Offensive Security Certified Professional (OSCP) Review

It’s just another Saturday, I wake up around 6:30 am, get ready and head into the office to start my 12-16 hour day of Penetration Testing with Kali Linux (PWK/OSCP) training from Offensive Security. Although, it’s not like the last 16 Saturdays, today is exam day.

OSCP Exam

I sat down at my desk around 7:30 am, just before the exam started at 8 am. The exam credentials and instructions came right at 8 am, and away I went. I spent the next 15 hours working on the exam without leaving my chair for more than a minute or two at a time. The exam started off really well but by mid afternoon I was stuck on something I thought should be easy. I decided to move on to other machines, which was a fantastic idea looking back. I realized the brain fog was starting to set in around 11 pm and needed a break. So I went home around midnight, took a nap from 1-4 am, and then went back at it. I left the office that night knowing I was close to passing the exam but I didn’t want to leave it up to luck.

I spent the remaining 3 hours (half-asleep) on the last box. There were so many damn rabbit holes I just couldn’t find the right thing to exploit! About an hour before the exam ended, I went back through my notes to make sure I had all of the required screenshots (Exam Requirements). After the exam time expired, I worked diligently on the report, which is obviously one of the most important parts of any pen test. After completing and then reviewing the report numerous times, I packaged everything up (Lab Report/Exercises/Exam Report) and sent it off to Offsec for their review.

OSCP Exam Complete

An email came a few hours later saying they had received my documents and that I should receive a pass/fail email in the next 3 business days. I received the pass email within 2 business days of submitting my report! I was so happy to have passed the OSCP on the first try! I’ll never forget the moment I received the email from Offsec, the stress and weight of the exam was immediately gone. Waiting for that email was absolutely painful even though I knew the report covered all the requirements and I had enough points to pass. It may not seem like it from this review, BUT this was the most grueling exam that I’ve ever taken. I don’t want to give too many details away about the exam but imagine banging your head on the wall or a desk for 24 hours straight…Welcome to the OSCP exam! 😉

OSCP Exam Recommendations

  1. Rotate through machines every 3-4 hours.
  2. Organize all notes and exploits for easy/quick access.
  3. Avoid rabbit holes – #1 helps with this.
  4. Take breaks, if you need to :).
  5. Know your limits.
  6. Spend at least 2-3 days working 14-16 hours straight on the PWK labs. Simulate the exam experience by attacking 3-5 machines during this period. I did this multiple times and it really helped me prep for the exam.
  7. Complete all exercises and the lab report for an additional 5 points on the exam.

OSCP Coursework

The coursework was great! The course came with a PDF and instruction video’s. PWK syllabus can be found here.  There were a few gaps where the PDF had more info than the videos and vice-versa but that’s really my only complaint.

OSCP Coursework Recommendations

  1. Complete ALL coursework/exercises before working on the lab machines. I cannot express this enough.
  2. Understand each exercise, don’t just complete the exercise and move on. Understanding is key.
  3. Utilize the PWK Forum and Offsec support as needed.

OSCP Lab

The first time I accessed the PWK lab I was a bit overwhelmed. There were a ton of machines in the public network and I didn’t know where to start. From there I devised a plan to go after the low hanging fruit first (the easiest to exploit). Some of the coursework helps you find the low hanging fruit, but after that, it’s all on you to devise a work-plan. The lab environment was awesome. There were all different kinds of servers from Solaris to XP and everything in-between. There were many different kinds of software and services running on these machines, which gave me a good look at many different vulnerabilities and exploits.

OSCP Lab Recommendations

  1. Make sure you’ve read the Exam Requirements BEFORE starting on the lab. Practice what you need for the exam throughout your lab work.
  2. Find the low hanging fruit.
  3. Rotate through machines every 3-4 hours. Take good notes so you can come back to the machine later.
  4. Get a good feel for Metasploit, Meterpreter and sqlmap but do not rely on it through-out this course. Get comfortable finding and editing exploits, you can only use Metasploit/Meterpreter on one machine on the exam.
  5. Utilize the PWK Forums only when stuck on the same machine for 8+ hours.
  6. Document everything you do and everything you learn. I used OneNote.

Start to Finish Recommendations

  1. Make sure your significant other, family, friends, etc. have a good understanding of the dedication needed to pass this exam.
  2. Make a promise to yourself to dedicate a specific number of hours every day to PWK. I chose to dedicate on average 4 hours a day for 4 months.
  3. Purchase 90 days of lab time when you will not have any vacations or extended periods away from the lab.
  4. Spend the first 2-3 weeks working on the exercises and coursework.
  5. Spend the next week or two rooting the low hanging fruit; and then, move on to harder machines and other networks.
  6. Root as many machines as possible without using Metasploit, Meterpreter, and sqlmap (or as little as possible).
  7. Once the lab time expires, work on buffer overflows, reporting and Vulnhub (See below).
  8. Take 2 days off previous to the exam. Go have some fun, because the upcoming exam will be anything but :).

Most importantly, DO NOT give up. The motto for Offsec, if you’re not familiar, is Try Harder! If you don’t succeed the first time….try, try, again :).

Vulnhub

If you’re not familiar with vulnhub.com, check it out. They have a ton of Boot2Root/CTF style vms and some of them are similar to lab machines. Below is a list of vms that were similar to lab machines that I completed while studying for the OSCP:

  1. Kioptrix Level 1
  2. Kioptrix Level 1.1
  3. Kioptrix Level 1.2
  4. Kioptrix2014
  5. pWnOS v2.0
  6. SickOs 1
  7. SickOS 1.2
  8. Stapler
  9. Tr0ll
  10. Tr0ll2
  11. Vulnix
  12. VulnOSv2
  13. FristiLeaks 1.3
  14. LordOfTheRoot 1.0.1
  15. mrRobot
  16. pwnlab_init

I don’t think I would have been successful in passing the exam if I did not complete these Vulnhub vms. I would HIGHLY recommend you complete all of these before taking the exam. DO NOT complete these vms without understanding every single step you take to root them and remember, document, document, and then document some more :).

Summary

The exam and training couldn’t have gone any better. If you follow the Start to Finish Recommendations above, I know you can pass the OSCP too! Offensive Security did a great job putting this course together and I can’t thank them enough. I can say I successfully Tried Harder! I look forward to taking the Crack The Perimeter class next year as I work towards the Offensive Security Certified Expert (OSCE). Check out this link for a list of links I used while studying for this exam. I hope this was helpful. Thanks for reading!

 

4 Replies to “Offensive Security Certified Professional (OSCP) Review”

  1. Hi there,

    I manage to root around 26 machines in two months. Since I am still have one semester to finish my bachelor degree in computer, I waited for 3 months before I do the exam.
    My exam time is next week. By the way, I root all the machines manually without metasploit.
    Do you think I can pass the exam after I study all the suggested Vulhub machines?
    Or do you think I probably need one more month lab time to root more machines?
    Well, I find your blog super helpful and I am going to suggest you to my fellow friends.
    Much appreciation for write the great review. Most importantly, thx for point out the direction. Most of the people, such as myself, don’t know where to continue after the lab time.

    1. Hi songchenhan, I think if you complete all the Vulnhub machines and practice buffer overflow you have a good chance at passing. Give the exam a try and let us know how you do. Good luck!

      1. Thx Jim.I already read <> which discussed buffer overflow clearly and artistically. I believe I have a strong understanding of buffer overflow knowledge.
        I will do some practice by repeat the curriculum’s question and some other machines.
        Thanks for your reply. I will work on it. You have no idea how much confidence you just gave me.
        Best regards.

Leave a Reply