OSCP - If I were to do it all over again...

Поделиться
HTML-код
  • Опубликовано: 23 янв 2025

Комментарии • 75

  • @marcschweiz
    @marcschweiz 4 года назад +14

    For someone wanting to start my OSCP in about two weeks this info was GOLD. I may want to go with manual pivoting to really learn it and then move over to sshuttle like you did. Love your content!

    • @vikarux
      @vikarux 3 года назад

      Any updates on this?

    • @BigManT
      @BigManT 3 года назад

      How did you do bro

    • @carlosdevil666
      @carlosdevil666 2 года назад

      Did you sit your exam already or are you still studying?

  • @ivanzhao4068
    @ivanzhao4068 2 года назад +1

    Thanks for sharing the sshuttle, very nice tool. Also thanks a lot for sharing the paths.

  • @HYPR.trophy
    @HYPR.trophy 2 года назад

    good info! I was distracted waiting for the ghost to peek out from the open door

  • @nate8824
    @nate8824 3 года назад +4

    I should have watched this again, getting *NO* sleep during the full 24 hour exam was really an expensive mistake that I have done, just a privesc away from passing.
    Going back to my privesc output the next day made me realize that the solution was really easy. If you're someone taking the exam in the future please have some time to rest/sleep.

    • @JSONSEC
      @JSONSEC  3 года назад

      Sounds exactly like my first attempt. Rest up and hit it again in a month! You got this

    • @nate8824
      @nate8824 3 года назад +2

      @@JSONSEC
      just a shameless plug,
      i passed the OSCP a month ago, did take breaks and other advices. Thanks again !

    • @ohokie4558
      @ohokie4558 2 года назад

      @@nate8824 hey woah congrats!! can u guide me with the resources to follow /roadmap ?
      I'm gonna start my prep in a month or so 😅

  • @ITSecurityLabs
    @ITSecurityLabs 4 года назад +1

    By ssh shadow you mean ssh tunneling ?

  • @CFH298
    @CFH298 3 года назад +2

    It seems to be more about building up your methodology and knowing when to use certain tools and being exposed to all situations when using the tools.

    • @JSONSEC
      @JSONSEC  3 года назад +1

      Great summary

    • @CFH298
      @CFH298 3 года назад +1

      @@JSONSEC just got my CISSP and I’ve been on the GRC side of Cyber for the past 2 years but looking at getting into the red size of the house. I’ll be following your OSCP recommendations as I start from square one. I’ll be leaving out eJPT, PTS, etc…thanks for the great videos!

    • @JSONSEC
      @JSONSEC  3 года назад +1

      Yeah eJPT isn't worth the effort. Could just jump straight to PTP

  • @diariomontadoraustralia
    @diariomontadoraustralia 4 года назад +1

    Thank you again, Json.
    Would mind adding the proposed path on the description? Thank you!

  • @pythoncure6755
    @pythoncure6755 4 года назад +3

    That's a lot useful info love to see your videos by the way I have a question:-
    I want to perform a mitm attack between a TCP telnet server and client and steal the unencrypted data...
    So I should just do ARP spoofing and run a sniffer to get the packets
    If it's all we need, can you do a practical please.....

  • @jjjjjkkkkk
    @jjjjjkkkkk 4 года назад +2

    Please do an exam prep guide!!

    • @JSONSEC
      @JSONSEC  4 года назад +6

      Already in the works!

  • @Mike01010011
    @Mike01010011 4 года назад +3

    Thanks for the tips, much appreciated! Question: if your company did not require you to do the PTP, would you have recommeded the PTP as an OSCP prerequisite? Looking forward to the hacking history videos!

    • @JSONSEC
      @JSONSEC  4 года назад +9

      This is a tough question.... I don't exactly see PTP as a pre-req as it covers more or less, all the same material but BETTER than the OSCP. What it lacks is the open labs to practice and the tough exam.
      I kind of see PTP as your University Degree where you learn and the OSCP like your Job Placement, where you get experience.
      PTP is a great thing to do prior as it will teach you well and teach all the underlying tech not just security concepts, but it'll make your journey longer and more expensive. So I guess it comes down to what your priorities are...

