/sec/ - Cybersecurity General

We are demerging from /cyb/ because they are LARPers who don't do shit IRL.

>we
By popular demand.

The following are resources that may be helpful to you. Don't trust anyone and do your own research.

Pastebin:
>hastebin.com/cesuxoribi.cpp

Why is it so empty?
>It is a rough copy of curated resources. As we have seen how well 400GB ebook torrents work, it was decided to make something easier for everyone to digest. More will be added.

Why are you so paranoid if you've got nothing to hide?
>philzimmermann.com/EN/essays/WhyIWrotePGP.html

IRC:
>There are none that are reputable. Start your own and invite only people you think are serious, lest you become like the old channels. It's not recommended to interact with anyone from the overarching Sup Forumsentooman community. >This general is a tool, not something to substitute as your identity.

Communities:
>There are many, none public are worth the time. Look for individuals with aptitude.

Thread archive:
>N/A

Previous thread:
>N/A


If you have a link that isn't in here, post it.

Other urls found in this thread:

prism-break.org/en/
privacytools.io/
mail.riseup.net
protonmail.com/
openmailbox.org/
tutanota.com/
cock.li/
linuxmail.info/
github.com/cliffe/SecGen
archive.is/5LfTV
archive.is/a4w6q
archive.is/0nySC
archive.is/jK3UV
archive.is/jMpu5
archive.is/4J0Ot
archive.is/UtlT3
archive.is/R1kJT
archive.is/gZ3LN
archive.is/WUHoi
jmdev.ca/sheridan/Comp_TIA_Security_Guide_to_Network_Secur.pdf
catb.org/~esr/faqs/hacker-howto.html
cybrary.it/
n0where.net/
offensive-security.com/metasploit-unleashed
resources.infosecinstitute.com/
windowsecurity.com/articles-tutorials/
sans.org/reading-room/
corelan.be/index.php/articles/
opensecuritytraining.info/Training.html
blackhat.com/html/archives.html
securitytube.net/
opensecuritytraining.info/Welcome.html
beginners.re/
threatpost.com/
deepdotweb.com/
packetstormsecurity.com/
cvedetails.com/
routerpwn.com/
exploit-db.com/
rapid7.com/db/
0day.today/
overthewire.org/wargames/
pentesterlab.com/
itsecgames.com/
exploit-exercises.com/
enigmagroup.org/
smashthestack.org/
3564020356.org/
hackthissite.org/
hackertest.net/
0x0539.net/
vulnhub.com
ringzer0team.com/
root-me.org/
microcorruption.com/
starfighter.io/
shodan.io
censys.io
zoomeye.org
njal.la/
nature.com/articles/srep43428
twitter.com/SFWRedditVideos

>Pastebin
>hastebin.cpp

What?
About the general, congrats, I like the idea. Just don't forget to mention DNScrypt. Everyone should install that in their computers and routers.

>Security Focused Operating Systems
OpenBSD
LibertyBSD
Parabola GNU/Linux
Arch Linux
Gentoo
Alpine Linux
QubesOS
Whonix

>Which software do i use?
prism-break.org/en/
privacytools.io/

>Which email provider do i use?
riseup.net mail.riseup.net
Protonmail protonmail.com/
Openmailbox openmailbox.org/
Tutanota tutanota.com/
cock.li cock.li/
Your own mail server. Postfix + Dovecot linuxmail.info/

Hastebin is quicker to deploy and less bloated.

So what's the issue with #Sup Forumssec?

What are we studying?

Ive finished taking notes from the first CCNA Cyber Ops exam book (SECFND) and will now parse my notes over and over until I have all the concepts embedded into my skull. Should sit this exam in 6 weeks, assuming work stays as quiet as it does.

At home I am going through
>penetration testing by georgia weidman
>hackers playbook 2
>slowly building a real virtual data centre
That one is for two reasons; to get my sysadmin skills up, and so I have something real to target; doing SMB exploits on unpatched windows boxes has lost its charm. I want to get my automation skills up so I can rapidly deploy a domain.

Creating a windows version of github.com/cliffe/SecGen is a project Id like to do.

Dead and runoff for Sup Forumspunk.

>runoff for Sup Forumspunk
What? Please detail a bit further.

Oh for fucks sake. The cyberpunk LARPers.

looking to purchase the most secure and private smartphone (out of the box) budget for £500 what should I get? blackberry keyone?

Yes I get the part about them being LARPers but I don't get the part where they ran off to #Sup Forumssec.

/sec/ was a thing on Sup Forums about a year back, had a much better OP

OPSEC and malware analysis. Currently following up on a large archive of advice dumped by the ew crowd.

You should post your notes if they're digital, they might help out others.
See: It's a holding pen for Sup Forumspunk when it gets too crowded. No one knows anything.

