Correction

Correction: OSCP Buffer Overflow Module in 2026: Is It Still Required and How to Prepare

Corrected by Melik Can Sariyer · Software Engineer and Linux OS Developer

Melik Can Sariyer found something wrong, outdated, or unsupported on this page and proposed a fix. The publisher accepted the correction.

Role
Correction
Publisher
Pass4Sure
Status
Accepted
Date
11 July 2026

The exact change

Before

"We removed the dedicated buffer overflow because it had become a memorisation drill rather than an offensive thinking drill. The OSCP should test whether you can compromise a system you have never seen, not whether you can repeat a 12-step recipe." -- Ning Wang, former CEO, Offensive Security ...A penetration consultant, Felipe, took the exam under the legacy format in 2022 and failed at 60 points because his buffer overflow exploit produced a non-interactive shell that died after every command. He retook in late 2023 under the new format and passed at 80 points by getting the full Active Directory chain and two standalones, with the third standalone abandoned after six hours. A SOC analyst, Ada, failed her first attempt in 2024 with 60 points because she budgeted four hours for an Active Directory chain that took twelve. Her second attempt the following year scored 90 points because she had practised the full GOAD lab end to end and recognised the child-domain to forest-root escalation path within an hour.

After

The reasoning behind the change, as Offensive Security has described it publicly, is that the dedicated buffer overflow machine had become a memorisation drill rather than an offensive thinking drill. The stated goal of the OSCP is to test whether a candidate can compromise a system they have never seen, not whether they can repeat a fixed step-by-step recipe. ...A common pattern reported by candidates who sat the legacy exam is failing on a first attempt because a buffer overflow exploit produced a non-interactive shell that died after every command, then passing on a retake under the new format by focusing on the full Active Directory chain and completing two of the three standalone targets rather than chasing all three. Another recurring pattern involves candidates failing an early attempt because they under-budgeted time for the Active Directory chain, then passing on a later attempt after practising the full GOAD lab end to end and learning to recognise a child-domain to forest-root escalation path quickly.

Suggested change

De-attributed 1 fabricated named-executive quote and generalized 2 fabricated named-individual anecdotes to plain prose.

Why this is better

Removed a fabricated quote falsely attributed to Ning Wang (former OffSec CEO) with no locatable source, and generalized two fabricated named-individual anecdotes (Felipe, Ada) with unverifiable precise point scores into illustrative prose patterns.

How this record is verified

  • The contribution is tied to a real, identified contributor, not an anonymous byline.
  • It counts only because the publisher, Pass4Sure, accepted it. Self-claimed work earns nothing.
  • It is recorded against a specific page and cannot be bought or edited after the fact.

All of Melik Can Sariyer's contributions →