Advice for someone whos maybe trying to get into the cybersecurity field thats in his early thirties? Am I going into this too late?
https://www.reddit.com/r/Pentesting/comments/1cti8vt/advice_for_someone_whos_maybe_trying_to_get_into/
<!-- SC_OFF -->Hello guys, To make this the shortest possible story here, Im 33, When I was 26 I shattered my spine after having a seizure and blacking out/from the fall. It took me years to find the right pain doctor/treatment I am, have been ever since the day of the fall, and will be in constant pain for the rest of my life. After 34 different doctors I finally found one that will treat me like a human being and actually cares about me not being in excruciating agony all the time but the search to find him took a very long time (time that I was not able to physically handle working leaving me with a job gap on my resume).
I have a bachelors IT degree, and am thinking about taking the certifications to go into the penetration testing/cybersec role, but with it being a 2 year long process basically (leaving me being 35 now) would I have more trouble finding a company that would hire someone for a security position that hasnt had much experience with the cyber sec industry itself? I do have several years of experience in the support/briefly a sys admin role so I do know what I am doing I just havent gotten to the higher level security training/certs yet. I dont want to potentially waste 2 years training for something that could prove to be extremely difficult to even get my foot in the door so Im wondering if anyone could give me any potential insight about whether or not this maybe a good idea, or a recipe for disaster. And whether or not having the certs like: (If there are ones more important than others I would welcome your opinion on which ones are the most critical that would be very helpful as well). -CompTIAA+ -CCNA Cisco certified network associate) -CompTIA Network -COMPTIA Security+ -Advanced cyber security certificate -Cyber and Network Defense Certificate -Certified ethical hacker -Certified Information Systems Security Professional (CISSP) Thank you all very much I really appreciate any insight/thoughts on whether or not this could be as promising as I am hoping it may be. <!-- SC_ON --> submitted by /u/Madddbob (https://www.reddit.com/user/Madddbob)
[link] (https://www.reddit.com/r/Pentesting/comments/1cti8vt/advice_for_someone_whos_maybe_trying_to_get_into/) [comments] (https://www.reddit.com/r/Pentesting/comments/1cti8vt/advice_for_someone_whos_maybe_trying_to_get_into/)
https://www.reddit.com/r/Pentesting/comments/1cti8vt/advice_for_someone_whos_maybe_trying_to_get_into/
<!-- SC_OFF -->Hello guys, To make this the shortest possible story here, Im 33, When I was 26 I shattered my spine after having a seizure and blacking out/from the fall. It took me years to find the right pain doctor/treatment I am, have been ever since the day of the fall, and will be in constant pain for the rest of my life. After 34 different doctors I finally found one that will treat me like a human being and actually cares about me not being in excruciating agony all the time but the search to find him took a very long time (time that I was not able to physically handle working leaving me with a job gap on my resume).
I have a bachelors IT degree, and am thinking about taking the certifications to go into the penetration testing/cybersec role, but with it being a 2 year long process basically (leaving me being 35 now) would I have more trouble finding a company that would hire someone for a security position that hasnt had much experience with the cyber sec industry itself? I do have several years of experience in the support/briefly a sys admin role so I do know what I am doing I just havent gotten to the higher level security training/certs yet. I dont want to potentially waste 2 years training for something that could prove to be extremely difficult to even get my foot in the door so Im wondering if anyone could give me any potential insight about whether or not this maybe a good idea, or a recipe for disaster. And whether or not having the certs like: (If there are ones more important than others I would welcome your opinion on which ones are the most critical that would be very helpful as well). -CompTIAA+ -CCNA Cisco certified network associate) -CompTIA Network -COMPTIA Security+ -Advanced cyber security certificate -Cyber and Network Defense Certificate -Certified ethical hacker -Certified Information Systems Security Professional (CISSP) Thank you all very much I really appreciate any insight/thoughts on whether or not this could be as promising as I am hoping it may be. <!-- SC_ON --> submitted by /u/Madddbob (https://www.reddit.com/user/Madddbob)
[link] (https://www.reddit.com/r/Pentesting/comments/1cti8vt/advice_for_someone_whos_maybe_trying_to_get_into/) [comments] (https://www.reddit.com/r/Pentesting/comments/1cti8vt/advice_for_someone_whos_maybe_trying_to_get_into/)
CVE-2023–52424: The WiFi SSID Confusion Attack Explained
CVE-2023–52424, also known as the SSID Confusion Attack, has brought new challenges to wireless network security.Continue reading on InfoSec Write-ups »
Read more...
CVE-2023–52424, also known as the SSID Confusion Attack, has brought new challenges to wireless network security.Continue reading on InfoSec Write-ups »
Read more...
Medium
CVE-2023–52424: The WiFi SSID Confusion Attack Explained
CVE-2023–52424, also known as the SSID Confusion Attack, has brought new challenges to wireless network security. This article explores the…
The Hacker’s Mind -Recon Mind map
By Tahir Mujawar, Certified Ethical Hacker & Cyber Security ResearcherContinue reading on Medium »
Read more...
