21 hours 43 minutes
using the displayed in the osc P or not?
Are learning objective is to determine the pluses and minuses of using medicine flight on the osc P.
So this is a question everyone has to ask themselves themselves during the osc p. Should I use medicine flight? And there's a lot of factors that go into that and it's probably something you should start to think about before you are in the exam.
So when you're in the environment, the lab environment for P W. K. And you look at the forum, as many people obviously say, don't use my display, you may see old boxes with exploits like eternal Blue.
So what I would do is I would find a non medicine plate way to exploit the eternal blue vulnerability
and, and go from there because again, when you're not relying on medicine ploy, you're reading code and modifying code and having to take additional steps, which I think will translate nicely into. Oh, SCP day when you know when you're trying to find the correct exploit code and you have some comfort in knowing well
in the labs I've done them without medicine Floyd
but also do do do them both ways use meta split and don't use medicine plate and I'll use that with things like sequel map.
I'll use sequel map in labs
and then I won't and I'll try to determine how much harder it is not using sequel map than when I do use sequel map. Same thing with municipal it. I try to determine okay I can use municipal it but what if I don't and that's why I think you know going through the labs and the examples that I have given
some medicine modules are very simple. There simply uploading a file with a curl command
and you could easily do that yourself. So when you have some comfort in looking at exploit code and knowing what an exploit does you understand the complexity? If there's hashing algorithms that go towards it or trying to brute force dates and times and things like that,
it gets more complex and then you should start thinking, well maybe municipal, it is the right way to go here
because you know, maybe it's difficult for me to try to figure out all this on my own.
And again, I think the worst feeling is deciding to use medicine flight and it not working. So I'd say go with your gut and if you think that that exploit is the correct one in medicine Floyd
and it doesn't work again, change up your payloads, look at the targets, you know, maybe there's something in there maybe didn't configure it correctly. Maybe you didn't set your L hosts or our hosts or
whatever it may be. Maybe you didn't do that. right? So double triple check whether you did it right or not and maybe you've lost the box somehow and you just need to simply need to reset it.
So don't use medicine as a crutch if you go through the P. W. K. Labs and you use medicine Floyd on every box. If you could. In theory, I don't know if you can,
but if you use menace flood in every box, you're really gonna do yourself a disservice because when it comes time to test day and you can only use it once,
um you're really not gonna know, you know how to use medicine very well, but you won't know how to look at code, analyze it. And again, that's what differentiates you from a script kiddie, someone who just goes into medicine flight and select the correct module and then just hits exploit or run.
You know, the the differentiator is the fact that you can look at code and you can become familiar with figure out what it does and of course that takes a lot of googling and a lot of enumeration, figuring it out.
So like I said, try both ways. Try using medicine. Try not using medicine Floyd and have that comfort and that that self confidence that you're able to do things. Not relying on medicine Floyd.
But in the end the choice is yours. Um, I think in my oh SCP attempts I use medicine plate.
I believe I used it every single time,
but it was typically towards the end of the test. My fear was using medicine play too early
and then not being able to use it again. So
weigh the costs,
the cost benefit analysis. You know, if I'm only two hours into SCP and I think I found a medicine plate module. Should I use it now? Your answer might be yes, your answer might be. I found some exploit. I've tried to find the code. All I can find is a medicine plate module. I don't know how to write ruby and I don't I don't feel comfortable
doing this on my own. So I'm gonna try medicine right now.
So it's really a case by case basis. But in my strategy, in my mind, it was always something that I should save for the end. Um when all else failed, I'll just try my display and see if it works.
And also know that, you know, if if you're thinking of
offensive security, who makes this,
do I make a box that is only explicable with medicine plate,
you know, do do I make somebody who's taking this test have to use it?
Um So think of it that way as well. I try to put myself in the mind of the test makers.
Um Just like someone who's taking the test is would they write something? Would they make a box only vulnerable to a meta split module? And are there other ways to exploit as other public exploit code out there available for somebody to find it?
And maybe there is and maybe it's just a matter of, you know, maybe it's not an exploit DB but it's in GIT hub. Someone else who has the exploit code. Um And you don't need to use medicine flight.
So that's why we always go back and you always hear enumerate enumerate enumerate. That goes the same for your your google searches or bing searches or whatever search engine you want to use is trying to find that exploit code and not having to go to medicine flight.
So here's our quiz which medicinally module can you use on more than one target.
I said this in the last lesson and you should know it. I preface this by saying
check the exam guide. You know from the time that this is recorded at the time that you take the Osc. P. Maybe things have changed. So go and check now before you know before this lesson ends. Go and check the the F. A. Q. And see what you're allowed to use and what you're not.
But the answer to this is going to be
multi handler which you've seen me use a few times. But again, go to the offensive security website, look at the exam guide and ensure that this information is up to date.
So when somebody should now be able to determine the pluses and minuses of using medicine plate on the osc P.