Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 44 guests and 1 member online
You are here:
EH-Net
May 23, 2013, 01:19:25 PM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Ethical Hacking Discussions and Related Certifications
>
Network Pen Testing
(Moderator:
don
) >
OSCE advice?
Pages:
1
[
2
]
Go Down
« previous
next »
Print
Author
Topic: OSCE advice? (Read 4320 times)
0 Members and 1 Guest are viewing this topic.
ajohnson
Recruiters
Hero Member
Offline
Posts: 1057
aka dynamik
Re: OSCE advice?
«
Reply #15 on:
February 06, 2013, 08:56:44 PM »
Quote from: DragonGorge on February 06, 2013, 08:35:55 PM
Well, like I said, after OSCP I took a hiatus to decompress. Time flies I guess.
How'd it go BTW? Did you write a review?
Totally understandable; I was just teasing
I'm way behind on a lot of reviews I want to write. The next 4-6 weeks are insane for me, so it'll be a bit longer still. I'll definitely post a link here when I have a chance to get to it though.
Suffice to say, it was both the most challenging and rewarding cert I've done.
Quote from: MaXe on February 06, 2013, 08:32:27 PM
Manual Shellcode:
http://www.exploit-db.com/wp-content/themes/exploit/docs/17065.pdf
Bypassing Anti-Virus Scanners:
http://www.exploit-db.com/wp-content/themes/exploit/docs/17066.pdf
MaXe, how many shells do you have from all of us opening those Intern0t PDFs?
Logged
WIP: GCFA |
www.infosiege.net
| @infosiege
The day you stop learning is the day you start becoming obsolete.
Dark_Knight
Sr. Member
Offline
Posts: 292
Re: OSCE advice?
«
Reply #16 on:
February 06, 2013, 10:20:20 PM »
Quote from: ajohnson on February 06, 2013, 07:20:28 PM
@DK: I assume you're not sending the shellcode because it doesn't make it there. Otherwise, that would be your first problem
You haven't got all the bad characters out, and even after that, you're not jumping back far enough. You'll currently land in the middle of the shellcode once you correct the characters.
x = ''
for i in range(0, 256):
x += "\\x%02x" % i
print x
will give you a list of all 256 hex bytes. To start, use that as your shellcode and just keep sending longer and longer lines until it doesn't work, and then strip out a character. I put a break point at the beginning of your jump back and then compared the bytes that were present with what I sent. You could also automate that with pydbg if you're feeling ambitious. There's an example in the courseware.
I seem to be missing something as it relates to jumping back into the stack. Currently I am jumping back approx. 512 bytes. I tried jumping back further but then I jump out of my allocated buffer.
Any help as it relates to jumping back?? Thats where I am having the problem..
Logged
CEH, OSCP, GPEN, GWAPT, GCIA
http://sector876.blogspot.com
MaXe
Hero Member
Offline
Posts: 669
I've just upgraded myself to a cyborg muahahaa!!1
Re: OSCE advice?
«
Reply #17 on:
February 06, 2013, 11:03:06 PM »
Quote from: DragonGorge on February 06, 2013, 08:35:55 PM
Quote from: ajohnson on February 06, 2013, 08:27:40 PM
Hm, maybe you just need to visit the forum more frequently; it said GCIA for about the last six weeks.
I put a very intense 4-6 months into the OSCE, so it's not like I just breezed through it.
Well, like I said, after OSCP I took a hiatus to decompress. Time flies I guess.
How'd it go BTW? Did you write a review?
No, but I did:
https://forum.intern0t.org/blogs/maxe/95-cracking-perimeter-part-1.html
https://forum.intern0t.org/blogs/maxe/101-cracking-perimeter-part-2.html
https://forum.intern0t.org/blogs/maxe/108-cracking-perimeter-part-3.html
https://forum.intern0t.org/blogs/maxe/111-cracking-perimeter-part-4.html
Quote from: ajohnson on February 06, 2013, 08:56:44 PM
Quote from: MaXe on February 06, 2013, 08:32:27 PM
Manual Shellcode:
http://www.exploit-db.com/wp-content/themes/exploit/docs/17065.pdf
Bypassing Anti-Virus Scanners:
http://www.exploit-db.com/wp-content/themes/exploit/docs/17066.pdf
MaXe, how many shells do you have from all of us opening those Intern0t PDFs?
A couple of thousand, people that appreciated reading them :-) I don't put bad stuff in my papers, code, pocs, etc.
(Some of them may have very basic anti script kiddie measures, but it's as simple as finding the field where I wrote: you have to uncomment this line or the script won't work.)
Logged
I'm an InterN0T'er
ajohnson
Recruiters
Hero Member
Offline
Posts: 1057
aka dynamik
Re: OSCE advice?
«
Reply #18 on:
February 06, 2013, 11:35:18 PM »
Quote from: Dark_Knight on February 06, 2013, 10:20:20 PM
I seem to be missing something as it relates to jumping back into the stack. Currently I am jumping back approx. 512 bytes. I tried jumping back further but then I jump out of my allocated buffer.
Any help as it relates to jumping back?? Thats where I am having the problem..
