237 karma · joined December 12, 2015
IRC logs of #hack etc. would be gold!
> Throw away your paid tools because this is some God level shit. Now with 4 hand written parsers, an intelligent payload generator, powerful fuzzing engine, DOM scanner, hidden parameter discovery and an incredibly fast crawler. F*cking retweet it!
- https://twitter.com/s0md3v/status/1061255510677057537
> Exactly, that's why you have no idea how it works and all. Well, it took me a month and being a developer of 30+ open source software, this is the first time I am saying this is some God level shit and I mean it.
I would also like to highlight the following other creators. For me seeing the process of others has been a lot more fruitful then just following text tutorials:
+ ippsec: https://www.youtube.com/channel/UCa6eh7gCkpPo5XXUDfygQQA
+ John Hammond: https://www.youtube.com/user/RootOfTheNull
+ Gynvael EN: https://www.youtube.com/user/GynvaelEN
+ Derek Rook: https://www.youtube.com/channel/UCMACXuWd2w6_IEGog744UaA
+ ...
I have also recently started a series on Pwn Adventure 3, where we are hacking a game and I explain my process: https://www.youtube.com/playlist?list=PLhixgUqwRTjzzBeFSHXrw...
Besides that, I can also really recommend livestreams/screenshares from the following creators. To me, seeing how somebody really does it and where they struggle, really really helped me break through a wall I was hitting:
+ ippsec: https://www.youtube.com/channel/UCa6eh7gCkpPo5XXUDfygQQA
+ John Hammond: https://www.youtube.com/user/RootOfTheNull
+ Gynvael EN: https://www.youtube.com/user/GynvaelEN
+ Derek Rook: https://www.youtube.com/channel/UCMACXuWd2w6_IEGog744UaA
+ ...
And like the other people responded, there are just wayyyy to many primes to make that feasible. Though it is a common Challenge in security competitions to find the factors to a public key through factordb. Or having two bad keys sharing one same prime - then you can use Euclidean algorithm (greates common divisor).
To be honest with you? I consider that sentence almost offensive. I hear you, but I think you have absolutely wrong expectations. You want to learn something that is not a profession like plumber where a really good expert can teach you everything you need to know with all the little tricks learned over the years. The field is sooo huge diverse and complicated that this won't work. And I think my playlist offers a rough outline that you can follow, but without going down rabbit holes left and right, and getting stuck many many times, you wont become good at it.
I understand the frustration that you don't want to "waste time" and that you are busy already. But everybody I know who is good in this field, including my own experience shows me, that nobody learns this stuff through a straight path. And everybody knows that most of the time will be spent chasing rabbits through a labyrinth and getting stuck.
Also there is no clear path. It's a complicated web you have to learn to traverse. For example like "Learn C" - what the f* does that even mean? To what extend? Hello World? Drivers? Or Operating System? "Learn assembler" - which assembler? have you looked into the Intel Instruction spec once? I doubt any human knows every instruction. Also who said that intel is the way to go, why not ARM or AVR. All of these fields offer a lifetime of studying in itself.
The "art" in becoming good at security and RE is to get a broad knowledge of a lot of things and try to simultaneously go deeper 'n deeper in all of them. And if you are interested in a specific field, put more weight on those topics.
You know how long it takes to reverse engineer something? People stare on IDA for weeks or months at a time. You can't learn RE just by reading a book or a blog. You gotta start to just doing it, and hopefully find a few blogs and people to keep up the spirit.
Quickly looking over the code I think you use a slightly different way to achieve the r/w than qwerty - you don't misalign a pointer, correct? Can you give a short description how you do it?
I wondered how to not crash the switch when done, and you seem to simply set everything to 0 `this.bufs[i] = 0;` and that solves that issue. Could you say a few words on why that is the case?
Any information yet you want to share about the execution environment? Is there some kind of sandbox? Anything interesting you can already access, or surprisingly not access?
Edit: One more question. Did you guys get to play any BotW yet? :D
I really love the overengineering of this toolkit <3
My job title is "Penetration tester" but I don't fall into that category. That's why I often refer to it as doing "application security analysis/audits". My current job is to do black/white box testing of single applications - and not a huge organisations where you just phish some employees. I have not worked for other companies, but as far as I can tell, many "penetration testing jobs" are actually what I do.
It's fun, challenging and very technical. And obviously no scanners are used - I have never in my career used nessus or any other click2exploit tool.
I have also recently started building https://liveoverflow.com, which might have a better structure than a YouTube channel or subreddit.
Also some people may have actually seen a video of mine, because my most popular video so far is the DirtyCow video which got referenced by news sites and on the dirtycow github repository.
My personal recommendation is to checkout the AngularJS Sandbox bypass series: https://www.youtube.com/playlist?list=PLhixgUqwRTjwJTIkNopKu...
Criticism and feedback is always welcome.
https://www.youtube.com/playlist?list=PLhixgUqwRTjxglIswKp9m...
I also record myself playing CTFs and I just created a video walkthrough of the pwnable 200 challenge from the 32c3 CTF: https://www.youtube.com/watch?v=wLsckMfScOg
Maybe it helps somebody.
> "I recorded a speedrun of level 5, clearly labeled as a speedrun of level 5, which spoils the twist midway through level 5." -- Fun
> We're OK with you publishing facts about Starfighter games/levels but don't want people to be exposed to intentionally hidden facts (discovery of which is, in many cases, the point of the level) unless they go looking for them.
I am asking because I sometimes record or stream myself playing CTFs and I first thought I couldn't do that with starfighter... But I can do it as long as I label it properly and this would not be frowned upon?
I understand that you cannot stop people from leaking and spoiling challenges. But I definitely want to be obedient with your vision.
Really looking forward to this! Thank you for your work