Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
Cloudflare Expands Relationship With Microsoft
Cloudflare Expands Relationship With Microsoft
Dark Reading: Attacks/Breaches
SailPoint Acquires SecZetta to Provide Comprehensive Identity Security for Non-Employee Identities
This move accelerates the company’s vision of becoming the de facto identity security platform of choice for the modern enterprise.
SailPoint Acquires SecZetta to Provide Comprehensive Identity Security for Non-Employee Identities
This move accelerates the company’s vision of becoming the de facto identity security platform of choice for the modern enterprise.
Yet another litany of "dumb" & "googlable" questions from a wanna-be red team member
https://www.reddit.com/r/redteamsec/comments/10abbzb/yet_another_litany_of_dumb_googlable_questions/
<!-- SC_OFF -->Background: I'm just a typical developer who aspires to be red team one day. I'm studying for the cissp and would like to eventually become a red team member for the government. I have some credentials that allow me to work in this space but I want to Branch out from development and be more active in cyber security. I am AWS certified and after the cissp I will get the security certification from AWS. Has anyone tried a Portapack H2 Mayhem (RFOne knock off I think)? Just curious if anyone has tried this device. I saw it on eBay for 240 bucks and I've got some money burning a hole in my wallet so I thought I might take a look at it, see what I can see with it. Reportedly it goes up to 40 MHz to 6 GHz. I don't think I'd ever be required to use it for any reason but it might be fun to play with and at least learn something that you guys know by heart. A. Should I just bite the bullet and get an RFOne off Hak5? In your professional opinion, what certifications might teach & test for the most useful skills? 2.A. Ones that are respected the most within the industry? Where might be sandboxes that I can use to hone my skills without getting sued or breaking the law? 3.A. in your opinion, what might be the best training ground to use to learn these skills? Is bug crowd one might use to practice and actively work on offensive security techniques? I signed up and it seems like they just released the client requirements then let you get at it hacking the client based on their specifications. You find anything you write the report and submit it and then wait and see if it's accepted. My previous question to this Reddit was concerning physical security, having learned that that is not a high demand skill, that leaves me internet and networking exploits to learn. In your opinion how would you go about learning everything you can about the tools and techniques for that facet of information security? RTFM, I know but I need a safe place to do so without breaking the law for any reason or inadvertently causing damage. I would not do anything to any system that has not given me express permission to do so. That's pretty obvious. I genuinely want to learn and become a white hat red team member and I'm willing to do what it takes, this is why I'm asking for your opinion as to where to get started. Thanks I'm sorry to annoy some here but a little guidance from professionals in the field would at least clue me in on where I need to start besides Google. Any advice you can provide is greatly appreciated. <!-- SC_ON --> submitted by /u/mikealicious- (https://www.reddit.com/user/mikealicious-)
[link] (https://www.reddit.com/r/redteamsec/comments/10abbzb/yet_another_litany_of_dumb_googlable_questions/) [comments] (https://www.reddit.com/r/redteamsec/comments/10abbzb/yet_another_litany_of_dumb_googlable_questions/)
https://www.reddit.com/r/redteamsec/comments/10abbzb/yet_another_litany_of_dumb_googlable_questions/
<!-- SC_OFF -->Background: I'm just a typical developer who aspires to be red team one day. I'm studying for the cissp and would like to eventually become a red team member for the government. I have some credentials that allow me to work in this space but I want to Branch out from development and be more active in cyber security. I am AWS certified and after the cissp I will get the security certification from AWS. Has anyone tried a Portapack H2 Mayhem (RFOne knock off I think)? Just curious if anyone has tried this device. I saw it on eBay for 240 bucks and I've got some money burning a hole in my wallet so I thought I might take a look at it, see what I can see with it. Reportedly it goes up to 40 MHz to 6 GHz. I don't think I'd ever be required to use it for any reason but it might be fun to play with and at least learn something that you guys know by heart. A. Should I just bite the bullet and get an RFOne off Hak5? In your professional opinion, what certifications might teach & test for the most useful skills? 2.A. Ones that are respected the most within the industry? Where might be sandboxes that I can use to hone my skills without getting sued or breaking the law? 3.A. in your opinion, what might be the best training ground to use to learn these skills? Is bug crowd one might use to practice and actively work on offensive security techniques? I signed up and it seems like they just released the client requirements then let you get at it hacking the client based on their specifications. You find anything you write the report and submit it and then wait and see if it's accepted. My previous question to this Reddit was concerning physical security, having learned that that is not a high demand skill, that leaves me internet and networking exploits to learn. In your opinion how would you go about learning everything you can about the tools and techniques for that facet of information security? RTFM, I know but I need a safe place to do so without breaking the law for any reason or inadvertently causing damage. I would not do anything to any system that has not given me express permission to do so. That's pretty obvious. I genuinely want to learn and become a white hat red team member and I'm willing to do what it takes, this is why I'm asking for your opinion as to where to get started. Thanks I'm sorry to annoy some here but a little guidance from professionals in the field would at least clue me in on where I need to start besides Google. Any advice you can provide is greatly appreciated. <!-- SC_ON --> submitted by /u/mikealicious- (https://www.reddit.com/user/mikealicious-)
[link] (https://www.reddit.com/r/redteamsec/comments/10abbzb/yet_another_litany_of_dumb_googlable_questions/) [comments] (https://www.reddit.com/r/redteamsec/comments/10abbzb/yet_another_litany_of_dumb_googlable_questions/)
Let’s hunt some bugs 🔍Continue reading on Pods » (https://blog.pods.finance/pods-bug-bounty-v2-993cd7ad69e0?source=rss------bug_bounty-5)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Deep Web
what should my security be on tor browser ?