I put a break point at the beginning of the piece that jumps back and then stepped through it. After it actually made the jump, I was in the middle of the shellcode I used after all the Bs. This is how I went about it with what you already had, so maybe we're going about it in a different manner?
Code:
expl = "\x41" * 1271 + "\x42" * (517-len(shell_reverse_tcp)) + shell_reverse_tcp + jmp_esp + "\x90" * 50 + jmp_back + "\x90" * 361
I'd just start your jmp_back code with a break point, step through it, and see where you end up. I'm also on a different SP as I had to change the jmp esp value, so maybe there are other variables in play. When in doubt, break and step.
Quote from: MaXe on February 06, 2013, 11:03:06 PM
A couple of thousand, people that appreciated reading them :-) I don't put bad stuff in my papers, code, pocs, etc.
(Some of them may have very basic anti script kiddie measures, but it's as simple as finding the field where I wrote: you have to uncomment this line or the script won't work.)
Yea, they're great. I definitely referred to the AV bypass one as I was going through the course.
Logged
WIP: GCFA |
www.infosiege.net
| @infosiege
The day you stop learning is the day you start becoming obsolete.
H1t M0nk3y
Hero Member
Offline
Posts: 865
Re: OSCE advice?
«
Reply #19 on:
February 07, 2013, 09:30:12 AM »
MaXe and ajohnson, you are both gold mines!!!
Now I have a ton of things to read and practice.
BTW, do you guys know where I can get a WinXP VM that I can use in my lab? I am running a AMD64 Linux machine at home...
Thx
Logged
OSCP, GPEN, GWAPT, GSEC, CEH, CISSP
UNIX
Hero Member
Offline
Posts: 1235
Re: OSCE advice?
«
Reply #20 on:
February 07, 2013, 09:37:54 AM »
You could try these ones:
http://www.microsoft.com/en-us/download/details.aspx?id=11575
Logged
H1t M0nk3y
Hero Member
Offline
Posts: 865
Re: OSCE advice?
«
Reply #21 on:
February 07, 2013, 10:36:48 AM »
Quote
You could try these ones:
http://www.microsoft.com/en-us/download/details.aspx?id=11575
Great thanks UNIX! You too (and many more here) are a gold mine!!
I have also found this
http://www.mydigitallife.info/how-to-convert-and-import-vhd-to-vmdk-vmware/
to convert these VHD to VMWare VMDK format.
Update: The last step:
http://hacktolive.org/wiki/Using_VMware_images_%28.vmdk_files%29
«
Last Edit: February 08, 2013, 09:52:50 AM by H1t M0nk3y
»
Logged
OSCP, GPEN, GWAPT, GSEC, CEH, CISSP
DragonGorge
Jr. Member
Offline
Posts: 83
Re: OSCE advice?
«
Reply #22 on:
February 07, 2013, 04:43:36 PM »
Quote from: MaXe on February 06, 2013, 11:03:06 PM
No, but I did:
https://forum.intern0t.org/blogs/maxe/95-cracking-perimeter-part-1.html
First off...I had to read the beginning of your review/blog twice...you took OSCE not having taken the OSCP?!?!
Whoa! I have to give you the Wayne's World "We're not worthy" bow.
Great review. One thing I noticed was that the writing in the beginning differed from the end which seemed much more frenetic - I attributed it to an abuse of Red Bull that Offsec seems to demand. Could also be all those exploded brain cells from the class/exam.
Also, noticed the line "I passed and nothing could ruin my mood. Ex was whining, angry customers, and heaps more bad stuff going on...." Earlier you wrote "my girlfriend understood me...." Couldn't help but wonder if the "ex" status was attributable to the OSCE. I know my SO was more than fed up by the end of the OSCP.
Again, great review.
Logged
MaXe
Hero Member
Offline
Posts: 669
I've just upgraded myself to a cyborg muahahaa!!1
Re: OSCE advice?
«
Reply #23 on:
February 07, 2013, 08:46:15 PM »
Indeed I did DragonGorge, and it was also my first course and certification I had ever taken, plus I don't have any lengthy education, or for that sake, a long history of relevant business experience. (Of course, as I am a community guy, I've been in the hacking world for a long time.)
Yea, during the course and the certification it became increasingly harder, hence the reason the writing style changed to display my frustration
I'd say it's exploded brain cells, it was nice to be in several scenarios where you have to think outside the box and come up with clever solutions
Well, in the beginning she said she understood I had to study most evenings where I could be at her place 10pm or so. After a couple of weeks the whining began, but during the actual exam I had specifically told no whining as I will lose concentration completely, she respected that and I am glad she did.
Afterwards though, she began to whine again but that day when I got the email, nothing could as previously said, ruin my mood. Passing a certification is just a great feeling when it's been a long and hard journey.
The reason she became my ex, was not related to OSCE, even though it could've been a cool story
"The only certification that will make your wife or girlfriend leave you" xD (I broke up with her, as I realised I now had OSCE and didn't need a girlfriend, jk, it was for other personal reasons
In short, she was bad for me (I know that most women complain about a lot of things (because it's socially accepted in most cultures), but this one was over level 9000), but it's the kind of bad that feels a little good hehe )
Thanks for the feedback / response, I enjoyed writing it :-)
Logged
I'm an InterN0T'er
cd1zz
Hero Member
Offline
Posts: 561
Re: OSCE advice?
