HNHacker News
TopNewBestAskShowJobs

Faelian2

128 karma · joined March 4, 2021

Pentester Freelance, based in Europe.

mail: olivier [at] lasne dot pro

submissionscomments
Faelian2··on The Holy Grail of Linux Binary Compatibility: Musl and Dlopen
I did wrote a small open-source tool in Rust. And I too did encounter that kind of issue when I did start to build a .deb.

Honestly, it was the kind of bug that is not fun to fix, because it's really about dependency, and not some fun code issue. There is no point in making our life harder with this to gatekeep proprietary software to run on our platform.

Faelian2··on What Happened in 2007?
Thanks for putting this site together. Despite all the comments here, I find your point pretty convincing.
Faelian2··on Quarkdown: A modern Markdown-based typesetting system
That's a really interesting project.

I have been generating documents for a while using https://github.com/enhuiz/eisvogel. It's nice to use markdown, but I feel really limited, and can't do much customization.

I would love to see some templates for this.

Faelian2··on Swedish minister eyes energy crisis steps, blames German nuclear phase-out
France is literally making billions by exporting in electricity. https://oec.world/en/profile/bilateral-product/electricity/r...

It's France 9th biggest export.

Faelian2··on Spies Jumped from One Network to Another via Wi-Fi in an Unprecedented Hack
An explanation of the attack by the company doing the investigation: https://www.volexity.com/blog/2024/11/22/the-nearest-neighbo...
Faelian2··on A summer intern once saved Valve from a near-fatal lawsuit
At what timestamp in the documentary do they talk about ?
Faelian2··on Listen to the whispers: web timing attacks that work
I love how he is porting every local attack to web applications.

I am also a bit frightening that the number of attack you have to know for the Burp Certification keeps getting longer.

Faelian2··on Pleasant Debugging with GDB and DDD
I don't use GDB a lot. But when I do, I generally use the pwndb extension. It's written for exploit development, but even for debugging a C program. It makes things a lot nicer.

https://pwndbg.re/

Faelian2··on Ask HN: What are you working on (September 2024)?
I am writing an hexadecimal editor in rust, with colors.

https://github.com/0xfalafel/hextazy

I am also playing a bit with Gtk4, Relm4, and creating Active Directory labs with vagrant. https://blog.lasne.pro/posts/ad_lab_part1/

Faelian2··on Why I avoid using empty() in PHP? A Closer Look
Do you guys know if `!isset()` is a good alternative ? Or if it also has some shortcomings ?
Faelian2··on Defenders think in lists, attackers think in graphs (2015)
As a pentester, I would argue that attackers don't think in graphs either.

Apart from Bloodhound, I can't think of any tools where we have graphs.

For web security, I can't think of something where "graph thinking" applies. But we have a pretty huge list of attacks to test https://portswigger.net/web-security/all-topics.

And ultimately, what is inside your pentest report ? Not a graph, a list of things to do:

- SMB signing.

- Don't use the domain admin to manage every machine.

- ...

The main reason this phrase is so popular, is that it panders to the hacker community: "We are the smart guys, all the defenders do is excel sheets."

IMHO, the nugget of truth in this is that defenders can spend considerable amounts of time on things that don't matter. Like doing CIS benchmark by hand on all servers. While missing the low-hanging fruits that would give them a strong security posture.

In a lot of companies, the defenders are just sysadmins that don't have any idea of what they should focus on.

Faelian2··on Ask HN: Freelancer? Seeking freelancer? (May 2024)
SEEKING WORK: Pentest / AppSec / Training / Cybersecurity | Remote, France

Cybersecurity expert, with 8 years of experience, I have audited multiple complex systems. From Internet Gateway (Linux embedded), to innovative web apps and complex Active Directory environment of Healthcare providers.

Website: https://lasne.pro Github: https://github.com/Faelian Email: olivier [at] lasne.pro

Faelian2··on Wisdom from Marcus Aurelius
I just read "Windows from Marcus Aurelius". Guess I need to spend some time AFK
Faelian2··on A BSD person tries Alpine Linux
Yeah, sorry guys. I did write too fast.

The last sentence should be :

So in that regard, Alpine is less secure by using musl. However, having a small and understandable system is a real advantage when it comes to security.

Faelian2··on A BSD person tries Alpine Linux
Just my two cents about the security aspect.

All Linux binaries are compiled with PIE nowadays. You can run `checksec` on any binaries on Ubuntu, and it will have those properties. (You can install checksec with `pip install pwntools`).

On the other hand, GLIBC has, to my knowledge, the most hardened heap implementation out there. And there are more mitigations for double-free and other heap exploits on GLIBC.

So in that regard, Alpine is less secure by using musl. Having a small, understandable system is a real advantage when it comes to security.

Faelian2··on VirtualBox KVM Public Release
I am really curious about this.

As a pentester, I run use Linux on my laptop and I spend a lot of time working inside a Kali VM with VirtualBox.

How much performance improvement can we expect with the KVM backend ?

Faelian2··on Ask HN: Freelancer? Seeking freelancer? (December 2023)
SEEKING WORK | France, Remote | Pentester, Cybersecurity expert

I am a cybersecurity consultant / pentester / trainer with 7+ years of experience. I have audited successfully internal networks, web applications, and embedded environments. I also do trainings for professionals and students.