  • @ciromleite
    @ciromleite Год назад

    Hello, how are you guys? So, I want to master cyber security but I have 0 experience, the only experience I have with pc is playing games, 6 weak months of mysql workbench(that made me hunger for cyber security and help others stop getting scammed, since my folks lost almost all of their 20 years of savings getting hacked last year, I had to left college and no one was able to help) and a little bit of technical assistance(Im opening my own shop soon). Which path you recommend me going?

    • @JSONSEC
      @JSONSEC  Год назад

      What my video on the Subject, How to build a cyber security Career

  • @Ganeshreddyyy
    @Ganeshreddyyy 2 года назад

    Tell me and what os we have learn when started hacking

    • @JSONSEC
      @JSONSEC  2 года назад

      You'll need to understand how to use Linux to really start

  • @globalwebdesign2024
    @globalwebdesign2024 3 года назад

    Thanks for the tips, I really appreciate them. You mentioned OSPG Play Machines and I have experimented with them, but still cannot figure out what I need to do. So frustrating. When I did e.g. the CEH course/labs, there was always an objective, like u have to hack into this windows machine and get that secret file, etc, whereas here no info is given as to the main target. Even when I click on the Walkthrough and try to follow it, it didn't work. They showed me some IP addresses that made no sense and even Nmap displayed that the host is unreahable... Could you help me, pls? Thanks

    • @JSONSEC
      @JSONSEC  3 года назад

      Maybe you're skillset isn't quite ready for the PG.
      Check out the Offensive Path on TryHackMe, it guides you through the methodology in the beginning and gradually gets you riding on your own 🙂

    • @globalwebdesign2024
      @globalwebdesign2024 3 года назад

      @@JSONSEC Thanks

  • @breakpointacademy
    @breakpointacademy 4 года назад +2

    Thank you for the awesome info Json,i really love your videos, cheers from Romania!

    • @JSONSEC
      @JSONSEC  4 года назад +2

      Pleasure, I'd love to go back to Romania, I've only really spent time around Cluj-Napoca. Would love to explore more! Beautiful country!

  • @abdiwahabahmedomar2399
    @abdiwahabahmedomar2399 4 года назад +2

    Thanks for the information from somalia

  • @TzZek
    @TzZek 4 года назад +1

    Thanks for your insight!

  • @tallst1
    @tallst1 4 года назад +1

    So read the PWK material but skip the exercises + report and spend as much time in the labs?

    • @JSONSEC
      @JSONSEC  4 года назад +3

      I don't see much value in reading the material either. I just skimmed over it enough to satisfy the exercise criteria

    • @tallst1
      @tallst1 4 года назад

      @@JSONSEC oh wow, would this apply to someone who has only taken the PTS and some few HTB boxes from the Tj null's list? Thanks for the reply

    • @JSONSEC
      @JSONSEC  4 года назад +3

      @@tallst1 I won't make any recommendations for you. Your experience and learning style may benefit from it. But if I were to do it all again I'd go straight to the labs

  • @nolimustermann1779
    @nolimustermann1779 4 года назад +5

    i want to ask a silly question. you mentioned that you worked as a developer too. can you say that working as a ethical hacker is generally "better" than working as a developer in terms of stress level, work-life-balance (do you have more peace in life) and so on, as long as you are not a very passionate programmer or very passionate ethical hacker. what does your objective observation say?

    • @JSONSEC
      @JSONSEC  4 года назад +8

      Wow great question! I suppose the context of the job is different. As a pentester you tend to work as a consultant so one client to the next, everything is time boxed so not much OT and good work life balance. Sometimes client after client can get a bit exhausting when theres no down time.
      Working as a dev you're typically internal and part of the project team. When deadlines approach you'll likely be doing OT. Plus you get a lot of people raising defects and last minute requirements. Though, Dev work definitely feels more creative.
      I can't objectively say which one is better, but it comes down to your working style, what you enjoy and how you are with other people.

