<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments for security.crudtastic.com</title>
	<atom:link href="http://security.crudtastic.com/?feed=comments-rss2" rel="self" type="application/rss+xml" />
	<link>http://security.crudtastic.com</link>
	<description>Security with added cheese</description>
	<lastBuildDate>Thu, 17 May 2012 19:02:30 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
	<item>
		<title>Comment on Ash&#8217;s mental thoughts going into the OSCP exam by Dudley</title>
		<link>http://security.crudtastic.com/?p=213&#038;cpage=1#comment-25528</link>
		<dc:creator>Dudley</dc:creator>
		<pubDate>Thu, 17 May 2012 19:02:30 +0000</pubDate>
		<guid isPermaLink="false">http://security.crudtastic.com/?p=213#comment-25528</guid>
		<description>Where should I send my scan results to?</description>
		<content:encoded><![CDATA[<p>Where should I send my scan results to?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Ash&#8217;s mental thoughts going into the OSCP exam by Dudley</title>
		<link>http://security.crudtastic.com/?p=213&#038;cpage=1#comment-25524</link>
		<dc:creator>Dudley</dc:creator>
		<pubDate>Thu, 17 May 2012 10:10:15 +0000</pubDate>
		<guid isPermaLink="false">http://security.crudtastic.com/?p=213#comment-25524</guid>
		<description>That would be great if you don&#039;t mind giving me a second opinion. I&#039;m sure I must have missed something.</description>
		<content:encoded><![CDATA[<p>That would be great if you don&#8217;t mind giving me a second opinion. I&#8217;m sure I must have missed something.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Ash&#8217;s mental thoughts going into the OSCP exam by ash</title>
		<link>http://security.crudtastic.com/?p=213&#038;cpage=1#comment-25522</link>
		<dc:creator>ash</dc:creator>
		<pubDate>Wed, 16 May 2012 20:46:10 +0000</pubDate>
		<guid isPermaLink="false">http://security.crudtastic.com/?p=213#comment-25522</guid>
		<description>Did you scan for both TCP and UDP, did you do some SNMP scans .. did you try throttling your nmap scans a bit? Did you version the services on the ports you found?

You only need to scan the servers that they have provided you .. theres no other systems to go for.

Did you want to email me your scans so I can see what you have and maybe give you some help?</description>
		<content:encoded><![CDATA[<p>Did you scan for both TCP and UDP, did you do some SNMP scans .. did you try throttling your nmap scans a bit? Did you version the services on the ports you found?</p>
<p>You only need to scan the servers that they have provided you .. theres no other systems to go for.</p>
<p>Did you want to email me your scans so I can see what you have and maybe give you some help?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Ash&#8217;s mental thoughts going into the OSCP exam by Dudley</title>
		<link>http://security.crudtastic.com/?p=213&#038;cpage=1#comment-25519</link>
		<dc:creator>Dudley</dc:creator>
		<pubDate>Wed, 16 May 2012 10:12:34 +0000</pubDate>
		<guid isPermaLink="false">http://security.crudtastic.com/?p=213#comment-25519</guid>
		<description>Yeah I did the course and thing I found was on exam that nmap scan yielded very few open ports. I&#039;m sure the boxes had firewalls. I got one with a buffer overflow and nadda after that one :-( Should I have scanned for other hosts that weren&#039;t being scored possibly?</description>
		<content:encoded><![CDATA[<p>Yeah I did the course and thing I found was on exam that nmap scan yielded very few open ports. I&#8217;m sure the boxes had firewalls. I got one with a buffer overflow and nadda after that one <img src='http://security.crudtastic.com/wp-includes/images/smilies/icon_sad.gif' alt=':-(' class='wp-smiley' />  Should I have scanned for other hosts that weren&#8217;t being scored possibly?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Ash&#8217;s mental thoughts going into the OSCP exam by ash</title>
		<link>http://security.crudtastic.com/?p=213&#038;cpage=1#comment-25518</link>
		<dc:creator>ash</dc:creator>
		<pubDate>Tue, 15 May 2012 20:59:34 +0000</pubDate>
		<guid isPermaLink="false">http://security.crudtastic.com/?p=213#comment-25518</guid>
		<description>Have you done the actual course? There&#039;s practice boxes in the lab for you to attack which are very similar to the machines for the final exam.

You need to scan all of your hosts, enumerate services, and then look at what vulnerabilities you can exploit. You may not be able to exploit a root vulnerability straight away, you may need to just get shell on the box and then do a local privilege exploit or something.

Go back to your manual and have a look at the process outlined in there for the best way to crack these boxes. Just because you see something obvious, it doesnt mean that its the answer .. you may find yourself going down a path that wont produce any results.</description>
		<content:encoded><![CDATA[<p>Have you done the actual course? There&#8217;s practice boxes in the lab for you to attack which are very similar to the machines for the final exam.</p>
<p>You need to scan all of your hosts, enumerate services, and then look at what vulnerabilities you can exploit. You may not be able to exploit a root vulnerability straight away, you may need to just get shell on the box and then do a local privilege exploit or something.</p>
<p>Go back to your manual and have a look at the process outlined in there for the best way to crack these boxes. Just because you see something obvious, it doesnt mean that its the answer .. you may find yourself going down a path that wont produce any results.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Ash&#8217;s mental thoughts going into the OSCP exam by Dudley</title>
		<link>http://security.crudtastic.com/?p=213&#038;cpage=1#comment-25517</link>
		<dc:creator>Dudley</dc:creator>
		<pubDate>Tue, 15 May 2012 10:10:08 +0000</pubDate>
		<guid isPermaLink="false">http://security.crudtastic.com/?p=213#comment-25517</guid>
		<description>I found this for hmailserver but could never get it to work maybe you could make some suggestions? My only guess is maybe I was doing something wrong when trying to do the exploit. Thanks 

