
In March 2017, I started an Ethical Hacking course at CertyAcademy. I saw this course as a way to understand how hackers operate so I could build more effective defense strategies. That's where I got the chance to learn about Metasploit and, for the first time, use an exploit to hack a Windows 7 machine vulnerable to MS17-010. After that and learning hacking techniques in the course, I realized how much I didn't know about security, and my curiosity to understand more about offensive security was born.
I started looking into the CEH certification, and while searching I came across OSCP. All the reviews pointed out that it was harder than CEH and offered the chance to not only learn theory but also practice. Since I'm someone who loves challenges, I didn't think twice and started preparing.
What is OSCP?
Offensive Security Certified Professional (OSCP) is an online certification where you can learn and practice general pentesting concepts. What makes this certification more interesting and difficult is that to pass, you have to hack 5 computers — or enough to reach at least 70 points — within a 24-hour period. Then you get another 24 hours to submit a report detailing how you hacked those machines, which gives you the feeling of doing a real pentest. If you want to learn more about the certification, click here.
The OSCP was the opportunity to experience what it feels like to do a penetration test on a company, learn concepts while searching for a way in, discover new tools, hear impressive pentesting stories, and above all gain deep technical knowledge of how to do it.
Background
By 2017, before starting the certification, I had 8 years of experience in technical support, Systems Administration, Network Administration, and Infrastructure & Communications Management. I had the opportunity to see the full lifecycle of a company and understand how an IT department operates internally.
This allowed me to learn about networks, firewalls, Windows, and security in general. I learned programming in university (C#) and Python as a hobby, using those languages for administrative tasks when I needed to automate processes. My Linux skills were at about 0.5 because I had to manage an Asterisk solution, but I did it through the GUI, so my Linux knowledge was practically zero.
Preparation
When I decided to pursue the OSCP, I started looking for information about the certification to prepare. Among the many things I read and reviewed, I did the following:
- I read the book "Penetration Testing: A Hands-on Introduction to Hacking" by Georgia Weidman, available on Amazon.
This book is fabulous. For someone like me who was getting into pentesting, it was a huge help. It's well-structured and covers much of the pentesting lifecycle. It also includes instructions for building a lab and testing concepts as they're discussed in the lessons, which lets you learn theory and practice at the same time. Some parts of the book I didn't learn as well, like Buffer Overflow or Mobile and Wireless Hacking — at the time I didn't dedicate time to those areas because I felt too much of a beginner, and for Wireless I didn't have the necessary tools.
- I started practicing with CTFs and found HackTheBox.
HackTheBox is the best thing I could have found on this entire journey. It's an incredible platform that lets you hack different machines, created by different people, on Windows and Linux, and in the process learn different hacking techniques like: Web Hacking, Service Enumeration, SQL Injection, XSS, exploitation of public vulnerabilities — everything really, including cryptography, Buffer Overflow, privilege escalation, truly everything.
When I started on the platform, a friend told me: "I suggest you start hacking and whenever you come across something you don't know, just research and learn." And that's exactly what I did.
I suggest doing all the retired machines and watching ippsec's videos or some from my YouTube channel — they'll be incredibly helpful for the OSCP.
Other platforms I used were Vulnhub, PentestIT RU, PentesterLab — these are useful too.
- Getting to know many InfoSec professionals. HackTheBox helped with this through their Slack channel, now moving to Mattermost. You can join here.
I think this was the best thing that happened to me during my OSCP preparation. I had the opportunity to meet many InfoSec professionals, pentesters, and engineers with years of experience who selflessly invested time in teaching me certain things. That's how I realized the InfoSec community is a collaborative community, one I'm proud to be part of — people willing to answer even those dumb script kiddie questions, which is what I was at the time.
Thank you to everyone who helped me, answered a question, wrote a post, tweeted, or made a video tutorial. Thank you to the entire InfoSec community! You're awesome!
- Practicing the OSCP Syllabus
I reviewed the OSCP syllabus and all the topics, focusing on those I had never studied. One important thing is learning to find and run exploits, SQL Injection, etc., without using automated tools like sqlmap or Metasploit.
Buffer Overflow – I learned BoF by first watching videos to understand the concept of why it works and how I could leverage that vulnerability to compromise a system. Then I followed about 100 tutorials on how to do it, practiced with some public code. This took me a long time, because it's not something you learn overnight if you've never heard of BoF. But with time and dedication, I was able to learn and even do more advanced BoF. It's not that hard after all. Here's a great example from Jesse Kurrus doing BoF on SLMail.
