# Penetration Testing Student (SP)

**URL:** https://legacy-community.ine.com/c/cyber-security/pts/15.md

[Latest](https://legacy-community.ine.com/latest.md) · [Categories](https://legacy-community.ine.com/categories.md) · [Tags](https://legacy-community.ine.com/tags.md)

---

## [About the Penetration Testing Student (SP) category](https://legacy-community.ine.com/t/about-the-penetration-testing-student-sp-category/70)

<div class="topic-metadata">

**Author:** [@Don](https://legacy-community.ine.com/u/Don)\
**Replies:** 2\
**Last updated:** [February 6, 2026, 12:08pm UTC](https://legacy-community.ine.com/t/about-the-penetration-testing-student-sp-category/70 "2026-02-06T12:08:21Z")

</div>

\*\* Included in Starter Pass This category is dedicated to students undertaking the Penetration Testing Student (PTS) Learning Path for job readiness as a Jr. Pentester or in prep for the eJPT certification exam. Use …

---

## [Berapa kah WhatsApp Tokopedia?](https://legacy-community.ine.com/t/berapa-kah-whatsapp-tokopedia/6111)

<div class="topic-metadata">

**Author:** [@himangpathak002-bb22](https://legacy-community.ine.com/u/himangpathak002-bb22)\
**Replies:** 0\
**Last updated:** [April 20, 2026, 11:53pm UTC](https://legacy-community.ine.com/t/berapa-kah-whatsapp-tokopedia/6111 "2026-04-20T23:53:52Z")

</div>

WhatsApp Tokopedia yang dapat kamu hubungi saat ini adalah +62822-6920-9086 membantu kendala Anda beritahukan permasalahan Anda di sini.

---

## [Problem with T1046 : Network Service Scanning lab](https://legacy-community.ine.com/t/problem-with-t1046-network-service-scanning-lab/6108)

<div class="topic-metadata">

**Author:** [@dorinbivoll-6f6de0d1](https://legacy-community.ine.com/u/dorinbivoll-6f6de0d1)\
**Replies:** 0\
**Last updated:** [April 7, 2026, 9:06am UTC](https://legacy-community.ine.com/t/problem-with-t1046-network-service-scanning-lab/6108 "2026-04-07T09:06:54Z")

</div>

Hi, I’m having an issue with the XODA file upload lab. I’m using the exact commands from the official solution, but the exploit fails — the server returns a 404 when trying to execute the uploaded PHP payload. My setup: R…

---

## [Help with the OJPTv2 CTF : Host & Network Penetration Testing: Network-Based Attacks CTF 1](https://legacy-community.ine.com/t/help-with-the-ojptv2-ctf-host-network-penetration-testing-network-based-attacks-ctf-1/6106)

<div class="topic-metadata">

**Author:** [@ea\_bessalah-191ea9ac](https://legacy-community.ine.com/u/ea_bessalah-191ea9ac)\
**Replies:** 0\
**Last updated:** [March 14, 2026, 11:22am UTC](https://legacy-community.ine.com/t/help-with-the-ojptv2-ctf-host-network-penetration-testing-network-based-attacks-ctf-1/6106 "2026-03-14T11:22:51Z")

</div>

Hello Team, i’m trying to take the “OJPTv2 CTF : Host & Network Penetration Testing: Network-Based Attacks CTF 1” but i’m stuck and seems like none of the video training i went through provide knowledge to be able to r…

---

## [Missing target file in eJPT lab](https://legacy-community.ine.com/t/missing-target-file-in-ejpt-lab/6105)

<div class="topic-metadata">

**Author:** [@sakthixyz-b0fc031237](https://legacy-community.ine.com/u/sakthixyz-b0fc031237)\
**Replies:** 0\
**Last updated:** [February 24, 2026, 7:32pm UTC](https://legacy-community.ine.com/t/missing-target-file-in-ejpt-lab/6105 "2026-02-24T19:32:32Z")

</div>

Hello, The Target file is missing in eJPT cybersecurity lab. Could you please give the location of it if I have missed it? Thanks

---

## [New eJPT Student](https://legacy-community.ine.com/t/new-ejpt-student/6096)

<div class="topic-metadata">

**Author:** [@CyberSecNewbie](https://legacy-community.ine.com/u/CyberSecNewbie)\
**Replies:** 5\
**Last updated:** [February 16, 2026, 7:02am UTC](https://legacy-community.ine.com/t/new-ejpt-student/6096 "2026-02-16T07:02:29Z")

