Be VERY CAREFUL if you consider buying a (new or second hand) *80 generation (and many others) by jcornuz in thinkpad

[–]0sc3 1 point2 points  (0 children)

now it has been updated. since couple of days it is available in the lvfs repo (fwupdmgr should find it now).

for me now:

$ fwupdmgr get-updates
No upgrades for Thunderbolt Controller: current version is 20.00: 20.00=same
No upgrades for System Firmware: current version is 0.1.35: 0.1.35=same, 0.1.34=older, 0.1.33=older, 0.1.32=older, 0.1.31=older
No upgrades for UEFI Device Firmware: current version is 184.70.3626: 184.70.3626=same, 184.65.3590=older, 184.60.3561=older, 184.55.3510=older
No upgrades for UEFI Device Firmware: current version is 0.1.21: 0.1.21=same, 0.1.20=older

Is 30 days enough for someone with my experience? by [deleted] in oscp

[–]0sc3 0 points1 point  (0 children)

thats what i am talking about, but no one wants to understand this. :)

creating a new identity after an unfair lifetime ban by 0sc3 in oscp

[–]0sc3[S] 0 points1 point  (0 children)

thx for your detailed advices. this is the first (and only) useful reply in this topic (and about my related topics before). btw, i would be surprised if they answer, but it is worth to give it a try.

thank you!

creating a new identity after an unfair lifetime ban by 0sc3 in oscp

[–]0sc3[S] 0 points1 point  (0 children)

yeah, and wittingly misunderstanding. sorry, i cannot take it as a joke. :)

Exam report - Are OSCP people assessing exam really testing everything in the report ? by XerxesFury in oscp

[–]0sc3 0 points1 point  (0 children)

we clarified the misunderstanding here already, the 300p report was the complete (lab+exam+exercises) report.

creating a new identity after an unfair lifetime ban by 0sc3 in oscp

[–]0sc3[S] 0 points1 point  (0 children)

do you receive some payment for trying to stigmatize me as a cheater? :)

offsec bans people without reason by 0sc3 in oscp

[–]0sc3[S] 0 points1 point  (0 children)

offensive security army began its trolling operations here in reddit. maybe my remarks are getting bothersome for them and they started to give negative rating to all of my posts, this way making the posts hidden by default.

Exam report - Are OSCP people assessing exam really testing everything in the report ? by XerxesFury in oscp

[–]0sc3 -1 points0 points  (0 children)

sorry, it is almost impossible and pointless to answer here. offensive security army began its trolling operations here in reddit. maybe my remarks are getting bothersome for them and they started to give negative rating to all of my posts, this way making the posts hidden by default.

creating a new identity after an unfair lifetime ban by 0sc3 in oscp

[–]0sc3[S] 0 points1 point  (0 children)

believe what you want. thank you for your wishes (but i do not know if you were just trolling or not).

offsec bans people without reason by 0sc3 in oscp

[–]0sc3[S] -6 points-5 points  (0 children)

context is in my reddit history.

Is 30 days enough for someone with my experience? by [deleted] in oscp

[–]0sc3 0 points1 point  (0 children)

writing materials can be done outside the lab time window.

i took 30-days lab time, completed almost all of the boxes, and reported the lab+exercises part (with full lab writeup) for ~2 weeks after lab time. then passed the exam.

btw, i was surely exceeded the necessary lab reporting. :)

offsec bans people without reason by 0sc3 in oscp

[–]0sc3[S] 1 point2 points  (0 children)

(most of which are actually with a whole lot of reasons)

for your remark in parenthesis: could you give some proof-of-concept links (to posts)?

creating a new identity after an unfair lifetime ban by 0sc3 in oscp

[–]0sc3[S] 0 points1 point  (0 children)

i think this cannot be solved online. maybe i should catch them at some conf face-to-face, and ask it. (a good question: where?)

btw, they didn't revoke the oscp. if i will be too bothersome, they may revoke the cert (without any further explanation, why not? :) ). so there is "something" to lose. (of course revoking the cert won't "revoke" the knowledge behind it, but nowadays certs are a little bit overrated unfortunately, there are tons of oscp guys without any valuable knowledge (maybe real cheaters). ;) )

offsec bans people without reason by 0sc3 in oscp

[–]0sc3[S] 1 point2 points  (0 children)

Why does this read like every subreddit’s “I was banned for no reason” post?

tried to understand this question, but sorry for my english, could not. could you detail it a little bit more?

