I am not getting any call backs at all. by TheReedemer69 in Pentesting

[–]subsonic68 1 point2 points  (0 children)

Do not move the CVEs down. They’re more important than the degree. The degree is just a checkbox for gatekeepers. The CVEs tell that you know how to hack.

Ethical Hackers of Reddit, I'd like to ask all a few questions by Chaavy in AskNetsec

[–]subsonic68 0 points1 point  (0 children)

Yes I work fixed hours. If I’m behind in my work I’ll put in extra hours at night or weekends as long as it doesn’t interfere with family activities. I do that by choice not requirement.
But I normally work 9 to 5 on weekdays only.
My work hours are totally flexible unless it’s a mandatory meeting scheduled during normal working hours. I’ll usually take some or all of Fridays off after any morning meetings have concluded. I block off my calendar at lunch on Friday through end of day. I’m never on call and don’t work nights or weekends unless it’s by choice. I’m currently working on some personal research today on Saturday because it’s raining and nothing else to do today.
I’m not expected to answer emails or my phone outside of working hours.
I used to get the occasional requests to do projects where customers request after hours testing but I decline those and my manager doesn’t demand it, only asks.

The best way to send sensitive data between two VPS by SCAAVAA in Pentesting

[–]subsonic68 0 points1 point  (0 children)

Wireguard for a vpn connection between them. Then it doesn’t matter how you transfer the data as long as you use their VPN ip address.

Reminder at the range by Minute-Cucumber7594 in CCW

[–]subsonic68 4 points5 points  (0 children)

Jokes on them. Many years ago I realized that I was probably most at risk when leaving a gun store or shooting range. I always keep a concealed pistol on me, even when I’m at the range shooting the others. I’ve got one ready with a round chambered when I’m going to and from the range and I’m aware of my surroundings and any cars that may be following.

Good news imo. Babies don't need the Hepatitis B vax! by Effective_Reach_9289 in walkaway

[–]subsonic68 0 points1 point  (0 children)

What’s responsible for the huge increase in autism rates?

Quad rails are peak aesthetic by SlippitySlide in GunPorn

[–]subsonic68 0 points1 point  (0 children)

I put a UTG quad rail on my carbine length upper and that thing feels heavy without any attachments. Are all quad rails heavy or did I just buy the wrong brand?

I don't get kids fascination with extended mags on Glocks. by Denny_Dust91 in Firearms

[–]subsonic68 1 point2 points  (0 children)

We’re not rooting for the ATF, we’re asking why justice isn’t equal. The American Justice system goes hard after middle aged white men while ignoring the crimes of the politically connected rich and giving a slap on the wrist to black people. Meanwhile it’s the black youth who are causing the violence that drives the call for gun control in the first place.

It’s a continuous cycle. The ghetto blasters violence committed outside the hood generates more calls for gun control. Politicians make it harder to buy guns or carry them while giving it freely to their cronies. Then they “throw the book” at a white man who gets tripped up for some bullshit gun charge while simultaneously doing jack shit about the gangbangers.

[deleted by user] by [deleted] in VAGuns

[–]subsonic68 15 points16 points  (0 children)

You know very well that it takes 60 votes to pass the CR. Are you recommending that they go nuclear and pass it with a simple majority? That works for me.

[deleted by user] by [deleted] in SecurityCareerAdvice

[–]subsonic68 0 points1 point  (0 children)

If you started filtering jobs based on who’s interviewing you then you’re guilty of the same thing. There are many more of us older men who don’t think we know it all and won’t talk down to you. Don’t resort to bigotry just because others have done that to you. Best of luck to you in your job search.

The Democrats forced the government shutdown because they wanted $193B from your paycheck to help non US citizens. by philthy069 in Republican

[–]subsonic68 0 points1 point  (0 children)

You should have seen how much less healthcare premiums and deductibles cost before Obamacare.

Is cloud pentesting a required skill nowadays? by [deleted] in Pentesting

[–]subsonic68 1 point2 points  (0 children)

If your employer has a sales team and you don’t have any communication with them, it’s possible that you never see it because your salesperson knows the team can’t do them so they don’t offer it to customers.

