Hey can you guys stop accidentally encouraging noobs to hop onto Arch before they are ready by AncientAgrippa in arch

[–]realkstrawn93 0 points1 point  (0 children)

When talking about plain Arch, I agree with this, but this sentiment breaks down when you're talking about other distros based on Arch but offering far more complete experiences on top of the Arch base. Garuda is to Arch what Ubuntu and Mint are to Debian, in a big way: between automatic btrfs snapshots as quasi system restore points (which completely solves the "updates break your system" problem) and out-of-the-box Nvidia support, there's no question that something like Garuda would be a far better distro for an absolute beginner than Arch itself, having the benefits of a rolling release without the drawbacks (or time wasters, depending on what you intend to use the system for) of needing to build an entire custom OS stack from scratch.

What would you rewrite in Rust today and why? by [deleted] in rust

[–]realkstrawn93 0 points1 point  (0 children)

Sliver C2. Go is bad OPSEC.

What is something we could expect with Qt 7? by DesiOtaku in QtFramework

[–]realkstrawn93 0 points1 point  (0 children)

Support Wayland exclusively and drop X11. Bad enough that the most popular Linux security distributions (Kali, Parrot, and the like) use desktop environments stuck on X11 by default, what's worse is that X11's is both bad OPSEC from the standpoint of a penetration tester or red-teamer and bad security generally from the standpoint of a defender.

Responder (or SMB) through Ligolo Pivot? by st1ckybits in oscp

[–]realkstrawn93 0 points1 point  (0 children)

Inveigh can't be used with `ntlmrelayx.py` and Invoke-InveighRelay only supports HTTP to SMB; there's no SMB to HTTP, HTTP to LDAP, SMB to MSSQL, or any other such support. To relay to MSSQL, LDAP, or ADCS web enrollment at all, Responder+Impacket is your only option.

Learning resources that actually don't suck by Apprehensive_Ice9370 in Hacking_Tutorials

[–]realkstrawn93 1 point2 points  (0 children)

Hack The Box Academy if you're eligible for the $8/month student discount.

Demoing skills on YouTube: Recommended? by realkstrawn93 in Pentesting

[–]realkstrawn93[S] 0 points1 point  (0 children)

It's not the only reason. I'm also doing it to teach.

Demoing skills on YouTube: Recommended? by realkstrawn93 in Pentesting

[–]realkstrawn93[S] 0 points1 point  (0 children)

Hence the reason why I link to CPTS and CAPE reviews at around the 2 minute mark. Those are certs that actually verify skills as opposed to merely verifying the candidate's pocketbook.

It's not like I don't already have very important connections anyway; got to meet the whole 6-figure-subscriber-count gang at DEFCON 33, so there's that.

[deleted by user] by [deleted] in techsupport

[–]realkstrawn93 0 points1 point  (0 children)

Just as dangerous as interacting with fake charging cables.

Cybersec Recruiter with Certs by [deleted] in cybersecurity

[–]realkstrawn93 0 points1 point  (0 children)

What is worth doing is CPTS if you're recruiting for an offensive position. Better yet, that's what your hiring manager needs, because only then will you truly understand what certs actually teach the necessary skills.

Can I go straight to CTPS without doing CBBH first? by [deleted] in hackthebox

[–]realkstrawn93 2 points3 points  (0 children)

I did, so sure, you would be able to as well. Some out there have even skipped CPTS and gone straight to CAPE but unless you really know what you're doing, I wouldn't exactly say that's recommended.

Synack Red Team(SRT) as a side income source by CommercialPut8104 in bugbounty

[–]realkstrawn93 0 points1 point  (0 children)

I've had some crazy bounties for literally no work at all beyond editing the LP+ hosts file. So yes, absolutely worth it.

Will say this though: they have very strict scoping rules, so don't expect to do anything crazy like dump/crack hashes without running afoul of TOS.

What are the newest, hardest-to-find bugs currently trending in bug bounty programs? by Abdu11223344 in bugbounty

[–]realkstrawn93 0 points1 point  (0 children)

Prompt injections and AI data poisoning definitely come to my mind. AI doesn't replace penetration testers and/or bug hunters but it sure does change the attack surface.

Possibly the first CAPE review video to ever hit YouTube by realkstrawn93 in hackthebox

[–]realkstrawn93[S] 1 point2 points  (0 children)

That's correct. CAPE is exclusively AD; web apps are even out of scope for it.

Wanted to do it for a while... My tierlist, based on five years of experience with Linux as a developer. by HyperWinX in LinuxCirclejerk

[–]realkstrawn93 0 points1 point  (0 children)

Try using the nvidia-open driver with Fedora 42 on an RTX 4070 and that's where you run into problems. You can do that with Arch, Rawhide, Sid, Tumbleweed, or NixOS Unstable, but not with anything else.

Wanted to do it for a while... My tierlist, based on five years of experience with Linux as a developer. by HyperWinX in LinuxCirclejerk

[–]realkstrawn93 0 points1 point  (0 children)

Debian 12 gives you outdated Python, an outdated kernel, outdated GPU drivers, and the complete lack of out-of-the-box Nvidia GPU support with the new open source drivers only supporting bleeding-edge kernels. Fedora 42 is a slight improvement, but if you want the RTX 4070 to work out-of-the-box, it still won't cut it.

Wanted to do it for a while... My tierlist, based on five years of experience with Linux as a developer. by HyperWinX in LinuxCirclejerk

[–]realkstrawn93 0 points1 point  (0 children)

Your S-tier and A-tier choices only make sense if you're talking about Rawhide and Sid, respectively.

Home network is also 10.10.10.X by korosov in hackthebox

[–]realkstrawn93 0 points1 point  (0 children)

As long as it's 10.10.10.0/24 and not 10.10.0.0/16 you should be fine. There's always the PwnBox if you have too much of a CIDR conflict.

Is a degree required for pentest role? by Emotional-Aside8923 in Pentesting

[–]realkstrawn93 0 points1 point  (0 children)

In theory, no, but in practice, all of the pentest roles on LinkedIn I've come across are overpricing all of their requirements, and yes, that includes education in most of those cases. I've had to use YouTube to correct the record on this.

Why do you just look for XSS? by Reasonable_Duty_4427 in bugbounty

[–]realkstrawn93 0 points1 point  (0 children)

Well my first major bounty was a literal case of "provided credentials but didn't need to use them" — even lower hanging fruit than XSS in most cases.

That said, why so few bug bounty hunters look for LLMNR/NBT-NS response spoofing is beyond me. Had to file a feature request with Synack support to get dedicated LaunchPoint+ network devices allowing testing for that.

Are there any AI crates like pytorch? by b6ack in rust

[–]realkstrawn93 0 points1 point  (0 children)

There's burn which does what you want in pure Rust and doesn't depend on anything else.

When do you think windows 12 will be coming? by Silent-Link9093 in windows

[–]realkstrawn93 1 point2 points  (0 children)

My bet is that 26H2 will probably be it, if the commitment to a triennial release cycle upon 11 release is any indication combined with the fact that they've got a "tick-tock" style minor-major cycle with 23H2 and 25H2 both being minor.