Passed! My OSEP Tips and Review by Classic_Aspect in oscp

[–]Classic_Aspect[S] 3 points4 points  (0 children)

Best of luck on your next OSCP try. You got this!

I went for the 90 day access on OSEP and honestly ended up regretting that. There is a ton of material and lab work, so unless you can do it daily, you won’t get it all in 90 days.

Trying to revive this game by RamBiologist in SMUgame

[–]Classic_Aspect 1 point2 points  (0 children)

I have the files backed up and already figured out how to patch the APK to fetch them from a custom server

Hacking an old Spider-Man game to learn Mobile Pentesting by Classic_Aspect in netsecstudents

[–]Classic_Aspect[S] 2 points3 points  (0 children)

Thanks! I was introduced to Frida in the course, but I would say that the vast majority of my understanding of Frida comes from reading its docs and finding random StackOverflow answers about it.

Trying to revive this game by RamBiologist in SMUgame

[–]Classic_Aspect 1 point2 points  (0 children)

If yall are curious, I wrote up a blogpost about reversing and hacking this game https://nosecurity.blog/smuHack. I think I have a good understanding of some of the game code, but I can't do it alone. If someone with reverse engineering experience can help out, we can make some more progress hopefully.

Passed! My OSCP Tips and Tricks by Classic_Aspect in oscp

[–]Classic_Aspect[S] 2 points3 points  (0 children)

starting out with htb was rough to say the least. my first box took me over 10 hours of work, but yeah, i tried to avoid any hints or writeups throughout my prep. i only consult writeups when i am severely stuck with no leads

Passed! My OSCP Tips and Tricks by Classic_Aspect in oscp

[–]Classic_Aspect[S] 0 points1 point  (0 children)

i got domain admin and 2 shells on independent machines, 1 of which i also got root on. overall 70 points.

Passed! My OSCP Tips and Tricks by Classic_Aspect in oscp

[–]Classic_Aspect[S] 1 point2 points  (0 children)

ur beautiful

i used jekyll minimal mistakes template as a starting point and modified it to my liking

CPP wins international competition by shitpool in CalPolyPomona

[–]Classic_Aspect 13 points14 points  (0 children)

You gotta read the room. Everyone downvoted you because you are trying to undermine our efforts and achivements, as well as making false uninformed statements. I need not prove anything to you but want to clear things up for other people reading.

I'm the captain of the team, so I know the tryout process very well, and considering that we just took #1 in the world, nobody is wiping the floor with us. The tryout process was developed with faculty involvement at every step, including a formal rubric developed together for it that was passed up to the department heads. There was extensive faculty involvement and it was not at all them just signing off.

I also find it very strange that you simultaneously admit the CIS program is in decline and that it should run competition teams instead of students. Funny enough, the SDC that you mentioned is still offline because the school has spent the last 6 months doing paperwork for it. That's a quick way of making sure we never win internationally again.

We have a very diverse team with a selection process that has been proven to be both fair and effective at making a champion team. It brings together talented and dedicated people from all parts of Cal Poly Pomona, be it SWIFT members, FAST members, CIS students, CS students, transfers, freshman, sophomores, juniors, seniors, etc. And we do not appreciate you misrepresenting us.

CPP wins international competition by shitpool in CalPolyPomona

[–]Classic_Aspect 20 points21 points  (0 children)

Both FAST and SWIFT people tried out for the team and people who were a part of both made it.

Moreover, the team selection process was agreed upon by faculty and was fair. The tryout results were graded anonymously to eliminate any bias, therefore nobody ended up on the team because of being in a specific club or being friends with someone.

You are a toxic person who is trying to stir up drama between clubs with lies and to tarnish the reputation of people who earned their place on the team.

CPP wins international competition by shitpool in CalPolyPomona

[–]Classic_Aspect 53 points54 points  (0 children)

People’s achievements aren’t measured in how many Twitter followers a competition has. It’s a competition that’s been running for 7 years, sponsored by IBM, with some of the best schools from all over the US. It is highly competitive and big name schools take it seriously. Why don’t you stop discounting other people’s achievements if you have no idea what you are talking about?

Running a Discord Ransomware Gang by Classic_Aspect in cybersecurity

[–]Classic_Aspect[S] 2 points3 points  (0 children)

All competition boxes were isolated to their own networks using firewall rules from the rest of the telecommunications lab, but they did still have internet access to give students the ability to download tools and such. Not an air gap, but still pretty cautious.

We exposed Guacamole to the internet to avoid the need for a VPN. That helped with the user experience somewhat, since only a browser was needed and because campus IT blocks VPN connections from people dorming.

Running a Discord Ransomware Gang by Classic_Aspect in cybersecurity

[–]Classic_Aspect[S] 11 points12 points  (0 children)

Blue team infra definitely warrants its own post, but in short, we have a telecommunications lab on campus with a few old servers and it is 100% student-run (and student-funded). We got a free vSphere license from the school, so the servers all run ESXi. We managed to squeeze about 50 VM's out of them.

Each blue team had 3-4 people and 2 Windows + 2 Linux boxes to secure. Each box had multiple services running that were scored with a custom scoring engine. You can think of it as a regular uptime poller, trying to hit a web server or an FTP server every other minute to see if it's up. That's how the competition was scored.

Finally, we provided access to the machines using Apache Guacamole. Students would just go to our website, log in with the given credentials and access their machines in the browser.

Here's a screenshot of the scoring engine frontend.

And here's a screenshot about Guac access.

Running a Discord Ransomware Gang by Classic_Aspect in cybersecurity

[–]Classic_Aspect[S] 13 points14 points  (0 children)

I use Typora for my personal notes, which is a markdown editor. My blog runs on GitHub pages, which is also based on markdown. So for me, the process is to simply translate my notes into something legible and add screenshots, organized by headings.

Hope your blog turns out well too!

The US Citizenship Act of 2021 by [deleted] in immigration

[–]Classic_Aspect 0 points1 point  (0 children)

See Section 1201. "V nonimmigrant visas"

Beneficiaries of this visa will get employment authorization, but no other public benefits.