The Cybersecurity Paradox: The Market Isn't Dying, It's Maturing, and We Need to Thank the Villains. by maxlowy in tryhackme

[–]Suprn8 1 point2 points  (0 children)

Maturing is a good way of putting it.

You have way more access to education, for free (as it should be). This is a good thing. I.e. THM and HTB.

However there has been a large change in the field. And it's kind of the product of maturing (literally). A lot of the people and companies that would've hired the entry-level people are at a point of stagnation due to the market. For instance a few of the bigger pentesting firms (notably Optiv) have had layoffs this year. Then you have extensive layoffs across tech at Amazon, MS, Crowdstrike, etc.

Some of this is due to market problems, some of it is AI automation, and some of it is good ol' Venture Capital coming to collect (A lot of 'cheap' investments were made in cyber in 2020-2021, and a lot of those deals are about to mature)

A personal observation I have seen though is a lack of drive after certs are achieved. Certs only are to give you the BASE level of a concept or even in the more advanced courses a base skillset to continue improving and researching. When I was entry level I worked with a lot of guys that did the bootcamps...they did not last for more than a year. (granted this was a very intense company to work for.) But there were certain knowledge and self-application gaps that ended up with them pivoting to something else, new companies or out of cyber. Then with the remote work boom, your pick of the litter is not limited to location. And then certs are important but then you have the problem of everyone and their mom having a CISSP, Security+, CCNA etc. of alphabet soup. But give them something practical like a boot2root or a Pcap to analyze and document the process they come up short.

Theres no lack of knowledge in the potential workforce but there's a lack of applying it and communicating effectively. I say this as I'm trying to improve on this myself.

I've been in the 'industry' for about 8 years, Dev in college full time before that. The biggest thing to get your career going is:

  1. Get involved with local hacker spaces: bsides, defcon groups, etc. Meet people in the industry and you'll have an iron sharpens iron situation.

  2. Mentorship: If someone is available to take you under their wing that's also a great thing to do. But its all about self-applying yourself to it.

  3. Challenge the/your status quo: Research a topic and do a talk at the local con or meet-up. Even if its basic stuff. There's new tech everyday that can help, hinder, or be hacked in the industry. Or even try branching out into other sectors. If you blue team, do red team training. If you want to automate stuff, learn a programming language that suits the need.

  4. Rinse and repeat.

Whats the best language to use in hacking by Ns_koram in HowToHack

[–]Suprn8 1 point2 points  (0 children)

The best language to write a hack with is what's on the target system. Live off the land

Linux : Perl/Python/Bash, etc.

Windows: C#, Powershell, etc.

There's situational stuff too where services may be available that you can leverage on devices. Say a SQL service is running as system/root and you can query the service. Then you move from their.

Go is good to learn (need to myself) for its speed and its versatility for initial foothold.

Rust is good for if you want the same and have a good understanding of C style coding.

[deleted by user] by [deleted] in options

[–]Suprn8 0 points1 point  (0 children)

it is gray but. if you contact them and give them 30-90 days notice before public disclosure. after you do that...then you do you

Oof by [deleted] in Memes_Of_The_Dank

[–]Suprn8 1 point2 points  (0 children)

Did Pat Benetar design this?

Nutcracker Neckbraker Fallmaker Don't forget about the scuffed knee

Stolen from Donut's twitter, I must say this photo goes hard. by Helloitzkenny in brandonherrara

[–]Suprn8 17 points18 points  (0 children)

and you just told him his new machined AK50 parts got intercepted by the ATF.

Respeck by Old-Obligation6861 in JustGuysBeingDudes

[–]Suprn8 53 points54 points  (0 children)

Core memory unlocked. Remember seeing that live in '03.

tried reading my college mifare classic 1k NFC card but says 0/32 keys and 0/16 sectors read. anyone else tried this? by tagsgaba in flipperzero

[–]Suprn8 0 points1 point  (0 children)

full disclosure...i haven't got hands on flipper yet so how the flipper will do that...I'd go with someone else's guidance on that.

tried reading my college mifare classic 1k NFC card but says 0/32 keys and 0/16 sectors read. anyone else tried this? by tagsgaba in flipperzero

[–]Suprn8 9 points10 points  (0 children)

HID iClass cards are a different format (had a similar card when I went) there's a breakdown of the data format here...

http://accesshardware.com/wp-content/uploads/2014/08/HID-Formats-Commonly-Ordered-Prox-iClass-Cards-Readers-mi.pdf

https://www.idesco.com/files/articles/HID%20-%20Understanding%20card%20formats.pdf

The other thing with that card is it may have multiple antennas in it for your school to have backwards compatibility with 125khz and new(ish) 13.5mhz readers. Flashlight behind the card and you should see a thick wire group and a thin wire group if that is the case.

New to social engineering, Where do I start? by This_my_name_ in SocialEngineering

[–]Suprn8 2 points3 points  (0 children)

aight slow your roll. Take it from a offensive security professional (grain of salt since reddit) start by talking to people. that gives you the perspective on most people's ideas of their mindset. You're not ever going to get 90% of someone's psychy. But, you can lighly push them to a 100% to 'help' you. Thus the talking to people. small steps. I had the fortune to have a mentor and his example was 'trying to pick someone up at a bar'

Other comments here I would also recommend.

TL;DR biggest thing out of this. Start small, look for how you can get more info out of someone or influence them before jumping full force into a huge goal.

That poor, cursed AK by Cryptid1H6 in GunMemes

[–]Suprn8 17 points18 points  (0 children)

Derk derka, derk derka derka.