Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 48 guests and 2 members online
You are here:
EH-Net
May 22, 2013, 02:56:13 AM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Ethical Hacking Discussions and Related Certifications
>
Network Pen Testing
>
OSCP - Offensive Security Certified Professional
(Moderator:
don
) >
Failed my first attempt at the OSCP exam
Pages:
1
[
2
]
3
4
...
7
Go Down
« previous
next »
Print
Author
Topic: Failed my first attempt at the OSCP exam (Read 11549 times)
0 Members and 1 Guest are viewing this topic.
impelse
Hero Member
Offline
Posts: 565
Re: Failed my first attempt at the OSCP exam
«
Reply #15 on:
March 05, 2013, 03:11:24 PM »
Sorry about that, probably you will need to staudy everything and try different ways to attack the machines in the lab
Logged
CCNA, Security+, 70-290, 70-291
CCNA Security
Taking Hackingdojo training
Website:
http://blog.thehost1.com/
r0ckm4n
Jr. Member
Offline
Posts: 74
Re: Failed my first attempt at the OSCP exam
«
Reply #16 on:
March 05, 2013, 05:02:26 PM »
Quote from: hayabusa on March 05, 2013, 10:41:09 AM
Sorry to hear it, r0ckm4n. I know it gets old when folks tell me this, but I'll pass it along anyway...
Don't get discouraged. As I'm sure you did last time, take it, learn from it, and keep growing. If it does NOTHING else, it'll teach you that, no matter how much you know, there's always things to be learned.
It's both a blessing and a curse, in the IT security realm. For those who LOVE change, there's ALWAYS change / updates / new ideas, methods and technologies. For those who don't... well...
Either way, I'm confident you'll continue to grow, and you will succeed, when you're ready.
Thanks for the encouragement, hayabusa.
If it were easy it wouldn't be that big of a deal. It just makes me want it that much more and I will appreciate it even more when I do pass the exam.
Logged
CISSP, IAM, working on OSCP
r0ckm4n
Jr. Member
Offline
Posts: 74
Re: Failed my first attempt at the OSCP exam
«
Reply #17 on:
March 05, 2013, 05:06:13 PM »
Quote from: impelse on March 05, 2013, 03:11:24 PM
Sorry about that, probably you will need to staudy everything and try different ways to attack the machines in the lab
Thanks for your support and advice, impelse.
Logged
CISSP, IAM, working on OSCP
hayabusa
Hero Member
Offline
Posts: 1632
Re: Failed my first attempt at the OSCP exam
«
Reply #18 on:
March 05, 2013, 08:17:37 PM »
Quote from: r0ckm4n on March 05, 2013, 05:02:26 PM
If it were easy it wouldn't be that big of a deal. It just makes me want it that much more and I will appreciate it even more when I do pass the exam.
That's the spirit! Stick with it, and you'll get it. Great attitude!
Logged
~ hayabusa ~
"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'
OSCE, OSCP , GPEN, C|EH
azmatt
Jr. Member
Offline
Posts: 78
Re: Failed my first attempt at the OSCP exam
«
Reply #19 on:
March 05, 2013, 11:28:58 PM »
Very well said by each of you.
Keep up the great attitude and effort. It's a matter of when not if.
Logged
GCFA, GCIH, GSEC, GCFE, CHFI
r0ckm4n
Jr. Member
Offline
Posts: 74
Re: Failed my first attempt at the OSCP exam
«
Reply #20 on:
March 06, 2013, 09:23:08 AM »
Quote from: hayabusa on March 05, 2013, 08:17:37 PM
Quote from: r0ckm4n on March 05, 2013, 05:02:26 PM
If it were easy it wouldn't be that big of a deal. It just makes me want it that much more and I will appreciate it even more when I do pass the exam.
That's the spirit! Stick with it, and you'll get it. Great attitude!
Thanks!
Logged
CISSP, IAM, working on OSCP
r0ckm4n
Jr. Member
Offline
Posts: 74
Re: Failed my first attempt at the OSCP exam
«
Reply #21 on:
March 06, 2013, 09:23:52 AM »
Quote from: azmatt on March 05, 2013, 11:28:58 PM
Keep up the great attitude and effort. It's a matter of when not if.
Thanks!
Logged
CISSP, IAM, working on OSCP
r0ckm4n
Jr. Member
Offline
Posts: 74
Re: Failed my first attempt at the OSCP exam
«
Reply #22 on:
March 06, 2013, 09:31:27 AM »
I have been on the bench since the end of December and I have a pentest next week and it will last three weeks. My over abundance of study time will be reduced, but I look forward to using what I have learned in the upcoming pentest. PWB has been very educational and I have improved a lot since I started my job as a pentester last April.
