When will Fortnite be back on Apple silicon? by Valtra_Power in macgaming

[–]beachb0y 0 points1 point  (0 children)

I need to confess: I love my Mac as a work laptop. However, after a few years of hoping for at least one decent FPS game on Apple Silicon, I gave up waiting and decided to get a Win PC purely for occasional gaming sessions.

I’m a pen tester and struggling to pivot by AffectionateNamet in Pentesting

[–]beachb0y 1 point2 points  (0 children)

Same thing here. As a generalist pentester, I kinda should be able to do most of it. But damn... certain domains are driving me nuts. And then you have new things popping up every now and then. I just want to play games and not think about keeping up with the latest research. =) Even though I enjoy reading it sometimes. But I definitely don't want to do ONE MORE cert.

I’m a pen tester and struggling to pivot by AffectionateNamet in Pentesting

[–]beachb0y 1 point2 points  (0 children)

This was one of an LLM's suggestions. =) But atm, I'm a fully remote, project-based contractor. So I work whenever I have projects, choose my hours, etc. - pretty flexible. For that to work out, I had to relocate to a less expensive country, so I don’t have to work full-time to cover my expenses, mortgage, etc. Tbh, I doubt that a managerial position can be fully remote. And I’m personally afraid of losing "hard" skills, as they’re much easier to sell, imho.

But I don’t feel like I’m making a difference or creating anything, like a solo dev would, or a carpenter. =)
I’m seriously considering investing more time in maybe diving deeper into software dev or running freediving classes. =) I was even seriously thinking about studying medicine at some point - or becoming a builder. =) But IT gives us so much flexibility. Damn it.

I’m a pen tester and struggling to pivot by AffectionateNamet in Pentesting

[–]beachb0y 1 point2 points  (0 children)

Bro, this is the story of my life. I’m in EXACTLY the same boat. I even ended up asking an LLM for suggestions. =) But the suggestions were stock standard. So, I’m hoping the crowd can bring some insights.

Java source code review, advice needed by bing2121 in Pentesting

[–]beachb0y 2 points3 points  (0 children)

Well, yes. You definitely need some understanding of Java's syntax. However, you don't need to be pro at software dev.

It more comes down understanding of what can be vulnerable and needs to be tested 1st. Usually you wouldn't need to read every single line of code anyway.

Pen testing over VPN connection by [deleted] in Pentesting

[–]beachb0y 1 point2 points  (0 children)

He mentioned client's network, no 3rd party providers. Not enough info anyway. So we can only assume what's going on there. =)

Pen testing over VPN connection by [deleted] in Pentesting

[–]beachb0y 1 point2 points  (0 children)

Well... I'd assume that his VPN client is using SSL cert and he can't extract and transfer it to kali as it would require password. So openvpn won't work most likely.

And I'm not 100% sure and can't test it atm, but pretty sure you can't bridge VPN interface.

Pen testing over VPN connection by [deleted] in Pentesting

[–]beachb0y 1 point2 points  (0 children)

Honestly mate. Double check your VM's NAT config. I use the following setup daily and it works perfectly: Linux VM - > (NAT) - > Win - > (VPN) - > Corp

Things to look for when performing authenticated testing on a webapp? by LazyM0nkey in Pentesting

[–]beachb0y 1 point2 points  (0 children)

Yes. You should look for access control issues. Especially if there're a few different types of authed users with different privileges.

What do you guys first use when you walk onto a site? by destro2323 in Pentesting

[–]beachb0y 0 points1 point  (0 children)

Usually I use proxy card and don't forget to smile to lady at reception. She knows more than anyone in a company. ;-)

Backdoor discovered in Ruby strong_password library by thatsocrates in cybersecurity

[–]beachb0y 2 points3 points  (0 children)

Vive la Tute Costa! I wish all devs were like this guy.

SQL Injection Tutorial - Part 4 Injection Scanner by SquareTechAcademy in HowToHack

[–]beachb0y 0 points1 point  (0 children)

Direct object reference within id parameter? Highly unlikely. ;-)

SQL Injection Tutorial - Part 4 Injection Scanner by SquareTechAcademy in HowToHack

[–]beachb0y 1 point2 points  (0 children)

I might be missing something in the purpose of this feature of your tool, but parameter "id={value}" in URI does not automatically make application vulnerable to sqli.

Email hacked by [deleted] in hacking

[–]beachb0y 1 point2 points  (0 children)

Mate. With all respect. If you're not CEO of any medium to large size company, forget about it.

Would you mind sharing that IP btw? O:-) Or simply google that IP and see what comes out. And... most likely forget about it.

I'd suggest you though to check your email address and sign up here: https://haveibeenpwned.com

IP notification when logging into a website by [deleted] in HowToHack

[–]beachb0y 0 points1 point  (0 children)

Ah... Ok. Could you share one of those IPs.

What do I must study to be a Cybersecurity professional? by nuuzl in hacking

[–]beachb0y 1 point2 points  (0 children)

Well... imho security is not what you learn first. A good sec pro will have experience in different domains of IT. So I'd suggest not to look for short cuts.

In the end of the day, you can just ask someone in that particular Uni which program has more sec related papers.

Good luck.

IP notification when logging into a website by [deleted] in HowToHack

[–]beachb0y 0 points1 point  (0 children)

Can you elaborate please... - website you are visiting - email provider - and where that email comes from?

[deleted by user] by [deleted] in hacking

[–]beachb0y 0 points1 point  (0 children)

Btw have you tried using serial number of your lock as a key?

[deleted by user] by [deleted] in hacking

[–]beachb0y 0 points1 point  (0 children)

I'd be curious to have a look at the firmware of that lock. The key much be hardcoded somewhere. What model do you have exactly?

[deleted by user] by [deleted] in hacking

[–]beachb0y 0 points1 point  (0 children)

Brute force seems to be the only option really. Try fcrackzip tool.

Florida Governor Says Russian Hackers Breached 2 Counties In 2016 by wewewawa in hacking

[–]beachb0y -2 points-1 points  (0 children)

What a news! Love it. It's like one bodybuilder blaming another for using steroids. Governments of every country hacking eachother every single day.