#cybersecurity-questions

140 messages · Page 1 of 1 (latest)

split dagger
#

hi guys! since nobody has posted @here, I figured I'd start! I've been in the industry for about a decade now and am happy to answer any questions anybody has about pentesting, vulnerability research and exploit development. I am a senior pentester and I do tool development for a different company as well so if anyone wants to ask any questions feel free to post in here or DM me! 🙂

winter oyster
#

Hi @split dagger - I would like upskill in career in Security space, I have been working in End user technology services in managing Mac devices. Can you share me guidance here to start with -. It’s really puzzling for me while searching in internet, red, blue teams.. please please suggest

split dagger
#

The good news is, is that the security community is amazing and is always going to be there to help push you forward on your journey! I wouldn’t be where I am today without my peers.

#

Would you like to DM me so we can chat more about this? I’d be happy to point you in the right direction and guide you where possible!

winter oyster
#

Sure, thank you.

thick sonnet
#

who can help me get an ip address?

radiant narwhal
#

XD

split dagger
thick sonnet
long pawn
#

What—did you realize how stupid your question sounds?

#

Go outside, kid.

split dagger
thick sonnet
#

I am a beginner and I would like to learn :(((

split dagger
#

we all know, he knows, we gotta be respectful

long pawn
#

I beg to differ, but I'll leave it at that

split dagger
#

there ya go

thick sonnet
#

There's a guy on Discord who insults me and everything and I'd like to have his IP

split dagger
#

and yep there it lol

thick sonnet
#

you can help me or not

long pawn
thick sonnet
long pawn
thick sonnet
#

Bro :/

long pawn
#

Move on with your life. You won't be getting help with illegal activity here.

thick sonnet
#

ah sorry

#

My bad

jaunty star
astral belfry
#

Hi! I have a few questions. For context, I’ve been a penetration tester for about 11 months, and I’ve recently been assigned to a cloud VAPT (Vulnerability Assessment and Penetration Testing). I can't reveal much information, but I have no one to turn to for help, and I lack experience in this area. To build a foundation, I took the ARTE course.

Since it’s a white-box test, I’ve been running various tools, but I don’t have the confidence to fully support some of my findings. I want to be accurate and relevant to the client by genuinely understanding whether the issues flagged by open-source scanners (like Prowler and ScoutSuite) are real concerns or not. I would really appreciate some advice from all the wonderful people here.

split dagger
#

If you want to go over the details of the findings with me (redacted) and give some context, I can help tell you what I would do in those situations

#

It can be difficult in the beginning making executive decisions about your clients, but you've been trained and are the expert in this situation, so if you don't want to share, I would say trust your gut. If you are really unsure, confer with your client to determine whether or not certain things which were identified are intended to be exposed or not. You do have to know when to draw a line though which is the hardest part imo

#

Some clients will ask you to downgrade findings severity, but you may feel that they are very critical, and you have to either find a balance with your client through discussions with them, or stick with your initial judgment.

#

I'm sure you can remember at the beginning, wondering whether to report an XSS as a high, medium, low, critical, whatever. You're just repeating the same process.

astral belfry
# split dagger Hi my man

Thank you so much for offering to help! I will be really happy to received your perspective on some of the specific findings. I’ll PM you shortly with some redacted details of the findings. Your guidance will be invaluable to me, thank you so much again for being willing to assist! 🥲.

split dagger
#

Of course man!

#

I may be hopping off soon, but if you send over your questions I can answer as best as I can real quick! If not tonight, tomorrow morning for sure

astral belfry
warped spire
#

Hi everyone,

I'm beginner in IT security especially in pentesting.
I'm writing to ask some questions about pentesting.
I have a job interview next Tuesday and I'd like to have your perspective as a pentester.
According to this: https://www.wizbii.com/company/sysdream/job/stage-securite-pentester-h-f could you tell me what kind of questions you will ask at the job interview?
What do I need to know about pentesting?

Wizbii.com

Stage : STAGE SECURITE/ PENTESTER - (H/F) chez Sysdream à Levallois-Perret. Postulez dès maintenant et trouvez d'autres jobs sur WIZBII

astral belfry
# warped spire Hi everyone, I'm beginner in IT security especially in pentesting. I'm writing...