Logged
CISSP, IAM, working on OSCP
superkojiman
Jr. Member
Offline
Posts: 60
Re: Failed my first attempt at the OSCP exam
«
Reply #23 on:
March 06, 2013, 10:23:29 AM »
Quote from: r0ckm4n on March 06, 2013, 09:31:27 AM
I have been on the bench since the end of December and I have a pentest next week and it will last three weeks. My over abundance of study time will be reduced, but I look forward to using what I have learned in the upcoming pentest. PWB has been very educational and I have improved a lot since I started my job as a pentester last April.
Hey as long as you keep learning, it's not a total loss
I assume you'll be tackling the exam again?
Logged
OSCP, GSEC
r0ckm4n
Jr. Member
Offline
Posts: 74
Re: Failed my first attempt at the OSCP exam
«
Reply #24 on:
March 06, 2013, 01:35:38 PM »
Quote from: superkojiman on March 06, 2013, 10:23:29 AM
Hey as long as you keep learning, it's not a total loss
I assume you'll be tackling the exam again?
Yes, I will be taking the exam again. I won't give up until I have that certification. I extended my lab time by two weeks, which also gives me another exam attempt. I only studied an additional two weeks after failing the first time before I retested. I figure I will take it again in a month if I feel like I am ready.
Logged
CISSP, IAM, working on OSCP
H1t M0nk3y
Hero Member
Offline
Posts: 864
Re: Failed my first attempt at the OSCP exam
«
Reply #25 on:
March 06, 2013, 02:24:50 PM »
r0ckm4n, you sound like me when I failed my second attempt!
I then waited a full month and tried again (3rd time), only to stop after 8 hours, totally discouraged...
So I decided to put OSCP on a shelve for a while. I did GPEN, CISSP and GWAPT and above all, studied quite a lot. I always had this exam in the back of my mind, always thinking about it.
2 full years after that, I felt ready and passed it with confidence. I really was a different person and it really, really felt good when I finally passed the 70 points mark!!!
So if you are failing now, it's because you had the guts to take on a great challenge. I am sure you have learn quite a lot just going through these attempts. This certification is much harder than most other ones and like you mentioned, that's why it is so good.
Don't dispair! Take a break and come back when you feel you're ready.
If I did it, you can do it too!
Logged
OSCP, GPEN, GWAPT, GSEC, CEH, CISSP
m0wgli
Full Member
Offline
Posts: 248
Re: Failed my first attempt at the OSCP exam
«
Reply #26 on:
March 06, 2013, 02:33:47 PM »
It's great that you still have the determination to continue.
You already pretty much said it yourself, "Nothing Worth Having Comes Easy".
I started the PWB course recently, so can appreciate the difficulty. I would be interested to know, where you felt you went wrong on this attempt.
Did you do all the extra mile excercises? And, how many of the machines in the lab did you manage to compromise before attempting the exam?
Logged
Security + | OSWP | eCPPT | CSTA
r0ckm4n
Jr. Member
Offline
Posts: 74
Re: Failed my first attempt at the OSCP exam
«
Reply #27 on:
March 06, 2013, 02:51:42 PM »
Quote from: H1t M0nk3y on March 06, 2013, 02:24:50 PM
r0ckm4n, you sound like me when I failed my second attempt!
I then waited a full month and tried again (3rd time), only to stop after 8 hours, totally discouraged...
So I decided to put OSCP on a shelve for a while. I did GPEN, CISSP and GWAPT and above all, studied quite a lot. I always had this exam in the back of my mind, always thinking about it.
2 full years after that, I felt ready and passed it with confidence. I really was a different person and it really, really felt good when I finally passed the 70 points mark!!!
So if you are failing now, it's because you had the guts to take on a great challenge. I am sure you have learn quite a lot just going through these attempts. This certification is much harder than most other ones and like you mentioned, that's why it is so good.
Don't dispair! Take a break and come back when you feel you're ready.
If I did it, you can do it too!
Thanks for the support, H1t M0nk3y! You're a good inspiration for those of us that have failed the exam.
Logged
CISSP, IAM, working on OSCP
r0ckm4n
Jr. Member
Offline
Posts: 74
Re: Failed my first attempt at the OSCP exam
«
Reply #28 on:
March 06, 2013, 03:23:39 PM »
Quote from: m0wgli on March 06, 2013, 02:33:47 PM
It's great that you still have the determination to continue.
You already pretty much said it yourself, "Nothing Worth Having Comes Easy".
I started the PWB course recently, so can appreciate the difficulty. I would be interested to know, where you felt you went wrong on this attempt.
Did you do all the extra mile excercises? And, how many of the machines in the lab did you manage to compromise before attempting the exam?
Thanks for the encouragement!
I didn't do all the extra mile exercises, although I spent most of my time on the areas I was having problems with. For me that was buffer overflows. I didn't spend my time wisely from the start. I started PWB last April. I wasn't studying enough for a long period of time and didn't study at all when I was doing pentests. If I would have done a better job studying from the start, I would be better off. January and February have been great months for me study wise.
