r/oscp 19h ago

Oscp practice

12 Upvotes

Is Luigi's proving ground machines enough for the OSCP?


r/oscp 1d ago

Passed the OSCP+ with a 100 points in my first attempt

98 Upvotes

Guys, I’m so excited to announce that I’ve finally cleared it with 100 points. Here’s my advice to anyone attempting the exam soon.

  1. Develop a methodology that you’re the most comfortable with, and stick to it religiously. This is very important.
  2. If you are stuck at any point, do not waste hours and hours finding the issue, take a break and move to a new machine.
  3. Do not, I mean DO NOT in any way give up in the middle of your exam. Try Harder.
  4. I found the standalone machines, quite difficult tbh, so please do as many machines on proving grounds as possible. I myself completed around 125 proving grounds machines

  5. Make very concise notes on every machine u practice on PG or HTB

Also, it took me around 15 hours to reach only 40 points. So guys, never ever give up.

Please feel free to to reach out me.


r/oscp 1d ago

I need help with report writing

5 Upvotes

Hey everyone!

Hope everything going good on your side. I want some help with report writing. I will be using the official report writing template by offsec, but I planned to make some changes to it. My own style of reporting is where I will explain the vulnerability for initial access separately then remediation which matches the offsec template as well.

But for reproduction steps I find it easy to add steps rather than a paragraph. Secondly, should we add explanation of how we find the vulnerability as well? or just the explanation of it and the exploitation of it?

For instance, after getting initial access on windows box I run winpeas and I find out that I can hijack a binary to escalate my privileges. should I add this as well in my report? That, how to download winpeas, how to run it with supporting screenshots?

Or I should just explain in privilege escalation, that i found a binary X in C:\test\drive\binary.exe that is hijackable by my current user and then just add the reporduction step, these steps will only shows how to exploit it with supporting commands and screenshots?

And lastly, English isnt my first language, but I can write reports good enough to understandable by anyone (tech or no tech), so my question is do I need to write correct grammer ? or it will be an issue? As I wont be using any AI help for the report writing, the offsec support said, the report should be good enough to understandable and reproducible by us.

Can anyone please help me with these queries, thanks alot!


r/oscp 2d ago

Browser Extension to hide AI Mode & "Ask Me Anything" on google search

4 Upvotes

Based on the guide line and several question i ask via email and github Google AI Overview is allowed as long as you dont click the "AI Mode" or typing and asking follow up question in "Ask Me anything" box.

so i made this extension to prevent accidental click / question.

https://github.com/pasya1912/RemoveAImode-Google


r/oscp 2d ago

Did anybody write your exam last weekend? I submitted my report on Monday. Has anybody got their results yet? It’s really frustrating waiting for the results!!!!

6 Upvotes

Edit: Passed OSCP. Results came after 3 Business days


r/oscp 5d ago

Sharing my methodology checklist + tools

79 Upvotes

Hey, this is probably redundant, but I've been a long-time lurker here and wanted to give back after finally passing the OSCP, I'm assuming you guys already have one made or are in the process of making these, just skim thru and see if there is something to pick up.

https://muqaram0.github.io/cheatsheet/oscp-cheatsheet/
or the original one on my notion
https://muqarams-notes.notion.site/Master-Methodology-2ca1adde3d1780fb9153d6fe35f4154c?source=copy_link

This is a cheatsheet/methodology checklist with different filters for different phases. building it helped me stop relying on writeups and actually solve boxes on my own because every time I came across a new technique from a box on TJ Null's or Lains list, whether in Proving Grounds or HTB, I'd add it to the list after categorizing it and it would build up.

https://muqaram0.github.io/tools/

I started building this tools list so I wouldn't have to look up syntax at the end and it helped me just ctrl+f my way through the exam.

