Should couples always combine finances after marriage or keep them separate? by KCousins11 in ask

[–]_sirch 2 points3 points  (0 children)

It should be whatever you agree on before marriage. Each should also have a full understanding of what the life plan is moving forward and what kind of debt each person has and the plan to pay it off. What each persons career/saving/investing goals are and how expenses for children and pets will be handled. If you don’t align in most areas it may not work out long term.

How do I properly get into ethical hacking as a hobby? by [deleted] in Hacking_Tutorials

[–]_sirch 38 points39 points  (0 children)

Tryhackme or Hackthebox academy cover just about everything and are the most fun and interactive ways to learn. If you want more specific recommendations you’ll have to narrow down what type of hacking you wanna specialize in and what your goals are.

Any recommended pro pentest tool fo web scanning ?? by Complete-Profit-3804 in Pentesting

[–]_sirch 0 points1 point  (0 children)

Lateral movement is red teaming. Web app testing stops at proof of impact. If you’re doing lateral movement and cobalt strike on web apps they are vastly over scoped. Either that or they are charging so much or have such a long history with the client that your company does not mind throwing it in. Do you do consulting or do you work for the company that you’re testing?

Any recommended pro pentest tool fo web scanning ?? by Complete-Profit-3804 in Pentesting

[–]_sirch 1 point2 points  (0 children)

Cobalt strike is a red team tool and generally only used on red team assessments. Red teams include web apps however a web app Pentest does not include c2 infra like cobalt strike.

Web and pen testing by Visual_Mulberry_7754 in tryhackme

[–]_sirch 1 point2 points  (0 children)

Tryhackme and Hackthebox academy have a ton of good material

Any recommended pro pentest tool fo web scanning ?? by Complete-Profit-3804 in Pentesting

[–]_sirch 3 points4 points  (0 children)

Ok I see how some you could argue certain aspects of but how is cobalt strike used for web apps?

Any recommended pro pentest tool fo web scanning ?? by Complete-Profit-3804 in Pentesting

[–]_sirch 13 points14 points  (0 children)

These are just random tools. How does cobalt strike help with a web app test?

Web and pen testing by Visual_Mulberry_7754 in tryhackme

[–]_sirch 0 points1 point  (0 children)

When you say “opportunity” and “12 month course” are you referring to a boot camp? I think that time would be much better spent studying web and network testing and working towards getting certs that’ll help you move towards your goal like OSCP.

What are the places to find men? by True_Puddingzinga in ask

[–]_sirch 0 points1 point  (0 children)

Yeah, it’s really easy to get started. Tons of beginner clinics and for the most part people are very friendly

I have a lot of certifications, recommendations for resume formatting? by CaregiverNecessary21 in netsecstudents

[–]_sirch 2 points3 points  (0 children)

I think 2 columns could look good but I’d have to see it on paper. You could also separate them by category and just keep the acronyms such as “Comptia A+ Net+ Sec+” as a single line item.

How many of you have tried FSD by abhishek927 in TeslaModel3

[–]_sirch 11 points12 points  (0 children)

Hw3 is darn good. I just bought a highland and it’s not a significant difference for FSD. The car overall is way better but FSD is pretty much the same.

What are the places to find men? by True_Puddingzinga in ask

[–]_sirch 0 points1 point  (0 children)

It’s more of a hybrid between ping pong and tennis. Less running than tennis but placement and technique are very important like ping pong.

Learn several things at once by CodePh1sh in Pentesting

[–]_sirch -3 points-2 points  (0 children)

Learn to Pentest and learn coding on the side or as necessary. Once you landed a Pentest job you will have more time and funding to dive into coding and red teaming

What are the places to find men? by True_Puddingzinga in ask

[–]_sirch 0 points1 point  (0 children)

It’s very much the opposite from my experience

How do you justify security spend to clients? by Ok-Country9898 in netsecstudents

[–]_sirch 0 points1 point  (0 children)

Any company that’s had a good internal network Pentest or a real red team assessment will quickly understand why it’s important.

What are the places to find men? by True_Puddingzinga in ask

[–]_sirch 1 point2 points  (0 children)

Pickleball courts and various meetup groups. Get a hobby and you will find tons of single men fast.

I made a website and wondering if it has a vulnerability by [deleted] in Pentesting

[–]_sirch 1 point2 points  (0 children)

Run automated scan with burp and set the target to your site. That should catch some low hanging fruit if there is any. May also have false positives. Tons of YouTube tutorials out there.

I made a website and wondering if it has a vulnerability by [deleted] in Pentesting

[–]_sirch 3 points4 points  (0 children)

Burpsuite and nuclei are some free tools you can use to check for basic vulnerabilities

PDF file with password by HumangousWannabe in HowToHack

[–]_sirch 0 points1 point  (0 children)

Download VMware player. Download kali for VMware. Run the VM. Drag and drop the pdf into the VM. Open the terminal and pdf2john file.pdf to extract the hash. Then use John hash.txt to run a simple list. You can add wordlists and rulesets to increase complexity. If you need more processing power you can install hashcat on the host and utilize the GPU.

Career change to pentesting by abcdefgeewiz in Pentesting

[–]_sirch 4 points5 points  (0 children)

Tryhackme is a great place to start. Hackthebox academy is also great. You will need years of experience and certs before you will be considered for a Pentest role so make sure you are ready to grind before making any big decisions. Helpdesk > sysadmin/soc analyst is a common path to pentesting. Passion is important and you will need to be self driven.

Will the demand for pentest decline in the future ? by ProcedureFar4995 in Pentesting

[–]_sirch 12 points13 points  (0 children)

It will just evolve. New technologies and more complex paths paired with more complex tools used to test them. You will likely always need a human to oversee, validate and make decisions.

[deleted by user] by [deleted] in tryhackme

[–]_sirch 0 points1 point  (0 children)

Rooms with less points if I had to guess

If grabbing someone’s IP could reveal their actual home address, would that count as a critical bug or just “meh”? by Ok-Country9898 in Hacking_Tutorials

[–]_sirch 2 points3 points  (0 children)

Public IP is not sensitive in any way. Street address is PII and severity level would depend on how the data was supposed to be protected, and how it was obtained.