226
9
submitted 2 years ago by [email protected] to c/[email protected]

Weekly thread for any and all career, learning and general guidance questions. Thinking of taking a training or going for a cert? Wondering how to level up your career? Wondering what NOT to do? Got other questions? This is the time and place to ask!

227
15
submitted 2 years ago by [email protected] to c/[email protected]

I am currently trying to learn cyber security, specifically pentesting. I also do blue team things now and then, but not too often. I've started about 2 years ago with programming in python, later golang. I feel like I am decent in both. However when it comes to pentesting and security in general. It doesn't feel like I'm doing progress whatsoever. I know about theoretical Linux, networking, programming and that stuff, but when it comes to the hands on tasks, I fail miserably. I know know how HTTP works, but can't do easy Hack the Box CTFs without a complete writeup (not just little hints). I solved a few CTFs on different platforms with the help of writeups because I thought I just lacked the creative thinking part, but I don't see any progress. And when I feel like doing CTFs, I quickly loose motivation because I don't get anything done. Can anyone relate? How can I overcome this?

228
7
submitted 2 years ago by [email protected] to c/[email protected]
229
2
submitted 2 years ago by [email protected] to c/[email protected]

Weekly thread to discuss whatever you’re working on, big or small, at work or in your free time.

230
6
submitted 2 years ago by [email protected] to c/[email protected]

Weekly thread to discuss industry certifications, trainings and other courses/learning. Ask questions, share your experiences and help others!

231
3
submitted 2 years ago by [email protected] to c/[email protected]

Weekly thread for any and all career, learning and general guidance questions. Thinking of taking a training or going for a cert? Wondering how to level up your career? Wondering what NOT to do? Got other questions? This is the time and place to ask!

232
4
submitted 2 years ago by [email protected] to c/[email protected]
233
8
submitted 2 years ago by [email protected] to c/[email protected]
234
3
submitted 2 years ago by [email protected] to c/[email protected]

From the video description:

Legendary cyber-security expert Professor Gene Spafford joins us to try to define what cyber-security even is! "Spaf" as he's known, is a faculty member at Purdue University and now Honorary Professor at the University of Nottingham.

Dr Spafford is a Fellow of the American Academy of Arts and Sciences, the Association for the Advancement of Science, the ACM, the IEEE, and the (ISC)2; a Distinguished Fellow of the ISSA; and a member of the Cyber Security Hall of Fame, the only person to ever hold all these distinctions.

The book "Cybersecurity, Myths and Misconceptions" can be found here: https://bit.ly/C_CyberMythsBook

235
4
submitted 2 years ago by [email protected] to c/[email protected]

Weekly thread to discuss whatever you’re working on, big or small, at work or in your free time.

236
50
submitted 2 years ago by [email protected] to c/[email protected]

I read most of this article trying to determine if I was impacted, so to save you the trouble:

The researchers traced the keys they compromised to devices that used custom, closed-source SSH implementations that didn’t implement the countermeasures found in OpenSSH and other widely used open source code libraries.

237
3
submitted 2 years ago by [email protected] to c/[email protected]

Weekly thread to discuss industry certifications, trainings and other courses/learning. Ask questions, share your experiences and help others!

238
7
submitted 2 years ago by [email protected] to c/[email protected]

Weekly thread for any and all career, learning and general guidance questions. Thinking of taking a training or going for a cert? Wondering how to level up your career? Wondering what NOT to do? Got other questions? This is the time and place to ask!

*Better late than never I say. Sorry folks!

239
9
submitted 2 years ago by [email protected] to c/[email protected]

Hello!

I'm working as a pentester/RT Operator in a cybersecurity company, which for some reason is a Windows shop, so we are mostly forced to work within VMWare VMs, WSL and similar. However, I've recently found out that we can in fact dualboot or reinstall our laptops, so I'm now looking for a good setup or recommended distros to use.

When I last tried switching to Fedora, my main issue was that since we are deeply integrated into O365, and our Exchange server isn't configured to allow 3rd party apps (and we can't create app passwords), accessing Teams, Mail or just writing reports in Office was a struggle. And another issue was the fact that our PT VPN is Checkpoint, which I did not manage to get working on Linux.

I'm of course familiar with Kali/Parrot/BlackArch, but I would not consider those fitting for a daily driver - each engagement can get pretty messy, and I think it's better to start with a fresh VM for every customer, just to avoid any potential issues.

I've recently discovered QubeOS, which in theory sounds like it should be perfect for this usecase - you can easily separate data for different customers, keep them safe in a storage qube, deal with per-customer networking/different VPNs in their respective Kali VM qubes, and spin up a Windows qube for report writing and backoffice/administration/communication. And if I really understand it correctly, it should also be possible to easily test out malware in a separate disposable qube without much risk.

But I didn't try working with QubeOS yet, so all of this is just a theory based on my understanding of it's features and usecases.

So, my question would be - what kind of setup do you use for engagements and backoffice/administrative work? What distro would you recommend, that works well with running different VMs without it being too much of a hassle? And most importantly, is there anyone who uses QubeOS in this field of work, or will it only slow me down and make everything a lot harder than it should be?

Thank you!

240
5
submitted 2 years ago by [email protected] to c/[email protected]
241
5
submitted 2 years ago by [email protected] to c/[email protected]
242
4
Chinese APT Targeting Cambodian Government (unit42.paloaltonetworks.com)
submitted 2 years ago by [email protected] to c/[email protected]
243
9
submitted 2 years ago by [email protected] to c/[email protected]

Weekly thread to discuss whatever you’re working on, big or small, at work or in your free time.

244
33
submitted 2 years ago by [email protected] to c/[email protected]
245
1
submitted 2 years ago by [email protected] to c/[email protected]

Weekly thread to discuss industry certifications, trainings and other courses/learning. Ask questions, share your experiences and help others!

246
15
submitted 2 years ago by [email protected] to c/[email protected]
247
2
submitted 2 years ago by [email protected] to c/[email protected]

Weekly thread for any and all career, learning and general guidance questions. Thinking of taking a training or going for a cert? Wondering how to level up your career? Wondering what NOT to do? Got other questions? This is the time and place to ask!

248
22
submitted 2 years ago by [email protected] to c/[email protected]

I'm working on a guide focused on securing Linux servers and I'd like to ask you what your essential hardening techniques and tips are? Your feedback would be greatly appreciated

249
43
submitted 2 years ago by [email protected] to c/[email protected]
250
3
submitted 2 years ago by [email protected] to c/[email protected]

Weekly thread to discuss whatever you’re working on, big or small, at work or in your free time.

view more: ‹ prev next ›

cybersecurity

4413 readers
7 users here now

An umbrella community for all things cybersecurity / infosec. News, research, questions, are all welcome!

Community Rules

Enjoy!

founded 2 years ago
MODERATORS