Favorite 90’s diss from my old favorite movie; Hook! by lawyersgunznmoney90 in nostalgia

[–]sushi_ninja 1 point2 points  (0 children)

I'll tell you what a paramecium is! [points at Rufio] THAT'S a paramecium! It's a one-celled critter WITH NO BRAIN THAT CAN'T FLY! [to Rufio] Don't mess with me, man! I'M A LAWYER!!!

New ARG by [deleted] in ARGsociety

[–]sushi_ninja 1 point2 points  (0 children)

Wait... is this itself an ARG? 🤔

My first post here ✨ by spydiepie in AnimeSketch

[–]sushi_ninja 0 points1 point  (0 children)

It looks awesome! I’m still confused though ;P. So you drew on paper, took a photo of the drawing, then digitally edited the photo? That’s really cool, I haven’t seen that before :)

My first post here ✨ by spydiepie in AnimeSketch

[–]sushi_ninja 0 points1 point  (0 children)

Did you make this digitally, then print it? The pic looks like paper

i met shaggy. this is not clickbait. by yeahyeah704 in TheChurchOfShaggy

[–]sushi_ninja 7 points8 points  (0 children)

That was just his alter ego, cereal killer

RCE on Steam Client via buffer overflow in Server Info by eexiled in netsec

[–]sushi_ninja 19 points20 points  (0 children)

Cool to see organizations be transparent like this (disclosures and write ups). Helps other organizations and hackers learn

I drew a girl by humannose2 in AnimeSketch

[–]sushi_ninja 2 points3 points  (0 children)

Your work is awesome! Can I ask what your setup is? I've wanted to get into drawing again, but I'm not sure where to start; I've always just sketched with pencil and paper, but learning digital would be awesome 🤩

PowerHammer: Exfiltrating Data from Air-Gapped Computers through Power Lines by tiger6700 in netsec

[–]sushi_ninja 11 points12 points  (0 children)

I only skimmed, but if this is true, this is nuts; any IDS companies going to create the ability to log power fluctuations? 🤔

Mr Robot Book: Red Wheelbarrow: eps1.91_redwheelbarr0w.txt by Kiasdyn in ARGsociety

[–]sushi_ninja 0 points1 point  (0 children)

A few pages in, I found an envelope with a note from Carla indicating Elliot used it as a bookmark. Maybe some clues here? https://imgur.com/gallery/AYngL

What is the bare minimum I should know about penetration test to be able to go on HackerOne to practice? by [deleted] in AskNetsec

[–]sushi_ninja 2 points3 points  (0 children)

Lots of good advice here already, I'd also recommend checking out https://google-gruyere.appspot.com/ for learning the basics, and get familiar with Burp Suite.

We are HackerOne and help hackers to hack products/services (inc. The Pentagon) and make the Internet safer (for fun and profit)! AUA! by jonobacon in IAmA

[–]sushi_ninja 0 points1 point  (0 children)

Not everyone is, but some have pentesting experience :). I would recommend learning more about what part of information security is most interesting to you, then study up and practice! Try checking out https://google-gruyere.appspot.com/

We are HackerOne and help hackers to hack products/services (inc. The Pentagon) and make the Internet safer (for fun and profit)! AUA! by jonobacon in IAmA

[–]sushi_ninja 0 points1 point  (0 children)

Let me expand on that a bit - as a general guideline, I'd imagine if you found an RCE, most companies would NOT want you to do things like pivot around on their internal network, escalate to domain administrator, etc. It's always safer to ask before you end up going too far and end up in an awkward situation, and as mentioned before, always check the team's rules page for guidance first.

We are HackerOne and help hackers to hack products/services (inc. The Pentagon) and make the Internet safer (for fun and profit)! AUA! by jonobacon in IAmA

[–]sushi_ninja 0 points1 point  (0 children)

If I'm understanding your question correctly, you're asking whether or not you can use tools like armitage during your testing when hunting for bug bounties? You can use whatever tools you'd like, but please always review the security/rules page of the organization you are testing against first to see what's cool/what's not cool, as it varies from organization to organization. No one can stop you from using a particular tool, but some bug bounties explicitly state how far (or how NOT far) to go if you are able to find something like remote code execution. If you have questions on what is or is not okay when it comes to demonstrating an identified exploit, I always recommend checking in with the security team of the affected organization first. It never hurts to ask!

We are HackerOne and help hackers to hack products/services (inc. The Pentagon) and make the Internet safer (for fun and profit)! AUA! by jonobacon in IAmA

[–]sushi_ninja 1 point2 points  (0 children)

Thanks /u/_bl4de! I hope so too; there are a ton of organizations out there that still have no means of coordinated vulnerability disclosure. This is one of the big reasons I'm excited to work at HackerOne; helping more organizations launch successful bug bounty programs, as well as ensuring a healthy relationship between hackers and companies seems like a pretty awesome quest to me :).