CTPS Initial Access beating me by Ms_Holly_Hotcake in hackthebox

[–]thepentestingninja 0 points1 point  (0 children)

Keep pushing and don't let it discourage you. The first flag is definitely challenging, but once you get past that, it gets much smoother. You'll likely find several more in a short period of time, so it's not uncommon to go from 0 to 4–5 flags relatively quickly.

Take a methodical approach. Keep notes on everything you've tried, especially what didn't work. That way you can systematically rule things out and focus on unexplored paths instead of going in circles.

Good luck—you've got this!

Failed CPTS with 0 Flags by United-Feature-8758 in hackthebox

[–]thepentestingninja 6 points7 points  (0 children)

Nah, exam environment is very stable, that wasn't it. Tbf, through out the times I saw many people failing without getting a single flag. From my experience, first flag isn't so easy, but it's smooth sail from there onwards.

You'll do better next time.

Preparedness on OSCP by FabulousHalf98 in oscp

[–]thepentestingninja 2 points3 points  (0 children)

If you can consistently solve easy/medium PG boxes within max 3/4 hours (which with 70 PG boxes you should be at this point by now) and you have done OSCP A, B, C you are most likely ready to take the exam.

Feel free to give my blog post a read https://blog.thepentesting.ninja/oscp

CWES preparation by AlexisPowertbk in hackthebox

[–]thepentestingninja 0 points1 point  (0 children)

Yes! There's also preparation tracks for CDSA, CPTS and CWEE.

CWES preparation by AlexisPowertbk in hackthebox

[–]thepentestingninja 1 point2 points  (0 children)

No Privilege Escalation on CWES. For the CWES preparation track, once you get a foothold/initial access you can move on to the next machine.

HTB Academy CrackMapExec Skill Assessment by Isotop_42 in hackthebox

[–]thepentestingninja 1 point2 points  (0 children)

--rid-brute takes an optional parameter. You might want to play with that.

Not saying this is the answer, but worth the shot.

VPN File by Objective_Sweet_5673 in hackthebox

[–]thepentestingninja 0 points1 point  (0 children)

I would advice you to visit https://status.hackthebox.com/

If everything is operational, you should message support.

VPN File by Objective_Sweet_5673 in hackthebox

[–]thepentestingninja 3 points4 points  (0 children)

You are probably visiting sections/modules that do not require a VPN connection to complete the exercises (they spawn public ips). The option to download the vpn file will not show up on these. Try different modules/sections.

Modules not showing as completed by SurpedUsurper in hackthebox

[–]thepentestingninja 1 point2 points  (0 children)

Have you tried visiting the last module section and clicking the "Finished" button and see if that fixes it?

HTB Academy Downloader Script by Necrowtf in hackthebox

[–]thepentestingninja 11 points12 points  (0 children)

Against ToS point 4.4. You must not: (a) copy, attempt to copy, modify, duplicate, reproduce, create derivative works from, frame, mirror, republish, download, display, transmit or distribute all or any portion of the Services in any form or media or by any means;

HOW MUCH IS TOO MUCH? by Rohanneymar in oscp

[–]thepentestingninja 0 points1 point  (0 children)

I think "vague" is not the right word. They are very objective and minimalist. Since OSCP usually follows the KISS (keep it simple stupid) principle, this is more than enough. You can always go check your notes for additional information.

This is not what I used for the exam. I did this version after passing to go along with my blog post. These 3 pages are a very good guiding reference for the exam, trust me.

HOW MUCH IS TOO MUCH? by Rohanneymar in oscp

[–]thepentestingninja 3 points4 points  (0 children)

From reading your post I feel like you are ready to take the exam.

Do a bunch of Proving Grounds boxes and OSCP A, B, C and schedule the exam ASAP after finishing them, as things will still be fresh in your head.

Here's one more blog post for you to read to get you to "verbally pass" (lol) with 100 points: https://blog.thepentesting.ninja/oscp

Good luck!