By Tahir Mujawar, Certified Ethical Hacker & Cyber Security ResearcherContinue reading on Medium »
Read more...
Medium
The Hacker’s Mind -Recon Mind map
By Tahir Mujawar, Certified Ethical Hacker & Cyber Security Researcher
CVE-2023–52424: The WiFi SSID Confusion Attack Explained
https://infosecwriteups.com/cve-2023-52424-the-wifi-ssid-confusion-attack-explained-26e43f5cff40?source=rss------bug_bounty-5
https://infosecwriteups.com/cve-2023-52424-the-wifi-ssid-confusion-attack-explained-26e43f5cff40?source=rss------bug_bounty-5
CVE-2023–52424, also known as the SSID Confusion Attack, has brought new challenges to wireless network security.Continue reading on InfoSec Write-ups » (https://infosecwriteups.com/cve-2023-52424-the-wifi-ssid-confusion-attack-explained-26e43f5cff40?source=rss------bug_bounty-5)
The Hacker’s Mind -Recon Mind map
https://medium.com/@tamhacker1/the-hackers-mind-recon-mind-map-39d14e3750fb?source=rss------bug_bounty-5
https://medium.com/@tamhacker1/the-hackers-mind-recon-mind-map-39d14e3750fb?source=rss------bug_bounty-5
By Tahir Mujawar, Certified Ethical Hacker & Cyber Security ResearcherContinue reading on Medium » (https://medium.com/@tamhacker1/the-hackers-mind-recon-mind-map-39d14e3750fb?source=rss------bug_bounty-5)
How I found my first mistake Or why you shouldn’t overlook the obvious.
My story won’t be too long, I am a novice hunter and I want to tell you about how I found my first bug . It’s not a manual on how to find…Continue reading on Medium »
Read more...
My story won’t be too long, I am a novice hunter and I want to tell you about how I found my first bug . It’s not a manual on how to find…Continue reading on Medium »
Read more...
Medium
How I found my first mistake Or why you shouldn’t overlook the obvious.
My story won’t be too long, I am a novice hunter and I want to tell you about how I found my first bug . It’s not a manual on how to find…
How I found my first mistake Or why you shouldn’t overlook the obvious.
https://medium.com/@nagavicyn2/how-i-found-my-first-mistake-or-why-you-shouldnt-overlook-the-obvious-1f1d443afa6b?source=rss------bug_bounty-5
https://medium.com/@nagavicyn2/how-i-found-my-first-mistake-or-why-you-shouldnt-overlook-the-obvious-1f1d443afa6b?source=rss------bug_bounty-5
My story won’t be too long, I am a novice hunter and I want to tell you about how I found my first bug . It’s not a manual on how to find…Continue reading on Medium » (https://medium.com/@nagavicyn2/how-i-found-my-first-mistake-or-why-you-shouldnt-overlook-the-obvious-1f1d443afa6b?source=rss------bug_bounty-5)
ShellSweep - PowerShell/Python/Lua Tool Designed To Detect Potential Webshell Files In A Specified Directory
http://www.kitploit.com/2024/05/shellsweep-powershellpythonlua-tool.html
Tags: Aspx, Encryption, Entropy, Hashes, Malware, Obfuscation, PowerShell, Processes, Scan, Scanning, Scripts, Toolbox, ShellSweep
ShellSweep - ShellSweeping the evil.
Shellsweep - Shellsweeping The Evil.
ShellSweep - ShellSweeping The Evil.
http://www.kitploit.com/2024/05/shellsweep-powershellpythonlua-tool.html
Tags: Aspx, Encryption, Entropy, Hashes, Malware, Obfuscation, PowerShell, Processes, Scan, Scanning, Scripts, Toolbox, ShellSweep
ShellSweep - ShellSweeping the evil.
Shellsweep - Shellsweeping The Evil.
ShellSweep - ShellSweeping The Evil.
