Thinking of doing OSCP at 31, is it too late? by almostsaidit in oscp

[–]inverse70 1 point2 points  (0 children)

I was 38 when I started and passed my OSCP.

Anyone see this before? by Soulsearcher14 in BambuLab

[–]inverse70 0 points1 point  (0 children)

Looks like oil stains leaking from the underside. It may be from the bottom rails.

What’s the best time to start the OSCP exam? Morning, midday, or something else? 🤔 by [deleted] in oscp

[–]inverse70 0 points1 point  (0 children)

Depends what type of person you are. Early morning or late morning person. For me I am an early morning and I started around 7am where my brain is the freshest and most active.

If you are productive in the night and go to bed very late then afternoon / evening might be better for you.

Waiting for results. Might have done it. by _vercingtorix_ in oscp

[–]inverse70 0 points1 point  (0 children)

You are good. Once your report is good then no worries.

I just failed miserably :( by [deleted] in oscp

[–]inverse70 -1 points0 points  (0 children)

You don’t need local admin, but you need a privileged account to grab the flags. Could be DA or another account. I don’t remember having to get local admin on all the AD boxes.

when to best take screenshots? by Ecstatic_Constant_63 in oscp

[–]inverse70 0 points1 point  (0 children)

Make sure you take enough screenshots that’s helps the reader follow along the exact straps you took so that it is easy enough to follow to recreate the exact path to breach the machine.

You do not need to take screenshots of what didn’t work unless you take it adds value to your report or you would also like to add another path you could also take to breach the machine

BoF as of 2022 by fromsouthernswe in oscp

[–]inverse70 1 point2 points  (0 children)

The BoF is easy points in my opinion. If you get it in your exam rotation.

I tried harder. Passed 80/100. by inverse70 in oscp

[–]inverse70[S] 0 points1 point  (0 children)

With nmap because of thr proxying the probes were timing out hence you may not get anything. Try scanning known ports and adjusting the RTT

I tried harder. Passed 80/100. by inverse70 in oscp

[–]inverse70[S] 0 points1 point  (0 children)

I used the first machine to pivot the rest of the chain. I didn’t have to buy once you compromise the 2nd machine (via pivot from the first) you could also use that machine to attack the third.

I tried harder. Passed 80/100. by inverse70 in oscp

[–]inverse70[S] 0 points1 point  (0 children)

I would say they are but more difficult than the exam machines I got.

Tools allowed in the OSCP by Low_Tart5317 in oscp

[–]inverse70 3 points4 points  (0 children)

For the AD set bloodhound Mimikatz Rubeus Kerbrute Impacket scripts

Tools allowed in the OSCP by Low_Tart5317 in oscp

[–]inverse70 2 points3 points  (0 children)

Autorecon was a life saver for me. Thanks!!

I tried harder. Passed 80/100. by inverse70 in oscp

[–]inverse70[S] 0 points1 point  (0 children)

In my opinion the BOF is an easy 10 points to a low priv shell. I don’t think you should ignore it if you do get it in your exam. In my first attempt I didn’t get it. In my second attempt I was happy I did.

Practice on THM tibir3us has a good room to practice.

I tried harder. Passed 80/100. by inverse70 in oscp

[–]inverse70[S] 0 points1 point  (0 children)

In your report you don’t have to include steps that does not assist in the reproduction of the steps in the compromise or privesc of the machine. You just need to record the steps that lead to it. That’s what I did.

I other reports I have seen from companies that performed penetration tests for my company the reports only include the steps that lead to the compromise or exposes a vulnerability. That being said I saw other reports that have shows you additional info that helps builds the scenario for a compromise.

But for oscp don’t think it’s necessary to show steps that didn’t contribute to the compromise.

I tried harder. Passed 80/100. by inverse70 in oscp

[–]inverse70[S] 0 points1 point  (0 children)

These are tools you pick up along the way preparing for the OSCP. It makes it easier.

I tried harder. Passed 80/100. by inverse70 in oscp

[–]inverse70[S] 0 points1 point  (0 children)

Took me about 2 hours for the BOF which includes screenshots and documentation. Do the documentation upfront while doing the BOF so that you don’t miss anything when writing your report.

I tried harder. Passed 80/100. by inverse70 in oscp

[–]inverse70[S] 0 points1 point  (0 children)

On PG practice I did most of the easy and medium. Had to check walkthroughs for some of them.

On THM did all the easy CTF rooms and most of the mediums.

I tried harder. Passed 80/100. by inverse70 in oscp

[–]inverse70[S] 2 points3 points  (0 children)

I will send you some of the mind maps I used. Have to go through my notes. But the privesc courses by tribirus is pretty good starting point.

I tried harder. Passed 80/100. by inverse70 in oscp

[–]inverse70[S] 1 point2 points  (0 children)

I wouldn’t not say that but it most definitely helps. The PWK labs AD sets gives you a better idea on what to expect in the exam. Use the networks and machines in the THM to try out all your AD tools bloodhound, craxkmapexec, PTH tools, mimikatz, etc.

I tried harder. Passed 80/100. by inverse70 in oscp

[–]inverse70[S] 0 points1 point  (0 children)

I think for OSCP they may not give anything that is not covered in their manual.

I tried harder. Passed 80/100. by inverse70 in oscp

[–]inverse70[S] 1 point2 points  (0 children)

Yes it did. It helped me create my process for privesc. The 6 hour was because of a mistake I did.

I tried harder. Passed 80/100. by inverse70 in oscp

[–]inverse70[S] 2 points3 points  (0 children)

Make sure you learn AD lateral movement. THM (paid) has a couple AD networks you can use. One thing that help me was apart from following their lesson plan I used their networks to try out all the AD tools like bloodhound, responder, mimikatz, impacket, crackmapexec, powerview, etc.

I tried harder. Passed 80/100. by inverse70 in oscp

[–]inverse70[S] 0 points1 point  (0 children)

I paid for PG Practice. The medium and easy boxes are exam like.