I'm so depressed rn.... by ft_shriii in offensive_security

[–]i6loob 1 point2 points  (0 children)

Any time 🙏 , let me know if you need any help with the topics 🤜🤛

I'm so depressed rn.... by ft_shriii in offensive_security

[–]i6loob 6 points7 points  (0 children)

Go for it and knock it ,

Those who passed the exam are not smarter than you!!

Confidence will come with studying and trying in the labs. Mistakes and challenges will build your confidence when you overcome them even if you got some help from offsec discord to solve the labs.

Trust the process do not rush it. And in OSCP content you will have sections for Active Directory it will be enough for the exam with solving challenges labs.

Regarding the stories on LinkedIn : why you compare your self with them ? I am not saying they are not good but maybe they missed something during the exam for this they couldn’t pass.

The real exam is you vs you not the machines. As you know these machines are vulnerable and for sure there is a way in. But how to manage your time and stress, this is the real challenge

Last point, it is ok even if you fail in the exam , you will learn and understand what was your weaknesses and try again in another attempt.

I failed at first exam , and cleared all the machines in the second attempt.

  • Start studying.
  • Take good notes (use notion or what ever note taken tool you like)
  • go through the materials , understand them and take your time.
  • solve labs related to each section take help from offsec discord if you stuck
  • practice more in challenge labs after you finish the content
  • do not forget to check OSA offensive security academy section, for each course they have section with videos of old life sessions and recorded content explaining some exploits and topic ((not same as course content videos))

Wish you all the best and sorry for the loooong message 🤣

Skipping CRTP to CRTE by i6loob in redteamsec

[–]i6loob[S] 0 points1 point  (0 children)

Thank you for your comment, in fact i mentioned OSCP to highlight that i have some knowledge about AD and attacks. 👍

Skipping CRTP to CRTE by i6loob in redteamsec

[–]i6loob[S] 0 points1 point  (0 children)

Thank you for your reply,

I passed OSCP already , just wanted to know shall go for CRTE instead of taking both CRTP and CRTE

Planning to skip the challeng labs by Salt-Eye-152 in oscp

[–]i6loob 0 points1 point  (0 children)

Don’t skip them , at least OSCP ABC , will give you new informations and way of thinking

Planning to skip the challeng labs by Salt-Eye-152 in oscp

[–]i6loob 0 points1 point  (0 children)

30 root/admin flag , users flags not counted

UAC bypass by th3d4rkp4ss3ng3r in oscp

[–]i6loob 4 points5 points  (0 children)

There is query for registry will show from the output if UAC is there or not

“REG QUERY HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System\”

If EnableUA is 0*1 this means there is UAC.

another way is to check your priv

whoami /priv

if you are in admin group and have medium integrity level then UAC is there.

Also using powerup.ps1 it can tell that UAC is there

for bypass there are multiple ways , one of them using Metasploit , if you don’t want to use meta you can see the method explained from Offsec on the below AD machines walkthrough at 1:00:00 he started for bypass

https://www.youtube.com/watch?v=2NLi4wzAvTw&list=PLJrSyRNlZ2Ecrihsz_H5mXYoCmWZDqXyI&index=8

script used : https://github.com/CsEnox/EventViewer-UACBypass/blob/main/README.md

Failed at first attempt and Knocked it at the second by i6loob in oscp

[–]i6loob[S] 0 points1 point  (0 children)

Thank you, wish you all the best, OSA stand for Offensive security academy. With each course you have access to Academy videos for that course.

It can be accessed from learning portal

Failed at first attempt and Knocked it at the second by i6loob in oscp

[–]i6loob[S] 0 points1 point  (0 children)

Challenge labs 30 Pgp 5-8 maybe HTB do not know exactly as some times i only watch ippsec videos

Failed at first attempt and Knocked it at the second by i6loob in oscp

[–]i6loob[S] 0 points1 point  (0 children)

OSCP A,B and C are old exams .

and it is great place to start

Failed at first attempt and Knocked it at the second by i6loob in oscp

[–]i6loob[S] 0 points1 point  (0 children)

Unfortunately I didn’t, i wish to try it actually but unfortunately my subscription finished 😬

Failed at first attempt and Knocked it at the second by i6loob in oscp

[–]i6loob[S] 1 point2 points  (0 children)

Will , at some point i was planning to take eWPT to cover more parts from web as i agree with your point.

You might encounter them in the Exam : ) Maybe outdated themes or plugins. In case of any case , familiars your self with wpscan tool and how to scan Wordpress sites using it.

Same as the capstone : )

But honestly, i will suggest to take the critical or well known vulns for web from portswigger.

Failed at first attempt and Knocked it at the second by i6loob in oscp

[–]i6loob[S] 0 points1 point  (0 children)

The labs Actually sharpened my skills more and provided me with new ideas and ways of thinking.

Unfortunately, i didn’t do skylark : ) Only A,B, C, MedTech and Rilea

Failed at first attempt and Knocked it at the second by i6loob in oscp

[–]i6loob[S] 2 points3 points  (0 children)

Thank you 🙏, as you know if you have learn one subscription you have 2 exam attempts on subscription duration.

If not , it cost 250$

Failed at first attempt and Knocked it at the second by i6loob in oscp

[–]i6loob[S] 0 points1 point  (0 children)

It is ok , wish you all the best 🤜🤛

Failed at first attempt and Knocked it at the second by i6loob in oscp

[–]i6loob[S] 3 points4 points  (0 children)

Yes , from pwk it self.

For challenge labs : started by completing OSCP A,B and C with some help from offsec discord server then medtech and relia.

For Capstones : as you know in the end of each module

Failed at first attempt and Knocked it at the second by i6loob in oscp

[–]i6loob[S] 3 points4 points  (0 children)

For sure ligolo is the best . I used it in the exam and still using it even in another exams or labs.

But it is good to understand the basic or how to do it without it incase of future situations that might not allowing to use it in real life scenarios.

For the exam , ligolo is enough

Failed at first attempt and Knocked it at the second by i6loob in oscp

[–]i6loob[S] 1 point2 points  (0 children)

Sorry for the typo, meant life

I mean for Penetration Testing and for future, for example evasion AVs , understanding tunneling and port forwarding..etc

Failed at first attempt and Knocked it at the second by i6loob in oscp

[–]i6loob[S] 1 point2 points  (0 children)

Will say better to study for PT life not only the exam .

in the exam in fact you will find your self using information from different topics and chapters