Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Trabisnikof
Dec 24, 2005

NevergirlsOFFICIAL posted:

" through an arduous twenty-four (24) hour certification exam."

holy moly

It is a lab based test so you have 24hrs to finish the lab and report, you don't actually have to spend all 24hrs testing

Adbot
ADBOT LOVES YOU

wyoak
Feb 14, 2005

a glass case of emotion

Fallen Rib
OSCP was the only course/exam track I've taken since college that was actually fun and didn't feel like a waste of time where getting the letters was the only real goal

maskenfreiheit
Dec 30, 2004

hackbunny posted:

I remember the time all internet was routed through Iceland, which IIRC would later be revealed by whistleblowers to have been a Tor deanonymization attack by the NSA

oooh interesting... got a source i'd like to read more about that

Agile Vector
May 21, 2007

scrum bored



ate all the Oreos posted:

the worst digimon

Daman
Oct 28, 2011
oscp takes like 8hrs max if you are familiar with msf(like not googling poo poo constantly) and already wrote your report template

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

Cocoa Crispies posted:

especially when it's a transcription error away from OCSP

I read it that way the first two times, figured it was a joke I wasn't getting.

maskenfreiheit
Dec 30, 2004

Daman posted:

oscp takes like 8hrs max if you are familiar with msf(like not googling poo poo constantly) and already wrote your report template

you can only use MSF on one machine

Diva Cupcake
Aug 15, 2005

you can still use msfvenom and multi/handler which should save time instead of dicking around with nc.

8 hours seems a bit aggressive though. most of the exam reviews i've read are in the 18-20 hours range to complete.

wyoak
Feb 14, 2005

a glass case of emotion

Fallen Rib
It took me about 11 hours to do the exam, then a couple more to compile the report, but I definitely wasted a couple hours on some wild goose chases

hackbunny
Jul 22, 2007

I haven't been on SA for years but the person who gave me my previous av as a joke felt guilty for doing so and decided to get me a non-shitty av

maskenfreiheit posted:

oooh interesting... got a source i'd like to read more about that

there were several separate incidents of bgp hijacks in 2013, where traffic was variously redirected to iceland, belarus, iran
an academic paper from 2014, and a 2015 followup describe how to attack tor with bgp

apparently though there's no hard, proven link between the bgp hijacks and nsa's long campaign against tor

maskenfreiheit
Dec 30, 2004

Diva Cupcake posted:

you can still use msfvenom and multi/handler which should save time instead of dicking around with nc.

8 hours seems a bit aggressive though. most of the exam reviews i've read are in the 18-20 hours range to complete.

wait whaaa

their training focuses a ton on not using msf... how can you use the msf handler w/o using ms? does handler == meterpreter,

or do you mean that you can use msfvenom to create, say, an windows shell payload?

Diva Cupcake
Aug 15, 2005

maskenfreiheit posted:

wait whaaa

their training focuses a ton on not using msf... how can you use the msf handler w/o using ms? does handler == meterpreter,

or do you mean that you can use msfvenom to create, say, an windows shell payload?
you can use msf but only certain modules. restrictions here...

https://support.offensive-security.com/#!oscp-exam-guide.md

quote:

You can only use Metasploit Auxiliary, Exploit, and Post modules against one target machine of your choice.

You may use the following against all of the target machines:
- multi handler (aka exploit/multi/handler)
- msfvenom
- pattern_create.rb
- pattern_offset.rb

Optimus_Rhyme
Apr 15, 2007

are you that mainframe hacker guy?

I just did my OSCP and you can only use meterpreter on one box. You *could* use multi/handler with -j on some port and have all your exploits connect to that (using shell_reverse_tcp in msfvenom) but at that point just use ncat or something in its own window with screen -L or somesuch.

TBH the Lab was ok but WAY out of date. Like, using exploits from 2008/2010 most of the time.

Took me about 18 hours all told. Mostly dead ends and jumping between boxes. Then another 4 hours on the report. And now I can add OSCP to my

maskenfreiheit
Dec 30, 2004

Diva Cupcake posted:

you can use msf but only certain modules. restrictions here...

https://support.offensive-security.com/#!oscp-exam-guide.md

Oh cool, so the handler basically keeps whatever session you set up with venom alive? Cool trick, I'll have to read up on that.


Optimus_Rhyme posted:

I just did my OSCP and you can only use meterpreter on one box. You *could* use multi/handler with -j on some port and have all your exploits connect to that (using shell_reverse_tcp in msfvenom) but at that point just use ncat or something in its own window with screen -L or somesuch.

TBH the Lab was ok but WAY out of date. Like, using exploits from 2008/2010 most of the time.

Took me about 18 hours all told. Mostly dead ends and jumping between boxes. Then another 4 hours on the report. And now I can add OSCP to my

ugh, makes me feel dumb - i got the 60 day, was hoping to finish in 30 before defcon then failed the exam (only got two boxes out of five). Then again, all my experience is academic so maybe that's not that bad...

i'm going to buy more lab time and try again in a month or two

maskenfreiheit fucked around with this message at 19:24 on Aug 30, 2017

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
there's apparently a new ublock origin for firefox that you have to remove and reinstall? lol https://twitter.com/ronindey/status/902645903210815489

endlessmonotony
Nov 4, 2009

by Fritz the Horse

anthonypants posted:

there's apparently a new ublock origin for firefox that you have to remove and reinstall? lol https://twitter.com/ronindey/status/902645903210815489

That's not an uBlock bug, it's a Firefox 55 bug they'll fix in Firefox 56, because they hosed up their own new extension system... again.

