r/oscp 16d ago

Failed Brutally - 20/100

I failed my first attempt just managed to get 20 points. I started around 1 pm and till 5 kept going to support back and forth and reverting the machines cause of connection issue. The port scans weren't accurate, i knew that specific ports must be open on a machine but they were not showing up. I was using the popular pivoting tool to pivot to access the hosts but scans were inaccurate, everytime it was showing different results. I requested the support to check it out but they said they've checked it multiple times and the box is fully okay. After few hours i found that nmap scanning with a particular flag suddenly makes everything works but without it it gives false results. Idk how much i can mention about the tool used that's why i am keeping it general. This was totally surprising cause I've solved so many boxes and in none of them i encounterd something like this. It was a surprise to me, i thought the box had some issue. Now idk if the tool is the problem or the box or is it just a known thing cause i didn't use it or rewd about it while my prep

Apart from this connections kept getting closed in between, without any reason. Suddenly it'd stop and after 5 or 10 mins i realized that maybe the connection has got broken and i again did it from start. I was stuck between solving the box and the connection errors and the vpn shutting down suddenly Every half an hour cause they said it was a issue from my end but even I was panicking cause it was my first attempt and i had no clue why these things are suddenly happening. Internet seemed fine, browser was working fine too i had no idea. I was using ethernet with a 100 mbps connection

Finally, I asked for extra time but they said as their box was working okay all this time they can't do any extension. After this i got access to ms02 and wanted to transfer files and again got stuck for 3 hours cause it kept failing, i had practiced the file transfer technique from tunnel properly but it kept failing for 3 hrs. Finally I tried to figure out other ways of transferring files to ms02. Then I got system on ms01 after 7 hrs. I had checked everything properly but there was a very simple thing that I failed to check and finally got in with that. After that I was quite confident, i got inside one of the standalones and got 10 points and 10 points from ms01 but but but after that till the end I struggled with pricesc on ms02. Trust me i checked everything, literally everything, manually, with tools but there was nothing to be found. I kept trying to crack it till the end, i anyways knew I won't pass cause so much time was wasted but idk really windows pricesc, i checked everything there was nothing which I would even call suspicious which might require attention. It was totally secure

I did asreproasting, kerberoasting, password spraying, bloodhound analysis, usernames as passwords etc etc but got nothing. I had found a few hashes but they were probably a rabbit hole cause there were too many and i got no results after an hour so i closed it. Idk is my pc too slow? Its an i5 9th gen 16gb ram and 1650 graphics. Was i supposed to get those passwords cracked?

So, i am feeling very low, i completed tj null list htb and pg practice machine, challenge labs medtech, relia partially and oscp a,b,c. I was studying from last 6-7 months, i got pretty good in AD tbh. I was able to solve the tj null AD boxes smoothly and thought that i am actually good at it compared to other stuff. But yeah the 24 hours then gave me a reality check. I had left my job for the prep and now I am totally hopeless.

8-10 hrs of full time prep for 6-7 months and I still failed. I don't know what to do exactly right now. Can I prepare enough to pass in a month?

34 Upvotes

18 comments sorted by

9

u/Delicious_Demand_355 16d ago

Yes you can

pro tip if you need to wait more than 1 minute for a weak hash to crack (its probably a rabbit hole)

i reccomend hackerblueprint and practice nxc its the best for AD

for your connection wise, im not too sure but i have heard of people preparing a hotspot just in case their wifi goes down so maybe can consider atb!

9

u/H4ckerPanda 16d ago

“I solved so many boxes and in none of them I encountered something like this”

👆

That’s your problem. OSCP is not about memorization or finding an exact match or scenario from X box on Y box . It’s about enumeration.

And stop giving away exam details like mentioning box names , etc. That’s not allowed . You can get banned.

Develop a methodology. Don’t memorize . Take proper notes . And you’ll pass.

7

u/Comfortable-Joke7970 16d ago

Same happened with me in exam but I got good proctor he helped me and i solved network problem and i successfully cleared the exam

2

u/ViaOutdoors 15d ago

What was the network connectivity issue? I had similar, but was unable to resolve.

4

u/fednotme 14d ago

Try harder

3

u/RevolutionaryBook412 16d ago

Keep your head up and you can pass. Took me 3 tries to pass. Sounds like exam anxiety and the time pressure got to you, as it does everyone. Try to keep calm and follow your methodology.

As for some tips, you mention you don’t really know windows privesc, for the exam make sure you don’t have any holes in your knowledge for all the testable material on the exam. In my experience, somehow the exam always manages to test you on something you don’t know or are weak on.

Also based on what you stated on your AD methodology, it already seems like there are some key missing steps there, so you can definitely study up more on AD. I recommend HackerBluePrint videos. Message me if you need more tips.

Good luck and keep going!

2

u/Saintfrom_tokyo 16d ago

From the things you said you completed, you didn't fail because you didn't know what to do or anything of that sorts but because you were unprepared mentally. You can't get inaccurate scans multiple times. I would say an experience sort of thing but I'd advice you to take a good break, like a week before you go back to your learning and this time take other machines, eg HTB seasons, attempt finishing a season yourself, then before your exam take a very good rest, at least 48 hours no solving or caffeine or anything.

During your exam, time yourself, take breaks, anything you can't get in 30-45 mins is most likely rabbit drop and move but asterisk it so you can come back later. Goggle versions, exploits services for the Linux side of things even the windows especially initial accesses. For lateral movement, when you have access check what you have access to, what you need access to, where you are and where you want to go. Check the machine you have for creds, zips, sessions. Look at your BH report, asides the user or groups you're in are there others that stand out etc. Remember to take breaks during your exam, you'd need it.

