Reply #90 on:
September 04, 2012, 08:52:35 PM »
Nice one! See told you not to give up :-)
Logged
www.securitymonkey.net
sternone
Full Member
Offline
Posts: 129
Re: My OSCP journey...
«
Reply #91 on:
September 04, 2012, 09:26:03 PM »
LOL!!!!!!!! Just rooted another one !!!
SERVER COUNT : 15 !!!!!!
Logged
Try harder....hmpf!!
jjwinter
Jr. Member
Offline
Posts: 76
Re: My OSCP journey...
«
Reply #92 on:
September 04, 2012, 09:27:36 PM »
Yar! Keep good notes. Make sure they says things other than "F-u #%@%!@ Server 14!"
Logged
SecurityMonkey
Jr. Member
Offline
Posts: 89
Re: My OSCP journey...
«
Reply #93 on:
September 04, 2012, 09:36:43 PM »
Dude your on FIRE!!!
Logged
www.securitymonkey.net
sternone
Full Member
Offline
Posts: 129
Re: My OSCP journey...
«
Reply #94 on:
September 04, 2012, 09:40:15 PM »
I can't anymore.. I really need sleep now ! haha
Strange, sometimes a buffer overflow that worked before is not working anymore.
I had it before, i reverted twice and then it worked again. Some exploits say in the code: this works only for 70% ...
Logged
Try harder....hmpf!!
SecurityMonkey
Jr. Member
Offline
Posts: 89
Re: My OSCP journey...
«
Reply #95 on:
September 04, 2012, 09:41:41 PM »
Quote from: sternone on September 04, 2012, 09:40:15 PM
I can't anymore.. I really need sleep now ! haha
Strange, sometimes a buffer overflow that worked before is not working anymore.
I had it before, i reverted twice and then it worked again. Some exploits say in the code: this works only for 70% ...
I guess it all has to do with memory locations.... and finding the right one!
Go to bed....
Logged
www.securitymonkey.net
shadowzero
Full Member
Offline
Posts: 120
It's a UNIX system, I know this!
Re: My OSCP journey...
«
Reply #96 on:
September 04, 2012, 09:57:19 PM »
Quote from: sternone on September 04, 2012, 09:40:15 PM
I can't anymore.. I really need sleep now ! haha
Strange, sometimes a buffer overflow that worked before is not working anymore.
I had it before, i reverted twice and then it worked again. Some exploits say in the code: this works only for 70% ...
Some exploits may take a couple of tries before it kicks in.
Logged
sternone
Full Member
Offline
Posts: 129
Re: My OSCP journey...
«
Reply #97 on:
September 05, 2012, 04:53:23 PM »
Rooted another one !!!!!
Maybe it is THE most important one.. because... THAT's what we wanna see right baby ??
SERVER COUNT : 16 !!
Logged
Try harder....hmpf!!
hayabusa
Hero Member
Offline
Posts: 1633
Re: My OSCP journey...
«
Reply #98 on:
September 05, 2012, 07:53:29 PM »
<grin> Looks 'slightly' interesting.
Logged
~ hayabusa ~
"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'
OSCE, OSCP , GPEN, C|EH
sternone
Full Member
Offline
Posts: 129
Re: My OSCP journey...
«
Reply #99 on:
September 06, 2012, 12:34:00 PM »
Routed another one.
One confession: This one box took me literally the whole day. That wasn't an easy one. Like a whole day.
Glad I rooted it.
I'm going to get into the tunneling stuff soon and might stop hacking the student network.
I can always come back and do the other servers anyway.
SERVER COUNT 17
Logged
Try harder....hmpf!!
ajohnson
Recruiters
Hero Member
Offline
Posts: 1060
aka dynamik
Re: My OSCP journey...
«
Reply #100 on:
September 06, 2012, 12:39:41 PM »
Quote from: sternone on September 06, 2012, 12:34:00 PM
One confession: This one box took me literally the whole day. That wasn't an easy one. Like a whole day.
It only gets worse. I went from rooting five per day at the start, to one every five days towards the end.
Quote from: sternone on September 06, 2012, 12:34:00 PM
I'm going to get into the tunneling stuff soon and might stop hacking the student network.
I can always come back and do the other servers anyway.
Not all systems exist in a bubble. Don't skimp on your research and info gathering.
Logged
WIP: GCFA |
www.infosiege.net
| @infosiege
The day you stop learning is the day you start becoming obsolete.
sternone
Full Member
Offline
Posts: 129
Re: My OSCP journey...
«
Reply #101 on:
September 06, 2012, 04:26:00 PM »
ROUTED ANOTHER ONE! SERVER COUNT 18
This was another nasty one. Buffer exploit days seems to be over...
It's all web script hacking and SQL injections from now on...
«
Last Edit: September 06, 2012, 04:29:27 PM by sternone
»
Logged
Try harder....hmpf!!
sternone
Full Member
Offline
Posts: 129
Re: My OSCP journey...
«
Reply #102 on:
September 07, 2012, 10:57:55 AM »
DAY 27
Routed another one: SERVER COUNT : 19
This was nasty again. No more low hanging fruit folks. I had to hack an application, then change a lot of settings in an application so I could finally have executed code.
Wow. Not easy and very time consuming.
Do all servers have multiple access ways ? Or is that only with a few ones ?
I'm also wanting to know exactly what tools you can use on the exam so I know what to practice with.
The lab is getting really harder now.
Logged
Try harder....hmpf!!
UNIX
Hero Member
Offline
Posts: 1235
Re: My OSCP journey...
«
Reply #103 on:
September 07, 2012, 11:04:02 AM »
Quote from: sternone on September 07, 2012, 10:57:55 AM
Do all servers have multiple access ways ? Or is that only with a few ones ?
I'm not sure if all, but when I did the labs I discovered on quite a few machines more than one way to get root/SYSTEM.
Logged
shadowzero
Full Member
Offline
Posts: 120
It's a UNIX system, I know this!
Re: My OSCP journey...
«
Reply #104 on:
September 07, 2012, 11:13:32 AM »
Some have more than one way. Some have red herrings. Some have only one way. The notorious ones, usually only have one way.
Logged
Pages:
1
...
5
6
[
7
]
8
9
10
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
OSCP - Offensive Security Certified Professional
: Failed my first attempt at the OSCP exam
(95) by
zeebee
News Items and General Discussion About EH-Net
: Change is Coming to EH-Net!!
(30) by
don
Tools
: Symbolic Exploit Assistant project is looking for collaborators
(0) by
galapag0
Greetings
: Hi from the UK
(5) by
prats84
GCIH - GIAC Certified Incident Handler
: Passed my GCIH
(9) by
prats84
Network Pen Testing
: Want a challenge? Want a GXPN practice exam?
(0) by
ajohnson
GCIH - GIAC Certified Incident Handler
: GCIH Free Practice test attempt
(1) by
prats84
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.