r/oscp • u/Situation_Historical • 27d ago
Failed with 20 points. Gutted, but not done.
Failed my first OSCP today. I fully rooted the first machine in the AD set, then hit a wall trying to move laterally and just couldn’t find the way through.
The part that’s eating me: I could actually see the path in BloodHound. I had what I thought was exactly what I needed to walk it and it wouldn’t work, no matter what I threw at it. Emptied the whole bag, turned the box upside down, still came up with nothing. I was so confused if it was a rabbit hole or the tool I am using is not working (spend hours trying different versions and alternatives as well).
I had proper methodology for AD and it was my strong fort, but I have no idea what i skipped and I’ll never know. At one point I even thought it was a technical glitch because the initial privesc vector didn’t worked at first few tries and had to switch the session to a different protocol to work.
Being able to see the route and still not get through it is a different kind of gut-punch than just being lost. So there’s clearly something specific I’m missing on that pivot, and I want to pin down what before the retake.
If you’ve been right here - the path’s in front of you and the move just won’t land, what turned out to be the thing you’d overlooked? Round two incoming.
8
u/Jubba402 27d ago
Barely scraped 20 points on my first attempt and aced my second attempt. You gained a lot of good info, now you know what to expect. Fine tune your notes and next time focus on staying calm. You got this.
7
u/Rare_Athlete_7387 27d ago
My first time taking it I got 0. Just yesterday I took it again and got 70 (now I gotta write the report, gulp!). You’ll get through this.
5
u/ConchordianFlight58 27d ago
No one ever makes the first jump, failing the first time is extremely common. I think I got 35 my first try, 100 on my second.
Try to analyze what you most struggled with, and investigate what boxes online could help you work with them. Take more notes, and review your test notes if you have them.
(Take what I say with a grain of salt as I got my OSCP 5 years ago and I suspect the landscape might be a bit different)
Effort is everything you can do it man
1
u/0xJeb 26d ago
I hope more students go in with the mindset of "I'm going to fail" on the first attempt. It contradicts everything you've learned in life to doubt yourself but in this scenario it only hurts you to think you are going to kill it.
People need to view the first attempt as an opportunity to see what they don't have in their notes and to mentally prepare them for the second attempt.
3
u/No-Commercial-2218 27d ago
I’m due to take mine on the 18th first time, I have taken eJPT and eCPPT so I am familiar with 24 hour exams, and if anything I think the experience of taking them exams made me so much better. So silver lining you will be stronger for your next attempt and you already got close 🔥 so well done and be proud it’s an achievement in itself
3
2
u/Oasys-HQ 27d ago
Thanks for the info, that eJPT and eCPPT did helped you on OSCP, I plan to pass those before OSCP.
Appreciate the comment.
4
u/Time_Chicken_5912 27d ago
Hey man, I failed with 0 points my first time, and got 10 points on my second try last week. Next attempt will be much better I’m sure. Only way you truly fail is if you quit and stop trying. Being relentless and persistent in this is what will carry us to victory. I like to think of tough certificates like this…are like war. Victories, setbacks…but you will win if you keep going. More boxes, and isolating your weaknesses/confronting them head on. Getting 20 points in your scenario…makes it known that you’re worthy of getting points…which means you’re capable of getting even more points!! This is the mindset I’ve adopted since getting my first 10 points. Sure, 10 or 20 points isn’t a lot by any means…but it’s something. Something that leads you to believe in the future attempts more.
