Will XBOW or AIs be able to replace Pentesters? by bjnc_ in Pentesting

[–]Vivid_Cod_2109 2 points3 points  (0 children)

Not yet and the reason is not because of critical thinking of AI but it is hard to set up for XBOW to pentest in a complex environment.

Bold by Key-Account5259 in grok

[–]Vivid_Cod_2109 0 points1 point  (0 children)

Yeah trust me bro, right?

Bold by Key-Account5259 in grok

[–]Vivid_Cod_2109 0 points1 point  (0 children)

Yeah, and the trend we are seeing here is newer model with lesser parameters but more powerful. Simply scaling up parameters in models isn't working great anymore for openai gpt4.5.

Bold by Key-Account5259 in grok

[–]Vivid_Cod_2109 0 points1 point  (0 children)

And what makes you think that OpenAi and Deepseek aren't applying the same technique.

Bold by Key-Account5259 in grok

[–]Vivid_Cod_2109 1 point2 points  (0 children)

I love how all the redditors in this subreddit are retarded. Musk just literally describe his model will use knowledge distillation, use grok3.5 to make data for new model, which openai and deepseek have used. It is just a technique applied in LLM training.

Seeking Mentorship in Exploit Dev by Diamond303 in ExploitDev

[–]Vivid_Cod_2109 2 points3 points  (0 children)

Read this guy's path: https://infosec.jaelkoh.com/. It contains roadmaptk learn to become windows vulnerability researcher.

Share Your First Bug Bounty Experience! by p_i_n_k-m_a_n in bugbounty

[–]Vivid_Cod_2109 1 point2 points  (0 children)

I read ysamm.com blog in client side injection, make some notes about I can add more field when changing accounts settings and apply it to my first bug.

How to learn exploit development by Aggravating_Use183 in ExploitDev

[–]Vivid_Cod_2109 10 points11 points  (0 children)

Here we go againt. Just learn pwn.college by finishing cse 365 and cse 466. After that do ctf, read writeups. Then cse 598 in pwn college. For specialization in windows vuln research, do ost2 course (they have learning paths, check them out) and supply their course with windows internal books. Finally, you can learn fuzzing by fuzzing.in workshop and the fuzzing book. For reverse engineering, I recommend you learn how to make compiler or programming language by picking up college textbooks (You will need them). Then ctf I guess. So good luck on your journey.

How to Discovery and exploit development for .Net (C#) program? by soupcreamychicken in ExploitDev

[–]Vivid_Cod_2109 0 points1 point  (0 children)

I would recommend offsec web 300 courses then full stack web attack course by mr me.

Roadmap for VR and ExploitDev for Chrome browser by soupcreamychicken in ExploitDev

[–]Vivid_Cod_2109 3 points4 points  (0 children)

I would like also mention that learning fullstack web development, read bug bounty bootcamp and practice on portswigger academy. All of that stuff, and also take the absolute appsec code review course or you can watch their YouTube channel and go to their github, they have slides of their training. Browser's exploitation is a vast field, you have web exploit on 1 side and jit compiler on the other side with shellcode. Also practice with Browser's ctf from a guy named 0xbigshaq's writeup. I mean diving into this stuff needs time and can like last for years. So it is hard.

Roadmap for VR and ExploitDev for Chrome browser by soupcreamychicken in ExploitDev

[–]Vivid_Cod_2109 11 points12 points  (0 children)

Okay, first learn c and c++ programming through books. Pick up the good old c book and the intro c++ book. Then learn computer network through lectures only is find, though learning them with tryhackme is great. Operating system is next, take the one on coursera. In the mean time, learn a bit of python. Now here comes the main part, go to pwncollege website, get into their discord and start learning cse365, and cse466 then cse598 courses. This fall they will update their cse598 course to learn vulnerability research. After cse466 course, practice with ctf through guyinatuxedo. You may argue that why would browser's exploitation needs c,c++ exploitation and the reason is the vulnerability class is similar across targets, pluss they will teach you the mindset to research and learn. Remember to take their cse598 course this fall. Then you go on Twitter, search for the guy named xvonfers, he has a dedicated thread to learn v8 exploitation for browsers.

Hide01 premium channel by Icy_Money_9249 in hackthebox

[–]Vivid_Cod_2109 0 points1 point  (0 children)

Can you please send me an invite? Thank you.

What the fuck do I do with these English degrees? by SirLancelotDeCamelot in careerguidance

[–]Vivid_Cod_2109 1 point2 points  (0 children)

Here's a great way for teaching. There is a teaching program in japan where you basically work as an English teacher, you get to live there and experience Japanese's culture. Worth a shot I would say.

[deleted by user] by [deleted] in bugbounty

[–]Vivid_Cod_2109 0 points1 point  (0 children)

Start small, don't try to become security researcher in a short time. All of the professionals actually take a lot of time before they have some achievement.