</div>

Anyone taking eJPT course? Just wondering if we could connect for some group study. :slight\_smile:

---

## [25:58 mark on Web Server Enumeration](https://legacy-community.ine.com/t/25-58-mark-on-web-server-enumeration/6100)

<div class="topic-metadata">

**Author:** [@CyberSecNewbie](https://legacy-community.ine.com/u/CyberSecNewbie)\
**Replies:** 0\
**Last updated:** [January 23, 2026, 8:06am UTC](https://legacy-community.ine.com/t/25-58-mark-on-web-server-enumeration/6100 "2026-01-23T08:06:52Z")

</div>

@AlexisA hello. Just a question on the 25:58 mark of the Web Server Enumeration Video. when you unset the USERPASS\_FILE and did the show options again it seems that nothing has changed because the default is still showin…

---

## [Conceptual question: Passive vs Active Information Gathering (web apps vs networks)](https://legacy-community.ine.com/t/conceptual-question-passive-vs-active-information-gathering-web-apps-vs-networks/6095)

<div class="topic-metadata">

**Author:** [@marianodifonzo2-7a92](https://legacy-community.ine.com/u/marianodifonzo2-7a92)\
**Replies:** 0\
**Last updated:** [December 17, 2025, 5:18pm UTC](https://legacy-community.ine.com/t/conceptual-question-passive-vs-active-information-gathering-web-apps-vs-networks/6095 "2025-12-17T17:18:10Z")

</div>

Hi, Based on what I’ve seen in the course, I got the impression that: Passive information gathering is used for web applications or a domain that is in a search engine. Examples are whois, netcraft, dnslookup, dig, waf…

---

## [ECPPT Web app pentest CTF 2 flag 3](https://legacy-community.ine.com/t/ecppt-web-app-pentest-ctf-2-flag-3/6081)

<div class="topic-metadata">

**Author:** [@sabrabaig0-8b3690c22](https://legacy-community.ine.com/u/sabrabaig0-8b3690c22)\
**Replies:** 0\
**Last updated:** [November 11, 2025, 4:25am UTC](https://legacy-community.ine.com/t/ecppt-web-app-pentest-ctf-2-flag-3/6081 "2025-11-11T04:25:13Z")

</div>

This query is about WEB APPLICATION PENTESTING CTF 2 flag 3. I have tried sqlmap as well as burpsuite for error based attacks on the field and all those efforts are rendered useless. As far as I ahve understood from th…

---

## [Help in eJPT - PTS course](https://legacy-community.ine.com/t/help-in-ejpt-pts-course/6076)

<div class="topic-metadata">

**Author:** [@deeksha.bharadw-3fde](https://legacy-community.ine.com/u/deeksha.bharadw-3fde)\
**Replies:** 3\
**Last updated:** [October 31, 2025, 3:41am UTC](https://legacy-community.ine.com/t/help-in-ejpt-pts-course/6076 "2025-10-31T03:41:36Z")

</div>

Okay so i finished the first part of the PTS course i did the info gathering but then in skill check i did not understand what to do, with the help of chatgpt i realised none of the curl or httrack commands were taught, …

---

## [SYN-PING Scan](https://legacy-community.ine.com/t/syn-ping-scan/6065)

<div class="topic-metadata">

**Author:** [@toyeebakintayo-7d9ad](https://legacy-community.ine.com/u/toyeebakintayo-7d9ad)\
**Replies:** 0\
**Last updated:** [September 9, 2025, 3:00pm UTC](https://legacy-community.ine.com/t/syn-ping-scan/6065 "2025-09-09T15:00:12Z")

</div>

I ran a TCP SYN-PING scan skipping the port scan and it wasn’t sending a TCP SYN Packet. I’m confused please

---

## [Exploit completed, but no session was created](https://legacy-community.ine.com/t/exploit-completed-but-no-session-was-created/5958)

<div class="topic-metadata">

**Author:** [@sj0b70d0](https://legacy-community.ine.com/u/sj0b70d0)\
**Replies:** 2\
**Last updated:** [August 29, 2025, 5:14pm UTC](https://legacy-community.ine.com/t/exploit-completed-but-no-session-was-created/5958 "2025-08-29T17:14:27Z")

</div>

When I am trying to use xoda exploit on the target machine as part of the ctf, the following error is showing up: exploit(unix/webapp/xoda\_file\_upload) \[\] Started reverse TCP handler on 10.2.8.23:4444 \[\] Sending PH…