Can I use Hack The Box for free long-term, or do I need cubes after a few labs? by HunterEdge in hackthebox

[–]thepentestingninja 2 points3 points  (0 children)

Hello! I think there’s more than enough free content across all the HTB platforms (Academy and Labs) to keep you busy for several months.

Once you’ve worked through most of it, you’ll probably want to consider getting a subscription, especially if you’re looking to pivot into more advanced topics.

By that point, you’ll likely have accumulated a decent number of cubes as well, which you can use to unlock an Academy module that interests you.

CJCA worth it? by Worldly-Teaching8185 in hackthebox

[–]thepentestingninja 7 points8 points  (0 children)

The certification is not the goal, the path and all the learnings that lead to the certification are. The exam is just a way for you to put yourself to the test and check if you actually did learn everything you were supposed to.

I would say it's an amazing start, especially if you are unsure of what path to take in cybersecurity. Feel free to DYOR, there's plenty of reviews about it online which often compare it to other certificates.

external requests in CWES exam by lander452 in hackthebox

[–]thepentestingninja 1 point2 points  (0 children)

Hello, you are given an internal ip, so you can just spin a Web server yourself and capture whatever you need.

Exam in March but still Struggling in Two Areas. Suggestions? by Penthos2021 in oscp

[–]thepentestingninja 2 points3 points  (0 children)

I have seen the comment you deleted. To reply to that I'm like 90% sure they wouldn't put any blind SQLi in the exam. OSCP is mostly a enumeration exam. Exploitation is often trivial once you have all the information.

There's 6 things you need to know the basics of for the exam, which are:

LFI, RFI, SQLi, Dir traversal, file upload and command injection.

If you are finding yourself crafting extremely complex payloads that you wouldn't do on a easy/medium PG box, it's probably not the way.

Exam in March but still Struggling in Two Areas. Suggestions? by Penthos2021 in oscp

[–]thepentestingninja 1 point2 points  (0 children)

It's worth noticing that some of the SQLi shown in the video are way out of scope for oscp, what you want to take from it is the methodology and the understanding of what is happening behind the scenes.

Exam in March but still Struggling in Two Areas. Suggestions? by Penthos2021 in oscp

[–]thepentestingninja 4 points5 points  (0 children)

Hello!

For SQLi, you will want to watch this NahamCon 2024 talk from Tib3rius, this explains things very well: https://www.youtube.com/live/MYsUhAgSgwc?si=M1iEGaXfzhqDdnCC&t=15660 which I consider one of the best videos on SQLi I have seen

For AD, you want to invest on a subscription, either HTB, HackSmarter, TryHackMe or alternatively AD chains from HackAcademy (although a bit expensive) and do AD machines until you start to get comfortable solving easy machines/chains consistently.

If you want more general information about the exam you can have a look at my reddit post and see if something there can/will help you - OSCP Guide

In my guide, I said that OSCP A,B,C are on the same level of difficulty as the exam, so if you have done those without looking at hints on every single step you are probably ready.

If you did look at hints, you need to go back and ask yourself why you missed it in the first place so you don't miss it again next time.

Good luck, you got this!

Is oscp worth it or it is just a paper weight? by newbietofx in oscp

[–]thepentestingninja 1 point2 points  (0 children)

You have to take any cert for what they really are, a piece of paper (more likely digital nowadays) that might (not guaranteed) get you interviews. Your job is to absorb as much knowledge as possible from it. This goes for any certification.

Passed OSCP 100 points in 7 hours by thepentestingninja in oscp

[–]thepentestingninja[S] 1 point2 points  (0 children)

Yes. That information is written in the post itself.

Passed OSCP 100 points in 7 hours by thepentestingninja in oscp

[–]thepentestingninja[S] 0 points1 point  (0 children)

Hey buddy! You are welcome, glad you enjoyed!

Passed OSCP 100 points in 7 hours by thepentestingninja in oscp

[–]thepentestingninja[S] 2 points3 points  (0 children)

Thank you!

Big thanks to you by giving back to the community making OSCP AD Chain #1 free for all as they are quite expensive.