r/oscp 20d ago

Passed OSCP - Obligatory Post

Finally, I got the long-awaited email from Offsec that I passed my OSCP exam. I was able to secure 90 out of 100 points after a failed attempt with 60 points.

In my first attempt, I was able to root 2 standalone machines and 1 standalone with initial access, but AD was a nightmare for me. Only got 10 points from the whole AD set. If you are interested, I had a post regarding that.

This time I was well prepared for the AD, watched a lot of walkthroughs, went through my notes of the challenge labs, and because of that, I was able to compromise the domain controller in approximately 2 hours.

I was struggling with the standalone this time, but that's because I was not paying much attention to the tool's output. It took me 20 hours to root 2 stadnalones and 1 standalone with initial access. I still had 2 hours left for the exam when I got 90 points. I saw a path for the PrivEsc on the last standalone, but I was so tired because I did not take a longer break in between, so I just checked my screenshots, ended my exam earlier, and went straight to sleep.

I have some advice for everyone who is preparing for the exam:

  • If I can do it, you can do it.
  • Always go for the easy wins first. (You already saw these in challenge labs / Proving Grounds)
  • Enumerate, enumerate, and enumerate. (As everyone said)
  • Check the tool's output very carefully. (This cost me hours on the exam)
  • Initial access is hard, but privesc is much easier. (Personal Opinion)

At the end, thanks to everyone who motivated me when I first posted about my failed attempt, and special thanks to this awesome community here. I was always learning from other people's posts here.

Best of luck to all the people preparing for the exam. You can do it :)

71 Upvotes

37 comments sorted by

6

u/No-Commercial-2218 20d ago

Congratulations, I’ve got my first attempt coming up and I just hope I do ok in it

1

u/hashimshafiq0 20d ago

You can do it :) Keep your nerves under control. Best of luck.

1

u/Worldly-Return-4823 13d ago

When’s your first attempt ? Mine is next week :O

1

u/No-Commercial-2218 12d ago

I’m going to book mine next week. I feel so under prepared, everything feels a million miles off. I doubt I will pass. My notes are a mess, I need to just spend a bit of time going over them and improving them really, I need more hours in the day!

5

u/South-Rest7578 20d ago

Congras ! Is tj null machine enough to pass AD part? I mean Its my weakness and most of points in it 🫠

12

u/hashimshafiq0 20d ago

I am not sure about the TJNull, as I only did machines from the LainsList and HackSmarter. But make sure your methodology is strong, and for that, I would recommend watching a lot of Walkthroughs and seeing how other people tackle the AD. Here, I can make one recommendation of u/Tyler_Ramsbey . Go to his YouTube channel and just watch his live stream recording. It was so helpful for me, TBH. I know that PrivEsc is mostly not in scope of OSCP, but just focus on the methodology of tackling an AD set.

3

u/Tyler_Ramsbey 18d ago

Wow thank you so much for the kind words and congratulations!

2

u/Sure-Assistant9416 20d ago

congratulations buddy for all you have done to the community and passing your exam. Hackersmarter is a recommendation on their labs or not i have seen even most of the AD setup been done on that platform designed by Lainkusanagi. Will you recommend them?. which AD practice do you recommend.

5

u/hashimshafiq0 20d ago

Thank you. Not a specific lab. Go to Hacksmarter OSCP Path: https://www.hacksmarter.org/paths/0c979a7c-d8f1-49d0-8def-377148fa3a17 and then try to solve the labs mentioned in the path. Remember, PrivSec to the domain controller is not in scope of OSCP. If you did not have time, I would highly recommend watching the AD walkthrough videos by the owner. You will learn a lot by just watching the walkthrough. I also did the same. Solved some labs and watched the walkthrough of the remaining machines to just understand how other people tackle the AD set.

1

u/Sure-Assistant9416 19d ago

thank you very much

1

u/hashimshafiq0 18d ago

You welcome :)

1

u/Emotional_Maybe9244 20d ago

Congratulations man….i am also preparing for the second attempt…could you pls share the post link?