>out of the box
None. Get as low-tech as possible, flash and disable unnecesary hardware, and replace kernel.

I'll find and set it up.

The cyb/sec general would list ONE irc for both, separate topics. Part of the reason why the demerge is occurring. To reclaim and have our own space.

>You should post your notes if they're digital
Negative ghost rider. I do on paper notes. Something about reading then WRITING it down makes it stick in my head. It does make it awful to hold onto later on though. I have manilla folders filled with loose leaf paper for random topics.

Ah too bad. Good luck with your exam.


Here is practical discussion on privacy of hardware:
archive.is/5LfTV
archive.is/a4w6q
archive.is/0nySC
archive.is/jK3UV
archive.is/jMpu5
archive.is/4J0Ot
archive.is/UtlT3
archive.is/R1kJT
archive.is/gZ3LN
archive.is/WUHoi

>None.
I'm asking whats the best out of the box option for a smartphone, not a good option, but the best available

I really don't understand your point, the channel is devoid of discussion because barely anyone springs up one, not even the LARPers.

What the fuck are you even talking about, #Sup Forumssec was made when /sec/ springed up back again.

>secure
iphone
>private
literally nothing. genuinely, and unironically, no smart phone is private. ios exploits are the most sought after thing in the goddamn world. because its not a flaming pile of dogshit like android

Generic tracfone, bought in area with no CCTV, paid in cash, activated with fake info 1000km+ away from anywhere you visit.

Smartphones are by design terrible. If you want breadth of features, any android phone without SD. Install f-droid and have fun.
Others have issue with the IRC. The main problem is it's not good, that is all.

whats the tech word for people trying to get you, attack group or red group or something?

>attack group or red group or something
Red team and APT

Read Team for offense. Blue team for defense.

that doesn't seem right, think it was scope something sorry for being so vague

Free sec textbook: jmdev.ca/sheridan/Comp_TIA_Security_Guide_to_Network_Secur.pdf

i would like to voice my opposition to the forceful de-merger by a handful of anons who took it upon themselves to do it, as someone who started with the cyb, and made my way to sec.
but i suppose i might as well lurk and see how it shakes out.

Please stop pushing comptia. It was you in the other thread who wanted that n+ to be put in the pasta didn't you. Their certs are literally useless. Just wait until your exam.

Kino.
As long as there is shit throwing from either side, it is a free market.

This isn't a democracy. Bask in the irony all you like.

>Kino
W-wut

>Others have issue with the IRC. The main problem is it's not good, that is all.
Then make it good? Owner of the channel here, I'll take any suggestion that I feel is good. Joined the #Sup Forumspunk channel for first time and for a second and saw a lot of common people in both, I could purge everyone if I feel that's what people want, I don't want quantity but quality of people in the channel, and some discussion if possible.

Could also put a password on the channel that needs to be unlocked as a flag or something.

Also people having severe issues with IRC are just mongoloids that don't even deserve into /sec/ and you can't prove me wrong, and the IRC guide was a mistake.

Sup Forums vernacular that has devolved into "nice."

Old /sec/ general:

How To Become a Hacker: catb.org/~esr/faqs/hacker-howto.html

>Learning
cybrary.it/
n0where.net/
offensive-security.com/metasploit-unleashed
resources.infosecinstitute.com/
windowsecurity.com/articles-tutorials/
sans.org/reading-room/
corelan.be/index.php/articles/
opensecuritytraining.info/Training.html
blackhat.com/html/archives.html
securitytube.net/
opensecuritytraining.info/Welcome.html
beginners.re/

>News/CVE releases
threatpost.com/
deepdotweb.com/
packetstormsecurity.com/
cvedetails.com/
routerpwn.com/
exploit-db.com/
rapid7.com/db/
0day.today/

>Wargames
overthewire.org/wargames/
pentesterlab.com/
itsecgames.com/
exploit-exercises.com/
enigmagroup.org/
smashthestack.org/
3564020356.org/
hackthissite.org/
hackertest.net/
0x0539.net/
vulnhub.com
ringzer0team.com/
root-me.org/
microcorruption.com/
starfighter.io/

>Resources
shodan.io
censys.io
zoomeye.org

He's misusing it because Sup Forums started using it for everything, as it more specifically means a REALLY HIGH QUALITY movie.

>How To Become a Hacker: catb.org/~esr/faqs/hacker-howto.html
Delete this.

Changing the name and removing the Sup Forums so larpers don't join is a good start. Removing voice from anyone that doesn't have a certain amount of flag points/ isn't verified to know what they're talking about is better.
>Could also put a password on the channel that needs to be unlocked as a flag or something.
This is good. I know a discord server for CTF uses this. They have a bot and ranks.
>Also people having severe issues with IRC are just mongoloids that don't even deserve into /sec/ and you can't prove me wrong, and the IRC guide was a mistake.
Yes.

