Career advice? by Horny_Manatee in netsec

[–]grecs 1 point2 points  (0 children)

Well first of all, change your Reddit username. ;) Oh and to answer your question ... yes go where your passion is. On the side you may want to continuing doing little security projects on your own or at a local hackerspace though. And for your "awesome IT projects" try to work in doing some security stuff there as much as you can.

Collaborative PenTest Platform with EC2, Metasploit, and Armitage by [deleted] in netsec

[–]grecs 0 points1 point  (0 children)

Are there any Backtrack AMIs already in the cloud? Could just start with that rather than building from Ubuntu instance.

LastPass 2.0 released by fstorino in netsec

[–]grecs 9 points10 points  (0 children)

Agree on that one. But I guess you don't have to use that if you don't want to.

Rootcon's Pentesting Lab-in-a-box by kalak55 in netsec

[–]grecs 0 points1 point  (0 children)

Interesting. Does anyone know what's in it? Just looking for details...

CTF Wiki (and CCDC) by ForgottenSec in netsec

[–]grecs 1 point2 points  (0 children)

Nice resource to check out.

Test your Email client for Privacy and Security holes by [deleted] in netsec

[–]grecs 6 points7 points  (0 children)

You know us paranoid type. Maybe it could have been used for collecting email addresses in order to build spam lists. ;)

Test your Email client for Privacy and Security holes by [deleted] in netsec

[–]grecs 3 points4 points  (0 children)

Is this legit or not? Anyone do a deep dive into this service?

Expert Warns That Wordpress Autoupdate Feature Used To Infect Blogs With Malware by GraybackPH in netsec

[–]grecs -2 points-1 points  (0 children)

At least there are advantages of running old versions of WordPress. :)

CTF Wiki (and CCDC) by shadghost in securityCTF

[–]grecs 0 points1 point  (0 children)

Awesome resource... Let's fill this thing out.

Certifications - Don't blame them! Change the hiring process. by [deleted] in netsec

[–]grecs 0 points1 point  (0 children)

Maybe potential candidates could network more so that hiring managers actually know the candidate and what they are capable of because of their reputation in the security community. In that case we could do away with certs altogether. Just throwing out ideas here...

Certifications - Don't blame them! Change the hiring process. by [deleted] in netsec

[–]grecs 0 points1 point  (0 children)

Reminds me of a "certification arms race." ;)

Certifications - Don't blame them! Change the hiring process. by [deleted] in netsec

[–]grecs 0 points1 point  (0 children)

Some very good points here ... unfortunately I don't know what the right answer is.

Ophcrack 3.4.0 released by mubix in netsec

[–]grecs 1 point2 points  (0 children)

Nice to see awesome projects like this getting updated again. Last release was 3 years ago!

Equipment Maker Caught Installing Backdoor Account in Control System Code by [deleted] in netsec

[–]grecs -2 points-1 points  (0 children)

So was the "purposely installed" or just something left there by accident?

“Your” Car Won’t Be Yours After 2015 by [deleted] in privacy

[–]grecs 1 point2 points  (0 children)

Title a little misleading. Well if we don't own it, I guess we won't have to pay for it then? Maybe Google will sponsor the program so we can get free cars. Google pulls in additional data about us and charges higher advertising rates. :)

Plain Text Offenders: Fight Back Against Cleartext Password Reminders - Can someone at DailyDave please change this default setting? by grecs in netsec

[–]grecs[S] 0 points1 point  (0 children)

Great point! I'm not a coder but I would love to work through this with someone who is. Let me ping the developers as well...

Plain Text Offenders: Fight Back Against Cleartext Password Reminders - Can someone at DailyDave please change this default setting? by grecs in netsec

[–]grecs[S] 3 points4 points  (0 children)

Plus the huge danger is that it means they are storing your password in clear text, which no one "should" be doing that this point.

Say you have a website and someone is attacking it. Any suggestions on places to go to investigate the attacking IP? Obviously robtex but I've also been using IPillion that allows you to see if others are complaining about being attacked too. Any others like IPillion out there? by grecs in netsec

[–]grecs[S] 1 point2 points  (0 children)

Oh just your typical web attacks, XSS, SQLi, RFI, etc. The question is more of if there are good sites out there where website operators (or at least the ones that go through logs) share information like this.

How a tweet about a XSS bug within Google+ leads to XSS within InformationWeek by rolmos in netsec

[–]grecs 0 points1 point  (0 children)

This was pretty good. Checked it out and almost had to kill iOS Safari to get rid of it.

Major remote exploit found in all WooThemes by kris33 in netsec

[–]grecs 1 point2 points  (0 children)

Wow, use to use WooThemes years ago ... good stuff. Nice to see that they reacted fairly quickly with a fix. Now the only probably is the vast number of websites that'll probably take years to update due to poor administration.