During interviews for a Penetration Testing role, I've commonly encountered the following questions:

  1. Web/Network Methodology: What are your methodologies used for web and network penetration testing.

  2. OWASP Top 10 Question: what do you understand about OWASP Top 10, like for example what is broken access control?

  3. Vulnerability Questions: Specific questions about vulnerabilities like SQL Injection, where I was asked to describe the vulnerability, provide a proof of concept, discuss its impact, and suggest remediation methods.

  4. Scenario-Based Questions: For example, handling a situation where a client refuses or rejects the findings. These questions assess how I communicate and manage client relationships, especially when there's disagreement.

I'm not sure if this will be useful for you... As your job role and mine are somewhat different. So I hope it will help 🙂

gray compass
#

Hi,
I am a software developer trying to change the career into cyber security. I like Pen Testing and I am following TryHackMe rooms and learning paths at the moment.

I have some questions related to Cyber Security. Greatly appreciate it if you can point me in the right direction.

  1. Do I have to have any cyber security certs? If so, which one is the easiest so I can start small?
  2. Is TryHackMe and HackTheBox is enough to learn things and become hireable in Cyber Security field?
  3. I like CTFs, but I saw some CTF competitions require a team. How do I get into a team and how to decide what each member do?
split dagger
# gray compass Hi, I am a software developer trying to change the career into cyber security. I...
  1. HR typically with scan you out without a cert. Unfortunately that's been my experience in the past. You'll want probably OSCP or CEH (which sucks but is common for HR people)

  2. It's enough to learn things yeah, but nothing will beat true experience.

  3. You can join the team I play on as long as you participate! That's our fearless leader's only rule really. 😅

Though I will say that CTFs, while fun, are not practical in the sense of you're gonna be seeing that in a real engagement. You might, but it's unlikely.

#

For example, this was a solve description for a recent CTF we played, "zlib oracle with xs leak, flask max redirect length"

#

Like there is like a .00001% chance of that occurring in the wild haha

azure sandal
# gray compass Hi, I am a software developer trying to change the career into cyber security. I...

I agree with @split dagger on all points.
I’d like to add more on THM/HTB: sure it is a way to learn, but most of the boxes are unrealistic. Sometimes because they’re too easy, most of the times because they’re too crazy.
I link for you three posts from my blog which could be useful for you:

./andregrigoletto

I took the process the wrong way 2020 has been quite a weird year for me and not just because of covid-19. I’ve earned my Sec+, I’ve read more InfoSec related books, I’ve spent a lot of time on TryHackMe and OverTheWire platforms, I’ve switched my job (again) and I’ve started the University.
It is a lot of changing, at least for me and that’s wh...

./andregrigoletto

Intro and how to read this article On August 30th I passed the OSCP exam.
Please, before jumping into reading this article, let me explain how it is structured. My aim is to provide a clear overview of the whole OSCP journey. Therefore, I divided it into two bigger sections:
The first one is about an-high level overview of the journey itself. S...

./andregrigoletto

Hey, there! With this blog post, I would like to tell you about some thoughts on job hunting that are running in my mind for a while.
A sort of disclaimer I don’t know who are you, where are you from, what have you been through, so I can’t say if what you’re going to read here could fit your life. Regardless, I hope it is going to help you or p...

#

Other than that, I would suggest you to get into bug bounty to learn web skills and soft skills (Reporting and communicating with triager). In the case you’ll go for it, do not chase money, work to learn, period. Study on portswigger academy and enrich your knowledge by reading published bug bounty report (Hackerone is plenty of them).

To learn skills related to infrastructure/network, go to Vulnlab which is great for that kind of stuff. Then, it would be so beneficial to set up your own vulnerable AD lab, to do so, check out GOAD by Orange.

#

Hope you’ll find this useful @gray compass pun_dog

gray compass
#

awesome..thank you @azure sandal

azure sandal
azure sandal
#

What?crycat

past sable
serene onyx
# past sable Why?

it needs at least one parameter like python sqlmap.py -h to show the help menu

zinc oracle
#

Anyone have any interview tips? I have a red team engineer interview next week?

radiant narwhal
#

you don´t want to end in a place where you are not comfortable or they are not comfortable with you, so just show them what you know, and most important, don´t try faking what you don´t.