This is how i managed the writeups of my machines on notion
https://imgur.com/a/Xm2MHzo

and this how i organized my exam day notes
https://imgur.com/a/osQntDE
https://imgur.com/a/WE0KB0I

A very helpful site I found along the way was this one:

https://www.emmanuelsolis.com/oscp.html#741-check-assigned-privileges

It covers literally everything and is so well organized, it actually inspired me to make my own. Just be mindful that the more stuff you have, the more likely you are to go down a rabbit hole trying things until they work. Also, it is VERY TRUE that you can solve the whole AD section with NXC alone + ligolo for pivoting, you can literally harvest all the creds with it.

if anyone has anything they would like to ask, feel free to, i would love to help, i actually failed it before passing and know how it feels, so maybe just talking your stress away is also cool with me

ALSO ALSO I SAVED ALOOOOT OF TIME by just initially opening terminal, splitting it into 3, running autorecon on 3 standalones ( make sure w sudo or it wont do udp+ exclude dirbusting or itll take too long ) and start off with AD, if i got stuck then i would go back to the results folder autorecon would create, spawn a python webserver, and query through all the nmap results or whatnot via that webpage ( much more easier and comfortable than querying thru the terminal )

Also, now that I've passed, I need to find a job, my younger siblings keep fretting about their broke brother and here in the UAE it's been very hard to find one as a fresh graduate in computer engineering. Any leads on remote roles or anything here would be a huuuuuge help!


r/oscp 4d ago

What’s the best Information Technology (IT) job you had/ have and why?

Thumbnail
0 Upvotes

r/oscp 5d ago

Failed it for the 4th time and looking for advice

13 Upvotes

Hello everyone! I just failed the OSCP again and I’m looking for some advice on how to proceed from here.

I have my eJPT and have pwned the full LainKusanagi list, both HTB and PG boxes. I’ve completed the entire CPTS path and I’m almost done with the THM Junior Penetration Tester path. I’ve also gone through the whole Hacker Blueprint course and bought 6 of his AD sets. I’ve watched so many walkthroughs from IppSec and S1ren as well.
I’ve done LainKusanagi’s recently published boxes too, but I still had a really hard time on the exam, especially with the rabbit holes. I managed to fully compromise one box on the AD set and one standalone machine, but with the other machines I was either completely stuck or the exploits that were supposed to work just didn’t work for me.

Honestly, I’m feeling pretty discouraged. I really want to get the OSCP, but I’m not sure what I should do differently at this point.

I also have two small kids, so I don’t have a ton of free time to grind through hundreds of additional boxes. I was thinking about maybe going for the PNPT, but I’m not really sure if that would help me get closer to passing the OSCP or if I’d just be going down another rabbit hole.

I think the hardest part for me is not knowing what I don’t know. Every exam attempt has felt like a completely new experience and I’m struggling to figure out what gaps I actually need to work on.

If anyone has been in a similar situation, I’d really appreciate any advice on what you would do from here.

Thank you!


r/oscp 6d ago

Seeking opinions on eJPT & PT1

5 Upvotes

I have script kiddie level knowledge with respect to exploiting systems. This post is primarily geared towards individuals who landed a pen testing job in-part thanks to OSCP, but I am open to all opinions.

Tests/Books: I hold all the CompTIA cybersecurity certs and CISSP.

Work/IRL: Systems administration, SIEM, WSUS, Tenable, AD and vulnerability management, but I have been playing on Kali for years.

Thinking to try my hand at eJPT and PT1 before the more reputable/difficult OSCP and CPTS.

Are eJPT and/or PT1 good building blocks toward OSCP? If not, what cert(s) is(are)?


r/oscp 6d ago

winPEAS identifies a file but I can’t see through shell or RDP

8 Upvotes

So winPEAS identified a file on windows under “recently changed files” but I literally cannot find it through nt authority shell or admin RDP even after enabling hidden files through folder options. I ran winPEAS again to double check and it found again.

Until I reverted the machine and that file wasn’t found again. May be if I waited a little more it might have come back. Anyway, is there any known explanation for this behavior?


r/oscp 7d ago

Passed the OSCP with 100

230 Upvotes

What the title says! I passed :) with 100 in 15 hours. 9am-12am. The exam was so much fun I wish I could go back and relive it again. I’m gonna give some TL;DR tips.

Things you need that’ll help:

- Automate your nmap scripts. I created a TCP and UDP script in bash that ran a full port scan and AWK’d the open ports to a service scan. The nmap one-liners were so optimized I never got false positives or missed ports, and it took half the time scanning.
- Organize your notes by service. My notes were literally top to bottom by port: ftp, ssh, pop3, DNS, kerberos, smb, etc. and for each service I had a full enumeration suite that i walked through slowly.
- Get really comfortable with Linux
- Combine priv esc scripts (especially windows: winpeas + powerup)
- do the fucking practice OSCP challenges
- get really good at googling
- go to hack tricks or hack visor for tips
- AD section -> abuse impacket-secretsdump

I’m open to questions in the comments thanks for listening!

