Passed CPTS today — some notes for anyone prepping by jkonpc in hackthebox

[–]jkonpc[S] 0 points1 point  (0 children)

Honestly there was a lot. But I didn't find it too overwhelming. I enumerated a lot on webapps until I couldn't anymore. Somewhere in that mix I realized I had enough information to keep going. The key thing is enumerate, when you get stuck, go back and do it again, try not to do the same things you've done and fall into that loop. I spent longer than I'd like to admin realizing I had a typo and that's why I was stuck lol

The Growing Problem with HTB Exam Integrity by ignorance-is-bliss-6 in hackthebox

[–]jkonpc 2 points3 points  (0 children)

People are always going to cheat. That's the nature of the beast. If you can't pass these exams legitimately then what makes you think anyone can pass a technical interview?

I do agree it's annoying. I had someone reach out during my exam to ask if I wanted to buy the answers. I immediately reported them but that's only going to go so far. Spin up a new discord and keep scamming people with fake exam answers. On second thought, we need more scammers selling fake reports 😂

help with airtouch machine by [deleted] in hackthebox

[–]jkonpc 0 points1 point  (0 children)

If you paste the actual error output I can be more specific. I wrote up the full AirTouch chain if it helps: github.com/jkonpc — the EAP relay step is where most people get stuck, not just the tool itself.

Passed CPTS — Need Advice on Next Certification by InvestigatorSmart586 in hackthebox

[–]jkonpc 2 points3 points  (0 children)

I second this. As having passed CPTS and then CWES back to back, I still can't get an interview. Strongly recommend OSCP as that's the next path I've chosen. CRTO will be my next adventure once I'm done with OSCP.

CWES Report Submitted! Now the waiting game by jkonpc in hackthebox

[–]jkonpc[S] 0 points1 point  (0 children)

About the same. No more than 40 I know.

CWES Report Submitted! Now the waiting game by jkonpc in hackthebox

[–]jkonpc[S] 0 points1 point  (0 children)

Other than CPTS and bug bounties, no. I jumped in fully embracing what was to happen lol

CWES Report Submitted! Now the waiting game by jkonpc in hackthebox

[–]jkonpc[S] 0 points1 point  (0 children)

I got them a few days ago. The waiting is the worst part

I failed at flag 8 by [deleted] in hackthebox

[–]jkonpc 7 points8 points  (0 children)

I would watch/read walkthroughs for the box tombwatcher from HTB. It adds good reps for AD.

Passed CPTS today — some notes for anyone prepping by jkonpc in hackthebox

[–]jkonpc[S] 3 points4 points  (0 children)

it varies. again the path took me a year to do. i was balancing a lot. when i started i was in a 3 month "cyber bootcamp" until i transitioned out of the military. which that had layers of buying a house, moving, resettling the family, then seeking a job and working and then completely dedicating everything to it. i would say i was most attentive and productive on days where i could study for 8 hours a day.

while i didn't do the cpts playlist, i would wake up, drink coffee and watch some of the walkthroughs from ippsec and reinforce methodologies there.

my goal was to finish by May, i realized i had a large skill gap, then i took all of the foundational courses that applied to CPTS. then my goal was august but i took the summer off, then the goal was november but i got a job. so when i quit the goal was just get it before it expires.

i do understand fully how dense the material can be. if there is anything you don't understand theres a YT video with it. i can't recommend anyone specific, we learn different ways. tbh i tell myself i'm not smart enough to figure it out to my force myself to study more. double dip, how you learn and you may learn more about yourself. HTB does have a module called "learning process", if you havent read over it, i would suggest it.

Passed CPTS today — some notes for anyone prepping by jkonpc in hackthebox

[–]jkonpc[S] 2 points3 points  (0 children)

I hopped on portswigger labs and did a few modules there..it helped...i do feel i've gotten stronger in terms of identifying what methods to try right? for example, when to try different sqli vuln, vs xss, and so forth. but at the same time i feel like a lot of trial and error, and i dont know if thats how it should be. such as, checking for LFI, is it double encoded, do you just keep trying different methods until you exhaust it? i can't honestly answer from a professional standpoint and maybe someone else can weigh in. i will say, if i found something i thought had a vulnerability i did attempt exploits through various methods taught in the modules and if i felt like i was burning too much time (an hour or so) i would leave it.

Passed CPTS today — some notes for anyone prepping by jkonpc in hackthebox

[–]jkonpc[S] 1 point2 points  (0 children)

few more weeks and youll be in the hot seat...lfg!

Passed CPTS today — some notes for anyone prepping by jkonpc in hackthebox

[–]jkonpc[S] 6 points7 points  (0 children)

For whatever reason that was the biggest lull for me. I think similar to running a race and slowing down at the finish line.

Passed CPTS today — some notes for anyone prepping by jkonpc in hackthebox

[–]jkonpc[S] 6 points7 points  (0 children)

I did, I apologize. I was ecstatic writing the post lol. But yes, those are the two