HTB Oscp Review
HTB Oscp Review
Discussions Categories
Home › O�-topic
For the past couple of months, I have been away from HTB, as I have
been working on the OSCP labs, as a preparation for my OSCP exam.
I have just �nished my OSCP exam and got my certi�cation, and
thought I would write this review, especially for HTB members, from
an HTB member perspective.
PWK lab
First of, I would like to review the PWK labs.
Before starting on the lab machines, I took 5 days to �nish the PWK
course materials, as there are some useful things here and there.
The PWK lab in general is very well designed and well structured.
This means that the lab can accommodate both beginners and
advanced users, and that beginners will have plenty of machines to
learn on before starting on advanced machines.
I have �nished all of the lab networks, except for the Admin
network, which I could not �nd the key to unlock it even though I
literally owned all other machines. The support was of no help as
well, as always.
Most of the machines in the PWK lab "80%" are designed for
beginners, and are directly exploitable. This gives beginners a lot of
space to learn and improve their skills before going for more
advanced machines.
1 of 18 03/04/19, 5:25 am
OSCP Exam review "2019" + Notes & Gift insid... https://forum.hackthebox.eu/discussion/commen...
-Alpha
-Joe
-Pain
-Ralph
As for the other labs "IT & Dev", only a couple of machines were
directly exploitable, and all of the rest needed credentials found on
post exploitation on other machines "i.e. in txt �le, repeated user
pass, golden ticket stealing, etc". The useful thing from using these
labs is having to learn pivoting properly, even though this is not
required for the exam. I took this chance to write my personal
instructions for pivoting using 5 di�erent methods, in both port
forwarding and dynamic forwarding.
My only negative take on the PWK lab machine is that they were
getting outdated. This means dealing mostly with Windows XP, 2008,
or REHL 5 machines, which meant too many unintended exploits,
making it di�cult to guess which one was actually the intended way.
I think the PWK lab might need an overhaul in the near future,
otherwise they might become irrelevant to the real world.
2 of 18 03/04/19, 5:25 am
OSCP Exam review "2019" + Notes & Gift insid... https://forum.hackthebox.eu/discussion/commen...
The main reason behind this is that O�Sec wants to make the lab
like a real pen testing, which in this case they did a very good job, as
real pen testing is mostly dealing with exploits.
Finally, I think any Pro Hacker in HTB is more than ready to take the
OSCP exam. However, I would still suggest taking the PWK lab, as
there are some things to learn, as I will mention next.
First o�, the machines are de�nitely not the same level as the PWK
lab, but more like the HTB machines I mentioned above, expect for
the 10 points one which is very straightforward .
The exam has several things that make it more challenging, and not
only the di�culty of the machines in it.
3 of 18 03/04/19, 5:25 am
OSCP Exam review "2019" + Notes & Gift insid... https://forum.hackthebox.eu/discussion/commen...
As for the proctoring part of the exam, even though you would not
have the freedom of doing the machines as if you were alone “i.e.
like in the lab”, since someone would be watching you all the time, I
think this part was very necessary and well thought by O�Sec. This
4 of 18 03/04/19, 5:25 am
OSCP Exam review "2019" + Notes & Gift insid... https://forum.hackthebox.eu/discussion/commen...
was just like when I took the PMP or CCNA exams, an online exam
with someone proctoring you to prevent cheating. If you are not
cheating, you have nothing to hide and should not have a problem
with proctoring ”cheating means someone else doing your work for
you". This will also give you credit for your e�orts, and not have
some people doubt that some OSCP holders might not have the
skill.
The BOF machine was fairly similar to the example shown in the
PWK course, which is basic Windows BOF, with nothing advanced
"ASLR, DEP, x64..etc".
You can �nd the python scripts I used with detailed instructions
here:
Redacted
As for the use of Metasploit in the exam, I have always preferred not
to use MSF unless it was necessary, as knowing how to manually
exploit teaches you much much more. Even in the PWK lab, I didn't
use MSF at all, except for post exploitation enumeration, so it would
be faster. However, in my exam, I did use MSF, because I faced an
exploit I knew that can only be done with MSF, as I have faced this
exact vulnerability before here in one of the HTB boxes, and back
then I tried everything without MSF "so did other people" and
eventually I had to use MSF. This saved me a lot of time, since I
already knew I have to use MSF here, and not waste my time trying
to exploit it without it.
At the end, I think that the PWK lab does prepare you for a real pen
test, and if you are OSCP certi�ed, then you are de�nitely quali�ed
to be a pen tester.
