So You Want To Be A Breaker, Part 1: Web Security
1–10 of 86 posts
Re: So You Want To Be A Breaker, Part 1: Web Security
#2This page has a lot of info on how we recruit. We're getting pretty good at turning systems programmers into breakers, and we love hiring from HN:
http://www.matasano.com/careers/
The great thing about this field is that it's always changing. A long-term dev job gives you a chance to master two or three different technology stacks. Your next three projects at an appsec shop might each be just two weeks apart, and each will use radically different technologies. Even (maybe even especially) with web software.
You could join one startup... or spend a couple years beating up all of all the startups.
Also: I understand why Cody didn't write it this way, but the reality is, if you're going to test web apps, Burp is the standard tool. You can use things like mitmproxy or even WebScarab, but most people end up in Burp. Burp is also extremely valuable for testing even if you're not doing appsec full-time.
Re: So You Want To Be A Breaker, Part 1: Web Security
#3If this stuff fascinates you and you're a solid software developer and you'd be interested in having this be your full-time job for awhile and you're willing to sink a little bit of your own time into ramping up, give us a ping. We'll help you get there. This page has a lot of info on how we recruit. We're getting pretty good at turning systems programmers into breakers, and we love hiring from HN: http://www.matasan…
(They aren't deliberately hard; they just cover a lot of ground --- you're starting with basic substitution ciphers and ending with RSA signature block forgeries).
I helped design them, and I'm really happy with how they came out. They're neat. You should see how many sets you can get through.
I hope it goes without saying that if you crush Sean's crypto challenges for fun and are interested in being a full-time appsec person, you will have our full and undivided attention. :)
Re: So You Want To Be A Breaker, Part 1: Web Security
#4If this stuff fascinates you and you're a solid software developer and you'd be interested in having this be your full-time job for awhile and you're willing to sink a little bit of your own time into ramping up, give us a ping. We'll help you get there. This page has a lot of info on how we recruit. We're getting pretty good at turning systems programmers into breakers, and we love hiring from HN: http://www.matasan…
I actually forgot to update that -- it was on my list of edits. Done now, thanks!
Re: So You Want To Be A Breaker, Part 1: Web Security
#5If this stuff fascinates you and you're a solid software developer and you'd be interested in having this be your full-time job for awhile and you're willing to sink a little bit of your own time into ramping up, give us a ping. We'll help you get there. This page has a lot of info on how we recruit. We're getting pretty good at turning systems programmers into breakers, and we love hiring from HN: http://www.matasan…
> Also: I understand why Cody didn't write it this way, but the reality is, if you're going to test web apps, Burp is the standard tool. You can use things like mitmproxy or even WebScarab, but most people end up in Burp. Burp is also extremely valuable for testing even if you're not doing appsec full-time. I actually forgot to update that -- it was on my list of edits. Done now, thanks!
Re: So You Want To Be A Breaker, Part 1: Web Security
#6Earlier quoted context omitted.
> Also: I understand why Cody didn't write it this way, but the reality is, if you're going to test web apps, Burp is the standard tool. You can use things like mitmproxy or even WebScarab, but most people end up in Burp. Burp is also extremely valuable for testing even if you're not doing appsec full-time. I actually forgot to update that -- it was on my list of edits. Done now, thanks!
I feel like I could justify the expense of Burp for a random freelance developer, even if they weren't billing out as a security tester. Like, I feel like we could convince Patrick McKenzie that it was worth his money. What do you think?
Re: So You Want To Be A Breaker, Part 1: Web Security
#7Earlier quoted context omitted.
I feel like I could justify the expense of Burp for a random freelance developer, even if they weren't billing out as a security tester. Like, I feel like we could convince Patrick McKenzie that it was worth his money. What do you think?
Justifying the expense wouldn't be difficult at all. However, I think the free version is Just Fine (TM) unless you need stuff like the scanner or intruder (intruder works in Burp Free, but is limited to something like 1 request/second).
I am weird among Matasanos (and ex-Matasanos :|) in that I live inside of Burp Intruder; I use it instead of Repeater. Why replay a request once when I can replay it 1000 times? So for me, non-crippled Intruder isn't optional.
I wish Burp didn't have a Scanner. I might pay $25 more for a branded version of Burp that specifically didn't have that feature, so I could reassure clients I wasn't ever using it.
Re: So You Want To Be A Breaker, Part 1: Web Security
#8Earlier quoted context omitted.
Justifying the expense wouldn't be difficult at all. However, I think the free version is Just Fine (TM) unless you need stuff like the scanner or intruder (intruder works in Burp Free, but is limited to something like 1 request/second).
Burp Intruder is the fuzzer inside of Burp. All the Burp-like tools let you capture requests your browser sends, edit them, and replay them. Burp Intruder lets you take a captured request and set up rules to send hundreds or thousands of variant requests. I am weird among Matasanos (and ex-Matasanos :|) in that I live inside of Burp Intruder; I use it instead of Repeater. Why replay a request once when I can replay i…
Re: So You Want To Be A Breaker, Part 1: Web Security
#9Earlier quoted context omitted.
Burp Intruder is the fuzzer inside of Burp. All the Burp-like tools let you capture requests your browser sends, edit them, and replay them. Burp Intruder lets you take a captured request and set up rules to send hundreds or thousands of variant requests. I am weird among Matasanos (and ex-Matasanos :|) in that I live inside of Burp Intruder; I use it instead of Repeater. Why replay a request once when I can replay i…
Huh, yeah, I've never seen anyone use intruder like that. I might use it once every other engagement, whereas I use repeater 24/7.
Re: So You Want To Be A Breaker, Part 1: Web Security
#10http://www.acloudtree.com/how-to-configure-burp-and-chrome-f...