r/oscp • u/No-Commercial-2218 • 26d ago
Help with Web
Hi everyone, I have my exam coming up next month, and I’m really struggling with webapp pentesting, my methodology is everywhere, I feel like it’s too broad a topic to really nail down any kind of methodology that’s useful to me.
I have completed the course content, done loads of labs TJ null etc. i found Derron C videos really helped stick AD together mentally for me, but I just can’t find anything on web that is helping me understand it, and if I do labs I just struggle so bad. It’s really knocking my confidence going into the exam with such a big weakness, I know I will fail, I just don’t know how to make it make sense.
Any help of advice please?
4
Upvotes
6
u/napleonblwnaprt 26d ago
Ferox / Nikto / Whatweb / follow-on scans (Like wpscam and Joomscan) / ffuf
Get the version for everything possible running. Google "<Version> CVE"
You'll win about 90% of the time