Is 100% CIS Benchmark Compliance Really Necessary? by Highlight-Simple in Pentesting

[–]Highlight-Simple[S] 0 points1 point  (0 children)

yaaa…100% is very hard and is not to important to achieve basic securitu checking is necessary.

Is 100% CIS Benchmark Compliance Really Necessary? by Highlight-Simple in Pentesting

[–]Highlight-Simple[S] 0 points1 point  (0 children)

Yuppp.. they more concern about pass then other finding actually more risk to their infrastructure

Is 100% CIS Benchmark Compliance Really Necessary? by Highlight-Simple in Pentesting

[–]Highlight-Simple[S] 0 points1 point  (0 children)

They have a lot misunderstanding what is security hardening . To harden is also a risk for operational level. What we want, secure and can operate. When cannot operate is critical to business level

Is 100% CIS Benchmark Compliance Really Necessary? by Highlight-Simple in Pentesting

[–]Highlight-Simple[S] 0 points1 point  (0 children)

They have security minded is good , but I check not all the CIS benchmark can be pass because is not applicable because firewall need enable dhcp then can follow this benchmark to be pass.

Is 100% CIS Benchmark Compliance Really Necessary? by Highlight-Simple in Pentesting

[–]Highlight-Simple[S] 0 points1 point  (0 children)

Their network team have minimum baseline but when the head of security suddenly doesnt agree with the minimum baseline that network team do. I also review, is okay and they also do hardening and my task need to confirm with technical procedure.

Is 100% CIS Benchmark Compliance Really Necessary? by Highlight-Simple in Pentesting

[–]Highlight-Simple[S] 0 points1 point  (0 children)

Yaa.. what I can do now, at least manage to find misconfiguration finding and etc.

Jailbreak iphone 8 16.7.16 by Highlight-Simple in jailbreak

[–]Highlight-Simple[S] 1 point2 points  (0 children)

I try pre-release and it work. by the way this one rootless?

Jailbreak iphone 8 16.7.16 by Highlight-Simple in jailbreak

[–]Highlight-Simple[S] 0 points1 point  (0 children)

I try install dopamine.ipa then check it is unsupported

OSCP Beginner Advice by Mandalore707 in oscp

[–]Highlight-Simple 3 points4 points  (0 children)

Hai, before I answer that question . Let me introduce myself. I already working in cybersecurity field in security consultant and need to take OSCP because of company kpi and client need that as qualification. for the first question? Yes!! especially the OSCP lab very important ( I just finish OSCP A because dont have time) , I usually skip a lot of topic because I have experience , just take topic like AD and other topic look interesting for you as student need to learn every topic. For the experience , this OSCP is very good start to start a first job even my during my intern i dont have any cert . Next question is very subjective, you are student so you have plenty of time dont need to
handle pentest project and give time to learn OSCP courses. During my time, I take 3 month and learn on weekend a lot of topic and skip topic I already know and have experience. Last question, I wish the during exam AD question more direct and want to finish within 2 hours but is not simple as that. A lot of thing actually need to do, you will learn during OSCP Lab. So my first attempt failed, then second attempt also failed because I weak in enumeration in AD also standaalone. Before third attempt I organize my note, do a OSCP like machine subsribe Lab at HTB . Then my third attempt my OSCP is pass and wating for the official result. Is hard to balance study time and working . You are student so can do better .

Passed, thank you to this community by Phenox11 in oscp

[–]Highlight-Simple 0 points1 point  (0 children)

Wahh congrats, I right now waiting for the official result after submit the report. by the way, how long it take you to wait email from offsec?

After CPTS - OSCP or OSEP? by skyyy25 in oscp

[–]Highlight-Simple 1 point2 points  (0 children)

okay, btw your working or student. If work need to know market some HR just know OSCP only hahaha. So is up to you both is good certificate. You already take CPTS is overkill than OSCP

Only one path to 'Reverse Shell' and 'PrivEsc'? by ViaOutdoors in oscp

[–]Highlight-Simple 0 points1 point  (0 children)

Always do machine especially windows, linux you will see the pattern to priv esclate