---

## [Issue with ine lab](https://legacy-community.ine.com/t/issue-with-ine-lab/6055)

<div class="topic-metadata">

**Author:** [@shaheer.yasir78-e1d6](https://legacy-community.ine.com/u/shaheer.yasir78-e1d6)\
**Replies:** 0\
**Last updated:** [August 28, 2025, 8:34am UTC](https://legacy-community.ine.com/t/issue-with-ine-lab/6055 "2025-08-28T08:34:06Z")

</div>

┌──(root㉿INE)-\[~/Desktop\] └─# msfconsole Metasploit tip: Use help to learn more about any command \_\_\_\_\_\_\_\_\_\_\_\_ \[%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%| $a, |%%%%%%%%%%%%%%%%%%%%%%%%%%…

---

## [eCPPT - Powershell for Pentesters CTF 1](https://legacy-community.ine.com/t/ecppt-powershell-for-pentesters-ctf-1/5926)

<div class="topic-metadata">

**Author:** [@user65432-f11e2d679](https://legacy-community.ine.com/u/user65432-f11e2d679)\
**Replies:** 5\
**Last updated:** [June 16, 2025, 4:38pm UTC](https://legacy-community.ine.com/t/ecppt-powershell-for-pentesters-ctf-1/5926 "2025-06-16T16:38:13Z")

</div>

Hi Everyone, I am currently working on the eCPPT - PowerShell for Pentesters CTF 1 and have successfully obtained the first two flags. However, I am encountering difficulties with the third task. So far, I have utilize…

---

## [Nessus](https://legacy-community.ine.com/t/nessus/2968)

<div class="topic-metadata">

**Author:** [@camjoro93-9ca31a16d6](https://legacy-community.ine.com/u/camjoro93-9ca31a16d6)\
**Replies:** 0\
**Last updated:** [October 16, 2022, 10:11am UTC](https://legacy-community.ine.com/t/nessus/2968 "2022-10-16T10:11:38Z")

</div>

I’m just bringing this up because I tried to create a ticket on the lab itself, but it is giving me an error. I just wanted to bring this to the attention of whoever puts these courses together. I’m in the PTS pathway an…

---

## [eJPT - Pass the Hash attacks video](https://legacy-community.ine.com/t/ejpt-pass-the-hash-attacks-video/5956)

<div class="topic-metadata">

**Author:** [@myathtun2210-47612ac](https://legacy-community.ine.com/u/myathtun2210-47612ac)\
**Replies:** 0\
**Last updated:** [May 30, 2025, 7:39am UTC](https://legacy-community.ine.com/t/ejpt-pass-the-hash-attacks-video/5956 "2025-05-30T07:39:44Z")

</div>

hi guys, First of all i am a new guy to a cyber and i am confused on a video about Pass Hash attacks video under Assessment Methodologies: Vulnerability Assessment topic. In the video the instructor said we will contin…

---

## [eJPT - CTF1](https://legacy-community.ine.com/t/ejpt-ctf1/5867)

<div class="topic-metadata">

**Author:** [@kenjisupremacy-fa9dd](https://legacy-community.ine.com/u/kenjisupremacy-fa9dd)\
**Replies:** 5\
**Last updated:** [March 26, 2025, 11:16am UTC](https://legacy-community.ine.com/t/ejpt-ctf1/5867 "2025-03-26T11:16:18Z")

</div>

Hi everyone. I don’t find flag 5. I have mirrored with httrack. Can you help me please ? Thank you

---

## [Nmap Default scripts](https://legacy-community.ine.com/t/nmap-default-scripts/5853)

<div class="topic-metadata">

**Author:** [@TheQuack](https://legacy-community.ine.com/u/TheQuack)\
**Replies:** 1\
**Last updated:** [March 11, 2025, 1:12pm UTC](https://legacy-community.ine.com/t/nmap-default-scripts/5853 "2025-03-11T13:12:37Z")

</div>

So I am working my way through the Penetration Testing Student course and just got through the Nmap Scripting Engine part of the course in relation to port scanning. From what i gathered from the video from that section,…

---

## [Nmap result is tcpwrapped after portfwd](https://legacy-community.ine.com/t/nmap-result-is-tcpwrapped-after-portfwd/3678)

<div class="topic-metadata">

**Author:** [@lys615743-5d03cd2b34](https://legacy-community.ine.com/u/lys615743-5d03cd2b34)\
**Replies:** 3\
**Last updated:** [March 11, 2025, 1:05pm UTC](https://legacy-community.ine.com/t/nmap-result-is-tcpwrapped-after-portfwd/3678 "2025-03-11T13:05:14Z")

