OSCP prep - Machine walkthrough & avoiding rabbit holes and report taking techniques

Поделиться
HTML-код
  • Опубликовано: 7 янв 2025

Комментарии • 25

  • @WadeThrillson
    @WadeThrillson Месяц назад +1

    this is the reason why i dont rush and buy the exam first. its great to learn from the guys like you in the first place. first it doesn't look intimidating at all, second your points on rabbit hole will probably save me some decent hours :) again very much appreciated.

  • @ezekieljills
    @ezekieljills Месяц назад

    loved the video man. learning alot on rabbit holes

  • @Dadstin
    @Dadstin 6 месяцев назад +3

    🔥 nice, i just did this box. Loved the commentary, i take my oscp this Friday

  • @pwolbrycht
    @pwolbrycht 3 месяца назад

    Fantastic walkthrough, thank you.

  • @iSgapetti
    @iSgapetti 3 месяца назад

    26:13 what is the proof-of-concept section of the report for? Is it the PoC for exploit code? So in this case, that would be N/A?

    • @redfire-359
      @redfire-359  3 месяца назад

      Yes its for the code you use, and yeah if its not a program (i.e. manual exploitation) there's no code so you can put N/A. For code you get from github you can just include the link and maybe a code snippet if you had to modify something.

  • @ellerionsnow3340
    @ellerionsnow3340 3 месяца назад

    The minute you put vim in I screamed. Great video though.

  • @sandeepd145
    @sandeepd145 6 месяцев назад +1

    Please make video on report writing

  • @AUBCodeII
    @AUBCodeII 6 месяцев назад

    Thank you very much for making this video, bro. I'm currently doing retired HTB boxes to train for the OSCP exam. So far I've completed almost 50. How many PWK lab machines have you completed before taking the OSCP exam?

  • @cedrOcs
    @cedrOcs 5 месяцев назад

    Isn't enum4linux prohibited on oscp?

  • @mafiadaniel94
    @mafiadaniel94 7 месяцев назад +1

    Does the OSCP exam has this many rabbit holes as well? The challenge machines OSCP A B and C weren't that full of rabbit holes.

    • @redfire-359
      @redfire-359  6 месяцев назад

      Depending on the exam you get, yes there could be a couple, I don't know exact numbers. And Offsec doesn't always put them in there intentionally but sometimes its just easy to get tunnel visioned on a port or service if its out of date, looks like it has an exploit available, etc.

  • @ungung7151
    @ungung7151 2 месяца назад

    Hi Friend, can share your note any command list?
    Thanks

  • @fatewalker6463
    @fatewalker6463 6 месяцев назад

    I have a question, I've made a lot of command alias and custom scripts to automate recon tasks, do I have to provide all my command alias and scripts code in the report? Would appreciate to get a reply

    • @ArvindJuneja
      @ArvindJuneja 5 месяцев назад

      I mean the report require that someone else using it should be able to „root the box” doing all steps included. If you skip some parts that is not filling up the requirements and goal of the reporting part

    • @redfire-359
      @redfire-359  2 месяца назад

      sorry this is kinda late but yeah i'd add your alias file in the report. Personally I just didnt use aliases during the exam just to be safe

  • @spoon2k
    @spoon2k 6 месяцев назад +1

    Is this machine retired on PG? I can't find it. Subbed!

    • @redfire-359
      @redfire-359  6 месяцев назад +1

      Yeup its still in the providing grounds play VM list, you could also get it here
      www.vulnhub.com/entry/seppuku-1,484/
      Thanks for the sub!

    • @Siik94Skillz
      @Siik94Skillz 5 месяцев назад

      Budddy... It's proving grounds! Good video, tho ​@redfire-359

  • @kodeish
    @kodeish 5 месяцев назад

    Could you please share your notes? I liked how they were organized. It's okay to remove any OSCP copyright stuff

  • @gamingtweaks3065
    @gamingtweaks3065 2 месяца назад

    i am making notes of this, never given this exam but i wanna be ready of i do, which is ironic itself

  • @ver4576
    @ver4576 5 месяцев назад +4

    If this is supposed to be "easy" and a actual OSCP machine would be "hard" then I'm giga F*d, this did not look easy at all and the rabbit holes would ruin me

    • @phillydee3592
      @phillydee3592 4 месяца назад

      Go for the low hanging fruit first..