Location: EU (France) Linkedin: https://linkedin.com/in/olasne Website: https://lasne.pro

Email: olivier [] lasne.pro

Faelian2··on Data accidentally exposed by Microsoft AI researchers
Honestly, the OWASP top ten is generic enough that most vulnerability fit in it : "injection", "security misconfiguration", "insecure design".

The problem is

1. knowing the gazillion of web vulnerabilities, and technologies

2. being good enough to tests them

3. kick yourself and go through the laborious process of understand and test every key feature of the target.

Faelian2··on Data accidentally exposed by Microsoft AI researchers
I work as pentester (as a freelance nowdays).

Getting out of bed and "real stuff" is supposed to be part of a pentest.

The problem is more the sheer amout of stuff your are supposed to know to be a pentester. Most pentesters come into the field by knowing a bit of XSS, a few thing about PHP, and SQL injections.

Then you start to work, and the clients need you to tests things like:

- compromise a full Windows Network, and take control of the Active Directory Server. Because of a misconfiguration of Active Directory Certificate Services. While dealing with Windows Defender

- test a web application that use websockets, React, nodejs, and GraphQL

- test a WindDev application, with a Java Backend on a AIX server

- check the security of an architecture with multiple services that use a Single Sign on, and Kubernetes

- exploit multiple memory corruption issues ranging form buffer overflow to heap and kernel exploitation

- evaluate the security of an IoT device, with a firmware OTA update and secure boot.

- be familiar with cloud tokens, and compliance with European data protection law.

- Mobile Security, with iOS and Android

- Network : radius, ARP cache poisoning, write a Scapy Layer for a custom protocol, etc

- Cryptography, you might need it

Most of this is actual stuff I had to work on at some point.

Even if you just do web, you should be able to detect and exploit all those vulnerabilities: https://portswigger.net/web-security/all-labs

Nobody knows everything. Being a pentester is a journey.

So in the end, most pentesters fall short on a lot this. Even with an OSCP certification, you don't know most of what you should know. I heard that in some company, people don't even try and just give you the results of a Nessus scan. But even if you are competent, sooner or later, you will run into something that you don't understand. And you have max 2 week to get familiar with it and test it. You can't test something that you don't understand.

The scanner always gives you a few things that are wrong (looking at you TLS ciphers). Even if you suck, or if the system is really secure. You can put a few things into your report. As a junior pentester, my biggest fear was always to hand an empty report. What were people going to think of you, if you work 1 week and don't find anything?

Faelian2··on OpenSSL 3.0.7 fixes X.509 email address buffer overflows
Is this exploitable ? With current mitigations (NX, Stack Canary, ASLR), I don't see how a buffer overflow on it's own could result in Remote Code Execution.
Faelian2··on My Fanless OpenBSD Desktop (2021)
My first thought when reading the title was "Oh, I guess he must have an issue with his fan drivers".
Faelian2··on IKEA’s Crimes Against Cartography
It's surprising to me that IKEA only has 464 stores (https://www.statista.com/statistics/241821/number-of-stores-...).

For a company that have a revenue of 42 billion, I was expecting that there would be more stores. I guess the world isn't that big.

Faelian2··on The Peter Principle (1974) [video]
Something that makes me smile every time, "The incompetence Opera : Dunning-Kruger Effect meet the Peter Principle". It was for an Ig Nobel Prize Ceremony.

https://www.youtube.com/watch?v=cNGusIvpVxc

Faelian2··on Show HN: Open Source Canva Clone
Nice
Faelian2··on How messed up was Germany's energy policy?
Pretty messed up : https://jancovici.com/en/energy-transition/societal-choices/...

250 to 300 billion euros, which is more than the cost of rebuilding from scratch all the French nuclear power plants, is what Germany has invested from 1996 to 2014 to increase by 22% the fraction of renewable electricity into the gross production of the country (that went from 4% to 27%).

For this price tag our neighbors did not decrease their energy imports, did not accelerate the decrease of their CO2 emissions per capita, that remain 80% higher to those of a French, increased the stress on the European grid.

Faelian2··on How to open a safe
In French, a 3 min presentation of the project : https://static.sstic.org/rumps2022/SSTIC_2022-06-02_P10_RUMP...
Faelian2··on Ask HN: How to break anxiety/fear-avoidance cycle?
Watching interviews from Jordan Peterson on youtube did help me a lot recently.

One good advice is that you are paralyzed because you fear what is before you. You don't know how to manage it, and your instinct to facing danger is "don't move". What you have to do is to think about the danger of not moving, and the cost associated. You use one fear to mitigate the other.

There is also something that I can't really explain about changing your vision and "Take responsibility for your life. Accept the burden that come with it".

Faelian2··on Germany boosts renewables with “biggest energy policy reform in decades”
For those interested, here is the primary energy use of Germany. There is still a long way to get rid of coal.

https://jancovici.com/wp-content/uploads/2016/05/chiffres_en...

Faelian2··on Russian forces invade Ukraine after Putin orders attack
France and Germany having a firm anti-Atlanticist tradition, and China being a danger for Russia are ridiculous.

I don't believe for a second that this represent Putin's strategy in any meaningful way.

Faelian2··on Europe Is Losing Nuclear Power Just When It Needs Energy
Coal is still the primary source of energy for Germany.

https://jancovici.com/en/energy-transition/long-series/germa...

Page 1 of 2Next →