Posts

Showing posts from 2017

Prepping for OSCP: Walkthrough for LazySysAdmin

Image
Prepping for OSCP: Walkthrough for LazySysAdmin With a request in for approval to start my OSCP training, I decided I should probably get started on some write-ups for the VulnHub VMs I've done. So without further ado, here is my guide for how I rooted LazySysAdmin: Discovery The first step to any engagement, is to know in which network you will be working.  To figure this out, I ran an ifconfig to see which IP address I pulled from DHCP: Figure 1 IP Address of Attacking Machine So it looks like I’ll be working in the 192.168.56.0/24 subnet.  With this information in hand, I could look for other hosts on this subnet using netdiscover: Figure 2 Netdiscover Results with Hosts As you can see in Figure 2, there are a couple of hosts on the network.  192.168.56.1 is the gateway, with 192.168.56.100 being the DHCP server and 192.168.56.101 being our target machine. Enumeration With the network mapped out, it was time to see what was open on our ta...

DerbyCon 7.0 & Tyler Hudak's Intro to Malware Analysis

Image
Copyright DerbyCon 2017 DerbyCon VII: Legacy DerbyCon VII: Legacy just ended, and I have to say, it surpassed last year's experience.  Now, I'm pretty new to the professional infosec world having just accepted my current job in August of 2016.  Like most people in infosec will claim, I am an introvert, so meeting people is a rather daunting task.  One of the things I like to do being new to the professional infosec world is follow a few of the more prominent people on Twitter.  This led me to following Lesley ( @hacks4pancakes ), as well as Dave Kennedy ( @HackingDave ), who is the founder of DerbyCon.  Lesley posted a tweet asking for volunteers for the Root Beer Float social that took place on Saturday.  Determined to meet more people, I volunteered, and met a great group of individuals. The DerbyCon 7.0 Root Beer Float Crew! I even gathered up the courage to meet Dave, who is a wonderful, humble, and caring ind...