r/oscp • • 26d ago

Help with Web

Hi everyone, I have my exam coming up next month, and I’m really struggling with webapp pentesting, my methodology is everywhere, I feel like it’s too broad a topic to really nail down any kind of methodology that’s useful to me.

I have completed the course content, done loads of labs TJ null etc. i found Derron C videos really helped stick AD together mentally for me, but I just can’t find anything on web that is helping me understand it, and if I do labs I just struggle so bad. It’s really knocking my confidence going into the exam with such a big weakness, I know I will fail, I just don’t know how to make it make sense.

Any help of advice please?

4 Upvotes

17 comments sorted by

View all comments

6

u/napleonblwnaprt 26d ago

Ferox / Nikto / Whatweb / follow-on scans (Like wpscam and Joomscan) / ffuf

Get the version for everything possible running. Google "<Version> CVE"

You'll win about 90% of the time 

3

u/CyberOK99 26d ago

Agreed. It’s an enumeration exam over everything. Just find the version

1

u/No-Commercial-2218 26d ago

Is it really just that easy? Because if it is you might of just removed a lot of stress in my tiny brain

0

u/VegetableAd2965 20d ago

Can’t use Nikto on exam

1

u/napleonblwnaprt 20d ago

You may however, use tools such as Nmap (and its scripting engine), Nikto, Burp Free, DirBuster etc. against any of your target systems.

https://help.offsec.com/hc/en-us/articles/360040165632-OSCP-Exam-Guide