out of the three options wich one should i use and what could happen if i use the first one ?
submitted by /u/ageneric_pybro
[link] [comments]
what should my security be on tor browser ?
out of the three options wich one should i use and what could happen if i use the first one ?
submitted by /u/ageneric_pybro
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Ducky script/snippet to send a sequence of modifier keys?
Hey!, not sure if this is the right place to post this question but some googling around pointed me to this forum so hopefully someone can point me in the right direction.
I have a KVM that is controlled by a sequence of keys and I want to try to automate its use (by integrating it with Home Assistant). Following this project here I managed to get a Ducky-like device that can receive commands from a network. When I connect it to my computer it works perfectly. All good so far.
What I can't figure out however is how to send sequence of modifier keys. The one I'm trying to mimic is hitting left control -> Releasing -> Left control again -> Release -> A number from 1 to 4.
All the examples I can find are about holding modifier keys while pressing something else or how to send just the Windows key without anything else but can't figure out how to script the sequence I need.
Any ideas?.
submitted by /u/Laucien
[link] [comments]
Ducky script/snippet to send a sequence of modifier keys?
Hey!, not sure if this is the right place to post this question but some googling around pointed me to this forum so hopefully someone can point me in the right direction.
I have a KVM that is controlled by a sequence of keys and I want to try to automate its use (by integrating it with Home Assistant). Following this project here I managed to get a Ducky-like device that can receive commands from a network. When I connect it to my computer it works perfectly. All good so far.
What I can't figure out however is how to send sequence of modifier keys. The one I'm trying to mimic is hitting left control -> Releasing -> Left control again -> Release -> A number from 1 to 4.
All the examples I can find are about holding modifier keys while pressing something else or how to send just the Windows key without anything else but can't figure out how to script the sequence I need.
Any ideas?.
submitted by /u/Laucien
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Can a hardware manufacturer track it's devices?
Hypothetically, if someone would order a windows laptop from the manufacturer, which got lost for 2 months in the shipping, and they would have retrieved the money back that they paid for it, and then it would show up one day and they don't mention this to the company; could the company find out that they are now using it, while keeping the refund? Do modern laptops have some kind of tracking that allows the manufacturer to track it's product? And i don't mean the windows finder function, that would be disabled, but the hardware. Could this person get in trouble, hypothetically?
submitted by /u/Hosentaschen_Mike
[link] [comments]
Can a hardware manufacturer track it's devices?
Hypothetically, if someone would order a windows laptop from the manufacturer, which got lost for 2 months in the shipping, and they would have retrieved the money back that they paid for it, and then it would show up one day and they don't mention this to the company; could the company find out that they are now using it, while keeping the refund? Do modern laptops have some kind of tracking that allows the manufacturer to track it's product? And i don't mean the windows finder function, that would be disabled, but the hardware. Could this person get in trouble, hypothetically?
submitted by /u/Hosentaschen_Mike
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Hacking Pedophiles
Basically I’m pretending to be an 11 year old disabled girl on chat avenue, many want to meet for sex.
I can get these idiots to click a link for pics and obtain there IP address anything I can do from there to find them and report them for predatory behaviour? Or at least scare them into not doing it again
submitted by /u/Junket_Turbulent
[link] [comments]
Hacking Pedophiles
Basically I’m pretending to be an 11 year old disabled girl on chat avenue, many want to meet for sex.
I can get these idiots to click a link for pics and obtain there IP address anything I can do from there to find them and report them for predatory behaviour? Or at least scare them into not doing it again
submitted by /u/Junket_Turbulent
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Doge Sound Club partners with Uppsala Security to enhance Web3 Security
https://cdn-images-1.medium.com/max/1200/1*orn5c4ajSu-9HiYehJTsag.png
Singapore, January 11th 2022 — Doge Sound Club, the first NFT project in South Korea, and Uppsala Security, a company specializing in…
Continue reading on Sentinel Protocol »
Doge Sound Club partners with Uppsala Security to enhance Web3 Security
https://cdn-images-1.medium.com/max/1200/1*orn5c4ajSu-9HiYehJTsag.png
Singapore, January 11th 2022 — Doge Sound Club, the first NFT project in South Korea, and Uppsala Security, a company specializing in…
Continue reading on Sentinel Protocol »