I didn't compromise all of the lab machines and only did about half. I would recommend hacking them all. I think that is the best gauge of whether you are ready for the challenge. Yesterday to I 15 of the 16 servers I had previously hacked in the lab for practice. I was hoping this would help me remember some things and think about how I compromised them. At first I spent a lot of time using Metasploit and that would bad from a PWB point of view, but good for my job as a pentester. I am better with Metasploit, which is a tool I use on pentests.
As far as this attempt goes and to state the obvious, I wasn't ready. I knew that I would start getting pentests, so my work load would pick up and I wouldn't have as much time to study. I wanted to pass the exam before work started picking up. I start a pentest next week and I will make sure to study in my free time. I need to get better with buffer overflows and modifying exploits. Due to lack of experience, coding is a weakness for me and this is an area I am emphasizing.
I would recommend doing all of the extra miles and hacking every machine in the lab. Like others have said, when you can hack everything in the lab you are ready for the challenge. Go over the study material more than once and focus on your weaknesses.
One of my problems is being impatient and wanting to get things done quickly, but I need to focus more on learning. I am trying to improve my study quality and not focus as much on study quantity.
Logged
CISSP, IAM, working on OSCP
H1t M0nk3y
Hero Member
Offline
Posts: 864
Re: Failed my first attempt at the OSCP exam
«
Reply #29 on:
March 07, 2013, 06:57:19 AM »
Quote
I would recommend doing all of the extra miles and hacking every machine in the lab.
This is obviously a good advice, but hacking all the machines in the lab could be quite time consuming. For me, in my early attempts, I had hack something like 12-18 servers. I still managed to get 60 points in the exam, but still, this didn't make me pass. The thing I later realize is that these servers were not picked up randomly. I was taking the approach "today, I will go after an FTP server" or "today, I am going after a web application". So I wasn't approaching a given host and try to break it, I was looking more at services...
In addition, all the exercises in the videos can be reproduce in the lab. So it's like if we are starting at 10 servers...
But on my last attempt, I felt I was ready because I targeted xxx.yyy.xxx.201, then xxx.yyy.xxx.202, then xxx.yyy.xxx.203, etc... I think I did 9 of the first 10 machines I targeted. At this point, I knew that I would eventually hack any machine I set my mind on. I then started picking up servers with very different configurations: Linux with a web server, FreeBSD with a mail server and things like that. After pwning all the machines I was targeting, I knew I was ready.
So yes, if you can, go after all machines in the lab. But if you don't have the time, you can be wise about it...
Logged
OSCP, GPEN, GWAPT, GSEC, CEH, CISSP
Pages:
1
[
2
]
3
4
...
7
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
Network Pen Testing
: AIX Vulnerability Assessments
(2) by
ras76
Tutorials
: Need guidance
(9) by
hanyhasan
Programming
: Finished Python Course in Codecademy now what?
(15) by
hanyhasan
Network Pen Testing
: Ruby on Rails Vulnerabilities / Attacks in BackTrack 5 r3
(0) by
SUdoctstudent
Network Pen Testing
: De-ICE 1.140 released!
(2) by
superkojiman
General Certification
: CPT Practical Submission
(1) by
UNIX
OSCP - Offensive Security Certified Professional
: Failed my first attempt at the OSCP exam
(94) by
azmatt
Tools
: Social-Engineer Toolkit (SET) Version 5.0 “The Wild West” Released
(2) by
m0wgli
Malware
: EICAR?
(3) by
UKSecurityGuy
Advisories
: HTB23154: Multiple Vulnerabilities in Exponent CMS
(0) by
AndyP
Advisories
: HTB23153: Multiple Vulnerabilities in Jojo CMS
(0) by
AndyP
Advisories
: HTB23151: Cross-Site Request Forgery (CSRF) in UMI.CMS
(0) by
AndyP
OSCP - Offensive Security Certified Professional
: Class Scheduled 6/8 - Linux n00b
(7) by
Taemyks
OSCP - Offensive Security Certified Professional
: OSCP exam scheduled
(6) by
gbhat
Incident Response
: LinkedIn Forensics
(0) by
AFENTIS_Forensics
General Certification
: Red Team/Blue Team
(1) by
ajohnson
Career Central
: Starter cert?
(3) by
Grendel
Network Pen Testing
: Beginner Ethical Hacker
(1) by
m0wgli
Web Applications
: Nessus and Nikto
(4) by
Seen
Network Pen Testing
: Cracking salted MD5 hash
(4) by
n37sh@rk
CEH - Certified Ethical Hacker
: Passed my C|EH
(3) by
n37sh@rk
Mass Media
: EC-council hacked, irony at his best?
(0) by
j0rDy
Web Applications
: SQL Injection into an INSERT statement.
(6) by
eyenit0
Network Pen Testing
: Solution for sipXtapi INVITE Message CSeq Field Header Remote Overflow
(1) by
m0wgli
Web Applications
: dns
(2) by
H1t M0nk3y
Other
: BSides Boston
(0) by
3xban
Career Central
: InfoSec in Central, FL
(2) by
tturner
Web Applications
: Web vulnerability scanner
(4) by
H1t M0nk3y
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.