5 of 18 03/04/19, 5:25 am
OSCP Exam review "2019" + Notes & Gift insid... https://forum.hackthebox.eu/discussion/commen...
I have tested this script on over 20 PWK lab machines, and I can say
that 95% of the time if there's something recon would tell you, you
will �nd it here. I have not yet tested this machine on HTB boxes, but
I assume it would work just the same, as it should be universal.
Finally, I have used this script during my OSCP exam "which was the
main reason I've written it", and I can honestly say that this was one
of the reasons I was able to �nish all machines in 10 hours. This is
simply because before starting any machine, I run this script with
the "All" option on another machine, and by the time I go to that
other machine, I would have a full recon report ready for me,
instead of wasting an hour or so waiting for that. I did not have to
run any other recon tool during my exam, as everything was
automatically laid out by this script.
I hope you like it, and please feel free to share it or improve it.
You can get it and read more about it from the following GitHub link:
https://github.com/21y4d/nmapAutomator
Future Plans
Now that I have obtained my OSCP certi�cation, I think I will directly
go for OSCE, as I have been preparing for both together. For those
who took it, how is it di�erent from OSCP? What skills do I need
before joining the CTP course and lab?
6 of 18 03/04/19, 5:25 am
OSCP Exam review "2019" + Notes & Gift insid... https://forum.hackthebox.eu/discussion/commen...
I also think I will take OSWE and OSEE after that, but we'll see about
that later.
[ ](https://www.hackthebox.eu/home/users
/pro�le/36215)
OSCP | CCNA | PMP
Oscp
Comments « 1 2 »
peek March 15
very good review, point 2 will help a lot. and thanks so much for
your tool.
Monty March 15
Exactly the review I needed as I'm considering taking the exam next
couple of months.
achayan March 15
@21y4d that's an amazing write up ... really useful for people like me
who prepare for such exams ... regarding the proctored part ....
"what about breaks in b/w ? " .. and could we see the person
watching us ? .. and were the machines were entirely new from
previous machines in exam ? .. again thanks for such a useful write
up
7 of 18 03/04/19, 5:25 am
OSCP Exam review "2019" + Notes & Gift insid... https://forum.hackthebox.eu/discussion/commen...
21y4d March 15
@achayan
Actually you forget about the proctor once you start focusing on the
exam. You cannot see the the proctor, as this would probably
distract students, and would give a feeling that someone is watching
you..
You can take short/long breaks whenever you need, you just need
inform the proctor before leaving and after returning, so that they
make sure they can still see your screen and webcam before you
start working again.
At the beginning of the exam you will need to show your ID and to
give a webcam tour of the room you're in, and you should be alone
in the room. Also, after a long break "several hours" you will have to
scan the room again, which take around 30 seconds.
[ ](https://www.hackthebox.eu/home/users
/pro�le/36215)
OSCP | CCNA | PMP
achayan March 15
ferreirasc March 15
8 of 18 03/04/19, 5:25 am
OSCP Exam review "2019" + Notes & Gift insid... https://forum.hackthebox.eu/discussion/commen...
I'll probably have some questions about the proctoring ... Could I ask
you?
21y4d March 15
I'll probably have some questions about the proctoring ... Could I
ask you?
[ ](https://www.hackthebox.eu/home/users
/pro�le/36215)
OSCP | CCNA | PMP
xd3m0n March 15
meh
Malone5923 March 15
Really good review @21y4d . I like the fact you wrote from a pro HTB
member perspective. Thank you for this. I will also appreciate a PM
of your pivoting notes as I am taking the exam next month and this
will be usefull to me.
9 of 18 03/04/19, 5:25 am
OSCP Exam review "2019" + Notes & Gift insid... https://forum.hackthebox.eu/discussion/commen...
Thanks a lot for this post, mate ! Really useful addition to the
reviews already out there, should help a ton
Would it be possible to have your notes on pivoting via PM, too ?
d1am0ndz March 16
B0rN2R00T March 16
B0rN2R00T
21y4d March 16
@Malone5923 @d1am0ndz
Check your PM
[ ](https://www.hackthebox.eu/home/users
/pro�le/36215)
OSCP | CCNA | PMP
10 of 18 03/04/19, 5:25 am
OSCP Exam review "2019" + Notes & Gift insid... https://forum.hackthebox.eu/discussion/commen...
