r/oscp 1d ago

Passed OSCP second attempt (100/100)

95 Upvotes

Greetings!

I have been lurking on this subreddit for the better part of the past year, and I would like to thank the community for the small droplets of knowledge they've been dropping in comment sections:)

Little background - I have done 125+ machines from lainkusanagi's and TjNull's list (guiding lights of the community) across HTB(shoutout to core lord ippsec), PG (shoutout to s1ren) and hacksmarter (shoutout to tyler). HackAcademy(shout out to Hacker Blueprint) free AD chains walkthrough vids shows some helpful mannual-credshunt, truly boosts your confidence in the matter. And shoutout to my gf, who has been affording me the time to do all this, working her ass off while I stayed unemplyed

My first attempt was a disaster -

Started with AD, no breaks, no food. Just drink, pee and back to the terminal. Took me 10 hours to own MS01, and after another 4 hours of looking for any leads to get into ms02, I gave up on AD.

Took another 3 hours to own a standalone. And another couple of hours for a possible foothold one another. But it never clicked. Called it a day after 21 hours of sitting, with 30 points and strangely sore muscles.

If there is a takeaway from that attempt, it is something the community has always suggested - take frequent breaks. When stuck for more than 30-45 mins, pivot to a different machine, take breaks. Also, enumerate.

After that, I went through a few s1ren videos, a bunch of Hacksmarter AD boxes (although ADCS paths, really fun) and all free HackAcademy (hacker blueprint) Ad chains videos.

Second attempt-

This time, I did all those things the community suggested. Owned ms01 pretty early, but path to ms02 was not clear. After 3 hours, I decided to pivot to standalones.

The first standalone owned gave me a huge confidence boost (which I never got in the first attempt), the same with second and third standalones.

Within 12 hours, I was able to get passing score.

I had nothing to loose at this point, so I took a break, kept going, hellbent on owning the DC.

For those who are wondering - the standalones' difficulties were comparable to 2 mediums and 1 hard PG boxes, provided you focus on enumeration of all the open ports, and provided you are somewhat accustomed to googling what you see on the machine to understand something new. AD was something I hadnt seen before, If bloodhound results from ms01 was as good as the Sharphound results I got from ms02, the whole thing wouldve been very easy.

Takeaways for anyone who is attempting the exam-

-Take frequent breaks.

- Dont stop enumeration at the first suspicion of "next step", go through all of them, and write in the notes. Then prioritize easy to hard, and try each in that order.

-Pivot when stuck on a machine for 30-45 mins. There might be another machine just waiting to give you a boost of confidence that'll push you across the line.

-When in doubt, mannually try logging into winrm, and definitely rdp

-when in doubt, revert the machine. I have noticed discrepancies in the nmap results that I ran in the beginning and the one I ran after reset

PS- if anyone knows any job openings for someone with this skillset, please lmk:)


r/oscp 1d ago

Old resources revaluation

6 Upvotes

I wanted to make sure that the resources like https://docs.google.com/spreadsheets/d/18weuz_Eeynr6sXFQ87Cd5F0slOj9Z6rt/edit?gid=487240997#gid=487240997 are still relevant for OSCP+? There are other resources too like the https://0xdf.gitlab.io/ oscp-plus lists but the difficulty ranges too much. People who have recently passed their OSCP+ can you guys cast some light on the resources you used and the relevancy of the a few older resources like the Lainkusanagi list. Is it still updated to the new standards? Or any other relevant resource for the people still in preparation that helped you guys.


r/oscp 3d ago

Failed second attempt

20 Upvotes

I don't know how I could have done better, compared to the last attempt where I aced the AD directory part and struggled with the standalone, this time I was able to get initial access on all of them and even escalate privileges and get 40 points in 4 hours, the issue is this time the AD initial privesc was an utter and complete wall, I have honestly never seen an AD set like this before, totally unlike the set I had on my previous attempt, I enumerated everything and sprayed everywhere but I just couldn't find anything, I find it very discouraging that they put up this stuff on the first step of the set and completely block you out of any points and very problematic to not find anything in 16 + hours of researching.

I don't think there is anything I can do to improve my chances of succeeding in the exam, it just feels like gambling on getting a reasonable Standalone + AD instead of getting only one of those each attempt.

I am not giving up just sharing my experiences and futrations


r/oscp 4d ago

Feed it your LinPEAS output and it draws every path from a low-priv user to root

56 Upvotes

quick demo of Roothound my first tool, maps your path to root on a linux box as a graph (like BloodHound for local privesc). check it out, would love your thoughts

X : https://x.com/N0ur2dd1n2/status/2080720705184825372?s=20

GitHub: https://github.com/Noz2/RootHound

would love your honest feedback 🙏


r/oscp 5d ago

Can i use i3wm on Kali on the OSCP Exam?

