OSEP - Offensive Security Experienced Penetration Tester (REVIEW)

Поделиться
HTML-код
  • Опубликовано: 21 авг 2024

Комментарии • 179

  • @ShinigamiAnger
    @ShinigamiAnger 3 года назад +103

    When you’ve been hearing everywhere that OSCP is ‘so hard’, even by experienced people that do crazy things, and then John “oscp is just the tip of the iceberg... 😐

    • @melvin6228
      @melvin6228 3 года назад +22

      IMO it becomes less hard. I haven't taken OSCP or OSEP, but I hacked at least one box of every level on hackthebox before the writeups (easy: enough boxes, medium: enough boxes, hard: Zetta, Insane: PlayerTwo) and what I've noticed are two things:
      1) It's still crazy hard, but since you're already used to that, it's fine.
      2) Sometimes it's not much more difficult, but it just involves an entirely different skill. If you've never done that skill, it feels insanely difficult. For example, with PlayerTwo the final challenge is doing a heap overflow. All you get is the binary, so you also need to know x86-64. If you've never read C and never did x86-64, then the task feels insurmountable. I was simply rusty on C and ok on x86-64. So I knew I could do it and that it'd take me a long time as understanding C (and reading malloc.c) was the predominant skill. Understanding SQLi is completely different to understanding how to do a heap overflow. You could argue it's harder, but a part of it is simply because you've never done it before.
      For example, the hardest thing I've ever done was to learn x86-64 assembly and C in a course, since those 2 things were seen as prerequisites and I never have seen either of them (I knew Java, lol).

    • @sharghaas7774
      @sharghaas7774 3 года назад +2

      I mean we all knew it that it''s pentester beginner level right? But that what's amazing we'll never get a shortage of challenges :D (I'm on my 2nd Try OSCP)
      I can't wait to get through all these challenges

    • @ShinigamiAnger
      @ShinigamiAnger 3 года назад +6

      @@sharghaas7774 yeah well, I only recently realized that oscp is considered beginner level. I've been studying so hard, dreaming of proudly getting oscp certification, just to find that it is nothing anyway.
      Probably not even a problem for me, as hard as I try, I always feel like I'm just beginning. I wonder when, and if, I will find myself comfortable in this field. Sometimes I fear like I have made the wrong choice, as I will never be good enough. It is a bit depressing.

    • @analactica
      @analactica 3 года назад +3

      @@ShinigamiAnger you're not alone , lol , that's all I can tell you , I'm definitely way behind you , and just maybe .... Older , so you can only imagine how that looks like to me , not to compare it to music production but i remember when I used to launch all that software and see all those knobs and frequencies and dig into audio engineering tutorials and classes how it all looked to me , now ?
      I do that to get my mind of things , litrally how i know the back of my hand , so to me , i just keep reminding myself how much i would've missed if i quit , and how much I'd regret it , same for Muay Thai to me as well , first leg kick from a pro guy and start Wondering why am I even doing that to myself , hahaha that was harder not to quit , but i didn't , everything has a learning curve , just hang on in there , you'll know when it's too much or not your field , just make sure you're not mixing that with the frustration of the slow progress at the beginning , everything seems to get bigger as you dig in , it only means you're actually learning a lot. Good luck
      Hope i didn't bore you with the long comment haha it's just that your comment hit home. Had to say something

    • @ShinigamiAnger
      @ShinigamiAnger 3 года назад +1

      @@analactica not bored at all, very appreciated, sincerely. I wish you all the best.

  • @rivhaaken9763
    @rivhaaken9763 3 года назад +27

    Just wanted to leave a big Thank You here John. Amazing guy with amazing content!

  • @ITSecurityLabs
    @ITSecurityLabs 2 года назад +1

    Thank you for this video. I watched it all. Today marks day one on my journey to the OSEP, I love this hands on learning and getting better everyday

  • @zhumzhum8323
    @zhumzhum8323 3 года назад +17

    Obsidian looks very similar to Joplin which is what I've been using. I think Obsidian has a better looking interface. Congrats on getting the OSCE, and thanks for coming to speak at my college a week before your exam.