How does ShellSweep find the shells? Entropy, in the context of information theory or data science, is a measure of the unpredictability, randomness, or disorder in a set of data. The concept was introduced by Claude Shannon in his 1948 paper "A Mathematical Theory of Communication (https://people.math.harvard.edu/~ctm/home/text/others/shannon/entropy/entropy.pdf)". When applied to a file or a string of text, entropy can help assess the randomness of the data. Here's how it works: If a file consists of completely random data (each byte is just as likely to be any value between 0 and 255), the entropy is high, close to 8 (since log2(256) = 8). If a file consists of highly structured data (for example, a text file where most bytes are ASCII characters), the entropy is lower. In the context of finding webshells or malicious files, entropy can be a useful indicator: - Many obfuscated scripts or encrypted payloads can have high entropy because the obfuscation (https://www.kitploit.com/search/label/Obfuscation) or encryption (https://www.kitploit.com/search/label/Encryption) process makes the data look random. - A normal text file or HTML file would generally have lower entropy because human-readable text has patterns and structure (certain letters are more common, words are usually separated by spaces, etc.). So, a file with unusually high entropy might be suspicious and worth further investigation. However, it's not a surefire indicator of maliciousness -- there are plenty of legitimate reasons a file might have high entropy, and plenty of ways malware might avoid causing high entropy. It's just one tool in a larger toolbox for detecting potential threats. ShellSweep includes a Get-Entropy function that calculates the entropy of a file's contents by: - Counting how often each character appears in the file. - Using these frequencies to calculate the probability of each character. - Summing -p*log2(p) for each character, where p is the character's probability. This is the formula for entropy in information theory. ShellScan ShellScan provides the ability to scan multiple known bad webshell directories and output the average, median, minimum and maximum entropy values by file extension. Pass ShellScan.ps1 some directories of webshells, any size set. I used: https://github.com/tennc/webshell https://github.com/BlackArch/webshells https://github.com/tarwich/jackal/blob/master/libraries/ This will give a decent training set to get entropy values. Output example: Statistics for .aspx files:
Average entropy: 4.94212121048115
Minimum entropy: 1.29348709979974
Maximum entropy: 6.09830238020383
Median entropy: 4.85437969842084
Statistics for .asp files:
Average entropy: 5.51268104400858
Minimum entropy: 0.732406213077191
Maximum entropy: 7.69241278153711
Median entropy: 5.57351177724806
ShellCSV First, let's break down the usage of ShellCSV and how it assists with identifying entropy of the good files on disk. The idea is that defenders can run this on web servers to gather all files and entropy values to better understand what paths and extensions are most prominent in their working environment. See ShellCSV.csv as example output. ShellSweep First, choose your flavor: Python, PowerShell or Lua. Based on results from ShellScan or ShellCSV, modify entropy values as needed. Modify file extensions as needed. No need to look for ASPX on a non-ASPX app. Modify paths. I don't recommend just scanning all the C:\, lots to filter. Modify any filters needed. Run it! If you made it here, this is the part where you iterate on tuning. Find new shell? Gather entropy and modify as needed. Questions Feel free to open a Git issue. Thank You If you enjoyed this project, be sure to star the project and share with your family and friends.
Average entropy: 4.94212121048115
Minimum entropy: 1.29348709979974
Maximum entropy: 6.09830238020383
Median entropy: 4.85437969842084
Statistics for .asp files:
Average entropy: 5.51268104400858
Minimum entropy: 0.732406213077191
Maximum entropy: 7.69241278153711
Median entropy: 5.57351177724806
ShellCSV First, let's break down the usage of ShellCSV and how it assists with identifying entropy of the good files on disk. The idea is that defenders can run this on web servers to gather all files and entropy values to better understand what paths and extensions are most prominent in their working environment. See ShellCSV.csv as example output. ShellSweep First, choose your flavor: Python, PowerShell or Lua. Based on results from ShellScan or ShellCSV, modify entropy values as needed. Modify file extensions as needed. No need to look for ASPX on a non-ASPX app. Modify paths. I don't recommend just scanning all the C:\, lots to filter. Modify any filters needed. Run it! If you made it here, this is the part where you iterate on tuning. Find new shell? Gather entropy and modify as needed. Questions Feel free to open a Git issue. Thank You If you enjoyed this project, be sure to star the project and share with your family and friends.
Download ShellSweep (https://github.com/splunk/ShellSweep)
Simple Tips for Bug Bounty Beginners: Finding PII Vulnerabilities
Personally Identifiable Information (PII) refers to any sensitive data that could potentially identify an individual such as usernames…Continue reading on Medium »
Read more...
Personally Identifiable Information (PII) refers to any sensitive data that could potentially identify an individual such as usernames…Continue reading on Medium »
Read more...
Medium
Simple Tips for Bug Bounty Beginners: Finding PII Vulnerabilities
Personally Identifiable Information (PII) refers to any sensitive data that could potentially identify an individual such as usernames…
Simple Tips for Bug Bounty Beginners: Finding PII Vulnerabilities
https://medium.com/@anishnarayan/simple-tips-for-bug-bounty-beginners-finding-pii-vulnerabilities-3db5a7151dd4?source=rss------bug_bounty-5
https://medium.com/@anishnarayan/simple-tips-for-bug-bounty-beginners-finding-pii-vulnerabilities-3db5a7151dd4?source=rss------bug_bounty-5
Personally Identifiable Information (PII) refers to any sensitive data that could potentially identify an individual such as usernames…Continue reading on Medium » (https://medium.com/@anishnarayan/simple-tips-for-bug-bounty-beginners-finding-pii-vulnerabilities-3db5a7151dd4?source=rss------bug_bounty-5)