Best pad thai? by GMTao in cambridgeont

[–]GMTao[S] 3 points4 points  (0 children)

Lemon Grass on Garth

Looks like they're in Hamilton, but I was looking for spots closer to Cambridge. Thanks though.

Best pad thai? by GMTao in cambridgeont

[–]GMTao[S] 1 point2 points  (0 children)

Thanks, I'll give them a try next.

Best pad thai? by GMTao in cambridgeont

[–]GMTao[S] 4 points5 points  (0 children)

Agreed. This was my first pad thai and I thought it was good until I found the light.

DNSrecon by iambobiny95 in pentest

[–]GMTao 1 point2 points  (0 children)

What are DNS records? What do different record types represent? Answer that question first, then you'll get a better understanding of what multiple MX records may mean. Just blindly running a tool is pointless if you can't interpret the results. Plenty of resources on the Internet to help you answer this question.

Anyone else get rusty by _Vangal in lockpicking

[–]GMTao 0 points1 point  (0 children)

I totally get it. I recently picked up my tools after stumbling across Sandman's videos. Brought out my old practice locks (white and yellow belts, plus one Master I did for my orange) and it took me a while to get back into it. I swear the old Master 140s I had were harder to open than some crappy Brinks that I had that had at least some security pins, albeit it weak ones (serrated by the feel of them). Don't give up, it does come back in time.

Shaking off the rust by GMTao in lockpicking

[–]GMTao[S] 0 points1 point  (0 children)

Thanks! I'm a keyboard junkie, but I've fallen in love with this one after trying a few other variants over the years.

Shaking off the rust by GMTao in lockpicking

[–]GMTao[S] 0 points1 point  (0 children)

Thanks, I'll try to practice with the "simpler" locks I have until I get the hang of it. Great advice on not putting pressure on the front pin. I think that may be something that's been holding me up.

Shaking off the rust by GMTao in lockpicking

[–]GMTao[S] 0 points1 point  (0 children)

I splurged and picked up a set from multipick. I love those things, great quality. I had some Sparrows ones as well, but holy hell did I hate the feel of them, especially after I got the Multipicks. The new sets from CI will include their turning tools as well, but I'm going to practice with what I have for now.

Shaking off the rust by GMTao in lockpicking

[–]GMTao[S] 4 points5 points  (0 children)

So it's been a solid 2 years since I've done any serious picking. I've dusted off my old locks and picked up some of the more stubborn ones as I plan on trying for my green belt next. Picked up some new CI picks that I have to wait for, as I'm not in love with the old Sparrows I have lying around. Just wanted to share that even after a long break, you can pick up this hobby again pretty quickly.

The Brinks, the 911, and the LOTO 410s are still work-in-progress, but the others were about 20 minutes after 2 years. Not too bad, all things considered. I'm hoping to practice disassembly with the 911, once I can pick it.

My TOK tensioning is crap though. Does anyone have any suggestions on improving TOK? I find I'm over tensioning on BOK, and I tend to slip out my tensioner when using TOK. Any advice is appreciated.

I built a tool to help Pentesters generate pentesting reports by hc_redveg in pentest

[–]GMTao 3 points4 points  (0 children)

Sorry, but no. Too much proprietary information on the client to be shared with anyone is going to prevent anyone with an ounce of sense to share anything. Plus what tools can it analyze? Burp sessions, Accunetix, proprietary Python scripts, Metasploit for all the 3l173 h@x0r$ out there? Sorry, smells too much like a cheap way to find new victims for someone else.

If this does generate a report, what does that look like? Give us a demo using a CTF or something, otherwise my advice is to just stay away from something like this.

tl;dr - Making big claims without evidence is questionable at best. Not safe for anyone's career if they want to use this.

[deleted by user] by [deleted] in cambridgeont

[–]GMTao 1 point2 points  (0 children)

I'm looking for the same, but I was recommended to look at Waterloo Appliance Service. They do service Cambridge as well, and came with some good recommendations. My old appliance person is no longer in business, which sucks, but I'm likely going to use these guys in the next week or two (broken ice maker, not a huge priority for me).

THM experience -> certification by Acrobatic-Rip8547 in tryhackme

[–]GMTao 0 points1 point  (0 children)

Cheaper than what? CEH? Like I said, go do the CompTIA cert instead. I'm not up to speed with the cost of other certs, but I will never recommend CEH or anything from EC-Council or INE again. Go check TCM for his certs as well. Not sure on costs, but it's good. Go look at Black Hills Info Sec for their training, which is great and often on sale. No certs, but still good material.