#

And show interest in the position of course

zinc oracle
# radiant narwhal I guess be yourself is always the way to go

Thanks sort of an interesting position. I already work at the company and have worked with the pentests teams before and this new red team engineer position is an internal listing they asked me to apply for. So it’s not as much of a shot in the dark.

coral sky
#

Hello ! Im new here! I need one support my Mac OS and iOS iPhone..
Have one guy talk portuguese?
Óbv i Pay the support

long pawn
#

???

twilit quail
#

how to pyass httpOnly when xss script

#

and how to fix it

zinc oracle
#

anyone do any work with istio or service messhes lately?

shut spruce
#

May You know if Microsoft introduced some security feature to edge? I try to still ntlm hash via xss (POC), had request on responder: „sensing ntlm authentication request” but not response from client appears

split dagger
#

Many internal networks don't allow NTLM to go past the internal network space

shut spruce
#

external perspective, host without vpn just standard edge browser login and responder set on external vps. Application works on docker inside azure vm

split dagger
#

When you see writeups about NTLM phishing and stuff, those people usually already have a foothold internally and are just using a private IP when writing out the <img> tags.

#

NTLM can be used over the network, but it requires a client-side application to craft an HTTP request with Authentication: Digest ... inside the request.

#

So you'll rarely get a situation where NTLM phishing is the way. I'd suggest giving OAuth Illicit Consent phishing a try. No creds have to be entered, but instead the user "consents" to the application, and then you can gain limited access to their account via the MS Graph API.

shut spruce
#

Thanks for Explanation!

split dagger
shut spruce
#

So I facing with the situation where the current configuration cause prevention from html injection. Somehow frustrating due to in the form I facing with blacklist and could not find possible xss payload instead of ie browser support or tags for ntlm droping xd

split dagger
#

It's worked for me more than standard phishing, because the user gets redirected to Microsoft.com to perform the consent. They then think, because they're on microsoft.com, that it must be legit!

shut spruce
#

hmm may You got some writeup for this, never trying it before

radiant narwhal
frosty lily
#

hello.

#

I want to know how to use the file encoded by shikata_ga_nai.

How do I do that?

Invoke the encoded shell from the rwx area of ​​memory?

split dagger
#

Seems like you already know the answer to your question.

#

You can change the output format to elf/exe with -f elf so it's already in binary format

#

Read the docs or google before asking in the future though, all of this is very well documented.

frosty lily
molten rapids
#

Hi guys, for internal attacks, what are thr most suggested? I am talking pth and other....

mild parrot
mild raven
#

Carlos are you familiar with the current AD apple exploit? I'm searching for a cyber security professional that can assist me in regaining control of my devices both Mac os and iOS as they are all under control of a network domain admin. There are just at first glance thousands of apple users that have been hijacked through the open directory or directly services fork of the Mac OS. It's very serious and while I'm not a researcher I'm well versed in IT and without doubt is the worst malware/hijacking I've ever seen or could conceive truly. With limited Microsoft windows experience I've been told that all the attackers need is a apple users phone number and a reply from a text message and all devices contained in the apple id are under control of the AD admin. Please excuse me if parts of my terminology aren't adequate but in closing I should mention that all my devices are hijacked and after using NSA level bitraser erasure my hard drives still contain a hidden HFS+ partition and in the recovery environment one of the first sequences is contacting the AD node and before Mac OS is even reinstalled the attack has begun. As I mentioned going out in a bit of a limb I'm suspecting this could be happening to a an enormous amount of users and I have also been told apple is aware of this which is discouraging to say the least but in reaching out to you to get your take and see if your interested in having a look. I'd be happy to compensate you for your time. Your thoughts, Jeff

shut spruce
#

May someone have simmilar issue with aws_iam_review

got syntax error and start thinking if this should be run on lower version of python

radiant sparrow
radiant sparrow
shut spruce
# radiant sparrow actually you need to run it in a higher python version

Put this to docker python 3.9:

inz@inz-VirtualBox:~/Desktop/Tool/aws_iam_review$ sudo docker run aws-iam-review
File "/app/aws_iam_review.py", line 112
print(f" - {colored('Privilege escalation', 'green')}: {', '.join(f"{p}" for p in ppal_permissions['known_privesc_perms'][:MAX_PERMS_TO_PRINT])}{more_than_str}")
^
SyntaxError: f-string: unmatched '('