    • @jbkhan1135
      @jbkhan1135 3 года назад +1

      I used to use Joplin and started looking at Obsidian as a result of this post. I kind of feel like Obsidian is a bit better so far that I've had a chance to try it.

  • @SuitUpDubstep
    @SuitUpDubstep 3 года назад +5

    As someone who's currently studying the basics (networks, programming and such) to get in to this line of work, this channel is great. Not only do you get awesome videos like this, you also get videos with pentesting on online resources. The school I'm in prepares for the students to be able to take the CEH cert, which isn't great - but at least it allows you to see pentesting on the horizon and can be a stepping stone into getting real actual certs. Looking forward to the day where I have studied, practiced and studied some more to have OSEP and other certs.

    • @mr.s5214
      @mr.s5214 2 года назад

      How's it going so far?

  • @nicholasw2994
    @nicholasw2994 3 года назад +8

    John you have been an inspiration for people getting started! You've been educational and entertaining. Loving the new intro and outro, really been stepping up the game! Keep up the amazing content!

  • @luigiceleste8453
    @luigiceleste8453 3 года назад +5

    Thank you John. I applied recently to OSEP course and I wanted to listen from who already experienced this path. First off, congratulations for how fast you passed this huge challenge. Then I would like to say that I love the passion that transpires from your words and your eyes when you talk about pentesting and hacking. It just makes me want to get up from my bed again and keep studying after a long day passed over the course. And also you well said: the coolest thing that comes out from these experiences are that everything is tangible, security is done effectively, and not spoken in a seminary (thing that I hate). This is in my opinion the biggest value of being a pentester.
    Thanks again for your valuable contents, my best wishes from Italy 🇮🇹

  • @dxdarrel8843
    @dxdarrel8843 3 года назад +2

    Sir, you're just not a content creator, you're a great teacher, a true inspiration. Thank you! I have a little bit more courage for taking OSCP.

  • @JohnSvazic
    @JohnSvazic 3 года назад +3

    First off, congratulations! Secondly, thanks for this. I was on my way back to OffSec for certs, and this is exactly what I was looking for in terms of what this new cert involved. I'm sold.

  • @twinsecurity5023
    @twinsecurity5023 3 года назад +4

    Thanks for the insight! I've felt like the OSCP is great for getting your feet wet with pentesting tools and techniques, but isn't a substitute for real-world experience. It's nice to know there's a more advanced course that accounts for the type of security and configurations found in enterprise environments.

  • @zanidd
    @zanidd 3 года назад +5

    Awesome. Congratulations. I plan on taking the OSCP after I finish my degree in summer

  • @ITachi_11.11
    @ITachi_11.11 3 года назад +1

    John bro, the world is a better place with you doing all of this free help to the ones in need. Keep inspiring man, much appreciate everything!

  • @night0x1
    @night0x1 7 месяцев назад

    I'm glad I cam across this video. Have not taken any of the offsec certifications but currently taking the ine certifications. I learned alot by just watching your video. Gotta start taking notes using obsidian.

  • @ChaseHatch
    @ChaseHatch 3 года назад +8

    Been waiting for this... taking the OSWE in March, trying to get it out of the way so I can get to this!

    • @dochood1966
      @dochood1966 3 года назад

      I just got my OSWE. Tackling this in a couple of months.

    • @ChaseHatch
      @ChaseHatch 3 года назад +1

      @@dochood1966 Passed! I've been working on the PEN-300 now for about a month.

  • @ccelikanil
    @ccelikanil 3 года назад +10

    Spoiler alert: John Hammond is just being John Hammond, don't expect anything less. This dude is basically a genius
    Edit: Oh huge congrats again on the results!

  • @roxanakovaci9342
    @roxanakovaci9342 3 года назад +2

    Great video! I love how representative this course is for a wide range of different cyber-security roles (started to apply what I've learnt during OSEP in my day-to-day job straightaway). Thanks for the great content and pieces of advice! Will definitely put them in practice soon for my own exam.

