Janne4 wrote: » Some people says it is easy (the course and the exam) but most people seem to think it is rather hard, at least what I have seen on forums and on blogs. I think those who say it is easy are those who are working as pentesters or have previous experience of such things. If you come from a programming background I think it is easier since much of pentesting is about finding, understanding and writing code (if you want to get good at pentesting). [...] I actually don't do this course because I want to be a pentester, I do it to learn and understand the methods and tools that is beeing used in the offensive field. I can see myself maybe working in a blue (defensive) team in the future, so an understanding of the red (offensive) side is good to have ; )
Janne4 wrote: » I also think that a mistake I have made is that I jump from attacking machine to machine instead of really focusing at one machine at a time. It is easy to start to explore Another machine when you get stuck or frustrated.
Janne4 wrote: » So, today finally the day came...my last day of lab access. I didn't think that I would have any time to spend in the labs today, had a busy day planned but my collegue got sick so suddenly I had a couple of hours at work I could use. No point in starting on a new machine at this stage, but I found two ways to access samba shares from Linux that I didn't know of before. I decided to start writing on my lab report while I still had some time left of my lab access in case I had forgotten to get or document something. Glad that I did, because when I started to list my proof files I found that I had missed to get two of these from machines I had previously compromised. Luckily I managed to get them before my time ran out. All in all I pwned 30 machines, all but one in the "public" lab network. Of these 19 were Windows machines and 11 Linux/Unix. I also had a shell on one more machine (Bethany) which I never succeeded to get priv escalation on, that machine will haunt me : ( On another machine I got the proof file but didn't have time to try and root it. Now it 's a couple days of report writing and then the 24 hour exam, and then some more report writing ; )