start
Differences
This shows you the differences between two versions of the page.
Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
start [2022/12/20 00:44] – [Hack the Box] gman | start [2024/02/04 01:34] (current) – [Projects] gman | ||
---|---|---|---|
Line 6: | Line 6: | ||
Outside of work, when I have some of " | Outside of work, when I have some of " | ||
- | * I passed the CompTIA [[https:// | + | * A while I ago I passed the CompTIA [[https:// |
- | * I just passed the CompTIA [[https:// | + | * I then worked on and passed the CompTIA [[https:// |
- | * I'm currently looking at the [[https:// | + | * Most recently |
- | * I have a Python book I want to go through, too... and Offensive Security' | + | * Next, I have in mind TCM' |
**Do the Thing:** A recommendation from Daniel Miessler' | **Do the Thing:** A recommendation from Daniel Miessler' | ||
> If you've been studying and planning to do something cool for a long time, stop it. Do the thing. You can still study after you're doing it, but don't let the studying trick you into thinking you're accomplishing something. You're not. It's a trick. Do the thing. | > If you've been studying and planning to do something cool for a long time, stop it. Do the thing. You can still study after you're doing it, but don't let the studying trick you into thinking you're accomplishing something. You're not. It's a trick. Do the thing. | ||
+ | |||
+ | ---- | ||
+ | |||
+ | ===== LaTeX ===== | ||
+ | |||
+ | Thinking about using LaTeX for some writing I have on my back-burner. Learn by doing: | ||
+ | - Go through a quick tutorial | ||
+ | - Then use it for their writing projects you have in mind. | ||
+ | |||
+ | Resources: | ||
+ | * [[https:// | ||
+ | * [[https:// | ||
+ | * [[https:// | ||
+ | * [[https:// | ||
+ | * [[https:// | ||
+ | * [[https:// | ||
+ | * [[https:// | ||
+ | * [[https:// | ||
+ | * [[http:// | ||
---- | ---- | ||
Line 40: | Line 59: | ||
* [[https:// | * [[https:// | ||
- | ==== Projects ==== | ||
- | |||
- | - TryHackMe (PenTest+ Learning Track) | ||
- | - 101 Labs (PenTest+) | ||
- | - Sit for the PenTest+ Certification Exam | ||
- | - Then... CEH? | ||
---- | ---- | ||
- | ===== Udemy Recommendations ===== | ||
- | [[https:// | ||
- | Privilege Escalation is vital, and these two Udemy Courses are highly recommended for anybody pursuing OSCP or other similar penetration testing endeavors: | ||
- | * [[https:// | ||
- | * [[https:// | ||
- | |||
- | For Layer 7/ | ||
- | * [[https:// | ||
- | |||
- | The new 2020 OSCP material is good, but in my opinion, it lacks sufficient material to help students address Layer 7 attacks like dealing w/ MSSQL. Fortunately for me, I've been doing this for a while, and it was not difficult to proceed with some of the new lab machines that utilize MSSQL, but you could read in the student forum of people' | ||
- | |||
- | An example of where OSCP coursework fails to address some layer 7 would be "Hack The Box - Jarvis." | ||
- | * [[https:// | ||
- | |||
- | ---- | ||
- | |||
- | |||
- | ===== eJPT ===== | ||
- | |||
- | This certification is offered by [[https:// | ||
- | |||
- | The eJPT is the eLearnSecurity Junior Penetration Tester (eJPT) is a 100% practical certification on penetration testing and information security essentials. | ||
- | * It's called a " | ||
- | |||
- | The eJPT is currently in version 2 ([[https:// | ||
- | |||
- | **First:** previously, with the [[https:// | ||
- | * Everything you needed to pass the eJPT(v1) exam was covered in the [[https:// | ||
- | * You can still sign up for the Starter Pass (it's free) and in that free package, you can still take the PTS course. | ||
- | * Problem: The PTS will not prepare you for the eJPTv2. Just check out the differences in the courses offered by INE: | ||
- | | ||
- | 1. [[https:// | ||
- | * Difficulty: novice | ||
- | * Duration: 48.25 hrs | ||
- | * Activities: | ||
- | * Sections: 1 | ||
- | * Courses: | ||
- | * Videos: | ||
- | * Quizzes: 29 | ||
- | * Labs: 22 | ||
- | * Slides: | ||
- | |||
- | 2. [[https:// | ||
- | * Difficulty: novice | ||
- | * Duration: 144.1 hrs | ||
- | * Activities: | ||
- | * Sections: | ||
- | * Courses: | ||
- | * Videos: | ||
- | * Quizzes: 154 | ||
- | * Labs: 120 | ||
- | |||
- | So, as you can see by a quick comparison of the course overviews, the PenTest Student v2 has considerably more material and training than the free version offered in the Starter Pass. Andrew Roderos, in his [[https:// | ||
- | * The previous Penetration Testing Student (PTS) course was death by PowerPoint. | ||
- | * This new version is death by videos. | ||
- | * The exam is essentially the summary of all the labs included in the PTSv2 course. If you understood and did all the labs, you should be able to answer the eJPTv2 exam questions. | ||
- | |||
- | **Second:** You have two options for eJPTv2 training and exam... | ||
- | - [[https:// | ||
- | - You get the eLearnSecurity Junior Penetration Tester v2 Exam Voucher | ||
- | - Plus you get 3 months of Fundamentals Monthly for free (after 3 months, $39 per month, billed monthly) | ||
