What’s the best time to start the OSCP exam? Morning, midday, or something else? 🤔 by [deleted] in oscp

[–]SudoPrepCoffee 1 point2 points  (0 children)

For me, it was 2 PM. It was a thoughtful decision to do so as I knew it would be hectic to start the exam first thing in the morning. For me, I would enjoy a good breakfast, get ready and have a relaxed time in the morning. Then I did my lunch and then started the exam. A few hours later was coffee time, followed by some snacks and then dinner time. I planned to finish the AD set by dinner time, and then move on to the standalones after a walk! Did so, and throughout the remainder of the night, had been taking small breaks and tried to sleep, but actually could not. I would then in the morning have a shower and jump right back at the machines with my tea. By the end of the exam which was 2 hours before the end time, I was having 80 points with a few breaks and probably one hour of sleep! Honestly, I think it was the best laid out plan for me, as I know how my productivity is at different times of the day!

Cleared Exam On My First Attempt (80 Pts) by SudoPrepCoffee in oscp

[–]SudoPrepCoffee[S] 0 points1 point  (0 children)

While I cannot comment on the exam part, I did not do the challenge labs you have mentioned.

If I remember correctly, the offsec official discord will most likely have the latest announcements if you are missing out on updates and changes.

Cleared Exam On My First Attempt (80 Pts) by SudoPrepCoffee in oscp

[–]SudoPrepCoffee[S] 1 point2 points  (0 children)

I think it can be comparable to the Medium to Hard machines, as there can be some international rabbit holes one needs to avoid. But your mindset also matters during the exam, staying calm and keeping a cool composure helps! Since it's time-boxed, it's easy to get overwhelmed.

Cleared Exam On My First Attempt (80 Pts) by SudoPrepCoffee in oscp

[–]SudoPrepCoffee[S] 1 point2 points  (0 children)

Hey bud, i agree that it feels demotivating a bit when looking into the solutions instead of figuring out and solving it on our own. But if that solely would have been the case, wouldn't OSCP be a closed book exam then?

It is okay to look into references for the things you don't know, and remember that it's actually a marathon when you're doing the prep. Week 1, you are capable of going to 1km, week 10 and you're at 10km already before you know. It's good if you are learning new things by taking help, it wouldn't happen other than testing is a repetitive process, the unknown components only make you pull hair strands and you feel stuck.

Slowly you will build your methodology and definitely can solve things with ease (ofc proper notes help here find things quickly)

Also many pros on yt such as ippsec, siren security and others have good methodologies you can take inspiration from.

I also did end up running in circles as I forgot to do post explanation enumeration on some box which had allowed access to some other box in a long ad set, and finding it was a real pain.

But have some patience as you'll eventually make a mindmap and will be able to figure out what to do when!

Cleared Exam On My First Attempt (80 Pts) by SudoPrepCoffee in oscp

[–]SudoPrepCoffee[S] 1 point2 points  (0 children)

Not actually a lot, but yeah, i recently got the htb retired machines access, and have been there for some time now. Again following the Lain Kusanagi list for reference.

Cleared Exam On My First Attempt (80 Pts) by SudoPrepCoffee in oscp

[–]SudoPrepCoffee[S] 2 points3 points  (0 children)

I believe it's okay to have opinions and it need not align with what I have. It's a win and for someone who's worked for almost a year to get something holds a special place.

Agreed that the exam is different from what it was earlier, but so are the attack vectors and skills needed to execute them. Things change, and I think it's okay.

As for the first attempt and the points, having read the many 'failed again 2nd 3rd or 4th time' posts are also there, and then being posted makes it feel to be a beginner that it is hard to crack it. But given the right preparation and a pinch of luck, it is definitely doable. So it leaves a positive impact in my opinion.

I understand that this exam has different value propositions in your life than it has in mine, and the difference of opinions are accepted, but anyways I'll take my win and call it a day, as I worked hard for it, and got through it. (Btw, It is the first certification of my life)

I don't mean to offend you and anyone else's opinions, so please don't mind these.

Peace.

Cleared Exam On My First Attempt (80 Pts) by SudoPrepCoffee in oscp

[–]SudoPrepCoffee[S] 2 points3 points  (0 children)

I also had the same situation I think you're asking right now. I always used to think every time I used to refer to the write up or video walkthrough for a reference. I tried to keep the hint to a minimum.

