Live data from Hacker News

So You Want To Be A Breaker, Part 1: Web Security

daeken.com

31–40 of 86 posts

Re: So You Want To Be A Breaker, Part 1: Web Security

#31
post #30
post #17

This guide is exactly what I've been looking for, thanks Cody. Been on the receiving end of some very talented pentesters, and really want to learn more about how on earth they find the things they do. Want to make sure I catch your future editions, do you have anything I can sign up for notification? Can't find an RSS feed on your blog.

I second the need for an RSS feed. I was actually a bit surprised when I couldn't find one.

It's something I thought about for a while and just decided it wasn't worth it. I just switched away from Posterous (c.f. https://news.ycombinator.com/item?id=5388857 ) and when I was building the new blog, I looked at my RSS subscribers and realized only 15 people actually use it. Just wasn't worth building.

Re: So You Want To Be A Breaker, Part 1: Web Security

#32
post #3
post #2

If this stuff fascinates you and you're a solid software developer and you'd be interested in having this be your full-time job for awhile and you're willing to sink a little bit of your own time into ramping up, give us a ping. We'll help you get there. This page has a lot of info on how we recruit. We're getting pretty good at turning systems programmers into breakers, and we love hiring from HN: http://www.matasan…

Oh, hey! And if you'd like to learn to break crypto at the same time as you work through Cody's web recommendations --- even if you don't want to be an appsec person --- mail sean at matasano dot com. He's got a pretty kick-ass set of ~40 crypto-breaking exercises. Something like 200 people have started them over the past 6 months; only a few people have made it through the end. (They aren't deliberately hard; they j…

Another person chiming in to say that these exercises are a lot of fun and educational too. Feel like I learned more than in some online cryptography courses.

Re: So You Want To Be A Breaker, Part 1: Web Security

#33
post #26

Earlier quoted context omitted.

Any idea why he's doing this stuff only primarily by e-mail? It'd be great if this stuff was online like in a blog or whatnot. I'd like to take the time and look over the crypto challenges.

We want to actually teach people how to do stuff, instead of giving people something they can toss around in message board and twitter arguments; we also want to track (in a macro sense) how people do with them, and to be able to tell people when we add more challenges (I'm working on 42-48 next week).

This sounds like an amazing win-win scenario you've got here. People can have fun and learn more about security and cryptography, and you guys get a channel from which to hire the best and brightest.

I sent Sean an email. Even if I'm not in that latter category, it still sounds like a great chance to learn a little something about a field which intimidates but interests me.

Re: So You Want To Be A Breaker, Part 1: Web Security

#35
post #2

If this stuff fascinates you and you're a solid software developer and you'd be interested in having this be your full-time job for awhile and you're willing to sink a little bit of your own time into ramping up, give us a ping. We'll help you get there. This page has a lot of info on how we recruit. We're getting pretty good at turning systems programmers into breakers, and we love hiring from HN: http://www.matasan…

Is the work at Matasano (and security consulting in general) mostly attacking web apps? How often do you get to use tools such as IDA Pro to reverse binaries?

Either way, it must be fun doing that full time. Nothing in the world comes quite close to the feeling of breaking someone's system. The building excitement and anticipation as you realise you might just have found a place where they don't properly encode one protocol into another. The intense satisfaction when you get to demo an exploit. Unlike the rest of app dev, you can prove your attack is right.

Re: So You Want To Be A Breaker, Part 1: Web Security

#36
post #2

If this stuff fascinates you and you're a solid software developer and you'd be interested in having this be your full-time job for awhile and you're willing to sink a little bit of your own time into ramping up, give us a ping. We'll help you get there. This page has a lot of info on how we recruit. We're getting pretty good at turning systems programmers into breakers, and we love hiring from HN: http://www.matasan…

I worked as an IT security consultant for a bit over a year and found it rather boring after a while. In theory, you do lots of interesting and different things, get to know many different technologies. Maybe it was just the job I was working at, but the actual penetration testing became pretty boring after a few months.

While it sounds compelling to beat up startups, startups are probably not the clients. Our consulting day rates were very expensive and usually only large corporations or the government could afford it.

You just go and check for the top OWASP vulnerabilities. Sometimes, it requires some creativity, but oftentimes, you get a "feeling" for a web app after a while. Many PHP projects, many open source software projects that got a few custom made plugins. And then it's a bit dull. Testing every single parameter of a web app with many attack vectors...

I have to admit that there was one guy at our company who did a lot of reverse engineering, iOS security, testing a DRM system for an ebook online library (key takeaway: you can't control the client. DRM makes it harder, but it is never impossible to crack the system as long as the hardware is not custom made or something), stuff like that. So this was quite challenging and changing, but this was rare.

One gem I want to add to the original post: If you're interested in SQL injection, check out sqlmap. That tool is a real breaker and worked wonders for us and we downloaded entire databases by having a tiny little sql injection vulnerability in the signup form of a newsletter or something like that.

Re: So You Want To Be A Breaker, Part 1: Web Security

#37
post #2

If this stuff fascinates you and you're a solid software developer and you'd be interested in having this be your full-time job for awhile and you're willing to sink a little bit of your own time into ramping up, give us a ping. We'll help you get there. This page has a lot of info on how we recruit. We're getting pretty good at turning systems programmers into breakers, and we love hiring from HN: http://www.matasan…

I wish you guys had openings in the DC area. I've been interested in this stuff since college, when I would try reverse engineering using Fravia+'s tutorials. That's how I learned assembly programming.

Re: So You Want To Be A Breaker, Part 1: Web Security

#38
post #2

If this stuff fascinates you and you're a solid software developer and you'd be interested in having this be your full-time job for awhile and you're willing to sink a little bit of your own time into ramping up, give us a ping. We'll help you get there. This page has a lot of info on how we recruit. We're getting pretty good at turning systems programmers into breakers, and we love hiring from HN: http://www.matasan…

Is the work at Matasano (and security consulting in general) mostly attacking web apps? How often do you get to use tools such as IDA Pro to reverse binaries? Either way, it must be fun doing that full time. Nothing in the world comes quite close to the feeling of breaking someone's system. The building excitement and anticipation as you realise you might just have found a place where they don't properly encode one p…

We definitely do both things. You wouldn't want to work here if you hated web apps. You wouldn't need to know your way around IDA Pro on day 1 (for reasons that will become clear in a few months, you'd be comfortable with the basics of assembly language within a month or so of starting).

Re: So You Want To Be A Breaker, Part 1: Web Security

#40
post #36
post #2

If this stuff fascinates you and you're a solid software developer and you'd be interested in having this be your full-time job for awhile and you're willing to sink a little bit of your own time into ramping up, give us a ping. We'll help you get there. This page has a lot of info on how we recruit. We're getting pretty good at turning systems programmers into breakers, and we love hiring from HN: http://www.matasan…

I worked as an IT security consultant for a bit over a year and found it rather boring after a while. In theory, you do lots of interesting and different things, get to know many different technologies. Maybe it was just the job I was working at, but the actual penetration testing became pretty boring after a few months. While it sounds compelling to beat up startups, startups are probably not the clients. