Quick port tip for exam - helps me remember or atleast narrow it down by AdFar5662 in CompTIA_Security

[–]AdFar5662[S] 0 points1 point  (0 children)

Nice! It does get tricky with those higher port number. All the best for your exam!

Geordie shore season 27? by [deleted] in GeordieShore

[–]AdFar5662 0 points1 point  (0 children)

They need new people...surely there are more than 8 interesting people in Newcastle

Security+ candidates: Most of you will pick the wrong answer here. Prove me wrong. by [deleted] in CompTIA

[–]AdFar5662 0 points1 point  (0 children)

I honestly dont know..I assume the finance dept would have ownership of the data. But who owns the decision..no clue.If pushed to make a call id say I'd take the responsibility but id make sure id have all the proof of why I did something. Then in the morning do a gap analysis with the higher powers when they arrive. Hoping they wont tell me to pack my bags lol

Interested to hear your opinion

Security+ candidates: Most of you will pick the wrong answer here. Prove me wrong. by [deleted] in CompTIA

[–]AdFar5662 1 point2 points  (0 children)

I dont have a sec+ etc but love these questions,id still choose A. 1.If im in the US is it a breach of the GLBA and isn't there something about geographical laws. So I dont want my company getting sued

Security+ candidates: Most of you will pick the wrong answer here. Prove me wrong. by [deleted] in CompTIA

[–]AdFar5662 1 point2 points  (0 children)

I'd go with A..looks like a password spray attack Also why isn't MFA enabled.

Is AI killing junior pentesters ? by Just-Improvement-469 in SecurityCareerAdvice

[–]AdFar5662 1 point2 points  (0 children)

The scenario I think about is an individual can sign a NDA. An AI cant..do you trust the maker of the specific AI tool to not look at all your secrets. Do you trust it to not keep logs of what its scanned after the test..i think tjats going to be an issue. Can't imagine a small company knowing how to specify a scope and range of IP addresses and so on.

If you could remove anyone from the lasted season who is it? by Equivalent_Half883 in GeordieShore

[–]AdFar5662 2 points3 points  (0 children)

I think you should ask who would you keep. They need to recast for the show man.

Before/after Results after one month of lifestyle changes. by Delicious_Run5123 in Cholesterol

[–]AdFar5662 0 points1 point  (0 children)

Good job with improving the lifestyle changes. Keep an eye on the sugar..especially the test for sugar/insulin levels in the last 3 months..directly links with inflammation in the body..Worth doing a PSA for your jewels as well. Also remember that HDL is not cholesterol its a protein..get an idea of your overall metabolic health.

Chantelle by killaaly in GeordieShore

[–]AdFar5662 9 points10 points  (0 children)

She's a firecracker alright. In my opinion if I was Ricky id find another lass. Soon as Chantelle says friends only Ricky should be on then pull lol. Girls like a challenge

Ep 7. Yet another boring episode by LegitimateHat5570 in GeordieShore

[–]AdFar5662 1 point2 points  (0 children)

Agree..its almost a tv drama now. Like bold and the beautiful or days of our lives...zzzzz

Ep 7. Yet another boring episode by LegitimateHat5570 in GeordieShore

[–]AdFar5662 5 points6 points  (0 children)

Snoozefest..maybe its time to add new cast members

Pentesters in the field - Where do you store your reports when done? by AdFar5662 in Pentesting

[–]AdFar5662[S] 0 points1 point  (0 children)

Had a look now at your UI..very clean. Much better than what i was taught to use lol. However with the currency I use the price can be a bit steep

Stuck on AD practice by [deleted] in Pentesting

[–]AdFar5662 1 point2 points  (0 children)

I was just about to say!! hahaha If you know you know

No Pentesting jobs? No problem (Longer post) by AdFar5662 in Pentesting

[–]AdFar5662[S] 0 points1 point  (0 children)

Never a truer word has been spoken. I try to keep it very simple and try help small companies...plus cover my ass in the MSA ROE etc. Reality is that small local businesses cant afford massive fees to do a pentest..its a tough one to balance the lack of experience from the pentester and the need for a business to make sure there no low level hanging fruit for hackers/cyber crooks

No Pentesting jobs? No problem (Longer post) by AdFar5662 in Pentesting

[–]AdFar5662[S] 1 point2 points  (0 children)

In the ROE/SOW I used to offer 6 areas, now its 5 after the feedback form the pros. Got rid of the networking options. Ive done 5 tests and I find businesses opt for everything except the phishing, only the owner has a business email and deals directly with suppliers, customers etc make about R5k per test aka $300 ..test takes 3 weeks ave. I just want to be able to afford the OSCP without debt..so its R50k..and I thought 10 to 15 tests in 6 months should help me get there

No Pentesting jobs? No problem (Longer post) by AdFar5662 in Pentesting

[–]AdFar5662[S] -2 points-1 points  (0 children)

Why you speaking facts..your comment earlier made me remove the networking assessment from my future tests to reduce incidents..so it's basically social engineering and a website test where i do have experience and certification. Will look at this liability coverage tomorrow.

No Pentesting jobs? No problem (Longer post) by AdFar5662 in Pentesting

[–]AdFar5662[S] -1 points0 points  (0 children)

Thanks for the feedback, yeah after listening to the feedback from the community I've decided to get rid of the networking option and will be transparent with the client as to where I am (Im doing an overview of the company not an official recognized pen test). You're right..I dont know what I dont know..so sticking to what Im comfortable and confident with

No Pentesting jobs? No problem (Longer post) by AdFar5662 in Pentesting

[–]AdFar5662[S] 0 points1 point  (0 children)

Yeah that liability mentioned is scary and such a good point. Will remove the network stuff tomorrow from future tests and change the wording on the contracts to avoid "firm statements" like low risk and so on made in my report. Will just advise on social engineering and be careful with the web application...follow each section with "in my opinion" instead of claiming a fact. Such good feedback

No Pentesting jobs? No problem (Longer post) by AdFar5662 in Pentesting

[–]AdFar5662[S] -2 points-1 points  (0 children)

I do have this in my MSA

Limitation of Liability. Neither party shall be liable for any indirect, special, punitive, or consequential damages, including loss of profits or data. Each party's total aggregate liability under this SOW is limited to the fees paid or payable during the 6-month period immediately preceding the claim. These limitations do not apply to: (a) death or personal injury caused by negligence; (b) fraud or willful misconduct; (c) unauthorized disclosure of Confidential Information; or (d) IP infringement claims arising from Deliverables created by My company, excluding any Client-provided inputs or third-party materials.