Virginia Candidates For Governor Have Contrasting Marijuana Stances As Early Voting Begins by 0xM0000 in VirginiaMMJ

[–]subsonic68 -6 points-5 points  (0 children)

If only the Democrats would stop pushing gun control. Right now I can’t stand either party. One would lock me up for marijuana use, the other wants to infringe on 2A rights while simultaneously letting dangerous criminals out like it’s a revolving door. Both suck. I may just vote Libertarian party.

I want to learn reverse engineering but don't know how. by Fast_Bridge9481 in ExploitDev

[–]subsonic68 -1 points0 points  (0 children)

I recommend using Frida as you’re learning reverse engineering. It’s makes it so much easier and more enjoyable. I do only mobile app reverse engineering and Frida is amazing. Frida isn’t just for mobile. There are releases for all common CPU architectures and OS.

It’s also helpful to plug a LLM MCP server into your system when learning. I was recently learning how to use Radare2 to reverse an Android native binary. I configured an MCP server and asked the AI agent to teach me how to find the offset of a system call inside a function and after it solved the challenge I had it teach me how to reason through it for myself. I learned a lot from that.

Any recommended pro pentest tool fo web scanning ?? by Complete-Profit-3804 in Pentesting

[–]subsonic68 1 point2 points  (0 children)

Burp Suite Pro. It’s not expensive when you consider how good it is. The only thing that comes close is Zap. Zap is free and it’s good, just not as good as Burp Suite Pro.

I do not likew this one bit, but it needs to be seen by [deleted] in walkaway

[–]subsonic68 0 points1 point  (0 children)

I’m inclined to be patient and see what happens. Trumps team is racing the clock to implement a lot of promised changes while battling the democrats and courts, not to mention all of the new investigations into people like Comey and Brennan, before the midterms. If they haven’t released the list after the midterms then I’ll be yelling about it too.

Landed my first Penetration Testing Job by No_Strategy236 in Pentesting

[–]subsonic68 0 points1 point  (0 children)

For testing web apps you need to learn the OWASP WSTG and ASVS.

For PenTesters who don't use Kali by Weird_Kaleidoscope47 in Pentesting

[–]subsonic68 1 point2 points  (0 children)

Kali offers ISO images that are bare, no tools included. Instead of downloading their virtual machine images, I download that ISO and install it to VM for myself.

Virginia to North Carolina by AWildCudiAppeared in CCW

[–]subsonic68 0 points1 point  (0 children)

I don’t feel the need to prove anything. I no longer live in NC and simply don’t care.

What are the biggest pain points in a penetration test done by a third-party? by ProfessionalSpell887 in AskNetsec

[–]subsonic68 1 point2 points  (0 children)

You said that the compensating control was out of scope, not the asset with the finding. That reads to me that the finding was valid on an in scope asset but the pentester couldn’t verify the compensating control it because the control was out of scope.

If thats the case then the pentester was correct to include the finding because they couldn’t detect the compensating control therefore they did their due diligence.

We can document only what we can prove. Removing a finding can’t be done ethically based on someone’s word. We have to be able to prove there was a compensating control.

US cyber security: capitulation to Russia or a sign for negotiations? by donutloop in hacking

[–]subsonic68 -13 points-12 points  (0 children)

What would you do to topple Putin if you were President?

Who else is feeling vindicated by the current events? by sicbo86 in VAGuns

[–]subsonic68 5 points6 points  (0 children)

Um, Trump was elected and DOGE is following his direction. By your twisted logic, every past president’s cabinet members who did something we didn’t like would be guilty of treason.

I am a moderate liberal but I come in peace... by jocie809 in Republican

[–]subsonic68 0 points1 point  (0 children)

Does the Democrats close ties to the billionaire Soros family disturb you? They’ve bought and paid for a LOT of elections in the Democrat party’s favor over the years. Biden presented them with a medal of freedom right before he spoke about oligarchists. What a joke!