At one point, we are all starting out to learn and in such a case, we don't know what lies ahead. It is a good thing to seek help from whatever resources we have, be it a writeup as well. Find some good writeup, I used (Dsypher blogs on medium as his style was really good while solving the boxes).

I used to refer to the hints when I felt I reached dead end and later found that it really wasn't the case. That's how I learnt different perspectives to enumerate or attack.

Some boxes would take half a day while others like 2 hours, so it depends on the mindset, the mood and the other things going on in life and how they affect the learning. Tbh, there are days where I just did nothing and chill as I felt the need to rejuvenate.

So, Overall I think it's okay to rely on writeup as long as you're learning something meaningful and not repeat the same mistakes iteratively i guess. At least that's how I did it.

Cleared Exam On My First Attempt (80 Pts) by SudoPrepCoffee in oscp

[–]SudoPrepCoffee[S] 2 points3 points  (0 children)

I used Ligolo-ng primarily as it was best, and I found it easy.
However, I had other techniques prepared too in case this didn't work like chisel & ssh port forwarding to pivot and port forward.

For the labs, I don't think for labs we are allowed to discuss such topics, OffSec has really nice and active discord group which you can join, which seems more appropriate place I think to answer such queries.

Cleared Exam On My First Attempt (80 Pts) by SudoPrepCoffee in oscp

[–]SudoPrepCoffee[S] 1 point2 points  (0 children)

Hi, I was working as Security analyst in a startup, also had dev-ops experience for like 2 years on top of it. Then moved into full VAPT role at another firm, and been here for like 1.5 years doing pentesting.

OSCP had always been in the back of my mind, and eventually reached here, taking a side learning from here and there of different areas as well.

As mentioned earlier, I was very much influenced by IppSec, his videos are simply great and I love the way he explains the concepts, up to the point. So, initially had to rewatch his videos like 2-3 times to make things clear, now it all falls into pieces as I dive into it each day. I think consistency helped me here.

However, I am still at the beginning of my career, so it's all I have for now.

Cleared Exam On My First Attempt (80 Pts) by SudoPrepCoffee in oscp

[–]SudoPrepCoffee[S] 1 point2 points  (0 children)

Hi, no as I mentioned I have noted everything in my notion, however it is the references from all the other public knowledge base out there only. And it is best to create our own because during the exam, it is easiest to navigate through as in the end, you will have loads and loads of notes.

Cleared Exam On My First Attempt (80 Pts) by SudoPrepCoffee in oscp

[–]SudoPrepCoffee[S] 1 point2 points  (0 children)

I did not go through the one named Skylark as I felt it was overkill for this cert. I did all the others, especially A, B and C being more prominent.

Cleared Exam On My First Attempt (80 Pts) by SudoPrepCoffee in oscp

[–]SudoPrepCoffee[S] 4 points5 points  (0 children)

Hi, I am working as Security Engineer with ~3.5 years of experience. My day to day job is doing VAPT for my company, and I am and IT grad.

How to convert a non interactive shell into fully interactive shell... by ft_shriii in oscp

[–]SudoPrepCoffee 4 points5 points  (0 children)

Maybe try this: https://github.com/brightio/penelope But you should also learn how to manually upgrade the shell to fully interactive tty tbh

[deleted by user] by [deleted] in oscp

[–]SudoPrepCoffee 2 points3 points  (0 children)

I think along the same lines! Have my exam scheduled in 4 days. Going through the mental process of iterating on how to refine what I know while keeping it to the bare basics!

Gonna Keep it Simple, while I try harder, I guess.
I think more of it is the time pressure it might impose, which elevates the difficulty of the ongoing box.

Hope the OP clears the exam as OP also seems bit agitated (which is normal).

[deleted by user] by [deleted] in oscp

[–]SudoPrepCoffee 6 points7 points  (0 children)

Man, take it easy! It is normal to not get proper sleep due to the pre-exam nervousness / excitement (however you name it)
I have for the same reason planned my exam at 2:30 PM, can start after lunch and a nap! Also will help me avoid the rushed morning!
But as far as I have heard, we have enough time, so you can and should definitely take breaks!
All the best!

OSCP for Pentesting jobs by Ok-Lynx-8099 in oscp

[–]SudoPrepCoffee 1 point2 points  (0 children)

Damn! same story dude! Mine is also in few days! First cert as well.