«
Reply #24 on:
February 07, 2013, 10:32:04 PM »
@H1t M0nk3y
OSCE is hard. Best advice I can give looking back is to simply practice. I used to go to exploit db, pull down exploits, strip out all the stuff in the middle and start with a simple crash. From there, rebuild the exploit. If you do that 100 times, you're in good shape
The course material is merely supplemental to what's needed for the exam, assuming you have no experience prior. Go for it though, even if you fail, keep going because it's really really good stuff. You'll eventually get it.
Logged
OSCE | OSCP | GXPN | OSWP | CISSP
http://www.pwnag3.com
http://www.networkadminsecrets.com
hayabusa
Hero Member
Offline
Posts: 1633
Re: OSCE advice?
«
Reply #25 on:
February 08, 2013, 08:07:00 AM »
Quote from: cd1zz on February 07, 2013, 10:32:04 PM
@H1t M0nk3y
OSCE is hard. Best advice I can give looking back is to simply practice. I used to go to exploit db, pull down exploits, strip out all the stuff in the middle and start with a simple crash. From there, rebuild the exploit. If you do that 100 times, you're in good shape
The course material is merely supplemental to what's needed for the exam, assuming you have no experience prior. Go for it though, even if you fail, keep going because it's really really good stuff. You'll eventually get it.
Great advice, there. Sums it all up, nicely. Even IF you fail the first time (MOST but not all of us did), it opens your eyes, and you'll definitely nail it on a second go, because you'll be confident. But if you follow cd1zz, ajohnson and MaXe's advice, you'll do well.
Logged
~ hayabusa ~
"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'
OSCE, OSCP , GPEN, C|EH
H1t M0nk3y
Hero Member
Offline
Posts: 865
Re: OSCE advice?
«
Reply #26 on:
February 08, 2013, 08:14:51 AM »
Thank you all for these great advice.
I have a pretty good idea now about what to do for exploit development. But what about the web apps and the network sections? Any advice on these two topics?
«
Last Edit: February 08, 2013, 09:04:58 AM by H1t M0nk3y
»
Logged
OSCP, GPEN, GWAPT, GSEC, CEH, CISSP
UNIX
Hero Member
Offline
Posts: 1235
Re: OSCE advice?
«
Reply #27 on:
February 08, 2013, 08:39:55 AM »
The sections about web application and network security are rather short, as the focus of the CTP course lies within application security. Being a web developer you already have a good background, so I'd just recommend to play around with some of the many available
vulnerable VMs
, if you want some further practice. If you haven't already read it, I'd also recommend
The Web Application Hacker's Handbook
in order to get a good overview on the subject.
In terms of the network security section, you could look into something like
GNS3
.
Logged
Pages:
1
[
2
]
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
Calendar Of Events
: CONFidence 2013
(1) by
factoragree
GCIH - GIAC Certified Incident Handler
: Passed my GCIH
(3) by
H1t M0nk3y
Greetings
: Hi from the UK
(3) by
UKSecurityGuy
GCIH - GIAC Certified Incident Handler
: GCIH Free Practice test attempt
(0) by
prats84
News Items and General Discussion About EH-Net
: Change is Coming to EH-Net!!
(27) by
don
Network Pen Testing
: AIX Vulnerability Assessments
(2) by
ras76
Tutorials
: Need guidance
(9) by
hanyhasan
Programming
: Finished Python Course in Codecademy now what?
(15) by
hanyhasan
Network Pen Testing
: Ruby on Rails Vulnerabilities / Attacks in BackTrack 5 r3
(0) by
SUdoctstudent
Network Pen Testing
: De-ICE 1.140 released!
(2) by
superkojiman
General Certification
: CPT Practical Submission
(1) by
UNIX
OSCP - Offensive Security Certified Professional
: Failed my first attempt at the OSCP exam
(94) by
azmatt
Tools
: Social-Engineer Toolkit (SET) Version 5.0 “The Wild West” Released
(2) by
m0wgli
Malware
: EICAR?
(3) by
UKSecurityGuy
Advisories
: HTB23154: Multiple Vulnerabilities in Exponent CMS
(0) by
AndyP
Advisories
: HTB23153: Multiple Vulnerabilities in Jojo CMS
(0) by
AndyP
Advisories
: HTB23151: Cross-Site Request Forgery (CSRF) in UMI.CMS
(0) by
AndyP
OSCP - Offensive Security Certified Professional
: Class Scheduled 6/8 - Linux n00b
(7) by
Taemyks
OSCP - Offensive Security Certified Professional
: OSCP exam scheduled
(6) by
gbhat
Incident Response
: LinkedIn Forensics
(0) by
AFENTIS_Forensics
General Certification
: Red Team/Blue Team
(1) by
ajohnson
Career Central
: Starter cert?
(3) by
Grendel
Network Pen Testing
: Beginner Ethical Hacker
(1) by
m0wgli
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
Free Business and Tech Magazines and eBooks
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.