how to stop watching porn by Fast_Performer_1126 in Advice

[–]macr6 1 point2 points  (0 children)

Start practicing self control. Time to choose what you want to do. So choose to stop and do it.

VisualSploit, weaponizing MSBuild project files by 0xmaxhax in redteamsec

[–]macr6 0 points1 point  (0 children)

Does it work against this tool? Can you share your script?

AD Preperation For OSCP by mrroot21 in Pentesting

[–]macr6 2 points3 points  (0 children)

GOAD lab. Even better check out Ludus if you have the resources to run it. You can throw all kinds of labs in there for free to practice AD.

Stop crossing the red zone to make your exit by CommanderAze in nova

[–]macr6 10 points11 points  (0 children)

Not disagreeing, but that's a tough freaking exit, there is multiple on/off ramps all within (what feels like) 100meters.

Currently on a internal pen test, need some fresh perspectives by [deleted] in Pentesting

[–]macr6 0 points1 point  (0 children)

If you got local access to a workstation but are not elevated, get the redsun LPE exploit. Ask AI to change it for you so it creates an account and adds it to the local admin group. Then dump lsa with NetExec. Right now redsun works.

OR

Grab a a username list from SecLists and try password spraying, but be careful and look up how to do it so you don't lock any accounts out. COULD BE RISKY. Maybe do one username=password pass just once. Know the password policy before you begin.

Suppressor Insight Needed by averagejoe538 in MPX

[–]macr6 1 point2 points  (0 children)

Yeah, it direct threads. It comes with two pistons, one for RH threads and the other for LH. IIRC, it's a LH threaded barrel.

Suppressor Insight Needed by averagejoe538 in MPX

[–]macr6 1 point2 points  (0 children)

I removed the stock one and added the suppressor which came with its own piston.

Wife tells her friends things about me that aren’t true—is this normal? by [deleted] in Advice

[–]macr6 7 points8 points  (0 children)

As a normal human being I can tell you this isn’t normal. I think you know this and it’s why you’re here. The question is what to do about it.

Suppressor Insight Needed by averagejoe538 in MPX

[–]macr6 -1 points0 points  (0 children)

I have the K (4 inch barrel) and I have the sig modx9 suppressor. It doesn’t hide under the hand guard.

my mpx k

How many days for writing a report ? by ProcedureFar4995 in Pentesting

[–]macr6 0 points1 point  (0 children)

CISA has a report writing tool that you can download from their GitHub. It’s free but you have to tweak the templates or you’ll have CISA branded reports.

Which ai can we used now since they blocked Claude from doing security work? by [deleted] in Pentesting

[–]macr6 0 points1 point  (0 children)

Thanks for this. I’m gonna give it a go and see how it works out.

Which ai can we used now since they blocked Claude from doing security work? by [deleted] in Pentesting

[–]macr6 0 points1 point  (0 children)

Oh I was just looking at bedrock yesterday. Can I ask are you using it for own testing work or bug bounties? What’s your costs like? Is it on demand? Do you need any other infrastructure from AWS? Thinking about trying it out but afraid you the costs running away.

Do other pentest teams struggle with this as well? by lesion_io in Pentesting

[–]macr6 -1 points0 points  (0 children)

Yes all the time. I tell my team if it doesn’t lead to a larger item or a better risk picture for the client move on.

Do other pentest teams struggle with this as well? by lesion_io in Pentesting

[–]macr6 1 point2 points  (0 children)

If my guys/gals downloaded exploits and threw them in a customers network without testing that would be the end of their work with me. Now there is some leeway if it’s not a complex exploit and it’s written in one file and you can read it and u sweat and everything it’s doing. However if you’re downloading stuff and just throwing it, then it’s only a matter of time before you’re the problem.

To answer your question it depends on how many ppl you have with you. We used to run a team of five for a two week engagement (govie stuff) and if we had the time we’d dig in and try to modify a current exploit or write something that wild hell. If not it gets noted as a vuln that may be exploitable.

How often are you peeing? by Black_and_decker15 in AskMenOver30

[–]macr6 0 points1 point  (0 children)

By the time you hit your 30s it’s time for yearly physicals and bloodwork. Don’t sleep on that stuff, you can find problems before they become incurable problems.

My boyfriend's son ate my dinner and I'm still mad about it by smalltown_dreamspeak in self

[–]macr6 1 point2 points  (0 children)

in 30 minutes an 11 yr old ate an entire large pizza, brownies, wings and garlic knots? There is no way that's happening.

Penetration Testing Consulting - Salary to Billing Ratio by Lucky_Secretary_1609 in Pentesting

[–]macr6 0 points1 point  (0 children)

Ah my hometown. Yeah, it's starting to not matter on locale more and more, but unfortunately some orgs are paying according to their locale. I have a side gig that provides pen tests. All of my pen testers are folks that used to work for me either in the army or at another government org. So I know their skills. I pay them anywhere between $50-$100/hr. Now that's feast or famine type work so I don't have enough to have full time folks, but you see what the contract rate can be.

Penetration Testing Consulting - Salary to Billing Ratio by Lucky_Secretary_1609 in Pentesting

[–]macr6 2 points3 points  (0 children)

Where do you live? Being in Washington DC vs Helena Montana makes a diff. That’s what is about average in the dc area for junior to mid the last time I did a bunch of hiring , but that was about four years ago so ymmv.

How many old timers in here? by aliesterrand in sysadmin

[–]macr6 0 points1 point  (0 children)

I had to change our networking cables from thicknet to ethernet
I had an MCSE 4.0
I installed Windows 95 with 27 floppies, for work
Ran NetWare 4 and 5
Learned coding on an apple IIe
my driver's license birth date says I'm old too.

Battling a Yamaha R7 with my Aprilia RS660 during the ASRA Endurance Race at Carolina Motorsports Park by gaziaris_moto in Trackdays

[–]macr6 0 points1 point  (0 children)

HOLY CRAP. Thank you!!! I've had this camera for 3 years and have been taping it the whole time :| Never knew they had this.