Giter VIP home page Giter VIP logo

oscp's Introduction

Offensive Security Certified Professional (OSCP) Journey


It took me a little bit working in the cyber security to realize that Ec-council and CompTIA certifications are pointless in the grand scale of all cyber security certifications. And realized that the only certifications that are worth a damn are GIAC certifications and Offensive Securtity Certifications.

In MY OPINION, The only reason a person should work to achieve CompTIA or Ec-council is if they have aspirations of working for the federal government, been there, done that. The reason why I believe CompTIA and Ec-council are pointless certification provider... CompTIA and Ec-council practicals are a joke and their pricing is so low that anyone can sign up for multiple of them and cram and pass the exam (and then knowledge dump right afterwards), GIAC and Offensive Security pricing, is priced in a way that a person isn't going to waste the money unless they know for sure they are going to pass.


I've made this so it could be used as others for tracking their progress.

Certifications Roadmap for the Rest of my career

OSCP (2022) > GWAPT (2022) > OSCE (2022) > GXPN (2022) > GREM (2022) > OSEE (2023)


Taking OSCP in March 2022.

  • I will be using github project to track my process as I prepare for the OSCP.
  • There is a issue created for every subsection for all of the sections below.

Schedule

April

May

Hack The Box

Box Name Operating System Completed Date Completed Link To Writeup
Blue 2021-May-03 Coming soon
Lame 2021-May-03 Coming soon

June

Hack The Box

Box Name Operating System Completed Date Completed Link To Writeup
Doctor Linux
SneakyMailer Linux
Passage Linux
Luanne Linux
Time Linux
Active Windows
Remote Windows
Fuse Windows
Omni Windows
Worker Windows

July

Hack The Box

Box Name Operating System Completed Date Completed Link To Writeup
Jeeves Windows
Bart Windows
Tally Windows
Kotarak Linux
falafel Linux
Sauna Windows
Cascade Windows
Querier Windows
Quick Linux
BlackField Windows

August

Box Name Operating System Completed Date Completed Link To Writeup
brainfuck
shocker
bashed
nibbles
legacy
Blue
Devel
Optimum
Bastard

OSCP Exam - March 30, 2022


oscp's People

Contributors

austinsonger avatar

Stargazers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

Watchers

 avatar  avatar  avatar  avatar

oscp's Issues

Managing Processes

  • Backgrounding Processes (bg)
  • Jobs Control: jobs and fg
  • Process Control: ps and kill

Buffer Overflow Walkthrough

  • Sample Vulnerable Code
  • Introducing the Immunity Debugger
  • Navigating Code
  • Overflowing the Buffer
  • Exercises

Win Buffer Overflow Exploitation

  • A Word About DEP, ASLR, and CFG
  • Replicating the Crash
  • Controlling EIP
  • Locating Space for Our Shellcode
  • Checking for Bad Characters
  • Redirecting the Execution Flow
  • Finding a Return Address
  • Generating Shellcode with Metasploit
  • Getting a Shell
  • Improving the Exploit

Web Application Enumeration

  • Inspecting URLs
  • Inspecting Page Content
  • Viewing Response Headers
  • Inspecting Sitemaps
  • Locating Administration Consoles

Loops

  • For Loops
  • While Loops

Netcat

  • Connecting to a TCP/UDP Port
  • Listening on a TCP/UDP Port
  • Transferring Files with Netcat
  • Remote Administration with Netcat

PowerShell and Powercat

  • PowerShell File Transfers
  • PowerShell Reverse Shells
  • PowerShell Bind Shells
  • Powercat
  • Powercat File Transfers
  • Powercat Reverse Shells
  • Powercat Bind Shells
  • Powercat Stand-Alone Payloads

Fixing Web Exploits

  • Considerations and Overview
  • Selecting the Vulnerability
  • Changing Connectivity Information
  • Troubleshooting the “index out of range” Error

Fixing Memory Corruption Exploits

  • Overview and Considerations
  • Importing and Examining the Exploit
  • Cross-Compiling Exploit Code
  • Changing the Socket Information
  • Changing the Return Address
  • Changing the Payload
  • Changing the Overflow Buffer

Wireshark

  • Wireshark Basics
  • Launching Wireshark
  • Capture Filters
  • Display Filters
  • Following TCP Streams

DNS Enumeration

  • Interacting with a DNS Server
  • Automating Lookups
  • Forward Lookup Brute Force
  • Reverse Lookup Brute Force
  • DNS Zone Transfers
  • Relevant Tools in Kali Linux

Vulnerability Scanning with Nessus

  • Installing Nessus
  • Defining Targets
  • Configuring Scan Definitions
  • Unauthenticated Scanning With Nessus
  • Authenticated Scanning With Nessus
  • Scanning with Individual Nessus Plugins

Port Scanning

  • TCP / UDP Scanning
  • Port Scanning with Nmap
  • Masscan

SNMP Enumeration

  • The SNMP MIB Tree
  • Scanning for SNMP
  • Windows SNMP Enumeration Example

Piping and Redirection

  • Redirecting to a New File
  • Redirecting to an Existing File
  • Redirecting from a File
  • Redirecting STDERR
  • Piping

Know Your Target

  • Passive Client Information Gathering
  • Active Client Information Gathering

Transferring Files with Windows Hosts

  • Non-Interactive FTP Download
  • Windows Downloads Using Scripting Languages
  • Windows Downloads with exe2hex and PowerShell
  • Windows Uploads Using Windows Scripting Languages
  • Uploading Files with TFTP

TcpDump

  • Filtering Traffic
  • Advanced Header Filtering

Linux Buffer Overflows

  • About DEP, ASLR, and Canaries
  • Replicating the Crash
  • Controlling EIP
  • Locating Space for Our Shellcode
  • Checking for Bad Characters
  • Finding a Return Address
  • Getting a Shell

SOCAT

  • Netcat vs Socat
  • Socat File Transfers
  • Socat Reverse Shells
  • Socat Encrypted Bind Shells

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.