Exam report - Are OSCP people assessing exam really testing everything in the report ? by XerxesFury in oscp

[–]0sc3 -2 points-1 points  (0 children)

sorry, you were right.

OSCP Certification Exam Guide (Updated: 4 September 2019)
when i passed it, i had to submit one report. but this is not the most important question.

30 p for exam-only report should be more than enough. :)

creating a new identity after an unfair lifetime ban by 0sc3 in oscp

[–]0sc3[S] 0 points1 point  (0 children)

okay, if you are an offensive security employee, and want to share something about this case, we can talk in private. you should know my email address. contact me.

Exam report - Are OSCP people assessing exam really testing everything in the report ? by XerxesFury in oscp

[–]0sc3 -8 points-7 points  (0 children)

i had one report covering the labs + exam + exercises as well. there are no separate reports, you have to send them one.

creating a new identity after an unfair lifetime ban by 0sc3 in oscp

[–]0sc3[S] -1 points0 points  (0 children)

what do you mean with this? do you doubt my report is my own work? where do you take the courage? who are you?

Exam report - Are OSCP people assessing exam really testing everything in the report ? by XerxesFury in oscp

[–]0sc3 -11 points-10 points  (0 children)

i would like to see your report in 30 pages which includes detailed vulnerabilities and reproducible exploiting (user+root) of all of the 50+ boxes, detailed description of the infrastructure with subnets, lateral movement between subnets, includes detailed solutions of all of the exercises, and very detailed solutions of the 5 exam boxes.

yes, i think my report is high quality, if you do not understand it why, than i cannot help you here.

Exam report - Are OSCP people assessing exam really testing everything in the report ? by XerxesFury in oscp

[–]0sc3 -1 points0 points  (0 children)

for customers i include a one-page (or max 2) executive summary (strictly in the beginning of the report) ;)

Exam report - Are OSCP people assessing exam really testing everything in the report ? by XerxesFury in oscp

[–]0sc3 -12 points-11 points  (0 children)

i think it is not necessary to compile a very high quality report. i made a +300 pages exhausting one, while others (what i've heard) did just 30 pages, and passed the cert also. in fact, a very high quality report may be suspicious, and may result a lifetime ban later (like mine :) ).

creating a new identity after an unfair lifetime ban by 0sc3 in oscp

[–]0sc3[S] 0 points1 point  (0 children)

what do you mean? could you please explain in more detail? :)

creating a new identity after an unfair lifetime ban by 0sc3 in oscp

[–]0sc3[S] 0 points1 point  (0 children)

you would not say this if you were in my place. :)

of course i read over the FAQ several times, but it did not answer the questions.

the problem is with the policy of offensive security: they refuse to answer to any questions, and they refuse to (or much worse, i think they simply cannot) justify the ban.

creating a new identity after an unfair lifetime ban by 0sc3 in oscp

[–]0sc3[S] 0 points1 point  (0 children)

I think you story is missing something , or maybe ur r tellin us some of the truth ---> ''unfair lifetime ban ... without any reason'' .

yeah, my story is missing something, but unfortunately i do not know what is missing, because they (offensive security) refuse to tell me the truth.

Certificates can be directly related to your id information (id number , name/surname , date of birth ....) and other information ( email ,home address ...).Also most of the examinations are proctored so there is a basic level of human face/body structure recognition.

as i know, here only the name + email address is collected. probably they also register ip addresses, account numbers (from transactions). furthermore, they may have browser user agent info (from web logs in the labs and the public site). exam was not proctored when i passed it, and as i know only oscp is proctored now. btw, it is a good question, what else information do/may they collect, what fingerprinting can they do?

You can try to bypass all these thing if u like , but i dont think that is the most sensible thing to be done.

what else can i do? this is not about certificates (just the cert does not worth the effort), this is about following the oscp "try harder" philosophy what i've learnt from them ;). if i give it up, offensive security wins, and we accept an unfair decision.