>Q: How can I get the password for someone else's account?
>A: This is cracking. Go away, idiot.
>Q: How can I break into/read/monitor someone else's email?
>A: This is cracking. Get lost, moron.
Kino.

>Owner of the channel here
>Also people having severe issues with IRC are just mongoloids that don't even deserve into /sec/

I like you and your channel already

Last part meant for

>How To Become a Hacker: catb.org/~esr/faqs/hacker-howto.html
This shit needs to fucking go.

People tell me to use VPN, to not use a VPN.

I'm confused. Why so much conflicting info?

Improperly setup is useless. Properly setup is good. Most likely if you need to ask you don't have the resources to setup properly.
Is it terrible? I skimmed and it seems like regular jaron file.

People who tell you not to use a vpn are mildly retarded, and people who tell you to use a vpn without also telling you need to combine it with Tor to be of any effect are more than likely just as retarded.

A vpn is for privacy, not anonomity. That is what tor is for. A vpn is not a magic bullet, and the people saying not to use one, are the sorts who found out that's it's not a be all and end all.

>Is it terrible?
Typical
>cracker not hacker!
type thing. That grinds my gears so fucking badly.

I've tried some out but never bought any or used one permanently.

What does set up properly mean to you guys? The ones I've tested worked well, just looking for more clarification.

Yeah. I'm not doing anything illegal. I just want to have privacy when connecting to a public wifi or at school, on a plane. etc.

>I just want to have privacy
Oh, well you're sorted then. Vpn it is.

>"Don't call yourself a ‘cyberpunk’, and don't waste your time on anybody who does."
Besides some historical shit, it seems pointless to have in a general anyway.
Regular VPN is fine for your usecase. Better to state intent with your question too next time, some are autistic and will go off on tangents.

The reason I named the channel #Sup Forumssec was just for the Sup Forums "naming convention" of IRC channels, I could for sure just nuke this one and swap to #/sec/ but I actually like the name.

I seriously don't have much time this week, but could start doing some stuff if I could get some help it would be amazing, never gotten much help from anyone really. Could start with nuking everyone from #Sup Forumspunk, although that will take some time, because obviously some sort of filtering should be done, namely just me filtering those that were actually more /sec/ than /cyb/.

People voiced were already those that had done stuff in CTFs, I was just keeping them voiced to give that sort of feeling that the channel had some sort of life and for people to start discussions or something.

Also I have the hacking.moe domain, could use that for the CTF to join the channel and finally give it a proper use.


Y-you too.

It all ends up in trust issues with those saying no to VPN, you could just route through tor too like said.

It's the MIT term of hacker.

Thanks guys... I appreciate the help. I might go with Trust.Zone VPN, still debating on buying a one month.

>The reason I named the channel #Sup Forumssec was just for the Sup Forums "naming convention" of IRC channels, I could for sure just nuke this one and swap to #/sec/ but I actually like the name.
There is no problem with keeping Sup Forumssec as the name, except a larger flow of users will need to be filtered. Sup Forums also doesn't mean what is used to five years ago, this is just another shitposting board.

I'll be glad to help with the site and IRC. I'm busphere on Rizon.

Trust.zone is cheap, but most recommend is PIA. If it's regular browsing, it doesn't matter, but trust.zone keeps logs.

I've heard a lot more negative about PIA..

I've heard the best about NordVPN. I used trust.zone trial and it worked well, I know they log bandwidth. According to that chart.

>I've heard a lot more negative about PIA..
This. I rolled my own VPN with alibaba for $30 a year.

how to disappear completely from the internet/freeze what is being stored?

Start by obscuring all of your info on current accounts.

You can't. The best you can do is abandon all your previous online presence. The internet is forever. You should know that, unless you're a newfag

What do you guys think about njal.la/ ? Been considering them a while. Any experiences to share?

Does PRISM still even work anymore now that ICANN isn't a government organization?

that's cause /cyb/ is pretty much an overlap with lainchan (the mlg h4xx0rgz fr33d0m fighters lul)

It's called XKEYSCORE now.
Muh sci-fi bookclub, so soykaf.

No experience, but seems like a gimmick. WHOIS Guard is good enough if you're not doing anything illegal.

What is this, the 5th time we've tried to seperate? We need the larpers to bump the thread. Asking "what does cyb have to do with sec" became so pointless it was a meme. You'll see. Also their OP pics were better.

t. butthurt /cyb/ larper
Go to /tg/

Lol nice meme defense, I'm an IT Sec Analyst out of Vegas I've been here lurking forever. I've seen the thread split before. Always goes back. You guys need to just give it up. We barely had 40 active posters as it was, if that.