Starting OSCP – The Lab
I started the OSCP on November 18, 2017, with 60 days of lab time. I spent the first week working through the manual and watching the videos. While working through the manual, I took the opportunity to document all the exercises (since I could earn 5 points by completing all exercises and submitting a report on 10 lab machines — more info here).
I started with machines where I found SMB vulnerabilities, which are usually easy to exploit, and then went through all the other public network machines in order. I had to skip some since they depended on others.
The lab was a real challenge. I worked mainly on the public network and compromised two or three machines from the other networks — I didn't do much pivoting during the lab. If I remember correctly, my total was about 43 machines. The interesting part is that I also spent time looking for different entry methods for many of the machines; on some I found up to 3 ways in.
The Exam
The part everyone dreads — the OSCP exam. 24 hours to compromise 5 computers is quite the challenge! This is where you have to prove you can actually hack an unknown environment in a short time.
The first thing I did was analyze myself, identify my weak points, and practice. I focused on Windows privilege escalation, and 3 days before the exam I practiced BoF using some public applications from a friend's GitHub repo, ihack4falafel.
I scheduled the exam a month in advance for Sunday, January 14, 2018, at 8AM. It's important to schedule the exam well ahead of time, since the date you want might not be available if you don't plan in advance.
I didn't study or touch the PC the day before the exam — I tried to relax. The exam was scheduled for 8AM, but that day I woke up at 3, 4, 5AM because I was so anxious. At 8AM the OSCP email arrived with the instructions and rules. I glanced over the information briefly, since I had already read the rules on their website in advance. I received the VPN access, the link to reset machines, and the target information and points for each machine.
1st PC – I started with the BoF one. For me it should have been the easiest part — once you learn basic BoF, it's just following each step. By 9:12AM I had compromised the machine and earned the first 25 pts 🙂
2nd PC – I started the enumeration process and by 9:40AM I had compromised the 2nd PC for another 10 pts.
3rd PC – I got user access by 10AM and needed another 40 minutes for privilege escalation. By 10:40AM I had another 20 pts.
Before starting the 4th PC, I thought I had the exam in the bag — in just 3 hours I had 3 machines. Hacking the other 2 shouldn't take long. But that's where a different story began.
4th PC – I started searching for information, enumerating, discovered some things, but couldn't get anywhere. At 4:00PM I decided to move on to the 5th PC.
5th PC – It took me approximately an hour and 45 minutes to find user access. By 5:45PM I had user access, giving me another 10 or 15 points. I wasn't sure of the exact amount since this machine was worth 25 points and we don't know how they distribute the score. I kept looking for ways to escalate privileges, but couldn't.
I slept from 12:20 to 2:20AM — about two hours — but couldn't get anything more. I tried going back to the 4th but still nothing. In the end, I used the last hour to review my notes and make sure I had everything I needed for the report, since that was the only thing that could help me pass at that point.
The Report
Thanks to documenting everything while working through the exercises and machines, writing the report wasn't too difficult. By the day before the exam, I had a pre-report ready that only needed some modifications, and that's what I did. At about 2PM I submitted my report with the exercises, the 10 lab machines, and the 5 exam PCs — even though I didn't fully complete 2 of the 5, I included relevant information about vulnerabilities I found.
Failing on two of the exam machines only made me realize how much I still have to learn. Although I've learned a lot in the last 8 months, in the world of pentesting I still have a long road ahead.
Exam Results!
Two days later, at 5PM I received the most satisfying email of my life — OSCP informing me that I had successfully passed the exam and was now OSCP certified!! This was my reaction on Twitter:
Acknowledgments
To my God who has allowed me to believe in myself, has given me wisdom, and has shown me that with effort and dedication everything is possible. To my beloved wife Mi Linda, who was there beside me throughout the entire process and during the exam, giving me all her support and listening to my hacker stories even without understanding what I was saying — thank you, Linda. To HackTheBox and ippsec who were an essential part of this journey, and to all my friends who in one way or another gave me advice, a hint, or guidance on how to learn certain things. And to my friends who, even without understanding what I was doing, congratulated me and showed interest in this challenging path I'm walking — to all of you, thank you!
Tips
- Enumerate. Learn how to enumerate different services — this will be the key to success.
- Take notes on everything.
- Don't think the exam will be the hardest thing in the world. Keep things simple and test.
- Look for multiple ways to compromise machines during the lab.
- Use Metasploit — it's a tool you need to learn — but try to find ways to run exploits without it.
- Believe in yourselves. Saying it's difficult won't help you pass. You have to believe in yourself and dedicate time to preparation. We don't all have the same background or the same learning capacity. Don't feel bad if you pass on the 3rd attempt — just keep trying!
- God bless you all! Happy Hacking!
