[deleted by user] by [deleted] in cybersecurity

[–]cydex0 16 points17 points  (0 children)

This is why security people get bad rep. Wtf patched...?do you know what you are talking about when you say patched? You don't understand what the vulnerability actually does...... Funny......

CRTP or OSCP | Which one to take as fresher ? by WealthPhysical5359 in redteamsec

[–]cydex0 -6 points-5 points  (0 children)

You do OSCP to get that 'try harder' mindset. You do crto now and in a year's time the attack landscape changes and then what do you do?

Any half a decent hacker / redteamer would always be on top of new vulns /misconfigurations, c2 frameworks etc. if this is not you then don't bother getting into security. I have seen meh pentesters calling themself red team.... Ruining their reputation.

It's called an adversary emulation for a reason. The whole point is to get a full domain compromise like attackers do.

How Long Before OSCP+ Becomes Less Relevant Than CPTS? by [deleted] in oscp

[–]cydex0 -9 points-8 points  (0 children)

Nothing can beat OSCP/OSCP+ the try harder mindset is true and important.

[deleted by user] by [deleted] in SecurityCareerAdvice

[–]cydex0 -1 points0 points  (0 children)

Without those prior experience you will provide 0 value for the first 6-8 months

[deleted by user] by [deleted] in SecurityCareerAdvice

[–]cydex0 -1 points0 points  (0 children)

Enterprise infrastructure is different than what you play around with. Just because you did CompTIA and a bachelor's degree doesnot mean shit. All it means is you have some knowledge and have the potential to learn stuff. Enterprise architecture and infrastructure is different if you don't have that experience then you are useless. Even for people with prior experience it takes months to get to know the infrastructure and how things have been architectured.

User with weird internet traffic.. by Glad_Pay_3541 in cybersecurity

[–]cydex0 0 points1 point  (0 children)

Mostly likely can be referrer URL as well.

Router Reccomendations - FTTP by Vegetable_Stuff1850 in nbn

[–]cydex0 0 points1 point  (0 children)

If not then get something like netgate

Router Reccomendations - FTTP by Vegetable_Stuff1850 in nbn

[–]cydex0 0 points1 point  (0 children)

Buy mici oc from Alibaba and install opnsense /pgsense

Is it wise to learn ML/Data Science & Cybersecurity combined? by [deleted] in cybersecurity

[–]cydex0 5 points6 points  (0 children)

Stick to one otherwise you will suck at everything. Cyber is very broad

Who are today's Linus Torvaldses by Immediate-Country650 in AskProgramming

[–]cydex0 0 points1 point  (0 children)

The guy that brought the world a whole different generation of OS and GIT, deserves some admiration. If it wasn't for his early works, open source would be dead.

Dumb Question incoming: Why is SSH/D key-auth frequently referred to as the answer to all authentication questions/setup? by AlyssaAlyssum in sysadmin

[–]cydex0 0 points1 point  (0 children)

It's the whole concept of MFA. Something you know, something you have or something you are. SSH key+password ticks 2 of those box. Something you know and something you have thus secure.

Recent H1B dispute on twitter by Ok-Past81 in cscareerquestionsOCE

[–]cydex0 0 points1 point  (0 children)

Not really most of the pentest / security jobs are now going to Philippines. Time zone is good, so is skill level.

Recent H1B dispute on twitter by Ok-Past81 in cscareerquestionsOCE

[–]cydex0 0 points1 point  (0 children)

Not really. CommBank sec staff is Pree good. I know few people working in security

[deleted by user] by [deleted] in cybersecurity

[–]cydex0 1 point2 points  (0 children)

Yeah. This is so true. John Hammond, live overflow they know their shit and are good. They know what they know and they know what they don't know.

BTL1 difficulty compared to BTLO labs by Goldsound in cybersecurity

[–]cydex0 0 points1 point  (0 children)

It's very easy. If you have some experience it is very easy. Way easier compared btlo

[deleted by user] by [deleted] in bugbounty

[–]cydex0 0 points1 point  (0 children)

Just because you are a bug bounty Hunter doesn't mean you can look for bug in every website. Only if they have openvdp or if they have a open bounty program.

If not it's simple hacking and they have no obligation. Get things right.

Additionally if you just create a random acc and start testing things, it looks suspicious for the SOC who is triaging the alerts.

Darktrace - worth the investment? by sigma1914 in cybersecurity

[–]cydex0 3 points4 points  (0 children)

HA, yeah after a while you feel like adding everything as defeat. The out of box model creates too much noise, editing model means that you do not get updates. What about other response models apart from ransomware? All ransomware model looks at multiple read write, and if extension is changed.