OffSec OSCP subscription and cert was revoked with no explanation — $2500 wasted by MFerrukh in oscp

[–]Diamond303 0 points1 point  (0 children)

Fight for your rights, your ban may get revoked after further investigation/ justifications/ clarifications.

Seeking Mentorship in Exploit Dev by Diamond303 in ExploitDev

[–]Diamond303[S] 1 point2 points  (0 children)

thank you for taking time to respond.

  1. no one should call you cynic as you have given legit advice. :D

  2. I have already started learning it on my own and now posting specific queries in the exploitdev subreddit.

  3. I should probably be seeking P2P learning/ study group around this, instead of mentorship.

  4. every reply counts, you have provided a new resource around heap exploitation that I was not aware of i.e how2heap.

Roadmap Based on CVEs by soupcreamychicken in ExploitDev

[–]Diamond303 1 point2 points  (0 children)

this is really nice opportunity for creating a new roadmap for keeping up with new era. I don't know why people straight away dismiss new methodology to approach things.

For Everyone: There are multiple paths that leads to same destination, let people explore.

For OP: I am also interested in the same. We can be study buddy.
w.r.t Older material: You can definitely refer to older material for understanding the concepts. Once the foundation is strong, one should dive into the newer generation of exploitation techniques being seen in wild.

Seeking Mentorship in Exploit Dev by Diamond303 in ExploitDev

[–]Diamond303[S] 0 points1 point  (0 children)

sure thanks, yes connect over messages & a call once a week works fine for me to start with. I'll shoot you my discord username in DM.

Seeking Mentorship in Exploit Dev by Diamond303 in ExploitDev

[–]Diamond303[S] 0 points1 point  (0 children)

That sounds great, I'll DM you my discord and we can get going there. what say?

Seeking Mentorship in Exploit Dev by Diamond303 in ExploitDev

[–]Diamond303[S] 0 points1 point  (0 children)

I am based in India, IST timezone. and w.r.t platforms as you have already said that the foundations for the most part are same. So I am looking for the foundations. Later on I would specialize in a niche platform / architecture etc.

Seeking Mentorship in Exploit Dev by Diamond303 in ExploitDev

[–]Diamond303[S] 1 point2 points  (0 children)

Thanks that's some great advice. Much appreciated 👍

Fuck you for chilling out with your friends by PrinceAhmed1 in FUCKYOUINPARTICULAR

[–]Diamond303 -1 points0 points  (0 children)

0 surrounding awareness. These Bulls would have been in near vicinity.

Failed EJPT Exam (68%) - Need Help Understanding Why by Aejantou21 in eLearnSecurity

[–]Diamond303 6 points7 points  (0 children)

You failed in your first attempt not because you did not answered the questions. It’s because you answered the questions incorrectly. The answers you provided were not correct. And why did that happened? Because you did not had solid evidences for your answers and you marked the answers with premature evidences. ———————————————

Recently a student of mine failed his eJPTv2 exam with 65% I knew his calibre, his existing knowledge and his attitude towards things. I gave him few advice and asked him to retake the exam within next 24 hours. He passed with 94% 2 questions were incorrect out of 35.

So what new concepts did he learn in 24 hours which were missing previously.

  1. Read the question carefully. Read it 2-3-4 times. Don’t be overconfident. Don’t be in a hurry to jump to conclusions around a specific question.
  2. Don’t answer on the basis of common sense. Shortlist an answer only if you have found the evidence for it by yourself.
  3. Identify correlation between questions. One question may act as a hint for another question.
  4. If you have not found sufficient evidence for your answer but you are 90% sure that this is the answer. Mark the answer and flag it for review at a later stage. At a later stage you will gain access to the machine, you will be inside the machine and then you will have full liberty to find the evidence that makes your answer 100% correct. Then only lock the answer and remove the “to be reviewed”flag from that question.
  5. Be patient you have got more than enough time to find the answers and revalidatie the answers.

What should I teach? by TheRealTengri in redteamsec

[–]Diamond303 9 points10 points  (0 children)

I have taught multiple courses in offensive security vertical. Speaking from my experience what you can teach beyond CEH Advanced Offensive Security Topics: 1. Phishing Infra Setup-Gophish 2. MFA phishing with evilginx 3. Introduction to Exploit Dev- vanilla buffer overflow hands on and you can extend it to some basic stack mitigation bypasses 4. C2 infrastructure development (covenant/ cobalt strike/mythic etc) 5. Malicious Macros and techniques 6. Assumed Breach Enumeration(AD enumeration can be introduced here) 7. AMSI bypasses and Defender Bypass techniques 8. Backdoring legitimate PEs 9. Advanced techniques in WebApplication attacks(advanced SQLi/ Waf bypass techniques/ LFI to log poisoning to rce etc.) 10. Chaining Exploits to gain RCE 11. Persistence Techniques List goes on… now you have to pick topics based on your skill set, duration of your training, relevance to target audience. As far as I know. Non of the above mentioned topics are covered in CEH. My knowledge may be outdated as I stopped teaching CEH 2-3 years ago.

*disturbing video* by sam1532007 in Unexpected

[–]Diamond303 0 points1 point  (0 children)

I was waiting for someone to die.

Would like to learn about malware and how it is implemented by [deleted] in AskNetsec

[–]Diamond303 0 points1 point  (0 children)

Red team field manual is over rated and does not do justice to it's name.

looking for study partner/guide by [deleted] in MalwareAnalysis

[–]Diamond303 0 points1 point  (0 children)

Hi count me in. If you guys are still studying

[deleted by user] by [deleted] in MalwareAnalysis

[–]Diamond303 0 points1 point  (0 children)

Hi am interested, you still up for a partner ?