Author Topic: OSCP  (Read 2945 times)

0 Members and 1 Guest are viewing this topic.

Offline lsquared

  • /dev/null
  • *
  • Posts: 15
  • Cookies: 0
    • View Profile
OSCP
« on: May 08, 2013, 07:00:05 am »
I have been contemplating the OSCP certification for quite some time. I am planning on enrolling within the next month or so. Has anyone taken the course and exam? Either way I am planning on leaving a review when I am done.


lsquared

Offline Stackprotector

  • Administrator
  • Titan
  • *
  • Posts: 2515
  • Cookies: 205
    • View Profile
Re: OSCP
« Reply #1 on: May 08, 2013, 09:49:30 am »
Quote
In order to enroll for the OSCP certification exam, you must first complete the Penetration Testing with BackTrack course.
That backtrack course is starting from 750 usd. I don't like them, they are to much focused on giving certifications to people in company's (because company's will pay that much money) for just a certification.
~Factionwars

Offline Mordred

  • Knight
  • **
  • Posts: 360
  • Cookies: 135
  • Nvllivs in Verba
    • View Profile
Re: OSCP
« Reply #2 on: May 08, 2013, 10:06:15 am »
I've been studying for the OSCP as I intend to take it after I graduate Uni, but before I go into the job market.

It's one of the cheaper certs out there (most of the other stuff is +1000$) and it covers quite a lot of ground in terms of introducing you to the world of penetration testing.

I have the course material in .pdf format if you're interested, versions 3.0 and 3.2. I also have the book that you need for the BT5 Wireless Pen-Testing course (if you're gonna do that one). If you need either of these, hit me up and I'll upload them.
\x57\x68\x79\x20\x64\x69\x64\x20\x79\x6f\x75\x20\x65\x76\x65\x6e\x20\x66\x75\x63\x6b\x69\x6e\x67\x20\x73\x70\x65\x6e\x64\x20\x74\x68\x65\x20\x74\x69\x6d\x65\x20\x74\x6f\x20\x64\x65\x63\x6f\x64\x65\x20\x74\x68\x69\x73\x20\x6e\x69\x67\x67\x72\x3f\x20\x44\x61\x66\x75\x71\x20\x69\x73\x20\x77\x72\x6f\x6e\x67\x20\x77\x69\x74\x68\x20\x79\x6f\x75\x2e

Z3R0

  • Guest
Re: OSCP
« Reply #3 on: May 08, 2013, 06:48:20 pm »
I have taken the course (haven't passed yet). It's difficult. Not impossible, not hard, just difficult. You're given X amount of days to go through the lab materials provided, try out attacks on a vpn network that OffSec gives you access to, you write a report on what you could break into. Finally, you are given the chance to take a hands-on exam for the actual cert where the goal is to break into 5 different machines of varying difficulty, and write a report on it.

Keep in mind, it is a pen-testing course. It is not a "break into as many computers as you can" course. You have to treat it like it's an actual pen-test, and write reports. Honestly, the most difficult part about it is not getting complacent with it, and just giving up.

Going off of what Factionwars said, yes it is a certification course. You take the course to hopefully pass the exam and get the certification like any other course. No one forces you to do it. And unlike fucking CEH, the lab materials are actually good, and have intellectual value. It's not just a course on how to use metasploit, or sqlmap (although both are mentioned, and shown examples of usage).

The actual vpn lab is no different than any other network with vulnerable stuff on it, other than the OffSec admins throw in a lot of "curve balls" if you will, and you actually have to use your brain to break into most of the machines. It's not just ./exploit <somecomputer>. You may have to do a client-side attack, or break into it with lesser privileges, and escalate, or use ssh tunnels to get into non-routable networks.

There isn't just attack techniques that you have to know in order to pass, you have to know a good amount of forensics too. The entire goal of the final exam is to grab "key files" to get points for breaking into said machines, but the files are well hidden, and not easy to find.

Having only gone through it, I certainly have more respect for anyone that has an OSCP cert than most other certs for this field.

Also, pro-tip for those who don't know...the more certs you have, the more likely you are to negotiate a good salary when you go in for an interview. That is UNIVERSAL for ALL career fields.