Open Menu
AllLocalCommunitiesAbout
lotide
AllLocalCommunitiesAbout
Login

Anon is a white hat hacker

⁨774⁩ ⁨likes⁩

Submitted ⁨⁨4⁩ ⁨months⁩ ago⁩ by ⁨Early_To_Risa@sh.itjust.works⁩ to ⁨greentext@sh.itjust.works⁩

https://sh.itjust.works/pictrs/image/1be19bb4-6173-467b-9712-1ff08720b46c.jpeg

source

Comments

Sort:hotnewtop
  • Cornelius_Wangenheim@lemmy.world ⁨4⁩ ⁨months⁩ ago
    1. No one’s hiring you unless you have an OSCP or similar certification.
    2. A real pen test will set off all kinds of alarms.
    3. You don’t get paid until you deliver a 100+ page report detailing what you did and your findings.
    source
    • echodot@feddit.uk ⁨4⁩ ⁨months⁩ ago

      You hope it’ll set off alarms. Sometimes it doesn’t, mostly because they don’t have monitoring setup.

      source
      • Cornelius_Wangenheim@lemmy.world ⁨4⁩ ⁨months⁩ ago

        Pen tests aren’t cheap. Even basic ones are ~$20k. There’s only 2 types of companies that bother with them: ones that care about cybersecurity and ones that have to do it for compliance (PCI/CMMC/etc). Both will have some kind of IDS and a SIEM.

        source
      • jol@discuss.tchncs.de ⁨4⁩ ⁨months⁩ ago

        Or because you hacked into the wrong company. This has happened multiple times.

        source
        • -> View More Comments
    • CaptainHowdy@lemm.ee ⁨4⁩ ⁨months⁩ ago
      1. Most folks dgaf about certs, and I agree with them. Certs are BS. I only have certs because employers paid for them and in tech (especially security) there’s a LOT of free time if you know what you’re doing. Certs only prove you can pass a test.

      2. Bold of you to assume most companies have intrusion detection systems and that their monitoring isn’t muted half the time.

      3. Findings come from an automated report generated by a scanner that does literally all the work.

      OP post is really not that far off. It’s an easy gig.

      Source: I’ve worked on both sides.

      source
      • expr@programming.dev ⁨4⁩ ⁨months⁩ ago

        Uh, certs are a huge deal in cyber security. Absolutely useless in most fields, but cybersecurity is not one of them.

        source
      • SaharaMaleikuhm@feddit.org ⁨4⁩ ⁨months⁩ ago

        So pen testing is a scam? I knew it! Opening all my ports right now.

        source
        • -> View More Comments
    • ameancow@lemmy.world ⁨4⁩ ⁨months⁩ ago

      You’re implying that people who post on 4-chan have no clue how the real world works and no idea what business is like and how people make money!

      source
  • sugar_in_your_tea@sh.itjust.works ⁨4⁩ ⁨months⁩ ago

    I’m pretty lazy, but I’d at least run a port scan so I have something to submit in a report. That takes a few minutes to run and can be scheduled to run daily so there’s something in their logs.

    That said, our audits always turn up something new (usually benign), so I’d be very suspicious of an “all clear” result.

    source
    • elvith@feddit.org ⁨4⁩ ⁨months⁩ ago

      Also, even without a prior pentest the admins should have a rough idea where problems areas are (or maybe even know them for a fact but cannot completely patch/disable them to not lock out legacy systems or so). A completely empty report would definitely raise suspicions

      source
    • TachyonTele@lemm.ee ⁨4⁩ ⁨months⁩ ago

      Just copy some report from online and change a few characters. Easy to do on the toilet.

      source
  • Agent641@lemmy.world ⁨4⁩ ⁨months⁩ ago

    As a professional pen tester myself, you have to test at least some of the pens to make sure the ink isn’t all dried up or run out. It’s not hard.

    source
    • Diplomjodler3@lemmy.world ⁨4⁩ ⁨months⁩ ago

      So which is your favourite flavour?

