HNHacker News
TopNewBestAskShowJobs

pentesterlab

40 karma · joined March 9, 2016

submissionscomments
pentesterlab··on Ask HN: Black Friday/Cybermonday deals for hackers?
PentesterLab has a special for Black Friday: https://pentesterlab.com/pro
pentesterlab··on Ask HN: How can I learn to be a cyber security expert?
As a dev, you should start learn about the most common bug classes and get a proper understanding on what is happening and how you can prevent them. Then it's worth looking into how you can exploit them. If you work for a big company, you may be able to spend some time working along your security team, that will help you get a foot in the door. Security teams are always looking for people who already understand the code bases and deployment processes and want to inject security everywhere :)

<shameless_plug>You may like https://pentesterlab.com/ if you are looking for a course</shameless_plug>

pentesterlab··on A Review of PentesterLab
Fair point and you're (obviously) spot-on for the attacks and very valid point on the names used.

It's a problem with most learning resources, you get what you put it. Most people get out of these exercises one of these two things (or both):

#1 a real understanding of the issue (best case scenario) #2 awareness that encrypted/signed doesn't mean bulletproof.

Worst case scenario, I think these exercises help people with #2 and may get them to look a bit deeper when they are reviewing applications. It's not meant to be a crypto training (IANAC), the goal is to help people gain some awareness around crypto issues they may encounter during an assessment.

pentesterlab··on Ask HN: I work for consulting firm that's illegally moving bank code to GitHub
I have contacts in the security team of most banks in Australia. Happy to help
pentesterlab··on Ask HN: Has anyone here successfully applied to Stripe Atlas?
Got in during the beta. Incorporated in less than 2 weeks. The process was quick and straightforward. I started the paperwork to get a debit card from SVB 3 weeks ago and I should receive it in few days.
pentesterlab··on Ask HN: My infosec auditor rejects open source. What now?
Quick answer: get a better auditor.

Long answer: it's a risk game, you may get away by showing that you have processes in place to manage this risk for open source projects: * internal backup of the source tree. * in-house skills to perform basic patching of the software if the development get discontinued. * alternative solution and roll-out plan in case the development of your current solution gets discontinued. * ...

Finally, risks can be accepted and someone ("the business") can sign-off on them. You don't have to remediate everything. It's just an awareness exercise for "the business".

pentesterlab··on Ask HN: Those making $1,000+/month on side projects – what did you make?
https://pentesterLab.com/. I started a paid version with additional content and videos in December. It's bring more and more revenue every month.