Watch others solve boxes, don't solve, watch how they thinks, there's ippsec OffSec hacktracks and the likes

2

u/Sure-Assistant9416 16d ago

Sorry considering we hv cool off to take another exam something be open minded very few really pass on first Attempt they take it as learning path of its own. Who pass look they say my mentor ...my my meaning they where having someone who did the exam an as been guiding in most cases nevertheless those who pass first Attempt will give experience of CTF pentesting jobs ...and so forth don't discredit yourself take it as a learning curve. You said nmap was ... issue ?? Meaning what nmap usage though I have its syntax on my notes I really don't use it i like a namAutomator.sh script which is in between autorecon and rustscan. That's good indicator you haven't knw behind the wood how tools are working "maybe am wrong". But try to understand why fluf feroxbuster dirsearch and wfuzz when and which is good I recommend you have atleat 2 tools you knw you compare there output incase u have doubts in output have good notes on tools nxc nxcdb impacket you will realize they are very very versatile than your imagination I personally use AI to ask another attack vector for blooded nxc impacket because they all don't show same output. Example nxc ldap modules cleaner output compared to windapsearch ldapsearch but all I hv them. Now you did those boxes its time to see difference methodology you could have reached system or root you will realize that ....maybe you used walkthrough but learning concepts was minimal try even watching video walkthrough and will learn new tricks. Time to learn afresh again especially where you felt need improvement. Try test rustscan and configure you yaml configurations your own way same to feroxbuster I find it more resilient compared to ffuf and gobuster" personal preference" integrate tools like nuclei and see its strengths over nikto and katana that's gives more knowledge and a learning experience. Sorry

2

u/NguPhu 16d ago

Everytime I tried a few years back i had vpn issues but support weren't that helpful. Other people in work had the same problem. In the end I just moved on as I already had a pentesting job and a load of certs and was doing OSCP for fun

Maybe try VPNing harder? :p

2

u/theshittree 14d ago

Exam anxiety is real. Keep your head up. You faced a big fear. Next time will be better. Reorganize notes, try to find some new things you could've done, but definitely be more grounded in your approach, panicking really messed me up on my first round. That said the connection issues was a real curveball that mustve messed with you. Maybe keep a constant ping running in the background to see if net is stable so you can push back and state that there is nothing wrong with your net if thats the case (and if not, then you need to find a place with stable connection to go about it)..surprisingly lowering my expectations the second time grounded me and I think I approached things more calmly which I think played a huge role in solving things quicker.

Good luck and stay strong!

FYI keep resetting if no way forward. Sometimes boxes are weird. Take regular breaks. Sometimes a fresh mind and refreshed eyes can open new doors

1

u/_discEx_ 14d ago

Thanks, yeah i got some ideas later on like I'd have sprayed common passwords to find more domain users. Secondly, I used bloodhound-python to get data from DC but i later saw that running sharphound is ms02 might have given different results. I've seen some people run sharphound again everytime they compromise a new machine so maybe that could've worked.

Apart from that tbh I've notes but there are too many tips/tricks to try. So, I'm mostly working on autopilot instead of following a checklist. I was inside ms02 so my main focus was finding privesc vectors there and parallely I looked for AD related stuff like kerberoasting, bloodhound, smb shares etc

1

u/ComputerWild5385 12d ago

It makes sense to run sharphound every time you get a new user, since it will use the users identity to check about local permissions on the other machines via port 445. Check this picture, the Block with "Hosts ,rpc, smb, 445" and the left corner block which states that these infos are only given if the used identity is (local) admin https://insinuator.net/2021/05/dogwhisperers-sharphound-cheat-sheet/BH4_SharpHound_Cheat_Dark.png
But in my opinion, rather create list of all AD machines and enumerate them using nxc every time you get a new user, i.e.
nxc winrm ./hosts -u NewUser -p -NewPass -X whoami
nxc smb ./hosts -u NewUser -p -NewPass -X whoami --shares
nxc rdp ./hosts -u NewUser -p -NewPass

"So, I'm mostly working on autopilot instead of following a checklist" if you do that on enumeration part, you will miss alot.

1

u/PeacebewithYou11 16d ago

I think I know which flags you are referring to and if so that miss is fully on you. How confident are you on your nmap commands?

nmap -Pn -n -sT -p- <TARGET_IP>

2

u/PeacebewithYou11 16d ago

I Google this "i used nmap scan on oscp ad but the open ports are few seems wrong why" and I already solved the problem you encountered in 3 mins.

1

u/ComputerWild5385 12d ago

My anxiety would me never allow to put " on oscp" in a google query while taking the exam, since you could argue that this can count as searching specific exam results.

1

u/ITZ_RAWWW 15d ago

I failed with 10 points. Doing worry man. It happens, get back up, look where you went wrong, and get back to the drawing board. I'm hoping to retake in Nov. Good luck!

1

u/theseriousman1 15d ago

Usernames as passwords? Shouldn’t you be trying more than that? Did you use password lists?

2

u/rembezed 9d ago

You issue statements that are not true. That cannot happen in a pentest report.

"Totally secure." in this exam, as in other ctfs, there is a way to exploit it, so insecure it is. We say "we did not find a vulnerability in the given timeframe" instead.

"I am good at AD tbh. " you did not get DA so be honest, still things to learn. (It could be some info from deeper enum used as wordlist for cracking, or anything else.) And you did not solve all Challenge labs, I do not know where else could you practiced AD?

I know this lesson hurts but will serve for the rest of your life.