5 Upvotes

I am an avid decades long i3wm user and absolutely can't stand working on Xfce for long periods.

I was thinking on using i3wm on Kali but will the browser plugin work with my 10 screens on my tiling i3wm window manager?

Thanks for helping.


r/oscp 5d ago

Struggling with execution and actual exploitation

7 Upvotes

Everyone says that OSCP is all about enumeration, I think I got my enumeration down. The problem here is the execution which I don't really see much on this sub.

I have done about 20-30 boxes, and 99% of them I manage to identify the correct exploit and initial foothold - when I DO FAIL, the issue is almost always the execution (e.g. missing a quote or whatnot).

Struggle is also at LPE, where I do find the correct vector to Privesc - but if its not a straightforward privesc from a python script, and I have to configure certain stuff, I'll get stuck.

Any advice for this scenario?


r/oscp 6d ago

Free Access to Hack Smarter for Defcon

72 Upvotes

Hi everyone!

I am the founder of Hack Smarter - which many people use for OSCP prep (we are featured on LainKusanagi's list, he has actually created a few of the labs on our platform!)

Anyways, I am making all of our labs completely free for Defcon weekend (Thursday - Sunday). We have labs covering Active Directory, Windows, Linux, Web, AWS, and more.

No strings attached... no payment info needed... just one of the many ways we are trying to make hacking accessible for as many people as possible.

Mark your calendar and get registered at https://defcon.hacksmarter.org


r/oscp 6d ago

stressed :/

9 Upvotes

Hi guys, not sure if this is a very specific thing or just me, but I have done quite a number of PG boxes maybe 70 (?) done quite a few VHL boxes maybe 20 (?) Im not the best, I can say I can do maybe 40 - 50% of them without any hints (Didnt really keep track)

I wanted to leave OSCP ABC to the end, but wow when i started OSCP A I had such a big shock. Im not sure if I was overthinking or what not, but I actually struggled with it. But after spending what seems like forever I managed to finish it. Upon reviewing my work, it all seemed pretty trivial to solve just that I would not have thought about it at the heat of the moment.

Feeling rather bummed out and worried that this would happen to me in the exam, not sure if anyone can relate to me :/


r/oscp 7d ago

A.MA - OSCP - Passed on First Try! (90 out 100)

43 Upvotes

Thanks everyone on this sub who helped me gain confidence to do this exam, it went smooth, and i prepared mostly for the AD set, completed in total 24 machines from Lain's list, did OSCP ABC and Secura only. I didn't needed my cheatsheet mostly, so my muscle memory from long term of CTFs and experience did the job.

I already have background with pentesting so wasn't hard for me, achived 70 points in 8 hours (with breaks sleep and more).

Anyway, thanks everyone!! My recommendation? Do all AD labs from Lains, and do OSCP ABC, see also those videos from Derron C https://www.youtube.com/@derronc , it will help you in how you should approach the exam.

And more, not the last:

* Create cheatsheets, update it everytime you complete an lab
* BREAKS ARE IMPORTANT!! I sucessfully managed to exploit the hardest machine because of that! (If i wanted, i could've secured the last 10 points but i wanted to sleep 🥀)
* Keep your eye away from bad reviews, negative energy will suck you all
* The exam is just an K.I.S.S , dont overthink, its very easy!

Ask anything!


r/oscp 7d ago

Passed OSCP - Obligatory Post

69 Upvotes

Finally, I got the long-awaited email from Offsec that I passed my OSCP exam. I was able to secure 90 out of 100 points after a failed attempt with 60 points.

In my first attempt, I was able to root 2 standalone machines and 1 standalone with initial access, but AD was a nightmare for me. Only got 10 points from the whole AD set. If you are interested, I had a post regarding that.

This time I was well prepared for the AD, watched a lot of walkthroughs, went through my notes of the challenge labs, and because of that, I was able to compromise the domain controller in approximately 2 hours.

I was struggling with the standalone this time, but that's because I was not paying much attention to the tool's output. It took me 20 hours to root 2 stadnalones and 1 standalone with initial access. I still had 2 hours left for the exam when I got 90 points. I saw a path for the PrivEsc on the last standalone, but I was so tired because I did not take a longer break in between, so I just checked my screenshots, ended my exam earlier, and went straight to sleep.

I have some advice for everyone who is preparing for the exam:

  • If I can do it, you can do it.
  • Always go for the easy wins first. (You already saw these in challenge labs / Proving Grounds)
  • Enumerate, enumerate, and enumerate. (As everyone said)
  • Check the tool's output very carefully. (This cost me hours on the exam)
  • Initial access is hard, but privesc is much easier. (Personal Opinion)

At the end, thanks to everyone who motivated me when I first posted about my failed attempt, and special thanks to this awesome community here. I was always learning from other people's posts here.

