Mixed Deck — All OSCP Topics Flashcards
100 cards from real OSCP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 20 Mixed Deck — All OSCP Topics flashcards as text
What is a common technique to bypass file upload filters that block PHP extensions?
Answer: Use double extensions like shell.php.jpg
Using double extensions such as shell.php.jpg can bypass naive file extension checks if the server processes the PHP extension before the final jpg extension.
What technique allows an attacker to maintain a persistent rootkit-level backdoor without modifying disk-resident files on Linux?
Answer: Loading a malicious kernel module (LKM rootkit)
Loadable kernel modules (LKMs) run in kernel space and can hide processes, files, and network connections; they can be loaded without leaving obvious file-system artifacts.
What type of attack involves tricking a victim into sending authenticated requests to a vulnerable web application without their knowledge?
Answer: CSRF
Cross-Site Request Forgery (CSRF) forges authenticated requests from a victim's browser to perform unintended actions on a web application where they are logged in.
What are NTLMv2 challenge-response hashes and how are they typically cracked in OSCP?
Answer: They are captured during authentication challenges (via Responder) and cracked offline with hashcat using module 5600
NTLMv2 hashes are challenge-response authentication tokens captured from network traffic or via tools like Responder, and are cracked offline using hashcat module 5600 (NetNTLMv2).
Which PowerShell command checks whether the current user can modify a specific service's binary?
Answer: Get-Acl -Path 'C:\path\to\service.exe' | Format-List
Get-Acl retrieves the security descriptor (ACL) of a file, revealing which users have read, write, or modify permissions on the service binary.
What does the SLEEP() function in a SQL injection payload help an attacker determine?
Answer: Whether the injection point exists via time delay
SLEEP() is used in time-based blind SQLi to confirm a vulnerable injection point by causing a measurable delay in the server's response.
What Kali Linux command would you use to recursively search all files in /etc for the string 'password'?
Answer: grep -r 'password' /etc
grep -r recursively searches file contents for the specified string within the given directory, making it ideal for credential hunting during post-exploitation.
What does the Responder tool do and how is it used in OSCP for credential capture?
Answer: It poisons LLMNR/NBT-NS/mDNS broadcast queries to capture NTLMv2 hashes from network hosts
Responder responds to LLMNR, NBT-NS, and mDNS broadcast queries with poisoned responses, tricking Windows hosts into authenticating to the attacker's machine and capturing their NTLMv2 hashes.
Which directory you are in can be determined
Answer: pwd
The `pwd` command (short for 'print working directory') is used in Linux to display the full path of the current directory you are in. This command is fundamental for navigating the file system and understanding your current location within the directory hierarchy. It helps users orient themselves and ensures commands are executed in the intended location.
What Hydra command would brute-force SSH on host 10.10.10.10 using username 'admin' with the rockyou wordlist?
Answer: hydra -l admin -P /usr/share/wordlists/rockyou.txt 10.10.10.10 ssh
The correct syntax uses -l for a single username, -P for a password list file, followed by the target IP and service name.
Which command would reveal kernel version information useful for finding local privilege escalation CVEs?
Answer: uname -a
uname -a prints the kernel name, hostname, kernel release, version, machine hardware, and OS, providing the key version details needed to search for kernel exploits.
What does the 'accesschk.exe' tool from Sysinternals help identify during Windows privilege escalation?
Answer: Permissions on files, registry keys, services, and other objects
Accesschk.exe audits permissions on Windows objects (files, services, registry, kernel objects), making it essential for finding world-writable services, files, or registry keys.
Which register is typically inspected after a crash to find the EIP offset when using a Metasploit cyclic pattern?
Answer: EIP
EIP contains the 4-byte value from the cyclic pattern at crash time, which msf-pattern_offset uses to calculate the exact offset.
Which Linux capability, if assigned to a binary, allows it to bypass file permission checks and is dangerous from a security perspective?
Answer: cap_dac_override
cap_dac_override allows a process to bypass discretionary access control (DAC) file read/write/execute permission checks, enabling access to any file.
In Kali Linux, what is the primary use of the 'sslstrip' tool during a man-in-the-middle attack?
Answer: Downgrades HTTPS connections to HTTP to intercept credentials in cleartext
sslstrip intercepts HTTP redirects to HTTPS and serves the victim plain HTTP, allowing credentials to be captured in cleartext before forwarding to the real HTTPS server.
Which Kali Linux command generates a reverse shell payload as an ELF binary for a Linux target?
Answer: msfvenom -p linux/x86/shell_reverse_tcp LHOST= LPORT= -f elf
msfvenom with the linux/x86/shell_reverse_tcp payload and -f elf format generates a Linux ELF reverse shell binary.
What is the purpose of adding rules (like best64.rule) when cracking passwords with hashcat?
Answer: Rules apply transformations to wordlist words (capitalize, add numbers, leet speak) to create more password candidates
Hashcat rules apply mutations to each wordlist entry (e.g., capitalize, append digits, leet substitutions), dramatically expanding the candidate pool without requiring a larger wordlist.
Which vulnerability occurs when user-supplied input is reflected in a web page without proper sanitization and executes in a victim's browser?
Answer: Cross-Site Scripting (XSS)
XSS allows attackers to inject malicious scripts into web pages viewed by other users, potentially stealing cookies or performing actions on their behalf.
What is a 'pass-the-hash' (PtH) attack and when is it used in OSCP?
Answer: Authenticating to Windows services using an NTLM hash directly without cracking it
Pass-the-hash allows an attacker to authenticate to Windows services (SMB, WMI, RDP) using a captured NTLM hash directly, without needing to crack it to plaintext.
During post-exploitation on Linux, which directory often contains bash history files for multiple users that may reveal credentials or internal commands?
Answer: /home/*/.bash_history and /root/.bash_history
Bash history files in each user's home directory often capture previously entered commands including passwords typed as arguments and internal hostnames.