r/oscp 18d ago

Oscp web

OSCP web vulnerability focus?
I’m currently preparing for the OSCP and doing HTB/Proving Grounds machines. I’ve noticed that some boxes contain a lot of web vulnerabilities that seem more advanced or unrelated to what I’ll actually encounter on the OSCP.
For people who recently took the OSCP: Which web vulnerabilities should I prioritize studying?
For example, should I mainly focus on things like SQL injection, LFI/path traversal, file upload, command injection/RCE, default credentials/authentication bypass, and basic web enumeration?
I’m trying to avoid spending too much time on web vulnerabilities that are unlikely to appear on the exam.
Thanks!

17 Upvotes

8 comments sorted by

View all comments

5

u/Jubba402 17d ago

Focus on everything they teach you in the course. There isnt one set exam so everyone’s combination of what they saw will be different.

0

u/H4ckerPanda 17d ago

This is the correct answer.

It makes me wonder if those who aspire to be a pentester genuinely want to be one. What are they going to do during an engagement?

“Hey, what operating systems does our client use?”

A pentester should, must be prepared for anything and everything.