http://www.exploit-db.com/exploits/7012/</description>
		<content:encoded><![CDATA[<p>I found this for hmailserver but could never get it to work maybe you could make some suggestions? My only guess is maybe I was doing something wrong when trying to do the exploit. Thanks </p>
<p><a href="http://www.exploit-db.com/exploits/7012/" rel="nofollow">http://www.exploit-db.com/exploits/7012/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Ash&#8217;s mental thoughts going into the OSCP exam by Dudley</title>
		<link>http://security.crudtastic.com/?p=213&#038;cpage=1#comment-25516</link>
		<dc:creator>Dudley</dc:creator>
		<pubDate>Tue, 15 May 2012 10:07:40 +0000</pubDate>
		<guid isPermaLink="false">http://security.crudtastic.com/?p=213#comment-25516</guid>
		<description>I was able to get app version but nmap was not able to get me an exact OS fingerprint :-( like in the case of hmailserver its running on either server 2003 or XP I suspect its server 2003. The filezilla beta are running on some version of freebsd and server 2003. Never messed with freebsd so not sure where to begin with that. I&#039;m pretty all the test machine were running a firewall due to the limited services and ports enumerated on them. Any suggestion would be greatly appreciated. Thanks Ash.</description>
		<content:encoded><![CDATA[<p>I was able to get app version but nmap was not able to get me an exact OS fingerprint <img src='http://security.crudtastic.com/wp-includes/images/smilies/icon_sad.gif' alt=':-(' class='wp-smiley' />  like in the case of hmailserver its running on either server 2003 or XP I suspect its server 2003. The filezilla beta are running on some version of freebsd and server 2003. Never messed with freebsd so not sure where to begin with that. I&#8217;m pretty all the test machine were running a firewall due to the limited services and ports enumerated on them. Any suggestion would be greatly appreciated. Thanks Ash.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Ash&#8217;s mental thoughts going into the OSCP exam by ash</title>
		<link>http://security.crudtastic.com/?p=213&#038;cpage=1#comment-25515</link>
		<dc:creator>ash</dc:creator>
		<pubDate>Tue, 15 May 2012 09:10:21 +0000</pubDate>
		<guid isPermaLink="false">http://security.crudtastic.com/?p=213#comment-25515</guid>
		<description>Well, Hopefully your scans are good enough to tell you what OSes and applications are installed on the machines in the exam. You could possibly rebuild this in your own lab environment now and work out what you need to do to root them.

That&#039;s where I would start my prep for a resit of the exam.

I wouldn&#039;t get too disheartened .. its a hard exam. One of my friends just passed it on the weekend .. and he struggled!</description>
		<content:encoded><![CDATA[<p>Well, Hopefully your scans are good enough to tell you what OSes and applications are installed on the machines in the exam. You could possibly rebuild this in your own lab environment now and work out what you need to do to root them.</p>
<p>That&#8217;s where I would start my prep for a resit of the exam.</p>
<p>I wouldn&#8217;t get too disheartened .. its a hard exam. One of my friends just passed it on the weekend .. and he struggled!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Ash&#8217;s mental thoughts going into the OSCP exam by Dudley</title>
		<link>http://security.crudtastic.com/?p=213&#038;cpage=1#comment-25512</link>
		<dc:creator>Dudley</dc:creator>
		<pubDate>Mon, 14 May 2012 11:57:00 +0000</pubDate>
		<guid isPermaLink="false">http://security.crudtastic.com/?p=213#comment-25512</guid>
		<description>So took the test and it kicked my butt. I got the buffer overflow written but struggled big time with other 4 machine. Thing is I&#039;m not sure where to start with preparing for retake. one of the server was running hmailserver which I&#039;m sure must have been vulnerable and the other box were runnin different version of FileZilla beta software but had no luck exploiting them at all LOL. Any helpful hints for preparing for retake would be great. Thanks a bunch</description>
		<content:encoded><![CDATA[<p>So took the test and it kicked my butt. I got the buffer overflow written but struggled big time with other 4 machine. Thing is I&#8217;m not sure where to start with preparing for retake. one of the server was running hmailserver which I&#8217;m sure must have been vulnerable and the other box were runnin different version of FileZilla beta software but had no luck exploiting them at all LOL. Any helpful hints for preparing for retake would be great. Thanks a bunch</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on CISM Study Notes by Shubhra</title>
		<link>http://security.crudtastic.com/?p=80&#038;cpage=1#comment-25508</link>
		<dc:creator>Shubhra</dc:creator>
		<pubDate>Sun, 13 May 2012 12:45:29 +0000</pubDate>
		<guid isPermaLink="false">http://security.crudtastic.com/?p=80#comment-25508</guid>
		<description>Thanks a lot for sharing the notes</description>
		<content:encoded><![CDATA[<p>Thanks a lot for sharing the notes</p>
]]></content:encoded>
	</item>
</channel>
</rss>