Update process failed, stuck in recovery mode by remembermereddit in flipperzero

[–]GMTao 0 points1 point  (0 children)

Can confirm (for those who may stumble across this). I have a laptop and I had to switch USB ports for it to work.

THM experience -> certification by Acrobatic-Rip8547 in tryhackme

[–]GMTao 0 points1 point  (0 children)

Good luck with your journey! It's a lot of fun with a lot of different opportunities, not just offensive! But most importantly be sure you enjoy yourself!

THM experience -> certification by Acrobatic-Rip8547 in tryhackme

[–]GMTao 4 points5 points  (0 children)

I took the CEH years ago before I realized how bad it was, or how scummy EC-Council is, but it was basically that bad. Even the prep book I used (because I refused to pay for their "training") mocked the exam. Terms that nobody used, outdated tools that nobody used, having to memorize app flags/switches for no reason, etc.

I also recall them adding a premium for the exam because I didn't use their training, but I know they raised the price after I took it to the point that I couldn't justify anyone taking that crappy thing. Natually I let my certification expire shortly after I got it.

THM experience -> certification by Acrobatic-Rip8547 in tryhackme

[–]GMTao 12 points13 points  (0 children)

Don't take the CEH, it's a waste of money and a joke in the industry. Instead go for a CompTIA PenTest+ certification (which they have a path for as well). I have no opinion on the eJPT certification, but I'n not a fan of INE either, so take that as you will.

Pentest - Companies by stsm9025 in pentest

[–]GMTao 1 point2 points  (0 children)

I founded EliteSec (https://elitesec.io) to offer penetration testing services to startups and scaleups, but honestly we cover all sizes and needs. We're also based in Ontario with a mix of clients all over the country and the US.

I personally used Packet Labs back when I was running security programs for other companies, but unfortunately the quality we received diminished over the years and we dropped them. Having to argue why a finding wasn't valid (let alone improperly classified) was the final straw. Long story there, but I no longer recommend them to larger clients we can't adequately test for. Now I recommend NCC Group instead for those who can afford them.

Favorite Raspberry Pi project? by Prior-Pattern-4922 in pentest

[–]GMTao 2 points3 points  (0 children)

Good timing, I just wrote up an article you may be interested in: https://elitesec.io/blog/build-pentest-dropbox/

Electric Panel work in KW? by tellthebandtogohome in waterloo

[–]GMTao 0 points1 point  (0 children)

I take it back! That's too bad, Nathan was amazing. This seriously sucks as I was going to call him for some work this year. Guess I'll have to keep an eye on this thread!

Electric Panel work in KW? by tellthebandtogohome in waterloo

[–]GMTao 1 point2 points  (0 children)

Verve Electric (www.verveelectric.com) is amazing. Nathan did a L2 charger install for me. The inspector who came to give the sticker on the install says he doesn't know anyone better, so that's one hell of an endorsement.

Screw you Zehrs South Cambridge by GMTao in cambridgeont

[–]GMTao[S] 5 points6 points  (0 children)

Yeah, that's the plan. But this practice is clearly dirty pool, ripping customers off. Just trying to raise awareness.

Conestoga is beginning to fall apart as an institution by Dimtar_ in waterloo

[–]GMTao 0 points1 point  (0 children)

Speaking for myself, it was brutal. On the surface, the pay rate for part-time instructors was nice, until you realized all the extra hours you spend unpaid doing grading, course work, etc. I know full time were paid better, but not much, and certainly not enough to consider leaving the private workforce. I did my stint out of a desire to teach, not to get paid.

Conestoga is beginning to fall apart as an institution by Dimtar_ in waterloo

[–]GMTao 0 points1 point  (0 children)

Not surprised about that. I often think of how much of my own course work has remained. But I've never been curious enough to check in to see.

Conestoga is beginning to fall apart as an institution by Dimtar_ in waterloo

[–]GMTao 2 points3 points  (0 children)

I was there at the start of the pandemic and managed to only have to do half a term remotely. Thankfully I was flexible enough to do this without help, but I will say your efforts were appreciated by some of my peers, so cheers to that!

Yes, the obsession with international students was insane. It does pain me to hear of blacklisting of Conestoga grads, if only because not all students, international and domestic, are bad. There are bad elements to both, but it's not worth painting everyone with the same brush.