I Tried The HackTheBox Certified Pentester Exam
Key Takeaways
Takes the HackTheBox Certified Penetration Testing Specialist exam and shares tips and experiences
Full Transcript
I failed I took the hack the Box certified penetration testing specialist course and exam and I didn't pass I ran out of time at least that's the excuse I'm giving myself I was actually moving across the country and for some reason I thought that oh I'd be able to squeeze in taking a hacking exam and that didn't go so well so hey in full transparency hack the box and hack the Box Academy paid for a review and some promotion of their cpts course and exam and this is a sponsored video but it's a little bit different because I didn't pass if you aren't familiar the hack the Box cpts brings you up to speed as an intermediate penetration tester and ethical hacker you learn all about different vulnerabilities you learn how to craft your own exploits you go through privilege escalation and active directory and all this cool crazy stuff it's a lot of material and it's all super high quality material but you need to have time that you can dedicate to it the cpts course itself is the penetration tester job roll path on hack the Box Academy it's super cool you learn through all these different modules it is text based but with lots of labs and exercises and activities to get you Hands-On But ultimately comes the exam the exam itself simulates a real world penetration test from the outside in right looking at the external attack surface and then getting in with an initial foothold and compromise and then getting the lay of the lands between Windows machines Linux machines and active directory environment and it's all real world in modern infrastructure with multiple machines to move through you have 10 full days to go through the exam and write a thorough professional commercial grade report and you even have a free retake with one purchase of the exam voucher and I know what you might be thinking I know you might be thinking whoa those 10 days are super generous compared to a whole lot of others hey you don't have a whole lot of time 10 days feels like a lot of time now I will be the first to say especially while trying to juggle like real life and normal obligations that it's even then not a whole lot of time cuz remember that penet ation tester job path on hack the Box Academy the core of the cpts course is like what 41 hours long of content and there's a lot to it the exam covers a vast majority if not almost everything that's covered in the course that's a blessing and a curse because hey you're going to be taking a test on everything that you've learned but you're going to be taking a test on everything that you've learned with that let me throwing a little nugget here when you're taking the exam when you're going through the cpts Capstone challenge here you use the global search within the hack the Box Academy especially when you run into some service or some technology or one kind of software that you're like oh I remember going through this I remember reading it but I don't know the exact commands right off the rip to be able to go ahead and beat up the service use the search functionality it will save your bacon trust me it did for me well sort of in the moment so I got about maybe 30% 40% I don't know if I'm being generous through the exam content and materials I had gained access and was inside of the internal Network and was starting to go enumerate active directory and then life got ahead of me and I couldn't pull it off but even in those steps to get into the environment I could tell man this exam has some grit to it I do want to absolutely emphasize and I think hack the Box takes a lot of pride in this and they say look this is not a CTF it's not a capture of the flag it's not something where you hey pull a vulnerability off the shelf maybe exploit DB or whatever you grab copy and paste some stuff off GitHub slap it in fire the gun it's not going to work that way because you are going to have to find discover uncover unravel vulnerabilities and know their impact so that you can then craft your own exploit to do what you are going to do with them this is awesome but also a little bit hard there is no easy button you can't just kind of load up metas sploid and just go fire and compromise a machine you really have to dig through it and craft your own stuff and if I may that means you kind of have to get creative like so I'll offer uh whatever Easter eggs that I can without alluding to the actual exam environment uh the first couple of things that you are going to compromise require some Innovative thought because you might see a vulnerability that looks like ooh something that you might naturally think of but it's not that it's something that you might otherwise think of in a different scenario and you just sort of have to bridge that Gap it also means really really thorough testing like you have to go take a look at o what does this input box do what does this input field do what does that input parameter do how can you give the best coverage of your own assessment and again a real world penetration test to go find your next foothold or find the next breadcrumb so you as the student as the penetration testing candidate here really have to go find alternate avenues for exploitation and then leverage the environment that you see in front of you taking advantage of software taking advantage of privileges taking