Live data from Hacker News

Viewing profile — 001spartan

001spartan

HN member
Joined
Fri, Nov 01, 2013, 8:00 PM UTC
HN karma
256
Public activity
75 items

About 001spartan

I like to break things. Information security guy.

Recent public activity

  1. comment
    Comment #28276463

    The vaccines are not failing. They are incredibly effective at preventing infections _and_ reducing severity of breakthrough infections. The Delta variant is more easily transmitte…

  2. comment
    Comment #28275990

    Vaccines work. Vaccinated people are far less likely to contract COVID, and when they do they are far less likely to require healthcare resources beyond the standard treatments for…

  3. comment
    Comment #28275929

    I agree! But the issue is that where these processes exist they are not designed for the scale of the current pandemic, are too inconsistent when implemented, and rely on spare per…

  4. comment
    Comment #28275883

    Building more hospitals is a long-term process. Training medical personnel is a long-term process. Emergency measures intended to bridge the gap are untenable politically, and peop…

  5. comment
    Comment #28275732

    Returning to normal is a terrible idea when COVID patients are overwhelming hospitals across the world. How can things be normal if our healthcare systems are nearing collapse? You…

  6. comment
    Comment #26866794

    That's why those of us in the security industry have to say "compliance is not security" whenever PCI is brought up.

  7. comment
    Comment #21806567

    Even Windows gets this wrong at times, with several UAC bypass techniques exposed by auto-elevating binaries. Still, Microsoft has done a great deal of work with the Windows privil…

  8. comment
    Comment #20127394

    1. Dozens (if not hundreds) of tools are used. It's all about personal preference, and what you're used to. Personally, I don't often use most of the tools you mentioned except Mim…

  9. comment
    Comment #20116244

    It is sexual assault to expose someone to unwanted sexual advances. It's the same thing as flashing. Why should someone be exposed to a picture of another's genitals when it's unwa…

  10. story
  11. comment
    Comment #17659931

    The Amazon Prime Visa gives 5% back on Amazon purchases.

  12. comment
    Comment #16734964

    Automated tools can only discover so much, because there are always edge cases that tools won't be able to analyze or exploit. Human creativity is a big part of penetration testing…

  13. comment
    Comment #16731832

    I can't speak for DNSDumpster, but a common technique I use to do subdomain enumeration is just brute forcing with a wordlist. By enumerating with a large enough wordlist, you can …

  14. comment
    Comment #16729869

    I think it's about on par with what developers earn for the same skill bracket and location. As a pentester, I don't think it's necessarily about having _more_ skill than developer…

  15. comment
    Comment #15519485

    When we use this technique (known as "tailgating") to break into client sites, we always recommend that the organization try to foster a culture of "trust, but verify". This means …

  16. comment
    Comment #15518639

    That's very true. In many cases, that's even _perfectly fine_. Not every organization needs enough physical security to deter a determined attacker. The ones that do hire people li…

  17. comment
    Comment #15518407

    I need about fifteen seconds of quality time with an unlocked computer before it belongs to me. Devices like the USB Rubber Ducky ( https://hakshop.com/products/usb-rubber-ducky-de…

  18. comment
    Comment #15518338

    If you did this job, you would not be surprised by the ease with which you can pull off these sorts of things. I've been doing this for a couple years now, and it's terrifyingly ea…

  19. comment
    Comment #15518311

    This is exactly why penetration testers and red teams do these types of engagements. We like to emphasize that organizations need to assume they've been compromised by someone, and…

  20. comment
    Comment #14647158

    It also appears to be using common Windows lateral movement techniques based on credential stealing (namely WMI and PsExec), in addition to EternalBlue.

  21. comment
    Comment #14023603

    If you leave your wifi on when you're not connected to a network, your device will automatically start sending probes for known networks. For instance, if your home wifi network is…

  22. comment
    Comment #12445798

    The F-16 is close to 40 years old, and the F-15 has been in service for 40 years as of 2016.

  23. comment
    Comment #12410228

    As someone who has very strong feelings about sites not letting me choose secure passwords, or storing them insecurely...no. Fines for storing passwords insecurely and getting brea…

  24. comment
    Comment #11382098

    I'll take your word for it. I guess I conflate them because they're both utterly abhorrent worldviews.

  25. comment
    Comment #11381919

    Weev is a well-known white supremacist. I would take anything he says with a hefty portion of salt.