machines, blood works, they can manipulate them again with the tools that biochemists make (pharmacuticals) and basically hack the body doing stuff that they ought to be doing. So being a doctor can be really fun, and maybe every great doctor should have decent enough of Dr. House in them, however they are not the guys who work on the molecular level on why something works the way it works, they can understand it figure connections out, but they are not creating anything new. So very skilled Pentesters are like Dr. House, they know all kinds of stuff, they can research them, they can put them in practice, with the right tools and methodologies for diagnosis they can test them and even again with the right tools they can manipulate and treat them, in a way they are fiddling with hacking, but without the biochemistry, there will be nothing but guessing, there will be no tools and methods to diagnose and no tools to treat, there will be some hacking, but no science. This doesn't mean that Dr. House is not awesome, it just means is different. In the real world I believe the number of people that are as good and deep in their knowledge as pentesters as Dr. House is as a doctor, is very few, just like in the real world where most doctors are very superficial, specialists included. So I am not talking about those people, I am talking about the Dr. Houses of pentesting, people that truly learn, research and implement and test and are curious, people that know a lot about all kinds of technologies and they know how and when to use each new tool to counter anything that counters achieving their goal, however they are not the guys working on the theorems, they are practical, they apply and they know how and when to apply it, but they do not discover it. While there can be great difference between two pentesters, it seems that AppSec allows less of that, just because tools are not the primary use, the skill ceiling can be higher of course. Pentesting can be a spectrum of Dr. House to script kiddie practitioners. Reading this subreddit there are a lot of people mentioning that they learn each day, I first wondered to ask, what do you guys learn each day? Do you just update yourself on the latest CVEs or is there more to it? Or maybe all your free time you spent learning of low level code, binary exploitation, work on embedded hardware, solder, lockpick, do you do CTFs - surely those are interesting, but not as applicable in day to day job. What exactly do you mean when you say you never stop studying and it is a 40 hour work week, but not lifestyle? Maybe I should post a poll about this very question, because if you do work as a pentester for a few years, I believe you can soak up the new information that you need to know the next day at work in 30 minutes average at best and/or learn more during your that work day. It seems that in a perfect world, I would be interested in both AppSec and Pentesting, to me it seems they compliment each other in terms of the hacker mindset, I cannot understand how LO says that he is not interested in checking tools at metasploit regularly, but also cannot understand if someone never studies binary exploitation. I am not there yet, so maybe I am too new too understand that it is not a natural progression and it truly is just different as I mentioned earlier, maybe I am just more into AppSec and I do not know that as I have not started with, or maybe Pentesting is what I truly like and I just am curious about the basics of low level code and nothing beyond, at last I have always been interested in new technologies and learning ways to use them efficiently and differently, so can I truly throw that out Maybe I know too little to understand all of this? Maybe Pentesting people are truly the hacker type of people, while AppSec guys would be the more academic research type of people that want to dwell into particular problems and find ways around them. Maybe I cannot categorize all of this and I am wasting
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
time trying to map personality traits of a person to this concept? I am just baffled and in a way want to look into the future of how some of my opinions will form, but I know I probably lack the knowledge and experience to come to that conclusion on my own, so I am asking you guys, not to give me a conclusion that I will consume as a bible, however read into some of your thoughts if any of you were in a similar thought situation as me at some point and how it turned out on the end. submitted by /u/appwizcpl (https://www.reddit.com/user/appwizcpl)
[link] (https://www.reddit.com/r/Pentesting/comments/udauts/pentesting_vs_pentesting/) [comments] (https://www.reddit.com/r/Pentesting/comments/udauts/pentesting_vs_pentesting/)
___________________________
@hacking_Attack
@Hacking_Video
[link] (https://www.reddit.com/r/Pentesting/comments/udauts/pentesting_vs_pentesting/) [comments] (https://www.reddit.com/r/Pentesting/comments/udauts/pentesting_vs_pentesting/)
___________________________
@hacking_Attack
@Hacking_Video
Reddit
overview for appwizcpl
The u/appwizcpl community on Reddit. Reddit gives you the best of the internet in one place.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Exploring Google Dorks
https://cdn-images-1.medium.com/max/600/1*QnLE__4w7_2CPyaVZlgkSA.jpeg
Note: This article is strictly for educational purpose only.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Exploring Google Dorks
