Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.9K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
How to transition to a consulting role?
https://www.reddit.com/r/Pentesting/comments/tbxwnk/how_to_transition_to_a_consulting_role/

I’m looking to move into a pentesting consultant role. However, the problem that I am facing is that pretty much every consultancy wants you to either be a senior-level tester, have prior consulting experience, or both. I have 3 years of pentesting experience from my time in the military which had a heavy appsec and embedded focus, but I performed some full-scope network pentests as well. It’s been nearly a year since I left the military, and I landed in a cybersecurity role at a defense contractor where I was told that I would be building out a pentest/vulnerability assessment capability, but I have mostly been stuck doing ISSO/ISSM work, which I find mind-numbingly boring, hence I am looking for a new job. I want to make the switch back to pentesting. I know I would excel in a consultancy position because I have strong soft skills needed for a client-facing role and I thrive when I am constantly diving into new projects and challenges. The problem is, how do I get experience as a consultant when consultancies want you to already have experience as a consultant? Also, I view myself as more of a mid-level tester than a senior. I feel that the guidance and mentorship that I could get from a senior would be invaluable, but it seems that most companies just want a senior that they can immediately throw into the weeds on day one. I have been unsuccessful so far in my efforts, despite applying for quite a few roles and receiving a handful of interviews. Any advice on how to move into one of these roles is much appreciated. I am young, hungry, and eager to learn! To that end, if anyone knows of companies openly hiring mid-level roles or who are open to mid-level professionals, I would love to hear about them. Some additional background on myself: I have my OSCP, CISSP, TS Clearance, and B.S. in Computer Engineering. My career has consisted of about 3 years of pentesting, but nearly 6 years overall of InfoSec/cybersecurity related experience. Currently been spending plenty of my free time on Hack the Box to try and keep my skills sharp since they aren’t being actively utilized in my current role. I’ve thought about working on some bug bounties as well, but with my free time being limited, Hack the Box has seemed like a better tool to stay sharp because of the wide variety of machines and challenges that the platform offers. submitted by /u/Systemtechno (https://www.reddit.com/user/Systemtechno)
[link] (https://www.reddit.com/r/Pentesting/comments/tbxwnk/how_to_transition_to_a_consulting_role/) [comments] (https://www.reddit.com/r/Pentesting/comments/tbxwnk/how_to_transition_to_a_consulting_role/)

___________________________
@hacking_Attack
@Hacking_Video
How I access other domains in infinityfree.net using Directory Traversal

Hi, it’s me again haha Kurt Russelle Marmol aka xkurtph, Web Developer (noobie) and Security Researcher.Continue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Automated WiFi Hacker

After watching David Bombal's most recent video using hcxdumptool & hashcat to crack WiFi passcodes, I Created a Python script to automate the capturing, sorting and creating hash files of matching WiFi networks to password hashes. On my GitHub if you guys wanna use it.

https://github.com/TrevorSatori/Wifi-Sweep

submitted by /u/BradPittOfTheOffice
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
From Recon via Censys and DNSdumpster, to Getting P1 by Login Using Weak Password — “password”

A simple story when Allah allowed me to get P1 by combining several issues, one of which was related to “weak credentials”.Continue reading on InfoSec Write-ups »
Read more...
Question: Operating system for pen testing
https://www.reddit.com/r/Pentesting/comments/tds2cq/question_operating_system_for_pen_testing/

I was wondering what OS I should use because I mainly see people using Mac and Linux but I never see windows being used(The OS on my computer) I would need recommendations on which OS I should use Would there be any specific branch of Linux that works best when it comes to pen testing? submitted by /u/Strange_Passenger_86 (https://www.reddit.com/user/Strange_Passenger_86)
[link] (https://www.reddit.com/r/Pentesting/comments/tds2cq/question_operating_system_for_pen_testing/) [comments] (https://www.reddit.com/r/Pentesting/comments/tds2cq/question_operating_system_for_pen_testing/)

___________________________
@hacking_Attack
@Hacking_Video
My Pentest Log -10- (A Little Tip)

Greetings to all from Khrysokeras,Continue reading on Medium »
Read more...