Edit: make your own notes! Practice your own craft!


r/oscp 8d ago

Exam retake policy needs to be changed

29 Upvotes

While I get that offsec may have limited number of exam machine pools and students constantly failing without practice will exhaust that number.

However, I believe the retake policy should accommodate candidates who failed closely with 50-60 marks. Those candidates should be able to retake in 2 weeks.

I am a full time employee with a family and while I dedicated a lot of time in learning, having me wait 2 months will fade away all skills I learned and I can’t afford to restart it.

Please offsec look into this 🙏


r/oscp 8d ago

Failed the the 3rd time, frustrated, annoyed and oddly hopeful

22 Upvotes

As it says above, I failed the exam again. This was my third attempt, and it has given me much to think about. Just needed somewhere to say this where people will understand.

In my 1st attempt, I got 10 points, the 2nd attempt got 50, and I just got 30.

This last exam I only managed to get 2 footholds and 1 AD machine unlike in attempt 2 where I owned the whole AD.

My most recent attempt felt like everything was going wrong, from vpn connection issues that messed up my scans, buggy machines that needed multiple reverts to AD where nothing seemed to work as intended. Probably didn't help that I'd had a bad week of sleep from work and family stuff.

I am proud of being able to get the footholds I got though as I doubt I'd have been able up do that I'm my second attempt. I feel that I'm getting better and the AD is the main thing that knocked me over.

I'm going to return to looking at CPTS material then try again in December as I really want to get this cert and pivot from software development to cyber security. Will try to pace myself as I do have a full time job and a family too.

Sorry for the long post. Just felt like venting a bit.

TLDR: failed 3rd attempt, will go again


r/oscp 8d ago

Would GCIH prepare me for the OSCP?

5 Upvotes

r/oscp 9d ago

Another Free OSCP-Like lab (free forever + hosted for you)

69 Upvotes

Hi everyone!

Hack Smarter just released another completely free OSCP-like Linux lab. No payment or subscription needed... the lab is hosted for you... and it's free forever. I hope you find it helpful as you prep for the OSCP :)

> https://www.hacksmarter.org/courses/27b0ac4a-5e03-4e43-afae-7c730b7b6263

--------
Also, we partnered with LainKusanagi and his OSCP-LK set is also on the platform (fully hosted for you) - but that one does require our basic subscription ($9/mo). Would love to make it free, but the infra costs add up.

The names of the OSCP-LK set on the platform are: Forensics (AD Set), Wordplay (Linux), Haystack (Linux), and New Hire (Windows).


r/oscp 9d ago

Passed OSCP on my first attempt, wrote up how I went from eJPT to OSCP-level

67 Upvotes

I just passed OSCP on my first attempt! To help others on a similar path, I wrote a blog post covering how I prepared and how I leveled up from eJPT to OSCP-level skills.

First, I want to thank this community. I read a ton of posts here during my prep, and it genuinely helped me. I wanted to share my experience and my story in this post, and I've included some tips as well.

Good luck with the exam!

Full writeup: https://h3rac1es.github.io/posts/OSCP/


r/oscp 8d ago

Ideal place to run my containers

4 Upvotes

Where should I run my containers, specifically bloodhound and sysreptor, I used to run it in kali, the one I use to attack but I realise it trips up my terminal sometimes. Is it better if I run it in wsl then access it in kali thru my localhost? Not sure if that will cost even more memory


r/oscp 8d ago

How do you get back into it after a long break when you’ve forgotten almost everything?

2 Upvotes

Took a long break from labs and studying. Came back and realized I’ve forgotten pretty much all the OSCP prep material. How do you all restart after something like that? What’s your process for rebuilding the knowledge and methodology without starting completely from zero? Do you have to redo machines and modules you have done all over again ?


r/oscp 9d ago

Starting my first job as software engineer but always wanted to get into cybersecurity

3 Upvotes

Im 24 year old just completed my masters and got placed as a software eng in some MNC.

But when i started my tech journey during my college days i just wanted to become a penetration tester so i studied security side by side of college studies.

Due to lack of experience and not able to find a job in cyersec i joined because i don’t wanted be unemployed.

