My last post was all about Goals for 2012, and I will tell you I am already failing them. I have had a lot going on personally, nothing bad, just a lot going on right now.
The only thing I have completed so far is I took the Offensive Security Pentesting with Backtrack class.
I highly recommend taking this class to anyone who works in Information Security. If you think a pentest consist of running a vulnerability scan and then maybe using metasploit to pop a system, you MUST take this course.
What I enjoyed about this class was the chaos in the labs. Most classes have labs were you follow a set procedure and you have root/admin. In the real world a pentest is not like that. Basically you are given a network address and told to attack. From there you penetrate further into the network using any number of techniques.
After the lab time expires you can register for the certification exam. The certification exam is like the lab, a number of systems must be rooted in a 24 hour period.
After registration I was prepared to sit the exam. When doing a test like this, I know when you get stuck on something move on to something else can come back later. Additionally, take breaks often to mentally recharge. I always do this for these types of test, except this time. I spent 18 hours on one problem with one 10-minute break, and made stupid mistake after stupid mistake. I lost complete confidence in myself after this and went to bed wiped out. I got about 4 hours of sleep, and pounded away to finish up and promptly fail the exam.
Although I failed the exam I learned a lot during the experience, and I don’t mean technically. I plan to sit for the exam again in a couple of weeks, and this time I will much more prepared. This time, I am sitting a maximum 15 minutes on a problem and then moving on.
To summarize, on how to fail at a hands on certification, go in with a game plan and at the first issue throw out the game plan. Even though I failed the OSCP first time around, I will pass it. I failed the exam, not because I didn't know what to do, I failed it because I did not stick to my game plan. Next time I wont make that mistake.
Showing posts with label training. Show all posts
Showing posts with label training. Show all posts
Sunday, April 29, 2012
Tuesday, August 16, 2011
30 days and counting……
I have not blogged in a while because of various things going on. However I looked at calendar today and realized in 30 days I will be on a flight to Vegas for the lab!
My final month is all about lab time and doing the exercises from the GSEC, GCIA and GCIH classes. As I am doing the exercises it’s about doing them fast and right. The clock is ticking during the exam so I have to be fast and accurate. Tools that I am not proficient at are the tools that I am spending a lot of time on to make sure I understand them.
So with everything set this will be my last blog post until after the lab. I will not be able disclose details about the lab, but I will post when I am back.
Sunday, July 24, 2011
I am alive, GSE prep and SANS Network Security 2011 facilitator…..
My short absence from updating the blog is both sad and funny. I originally planned to skip one week because of short 3 day holiday with my wife and friends. While on holiday I received a phone call from my father explaining to me how he just broke his leg 500 miles from home! To complicate matters, my mother just had knee replacement surgery a few weeks earlier and was home in bed unable to do anything. So after returning from holiday I jumped on the next AA flight to COS to get my dad home to Kansas City. Once in KC I had to get my mom to a follow up surgery (she reinjured the new knee), and get my dad through his. My sister was a big help during this, but this family emergency through all kinds of wrenches in my GSE study plan. I returned to DFW earlier this week and started to catch up.
For GSE this week I spend time looking over the Incident Handling domain. I reviewed the incident handling process as defined by SANS:
Preparation
Identification
Containment
Eradication
Recovery
Lessons Learned
Additional areas covered in the IH domain include common attacks, malware and preserving evidence. Fortuantly I was able to get those areas covered as well. This week I hope to cover the ITSEC domain, OS security, secure communications, and protocols.
Turns out this week I was also accepted to facilitate FOR 610: Reverse Engineering Malware with Lenny Zeltser at SANS Network Security 2011 in Las Vegas. This is the first time I have done facilitating for a SANS course and will tell you I am very excited about the opportunity.
I should be back to posting once a week again, and after the GSE lab I plan on doing more technical and interesting blog posts!
Labels:
certification testing,
GSE,
malware analysis,
training
Wednesday, November 3, 2010
Completed OWSP challenge …………………and passed!
A few months ago I blogged about taking the Offensive-Security Wifu class, which can be found here. I finally completed the second part of the class and signed up for the challenge to get the Offensive Security Wireless Professional (OWSP).
The second part of the class, which had several videos with it, was focused on gathering information and using that information to attack wireless networks. The class focused on the different applications that make up the aircrack-ng suite of tools. After learning what you used the various tools for the put it all together to show how to crack WEP-OPN, WEP-SKA and WPA-PSK. They also discussed different ways to attack wireless networks that have no associated clients or very little network activity.
After completing the class I studied the lab material and ran through every attack scenario a few times to make sure I was able to successfully perform each type of attack. Once I was comfortable with all of the attack types I registered to take the OWSP challenge.
The OWSP exam is different than other certifications exams in which they ask you a question and you typically choice a multiple choice answer. For the OWSP I had to connect to a system on the Internet and perform a series of attacks to gain access to wireless networks within 4 hours. Once you complete the objectives you write up how you performed the attacks and they send you the answers back with-in 72 hours.
I started my exam on time, but ran into 1 technical issue. I contact exam support and the issue was resolved immediately. After the issue was resolved I went about my exam and completed all my objectives in about an hour and half. I should have been done sooner but I made a mistake on one attack that added about 20 minutes to the length of the exam. After completing my objectives I had 24 hours to prepare my documentation and turn in for grading.
I completed the documentation a couple of hours after the exam and sent off to be graded. I receive a confirmation they received the documentation and went about my business, expecting to hear back in a couple of days. This morning I was pleasantly surprised to receive an email stating that I had successfully passed my challenge and was certified as an OWSP.