  • @DrGamer666
    @DrGamer666 3 года назад

    I seriously can't tell how much i have learned from this guy. He is extremely talented and more importantly a good person we all got to know. Thank you john and congratulations for the result

  • @bhupenderbhardwaj6991
    @bhupenderbhardwaj6991 3 года назад

    Big Congratulations to you John ! You walk the talk.. There are not too many people who are knowledgeable, Hands-on, accredited and also Share the knowledge ! InspiringCyberLeader !

  • @dropcake
    @dropcake 3 года назад +1

    Awesome work John. Great info. Aiming for OSCP before summer starts

  • @Twistidskull
    @Twistidskull 3 года назад +27

    Basically John said "gg2ez who's next"

  • @reality144th
    @reality144th 10 месяцев назад

    This was very enlightening, I plan to take this course because it seems like a great deal of knowledge can be gained.

  • @Gustavo-hs6jy
    @Gustavo-hs6jy 3 года назад

    That outro volume blew my ears off haha. Amazing video John, I love your passion for security it's encouraging and inspirational. Great job on the review and passing the OSEP. I'm taking the OSCP in May and have been studying too (notes, notes, and more notes). Your suggestions tools/techniques are helping a lot.

  • @FlashNapster2011
    @FlashNapster2011 3 года назад +1

    Thanks alot for the review. I already registered the course 2 days ago. Can't wait to start

  • @pbx7257
    @pbx7257 3 года назад +1

    John Legend right here. Man, congrats!

  • @MingerHarrier
    @MingerHarrier 3 года назад +4

    I liked the "What's up" intro

  • @tomasgorda
    @tomasgorda 3 года назад

    Congratulations John for this amazing new cert 👍. You are the man 👍👍👍

  • @Topherelius
    @Topherelius 3 года назад

    You rock John! Thanks for being a best friend! =) Congratulations 1000!!

  • @dilandodangoda109
    @dilandodangoda109 3 года назад

    Really great video. I learn something every single time I watched your video. You doing a lot for the community. I really appreciate and admire your work. Thank you

  • @swift87100
    @swift87100 3 года назад

    Congratulations dude and congratulations in advance if you actually are the first person to clear the exam. Good start for this year.

  • @olivert.7192
    @olivert.7192 3 года назад

    i remember last year when they announced it, i said i would sign up with a friend. I only just signed up this week. Im so excited to get in.

  • @sinwolf5539
    @sinwolf5539 3 года назад

    Thank you for taking the time to tell us about OSEP !

  • @jorgevilla6523
    @jorgevilla6523 3 года назад +1

    Thanks for the great review as always! and of course Grats.

  • @iRevitalize
    @iRevitalize 3 года назад +1

    Production quality is lookin sharp

  • @EXPmusic
    @EXPmusic 3 года назад

    congrats!
    id love a separate video just about Obsidian and Latex and your note taking process

  • @Urbancorax2
    @Urbancorax2 3 года назад

    That’s a great video! Thank you John! You’re a live reminder that everything is possible. Thank you.

  • @MeMe-vn5zh
    @MeMe-vn5zh 3 года назад

    Really awesome video, such genuine advice, such detailed content, we need more like you John! Thank You.

  • @m4l138
    @m4l138 3 года назад

    Thank you for sharing! You are definitely a certification killer! Congratulations John!

  • @KhalidHakimi010
    @KhalidHakimi010 Год назад

    You are incredible John ❤️

  • @brad.myrick4633
    @brad.myrick4633 3 года назад

    welp I found you because I was eyeing this course. now I'm subscribed, great video.

  • @crispyhaole8533
    @crispyhaole8533 3 года назад

    Congratulations and thank you for inspiring so many!

  • @juliantan3432
    @juliantan3432 3 года назад

    Gosh I'm excited hearing about this course already!

  • @emzgalante2640
    @emzgalante2640 3 года назад

    You're Amazing Sir Hammond, (Subscribed), Most definitely my role-model/online mentor. Thanks for your time, knowledge and inspiration!!!!

  • @m3tac0m
    @m3tac0m 3 года назад

    Thank you for sharing! Congratulations John! I'm curious when you do OSED :) I love exploit development. I'm waiting to see your video about OSED.

  • @emmanuelsadiq2165
    @emmanuelsadiq2165 3 года назад

    Big win. You inspire me John

  • @djay2600_yt
    @djay2600_yt 3 года назад

    Congrats ! Very interesting and instructive like all your content. Thank you so much !