advantage of what you might have access to in One Direction and then take it with something in a different direction to find the next way deeper into the environment and again if I kind of go out on a limb here I think that is especially vital and important kind of in the early stages and like the beginning of the exam because you are going to do all your enumeration you're going to go find hey what can I go interact with what can I play with and it's a little bit of a flood I think they give you maybe a lot to run with to start and then you just kind of have to put the puzzle pieces together knowing what you've seen knowing what you found and knowing what you might be able to do next and I mean that especially with web application security hey you're going to be taking a look at the public facing websites you're going to be looking at HTTP services and you want to be thinking of those hey local file inclusion remote file inclusion all these vulnerabilities that you might be able to chain together even if it's something like a cross-site scripting or SQL injection tricking the database or serers side template injection all those things you kind of want to have armed and ready on your tool belt so that once you find the small thing that you could push and pull on one thing that you got that thread now you can keep moving forward but you need need to know ooh I can mix these two together I'm painting the picture here let me go put these colors in a way they've never gone before that's cool but as you know that external attack surface is just the tip of the iceberg that first shell is only the beginning once you get inside of the environment you're going to be doing lateral movement you're going to be pivoting you're going to be throwing chisel out there you're going to be getting proxy chains Rock and you're going to be doing everything that you might already naturally do for real legitimate penetration testing and inside of an active director environment you're going to have to be I don't know swinging back and forth between RDP sessions you're going to be locking onto SMB shares and using evil winrm to kind of bounceing forth yes obviously blood Hound's going to be in the mix crack map exec is going to be in the mix you're going to be throwing out rubius and that is where I'm trying to drive the point home and that is a extremely culminating and and a good compilation of everything that hack the Box teaches you whether it's in hack the Box Academy or even hack the Box machines on their own so let me be honest let me be fully transparent here because I basically came to hack the box like a dog with my tail between my legs and being like I'm sorry I I couldn't get it done hey kind of drive across the country here and I I just kept running out of time like I I feel like I'm not going to do justice giving you a review when it's not I don't know anywhere near what it should have been and hack the Box always as generous and as kind as they are said like listen John let me just let me tease you with what else is coming within the exam and you can see the absolute C C that we want to bring to students in this cpts exam and Capstone challenge here and even with just that little Peak the the small little glimpse of what was to come next in the exam environment I knew man okay goodness there was no way that I was going to be able to get that done while trying to move across the country and all the other crap that I was going on so look that's a fault on me but I want to bring that and drive that point home to you and that like you've got 10 days for this exam you've got a lot of time and make the most of it allocate all that you can for this because you you got to be creative and Innovative and you have to be thinking and you have to be with it so I I can't say it enough please please please take those 10 days seriously and because especially in that internal assessment that you do it is so comprehensive and you're going to be cracking passwords you're going to be firing up hashcat you're going to be using John the Ripper whatever you use you're going to be figuring out weak access controls you're going to be seeing Oh what privileges do this thing have or shouldn't have and be able to take advantage of that and I know hey all that is just kind of fluff though everyone can say that but the best tidbit that I might be able to give you even with hey the half complete or Half Baked attempt that I gave uh my nugget or again some maybe words of wisdom and that whenever you see something whether it's hack the Box cpts in its exam or even any other exam if I might for just general advice if you see something that seems out of the ordinary or out of place or just odd because it's not normally there or even if it normally is there take a second look take a third look because if it's there it's there for a reason and the way that this is a cated exam environment to test you everything has a purpose in its placing and placement so with that let me go down a couple other different directions here because I think one thing that again sets hack the box and the cpts apart from others is that report that comes at the end of it because I've I've taken other hey hacking industry certification exams and stuff like that but the again gravity or or caliber of of what they're hoping for and they want to receive from you from this exam report is top tier it's high quality it's breakdowns of vulnerabilities impact cve