Want to start hacking?
about.gitlab.com
about.gitlab.com
At some points, it is just getting to the answer no matter the method (algorithm, memory, quick trick etc.) At the end of the day, it's still just problem solving and learning existing tools better.
I set up a Kali VM to do all my HTB stuff from and keep a notebook of my typical flow so the process is pretty simular for each box I attack. The easy boxes usually require you to somehow identify a waekness and use a ready made exploit for it (or some easily reproducable steps). Privesc is usually also pretty straightforward. However they are not supereasy by any means if you've never done this.
> I know for stuff like this the key is to just get started, and the understanding will follow, but I'm curious if anyone has any recommendations for how to do that.
The single tip I give anyone getting started is:
Follow all the rabbit holes.
Seriously, all of them. Any time you have some random question come up, "Would doing X be vulnerable", "Could I exploit Y feature", "Why didn't this writeup author do Z", "How does A work", "Why send B this way instead of this way" ... all of them. When you have the question, just go spend the time to figure it out. Every rabbit hole you go down, even if it ends up being a dead end, is adding bits and pieces to your knowledge. Over time you build up an immense library of random bits of knowledge that you can draw from in the future.
I have a blog post about getting started with manual vulnerability auditing: https://dayzerosec.com/blog/2021/05/21/from-ctfs-to-real-vul...
While I wrote that with an eye towards doing binary-level exploit development against modern targets, the advice for doing manual auditing is pretty universal. It's like how to learn to program you actually have to write code, reading about writing code isn't enough. Practice against anything can be useful.
I'll also leave you my favorite vuln research quote:
"Frustration is a key part of exploit research and you must embrace it accordingly"
One of my big regrets is spending too much time in chatrooms and forums in my 20s instead of practicing. Now I have less capacity to do that because I do this stuff (and love it) as part of my job, I need a break afterwards.
In CTFs either I get distracted or I follow red herrings because of curiosity and waste time.
One thing that helped me before and I am recently considering is getting rid of TV/netflix/prime and social media (maybe exempt HN? Lol) to help with time.
I’m also going to plug my favorite resource: Pentesterlab. I get nothing from this, I just think it’s a great product. It’s been my most used resource since I decided I wanted to be a pentester. I think I’ve seen Louis post here before, so if you read this, thanks for making a great site.
Side note I was watching briefly some John Hammond videos and the way they obfuscate/package say powershell command in a word doc image is pretty insane. I've heard of some other wilder ones like the Apple gif overflow attack.
It allowed to jailbreak with nothing more than a pdf with a corrupted font.
https://www.intego.com/mac-security-blog/ios-vulnerability-a...
On the application I said my skills were a bit rusty because I hadn't done pro pentesting in about a decade, and the platform ignored it and wouldn't respond to followups. The institution has moved on to other priorities and the window to drive that change passed, but if there are any upstart platforms interested, a specialized version for regional public sector services that yields the outcomes above is still an opportunity. If the incumbent platform is starting to act like the incumbent, this may even be the bigger opportunity.
DALL-E will be an incredible tool against DMCA-scraper bots that just run rampant scanning for images that have a copyright and submitting to the registrar.
DALL-E finally shuts this loophole down, for now at least it seems.
EDIT: and it seems like the real keyboard was found! The mere fact that we are having trouble distinguishing a real or fake keyboard leads me to think of greater problems that will lie ahead; authorities or figures claiming they did or did not do/say certain things. The world of artificial intelligence is going to be an exciting time, that’s for sure. :)
That being said right now security is becoming a very lucrative field and you know what to do to make money in a gold rush especially if you're a software engineer.
I found most of the pentesting salaries came in lower than engineering ones, and I felt that pentesting was the more difficult job.
But there is "application penetration testing" and just application security in general which tends to pay competitively with software engineering. And of course plenty of people do both at the same job.
So pentesting can be competitive but it depends on definitions a bit. That said on the upper end, software dev tends to have more chances to get a big exit by being part of building something. In security you might be with a consulting firm where you have a slight chance at that, but its not common for a security guy to have that sort of big exit.
(Very rarely seen “noddy” used to describe an extremely rough throwaway utility program since then, though)
While i agree with you on the hijacking of the term, i do support more people getting involved with security and especially security awareness. The more, the merrier! So, overall its a good thing, even if it creates a little pain for folks who are more kung fu gurus of the hacking way. I think a more general term like "security practitioner" might be more apt...but headlines gonna be headlines, hence writers gonna jazz things up with "hacker". Then again, what do i know.
Anecdotical, but it happens.
Where I agree most bugs are self inflicted, there are plenty found in acquired software too.
EDIT: My bad, misread your comment.
I'm hoping that's hyperbole, but even if it is, the notion sickens me. I really hate the normalization of this idea that anyone who works in this field spends their 100% of their leisure time there as well. Get in shape. Make art and music. Build things. Be more than your job. Especially if you have a family. What kind of 1-dimensional example do you want to set for your children?
The author is clearly showing His family as the priority.
I have no idea what you’re getting on about.
OP must be interpreting the above statement which implies that this hacker is either with family or basically doing work related stuff, nothing else
Basically OP is deriding the author when the author is subverting the exact same trope that disgusts OP.
I can only assume these capitalize on fame because it can lead to jobs in the industry. If it WAS about the money, and (not that I encourage it) your moral compass is sufficiently adjusted, there is far more money to be made selling the exploits for bitcoin elsewhere.
Companies are saving an absolute metric boatload of money by having people work as red team for free, and only paying a pittance to solve most bugs (with some exceptions).