This time it'll be different.

>security focused systems
>arch
fucking what?

History is not with us.

Don't know if it's been posted already but I want to contribute to the first /sec/ thread so

Linux distros without systemD

4MLinux
Absolute Linux
Amazon Linux
Bedrock Linux
Calculate Linux
Cromnix
Dragora
Dynebolic
Funtoo Linux
Kwort Linux
Legacy OS
Linux Console Mate or LXDE desktop
Milis Linux
NuTyX
Openwall
OviOS Linux
Pentoo
Pisi Linux
Plamo Linux
Plop Linux
Porteus
Porteus Kiosk
PostX
Redcore Linux
SalentOS
Simplicity Linux
Spark Linux
Star Linux
Tiny Core Linux
TLD Linux
Vector Linux
Void Linux
Window Maker Live
Zenwalk

Feel free to add any I forgot.

Security is not privacy.
Those are two different things.

Greater control. They were another's recommendation.
Thanks, user.

Forgot Source Mage and Gentoo I think it's only an option to use systemd

Ok sure. Security is a tool and privacy is a problem security solves. What's the point?

i don't think arch has any place on that list. you have no more control over arch than you do over ubuntu or gentoo or debian etc. also why is hardenedBSD not in the list? literally a fork of freebsd designed for security

I believe Alpine Linux doesn't use systemd.

I dislike putting this directly tied to CTF points like ctftime if that's what you are talking about. It's bad enough we are making hacking an esport, people still need to be able to ask the occasional stupid question. /r/reverseengineering (plebbit) manages to get by fine with very few barriers to entry. You need to create a culture of excellence in the channel rather than just exclude retards. If you focus on exclusivity the channel will eventually die because old fags will leave and no one wants to jump through hoops for a Mongolian shadow puppet boards /sec/ thread.

HardenedBSD is just OpenBSD with lesser code quality.
This is a good point, but how do you achieve it without turning into freenode 1000+ user mess? I have some ideas, but using them with IRC will be heavy.

First don't frame it as a hacking channel. Keep the focus on stuff like upcoming ctfs, industry news, sharing research etc. Hacking channels bring all the morons out of the woodwork.
Kicking retards asking for how to hack their friend is fine but if everyone in chat is talking about sha2017 or something it sets a tone.

Thank you.

Who says the CTF stuff will be hard, it's just as an entry barrier. And the occasional stupid question can usually be answered in the thread or in another more proper place.

Silly questions are usually asked by skids that can barely breath and type at the same time anyway.

>First don't frame it as a hacking channel. Keep the focus on stuff like upcoming ctfs, industry news, sharing research etc.
That was literally what #Sup Forumssec was trying to accomplish, but it had barely any activity.

How can I use Fiddler for Malware Analysis? Do I need to be in a VM to be safe?

Fiddler checks HTTP traffic on webapps. You don't need to use a VM, but it's pretty much mostly for browser work.

Wrong it works on any application not just browsers.

I asked something similar here a few weeks ago and the guy reccommended vm with windows + procmon + netmon.

Yeah, I forgot the uses of HTTP in non-browser malware.

>Encryption key distribution via chaos synchronization

nature.com/articles/srep43428

Thoughts?

HardenedBSD is FreeBSD, friend.

That's why it's being compared with OpenBSD, not FreeBSD.

My bad hombrè, misunderstood

It's no big deal, दोस्त

Ty

Anytime, compadre.

security focused OS, not one pentesting distro amongst them..baka

>An empty OP.
>Don't interact with anyone!
Whoa, I'm sure this'll last long.

>pentesting
>not half a step above a cracker kiddie
...

All jokes aside, you can cross-compile many tools that are in Kali Linux, Pentoo, and BlackArch (+ BackTrack, etc.) for whatever distro you're using, bud.

Looks like you're in the wrong place, amigo.

>Looks like you're in the wrong place, amigo.
You don't own the Internet, nor Sup Forums.

Install DNScrypt, isolate your network (don't let devices see each other).
Hide your modem, if you type 192.168.0.1 or 192.168.100.1 you shouldn't see the modem login or info page.
Install dnscrypt in the router.
Only one computer should be able to log into the router.
Create a separate vlan to log into the router. Ideally you must physically move to the router to plug the Ethernet cable into the right port.
Don't manage your router while being online.

I work for the masked men they call Sup Forums.

This is interesting, where did you learn this?

ive been using backtrack since forever, done me good so far..cant see why ide want to use another distro when everything is already there in one OS?

It's up to user choice. I don't use backtrack because it's linux. BSD works well for me.

wouldnt checking for DNS leaks once connected to vpn show if anythings amiss?

>>I don't use backtrack because it's linux.

whats the isue with linux?