Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 40 guests online
Free Business and Tech Magazines and eBooks
You are here:
Home
Ethical Hacking Discussions and Related Certifications
Network Pen Testing
OSCP - Offensive Security Certified Professional
My OSCP journey...
EH-Net
May 18, 2013, 09:17:47 PM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Ethical Hacking Discussions and Related Certifications
>
Network Pen Testing
>
OSCP - Offensive Security Certified Professional
(Moderator:
don
) >
My OSCP journey...
Pages:
1
...
6
7
[
8
]
9
10
Go Down
« previous
next »
Print
Author
Topic: My OSCP journey... (Read 34627 times)
0 Members and 1 Guest are viewing this topic.
hayabusa
Hero Member
Offline
Posts: 1630
Re: My OSCP journey...
«
Reply #105 on:
September 07, 2012, 01:03:59 PM »
It's been said many times... the big tool note on the exam is Metasploit... You'll be given a limitation regarding its use. (How many times and on which boxes)
Aside of that, you should know we can't really give you a direct "this is what you should know how to use on the test"
I'll say this, though. Automation is your friend. You'll find you can accomplish more, faster, if you have automated some tests (either prepared before or during the exam), that you can be doing multiple things, at the same time. Just as in many real-world tests, you 'likely' won't have time to attack the exam boxes with a 'single-threaded' manner / mindset,
Make sure you're comfortable with BASH or some other scripting methods.
Logged
~ hayabusa ~
"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'
OSCE, OSCP , GPEN, C|EH
sternone
Full Member
Offline
Posts: 129
Re: My OSCP journey...
«
Reply #106 on:
September 08, 2012, 11:13:34 AM »
DAY 28
Rooted 2 more servers. But the big news is, I got the network key for the IT Department !!! There it was... I grabbed it and inserted it !!!
SERVERS ROUTED : 21
Logged
Try harder....hmpf!!
azmatt
Jr. Member
Offline
Posts: 76
Re: My OSCP journey...
«
Reply #107 on:
September 08, 2012, 02:04:23 PM »
You're killing it man!! Keep up the good work.
Logged
GCFA, GCIH, GSEC, GCFE, CHFI
SecurityMonkey
Jr. Member
Offline
Posts: 89
Re: My OSCP journey...
«
Reply #108 on:
September 08, 2012, 08:02:39 PM »
Got to say that this is one of the best threads about the OSCP on this forum. The blow by blow account is great!!!! As soon as I have finished moving house I plan on doing the PWB training!
Not sure I have the brains to do the cert but the training sounds great!
Logged
www.securitymonkey.net
azmatt
Jr. Member
Offline
Posts: 76
Re: My OSCP journey...
«
Reply #109 on:
September 08, 2012, 09:27:21 PM »
I'm in the same boat money. I know it's going to hurt but I'm going to try anyway. I just signed up for the ninja sec course to try to learn as much as possible pre PWB.
Logged
GCFA, GCIH, GSEC, GCFE, CHFI
sternone
Full Member
Offline
Posts: 129
Re: My OSCP journey...
«
Reply #110 on:
September 08, 2012, 10:15:40 PM »
I try to read as much as I can to know about tunneling now.
The OSCP is extremely frustrating in not guiding you where you should learn what. They only show you what you 'can' do and then it's up to you.
Ok, thanks OSCP, you showed me this now, and I understand what you're doing, but I have to learn more about it. Where and what should I learn exactly ? Oh.. try harder. There you go. Well I got some reply to you: fuck you too.
That sucks. Bigtime.
If I had knew, I would not started the lab before I would have read other books and done more experience. I would like to know if real newbies unexpierenced hackers really succeed in the test on the first try.
It's frustrating. While I am hacking myself true the lab succesfully, I'm frustrated in the pain it needs to figure things out myself without having some guidelines that are more than 'showing you what can be done'
Hacking is every time different, and how can you learn it by only seeing 1 example and then basically they tell you to go fuck yourself ?
As you can read from my post. I'm kind off sick of googling around and reading stupid blogs to try to learn something more in depth.
Logged
Try harder....hmpf!!
azmatt
Jr. Member
Offline
Posts: 76
Re: My OSCP journey...
«
Reply #111 on:
September 08, 2012, 10:24:21 PM »
Sorry you're hitting a rough spot man but you'be made a lot of progress and you'll make a lot more. You've hacked 21 more servers than me and most others here
Logged
GCFA, GCIH, GSEC, GCFE, CHFI
shadowzero
Full Member
Offline
Posts: 120
It's a UNIX system, I know this!
Re: My OSCP journey...
«
Reply #112 on:
September 08, 2012, 11:28:16 PM »
The course gives you the fundamentals. It's up to you to take it to the next level.
You're right, you can't learn or master anything from just one example. That's what the lab is for. Practice on it, make mistakes, learn from your mistakes. More importantly, expect to spend a lot of time doing research outside of the course material if you intend to hack into all the machines in the lab and pass the exam challenge.
Logged
sternone
Full Member
Offline
Posts: 129
Re: My OSCP journey...
«
Reply #113 on:
September 09, 2012, 01:45:59 AM »
2.44 AM
Ok, got a server rooted in the IT DEPT using tunneling.
That was cool stuff.
Is it normal that my typing is slower now ?
But I'm still pissed on Offensive Security on letting me read 100's of blogs of folks that can count their pubertal hairs on 1 hand.
Logged
Try harder....hmpf!!
sternone
Full Member
Offline
Posts: 129
Re: My OSCP journey...
