
But don’t worry if you know nothing about buffer overflows. Because, if you are good at exploiting buffer overflows, you are sure to get the maximum point machine in the practical exam. Usage of Metasploit in the exam is limited to only one machine, but still, you can practice it in labs to know about the tool in depth.īuffer overflow is a very important concept you should practice. Metasploit unleashed by Offensive Security: Vivek Ramachandran’s Metasploit Megaprimer Videos: Especially the Metasploit post-exploitation modules. Metasploit is a very powerful tool and it is necessary for all the pen testers to know how to use it. Sometimes research on simple concepts will give good ideas on enumeration, for e.g., How SSH works, How service runs on ports, How Sockets works etc. Check out various videos on YouTube on basic concepts such as port-scanning, web application testing, etc.An awesome simple tutorial by Vivek Ramachandran is preferable If you are not aware of programming languages, it is highly recommended to learn one.Pro-tip: If you have more time in your hands and want to Learn Linux in a fun way, you can try the wargames here Practice all the common commands, and refer the man page for each of these commands.

If you are new to Linux, refer the Linux command guide. If you are not a newbie in Pen testing and aware of buffer overflow exploitation, you can skip this section and start enrolling.įor the rest, you need to cover the following aspects: Basics We will divide the OSCP journey into 2 phases:

Those should be figured out by you on your own. Here I will not be explaining the technical concepts. I will also share some resources that I found useful during my preparation. In this blog, I will provide you with a strategy for OSCP preparation. Even I was once an amateur before starting on my OSCP journey. If you are a newbie in Penetration Testing and afraid of OSCP preparation, do not worry.