If you have any interested in wireless security this is a great course to start off with, especially if you factor in the cost of the course and certification. If you need to take a wireless security course and have limited funds, this is a great course to take and I will recommend it to anyone.
The second part of the class, which had several videos with it, was focused on gathering information and using that information to attack wireless networks. The class focused on the different applications that make up the aircrack-ng suite of tools. After learning what you used the various tools for the put it all together to show how to crack WEP-OPN, WEP-SKA and WPA-PSK. They also discussed different ways to attack wireless networks that have no associated clients or very little network activity.
After completing the class I studied the lab material and ran through every attack scenario a few times to make sure I was able to successfully perform each type of attack. Once I was comfortable with all of the attack types I registered to take the OWSP challenge.
The OWSP exam is different than other certifications exams in which they ask you a question and you typically choice a multiple choice answer. For the OWSP I had to connect to a system on the Internet and perform a series of attacks to gain access to wireless networks within 4 hours. Once you complete the objectives you write up how you performed the attacks and they send you the answers back with-in 72 hours.
I started my exam on time, but ran into 1 technical issue. I contact exam support and the issue was resolved immediately. After the issue was resolved I went about my exam and completed all my objectives in about an hour and half. I should have been done sooner but I made a mistake on one attack that added about 20 minutes to the length of the exam. After completing my objectives I had 24 hours to prepare my documentation and turn in for grading.
I completed the documentation a couple of hours after the exam and sent off to be graded. I receive a confirmation they received the documentation and went about my business, expecting to hear back in a couple of days. This morning I was pleasantly surprised to receive an email stating that I had successfully passed my challenge and was certified as an OWSP.
If you have any interested in wireless security this is a great course to start off with, especially if you factor in the cost of the course and certification. If you need to take a wireless security course and have limited funds, this is a great course to take and I will recommend it to anyone.
Labels:
certification testing,
penetration testing,
scanning,
tools,
training,
wireless
Tuesday, August 24, 2010
Offensive- Security.com WiFu Training Class……………..
A couple of weeks ago I was looking at that the latest Backtrack release and decided to finally check out offensive-security.com. For those of you unfamiliar with offensive-security.com it is a training organization that uses Backtrack to teach penetration testing. It was founded by Mati Aharoni, creator of WHAX and a core developer of Backtrack.
Offensive-Security offers 3 training courses, Pentesting With Backtrack (PWB), Cracking the Perimeter (CTP), and Offensive-Security Wireless Attacks (WiFu). Upon successful completion of the course and hands on lab for that course you are awarded the OSCP(PWB Course), OSCE(CTP) or the OSWP(WiFu) certifications.
What makes these certifications challenging is they are not testing on your ability to memorize answers, they present you with a challenge and you must correctly complete the challenge in an allocated amount of time to be awarded the certification.
I did some online research and saw some really good reviews so I thought I would look into the cost of some classes. I was surprised by the cost ranging of the course, 350 USD for WiFu to 1500 USD for CTP with 60 days of lab access. Although I had done some wireless security work in the past I thought I would give the WiFu course a try.
I went through the registration process and received my course material in the allotted amount of time. The material included a PDF for the class, and some video tutorials. I would say the PDF (and the class) is broken up into two parts, the first is about wireless and wireless security, and the second is about attacking wireless.
I spent last week going over the first half of the class. Because I had not used my wireless skills in a long time this was a great refresher. This part of the class covered 802.11 standards, different wireless modes, different types of packets you will see on a wireless network, and how to choose hardware.
The hardware section was of great interest to me, because of the details it gave. In this section it covered different type of wireless adapters, chip sets, and antenna's details. This section gave some good details on how to choose wireless equipment for what you are testing.
The information in the first part of the class as been wonderful so far and I am looking forward to the "attacking" phase of the class. Once I get more into the attaching phase of the class I will post some more blogs about the class.
Offensive-Security offers 3 training courses, Pentesting With Backtrack (PWB), Cracking the Perimeter (CTP), and Offensive-Security Wireless Attacks (WiFu). Upon successful completion of the course and hands on lab for that course you are awarded the OSCP(PWB Course), OSCE(CTP) or the OSWP(WiFu) certifications.
What makes these certifications challenging is they are not testing on your ability to memorize answers, they present you with a challenge and you must correctly complete the challenge in an allocated amount of time to be awarded the certification.
I did some online research and saw some really good reviews so I thought I would look into the cost of some classes. I was surprised by the cost ranging of the course, 350 USD for WiFu to 1500 USD for CTP with 60 days of lab access. Although I had done some wireless security work in the past I thought I would give the WiFu course a try.
I went through the registration process and received my course material in the allotted amount of time. The material included a PDF for the class, and some video tutorials. I would say the PDF (and the class) is broken up into two parts, the first is about wireless and wireless security, and the second is about attacking wireless.
I spent last week going over the first half of the class. Because I had not used my wireless skills in a long time this was a great refresher. This part of the class covered 802.11 standards, different wireless modes, different types of packets you will see on a wireless network, and how to choose hardware.
The hardware section was of great interest to me, because of the details it gave. In this section it covered different type of wireless adapters, chip sets, and antenna's details. This section gave some good details on how to choose wireless equipment for what you are testing.
The information in the first part of the class as been wonderful so far and I am looking forward to the "attacking" phase of the class. Once I get more into the attaching phase of the class I will post some more blogs about the class.
Subscribe to:
Posts (Atom)