CVSs scores you know just showing what it could mean and what it could really do to a business if this is taken to its extreme in a legitimate corporate real business environment with that you need to be thorough you need to be organized you have to have something that is a professional commercial grade report and they're not going to take anything less like I've seen some of the comments and feedbacks from others CU I'm sure hey me just like you might be looking around to see who else has taken this thing what have they been up to what have what are they up against and what feedback they give you when they hey there are criterias that they want to see met for your exam report they hold you to a really high standard and that's a good thing you just need to be prepared for it and ready for it it's not just writing a a CTF write up that you slap on CTF time you know what I mean an important thing to note is that hey a real person is going to be reading your report and giving you real feedback so you've got 10 days to complete the exam but it's going to take I think they say 20 days at the latest to get back feedback to you usually it's way sooner and from what I've seen it's fast and once you pass you'll be able to pull down your certificate hey show it off brag about it put it on the fridge and that thing never expires one of the coolest things about hack the box and their cbts or any other certifications that they never expire you've got that for life and you can you know show with pride and I want to pull on that thread just a little bit more here because I think it's something super duper important uh because it's been proven to me like now that I've seen it with my own eyes at the end of this thing as you round out cpts in the exam a cpts CT holder someone who succeeds and passes here earns their certificate you are a now battle tested and such a valuable asset to any company organization or business as a penetration tester and as an ethical hacker by today's standards this I think puts you through the gauntlet in the best way that you prove your Merit and you just kind of put the flag Stak in the ground and say look hey I'm a certified penetration testing specialist and that's true that's a fact and maybe a funny thing I guess is like hey I I can't say that I I I can't say that right now because I I didn't pass and and I want to take this exam again I do I do want to take it again and I don't know maybe I just sort of come to terms with see and and I'm understanding you know life does its thing and time and resource allotment is just other thing um but I also come to terms and realize like look I I'm not a penetration tester and I don't know if folks often times even realize or aware I am not a pentester I've never had pentesting as a job and it's not my job right now so hey I've got a lot to learn like I'll be the first to admit and I want to learn more and I think this hack the box cpts with the certified penetra testing specialist is one great way to do it cuz it covers so much it's so top tier high quality and there is the grit there is the determination and there is the stubbornness when it's not being spoonfed to you there's so much more that you gain from it and I I realized that's kind of a weird thing to chat about but I was speaking with others with other students with other folks going through the cpts I felt good in some tases because they said and we agreed like this is tough that's kind of it's kind of tough with that I've been rambling for way too long but hey my goodness hack the Box hack the Box Academy the cpts certified penetration testing specialist you've got my two thumbs up you've got my 10 out of 10 review You've got my I want to come back I want to do it again I want to knock this thing out of the park uh and I hope that you listening in maybe got some inspiration and some motivation to go take a crack out of yourself and go beat me go finish it Go pass before I do cuz man hey it's one of the great ways to learn it's one of the best ways to be battle tested and a penetration tester a certified penetration testing specialist in today's world so thanks for watching everyone like comment subscribe see you in the next video
Original Description
https://jh.live/htb-cpts || Try your hand at the HackTheBox CPTS: Certified Penetration Testing Specialist training and certification exam at HackTheBox Academy! https://jh.live/htb-cpts
00:00 - CPTS Exam
00:33 - about CPTS
01:31 - Timeline
02:23 - Some tips for taking the exam
06:08 - After the first steps
08:10 - Internal Assessment
10:44 - Certificate
13:03 - Final Thoughts
🔥 YOUTUBE ALGORITHM ➡ Like, Comment, & Subscribe!
🙏 SUPPORT THE CHANNEL ➡ https://jh.live/patreon
🤝 SPONSOR THE CHANNEL ➡ https://jh.live/sponsor
🌎 FOLLOW ME EVERYWHERE ➡ https://jh.live/discord ↔ https://jh.live/twitter ↔ https://jh.live/linkedin ↔ https://jh.live/instagram ↔ https://jh.live/tiktok
💥 SEND ME MALWARE ➡ https://jh.live/malware
Watch on YouTube ↗
(saves to browser)
Sign in to unlock AI tutor explanation · ⚡30
Playlist
Uploads from John Hammond · John Hammond · 0 of 60
← Previous
Next →
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
Code Commentaries? PHP to JavaScript in Bash and PHP!
John Hammond
Tutorials? MySQL connection with PHP and Bash!
John Hammond
Variable Naming in Python! Happy Birthday, Linux! Nokia N900!
John Hammond
JavaScript Splits The URL!
John Hammond
HTML Tables in Python!
John Hammond
HTML, Net Shares, GML!
