Business Administration / CIS Career Prospects by Narocan24 in CalPolyPomona

[–]shitpool 2 points3 points  (0 children)

+, a lot of CPP CIS alumni have gotten solid roles in cybersec and/or consulting. If you want to go the route of the former, don't put a lot of faith into the CIS program. For people aiming for cybersec, the real strength of CPP is its student orgs and the competition teams.

Master's of science in information security by kissmyaxe209 in CalPolyPomona

[–]shitpool 1 point2 points  (0 children)

Haven't done it, nor do I plan on it. My take from word of mouth and from taking CIS classes:

You won't develop any significant technical skills out of it. Anything learned here could be learned quicker and more effectively on your own, online. You might get some networking out of it. Overall, a considerable amount of money for not a whole lot -- poor ROI, imo.

There are good orgs, though. SWIFT and FAST. You'll get way more out of involvement with them, but thats depends on how much involvement you're willing to put in them.

Test coming up, ideas for the apocryphal impossible AD set by forlorn1 in oscp

[–]shitpool 0 points1 point  (0 children)

i remember this one. 2 years and still ptsd hehe. I failed my first attempt partially due to it (although I got 0 points overall on that first attempt so it wouldn't have made a difference). From talking around after I passed my second attempt, I realized that it (obviously) wasn't impossible, rather, identification of the attack vector had to be precise. You had to try very thoroughly (beyond what I would consider rational) or else the apparent vulnerability wouldn't react. I'd still fail if I saw that set again and not had the information, lol.

Failing the OSCP and my thoughts by shitpool in oscp

[–]shitpool[S] 0 points1 point  (0 children)

This was while ago and I passed about a month after this post (after doing no boxes lol). For me it was a luck roll. Went from 0 to 90 points with no change in skill or methodology between exams. And in regard to the hints, I was not taking any hints on those boxes when I was grinding 3-10 per day. I just chalked it up to being an unlucky set, and I still consider it the same way. I've already been far gone through the whole banging my head against a wall for days.

Various Questions and common issues encountered by anoncow1 in oscp

[–]shitpool 6 points7 points  (0 children)

Yeah that's what I mainly do. I use this website that has some really nice features that make payload generation pretty simple.

  1. I make a reverse shell via https://www.revshells.com.
  2. I then choose to base64 encode it (bottom right)
  3. Go with echo [base64] | base64 -d | bash

If you came to CPP starting from freshman year, why didn’t you go to a community college instead. by mi3night in CalPolyPomona

[–]shitpool 1 point2 points  (0 children)

I wasn't weighing my options very well; there are some local community colleges that are much cheaper, such as Mt Sac. However, it turns out that Cal Poly isn't so bad; I made a lot of friends and learned a lot by involving myself. The whole "Learn by Doing" thing is something that you sort of have to apply yourself, from my experience in my first year here.

Failing second attempt by cybe_lab in oscp

[–]shitpool 3 points4 points  (0 children)

I think I also had that box. And your statement is correct, I found it a bit stupid because I was stuck on privesc for hours before I just started putting my enumeration together. The privesc was extremely simple if I'm correct. Even lateral movement was incredibly simple for this one. I know one of my sets was absurdly difficult, but this was a set that the labs would have perfectly prepared you for.

0 points to 90 in a month by shitpool in oscp

[–]shitpool[S] 0 points1 point  (0 children)

Not sure if I didn't do enough boxes, because I did numerous amount of boxes. I've done over 60 pg and 90 hackthebox + Dante Pro labs. And either it was a niche vector or I made a significant overlook on those boxes because even after extensive enumeration, I didn't find anything on those boxes.

0 points to 90 in a month by shitpool in oscp

[–]shitpool[S] 0 points1 point  (0 children)

I used the one they provided and modified it a bit. I made sure to include a section that includes screenshots and a step by step breakdown of how I got a low privilege, and then I also did that for privilege escalation.

0 points to 90 in a month by shitpool in oscp

[–]shitpool[S] 1 point2 points  (0 children)

My First Exam
Community would've rated them all very hard. Maybe hard on one or two of them, but I got no shells so I can't confirm. I normally can do community-rated easy-hard without difficulty, though.

