4 ms·
The world is not an RPG video game, you likely can't just strictly "improve" yourself up to any given standard (no matter what any employer or teacher tells you
by explaingarlic 5y ago
The world is not an RPG video game, you likely can't just strictly "improve" yourself up to any given standard (no matter what any employer or teacher tells you - they're just trying to buy time as you sit in their classroom or accept a lower paycheck than you are worth). Experience is key, and it ISN'T best measured in years - you can likely put in more time than anybody on something given that you seem like a young kid who's eager.
That being said, and now that it's clear that you aren't just going to push a number higher until you can send all of your cyber zerglings into the enemy's virtual mineral line, this is a good process to follow for finding serious vulnerabilities - exploiting them should be trivial if you have a good enough understanding of the system:
- Think of a system in use, at any layer of the stack. This could be a specific web application in use by the enemy, a runtime that's used by some applications of theirs, or a memory/cache model on a CPU architecture that's flawed or anything like that
- Learn enough about that system that you can understand any inner working of it
- Painstakingly look through areas where you, just via inference, can tell that there could be some sort of vulnerability - key areas to focus on are something that is something downstream to user input, or something similar.
All of that is to say that, if you aren't already "useful", your country is probably going to have a regime change before you can find anything strictly useful.
If there's something simple enough that someone who's relatively unexperienced can do it, then it's probably automated.
OR - use a bunch of stolen credit cards you bought online for $3 each to rent a few VPS' (maybe come up with some consolidation solution to more easily make accounts and setup SSH boxes) and throw as much layer 4 traffic at Russian endpoints as you can :-).
- imwillofficial 5y agoI laughed so hard at “cyber zerglings”
- jerome-jh 5y agoIn the short term, low intensity large scale "offensive" action is probably the course to take with most potential return. Just poke with as many Russian server/service as possible. Since your country has a high risk of being (unfortunately) under Russian control soon, take some minimal precautions to cover your traces. This is basically the same principle as international sanctions. Try to make everything harder for Russia and (unfortunately) for Russian people. Playing people's opinion against their leader. You can do the same in Belarus that saw civil unrest recently, mobilizing Russian soldiers.
- explaingarlic 5y agoThat's what I was suggesting with my little addendum at the bottom. Would honestly like to try it, if someone would like to pay my mortgage + fooooood costs with VC bucks for a few years.