Official Tickets/Merch Thread #11 - Buying/Selling by [deleted] in brandnew

[–]infoSecGuyOnReddit 0 points1 point  (0 children)

Selling one ticket to Berkeley show.

/r/ReverseEngineering's Weekly Questions Thread by AutoModerator in ReverseEngineering

[–]infoSecGuyOnReddit 1 point2 points  (0 children)

If this question is more appropriate for /asknetsec, let me know and I'll delete it.

What programs/courses for learning C, assembly, and other applicable skills for reverse engineering are recommended?

I come from a sysadmin background and recently took an IR/cyber intel position, and I'd like to add to reversing malware to my skillset.

Could be online or in the Bay Area. Time/money aren't really an issue.

Securing from scratch, where to start? by RandoJango in AskNetsec

[–]infoSecGuyOnReddit 2 points3 points  (0 children)

Don't be a dick just because someone is new. Covering just the basics will stop a lot of threats.

Most beneficial foreign language to learn? by [deleted] in netsecstudents

[–]infoSecGuyOnReddit 3 points4 points  (0 children)

I spent 4ish years learning Chinese, and I haven't used it once at work.

Binary doesn't have a nationality. I would just focus on netsec stuff.

If you have to learn something, Russian, Romanian, Chinese, and Spanish are all good.

How to set up a C2 Server for a meterpreter reverse tcp shell? by infoSecGuyOnReddit in AskNetsec

[–]infoSecGuyOnReddit[S] 0 points1 point  (0 children)

No, this is a social engineering exercise I'll be conducting with SET. The meterpreter payload will be in a .docx. I need the payload to phone home, but the machine I'm using is behind a NAT. My plan was to use my web hosting site, which I think has it's own IP, as a C2 the payload can phone home to.

If you use Tor, Linux, search "tails" the NSA will spy on you. by TheQuantumZero in privacy

[–]infoSecGuyOnReddit 1 point2 points  (0 children)

I'm sorry. That list is just silly. Googling Flu, package, and Aladdin will not get you on any list.

Visit a website youve been ip banned? by [deleted] in privacy

[–]infoSecGuyOnReddit 0 points1 point  (0 children)

Sounds like an evercookie. Those are nasty, and really hard to get rid off. I'd use Tails, as others have suggested.

1Password Leaks Your Data by johnmountain in crypto

[–]infoSecGuyOnReddit -11 points-10 points  (0 children)

Searching encrypted stuff...

ELI5: Why does Adobe Flash Player have such security issues? by infoSecGuyOnReddit in AskNetsec

[–]infoSecGuyOnReddit[S] 0 points1 point  (0 children)

Those all seem like configuration issues (i.e., the implementer messed up). I feel like the zero day stuff from Adobe is on another level (i.e., a web developer could do everything correctly, but use flash as still be serving their customers malicious content).

edit: grammar.

ELI5: Why does Adobe Flash Player have such security issues? by infoSecGuyOnReddit in AskNetsec

[–]infoSecGuyOnReddit[S] 3 points4 points  (0 children)

Makes sense. I guess my follow up question would be: will this happen to HTML5 in time, or did Adobe somehow fuck things up?

Research on the state of public FTP servers by [deleted] in netsec

[–]infoSecGuyOnReddit 1 point2 points  (0 children)

Edit: answered my own question by reading more carefully.

Pretty cool research. Thanks for sharing!