#

could You give a version of python on which You test it ? :d

radiant sparrow
shut spruce
# radiant sparrow python 3.13 should work

Yep its working 😄 one more question if output looks like this:

inz@inz-VirtualBox:~/Desktop/Tool/aws_iam_review$ python3.13 aws_iam_review.py default
[-] No OpenAI API key specified.
[-] No analyzer found

it means that the provided account was not loaded correctly? (in credentials got 3 parameters:
aws_access_key_id
aws_secret_access_key
aws_session_token

radiant sparrow
shut spruce
#

okej, so additional access should make it work, I just thinking if in case of federation it will also dill with such appoach (strange thing if I go to the console in our AWS I just see roles but 0 users)

radiant sparrow
shut spruce
#

So I need to ask our admins for adding additional policy to my current test account: arn:aws:iam::aws:policy/AWSAccessAnalyzerReadOnlyAccess and I will be able to check if in company we do not use potential dangerous policy sets ? 😄

radiant sparrow
shut spruce
#

Ok I will try and let know thanks Carlos!

umbral hollow
#

Hello! I am looking for a Personal firewall and network monitor for windows something like glasswire any recommendations ?

zinc oracle
shut spruce
#

Which tools You recommend to security assessment for k8s (i typically use scoutsuite and kubench)

gleaming vessel
#

Anyone know why I have these

gusty laurel
#

What your the best made payload in msfvenom?

shut spruce
#

Or give some better alternatives 😁

simple kernel
#

hi @gusty laurel

silent gull
neon zephyr
coral tendon
#

Is the HACKTRICKS (AZRTE) AZURE RED TEAM EXPERT good with zero Azure knowledge?

radiant sparrow
outer charm
#

@radiant sparrow Hey carlos! Hopefully you dont mind me pinging you just to ask about a PR i submitted to linpeas that failed but failed for an unrelated reason to my PR(the AWS module seems to have smth goin on). Should i make another PR or is it once the aws module is fixed then my pr can be processed again? sorry to ask ahhaha id never submitted a PR before

radiant sparrow
outer charm
radiant narwhal
#

Prowler update booooyys

trim bluff
#

Comment installé kali linux de a z

warm burrow
#

does anyone know if the hacktricks-feed is an RSS feed somewhere so i can feed it into my collection? or what the bot works against?

radiant sparrow
warm burrow
radiant sparrow
visual narwhal
#

I’m currently building a network scanning tool that wraps around existing tools like arp-scan, masscan, and nmap. The idea is to scan large subnets (e.g. a /16) in parallel for better performance.

However, I ran into a problem: if my host is assigned to a VLAN with a /24 subnet mask, how can I scan hosts in other VLANs within the larger /16 range?

radiant narwhal
#

Check your routing table

#

You might be restricted to your vlan

steep warren
#

Hey everyone, so, I have a question not related to technical skills exactly.
I’m doing pentests and frequently the sheer volume and breadth of data is just massive. Thousands of servers, users, etc.
One of my biggest challenges is organizing this information into notes and querying it. By the end of the engagement I often have a more complete listing of the org’s assets than they do! Prioritizing all of this is hard too - there’s credentials and what services you have tried them against, there’s exploits and their results, etc.
Right now, I’m using an Obsidian for taking notes alongside various data files for tracking all of it. I often have an excel spreadsheet for tracking my most promising data. I’m kind of envisioning a database scheme for tracking this information and I bet there’s some good stuff on GitHub but so far I am not aware of anything pre-made that’s portable, can be shared easily across my team and super promising.

I’m just wondering what other red teamers and pentesters are using to organize their engagement data and if you have resources, blogs, templates etc. you’ve found helpful. Thank you

radiant grotto
steep warren
lofty rose
#

Sirius — 20:12
Hii guys
i need a help
i have received this task
Please work on below activities

Definition of secure configuration document for Windows 11

Script for checking compliance with above security standards
You first identify parameters which you will include in Windows 11 SCD then work on assessment script
can anyone help me out with this task

keen thistle
#

Hey,
Does anybody have any guidelines how to do a review of 'Amazon Q' ? I don't think tools such as i.e. scoutsuite even cover this 🙁

slim rover