HNHacker News
TopNewBestAskShowJobs

ifoundthetao

113 karma · joined September 17, 2015

submissionscomments
ifoundthetao··on PHP in 2021
People also use PHP to write backend scripts, without web use at all.

While the original and primary purpose may have been for personal home pages, it has evolved considerably since then. Consider an accounting/aggregate billing script for a PHP application that runs on a scheduler. That isn't dependent on the web necessarily, but it does interface with the moving parts of the overall application. Async would be great here.

ifoundthetao··on Amazon Is Forcing Its Warehouse Workers into Brutal 'Megacycle' Shifts
Agreed. I worked 4-10's before, and I looooved it. It was awesome. I had Wednesdays and weekends off.
ifoundthetao··on ReDoS: Regular Expression Denial of Service
Edit: Never mind, clicked on the article, lots of sources!

Is your paper available for reading? I'm very interested in it.

ifoundthetao··on The Go Language was rid of blacklist/whitelist and master/slave
I don't think the poster is even addressing that, they're instead addressing the gate keeping mentality of the poster they replied to.
ifoundthetao··on BaseSAFE: Baseband SAnitized Fuzzing Through Emulation
Would you be willing to talk about how you went about doing this? I do a good amount of fuzzing and would like to expand into fuzzing infra as well.
ifoundthetao··on Show HN: An online collaborative UML editor using PlantUML
Well, I think you did a great job. (:
ifoundthetao··on Show HN: An online collaborative UML editor using PlantUML
Friendly tip: you should sanitize your inputs / ouput.
ifoundthetao··on Ask HN: Successful one-person online businesses?
Man, I remember thinking that Elixir was going to take the world by storm about 5 years ago. I was so excited for it. I hope it does though, it has a lot of great things going for it, and I'd love to see it adopted.
ifoundthetao··on A new Go API for Protocol Buffers
That makes the most sense, and throws a great seasoning of context on that decision. Thanks for providing that here.
ifoundthetao··on Ask HN: What are some books where the reader learns by building projects?
Well, I'm interested and will purchase this.
ifoundthetao··on Ask HN: What are some books where the reader learns by building projects?
It's pretty practical so far. Right now I'm just finishing up chapter 4 (HTTP Servers, Routing, and Middleware), so I haven't completed all of it. But as it stands, a lot of what you go through, you reasonably expect you may be able to use on an actual pen test. The real power though, is when you're building out your own tooling with these things.

You just set up a framework in the book, but this is all easily extendable to whatever you want. I'm not the best at Go, so it's a useful "nightly devotion" of time to spend working through it for an hour or so.

I've also been going through Writing an Interpreter in Go, and have picked up the companion to that Writing a Compiler in Go. So far, that's pretty good too, but I'm focusing on Black Hat Go first, to complete it.

ifoundthetao··on Ask HN: What are some books where the reader learns by building projects?
Black Hat Go -- Excellent book!
ifoundthetao··on Fyne: Native Mobile UX in Go
I was looking at this last night. I'm interested in setting up a simple project with it -- so far, it looks the most promising to fill the GUI gap.
ifoundthetao··on Ask HN: What's the best resource for learning modern x64 assembly?
I enjoyed the Pentester Academy course, and have recommended it several times.
ifoundthetao··on Show HN: My Book, Hands-On Software Engineering with Golang
Thanks for writing this!
ifoundthetao··on 64 Core Threadripper 3990X CPU Review
Yep, and with the ease of concurrency in Go and Rust, it'll be freakin' awesome. And hopefully, we'll get some novel security research in areas dealing with attacks against concurrency and parallel execution.
ifoundthetao··on Reverse engineering course
Excellent! Thanks. I followed the links on Github, btw. I'm looking into some of the trainings you're offering.

Last August, I took the Advanced Windows Exploitation course from Offensive Security (for the OSEE), and then I followed it up with the awesome Advanced Fuzzing and Crash Analysis course taught by Richard Johnson. Both were incredible courses, but my RE sucks.

I'm looking at the Advanced Browser Exploitation course next, but I'd really like to get better with reversing in order to get more out of these classes.

ifoundthetao··on Reverse engineering course
This is great! Do you have other related curated lists that you're willing to share?
ifoundthetao··on In-Memory-Only ELF Execution Without Tmpfs
Thanks!!
ifoundthetao··on Expert Networks: A Secret World of $500 per Hour Consultations
It can be justified in the context of hiring that person keeps that knowledge resource from competitors. Then it makes a lot of sense to pay them enough to stay, as it allows you to outpace competition in the marketplace.
ifoundthetao··on In-Memory-Only ELF Execution Without Tmpfs
Would you be willing to share how you did that (avoiding procfs too)?
ifoundthetao··on History and Effective Use of Vim
I am right there with you. I did the same thing, and now when I jump into Vim from anywhere, it's so much easier.

Though I really do like having the Capslock key remapped to escape.

ifoundthetao··on Black soldier fly maggots: high in protein with a small carbon footprint
It is. And it's an excellent input for aquaponics too. I used to do this about 10 years ago for a while. It was fun.

I learned a lot, and the peppers were delicious.

ifoundthetao··on Fuzzing DNS Zone Parsers
Excellent! Would you be willing to do a second article on the process you used when wading through the findings?
ifoundthetao··on Cutter 1.8.3 – open source GUI for reverse engineering
Thank you! I'm incredibly new to RE, but I'm decent at exploit dev, so my RE is growing.

I'll see how I can contribute, but if you have any specifics that you'd like, please let me know. I'm looking over the issues on github to see where I'd be most useful.

ifoundthetao··on A giant whiteboard for $14 plus nails
Yeah, that was my exact experience too. They're nice for a while, and they can make great Kanban boards, if you're into that. But I only got a couple years out of them (which is honestly fine, for their cost). If I were a bit more clever, and still needed those types of whiteboards, I would have engineered something to make it easier to remove them from the wall, without having to redrill holes.
ifoundthetao··on YouTube bans content “showing users how to bypass secure computer systems”
https://www.reddit.com/r/DataHoarder/comments/c6fh4x/after_h...
ifoundthetao··on Reverse Engineering Cyclic Redundancy Codes
Maybe there are CRC values that signal hashes, and are used as such. So instead of looking at a message, it'll look at the CRC instead. This gives you the ability to not have to know the full message, but leverage this with part/none of it.

Another reason might be for QA testing, or for fuzzing purposes.

You don't always know the implementation details, but this type of control allows one to get more understanding of those details, by seeing how the software under test reacts. This stuff is not wildly uncommon in low-grade IoT devices, or high-end devices with a low level of security maturity.

ifoundthetao··on Hack the Box – Pentesting Labs for Free
Yep, they're great courses. Make sure you actually do it.

Vivek is an excellent instructor, and he goes from nothing to getting you up to speed pretty quickly.

The first parts might be a bit dry, because it's a lot of architecture and theoretical stuff. But after you get through that, and start doing things, you'll find that it's awesome.

Also, if you don't want to be a pentester, you might find a particular affinity for exploit development. And that's a niche field that pays well. That's where I'm going with my training, research, job. Not easy, at all, but it's deep, and fun.

ifoundthetao··on Hack the Box – Pentesting Labs for Free
100% agreed

I love Pentester Academy. I've had a subscription to it for the last year or so.

And OffSec is nice, too. I've got OSWP, OSCP, OSCE, and I'm in the Black Hat training this year for OSEE. So we'll see how that goes. I haven't tried their On-Prem labs though, but I think they'd be pretty fun.

Page 1 of 4Next →