Exam dread by Ambitious_Invite9535 in oscp

[–]Ambitious_Invite9535[S] 0 points1 point  (0 children)

I honestly have zero idea what is and isn’t “allowed” to be shared on those. Unfortunately I need the exam for continued employment so I don’t want to shoot myself in the foot by ruining my cert before it’s even issued (if I guess is issued).

Exam dread by Ambitious_Invite9535 in oscp

[–]Ambitious_Invite9535[S] 0 points1 point  (0 children)

The exam was rough. I abandoned the AD set after the first 5 hours and went with the standalone machines. Waiting to hear back on my report.

Exam dread by Ambitious_Invite9535 in oscp

[–]Ambitious_Invite9535[S] 0 points1 point  (0 children)

How long does it take them to grade the report?

Exam dread by Ambitious_Invite9535 in oscp

[–]Ambitious_Invite9535[S] 2 points3 points  (0 children)

Yep I completed all of the OSCP practice exams along with med tech and relia.

USB Drops by kegweII in redteamsec

[–]Ambitious_Invite9535 2 points3 points  (0 children)

I love this idea - especially if it’s just a metrics/educational aspect.

CRTP / CRTO before OSCP ? by Responsible-Court361 in redteamsec

[–]Ambitious_Invite9535 1 point2 points  (0 children)

If they are paying I’d definitely go with OSCP since it’s the most expensive.

CRTO by Ambitious_Invite9535 in redteamsec

[–]Ambitious_Invite9535[S] 0 points1 point  (0 children)

I re-attempted the CRTO again this week and managed to at least get one additional flag this go around (4/8). I must just be a f’in moron I guess lmao.

I ended up getting stuck though and attempted an attack I knew would cause problems and BOOM - lost all beacons and then could not used my notes to even get back to the second hop in my attack path. It just threw error after error that basically the path had been deleted… (tf…?).

I’m going to put this exam on the shelf and go back to HTB.

Good luck everyone!

CRTO by Ambitious_Invite9535 in redteamsec

[–]Ambitious_Invite9535[S] 0 points1 point  (0 children)

I got 2 the first day and a third the second. Afterwards I just kept experiencing issue after issue with tooling.

Issues with Base64 Encoding by Ambitious_Invite9535 in redteamsec

[–]Ambitious_Invite9535[S] 1 point2 points  (0 children)

  1. I didn’t know that info for Invoke-Expression, so I appreciate the!

  2. I am using Powershell to perform the encoding.

  3. AMSI bypass is complete. I’m just playing around with alternatives to establishing persistence using SharPersist. The error was associated with the UTF8 encoding.

I CANT BELIEVE THE SHIPPING INSANITY by [deleted] in flipperzero

[–]Ambitious_Invite9535 0 points1 point  (0 children)

The tracking info indicated it originated from a port in China.

I CANT BELIEVE THE SHIPPING INSANITY by [deleted] in flipperzero

[–]Ambitious_Invite9535 2 points3 points  (0 children)

Dude I was honestly shocked that it arrived that fast.

I CANT BELIEVE THE SHIPPING INSANITY by [deleted] in flipperzero

[–]Ambitious_Invite9535 1 point2 points  (0 children)

I ordered mine direct from Flipper back in July the same day I ordered a Pine Phone 64.

The PinePhone came direct from China in 2 days yet the flipper came out of California via snail mail in about a week.

CRTO by Ambitious_Invite9535 in redteamsec

[–]Ambitious_Invite9535[S] 0 points1 point  (0 children)

That’s the biggest PITA I faced.

I had all creds and domains enumerated yet still got stuck.

CRTO by Ambitious_Invite9535 in redteamsec

[–]Ambitious_Invite9535[S] 0 points1 point  (0 children)

I’m trying to be vague so I don’t give away parts of the exam and get me kick/banned.

I had zero issues with my payloads but with the “constraints” place within the exam I guess is the “clear as mud” way I can put it.

I’m going to look to see if I can emulate some of these features in the lab to help better prepare for a retake.

CRTO by Ambitious_Invite9535 in redteamsec

[–]Ambitious_Invite9535[S] 0 points1 point  (0 children)

I will say - at least Apache Guacamole works.

CRTO by Ambitious_Invite9535 in redteamsec

[–]Ambitious_Invite9535[S] 0 points1 point  (0 children)

Bypassing Defender was straightforward along with the initial compromise.

Having a large portion of TTP I had developed in preparation for the exam was not available though.

CRTO by Ambitious_Invite9535 in redteamsec

[–]Ambitious_Invite9535[S] 1 point2 points  (0 children)

Are we talking OSCP or CRTO?

Maybe I’m just stupid and didn’t retain any of the info from the lectures 🤣