- | - If you can get the training in during the three months, you'll save $50.00 over the second option... | ||
- | - [[https:// | ||
- | - You get the eLearnSecurity Junior Penetration Tester v2 Exam Voucher (included in the annual subscription but **not** in the monthly subscription). | ||
- | - Plus you get a butt-ton of goodies (access to 8 different learning paths, including the Pentester Student that you need for the eJPT). | ||
- | |||
- | The eJPTv2 Exam Format: | ||
- | * 35 questions | ||
- | * 50 hours to complete (basically 2 days, compared to the 3 days you had with v1) | ||
- | * Dynamic exam | ||
- | * Hands-on exam | ||
- | |||
- | With all this in mind, I found a couple good articles with overviews, tips, advice, etc. | ||
- | * Bear in mind they are dated--they refer to the eJPTv1 that you could train and sit for with the free Starter Pass. | ||
- | * That ship has sailed. INE beefed up the training a lot, and they (rightfully so) are charging for it. You get what you pay for. | ||
- | |||
- | ---- | ||
- | |||
- | ==== Clark' | ||
- | |||
- | From [[https:// | ||
- | |||
- | I focused my energy on the Penetration Testing Basics & Penetration Testing Prerequisites sections. | ||
- | |||
- | === Initial Study Strategy (bad) === | ||
- | |||
- | I read all of the slides first. Then I watched all the videos. Then I attempted labs. I did this because I was intimidated by the labs and not for any strategic reasoning. | ||
- | * Looking back, I understand why I would get stuck - I didn’t practice the theory I learned or understand fully why I was learning it. I could have saved so much time if I had done the labs along with it. | ||
- | * I don’t recommend studying in the same order I did | ||
- | |||
- | === Study Recommendations === | ||
- | |||
- | I recommend starting with the goal of completing the labs. | ||
- | * Let’s be clear: If you are studying this, it is either to learn cyber security or to get that shiny eJPT certification. You cannot do either without hands-on experience. | ||
- | * You will need to spend a considerable amount of time in the lab environment in order to prepare yourself for the exam. | ||
- | * If you have the goal of completing a lab, you will pay better attention to the slides and videos leading up to it. | ||
- | |||
- | === Write Lab Reports === | ||
- | |||
- | I cannot stress this enough. | ||
- | * For each lab you do, create a report for yourself that includes common commands for the tool or technique you are learning, which commands you needed to complete the report, and any screenshots you have so you may replicate the outcome later. | ||
- | * Do this for every lab. | ||
- | |||
- | === Exam === | ||
- | |||
- | You can expect lessons from many of your labs coming in handy (and this is why you’ll want to create those reports). | ||
- | * The Programming prerequisites section will not be directly tested. | ||
- | * This module has great knowledge within it and can help you automate tasks, however, you can easily pass the exam without this section. | ||
- | |||
- | ---- | ||
- | | ||
- | ==== Kumar' | ||
- | |||
- | From [[https:// | ||
- | |||
- | === Study Guide === | ||
- | |||
- | Here are Kumar' | ||
- | - Complete all the labs from the section Penetration Testing Prerequisites section and Penetration Basics section. | ||
- | - Don't ignore the secret server lab from Penetration Testing Prerequisites. | ||
- | - Experience from https:// | ||
- | | ||
- | The above materials are more than enough to pass the exam. | ||
- | * You can avoid black-box labs if you don't feel like doing them. | ||
- | * But I recommend you to do it since it makes you familiar with the exam environment and you can practice without attempting the exam! | ||
- | |||
- | === Recommended Resources === | ||
- | |||
- | [[https:// | ||
- | * Cost is free (or $10/mo which I pay for now but didn’t at first) | ||
- | * Can reinforce skills and tools learned in PTS such as Nmap, BurpSuite, and Metasploit | ||
- | |||
- | [[https:// | ||
- | * Cost is nothing | ||
- | * John makes [[https:// | ||
- | * I enjoyed watching his videos because I had no experience in a Linux environment and watching someone else’s workflow helped me realize how simple it can be if I know the right shortcuts and commands | ||
- | |||
- | ---- | ||
==== Learning Paths ==== | ==== Learning Paths ==== | ||
Line 240: | Line 115: | ||
| | ||
At this time, the main Hack The Box platform and HTB Academy use separate accounts, so even you've already registered for Hack The Box, you'll need to make a separate account for Academy. | At this time, the main Hack The Box platform and HTB Academy use separate accounts, so even you've already registered for Hack The Box, you'll need to make a separate account for Academy. | ||
- | - [[https:// | + | - [[https:// |
- | - [[https:// | + | - [[https:// |
| | ||
Semi-helpful Blog Article: [[https:// | Semi-helpful Blog Article: [[https:// |
start.1671497061.txt.gz · Last modified: by gman