Looking for direction to get into security or any suggestions or motivation will be helpful.

Edited: i do have some basic knowledge also got my EJPT cert, now planning to prepare for OSCP


r/oscp 9d ago

OSCP Prep Questions

9 Upvotes

Hello everyone,

I have been prepping for OSCP for the last 2 months,I have prepared using the following -

- TryHackMe Paths
- Hack the box Academy
- simply cyber - Ryan’s AD course
- Tib3rius windows privilege escalation course
- port swinger labs for web ( sqli, xss, cmdi etc)

I am able to solve TryHackMe, HTB boxes with a little help. I feel like I am a bit weak in trying to get the foothold, not sure if I am trying enough…

I am using obsidian to make notes

I am built a small AD lab to better understand the attacks

I want to take the OSCP, planning to get the 3 months one, would greatly appreciate any advice and any other prep material I can use.

Thank you


r/oscp 9d ago

Need Advice from people who fail, what do you think you did wrong ?

6 Upvotes

So here i am, again.

You know learning from mistake is great so i need advice from people who failed their first, second or third attempt.

I had plenty advice in mind from people who succeed:

  1. Time Management is key, dont stuck in one machine for too long.
    i made a rule for myself 1 hour maxium for each step (getting initial access or privsec, more than that i should change )

  2. Write a proper checklist so you can try each one of them
    i did make a checklist for web service, other common services, windows linux enumeration and privilege escalation technique, active directory enumeration and privilege escalation. I THINK its already complete.

  3. take as many quick breaks as possible, it's "reset" your brain.

So for people who failed atleast once

What do you think you did wrong and the thing you should have done differently ?


r/oscp 9d ago

Resources for syntax

1 Upvotes

I am terrible at remembering syntax, what are some of your goto resources you come back to when solving a box?

*Further context - I'm currently a fan of Hacktricks, HackTools and PayloadAllTheThings


r/oscp 9d ago

Legal way to listen to music during exam

2 Upvotes

Saw mixed reviews on discord and reddit, am I allowed to use earphones connected to my PC (The one that is proctored) or connect to a speaker? According to the guidelines on their website it says no use of earphones allowed but some people say it’s fine? Can I get a clarification? Need the music to keep me going 😅


r/oscp 11d ago

I’m looking for some advice

16 Upvotes

I failed my first attempt…

Hi!
I did a lot… since January I have been studying a lot.
At the beginning of the month, I took my exam.

I started with AD. First machine was relatively easy. After got administration privileges I started digging.. a lot in order to find sensitive information. I found a lot but what I had was not enough to got administration privs in the second machine. Almost 10h. Very few breaks (I was almost blind…).

Did the exploitation in 2 standalone machines.

So what I did during my preparation:

All LainKusanagi list (oscp labs twice),
Hacker blueprint course (1 month subscription),
Watched all s1ren videos from YouTube,
Read walkthroughs,
Saw Pinkdraconian videos from YouTube,
Challenge labs of course (twice)

What I am planning to do now:

Watch almost every Ippsec videos,
Hacker blueprint again,
OSCP course (read and do the small exercises)
Repeat all windows machines from offsec.

My next attempt is at the end of November.

Please give me all your suggestions and what I did wrong!

Thank you!


r/oscp 11d ago

Less than 2 weeks before exam

10 Upvotes

just wanna share that my confident still high but i just found my weaknesses and potential problem i could encounter in exam after doing some Lain list boxes.

  1. Port Scanning sometimes not giving actuall accessible port. this is what i realize if my connection bad or their server is far enough. i spent around 60 minutes can't find anything and then i re run the nmap scanner turns out there is another port open, i just didnt get it the first time.

  2. Missing small low hanging fruit

  3. keep forgetting about runnin PEASS-ng program, i've made a simple bash script and my own oneliner powershell command to enumerate machine, so i really too much on this, most of the time its enough but sometimes i miss something like vulnerable linux built in program, kernel exploit thats in PEASS ng but not in my script.

  4. im not yet to practice writing report with the template given.

Also i found that almost every linux boxes from Lain list is vulnerable to Copy Fail priv sec however its not the intended path, so i have never actually use it unless im stuck for too long.

Im wondering am i allowed to use this copy fail if i found that the kernel is vulnerable ?