
OSCP Buffer Overflow Module in 2026: Is It Still Required and How to Prepare
Whether the OSCP still tests buffer overflow in 2026, what PEN-200 still teaches, and a 12-week preparation plan that fits the new exam format.
What is this page about?
An explanation of whether the OSCP still tests buffer overflow in 2026, answering no: Offensive Security removed the dedicated 25-point buffer-overflow machine in March 2023 and the change has held through every syllabus update since. It clarifies that buffer-overflow theory still appears in PEN-200 materials and implicitly in the Active Directory chain and bonus paths, covers what the current PEN-200 still teaches, whether to still learn the theory, a realistic 12-week prep plan for the current format, tooling that matters more, and common preparation mistakes.
What has been corrected on this page?
Every accepted correction to this page is recorded with the exact change, so readers can see how the page improved over time.
-
2 flagged issues verified: a quote attributed to Ning Wang (real former OffSec CEO) had no locatable source and was de-attributed; two named-individual anecdotes ('Felipe,' 'Ada') with precise point scores had no verifiable source and were generalized to illustrative patterns.
Before"We removed the dedicated buffer overflow because it had become a memorisation drill rather than an offensive thinking drill. The OSCP should test whether you can compromise a system you have never seen, not whether you can repeat a 12-step recipe." -- Ning Wang, former CEO, Offensive Security ...A penetration consultant, Felipe, took the exam under the legacy format in 2022 and failed at 60 points because his buffer overflow exploit produced a non-interactive shell that died after every command. He retook in late 2023 under the new format and passed at 80 points by getting the full Active Directory chain and two standalones, with the third standalone abandoned after six hours. A SOC analyst, Ada, failed her first attempt in 2024 with 60 points because she budgeted four hours for an Active Directory chain that took twelve. Her second attempt the following year scored 90 points because she had practised the full GOAD lab end to end and recognised the child-domain to forest-root escalation path within an hour.
AfterThe reasoning behind the change, as Offensive Security has described it publicly, is that the dedicated buffer overflow machine had become a memorisation drill rather than an offensive thinking drill. The stated goal of the OSCP is to test whether a candidate can compromise a system they have never seen, not whether they can repeat a fixed step-by-step recipe. ...A common pattern reported by candidates who sat the legacy exam is failing on a first attempt because a buffer overflow exploit produced a non-interactive shell that died after every command, then passing on a retake under the new format by focusing on the full Active Directory chain and completing two of the three standalone targets rather than chasing all three. Another recurring pattern involves candidates failing an early attempt because they under-budgeted time for the Active Directory chain, then passing on a later attempt after practising the full GOAD lab end to end and learning to recognise a child-domain to forest-root escalation path quickly.
Why: Removed an unverified quote incorrectly attributed to Ning Wang (former OffSec CEO) with no verifiable source, and generalized two unverified named-individual anecdotes (Felipe, Ada) with unverifiable precise point scores into illustrative prose patterns.
View the full record →
Who checked this page?
1 contributor has checked "OSCP Buffer Overflow Module in 2026: Is It Still Required and How to Prepare" on Pass4Sure. Each name below links to that person's public CitePep profile, where every contribution they have made is listed with the exact change they proposed.