https://cdn-images-1.medium.com/max/600/1*QnLE__4w7_2CPyaVZlgkSA.jpeg
Note: This article is strictly for educational purpose only.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Exploring Google Dorks
Note: This article is strictly for educational purpose only.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Introducing Burp Suite, OWASP ZAP, and WebGoat
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Introducing Burp Suite, OWASP ZAP, and WebGoat
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Introducing Burp Suite, OWASP ZAP, and WebGoat
To start with tools like Burp Suite, OWASP ZAP, and WebGoat, you need to install Kali Linux in your virtual box. We will do that for one reason: Kali Linux comes up with all these tools by default. Therefore you don’t have to install them separately. I strongly…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Swordfish
https://cdn-images-1.medium.com/max/1000/1*OTQBC5NyZDAEk28f5mkUpQ.jpeg
He can sing, he can dance, but can Hugh Jackman hack? Find out in my long belated review of this 2001 train-wreck of a movie.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Swordfish
https://cdn-images-1.medium.com/max/1000/1*OTQBC5NyZDAEk28f5mkUpQ.jpeg
He can sing, he can dance, but can Hugh Jackman hack? Find out in my long belated review of this 2001 train-wreck of a movie.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Swordfish
He can sing, he can dance, but can Hugh Jackman hack? Find out in my long belated review of this 2001 train-wreck of a movie.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Passive Reconnaissance Using Only Kali Terminal | Infosec |
https://cdn-images-1.medium.com/max/1920/1*fEhrN19N3AXLe7afEEYDSQ.png
Disclaimer: This blog is only for educational purpose.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Passive Reconnaissance Using Only Kali Terminal | Infosec |
https://cdn-images-1.medium.com/max/1920/1*fEhrN19N3AXLe7afEEYDSQ.png
Disclaimer: This blog is only for educational purpose.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Passive Reconnaissance Using Only Kali Terminal | Infosec |
Disclaimer: This blog is only for educational purpose.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
What’s To Stop Twitter’s New Owner From Publishing The Company’s Historical Internal Emails?
https://cdn-images-1.medium.com/max/600/1*ypEO_JnNfWQWQADd0WwXbA.png
Selective Leaks of Previous Discussions & Policy Debates In The Name of ‘Transparency’ Would Put Twitter Employees At Risk
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
What’s To Stop Twitter’s New Owner From Publishing The Company’s Historical Internal Emails?
https://cdn-images-1.medium.com/max/600/1*ypEO_JnNfWQWQADd0WwXbA.png
Selective Leaks of Previous Discussions & Policy Debates In The Name of ‘Transparency’ Would Put Twitter Employees At Risk
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
What’s To Stop Twitter’s New Owner From Publishing The Company’s Historical Internal Emails?
Selective Leaks of Previous Discussions & Policy Debates In The Name of ‘Transparency’ Would Put Twitter Employees At Risk
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Hacking IPMI and Zabbix in HackTheBox — Shibboleth
https://cdn-images-1.medium.com/max/1400/1*PTft7givWyB1L9cav7nrZw.png
Port Scanning
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Hacking IPMI and Zabbix in HackTheBox — Shibboleth
https://cdn-images-1.medium.com/max/1400/1*PTft7givWyB1L9cav7nrZw.png
Port Scanning
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Hacking IPMI and Zabbix in HackTheBox — Shibboleth
Port Scanning
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Daily Bugle
https://cdn-images-1.medium.com/max/1073/0*WHPwSCtRUIsJUYUp
Makineye erişim sağlayabilirsiniz.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Daily Bugle
https://cdn-images-1.medium.com/max/1073/0*WHPwSCtRUIsJUYUp
Makineye erişim sağlayabilirsiniz.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Daily Bugle
Makineye erişim sağlayabilirsiniz.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Hacker Steals Over $620 Million From Axie Infinity’s Ronin Sidechain
https://cdn-images-1.medium.com/max/1920/1*lOEy_SP0sJ_ylNl6VE2GWw.png
Hack on Sidechain Ethereum Ronin : this becomes the second largest in the history of cryptocurrencies.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Hacker Steals Over $620 Million From Axie Infinity’s Ronin Sidechain
https://cdn-images-1.medium.com/max/1920/1*lOEy_SP0sJ_ylNl6VE2GWw.png
Hack on Sidechain Ethereum Ronin : this becomes the second largest in the history of cryptocurrencies.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Hacker steals over $620 Million from Axie Infinity’s Ronin sidechain
Hack on Sidechain Ethereum Ronin : this becomes the second largest in the history of cryptocurrencies.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
MEPMS (Mission-Extensive-Profile-Management-System)-A concept Model
https://cdn-images-1.medium.com/max/1556/1*gpiRGJbMskFZ2_FHjz1fWg.png
Problem-statement
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
MEPMS (Mission-Extensive-Profile-Management-System)-A concept Model
https://cdn-images-1.medium.com/max/1556/1*gpiRGJbMskFZ2_FHjz1fWg.png
Problem-statement
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
MEPMS (Mission-Extensive-Profile-Management-System)-A concept Model
Problem-statement