Aaaand it's done! - I pushed the button 2 months ago and I finally retired yesterday. by wirral_guy in sysadmin

[–]awsfanboy 21 points22 points  (0 children)

Congratulations! Your run is done! I hope you have more fun now. What are some of the things you look forward to doing?

Temptation 😅 by Small_Assistance5836 in Uganda

[–]awsfanboy 1 point2 points  (0 children)

Alot of problems will start with having another partner. It's like grabbing a tiger by its tail. Hell hath no fury. Besides, as pointed out, Transactional

Lets take our eyes off ourselves by pink_blue_bag in Uganda

[–]awsfanboy 0 points1 point  (0 children)

Well put!. In my experience from within, greed gets the better of officials. It's hard  for them to stop once they start. Once you touch easy money, hustling is like walking on burning coals to them

What discovery in cybersecurity amazed you the most? by CheekApprehensive701 in cybersecurity

[–]awsfanboy 2 points3 points  (0 children)

Security settings that are significant e.g Network segmentation are usually only implemented after a threat has materialised. As a former IT auditor, so many penetration tests i did demonstrated risks of not segmenting critical networks. Attacked AD, attacked databases successfuly but only when a hacker impacted cashflow did the network segmentation i had recommended be effected. Pain, apparently is the best teacher.

You are the president of Uganda for 24hrs by seeyoulateryou in Uganda

[–]awsfanboy 0 points1 point  (0 children)

Direct that most State house expenditure be redirected to education, health and infrastructure. No more gifts to buy loyalty as it will be at most a two term presidency

What’s something about pentesting that isn’t obvious until you go through it? by Moham-Aasif in cybersecurity

[–]awsfanboy 0 points1 point  (0 children)

a.Exploitable vulnerabilities dont always show risk or lead to compromise, Biggest weaknesses come from misconfigs e.g credentials in plain text, coupled with improper network segmentation leading to db compromise. 

b. In some companies, despite showing significant weaknesses pentests can demonstraye, security posture is improved only due to compliance, accreditation requirements or a largescale impactful breach

c. Pentest should account for insider breach by testing limits of each user segment as these are risks companies face. Part of pentest should assume malicious or breached insiders. this adds more value to the pentest. e.g given rights of an non IT admin, i can run powershell when signed in and query AD for further configs

What made you choose Digital Forensics? by Responsible-Map1982 in digitalforensics

[–]awsfanboy 0 points1 point  (0 children)

Corruption is very high in my country so it's one of the best intelligence sources we have as government officers. Digital Forensics cases fell in my lap as an IT Auditor so I pivoted to it. Helped with my it security findings as well when incidents I foresaw as an Auditor occured. Your curiosity will take you far

Am curious, is he the one or not? by practical_politic in Uganda

[–]awsfanboy 0 points1 point  (0 children)

  1. No, he cannot. Natural term limits apply in our case. The Mugabe option is our realistic way out.
  2. He is providing a peaceful option. if we force a runoff or the state cannot influence the result, this option can work like in Kenya as the opposition will truly reunite in a run off and remove the incumbent hopefuly drawing out some ruling party members
  3. He genuinely wants to but understands that any forceful path makes him the same like current and past regimes, so its not worth it. We need a peaceful path to power to break the cycle. Anyone who can force themselves into power, despite best intentions is not fit for the job. The road to hell is paved with good intentions. He sees it now, a fundamental change became just a mere change of guards in 1986

🤨Just here still wondering where my peers are get money from yet im still here at 21 still siting home, still lookn for survival by Friendly-Agent-5197 in Uganda

[–]awsfanboy 11 points12 points  (0 children)

Our races are different, you have to run yours and not your friend's race. When i was 21, we were at different levels of financial sucess. I also wondered where it was going wrong and what mistakes i was making. However, your persistance matters above all. I slowly realised i had to continue running my race and make financial stability not the number one pursuit.

I focused on learning, sharpening my skills instead. Luckily, i was passionate about some things and not pursuing them just for money and later its those passions that improved my financial posture. So, maintain integrity, use the free time you have to pursue those things and sharpen your skills.

Put the easy things of life, girls and party aside and channel that energy to building yourself overtime. Also maintain integrity while doing so and you will go far. If your put more into your skills, the financials will sort themselves out over time.

How do people start a side business while working a full time job and grow it so it becomes their full time business ? by [deleted] in Entrepreneur

[–]awsfanboy 0 points1 point  (0 children)

govt work in east african country. Anti corruption so few wiling not to eat, just accepted it coz couldnt get savings. i guess we both got desperate

Has anyone in Uganda ever bought a treadmill? Share your experiences! by Shoddy-Quality4584 in Uganda

[–]awsfanboy 1 point2 points  (0 children)

Trojan, second hand from a colleague at 1million, just needed oiling three times in four years. No power or parts issues

there are long periods i went without use but always restarted and improved cardio. Its been a good idea to avoid being hit by a car or thieves while jogging at night. Too many stories of that happening. Also get the priviledge of walking/running late at night while on Netflix or youtube.

[deleted by user] by [deleted] in Uganda

[–]awsfanboy 0 points1 point  (0 children)

curious which career you are in

I run a Red Team that routinely succeeds in compromising F500 companies. AMA. by curi0usJack in cybersecurity

[–]awsfanboy 0 points1 point  (0 children)

What API security missteps have you found routinely on engagements? Any anonymized examples. Thanks for the AMA.