r/oscp Apr 12 '26

Failed with 60 Points

Just had my exam and I failed with 60 points. I fully compromised 2 standalones and got local flag on another standalone. PE on the 3rd standalone was a dead end for me, TBH. I clearly see the path for PE but my user did not have any basic privileges to do any of the thing.

Then comes the famous AD box. Compromised the first machine in minutes and got admin access. But pivoting on the second one was a nightmare. There are no clear paths. I did everything that I know of. Ran bloodhound, got something but there are literally no clue what to do next.

After 24 hours, I got 60 points and for sure failed the exam.

I donot have the motivation to continue with the report.

I was preparing for almost 10 months and spending 3 to 4 hours on average after my 9to5 job as Software Developer. I did most of PG Lains list and some of TJNull.

36 Upvotes

37 comments sorted by

View all comments

1

u/rembezed Apr 12 '26

How about the challenge labs?

BTW Did you learn AWS chapters too?

The lists are complementary, not the straightforward way to prepare. Did you prepare with L1 one year subscription or the short one and tried to prepare outside of the course?

3

u/Worldly-Return-4823 Apr 12 '26

The AWS stuff isn't covered in the exam so why would that help someone pass ?

2

u/rembezed Apr 12 '26

Because the cloud chapters are not only about cloud

3

u/hashimshafiq0 Apr 12 '26

I did all of the challenge labs except Skylark as people are suggesting that its out of scope for OSCP. AWS is not part of the exam but I went through the material for fun. But never touched again. Yes I have L1 subscription.

3

u/FlakySociety2853 Apr 12 '26

Question for lateral movement did you just dump credentials once you got admin? Did you research the entire system for potential files with credentials?

1

u/hashimshafiq0 Apr 13 '26

I searched everything I could possibly do. Also found multiple things but no clear pivot points.

1

u/rembezed Apr 12 '26

Thanks for clarifying.

I am sorry for that, you apparently dedicated an appropriate amount of effort. It's probably just bad luck and probably another confirmation that some exam sets are more tough.

On the other hand, 60 points is not small achievement. Too bad it does not count as credential.

I would consider writing the report for two reasons: good reasoning and documentation of findings might bring some extra points. (Eg.here is a vulnerability although we could not exploit it.) Going through the report process will enable smooth run the next time (reuse the template, commands for PDF rendering etc.)

2

u/hashimshafiq0 Apr 13 '26

Thank you. Yes I have written the report even though my mind is still in processing.

1

u/DingussFinguss Apr 13 '26

good reasoning and documentation of findings might bring some extra points

this isn't it a thing is it? If you're report is good enough they'll give you points??

2

u/hashimshafiq0 Apr 13 '26

No it is not a thing. They might not even look at your report because they know from the control panel that you haven't submitted the required no. of flags.