YanTayga March 16
21y4d March 16
[ ](https://www.hackthebox.eu/home/users
/pro�le/36215)
OSCP | CCNA | PMP
sysDom March 16
This is a great review, thanks! I'm about to start the OSCP lab, so I'm
focusing on HTB until it starts. I'm really worried about the time
contrainsts, more so because of the awkwark kali vm they make you
use. It normally takes me a full night to get through just dirb; so
maybe nmapAutomator will help with timing. I'm going to test it out
on HTB and the OSCP labs, thanks so much for posting it.
11 of 18 03/04/19, 5:25 am
OSCP Exam review "2019" + Notes & Gift insid... https://forum.hackthebox.eu/discussion/commen...
21y4d March 17
[ ](https://www.hackthebox.eu/home/users
/pro�le/36215)
OSCP | CCNA | PMP
sthml�um March 17
MinatoTW March 17
Ahm3dH3sham March 17
Thanks for the review and the tool that's a great contribution.
Congrats !
https://0xrick.github.io
Chuspi1k March 19
Thanks a lot @21y4d for your review, I'm right now training to pass
the OSCP test and your information is amazing.
I hope that your tools and notes will be incredibles too.
12 of 18 03/04/19, 5:25 am
OSCP Exam review "2019" + Notes & Gift insid... https://forum.hackthebox.eu/discussion/commen...
ikuamike March 19
CGonzalo March 19
Congrats!!!
xformer1337 March 20
21y4d March 20
[ ](https://www.hackthebox.eu/home/users
13 of 18 03/04/19, 5:25 am
OSCP Exam review "2019" + Notes & Gift insid... https://forum.hackthebox.eu/discussion/commen...
/pro�le/36215)
OSCP | CCNA | PMP
Farbs March 22
bansheepk March 22
14 of 18 03/04/19, 5:25 am
OSCP Exam review "2019" + Notes & Gift insid... https://forum.hackthebox.eu/discussion/commen...
pingunrchable March 23
Should I:
21y4d March 23
@bansheepk said:
> Congratilations on passing it the �rst time!!! I passed in the OSCP
Exam on February 20th, but I failed multiples times, I started the
PWK course having a very poor hacking knowledgement, and started
learning everything during the course, and from there I met HTB.
HTB really helped me to keep practicing to the exam after I pwned
the whole o�sec labs (except the PI box) and however I think the
HTB machines intend to be more CTF-like boxes than o�sec, the HTB
boxes are much more di�cult in general. I want to go for OSCE too
as soon as I feel prepared, but I started reading "The Shellcoders
Handbook" as a preparation for OSCE, but I couldnt replicate most
of the things the book teaches, I could never develop a shellcode to
pop a calculator on windows, even after reading corelan guides,
because of that I am feeling uncon�dent.
15 of 18 03/04/19, 5:25 am
OSCP Exam review "2019" + Notes & Gift insid... https://forum.hackthebox.eu/discussion/commen...
I suggest you check Pentester Academy, they have some very useful
courses that can help you a lot in learning shellcoding from scratch.
[ ](https://www.hackthebox.eu/home/users
/pro�le/36215)
OSCP | CCNA | PMP
« 1 2 »
SIGN IN to comment.
Howdy, Stranger!
Click here to create an account.
SIGN IN
Categories
Recent Discussions
Activity
Categories
16 of 18 03/04/19, 5:25 am
OSCP Exam review "2019" + Notes & Gift insid... https://forum.hackthebox.eu/discussion/commen...
Support 238
Billing 23
Website 71
Discussion 1K
Machines 511
Challenges 252
RastaLabs 11
Exploits 41
Programming 7
O�-topic 205
Tutorials 403
Writeups 242
Video Tutorials 48
Tools 58
Other 53
Links 8
News 8
In this Discussion
pingunrchable March 24
bansheepk March 22
Farbs March 22
Draco123 March 22
xformer1337 March 20
CGonzalo March 19
ikuamike March 19
Chuspi1k March 19
Ahm3dH3sham March 17
MinatoTW March 17
17 of 18 03/04/19, 5:25 am
OSCP Exam review "2019" + Notes & Gift insid... https://forum.hackthebox.eu/discussion/commen...
sthml�um March 17
sysDom March 16
YanTayga March 16
B0rN2R00T March 16
d1am0ndz March 16
Patapinh0 March 16
Malone5923 March 15
xd3m0n March 15
ferreirasc March 15
21y4d March 23
18 of 18 03/04/19, 5:25 am