My OSCP Journey

#Certifications#writings

A short glimpse into my journey of trying harder. How I went from zero to getting OSCP certified.

Why and how it all started?

My journey to cyber security started during the Covid restriction. Around this time, I came across a lot of bug bounty posts, videos, and news on security breaches. With nothing in particular to do during the boring days of lockdown, I started researching on how to get started in this field.

I joined various community and talked with people who were already thriving in this field. One of them being Digital Overdose on discord. One of the mods from that channel suggested me to try for OSCP, and I figured why not without actually knowing what was in the store for me.

After some research (and pestering my parents to fork out the fund) began my preparation.

The preparation

I only had some basic knowledge of networking, tools, vulnerabilities, and Linux. I used THM extensively (profile at the end of this section) to learn the very basic stuff. After getting comfortable with Linux and some security concepts, I began looking into some of the vulnhub boxes. Besides THM, I used the following resources:

Linux

Web

Study plan!

I created a study plan with one of my friend and decided to tackle certain number of boxes per week. List of Vulnhub boxes we did.

  • Kioptrix series (1,2,3,4 & 2014)
  • Pwnlab
  • Development
  • Mercyv2
  • Symfonos series (1–4)
  • Misdirection
  • Sar

Then some retired (easy) machines on HTB as well as Proving ground from @Tj_Null’s list.

PWK Lab

After some preparation, I finally decided to sign up for the official course. I took one month of lab which started on Sep 12. It came with 800-page PDF and 12+ hour of video. The video content was too dry for me to go through, so I skipped the videos and only referred to PDF when needed.

I didn’t have much trouble with lab machines, as I had practiced a lot (HTB and Vulnhub) and developed a decent methodology that worked for me. I cracked about 50–55 machines in total. Almost all machine from public subnet and 5 from IT. Didn’t pivot into other networks as my experience with lab was horrible. It had a ton of technical problems and unstable most of the time.

Post lab/final prep

After my lab time ended, I scheduled my Exam for Dec 2. I spent my days before the exam going through HTB machines (did about 20+ machines from it, retired as well as active ones, rated Easy & Medium) and Offsec Proving Grounds. It is one of the best resources out there to prepare for OSCP IMO. Did about 55 machines (mostly rated intermediate) from the proving grounds before my D-day.

Proving Grounds machine, that I attempted or completed:

Windows Linux Try Harder
Nickel ClamAv Bratarina
Slort Wombo Internal
Authby Payday Clyde
Jacko Fail Vector
Meathead Nibbles Shify
UT99 Banzai XposedAPI
Medjed Hunit Helpdesk
Algernon Dibble Twiggy
Billyboss Zino Hawat
Butch Hetemit Cookiecutter
Kevin Peppo Sirol
Metallus Postfish Panic
Shenzi Malbec Heist
Hutch Sybaris Chatty
Fish Walla Muddy
Nukem
Roquefort
Pelican
UC404
Nappa
Snookums
Zenphoto
Sorcerer
Quackerjack
Webcal
Apex
Surf
Interface

The D-Day

I scheduled my exam to start on 6 am. Connected to proctoring software and went through some procedures. Started my scan on around 7. My game plan: BOF → 25 → 20 → 20 → 10.

I was done with BOF within first 45 minutes (Tryhackme BOF FTW). Then I attempted 25 pointer. I got side-tracked because of rabbit hole for some time. But was able to get root on it by 12pm, now I had secured 50 points in first 6 hours.

At 12 hours mark I had 80 points (one 20 pointer remaining, I felt like I knew the attack vector but couldn’t exploit it). Instead of tackling the last machine, I started preparing my report as I didn’t want to miss crucial screenshot resulting in incomplete report and failing because of it. For report, I used whoisflynn’s report template. By the time I finished writing report I had about 2 hours left before my conection to exam environment expired.

I only took small break and was awake for straight 22 hours at this point. But I still went for the remaining 20 pointers and was able to get root at last minute of the exam (it was the easiest machine of the bunch, turns out I was just complicating it).

Then I updated my report, proof read it 4, 5 times before submitting the report. Got my result after 3 days on 5th dec and was officially OSCP certified. I was awake for almost 30 hours by the time I submitted my report and went to sleep. I do not recommend doing this at all. Exhaustion will result in tunnel vision, and you might miss obvious exploits or vulnerability. Which I did experience on one of the 20 pointers. So definitely take a lot of breaks and don’t be afraid to start over.

Additional Resources and Tips

Big Changes to OSCP Exam

OSCP Exam Change - Offensive Security (offensive-security.com)

The new exam structure will become available for students beginning on January 11, 2022. **All scheduled exams for January 11th onward are subject to the new structure.**

OSCP exam format is set to change which will include 40 points AD and 3 20 points machines. BOF is now low privilege vector worth 10 point instead.

Resource for AD.

Machines to practice AD

HTB PGP
Forest Heist
Resolute Hutch
Cascade Vault
Traversex
Monterverd
Sauna
Sizzle
Multimaster

What’s next???

Honestly, I’m not really sure what’s next for me. But during all this I realized one thing, I’d rather spend my time just having fun with CTFs and Labs, poking around at stuff than having an exam clock ticking at the back of my head. So I will probably just continue doing practical labs to further improve my skills while posting writeups on those challenges once in a while.

If you’re in the process of “trying harder” as well, feel free to reach out to me. Always happy to talk, share resources, or just complain about rabbit holes together.