      source
      • prettybunnys@sh.itjust.works ⁨4⁩ ⁨months⁩ ago

        Only the best marines are able to become pen testers.

        source
      • SatansMaggotyCumFart@lemmy.world ⁨4⁩ ⁨months⁩ ago

        Sharpies smell great.

        source
    • SkaveRat@discuss.tchncs.de ⁨4⁩ ⁨months⁩ ago

      It’s not hard.

      well, unless the ink has dried

      source
      • swab148@lemm.ee ⁨4⁩ ⁨months⁩ ago

        Get a lighter

        source
  • Ilovethebomb@lemm.ee ⁨4⁩ ⁨months⁩ ago

    And the company doesn’t ask for references, or proof of what was done?

    source
    • LandedGentry@lemmy.zip ⁨4⁩ ⁨months⁩ ago
      [deleted]
      source
      • agamemnonymous@sh.itjust.works ⁨4⁩ ⁨months⁩ ago

        “How do I know you won’t use my techniques to become bad hackerman to hack your competitors? Sorry, I’m a professional”

        source
  • JoMiran@lemmy.ml ⁨4⁩ ⁨months⁩ ago

    LOL. I wish it was that easy. Also, if you say you did a pen test bjt didn’t, then the client gets hit through an exploit you said you checked or should have checked for, you and your company are done.

    source
    • MimicJar@lemmy.world ⁨4⁩ ⁨months⁩ ago

      Not me, just my company Try-N-Hack LLC.

      Luckily I’ll be back on my feet as ThisGuyHacks LLC in no time!

      source
      • JoMiran@lemmy.ml ⁨4⁩ ⁨months⁩ ago

        Not how that works. They will go after the company and individuals. You can bet that fraud charges will be filed with the police and don’t think that wire fraud with the feds is out of the question.

        source
        • -> View More Comments
    • HeyThisIsntTheYMCA@lemmy.world ⁨4⁩ ⁨months⁩ ago

      Just the same method I employ when people want refunds

      Image

      source
  • shneancy@lemmy.world ⁨4⁩ ⁨months⁩ ago

    />get sued a week later when a real hacker breaks into their system and the IT department notices a security flaw that would easily be addressed by first few staps in pen testing

    source
    • GhiLA@sh.itjust.works ⁨4⁩ ⁨months⁩ ago

      It’s in crypto and I’m in Portugal.

      source
    • Jiggle_Physics@sh.itjust.works ⁨4⁩ ⁨months⁩ ago

      Points out where working with me give no security guarantees, that they accept when agreeing to allow me to hack them, either in person, writing, or electronic communications, along with allowing the terms to change at any time, for any reason, without notice.

      source
  • Glitterbomb@lemmy.world ⁨4⁩ ⁨months⁩ ago

    This is why you should hire me, the pen tester tester. For $2000 I’ll make your network slightly less secure to see if the pen test catches it.

    source
  • rumba@lemmy.zip ⁨4⁩ ⁨months⁩ ago

    With the exception of Girl Scout cookies, I don’t buy anything from anyone that shows up unannounced.

    If I didn’t know I needed it until now, I need to do research before I buy into it.

    If I did know I needed it and you showed up randomly, I have no reason to expect that you provide any reasonable value with your services.

    Door to door sales are as dead as cold calls and email.

    source
  • nebulaone@lemmy.world ⁨4⁩ ⁨months⁩ ago

    At least do some auto scans with WebCheck, Shodan, nmap + vulnerability scans and some basic OSINT on their boss so you can report something and at least spook them a little bit.

    source
  • milicent_bystandr@lemm.ee ⁨4⁩ ⁨months⁩ ago

    Providing one half of a double blind study.

    source
  • ch00f@lemmy.world ⁨4⁩ ⁨months⁩ ago

    I’ve always wanted to start a ghost busting business.

    Just explain that after I’m done, all the strange sounds they hear have a perfectly logical explanation.

    source