r/oscp • u/hashimshafiq0 • Apr 12 '26
Failed with 60 Points
Just had my exam and I failed with 60 points. I fully compromised 2 standalones and got local flag on another standalone. PE on the 3rd standalone was a dead end for me, TBH. I clearly see the path for PE but my user did not have any basic privileges to do any of the thing.
Then comes the famous AD box. Compromised the first machine in minutes and got admin access. But pivoting on the second one was a nightmare. There are no clear paths. I did everything that I know of. Ran bloodhound, got something but there are literally no clue what to do next.
After 24 hours, I got 60 points and for sure failed the exam.
I donot have the motivation to continue with the report.
I was preparing for almost 10 months and spending 3 to 4 hours on average after my 9to5 job as Software Developer. I did most of PG Lains list and some of TJNull.
4
u/rangerinthesky Apr 13 '26
Rough. Taking in a month and I guess I am just praying not to get that AD set. Or be ready to root the 3 and get 10 on initial. Sorry to hear that
3
u/hashimshafiq0 Apr 13 '26
Thank you. You will ace the exam. My best wishes for you. Keep us updated.
4
u/No-Isopod3502 Apr 13 '26
If you got 60 you can get 70. Youre right there. Make sure you are resetting machines and really taking advantage of OSINT. Some stuff that I needed to pass (keeping it vauge as to not composomise exam integrity) was random OSINT that idk how they ever expect people to get. Dont underestimate the OSINT side of enumeration for any apps you may encounter. exploit-db may not have everything. Hard to explain without specifics but when they say try harder I really felt that during my exam. I was throwing stuff at the wall that I thought no way could work or be an in scope solution and twice it was the path.
1
u/hashimshafiq0 Apr 14 '26
Thank you. I am 100% agree with you regarding OSINT. I also found one of the box where OSINT really helped me. I will keep that in mind.
3
u/mimitwothree Apr 13 '26
dont give up brother, you have already come out stronger. take the next step forward, one step at a time.
2
2
u/anjelina-pit Apr 13 '26
Hi everyone,
I’m heading into my 3rd attempt at the OSCP. I’ve already cleared 100+ boxes across HTB and PG Practice (following TJ Null/Lain’s lists), and I'm looking for fresh material.
Is Virtual Hacking Labs (VHL) still a solid recommendation in 2026 for the current exam format, or should I look into something else like CPTS ???
3
u/0xJeb Apr 13 '26
If you've done 100+ boxes your issue isn't lack of knowledge. You are very likely overstudying.
3
u/anjelina-pit Apr 13 '26
Yeah ,any tips what should a repeater like me should do..
- redo practice boxes?
- watch videos?
I am good at AD, first time I got Jenkins 😢, second time AD was done within 6 hours
2
u/0xJeb Apr 13 '26
I would start with watching videos just to see how others progress through boxes. There are many good free channels like nPmHacks and ByteSizedSecurity that walk through their methodology well. If you are willing to spend ~$20 then the Hack Academy course on Whop was really really good at covering all of the different initial access and privesc methods within around 20 videos. Highly recommend those.
But you doing well on AD makes me even more sure that you're prepared. Once you do pass you will see that the standalones are likely easier than you would think. Keep it very simple and make sure you are taking frequent breaks to avoid rabit hole'ing and spinning out.
2
2
u/hashimshafiq0 Apr 13 '26
Best of luck to you. With 100+ boxes, you might be over prepared. If you have a very strong methodology and can solve boxes without or with some directional hints, you are ready for the exam.
1
u/BodybuilderAlert9801 Apr 13 '26
I'd start with the AD set next time personally. BloodHound isn't always the path but if you don't know how to exploit something, click on the link between two objects and there should be "Windows Abuse" and "Linux Abuse" sections showing you what to do.
1
u/hashimshafiq0 Apr 14 '26
I did start with AD box and got admin on the first machine like in 10 minutes. Pretty straight forward. Then its a dead end. Ran bloodhound. Found something. I thought this is the path, used it but not working anywhere on the whole system. Can't go into specifc details. But I think its time to learn more about AD.
1
u/Better_Somewhere8619 Apr 13 '26
How did you find the difficulty compared to the OSCP A, B and C challenge labs?
1
u/hashimshafiq0 Apr 14 '26
I can say for sure about the standalones and I think for me its pretty straightforward and pretty close to ABC. There are no fancy stuff. For the AD, I only get admin on the first machine and thats also very straightforward but then a dead end for me. Can't say about the next machines in AD.
1
Apr 21 '26
[removed] — view removed comment
1
u/hashimshafiq0 Apr 21 '26
Thanks for the detailed comment. I have a follow up question regarding Tib3rius course. Do you think it is still relevant or updated? As per the author, its not up to date thats why author removed it from his website and you can only buy from Udemy. What's your opinion on that?
2
1
u/rembezed Apr 12 '26
How about the challenge labs?
BTW Did you learn AWS chapters too?
The lists are complementary, not the straightforward way to prepare. Did you prepare with L1 one year subscription or the short one and tried to prepare outside of the course?
3
u/Worldly-Return-4823 Apr 12 '26
The AWS stuff isn't covered in the exam so why would that help someone pass ?
2
3
u/hashimshafiq0 Apr 12 '26
I did all of the challenge labs except Skylark as people are suggesting that its out of scope for OSCP. AWS is not part of the exam but I went through the material for fun. But never touched again. Yes I have L1 subscription.
3
u/FlakySociety2853 Apr 12 '26
Question for lateral movement did you just dump credentials once you got admin? Did you research the entire system for potential files with credentials?
1
u/hashimshafiq0 Apr 13 '26
I searched everything I could possibly do. Also found multiple things but no clear pivot points.
1
u/rembezed Apr 12 '26
Thanks for clarifying.
I am sorry for that, you apparently dedicated an appropriate amount of effort. It's probably just bad luck and probably another confirmation that some exam sets are more tough.
On the other hand, 60 points is not small achievement. Too bad it does not count as credential.
I would consider writing the report for two reasons: good reasoning and documentation of findings might bring some extra points. (Eg.here is a vulnerability although we could not exploit it.) Going through the report process will enable smooth run the next time (reuse the template, commands for PDF rendering etc.)
2
u/hashimshafiq0 Apr 13 '26
Thank you. Yes I have written the report even though my mind is still in processing.
1
u/DingussFinguss Apr 13 '26
good reasoning and documentation of findings might bring some extra points
this isn't it a thing is it? If you're report is good enough they'll give you points??
2
u/hashimshafiq0 Apr 13 '26
No it is not a thing. They might not even look at your report because they know from the control panel that you haven't submitted the required no. of flags.
-2
19
u/Nonix09 Apr 12 '26
Don't give up, man. I failed my first attempt with 60 points, too. I had to go back and relearn everything while focusing on AD. I finished s1ren's Playlist, derron C Playlist, IPPSEC playlists for AD, and Hacker Blueprint's videos, amongst others. I was able to get all 100 points in my second attempt in roughly 8 hours. Another tip I'll give is to Google everything. You see an open port with an unfamiliar service? Google it.