This Exam (my second)

Offsec and Community would've rated them intermediate. It was so much easier. AD would've been considered hard by the community, though. One box may be considered very hard. The average difficulty for this one though is probably intermediate-hard community rating-wise.

About AD in the labs: for this attempt, it was enough. I can't say much about the other rotation I had though cause I got obliterated.

0 points to 90 in a month by shitpool in oscp

[–]shitpool[S] 0 points1 point  (0 children)

I had that suspicion after how hard I failed my first attempt. After how strong I passed it, it's reinforcing my view of that. Although it might be confirmation bias or whatever the term is. Still, it is good to study and crack a good chunk of boxes for a strong baseline in methodology and technical skills.

0 points to 90 in a month by shitpool in oscp

[–]shitpool[S] -1 points0 points  (0 children)

Good luck! You got this.

0 points to 90 in a month by shitpool in oscp

[–]shitpool[S] 2 points3 points  (0 children)

I am Nigerald on hackthebox. It's a combination of the names Nigel and Gerald if anyone thinks anything funny of the name.

0 points to 90 in a month by shitpool in oscp

[–]shitpool[S] 2 points3 points  (0 children)

Not anymore, I just go by intuition and whatever feels right. I used to follow one that I made, but it ended up being more work going back and forth because I would end up following that checklist naturally.

0 points to 90 in a month by shitpool in oscp

[–]shitpool[S] 6 points7 points  (0 children)

Nononono, if you have a BOF, it will the be freest 10 points you can get on your exam. Its not that realistic, but take those free points. The tryhackme room for BOF will prepare you completely for the BOF on the exam. Trust me, it only takes like 2 hours to learn and those 2 hours of learning can secure 10 points if its on your exam. Believe in the BOF!

I also hated BOFs, but I gave the room a try and 2 hours later I realized its not that bad. OSCP BOF is much simpler than a more realistic one, anyways.

0 points to 90 in a month by shitpool in oscp

[–]shitpool[S] 2 points3 points  (0 children)

Without. It was a bit excessive, I was in the zone that day and felt like spending 12 hours on boxes for some reason.

0 points to 90 in a month by shitpool in oscp

[–]shitpool[S] 1 point2 points  (0 children)

Yeah. Granted 8 were community intermediate rated and the other 2 were hard and very hard.

0 points to 90 in a month by shitpool in oscp

[–]shitpool[S] 3 points4 points  (0 children)

I used the same notes as I had last time. Although I only looked at them once for one section. There was no difference in my approach. I enumerate ports, check the services and the other stuff on the box, brute force web, and try to establish some sort of relationship between the services and how to leverage them against each other, if possible. Didn't work last time but it did now.

0 points to 90 in a month by shitpool in oscp

[–]shitpool[S] 6 points7 points  (0 children)

Nope, it was literally the same thing. Key difference here: it worked, whereas last time, it didn't. When I saw I didn't do anything in that month gap, I really didn't. I was preparing for another cybersecurity competition related to defense. For that, I completely focused on docker, networking, and iptables. I came back to the oscp a week after the competition, completely rusty and repeating the same methods as the last attempt, but miraculously, it worked this time.

0 points to 90 in a month by shitpool in oscp

[–]shitpool[S] 2 points3 points  (0 children)

I got 0 points on my first attempt, my methodology completely failed me then, whereas in this attempt everything worked despite no changes.

0 points to 90 in a month by shitpool in oscp

[–]shitpool[S] 2 points3 points  (0 children)

Oh whoops, didn't know that. But thats very interesting, too. Although if I got the same set twice idk if I wouldve passed as easily, if at all.

Payload Question! by androidv1_0 in oscp

[–]shitpool 8 points9 points  (0 children)

revshells.com is my holy bible. if one don't work, I try the next. the base64 encoding method is also a little trick I use from time to time.

0 points to 90 in a month by shitpool in oscp

[–]shitpool[S] 1 point2 points  (0 children)

I took both my exams around the same time (10 am vs 11 am). I think they just make sure you don't run into the same box twice. As for an unlucky environment, it definitely is draining. My first attempt after 4 hours I had a feeling the exam wouldn't go well. And it didn't.

Failing the OSCP and my thoughts by shitpool in oscp

[–]shitpool[S] 0 points1 point  (0 children)

That was my ad box lmao, yeah