Hey everyone!
I wanted to write a review like everyone else but I guess by now you all know what OSCP is and how long the exam is so I just decided to make a quick guide and some tips.
About Me
I’m just a guy who’s cyber security is my hobby, I didn’t major in any computer-related field such as Computer Science and what not.
I know the basics of most of the languages and that’s all, I don’t program my own tools…etc.
Before taking the exam I was your regular black hat hacker lol, I kept hacking here and there until I decided to go the professional path = OSCP.
Material and Lab
The material will guide you through the basics only, and not EVERYTHING the true learning is in the labs.
The PWK lab will prepare you for the exam, however, if you want some resources outside the labs you HAVE to do these machines:
- Vulnix
- Brainpan
- Metasploitable (all)
- Mr. Robot
- Kioptrix (all)
HTB Windows Machines:
- Optimum
- Tally
- Devel
- Active
- Jeeves (Priv Escalation Part Is Great)
I know there’s a lot of other boot2root machines you can try, but those are my recommendations.
Exam
You have to connect both your webcam and ScreenConnect software before the exam in 15 minutes so the proctor can finish verifying your identity and some other stuff.
It’s okay to use an external machine for your webcam feed, for me I used my laptop for the webcam and the ScreenConnect on my working PC.
Be relaxed, the exam is for 23 hours and 45 mins, you have time.
for me I didn’t sleep, I just stayed up, finished in 12 hours then started writing my report.
Exam Report
You have to submit your whole walkthrough as a professional report, they have a report template available for you, use the latest one.
Make sure you include tons of screenshots for every command and output, that’s what I did my report ended being around 50 pages so it’s okay to include tons of screenshots.
You can read their exam guide here:
https://support.offensive-security.com/oscp-exam-guide/
They will fail you for the file format submitted and for the screenshot of the local.txt and proof.txt along with whoami/ipconfig/ifconfig so make SURE you don’t miss that.
Tips
- Get yourself comfortable with windows, I know most of us know exactly how to enumerate a Linux system but do you know windows?
- Check all the ways you can get a higher privilege other than just spamming kernel exploits (I didn't use a single kernel exploit in MY exam)
- Enumeration is the key
- if you have 2 vulnerabilities maybe you need to chain them???? Think out of the box.
- If you're trying the same thing over and over again, you're in a rabbit hole, GET OUT.
Hope it was kinda informative for you guys, if you have any questions I’m happy to answer without spoiling anything of course.
Thank you!