244 karma · joined June 3, 2013
As others have indicated, a VPN server of your choosing (openvpn/wireguard) can solve your issues. Even if at some point there's an "unauthenticated RCE" exploit for gitea, having it behind a VPN will mitigate that.
If you enjoy pentesting, I'd just look for another job, especially since the demand for ex-devs in pentesting is huge. Have a look at a previous comment I posted: https://news.ycombinator.com/item?id=32303528#32305561
I made that exact jump from development to pentesting 6 years ago, after about 10 years of development. Will you miss development? Absolutely. Are there opportunities to scratch that itch? Yes there are - but it's with scripting. The things that can be scripted to make you more efficient are insane. Your ability to understand not only what is broken but also why it's broken will help you advance yourself. You have probably even coded that exact bug in the past so you know where else to look, and you know how to do code reviews. In general, the need for pentesters with a dev background is very very high, especially since now companies worry about supply chain attacks, SDLC, etc.
My solution was to keep coding in my spare time, when I have an MVP I show it at work and then ask for time to work on it. I've significantly improved internall processes, and I've released a few offensive security tools, two of them I even presented at security conferences - as in full blown applications rather than "here's a script that does X". This way I get to pentest and provide solutions to industry-related problems. One thing to note is that most of the security tooling out there (the open sourced ones) is very python/C#/Go centric. I've seen applications written in Rails/Java that didn't get the love they deserved just because it's a pain to install them. I had to learn both python and C#, but it was totally worth it.
If you do make the jump, get ready to take a salary hit as you'd be hired as a mid-level consultant at best - and that's only if you've proven that you know a lot about cyber security, OWASP vulnerabilities, etc. But don't let that stop you, I've seen people join the industry as juniors and in 6 years making over 6 digits (UK). YMMV, but if you put in the time and effort, it's worth it.
I don't have a solution for this, I just think the effort/reward should be considered.
If you want you could pull real-time exchange rates and have a button that indicates the conversion for someone who wants to see the "most likely" price (depending on when they actually pay for it).
For example if you sell something for $9.99 just leave it as such, and Stripe will make the conversion and you'll always sell at the same price regardless from where someone is coming from.
That's how I feel about it anyway!
I know 2 people who had it around the same time as me, and only one has -1 in one eye after another 7 years. The other person is still glass-free.
My advice is to not go cheap. Don't choose a doctor that "also does eye surgery" (there are a few like that), go to someone who specialises in it and only does that.
Unfortunately I don't have anyone to recommend in the UK as I've done mine in Greece, but I've had -5 on both eyes and lasik did wonders.
I suspect it only sends data to them server if you are logged in so you can use the functionality such as "sync between devices", which kind of makes sense.
I was doing a security assessment for a client, and after gaining foothold on the host we needed to establish persistence. As the endpoint protection was blocking anything non signed, I used slack to inject a powershell payload that's executed on startup and gains us access back to the internal network.
So the risk is there, but not the individual user but the organisations using it. I didn't expect this to become a big deal over "redistribution" but I hoped for the command execution without modifying the binary.
Having said that, this can be solved with a simple integrity check of the asar files. Sure, the attacker can modify the binary file too, but then it's not signed anymore.
On the other hand, the "Firefox Focus" app and Chrome do not seem to have this issue. Is there any way to fix this, because it's literally the only thing that stopping me.
- mount truecrypt container
- run getmail for each account I want to backup (separate .conf files)
- unmount container
- sync offsite to rsync.net
All of this runs on my raspberry pi 2 and it's really easy to setup (it's practically a bash file with 4 commands).
The output is an mbox file which you can import into Thunderbird or any other client that supports them.
https://www.reddit.com/r/netsec/ General news about netsec
https://github.com/enaqx/awesome-pentest List of tools and resources
https://github.com/wtsxDev/Penetration-Testing Another list of tools and resources
https://www.hackthebox.eu/ Hands on hacking (OSCP style) but free, unless you want to pay for a VIP version and get access to even more machines.
https://www.vulnhub.com/ Individual VMs you can hack into, most of them providing walkthroughs.
Web application wise I'd suggest starting with https://www.owasp.org/index.php/OWASP_Juice_Shop_Project which is a modern version of the "damn vulnerable web app (DVWA)".
These may look quite "massive" for a beginner but I think it's the best way to start. The approach I would suggest would be to go download a VM from vulnhub and read its walkthrough. Then learn to use the tools in that walkthrough (each machine may use a tool in a different way) until you're confident enough to make an attempt on your own.
Hope this is helpful!
It works fine and gave me some peace of mind!
Works on both Windows and Linux but the passwords are stored online (GPG encrypted). The main idea was to be able to revoke a password if a machine has been compromised.
But it also depends where you are located (country wise I mean).
So I made https://www.remotepassword.com where you can store a GPG encrypted version of the password and then call-decrypt-passthrough the password to the command line. If the device is compromised, you can deactivate the online password and no-one can get access to your data.
If your project lifts off and Linode doesn't cover you, you can look at AWS then.
My security skills were average (hobby for about 10 years but mostly because I was a web developer) but like I said the OSCP did most of the work in terms of getting the interview and doing any technical test. The course itself took about 2 months, 6 hours every day after work, and fulltime weekends!
My suggestion would be to do the OSCP course and if you like it then go for it. There is also vulnhub.com which has a lot of CTF VMs where you can practice (I personally dislike CTFs because I find them unrealistic).
If you look at my previous comments I always say the same thing: get the OSCP certification. It will definitely get you an interview but the course is hard and demanding.
Also, get ready to take a paycut and a role downgrade as 4 years of pentesting have more value than 10 years of development.
Obviously you bring other skills to the table like better client communication and knowing how things work under the hood, but you'll have to take a step back before you take two steps forward.
I definitely recommend you go that way, but think hard before you do, and please be sure it's not because you're "bored".
Last but not least, prepare to travel to clients. Sure there is the "internet" and "vpn" but a lot of clients have internal apps need testing and do not give you remote access.
If you have any questions I'll be happy to help out.
Battery-wise, the "best" one I've found is the Lenovo P2 which has 5100mAh (S8 Plus has 3500) but not sure if its hardware is any good. I'm planning however to get OnePlus 3t which has 3400mAh and seems like a better long-term choice.
How can I self host the API documentation (as reference) without setting up the whole UI? Everything I've tried is "experimental", "not tested" and "almost working".
The easiest thing you can do is e-mail all penetration testing companies who can find near (or far) from where you live and ask if they are looking for interns or graduates. Even if they don't advertise at the moment, there's a good chance you'll get a positive reply, because the demand is greater than the supply.
Most security companies have a research department which you'll be able to apply for, after you've joined (at least in the UK such departments require security clearance).
Also, having an OSCP or OSCE certificate will definitely get you an interview.
That's the way I personally moved to security and can't recommend it enough. It's a bit expensive but you definitely get your money's worth.