How to learn hacking
fsecurify.com
fsecurify.com
His subreddit:
https://reddit.com/r/liveoverflow
His YouTube channel:
https://www.youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w
I have taken more traditional infosec coursework for $DAYJOB. I must say this stuff, the more novice stuff beneath and the more advanced stuff above my head, is well structured, even if informal, entertaining, and inspiring. I definitely want to give back to the community like him with solid content and a very unassuming attitude. This is exactly the kind of teacher we need in this space!
(This is not to say F Security is assuming or crappy, I just wanted to talk up someone who really is teaching how to hack the way I think it ought to be done!)
I have also recently started building https://liveoverflow.com, which might have a better structure than a YouTube channel or subreddit.
Also some people may have actually seen a video of mine, because my most popular video so far is the DirtyCow video which got referenced by news sites and on the dirtycow github repository.
My personal recommendation is to checkout the AngularJS Sandbox bypass series: https://www.youtube.com/playlist?list=PLhixgUqwRTjwJTIkNopKu...
Criticism and feedback is always welcome.
More stuff with radare, please! Hopper seems cool, as does Binary Ninja, but I see us like scientists, and I don't like IDA and their ilk with their price tag. Not because I cannot afford it, but how do we as IT professionals not take reproducible research seriously!?
Also, keep up with your slick GDB fu. I watched you Boston Key Party vids last night and they are an education, let me tell you.
Your Angular stuff is my personal favorite, as I have not even done a sufficient amount of web hacking.
I happened to bring up your videos at a recent, very expensive infosec cert course and no one had heard of you. The instructor did take refs to the guy you cite for the Angular XSS bypasses, as he was European knew that guy, and I sent him your stuff too. Super happy to talk you up!
Also really confusing name considering there's the Finnish security company called F-Secure who also have a technical blog: https://labsblog.f-secure.com/
And now also run a security course in Helsinki University: http://mooc.fi/courses/2016/cybersecurity/
There is no business of this company. All I do is learn stuff, try to come up with good articles and post them. I plan to convert it into a proper company once my studies are over. I am just a student at the moment.
Hope everything is good now.
Best Regards.
Currently, name & logo look like something a company would use and are potientally easily confused with other companies using similar names; as mentioned in other comments.
Just to be clear, it is obvious you put a lot of work into this, thanks for sharing. Keep it up!
I recommend the all-time classic "How To Become A Hacker" by Eric S. Raymond:
I don't know Eric enough. I know he is right wing, but not sure if he is racist.
Suppose he is a racist, can't his text about being a hacker be great?
I read "How to become a hacker" in 2014. It is awesome and he does not say anything about woman and race on the text.
According to some historians, Da Vinci was a dushbag. Should we ignore his crafts just because, apparently, he was a bad person?
I don't think so.
> There is another group of people who loudly call themselves hackers, but aren't. These are people (mainly adolescent males) who get a kick out of breaking into computers and phreaking the phone system. Real hackers call these people ‘crackers’ and want nothing to do with them. Real hackers mostly think crackers are lazy, irresponsible, and not very bright, and object that being able to break security doesn't make you a hacker any more than being able to hotwire cars makes you an automotive engineer. Unfortunately, many journalists and writers have been fooled into using the word ‘hacker’ to describe crackers; this irritates real hackers no end.
Best Regards.
My job title is "Penetration tester" but I don't fall into that category. That's why I often refer to it as doing "application security analysis/audits". My current job is to do black/white box testing of single applications - and not a huge organisations where you just phish some employees. I have not worked for other companies, but as far as I can tell, many "penetration testing jobs" are actually what I do.
It's fun, challenging and very technical. And obviously no scanners are used - I have never in my career used nessus or any other click2exploit tool.
"This Account has been suspended. Contact your hosting provider for more information."
_________
Google's Cache: http://webcache.googleusercontent.com/search?q=cache:http://...
Best Regards.
http://webcache.googleusercontent.com/search?q=cache:http://...
It's a dead link
step 1: figure out how to run it
step 10: deface some useless site or get access to computer of your friend.
step 11: buy t-shirt with words "haxx00r" or "the matrix green failing letters".
step 13: profit