Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
001spartan
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
by
001spartan
5y ago
The vaccines are not failing. They are incredibly effective at preventing infections _and_ reducing severity of breakthrough infections. The Delta variant is more easily transmitted and more likely to cause breakthrough infections, but that
2.
▲
by
001spartan
5y ago
Vaccines work. Vaccinated people are far less likely to contract COVID, and when they do they are far less likely to require healthcare resources beyond the standard treatments for someone who has the flu (stay home, rest, treat symptoms as
3.
▲
by
001spartan
5y ago
I agree! But the issue is that where these processes exist they are not designed for the scale of the current pandemic, are too inconsistent when implemented, and rely on spare personnel that do not currently exist.
4.
▲
by
001spartan
5y ago
Building more hospitals is a long-term process. Training medical personnel is a long-term process. Emergency measures intended to bridge the gap are untenable politically, and people are dying because of it. Thousands of them per day. The a
5.
▲
by
001spartan
5y ago
Returning to normal is a terrible idea when COVID patients are overwhelming hospitals across the world. How can things be normal if our healthcare systems are nearing collapse? You might be willing to accept the risk of getting sick on your
6.
▲
by
001spartan
5y ago
That's why those of us in the security industry have to say "compliance is not security" whenever PCI is brought up.
7.
▲
by
001spartan
7y ago
Even Windows gets this wrong at times, with several UAC bypass techniques exposed by auto-elevating binaries. Still, Microsoft has done a great deal of work with the Windows privilege model to prevent things like this, and these issues are
8.
▲
by
001spartan
7y ago
1. Dozens (if not hundreds) of tools are used. It's all about personal preference, and what you're used to. Personally, I don't often use most of the tools you mentioned except Mimikatz; I use a commercial framework paired wi
9.
▲
by
001spartan
7y ago
It is sexual assault to expose someone to unwanted sexual advances. It's the same thing as flashing. Why should someone be exposed to a picture of another's genitals when it's unwanted? It's forcing someone else to engag
10.
▲
Not a Security Boundary: Breaking Forest Trusts
(posts.specterops.io)
1 points
by
001spartan
8y ago
|
0 comments
11.
▲
by
001spartan
8y ago
The Amazon Prime Visa gives 5% back on Amazon purchases.
12.
▲
by
001spartan
9y ago
Automated tools can only discover so much, because there are always edge cases that tools won't be able to analyze or exploit. Human creativity is a big part of penetration testing, whether it's web application assessments or othe
13.
▲
by
001spartan
9y ago
I can't speak for DNSDumpster, but a common technique I use to do subdomain enumeration is just brute forcing with a wordlist. By enumerating with a large enough wordlist, you can discover matching subdomains for a target domain.
14.
▲
by
001spartan
9y ago
I think it's about on par with what developers earn for the same skill bracket and location. As a pentester, I don't think it's necessarily about having _more_ skill than developers, it's just a different set of skills.
15.
▲
by
001spartan
9y ago
When we use this technique (known as "tailgating") to break into client sites, we always recommend that the organization try to foster a culture of "trust, but verify". This means employees stopping people if they don&#x
16.
▲
by
001spartan
9y ago
That's very true. In many cases, that's even _perfectly fine_. Not every organization needs enough physical security to deter a determined attacker. The ones that do hire people like Sophie (or me), and take the lessons to heart.
17.
▲
by
001spartan
9y ago
I need about fifteen seconds of quality time with an unlocked computer before it belongs to me. Devices like the USB Rubber Ducky ( https://hakshop.com/products/usb-rubber-ducky-deluxe ) make it trivial to compromise u
18.
▲
by
001spartan
9y ago
If you did this job, you would not be surprised by the ease with which you can pull off these sorts of things. I've been doing this for a couple years now, and it's terrifyingly easy to compromise data or physical security for org
19.
▲
by
001spartan
9y ago
This is exactly why penetration testers and red teams do these types of engagements. We like to emphasize that organizations need to assume they've been compromised by someone, and they need to constantly keep that in mind when they bu
20.
▲
by
001spartan
9y ago
It also appears to be using common Windows lateral movement techniques based on credential stealing (namely WMI and PsExec), in addition to EternalBlue.
21.
▲
by
001spartan
10y ago
If you leave your wifi on when you're not connected to a network, your device will automatically start sending probes for known networks. For instance, if your home wifi network is called "duggan's network", and you'
22.
▲
by
001spartan
10y ago
The F-16 is close to 40 years old, and the F-15 has been in service for 40 years as of 2016.
23.
▲
by
001spartan
10y ago
As someone who has very strong feelings about sites not letting me choose secure passwords, or storing them insecurely...no. Fines for storing passwords insecurely and getting breached, sure. This is already handled by PCI/HIPAA, but c
24.
▲
by
001spartan
11y ago
I'll take your word for it. I guess I conflate them because they're both utterly abhorrent worldviews.
25.
▲
by
001spartan
11y ago
Weev is a well-known white supremacist. I would take anything he says with a hefty portion of salt.
26.
▲
by
001spartan
11y ago
Yes, this shows that antivirus is trivial to bypass. However, antivirus is not the last word in endpoint protection. While this method can be used to get otherwise ordinary payloads past antivirus, behavior-based detection and application w
27.
▲
by
001spartan
11y ago
I had the UltraPro as my work laptop at my last employer, and I despised it. The keyboard was impossible to work with (typos, keys didn't always register), and it felt flimsy and cheap. Not what I would expect from a system that cost a
28.
▲
by
001spartan
11y ago
I've been a vim user for a few years (I wouldn't consider myself a power user, though). I switched to Spacemacs last year, and I don't regret it at all. The power of the Emacs ecosystem mixed with excellent hotkeys (on top of
29.
▲
by
001spartan
11y ago
That may be, but it's still a backdoor by definition. There are better ways to allow a vendor to access a device, and a hardcoded password that nobody else knows about is not exactly a "front door".
30.
▲
by
001spartan
11y ago
Correct, you can't use the password alone, but the challenge/response method used is readily available online, and easy to implement.
More ›