  • @huwjones3241
    @huwjones3241 3 года назад

    Congrats John!

  • @abhishek_k7
    @abhishek_k7 3 года назад

    Congratulations! You are an inspiration!

  • @ashishashish-di3cg
    @ashishashish-di3cg 3 года назад +1

    Congratulations 🎉

  • @thekurdgamer8366
    @thekurdgamer8366 3 года назад +1

    Legend is back

  • @vuanh0110
    @vuanh0110 3 года назад

    Sold! I'll try to load some C# into my smooth brain and then register for the course!

  • @sahilnayak6693
    @sahilnayak6693 3 года назад

    Just one word after watching this:
    Fire 💥💥💥

  • @Westar.
    @Westar. 3 года назад

    Congrats John!

  • @anubhav9476
    @anubhav9476 3 года назад

    John congratulations 🔥

  • @ardubz1981
    @ardubz1981 3 года назад

    Thanks for the Obsidian commercial.

  • @alexeysolovyev1107
    @alexeysolovyev1107 3 года назад

    Another motivated video:) Tanks!

  • @sharghaas7774
    @sharghaas7774 3 года назад

    Insane I was just doing forest (HTB) and using bloodhound and your tip came sooooooo handy!!!

  • @Katsumato0
    @Katsumato0 3 года назад

    great video John. Hope you're doing well

  • @wolfiedgr8t
    @wolfiedgr8t 3 года назад

    Well done John 👍

  • @MaximusIA
    @MaximusIA 3 года назад

    Thanks @John and congratulations

  • @pranavdarwai7349
    @pranavdarwai7349 3 года назад

    Congratulations, I am Happy for you.

  • @ayodub
    @ayodub 3 года назад +3

    @15:20 Maybe the hacker you were tracking was mid-way through their OSEP, and was trying out some of the stuff they had learnt.

  • @jonjontanyag7998
    @jonjontanyag7998 3 года назад

    Congrats man.

  • @dipanshusendre9625
    @dipanshusendre9625 3 года назад

    Amazing video ❤️... Can you make a video on a journey of oscp or how to prepare for oscp ... That would be amazing for us newbies

  • @smitmoradiya7453
    @smitmoradiya7453 3 года назад

    Congratulations :D

  • @LinuxSploitOfficial
    @LinuxSploitOfficial 3 года назад +1

    Congratulations

  • @hope4scotland734
    @hope4scotland734 3 года назад

    @John Hammond i would love to learn more how exciting ThankQ for sharing your work

  • @saikatkarmakar955
    @saikatkarmakar955 3 года назад

    How you're so good at this🙏

  • @FP01
    @FP01 3 года назад

    I also want to take the OSEP course!! Rn on OSCP journey ...long way to go tho lol! Many things to learn...

  • @CybrJames
    @CybrJames 3 года назад

    Great video. Thanks John..

    • @CybrJames
      @CybrJames 3 года назад

      @John Hammond. I had some questions regarding the Offensive Security Certs. First are you open to answering a couple questions? If so where do I direct them? Thank you as always sir.

  • @hashimmirdad8678
    @hashimmirdad8678 3 года назад

    John You the best mentor for penetration tester but with the request could you make a series of training "Python for Hacker" because your explanation is awesome.

  • @mohammedalsuweidi9947
    @mohammedalsuweidi9947 3 года назад

    Congratulations very inspiring

  • @mattlebutter9162
    @mattlebutter9162 3 года назад

    Great review, thanks. If you ever do a follow-up or something with more questions here is one: it is commonly said that the right strategy for OSCP is to go in once you already have some good knowledge in order not to waste the timelab on learning theory (knowing how to exploit basic BoF for instance, or the basics or privesc in linux and windows).
    As OSEP is also based on lab time that costs money, what are the technical fields to already be comfortable with, in order to not spend 1month just getting to grips with theory rather than live practice ?

  • @jayarmstrong6870
    @jayarmstrong6870 3 года назад

    Nice studio bro!..willing to get this course

  • @zackaryhaddon5445
    @zackaryhaddon5445 3 года назад

    This was great! - can you do a video with you doing a quick CTF and how you were taking notes, how you documented what you did etc... I'm curious to see the flow... thank you!

