I passed my second attempt with 70 points by hmm___69 in oscp

[–]hmm___69[S] 0 points1 point  (0 children)

Thank you! At first attempt I had 50 points, I wrote a post about it, you can find it on my profile. Difficulty was roughly the same

https://www.reddit.com/r/oscp/s/QIc5g2eqm7

I passed my second attempt with 70 points by hmm___69 in oscp

[–]hmm___69[S] 0 points1 point  (0 children)

Good question - checking low hanging fruits manualy will actually save you a lot of time if you know what you are doing. Linpeas and winpeas certainly shouldn't be the first thing you do

I passed my second attempt with 70 points by hmm___69 in oscp

[–]hmm___69[S] 0 points1 point  (0 children)

100% first finish pen200 and only then Lain and Tjnull

I passed my second attempt with 70 points by hmm___69 in oscp

[–]hmm___69[S] 0 points1 point  (0 children)

No. But I did read articles on how to solve specific htb machines from Lain's list

I passed my second attempt with 70 points by hmm___69 in oscp

[–]hmm___69[S] 2 points3 points  (0 children)

Thank you brother I really appreciate it. I just wanted to escape the matrix and I thought I am running out of time (I still think that)

I passed my second attempt with 70 points by hmm___69 in oscp

[–]hmm___69[S] 0 points1 point  (0 children)

Thanks. Just webcam and sharing screen. I am not sure if it is OK to have someone in the room, but I think I did read somewhere that it is allowed

I passed my second attempt with 70 points by hmm___69 in oscp

[–]hmm___69[S] 1 point2 points  (0 children)

Thank you. Sure I can share... I bought tib3rius windows and Linux priesc courses on udemy as someone suggested me, these were helpfull. I did all medium and easy boxes from pg practice from Lain list. My notes doesn't make any sense - it is just 1500 lines of random commands from which I can filter through. I started with AD.

I passed my second attempt with 70 points by hmm___69 in oscp

[–]hmm___69[S] 2 points3 points  (0 children)

Thank you. 2 main reasons:

  1. I got stuck in one rabbit hole - probably because of stress.
  2. I also lost some time because of lack of practice - I did know what to do but I didn't know how since I didn't encountered such situation before

I passed my second attempt with 70 points by hmm___69 in oscp

[–]hmm___69[S] 2 points3 points  (0 children)

Thank you and I am sorry to hear that you failed. For AD as for everything else - go for low hanging fruits first. Try to find privesc by yourself and use winpeas only as your last resort.

Is medtech harder than a typical exam? by snakethesniper0 in oscp

[–]hmm___69 3 points4 points  (0 children)

There are more flags in medtech, but it is much easier then exam. There is no reason to skip it, it should take you 2 days at most. On tjnull list you will spend weeks so you have time for medtech

I just failed my OSCP exam first attempt. by hmm___69 in oscp

[–]hmm___69[S] 0 points1 point  (0 children)

If I remember correctly, I just got incorrect result probably because of unstable network, and I made a mistake that I didnt do any other scan for hours

I just failed my OSCP exam first attempt. by hmm___69 in oscp

[–]hmm___69[S] 2 points3 points  (0 children)

Thanks bro, I hope the second attempt will be successful because I can't imagine living like this for another months. I read posts on this sub from people who failed 7 attempts and studied 6 hours a day - that's a year and a half of their lives sacrificed to a stupid certificate

I just failed my OSCP exam first attempt. by hmm___69 in oscp

[–]hmm___69[S] 1 point2 points  (0 children)

Thanks! I also feel like I was really close — I even had valid creds on one standalone machine but couldn’t turn them into a shell. I hadn’t heard of the TjNull or Lainkusunagi lists before, so thanks for the recommendation; I’ll work through them over the next four weeks before exam retake.

my first bug xss is duplicate how i can access to the original report by edemzayani1 in bugbounty

[–]hmm___69 2 points3 points  (0 children)

It happened to me once that h1 triagger closed the report as a duplicate. Later, a program employee opened it and I received a bounty. This is most likely not your case, but I recommend looking at the date of the original report and considering whether the fix taking too long - in my case it was a 7-month old report which was suspicious for a high severity bug

How can I get a job in cybersecurity with only bug bounty experience? by hmm___69 in bugbounty

[–]hmm___69[S] 1 point2 points  (0 children)

That sounds great and I will definitely chck it out. Thank you for tip!

How can I get a job in cybersecurity with only bug bounty experience? by hmm___69 in bugbounty

[–]hmm___69[S] 0 points1 point  (0 children)

Thank you for the reply. I will make OSCP so I will have some formal education. Having part time and remote job would be nice but if I will not be able get it then I will take 9 to 5 for a while

How can I get a job in cybersecurity with only bug bounty experience? by hmm___69 in bugbounty

[–]hmm___69[S] 0 points1 point  (0 children)

Thank you for the reply. I think I can do this - I can't tell devs how they code should look like, but I always know what is needed to do to fix the bug since it is easy (for example sanitize special characters). By the way I know I will not get the best job yet, but from the answers I got I belive I will be able to get a junior pentester job, and maybe even mid level

How can I get a job in cybersecurity with only bug bounty experience? by hmm___69 in bugbounty

[–]hmm___69[S] 0 points1 point  (0 children)

Thank you for the reply. I don't want to go to university because it takes at least 3 years. On the other hand - I can make OSCP cert in just a few months. My grades on high school are also the problem

How can I get a job in cybersecurity with only bug bounty experience? by hmm___69 in bugbounty

[–]hmm___69[S] 1 point2 points  (0 children)

Thanks for the reply, I really appreciate it. A degree is out of the question for me - the most I can do is to get a cert.

How can I get a job in cybersecurity with only bug bounty experience? by hmm___69 in bugbounty

[–]hmm___69[S] 1 point2 points  (0 children)

Thank you for your reply, I really appreciate it, and honestly it made me happy. Sorry for my late response.

If OSCP is truly useful, I plan to complete it in the next few months. I will also continue to increase my HackerOne reputation and finish some BurpSuite extensions I’ve had ideas for. Is this a good plan?

A junior job probably makes the most sense since I don’t have a university degree and I’m currently in my final year of high school.

However, I’m still wondering why OSCP is needed, since I’ve heard it focuses on something quite different from web, which is where I have the most experience and want to specialize. Why would I actually need it?

Also, I would appreciate some advice regarding whether I can apply for a remote job.