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

it's such a mess

fishmech
Jul 16, 2006

by VideoGames
Salad Prong

anthonypants posted:

there's apparently a new ublock origin for firefox that you have to remove and reinstall? lol https://twitter.com/ronindey/status/902645903210815489

it's a thing where it will ahve problems moving the database for ublock settings forward to the new storage setup. for some people it transfers fine for others it doesnt.

if you dont care about your previous settings, you can simply set up ublock again, pickign ur lists etc. if you happened to have a backup of previous settings you can reimport your filters and such

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

endlessmonotony posted:

That's not an uBlock bug, it's a Firefox 55 bug they'll fix in Firefox 56, because they hosed up their own new extension system... again.
lol

Pile Of Garbage
May 28, 2007



anthonypants posted:

there's apparently a new ublock origin for firefox that you have to remove and reinstall? lol https://twitter.com/ronindey/status/902645903210815489

yeah FF went to poo poo performance and stability wise after upgrading to v55 and removing/reinstalling ublock fixed it up.

still better than chome :chome:

FAT32 SHAMER
Aug 16, 2012



Shinku ABOOKEN posted:

it's me. i'm the guy using a saudi messaging program. *HASSAN CHOP is heard in the background, head rolls*

holy gently caress I totally forgot about that cartoon until this brought it all back

https://www.youtube.com/watch?v=OlMJfX_V6Ic

maskenfreiheit
Dec 30, 2004

cheese-cube posted:

yeah FF went to poo poo performance and stability wise after upgrading to v55 and removing/reinstalling ublock fixed it up.

still better than chome :chome:

freedom isn't free

Lutha Mahtin
Oct 10, 2010

Your brokebrain sin is absolved...go and shitpost no more!

https://www.youtube.com/watch?v=jbFiQvaXi6Q

Schadenboner
Aug 15, 2011

by Shine

I'm the Moka pot.

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
lmao

Midjack
Dec 24, 2007




lm rear end o

Wiggly Wayne DDS
Sep 11, 2010



On Dumpster diving, this is my opinion. I used to be in the food industry, I dropped out of Culinary school, most of the "food rules" we have are extremely conservative which makes sense for liability reasons. I've found over the past couple years that in my experience as long as my body doesn't reject the food it's most likely safe to eat. I assume it's the same thing as listening to my intuition and that in the beginning it's hard to tell what your reaction to the food is, but the more aware I've become of how I am, the more reliable my judgement is.

hackbunny
Jul 22, 2007

I haven't been on SA for years but the person who gave me my previous av as a joke felt guilty for doing so and decided to get me a non-shitty av

Schadenboner posted:

I'm the Moka pot.

a 3-cup pot by the looks of it, too. that's a lot of coffee for one person

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

she looks so happy :3:

Optimus_Rhyme
Apr 15, 2007

are you that mainframe hacker guy?



lol

Jimmy Carter
Nov 3, 2005

THIS MOTHERDUCKER
FLIES IN STYLE

you're doing it wrong http://www.ursaminorvehicles.com/campers/element-camper.html

hackbunny posted:

there were several separate incidents of bgp hijacks in 2013, where traffic was variously redirected to iceland, belarus, iran
an academic paper from 2014, and a 2015 followup describe how to attack tor with bgp

lol wasn't the Iran thing them trying to block Youtube by null-routing their IP block via BGP and they hosed up and advertised the route to the entire world

spankmeister
Jun 15, 2008






Jimmy Carter posted:

you're doing it wrong http://www.ursaminorvehicles.com/campers/element-camper.html


lol wasn't the Iran thing them trying to block Youtube by null-routing their IP block via BGP and they hosed up and advertised the route to the entire world

That was Pakistan.

Meat Beat Agent
Aug 5, 2007

felonious assault with a sproinging boner
https://twitter.com/taviso/status/902960795977318400

https://twitter.com/taviso/status/902961399164420096

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...
Fess up, which one of you did this

hobbesmaster
Jan 28, 2008

Jimmy Carter posted:

you're doing it wrong http://www.ursaminorvehicles.com/campers/element-camper.html


lol wasn't the Iran thing them trying to block Youtube by null-routing their IP block via BGP and they hosed up and advertised the route to the entire world

seems kinda expensive for not all that much extra space?

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
https://twitter.com/Icheyne/status/902966358480228352

maskenfreiheit
Dec 30, 2004

i'm the handwritten "personal and confidential" stamp

Proteus Jones
Feb 28, 2013




:drat:

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
one of our devs lost the ability to sftp to a customer's site to pull data and he's getting a "Key exchange failed." error from some garbage third-party .net sftp module, and he started getting this error after they updated their poo poo, but he came to me because his sftp was working against our servers, so he didn't believe anything was wrong on our end. eventually they told him to stop using a 1024-bit key so now his plan is to update the .net module he's been using.

Adbot
ADBOT LOVES YOU

akadajet
Sep 14, 2003


lol

  • Locked thread