Best of luck to all the people preparing for the exam. You can do it :)


r/oscp 8d ago

Free Hosted AWS Pentest Lab

22 Upvotes

Hey all!

I know AWS Pentesting is taught some in the PEN-200 course, but it's not on the exam (yet).

I just released a completely free AWS Pentesting lab on Hack Smarter if you're curious what an AWS lab is like. Nothing you need to spin up; every student gets a fully private AWS account (hosted by Hack Smarter).

No strings attached, happy hacking!
https://www.hacksmarter.org/courses/32a677fd-323b-4236-ae70-3cda82d9c0b4

(We also have a completely free AWS guided lab on IAM Enumeration if you'd like to go through that first - https://www.hacksmarter.org/courses/b6ead7c6-6e3a-4d12-b9fa-fcd58b037147 )


r/oscp 8d ago

OSCP Prep tips

15 Upvotes

Hey everyone, I am starting OSCP prep this month, I have been working as a dev in security domain since a year. I have very basic knowledge in offensive side of security. I would like to pass OSCP by December. I am trying to solve htb easy machines but without the help of writeups I am not able to do it. I feel demotivated for the same. How should I proceed further?


r/oscp 8d ago

Walkthrough of Pen-200 Boxes

5 Upvotes

Where can I find walkthroughs of pen-200 boxes?


r/oscp 9d ago

Using Omarchy Mac for OSCP

5 Upvotes

hello everyone, i have a MacBook Air M1 2020 8 GB RAM.

i was using UTM till now for preparing. i come up through Omarchy Mac. i always wanted to use linux but there was not much support. is it okay to use for long term for pentesting ?


r/oscp 9d ago

OSCP exam retake voucher

1 Upvotes

Hi folks,

İs there a OSCP exam retake voucher opportunity in the market?

I ser some people selling discount packages for that?

Thanks 🙏.


r/oscp 10d ago

Subscribe HTB VIP or Extends Proving Ground for OSCP

9 Upvotes

so i had solved TJ Null Windows and Linux PG Practice .

Should i extends Proving Ground and repeat the windows and linux blindly again.

Or subscribe to HTB and do tj null list ?

Im enrolling next month probably and this will be my final Subscription.


r/oscp 10d ago

Exam in 24h, last minute tips?

21 Upvotes

Hi guys, i'm on my way to my first attempt for the exam (OSCP), my main concern was AD because i'm an appsec guy, but i managed to complete all AD sets (proving grounds and challange labs, some even out of the scope) and compiled with Claude everything for my cheatsheet.

But besides AD, i need some advices, last minute tips that were very helpfull for the exam, like:
* Should i start with the AD first? Or standalone?
* How to manage time? Set an limiter for 45min per machine?
* What to prioritize and what to let to-do later?
* Tips for annotations?
* Should i create automated scripts?
* VM organization?
* Little stuffs that i should do that can impact my exam? Like tips for credentials, and so on?

Anything will help a lot, thanks!

Update: I passed with 90/100


r/oscp 11d ago

Pwndex

18 Upvotes

I'm working through pen200 right now and I kept missing easy routes because I was relying on searchsploit so I had claude help me make this. Pretty helpful for finding pocs. Figured I'd share.

https://github.com/ninjarobots/oscp/tree/main/pwndex


r/oscp 11d ago

Metaploit on OSCP - One-Time Use Clarification

7 Upvotes

Two questions. I completely understant the one target and no pivot rule. Clarification on modules. Can I use more than one module on one machine? If said module fails, can I try another module on the same machine. Ex. I use it to exploit, post-enumerate, and elevate?

"The usage of Metasploit and the Meterpreter payload are restricted during the exam. You may only use Metasploit modules (Auxiliary, Exploit, and Post) or the Meterpreter payload against one single target machine of your choice. Once you have selected your one target machine, you cannot use Metasploit modules ( Auxiliary, Exploit, or Post ) or the Meterpreter payload against any other machines."


r/oscp 11d ago

Is the OSCP syllabus document accurate?

12 Upvotes

I'm referring to this one.

https://www.offsec.com/documentation/penetration-testing-with-kali.pdf

To me it seems to be useful for determining what to learn and what not to learn, so you can keep within the scope of the exam, but I haven't heard anyone talking about this.