</div>

hi there, i‘m doing lab \[post-exploitation\]. After adding route to second host \[demo1.ine.local\], starting socks4a, use portfwd, etc, the local port scan using nmap only gives me tcpwrapped. this is the same in \[clien…

---

## [Ejpt ctf1](https://legacy-community.ine.com/t/ejpt-ctf1/5840)

<div class="topic-metadata">

**Author:** [@migueldu54-9ac373572](https://legacy-community.ine.com/u/migueldu54-9ac373572)\
**Replies:** 0\
**Last updated:** [January 4, 2025, 10:35pm UTC](https://legacy-community.ine.com/t/ejpt-ctf1/5840 "2025-01-04T22:35:17Z")

</div>

Hello, I don’t find flag 1 in directory webdav. I have access on disk C by reverse shell but i don’t find flag. Can anyone help me please ?

---

## [Assessment Methodologies: Enumeration CTF 1](https://legacy-community.ine.com/t/assessment-methodologies-enumeration-ctf-1/5812)

<div class="topic-metadata">

**Author:** [@williamk99-83cca34e8](https://legacy-community.ine.com/u/williamk99-83cca34e8)\
**Replies:** 0\
**Last updated:** [December 18, 2024, 9:41pm UTC](https://legacy-community.ine.com/t/assessment-methodologies-enumeration-ctf-1/5812 "2024-12-18T21:41:47Z")

</div>

I am having an issue many have had with this lab and similar labs, the dreaded protocol negotiation failed error I tried both fixes offered in this forum for /etc/samba/smb.conf Add the following under global section …

---

## [Previlage Escelation](https://legacy-community.ine.com/t/previlage-escelation/5670)

<div class="topic-metadata">

**Author:** [@shamsulhaq1572-66654](https://legacy-community.ine.com/u/shamsulhaq1572-66654)\
**Replies:** 1\
**Last updated:** [October 25, 2024, 3:55pm UTC](https://legacy-community.ine.com/t/previlage-escelation/5670 "2024-10-25T15:55:09Z")

</div>

there are multiple methods of privilage escelations but how to take decission when and which method to be used first as juniour pentrations tester for privilage escelation

---

## [Something incorrect in LAB DNS & SMB Relay Attack in course: Network based attacks](https://legacy-community.ine.com/t/something-incorrect-in-lab-dns-smb-relay-attack-in-course-network-based-attacks/5753)

<div class="topic-metadata">

**Author:** [@lisadijkman-7e7f5955](https://legacy-community.ine.com/u/lisadijkman-7e7f5955)\
**Replies:** 0\
**Last updated:** [September 21, 2024, 6:28pm UTC](https://legacy-community.ine.com/t/something-incorrect-in-lab-dns-smb-relay-attack-in-course-network-based-attacks/5753 "2024-09-21T18:28:35Z")

</div>

@AlexisA Hi! I’m running into a question while doing the lab: DNS &S MB Relay Attack in course: Host & Network Penetration Testing:Network based attacks The goal is to intercept the NTLM hash from the client to authen…

---

## [I believe there is a mistake in this quiz!](https://legacy-community.ine.com/t/i-believe-there-is-a-mistake-in-this-quiz/5725)

<div class="topic-metadata">

**Author:** [@ahmed-99b29173035c4d](https://legacy-community.ine.com/u/ahmed-99b29173035c4d)\
**Replies:** 1\
**Last updated:** [September 10, 2024, 8:52am UTC](https://legacy-community.ine.com/t/i-believe-there-is-a-mistake-in-this-quiz/5725 "2024-09-10T08:52:20Z")

</div>

Hi In eJPTv2 under the course Assessment Methodologies: Footprinting & Scanning, Evasion, Scan Performance & Output section there is a quiz: Which output format in Nmap provides a machine-readable format that can be ea…

---

## [All the GUI labs in eJPT courses keep disconnecting. I tried changing servers, browsers, internet source, the problem persists. What if this happens in the exam? The INE team only says "change the browser" but nothing solves the issue](https://legacy-community.ine.com/t/all-the-gui-labs-in-ejpt-courses-keep-disconnecting-i-tried-changing-servers-browsers-internet-source-the-problem-persists-what-if-this-happens-in-the-exam-the-ine-team-only-says-change-the-browser-but-nothing-solves-the-issue/5681)

