My OSCP journey was between March 2019 - April 2019. This makes reading the data easier. Specifically a lab walkthrough from the eLS PTP course. That is, without a user. Reconnaissance & enumeration - Securable - OSCP cheat sheet A Little Guide to SMB Enumeration - Hacking Articles Null sessions, In windows NT2000/XP default config for SMB allows for nullsessions to be created. PEN-200 Labs Learning Path - Offensive Security Support Portal I highly recommend to start with two weeks of fulltime preparation by, for instance . Sites: OSCP Exam Guide, PentestMonkey, Hash Cracking Sites, Privilege Escalation, Practical OSCP Tips/Tricks, Exploit-DB, Low Priv Enum Linux (g0tmi1k), Default Credentials (open-sez.me), RTFM . tactics: enumeration # enumerate services and use default scripts - `nmap -sC -sV. #rpcclient -U "" ///when asked enter empty password #rpcclient $>srvinfo #rpcclient $>enumdomusers #rpcclient $>querydominfo #rpcclient $>getdompwinfo //password policy #rpcclient $>netshareenum #nmblookup -A #rpcinfo -p <target> Enumerate using smbclinet: #smbclient -L // #DNS Tools. A Linux alternative to enum.exe for enumerating data from Windows and Samba hosts. Tunneling: sshuttle is an awesome tunneling tool that does all the hard work for you. The -a parameter specifies reverse name resolution to be performed on the destination IP address. Useful Commands and Tools - OSCP - Yeah Hub This was the cheatsheet and containing the methodologies that were compiled when I took my OSCP. enum4linux - Kali Linux tools - Core dump overflow - GitHub Pages CREATE AN SMB SERVER. Many ftp-servers allow anonymous users. From there, I . Another Lame HackTheBox Writeup It also includes the commands that I used on platforms such as Vulnhub and Hack the Box.

