After competing the eJPT, I finally pulled the trigger and signed up for eLearn Security’s eCPPT (Certified Professional Penetration Tester)

There is a ton of material to go through!

I mean, like a lot. Something around 7000 slides of information! So I didn’t want to waste anytime and jumped right in. And within the first twenty pages it starts to get pretty hairy, covering things like Assembly language basics, Registers, “the Stack” and more. This was in preparation of the infamous Buffer Overflow (BoF) requirement. But after researching a bit more, I realized that I wasn’t the only one that felt this sentiment and found helpful third party resources in the community to fully grasp Win 32 BoF’s. The best lab that I found was TryHackMe’s Overflow room. I also considered it a bad course flow to include the most complicated and painful section right at the beginning. But after I learned the basics through other sources, going back over their extensive material, including creating custom shell code in detail, I found it very useful.

I’m an avid note taker, so I started diligently copying nearly everything in the slides to a Cherry Tree document. Unlike the eJPT, I was not retaining or even understanding all of the content pretty early on. So I did what I do best, spending hours going down rabbit holes.

I really want to have a strong foundation in ethical hacking and want to make sure that I firmly get the basics down. So I didn’t want to move on until I really understood things like “the Stack”, registers, pointers, memory instructions and more. In order for me to become proficient with Buffer Overflows I needed to do a lot more research before diving too deep into the pdf.

As others have pointed out, starting the course with the nitty gritty world of Buffer Overflows and Assembly is a little discouraging. But I’m determined to power through it and not stop until I get it down.

Many of the labs had issues, or tools had been deprecated in Kali so some techniques covered in the course material didn’t work as explained. But to me, this was only an opportunity to learn from the past, and figure out how to exploit these vulnerabilities with modern and up to date tools. And in essentially every case, there was a way around these bumps in the road.

I can tell that the eCPPT isn’t going to be a “walk in the park” and is going to really be challenging yet rewarding course.

 

Privacy Preference Center