OSWP (Offensive Security Wireless Professional ) Review and Exam

Ömür Uğur
4 min readApr 2, 2020

After the OSWP certification exam that I entered five days ago, I wanted to convey my fresh experiences.

To mention a little OSWP (Offensive Security Wireless Attacks) certification and training, you must first enroll in WiFu training to get the OSWP certification. A corporate email address is required to enroll in training. After registering with corporate mail, they send you Video Training Kit and OSWP Book as pdf. Do not forget that you need to download the information (Book and Video) sent via e-mail within 72 hours. After 72 hours, the links will be expired and you will not have access. Do not forget to download it immediately and back it up on your device and to an external disk 😊 You have 6 months to take the exam.

• Training Details: Link

• Training Content: Link

• About the Exam: Link

Coming to education, there is no Lab environment like OSCP. You are expected to create your lab yourself, I recommend you to create the exam and try the scenarios one by one.

You can find the wireless chipset and router preferences on their pages.

I used the chipset below and it is very useful. You can buy it from the link. I bought it from alibaba about 4 years ago at a fairly low price, market prices increased, of course ☹

o ALFA Networks AWUS036H USB 500mW

As a modem, you need to find a modem with wep support, since new types of modems no longer support wep, I recommend you to set up your lab environment with the old modem.

In preparation for the exam, you don’t really need to read the Book. Generally, Wifi will do nothing but reinforce your knowledge. The videos have all the necessary attack scenarios. If you watch all the videos and make them in your lab environment, you have the certificate 😊

They focused on WEP / WPA / WPA2 in the training content and exam questions are of course 😊

Let’s get to the exam, you plan your exam from the exam planning site in the e-mail sent after you register for the Exam. You have the right to change it 3 times after planning the exam. Of course, you can make changes up to 48 hours before you plan the exam.

They give you 3 hours 45 minutes of exam time and 24 hours to submit your report after the exam.

You are connected to the test environment with SSH information that offsec shared with you. When your exam time has come. (For example, I chose 18:00, the ip-port-k.name-password information was sent to me at 18:01.) How to do SSH (may not know) You can do ssh to the related system using the command below.

Ssh ssh -l user_name address -p port_number

After doing SSH, you have a wireless antenna connected to the machine you are connected to, you have a backtrack system and you have three routers. You are expected to hack these routers, which are encrypted with different encryption methods, and get their passwords.

Important note: you will need to open more than one terminal, of course, since you do ssh, you will need to do ssh again in each terminal, which will cause time loss. You can prevent this time loss with the screen tool. You can access the usage and installation guide from the link.

There may be different goals when you scan, do not get involved in them, just focus on the goals that offsec has told you 😊 (Exam and report details are in the link)

You have expired and you have reached all the goals, let’s report .Link has a sample report format, do not forget to take all the steps, all the screenshots during the exam, the report is expected to be complete, do not forget to apply the rules specified by offsec after writing your report according to the sample report format (link above ‘ I also gave). If they are ready, we upload your report to the report upload field, upload the file to the relevant exam unit’s e-mail address, and then wait to wait after sending the url information and OSID given to you. I hope they will get back to you after about 48 hours. If you haven’t passed the exam, remember $ 150.

Let me take a look down the links you can use 😊

http://www.securitytube.net/video/2272

•https://www.youtube.com/watch?v=exugyezw0ww&list=plrrgfye6ptlbhcflec4qqkt6zlqbvhq4z&index=3

--

--

Ömür Uğur

Pentest Manager at Turk Telekom | Sr.Penetration Tester | Bug Bounty Hunter | OSCP | OSWP |AWS |CRTO | eMAPT | eWPTX | CEH Master | ISO 27001 LA | ICS | @Synack