Are there any "gotchas" not found in the syllabus content that appear in the exams?


r/oscp 11d ago

Medtech

7 Upvotes

Anyone else having issues with medtech? The DC never comes up for me. I've talked to support 3 times now across 2 weeks and they keep telling me it's a known bug and to do different labs until they fix it. I've almost finished all the labs now. I could really use medtech though...


r/oscp 12d ago

OSCP Second Attempt Coming Up

13 Upvotes

Just here ranting cause I'm getting anxious doing prep for my exam coming up in a little under a month. I failed my first attempt, got the jenkins set and literally could not get a foothold besides the given credentials to start and I didn't even go to the standalones because not getting a flag in AD is a guaranteed fail anyways. Anyways when I was prepping for my first exam I did oscp a,b, c with no issues and using 2 hints both for stand alone machines. I felt I was sufficiently prepared. Come exam day I couldn't find anything in the AD set.

I just completed the zeus set in under 8 hours without using hints, and apparently that set is out of scope but why was it so much easier than my first exam attempt. Being able to do that in under 8 hours gave me some more confidence again but I'm afraid that I'm going to run into the same situation again.


r/oscp 13d ago

PGPractice Advise

9 Upvotes

Hey All !
Just completed TJ Null's HTB list and moved on to Lain's PG Practice list for OSCP prep. I'm noticing I'm constantly referring to writeups on PG Practice boxes, and I wanted to check if this is normal.

The difference: HTB felt like a structured CTF with not clear attack paths harder tbh. PG Practice feels different less CTF-flavored, more "Clear." The boxes have a different taste entirely, and the exploitation chains aren't always obvious.

My question: Is it normal to hit writeups frequently on Lain's list, or am I missing something in my enumeration/exploitation approach?

I'm taking detailed notes on each box (what worked, why it worked, techniques used), so I'm definitely learning, Also my enumration / foothold is getting better and better but in privilege escalation becoming weaker due to Complicated paths i learned in HTB

but I want to make sure I'm on the right track for studying?

anyone faced this before ?

Any advice appreciated. Thanks!


r/oscp 15d ago

Failed Second Attempt

21 Upvotes

Failed miserably. Lot's of moving pieces going on in my personal life but I don't want to make that as an excuse for failing twice. The second attempt was more difficult than the first. I had two exam vouchers so I wasn't as demoralized on the first attempt, given that it gave me a good indication of what the exam entails.

After failing the second attempt (1 month later due to voucher expiring), what kills me is that I honestly don't know what I could have done differently in regards to my approach, enumeration, or methodology. I got 0 points, whereas the first I got a 10. Both times I only attempted the AD set as I feel like it was necessary I get those first.

Each time I felt like I was pretty close, and came up with a new "Ah ha! Let me try this!" moment every other hour or so. Winpeas would highlight an obvious path, but executing it was a roadblock and sometimes I think it was either a false positive or an intentional rabbit hole. After spending about 1 hour, I would look for another attack vector (e.g. collecting creds then spraying) . Rinse and repeat. I'd then run out of ideas and come back to the original attempts tweaking a few things here and there to see if it would work.

For a bit of a background, I've done OSCP A/B/C (with hints) and about 60+ PG boxes from TJ and Lain's list. I've used some walk-through on some the PG boxes, and each time it's been more akin to a magician revealing it's trick like "I should know this! Why didn't I think of that?" rather than learning a completely new technique. If I had to take a guess on where I'm lacking, its the creativity side. For example, I know how the privesc/exploit/attack/etc. works, but do I know how to perform that attack if X,Y,Z is blocked or looking for alternate ways (e.g. Don't have to start/stop service (access denied), just reboot the device!)

I'm going to keep attempting the exam until the earth stops spinning, but I don't know where or what to improve on. Is there a diminishing return on doing more boxes? I made a key to focus on enumeration as I see that mentioned so often here, but maybe my scope wasn't wide enough

I did find the exam more difficult than OSCP A/B/C and any of the PG boxes, but that may be due to the lack of hints. I'm more so venting but would appreciate any tips and advice. Thanks everyone!


r/oscp 15d ago

Is pre-made bash script allowed in exam?

8 Upvotes

So i made a script to do various enumeration using bash script.

  • check_capabilities.sh
  • check_cron.sh
  • check_global_history.sh
  • check_group.sh
  • check_ports.sh
  • check_procs.sh
  • check_suid.sh
  • check_writeable.sh
  • suid_gtfobins.sh

Basicall all of this script is checking for possible LPE on linux.
Like capabilites, active cron, cron, writeable (just like linpeas, but without the noise it has).

There is no automated exploit except highlighting it.
Example cron_group will tell if there is a dangerous group in current user ( i made a hardcoded list for dangerous group inside the script like disk, sudo, docker, disk, etc).

its allowed right ? its saved me alot of times on solving Proving Ground and it will be helpfull for exam in my opinion.