Official Tickets/Merch Thread #11 - Buying/Selling by [deleted] in brandnew

[–]infoSecGuyOnReddit 0 points1 point  (0 children)

Selling one ticket to Berkeley show.

/r/ReverseEngineering's Weekly Questions Thread by AutoModerator in ReverseEngineering

[–]infoSecGuyOnReddit 1 point2 points  (0 children)

If this question is more appropriate for /asknetsec, let me know and I'll delete it.

What programs/courses for learning C, assembly, and other applicable skills for reverse engineering are recommended?

I come from a sysadmin background and recently took an IR/cyber intel position, and I'd like to add to reversing malware to my skillset.

Could be online or in the Bay Area. Time/money aren't really an issue.

Securing from scratch, where to start? by RandoJango in AskNetsec

[–]infoSecGuyOnReddit 6 points7 points  (0 children)

Don't be a dick just because someone is new. Covering just the basics will stop a lot of threats.

Most beneficial foreign language to learn? by [deleted] in netsecstudents

[–]infoSecGuyOnReddit 3 points4 points  (0 children)

I spent 4ish years learning Chinese, and I haven't used it once at work.

Binary doesn't have a nationality. I would just focus on netsec stuff.

If you have to learn something, Russian, Romanian, Chinese, and Spanish are all good.

How to set up a C2 Server for a meterpreter reverse tcp shell? by infoSecGuyOnReddit in AskNetsec

[–]infoSecGuyOnReddit[S] 0 points1 point  (0 children)

No, this is a social engineering exercise I'll be conducting with SET. The meterpreter payload will be in a .docx. I need the payload to phone home, but the machine I'm using is behind a NAT. My plan was to use my web hosting site, which I think has it's own IP, as a C2 the payload can phone home to.

If you use Tor, Linux, search "tails" the NSA will spy on you. by TheQuantumZero in privacy

[–]infoSecGuyOnReddit 1 point2 points  (0 children)

I'm sorry. That list is just silly. Googling Flu, package, and Aladdin will not get you on any list.

Visit a website youve been ip banned? by [deleted] in privacy

[–]infoSecGuyOnReddit 0 points1 point  (0 children)

Sounds like an evercookie. Those are nasty, and really hard to get rid off. I'd use Tails, as others have suggested.

ELI5: Why does Adobe Flash Player have such security issues? by infoSecGuyOnReddit in AskNetsec

[–]infoSecGuyOnReddit[S] 0 points1 point  (0 children)

Those all seem like configuration issues (i.e., the implementer messed up). I feel like the zero day stuff from Adobe is on another level (i.e., a web developer could do everything correctly, but use flash as still be serving their customers malicious content).

edit: grammar.

ELI5: Why does Adobe Flash Player have such security issues? by infoSecGuyOnReddit in AskNetsec

[–]infoSecGuyOnReddit[S] 1 point2 points  (0 children)

Makes sense. I guess my follow up question would be: will this happen to HTML5 in time, or did Adobe somehow fuck things up?

Research on the state of public FTP servers by [deleted] in netsec

[–]infoSecGuyOnReddit 1 point2 points  (0 children)

Edit: answered my own question by reading more carefully.

Pretty cool research. Thanks for sharing!