    • @zackaryhaddon5445
      @zackaryhaddon5445 3 года назад

      NVM I actually found a video you did - lol thanks! :-)

  • @thepankechannel
    @thepankechannel 3 года назад

    First of all congrats!!! what a great review! Now OSEP vs ecptxv2? I'm starting the ecptxv2 course, from what I can see many things overlap. OSEP seems to have more Linux.

  • @abisrug4898
    @abisrug4898 3 года назад

    This guy rt here makes me feel good

  • @aye_scythe
    @aye_scythe 3 года назад

    I was here when it was live for the first time. 👀

  • @nero2k619
    @nero2k619 3 года назад

    Now time to review OSED :)

  • @chris8206
    @chris8206 3 года назад

    Awesome video

  • @higoogle7860
    @higoogle7860 3 года назад

    That was awesome

  • @dharunkumarshanmugam8206
    @dharunkumarshanmugam8206 3 года назад

    Thanks John.

  • @sampritdas783
    @sampritdas783 3 года назад

    😁 Thanks for review

  • @remyhamon1154
    @remyhamon1154 3 года назад

    congrats from France ;)

  • @pi8tol
    @pi8tol 3 года назад

    i watch it !!

  • @robertwouda
    @robertwouda 3 года назад

    Very epic

  • @mohammadalsoussi1554
    @mohammadalsoussi1554 3 года назад +1

    Pretty nice

  • @Umar0x01
    @Umar0x01 3 года назад

    Thanks man!

  • @s.aravindh6227
    @s.aravindh6227 3 года назад +1

    Nice bro 😀😀

  • @smailhamou4115
    @smailhamou4115 3 года назад

    Thanks you so much ❤❤❤❤

  • @oy9804
    @oy9804 3 года назад

    we want osep course 🤗🤗 Do it for us

  • @zanidd
    @zanidd 3 года назад

    Oha, reporting in markdown. Nice

  • @exploiter_soloo
    @exploiter_soloo 2 года назад

    super

  • @Detonati0n
    @Detonati0n 3 года назад

    Congrats on passing! Hopefully they send you a commemorative "first blood" certificate 🤣 Would you say that learning an alternate C2 like Empire or Covenant was necessary?

  • @sh3bu
    @sh3bu 3 года назад +1

    John start streaming on twitch .Want to see you struggling solving boxes lol :) - Im literally a John hammond fanboy haha

  • @quadrivium333
    @quadrivium333 3 года назад +2

    Ahh, the old “I hardly used any of my lab time” spiel. Ive known several people who while prepping for these exams spent countless hours in the labs/range, complained about how tough it was, said it was next level but magically once they passed the exam their story changed to “it wasnt that hard,” “i only spent about 3 weeks studying,” “the course is entry level stuff.” Classic hindsight memory distortions or ego stroking. Not sure which but it’s annoying af. Otherwise good video.

  • @franklebouthillier8633
    @franklebouthillier8633 3 года назад +1

    Hey John, thanks for the video that's some great info! How does this compare in terms of difficulty to the eCPPTv2?

    • @thepankechannel
      @thepankechannel 3 года назад

      it's definitely more difficult. It seems to be above ecptxv2

  • @phillydee3592
    @phillydee3592 Год назад

    Damn!!!I'm from South Africa, so the rand/dollar makes this course damn expensive for me unfortunately 👎🏼
    Very late but congratulations 🥳🥳😁

  • @token112
    @token112 3 года назад +1

    And here I was hoping they had made something between zero and OSCP...

    • @token112
      @token112 3 года назад

      @Fouad Issa I'd be more prone to Pentest+ or CEH if simply for the 8570 compliance. Just a little let down there isn't an "in-house" option within offensive security's pipeline.

  • @ARZ10198
    @ARZ10198 3 года назад

    GG ez for john

  • @prabingurung4844
    @prabingurung4844 3 года назад

    A quick question as a beginner while taking certification exams(specially during the exam) what are you allowed and not allowed to do. Is there any video about it?🤔🤔