John Hammond
Python 08 Programming Style and Comments
John Hammond
Python 26 Object Oriented Programming
John Hammond
75 Python Tutorials, Out Now!
John Hammond
Batch 14 Mathematical Expressions
John Hammond
Batch 85 Array Append
John Hammond
Batch 86 Array Count
John Hammond
Batch 87 Array Index
John Hammond
Batch 88 Array Insert
John Hammond
Batch 89 Array Remove
John Hammond
Batch 90 Array Reverse
John Hammond
Python [colorama] 00 Installing on Linux
John Hammond
Python [colorama] 09 Cursor Position
John Hammond
Python [hashlib] 02 Algorithms
John Hammond
Python 00 Installing IDLE on Linux
John Hammond
Python [pygame] 11 Rectangular Collision Detection
John Hammond
Python [pygame] 12 Platforming Rectangular Collision Resolution
John Hammond
Python [XML-RPC] 01 Research
John Hammond
Python [pyenchant] 03 Personal Word Lists
John Hammond
FancyURLopener Authentication and User-Agent [urllib] 03
John Hammond
Python 04: PEP8 Coding
John Hammond
Python Challenge! 17 COOKIES
John Hammond
Google CTF 2016: Ernst Echidna
John Hammond
Google CTF 2016: Spotted Quoll
John Hammond
Google CTF 2016: Can you Repo It?
John Hammond
Google CTF 2016: No Big Deal
John Hammond
Google CTF 2016: In Recorded Conversation
John Hammond
Homemade CTF Challenge: 01 "Orchestra"
John Hammond
Homemade CTF Challenge: 02 "Bae's Base"
John Hammond
Homemade CTF Challenge: 03 "Web Hunt"
John Hammond
Homemade CTF Challenge: 04 "UPX"
John Hammond
Homemade CTF Challenge: 05 "The Assumption Song"
John Hammond
Homemade CTF Challenge: 06 "A Brisk Stroll"
John Hammond
Homemade CTF Challenge: 06 "I lost my password!"
John Hammond
web25 :: Mr. Robot : EKOPARTY CTF 2016
John Hammond
web50 : RFC 7230 :: EKOPARTY CTF 2016
John Hammond
misc50 : Hidden inside EKO :: EKOPARTY CTF 2016
John Hammond
Hack The Vote 2016 CTF: Sander's Fan Club [web100]
John Hammond
Hack The Vote 2016 CTF Warpspeed [forensics150]
John Hammond
Juniors CTF 2016 :: Black Suprematic Square
John Hammond
Juniors CTF 2016 :: Six Strange Tales
John Hammond
Juniors CTF 2016 :: Lost Code
John Hammond
Juniors CTF 2016 :: Here Goes!
John Hammond
Juniors CTF 2016 :: Southern Cross
John Hammond
Juniors CTF 2016 :: Clone Attack
John Hammond
Juniors CTF 2016 :: Dirty Repo
John Hammond
Juniors CTF 2016 :: Hackers Blog
John Hammond
Juniors CTF 2016 :: Voting!!!
John Hammond
Juniors CTF 2016 :: The Good, The Bad and The Junkman
John Hammond
Juniors CTF 2016 :: Stop Thief!
John Hammond
Juniors CTF 2016 :: ROFL
John Hammond
Juniors CTF 2016 :: Restriced Area
John Hammond
Juniors CTF 2016 :: Oh SSH!
John Hammond
HackCon CTF 2017 TRIVIA and BONUS Challenges
John Hammond
HackCon CTF 2017 "Bacche" Challenges
John Hammond
More on: Tool Use & Function Calling
View skill →Related Reads
📰
📰
📰
📰
I Built a Free Privacy-First Developer Toolkit - No Data Leaves Your Browser
Dev.to · RavikiranReddy Balemla
A Non-Technical Way to Look at SSH
Dev.to · AbdulRasheed Agunbiade
CCIP Has Three Ways to Move Tokens Cross-Chain. Choosing the Wrong One Is an Audit Finding.
Dev.to · Ramprasad Edigi
Electron's docs quietly dropped their recommended security tool. What now?
Dev.to · Gyu
Chapters (8)
CPTS Exam
0:33
about CPTS
1:31
Timeline
2:23
Some tips for taking the exam
6:08
After the first steps
8:10
Internal Assessment
10:44
Certificate
13:03
Final Thoughts
🎓
Tutor Explanation
DeepCamp AI