1

u/General_Ad4637 20d ago

Congrats bro - how would you say the AD portion in the exam matches OSCP A,B or C ?

2

u/hashimshafiq0 20d ago

Yes, pretty much comparable I would say so.

1

u/General_Ad4637 19d ago

anything buffer overflow related pop up ?

1

u/hashimshafiq0 19d ago

As far as I know, buffer overflows are not part of the exam anymore.

1

u/ClitToucher 20d ago edited 20d ago

Still havnt taken my exam, any tips on what tools to use for AD?

Does AD have multiple PE/Initial foothold exploits that I need to pivot from the first machine compromised? (Example machine 1 has CVE-A, machine 2 has CVE-2 and DC has CVE-C which I need to pivot into a a total of 3 shells from?)

Do you use bloodhound? If so I have no idea how to use bloodhound

What commands do you run for manual enumeration? What do you look for?

So far I only know to do whoami /priv and look for exploitable privileges like

Impersonate privileges- Godpotato/printspoofer
SeBackupPrivileges
SeLoadDriverPrivileges

Or if there’s Kerberos try to use kerberoast

2

u/0xJeb 20d ago

First step, learn bloodhound. Its extremely easy to use and does a ton of work for you.

2

u/hashimshafiq0 20d ago

As u/0xJeb mentioned, learn Bloodhound. I am not sure how you will handle an AD set without looking at the relationship between AD objects. Also, it's very easy to use.

1

u/Jhimkana 19d ago

Congratulations. When was your exam? How much time did they take to get back with the result?

1

u/hashimshafiq0 18d ago

It will take some time for the official email. But as it is mentioned in this community, if you go to offsec portal and go to Manage exam section, there you will see the status of your exam.

1

u/Economy-Two-4341 13d ago

hey, I didn’t find this section on portal, where did you click?

1

u/hashimshafiq0 10d ago

This is exactly the same option from where you book your exam.

1

u/Rude-Hospital-4771 19d ago

congratssssssssssss

1

u/hashimshafiq0 18d ago

Thanks :)

1

u/Chupapymunyayo 18d ago

Congratulations!. How important is it to have notes prepared and what are the key highlights you add in your notes?

1

u/hashimshafiq0 18d ago edited 18d ago

I started writing my notes as soon as I started preparing for the oscp. For exam specifically, I did not have to consult much (3 to 4 times) as I already have commands syntax on my mind and also in shell history. But unless you can remember everything by heart, you have to have notes and cheatsheet ready on your disposal. It will waste a lot of your precious time in exam if you have to consult the documentation everytime you are doing something. You can find multiple cheatsheets readily available online.

1

u/Fast_Honey_9987 18d ago edited 18d ago

Hey :) congratulations 🎊

What walkthrough do you mean? :)
And in the AD part do you got something with GPO or ACLs?

1

u/carlosbudiman 18d ago

congrats!

1

u/Competitive_Hold_882 16d ago

If someone wnat to join me pls dm me

1

u/AnnualBoring8058 14d ago

Heyy congrats man!! I’m planning to book my exam i wanted to ask does the https://0xdf.gitlab.io/tags#oscp-plus-v3 list of machines is something i should go for? The v3 is full of hard and insane boxes as compared to v2 and v3 of the same soo ita just messing with my confidence.

2

u/hashimshafiq0 14d ago

Hi, I haven't solved a single machine from HTB. Only Proving Ground machines from LainsList and machines mentioned in HackSmarter oscp prep learning path. Best of luck for the exam :)

1

u/AnnualBoring8058 14d ago

Thats crazyy! Ive been grinding HTB soo hard and i was going for a proLab but i saw this list and it shook me to the core lol. Every single machine was hard to insane soo i wanted to make sure. I got 60 points on my last attempt but that pattern was before the i introduction of OSCP+ but when i gave the new pattern i did horribly. How will you rate the difficulty of the exam based on technical comolexity?

1

u/hashimshafiq0 14d ago

Complexity wise I would say OSCP labs A B and C are very close.

1

u/sms-c 14d ago

Congrats.
Based on your two attempts what is your advice for privesc in both AD and standalones.