«
Reply #114 on:
September 09, 2012, 01:48:19 AM »
That puts the servers rooted on 22
Logged
Try harder....hmpf!!
jjwinter
Jr. Member
Offline
Posts: 75
Re: My OSCP journey...
«
Reply #115 on:
September 09, 2012, 08:04:17 AM »
Continued thanks for the updates as you go through the labs. Nice job working through the tunneling problems.
You should submit your posts to a sleep deprivation study forum too.
Logged
shadowzero
Full Member
Offline
Posts: 120
It's a UNIX system, I know this!
Re: My OSCP journey...
«
Reply #116 on:
September 09, 2012, 08:52:10 AM »
Quote from: sternone on September 09, 2012, 01:45:59 AM
2.44 AM
Ok, got a server rooted in the IT DEPT using tunneling.
That was cool stuff.
Is it normal that my typing is slower now ?
But I'm still pissed on Offensive Security on letting me read 100's of blogs of folks that can count their pubertal hairs on 1 hand.
Not sure what blogs you're reading. There are blogs geared towards penetration testing written by professionals. You can always just read RFCs and white papers.
Logged
hayabusa
Hero Member
Offline
Posts: 1630
Re: My OSCP journey...
«
Reply #117 on:
September 09, 2012, 10:28:48 AM »
Quote from: sternone on September 09, 2012, 01:45:59 AM
But I'm still pissed on Offensive Security on letting me read 100's of blogs of folks that can count their pubertal hairs on 1 hand.
WTH are you talking about???
A.) Offensive Security 'letting' you read something, or 'making' you read something? What you see now is what you're going to see in real life. You'll often need some info on an exploit or topic and have to go find it. I don't recall Offensive 'making' me look at anything, in particular. Specifically if you're referring to blogs. Blogs are others' writings, not Offensive's.
Maybe you're just venting about something, but your vent just made no sense, as written...
Logged
~ hayabusa ~
"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'
OSCE, OSCP , GPEN, C|EH
ajohnson
Recruiters
Hero Member
Offline
Posts: 1056
aka dynamik
Re: My OSCP journey...
«
Reply #118 on:
September 09, 2012, 11:51:57 AM »
You're killing me, dude. If you just want walk-throughs of how to exploit systems, hop on SecurityTube and watch the videos. There is no shortage of that type of instruction available, and that is not remotely the purpose of this course.
What do you think a real pen test is like? Do you expect to be able to walk into an organization and completely understand how everything is configured, how their custom in-house applications work, etc., right off the bat?
You're currently working on what, 40-50 systems over 90 days? Try hundreds or thousands of systems over five days. There's always going to be weird stuff you've never encountered before, and you need to be able to adapt and get acclimated to that environment quickly. That gets stressful while dealing with fast-approaching deadlines. You can't just stop when you're burned out and return to a troublesome system after taking a weekend off.
While some of the non-standard configurations in this course are frustrating, there's probably more of that in the real world. Try dealing with NAC or other controls that'll shutdown or temporarily disable your switchport if triggered, or users (surprisingly) taking their system to IS when an exploit unexpectedly triggers an AV alert. Try adding the complexity of things that break after being subjected to a basic nmap scan; I've yet to visit a client that provides "revert" functionality (unless you count rebooting the system after yelling at the tester).
This type of work is rarely easy, things rarely go as expected, and you're never going to master everything. You can view this as challenging or frustrating, and I think your perspective will really determine how far you'll go professionally.
Logged
WIP: GCFA |
www.infosiege.net
| @infosiege
The day you stop learning is the day you start becoming obsolete.
shadowzero
Full Member
Offline
Posts: 120
It's a UNIX system, I know this!
Re: My OSCP journey...
«
Reply #119 on:
September 09, 2012, 12:42:40 PM »
This course is meant to be difficult, and I think those of us who've earned our OSCPs like it that way. The difficulty and hands-on aspect is what separates it from other certifications. Dumbing the course down waters down the reputation of the certificate.
You need to be able to think quickly, out of the box, and pull rabbits out of your hat. The exam will test you on that. Think of it as a black box test on an organization. No hints, no information before you step in. That's part of the challenge. Everything you learn in the lab, and out of the lab, will come in handy.
Logged
Pages:
1
...
6
7
[
8
]
9
10
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
General Certification
: CPT Practical Submission
(0) by
z28power4u
OSCP - Offensive Security Certified Professional
: Class Scheduled 6/8 - Linux n00b
(5) by
MrTuxracer
Career Central
: Starter cert?
(0) by
Alert
Web Applications
: Nessus and Nikto
(4) by
Seen
Tutorials
: Need guidance
(7) by
impelse
Malware
: EICAR?
(2) by
SephStorm
Network Pen Testing
: Cracking salted MD5 hash
(4) by
n37sh@rk
CEH - Certified Ethical Hacker
: Passed my C|EH
(3) by
n37sh@rk
Mass Media
: EC-council hacked, irony at his best?
(0) by
j0rDy
Web Applications
: SQL Injection into an INSERT statement.
(6) by
eyenit0
Network Pen Testing
: Solution for sipXtapi INVITE Message CSeq Field Header Remote Overflow
(1) by
m0wgli
Web Applications
: dns
(2) by
H1t M0nk3y
Other
: BSides Boston
(0) by
3xban
Career Central
: InfoSec in Central, FL
(2) by
tturner
Web Applications
: Web vulnerability scanner
(4) by
H1t M0nk3y
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.