/netsec/ - Net Sec General

/netsec/ is dedicated to everything about computer security, networks, exploits, reverse engineering, social engineering, hacking, tricks, etc.

Daily Programming Thread: (Cross-thread)
Web Dev General: (Cross-thread)

How To Become a Hacker: catb.org/~esr/faqs/hacker-howto.html

Learning
cybrary.it/
n0where.net/
offensive-security.com/metasploit-unleashed
resources.infosecinstitute.com/
windowsecurity.com/articles-tutorials/
sans.org/reading-room/
corelan.be/index.php/articles/
opensecuritytraining.info/Training.html
blackhat.com/html/archives.html
securitytube.net/

News/CVE releases
threatpost.com/
deepdotweb.com/
packetstormsecurity.com/
cvedetails.com/
routerpwn.com/
exploit-db.com/
rapid7.com/db/
0day.today/

Wargames
overthewire.org/wargames/
pentesterlab.com/
itsecgames.com/
exploit-exercises.com/
enigmagroup.org/
smashthestack.org/
3564020356.org/
hackthissite.org/
hackertest.net/
0x0539.net/
vulnhub.com
ringzer0team.com/
root-me.org/
microcorruption.com/
starfighter.io/

What are good proxies to use?

This is the best 'general' on Sup Forums.

Full stop.

Anyone got recommendations for a good security podcast?

proxies are garbage thats baby tier security this isnt 20th century

So about that esr dude. I like his writing and his ideas but how do you make a living being a hacker according to his view of the term? How do you get food in the table only writing open source / free software?

On the table *

Also I wonder how this topic seemingly attracts nobody. Not even (that many) snarky comments.

I'm interested but have no time because of work.

does the hackrf one make a decent spectrum analyzer or is it really that much better to get expensive equipmen?.

you get hired by a company doing open source development or create a software support company that sells technical support to companies using open source software. there's no money in giving your stuff away for free, but maybe you can hack that system and figure something out.

I've only ever heard that you should buy Ettus Research or better.

aes-xts-plain64

what does plain64 mean? is it plain text?
Also i hear xts is bad. what should i use instead,and how to change it

Defensive Security is pretty good

Risky.biz is fab

How would one get started in bug bounties and such? Should I start off spending loads of time on sites like root-me, dvwa etc to build up skills then move on to bounties? Or should I just try and try and try on "real" websites and learn that way?

>be me
>want to debug elf file in debugger
>download edb-debugger (open source).
>doesn't have any 3rd party plugin, especially to hide debugger
>missing features from closed source Windows debugger
>run application
>closes itself because it detects debugger
>close edb-debugger
>segmentation fault

4/10 see me after class.

i thought bug bounties were offered on specific products? maybe you should start by working on those products.

They are - what I meant was should I start by trying to attack those products, or should I start by spending loads of time on practice sites (as in, which would I learn more from and make better progress in). Perhaps I am best to take the direct approach though!

What about VPNs? Now lets say a VPN wasn't available and you needed to use a proxy, would proxies like hidemyass be good?

what's with endbranch? can you still jump into the middle of an instruction as long as the bits match endbranch? what about direct jumps?

if you have the skills, don't waste time on contrived tests. the real stuff is much more tricky and as long as you can legally attack an application or system you should legally attack that application or system.

only if you chain proxies through multiple jurisdictions and bounce through a few different anonymous hosts.

Alright cool, thanks for the advice!

fuck this thread

CANCER
A
N
C
E
R