6 ms·
Likewise, my story about how I got into and out of security: it really just takes basic programming knowledge, understanding reverse engineering concept, and co
by hamhamed 11y ago
Likewise, my story about how I got into and out of security: it really just takes basic programming knowledge, understanding reverse engineering concept, and constantly testing shit.
When I got kicked out of college for my hack (rm https://news.ycombinator.com/item?id=5090007 https://news.ycombinator.com/item?id=5090007) all I did was spam URLs with different IDs and test if they returned 200 or 404.. and bam press coverage + job offers. Sometimes the simplest of stuff can lead to nirvana.
I'm no longer in security since it was getting very addicted (I would start testing every website I'd visit for vulbs)..and I had to change and decided to jump into the startup world.
- jacquesm 11y ago> I would start testing every website I'd visit for vulbs That's a pretty bad idea if you don't have permission from the owners of the site.
- hamhamed 11y agoPermission is the enemy of a hacker. Us enthusiasts don't mean any harm and almost never perform tests that break the software (or network). There's a reason why bounty programs exist.
- jacquesm 11y agoUs enthusiasts might end up in court and/or trouble for that. Do not do pen-testing on systems you don't own or have explicit permission to work on (such permission might be a bug bounty program or something to that effect). Yes, there is a reason why bounty programs exist, they make it plain that testing is 'ok'. In absence of a bounty program or a relationship with the company you can't claim that you 'don't mean harm' and that your tests would never break the software or the network. It's going to be lumped in with actual attacks.
- homakov 11y agoOne caveat: client side attacks like XSS that don't execute or break backend part are rather ok 100% of time
- tptacek 11y agoNot even close to true.
- homakov 11y agoAt least non-admin XSS is much harder to define as "hacking" by a judge. Otherwise, writing something like "Send your password to ha@ck.er plz!" would be considered severe hacking attempt too.
- tptacek 11y agoI don't know what country you're referring to, but in US criminal law, there is no such thing as "hacking". There is only unauthorized use. Cases will turn on whether you should have known that your use of the site while testing for security bugs was unauthorized (short answer: yes, you should have known), and whether it caused damage. But that's criminal law. That's a real concern, but the bigger concern is tort law. If you blow up someone's site by getting an XSS input cached and replayed to all its users (or, heck, even if you just cause an alarm that they have spend money responding to), you are going to be liable.
- homakov 11y agoThat's true. I myself would never poke around some corp. website w/o a bounty program
- jacquesm 11y agoThen please don't indirectly tell others it is ok to do so. You could cause a lot of trouble for someone who sees you as an authority figure. Of course 'homakov said it was ok' is not a very good defense, but still, better not to encourage dumb/bad behavior.
- tootie 11y agoIs it really? If I just point Burp Suite to some website they're going to come after me?
- david_shaw 11y agoIt depends. If you're testing Facebook, probably not. If you're trying to CSRF wire transfers through your bank, you might get a visit from the authorities.
- fmavituna 11y ago> ... I had to change and decided to jump into the startup world. You don't have to choose one of them. I was in a similar position about 6 years ago, software + security background and passion for startups which led me to start my own company (https://www.netsparker.com/ https://www.netsparker.com/), we're building a tool to automate web app security and advancing the automated scanning in web apps, it's really fun stuff if you are into security. Security industry is great for startups and new comers, another option is obviously working for a security startup, there are tons of them.
- hamhamed 11y agoVery cool, and indeed combining your strength and helping other ppl at the same time is key for a successful business. Best of luck with Netsparker!
- kjax 11y agoI've actually heard about your product, as someone was using it against a customer's app portal (on one of our servers). It didn't find an exploit per-se, but it helped us to discover a performance/DoS issue when it would occasionally start crashing + restart a vhost. So, indirectly, thanks for the great product!