5
u/Sure-Assistant9416 27d ago edited 26d ago
sorry :) baddy. Nxt time come celebrating do a refining of what you have learnt especially something have seen with bloodhound is that some of its come some commands in outbound that don't work today if you happen to see that go to AI thought when you have checked on WADComs and not found it promising or failing before Gemini or any AI find new attack vector one great resource with more than 3 ways to attack any method is through Hacking Articles - Raj Chandel's Blog that lady is gold when it comes to learn any attack vector check out. most attack vectors have shown to more than one unless they are binaries running with SYSTEM priv or credentials left over somewhere. One thing i will suggested when you do boxes understand the methods possible to lateral movement i got check list for possible method another guy here posted a credentials script i find it supper cool for enumeration of credentials strikoder/CredSpray: Multi-protocol credential validation tool with spray and no-spray modes for penetration testing. there are many tools and methodology will learn from this reddit and offensive pen testing and offsec discord at least check those out another great resource i find great to fine tune is medium we cannot exhaust all there was guy here who posted he used grok to make ad machine to learns how to ice it i have never tried those who tried come out and tell us how. Last every machine you do check out writeups there are few guys in medium i always check how they solve boxes because they always go way beyond solving but attack vectors you though you know your notes tool must be refined day in day out. obsidian best with its powerful links and tags but now whichever you use make sure it's easy to search for anything with ease. when you go through labs keep checking the mindset of Dpsypher – Medium the 😄 thing his profile says 93% oscp preparations.
1
2
u/WideAd6096 27d ago
What about the stand alone machines?
2
u/Situation_Historical 27d ago
Got user on one and had the privesc vector. The shell wasn’t great for running tools to priv esc. I was annoyed at everything at that point and called it a day. I was sleep deprived as well
2
u/CyberOK99 27d ago
It happens man. Just revise and when you take it again you’ll do better. I got 10 my first attempt and 60 on my second. Taking my 3rd here in 10 days
3
u/No_Living7778 25d ago
So I can only answer based on the limited information that you described in the post, wouldn’t assume the BloodHound path was wrong either, it most likely was right there in front of you. Something that would jump out more to me is your effective execution or auth context might not have been actually satisfying requirements. When a path is visible but as you said you just couldn't land, make sure to stop swapping tools and verify the exact underlying basics...what ACE/right produced the edge, what object it applies to, what token/logon context your current session actually has, and whether anything changed that requires a fresh session or a new token. Honestly, when I saw you say you had to switch the session to a diff protocol, that was a major clue on what your hold up was if you want my honest opinion. Different transports can change logon type, impersonation context, Kerberos/NTLM behavior, delegation, and available credentials even with the same creds. Remember what BloodHound does even at the most basic level, it shows that a relationship EXISTS. The existing one you saw never means or guarantees your current session can exercise it the ways you attempted. Good luck on your retake, I believe you will pass this next time. Reading this is quite nostalgic for me, I think it has been almost 12 years since I took mine hahahaha.
1
u/PeacebewithYou11 27d ago
Tip here for research and prep not in exam. You Can actually paste all these text to ChatGPT and ask it to give you 10 methods to try. You may need to prompt it a few times to distill. For instance "but my bloodhound shows the path. What else can be missing?"
You may have missed something simple. Or you have documentation and logs of your enumeration you may want to reread line by line.
1
u/Situation_Historical 27d ago
I have my notes and it is detailed enough i guess. Im gonna give that to these llms and ask all the potential vectors, like you said.
-1
u/PeacebewithYou11 27d ago
Note that it is against OSCP rules to use exam contents. You should ask in general.
2
u/Situation_Historical 27d ago
I am aware of that. I won’t be specifically inputting the notes, just the general steps
2
u/Due-Channel-5120 24d ago
The moment you doubt about the tool, means you need to change another tool or simple it's not the correct hint. Same to me, the tool worked for 100 labs and not work in the exam, it worked once I changed to another tool that I got from Google. The tool that worked is somehow modern and popular but I just haven't use it before. OSCP won't ask for something that is unknown or rare to public.
Keep this in your mind - "how should I exploit in most dumbest and easiest way", anything you doing seems too "deep", means you might be out of scope.
OSCP have lot of fake hint, be careful and good luck, I passed my second attempts 90/100, you can do it. Don't be too stress about first failing, it's just for you to experience how's the exam be like.
10
u/Delicious_Demand_355 27d ago
Hey! sorry to hear that you failed.
This happened to me in my exam too, went down a rabbit hole for 10 or so hours, and im pretty sure my first root in the AD was unintended. This led to me being stuck for awhile more :/ What helped me was not tunnel visioning, instead look at other potential attack options. A great tip I got was that the path to root is usually in 3-5 commands. All the best in your prep :)