    • @nolimustermann1779
      @nolimustermann1779 4 года назад +1

      @@JSONSEC Thank you very much for the quick answer.

  • @alanpatrick7465
    @alanpatrick7465 3 года назад

    Do you recommend the wptx? I have the option to take it, but am weighing it against just doing the burp certification. There aren’t too many appsec certs out there.

    • @JSONSEC
      @JSONSEC  3 года назад

      Good question. The port swigger material is shit tonnes better than ewptx but the cert is less known.
      Personally I'd be a pioneer and go the burp route. The cert is currently free till the end of the year too

  • @itsm3dud39
    @itsm3dud39 3 года назад

    can we do exam in virtual machine?

  • @itsfran76
    @itsfran76 3 года назад

    How did PTP help you with OSCP? THANKSSS

    • @JSONSEC
      @JSONSEC  3 года назад +1

      Taught the basic concepts, bof, pivoting, Linux ... Everything. OSCP was more like the work experience and ptp is like University

    • @itsfran76
      @itsfran76 3 года назад

      @@JSONSEC many thanks

    • @buretmarcano8851
      @buretmarcano8851 2 года назад

      @@JSONSEC hello, ptp in the one from elearning security!?

  • @nixcutus
    @nixcutus 4 года назад +1

    This is an amazing video bro thanks.

  • @sirisonto
    @sirisonto 3 года назад

    so between the 1st and the 2nd it was PG's? failed 1st too =(

    • @JSONSEC
      @JSONSEC  3 года назад +1

      Yeah pretty much, I think I started pg practice a week before my 1st

    • @sirisonto
      @sirisonto 3 года назад

      @@JSONSEC you meant your 2nd? id like to know what was your prep between the 2 exams

  • @SuperHtownswag
    @SuperHtownswag 2 года назад

    GREAT ADVICE

  • @emilymcgettrick4435
    @emilymcgettrick4435 2 года назад

    Did you say 39 hrs per week or 3 - 9 hrs per week?

  • @hackerblack7542
    @hackerblack7542 4 года назад +1

    Good information!

  • @Trent_111
    @Trent_111 4 года назад +1

    Great video

  • @mrprogram293
    @mrprogram293 3 года назад

    Amazing video thanks very much

  • @supriyoguha9314
    @supriyoguha9314 4 года назад

    Sir, please share the links of vulnerable lab machines....😄

    • @JSONSEC
      @JSONSEC  4 года назад +1

      portal.offensive-security.com/control-panel

  • @CampingShadowComplex
    @CampingShadowComplex 3 года назад

    When I know I'm ready for the OSCP exam?

    • @JSONSEC
      @JSONSEC  3 года назад +4

      You never will...

  • @michael30000
    @michael30000 3 года назад

    Hey mate, great video. Would you still do your eptp before oscp if you were to do it for free ? Cheers

    • @JSONSEC
      @JSONSEC  3 года назад +1

      I did actually do the PTP a year prior to starting the OSCP. If I could do it for free? Hell yes!

  • @M4lch4t
    @M4lch4t 4 года назад +1

    No HacktheBox at all?

    • @JSONSEC
      @JSONSEC  4 года назад +1

      I wouldn't say none but it wouldn't be my main focus

    • @rolfvreijdenberger1639
      @rolfvreijdenberger1639 4 года назад +1

      @@JSONSEC thanks, didn't know about the proving grounds. Why not HTB as main focus? Ah, I hadn't reached 4:36 yet :)

  • @micosair
    @micosair 4 года назад +16

    This guy has such an Australian accent that a kangaroo jumped at me from the screen, WTF.

  • @pinglocalhost
    @pinglocalhost 4 года назад +3

    < < nom nom nom my brain can lift more lbs now with this info.

    • @JSONSEC
      @JSONSEC  4 года назад +5

      Thanks, but we use the metric system here 😂