Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 36 guests and 1 member online
 
Advertisement

You are here:
EH-Net
May 23, 2013, 03:24:53 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1] 2 3   Go Down
  Print  
Author Topic: SANS GXPN Review  (Read 9699 times)
0 Members and 1 Guest are viewing this topic.
cd1zz
Hero Member
*****
Offline Offline

Posts: 561


View Profile WWW
« on: October 22, 2012, 09:54:28 PM »

FWIW
http://www.pwnag3.com/2012/10/gxpn-review.html
Logged

azmatt
Jr. Member
**
Offline Offline

Posts: 78


View Profile WWW
« Reply #1 on: October 22, 2012, 11:33:08 PM »

Congrats!!!!

I took my first GCIH practice test yesterday and take the real one in two weeks so I'm in a SANS mood Smiley
Logged

GCFA, GCIH, GSEC, GCFE, CHFI
MaXe
Hero Member
*****
Offline Offline

Posts: 669


I've just upgraded myself to a cyborg muahahaa!!1


View Profile WWW
« Reply #2 on: October 23, 2012, 12:19:25 AM »

Grats  Grin I look forward to read the review  Smiley
Logged

I'm an InterN0T'er
UNIX
Hero Member
*****
Offline Offline

Posts: 1235


View Profile
« Reply #3 on: October 23, 2012, 12:37:03 AM »

Nice review - congrats, cd1zz!

What's next?
Logged
ajohnson
Recruiters
Hero Member
*
Offline Offline

Posts: 1057


aka dynamik


View Profile WWW
« Reply #4 on: October 23, 2012, 01:42:22 AM »

Nice review - congrats, cd1zz!

Yes, congrats and thanks. As someone who was on the fence as to whether I should pay for this myself, your feedback was definitely appreciated.


What's next?

Corelan Cool
« Last Edit: October 23, 2012, 01:23:13 PM by ajohnson » Logged

WIP: GCFA | www.infosiege.net | @infosiege

The day you stop learning is the day you start becoming obsolete.
SephStorm
Hero Member
*****
Offline Offline

Posts: 530


View Profile WWW
« Reply #5 on: October 23, 2012, 08:20:15 AM »

What I really appreciated was this article: http://www.pwnag3.com/2011/12/my-road-to-pen-testing.html

Thank you.
Logged

cd1zz
Hero Member
*****
Offline Offline

Posts: 561


View Profile WWW
« Reply #6 on: October 23, 2012, 08:45:44 AM »

@UNIX ajohnson is right. We're in the process of getting Peter from Corelan to come to the office for a brain melting two day training session.  I've got my eyes set on the OSWE and OSEE, if they don't kill me first.
Logged

UNIX
Hero Member
*****
Offline Offline

Posts: 1235


View Profile
« Reply #7 on: October 23, 2012, 08:53:40 AM »

Oh, that's great. Please be sure to write a review about his course too, as I'd be interested to read about how it is compared to CTP, AWE, and other similar courses. I'd also be interested to read about how much additional material is covered, which is not already present in his tutorials (like the module on Windows 8 ). He covers quite a few topics in a rather short amount of time, but so far all reviews I've read about his course were very positive.
Logged
cd1zz
Hero Member
*****
Offline Offline

Posts: 561


View Profile WWW
« Reply #8 on: October 23, 2012, 08:56:02 AM »

Yeah it's literally going to be crammed into two days, over a weekend. That's in December, I'll let you know...
Logged

Agoonie
Full Member
***
Offline Offline

Posts: 177



View Profile WWW
« Reply #9 on: October 23, 2012, 11:23:21 AM »

Congrats! Nice review! Always hard at work. When you get the OSEE/OSWE, I would love to know your thoughts on the courses. 
Logged

OSCE, OSCP, OSWP, CISSP, GPEN

www.agoonie.com
Dark_Knight
Sr. Member
****
Offline Offline

Posts: 292


View Profile WWW
« Reply #10 on: October 23, 2012, 11:59:05 AM »

Congratz...check pm

Couple questions:

Building a Metasploit Module:
The candidate will demonstrate a high-level understanding of how to create a Metasploit module


Q:How does this differ from the msf module in the OSCP?

Python and Scapy For Pen Testers   
The candidate will demonstrate an understanding of the ability to read and modify Python scripts and packet crafting using Scapy to enhance functionality as required during a penetration test

Q: How deep do you into using scapy?

Advanced Stack Smashing   The candidate will demonstrate an understanding of how to write advanced stack overflow exploits against canary-protected programs and ASLR
Q:Is this partial overwrite technique?

In terms of value for money which would you say would better suite a pentester the OSCE or GXPN?
« Last Edit: October 23, 2012, 12:03:19 PM by Dark_Knight » Logged

CEH, OSCP, GPEN, GWAPT, GCIA
http://sector876.blogspot.com
cd1zz
Hero Member
*****
Offline Offline

Posts: 561


View Profile WWW
« Reply #11 on: October 23, 2012, 02:25:24 PM »

Quote
Q:How does this differ from the msf module in the OSCP?
I took OSCP v3.0 and I don't recall any msf sections outside of basic usage. This the SANS module is only 15 pages but its more about porting an existing PoC to a msf module

Quote
Q: How deep do you into using scapy?
Pretty basic, but it will get you comfortable which is enough to probably do anything you want.

Quote
Q:Is this partial overwrite technique?
This is specific to *nix exploitation and walks through defeating Linux SSP. It's pretty cool stuff.

Quote
In terms of value for money which would you say would better suite a pentester the OSCE or GXPN?

Good question. I think if your goal is to become a better pen tester, definitely go with GXPN. There are a lot of practical techniques you can immediately walk away with and use. If your goal is to become a better exploit developer, go with both courses...
 
Logged

ajohnson
Recruiters
Hero Member
*
Offline Offline

Posts: 1057


aka dynamik


View Profile WWW
« Reply #12 on: October 23, 2012, 06:43:25 PM »

Also, if you're looking for more advanced MitM attacks (and haven't seen it already), check out Ryan Linn's DerbyCon talk where they embedded Lua in Ettercap. I haven't had a chance to play around with it personally, but it looks pretty cool.
Logged

WIP: GCFA | www.infosiege.net | @infosiege

The day you stop learning is the day you start becoming obsolete.
3xban
Hero Member
*****
Offline Offline

Posts: 608


View Profile WWW
« Reply #13 on: October 24, 2012, 04:07:37 PM »

Nice review man!  SANS courses are pretty decent (they better be for the cost).  That is really the only negative I have on them and the GIAC certs.
Logged

Certs: GCWN
(@)Dewser
alucian
Full Member
***
Offline Offline

Posts: 225



View Profile
« Reply #14 on: October 24, 2012, 08:35:36 PM »

woot!

Congrats! This one is no 2 or 3 on my SANS list.

Nice review!
Logged

CISSP ISSAP, CISM/A, GWAPT, GCIH, eCPPT, OSWP
Pages: [1] 2 3   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.581 seconds with 23 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.