<div class="topic-metadata">

**Author:** [@shadabshkh008-4b87e5](https://legacy-community.ine.com/u/shadabshkh008-4b87e5)\
**Replies:** 1\
**Last updated:** [August 30, 2024, 12:58pm UTC](https://legacy-community.ine.com/t/all-the-gui-labs-in-ejpt-courses-keep-disconnecting-i-tried-changing-servers-browsers-internet-source-the-problem-persists-what-if-this-happens-in-the-exam-the-ine-team-only-says-change-the-browser-but-nothing-solves-the-issue/5681 "2024-08-30T12:58:55Z")

</div>

All the GUI labs in eJPT courses keep disconnecting. I tried changing servers, browsers, internet source, the problem persists. What if this happens in the exam? The INE team only says “change the browser” but nothing so…

---

## [Issue with my eJPTV2 labs](https://legacy-community.ine.com/t/issue-with-my-ejptv2-labs/5743)

<div class="topic-metadata">

**Author:** [@faisalbasha.and-74e1](https://legacy-community.ine.com/u/faisalbasha.and-74e1)\
**Replies:** 0\
**Last updated:** [August 30, 2024, 12:56pm UTC](https://legacy-community.ine.com/t/issue-with-my-ejptv2-labs/5743 "2024-08-30T12:56:50Z")

</div>

Hi, I bought the eJPTV2 exam + course. I have been trying to do the “Scan the Server 1” lab from the Assessment Methodologies: Footprinting & Scanning chapter. But the labs do not work saying that “Gucamole server is un…

---

## [Windows Recon: Zenmap](https://legacy-community.ine.com/t/windows-recon-zenmap/5714)

<div class="topic-metadata">

**Author:** [@chaitanyasalokh-1225](https://legacy-community.ine.com/u/chaitanyasalokh-1225)\
**Replies:** 0\
**Last updated:** [July 9, 2024, 10:47am UTC](https://legacy-community.ine.com/t/windows-recon-zenmap/5714 "2024-07-09T10:47:27Z")

</div>

I read in the lab instructions that the task is to discover the live host machines and to primarily focus on the subnet 255.255.240.0 (CIDR 20). So the first thing i did was view my ip configuration and it was 10.0.17.61…

---

## [Scan the server 2 - tftp and snmp](https://legacy-community.ine.com/t/scan-the-server-2-tftp-and-snmp/3306)

<div class="topic-metadata">

**Author:** [@royoblazquez-4785dec](https://legacy-community.ine.com/u/royoblazquez-4785dec)\
**Replies:** 4\
**Last updated:** [July 8, 2024, 9:40am UTC](https://legacy-community.ine.com/t/scan-the-server-2-tftp-and-snmp/3306 "2024-07-08T09:40:47Z")

</div>

In Scan the server 2, in Footprinting & Scanning. Why can we assume that it is a tftp server? In the solution just say “Given that we have discovered that UDP ports 177 and 234 are running a DNS and SNMP server respecti…

---

## [How can I know where the TARGETURL](https://legacy-community.ine.com/t/how-can-i-know-where-the-targeturl/5707)

<div class="topic-metadata">

**Author:** [@a7med14pro-f24e247e8](https://legacy-community.ine.com/u/a7med14pro-f24e247e8)\
**Replies:** 0\
**Last updated:** [July 3, 2024, 12:22pm UTC](https://legacy-community.ine.com/t/how-can-i-know-where-the-targeturl/5707 "2024-07-03T12:22:09Z")

</div>

Hi there I’m in metaspoit-framework secion and particular is post exploition, so how can I know what the exactly url which I should to used it when I exploit the target in both web page and operating systeam

---

## [Why i can't connect to the lab exam?](https://legacy-community.ine.com/t/why-i-cant-connect-to-the-lab-exam/4841)

<div class="topic-metadata">

**Author:** [@serradamir-efe4ad6dc](https://legacy-community.ine.com/u/serradamir-efe4ad6dc)\
**Replies:** 2\
**Last updated:** [June 25, 2024, 6:30pm UTC](https://legacy-community.ine.com/t/why-i-cant-connect-to-the-lab-exam/4841 "2024-06-25T18:30:44Z")

</div>

I’ve been trying to connect on the exam lab almost the 48hours of exam and i can’t, the lab is not working. How I’m supposed to pass the exam without using the lab???

[Next page](https://legacy-community.ine.com/c/cyber-security/pts/15.md?page=1)
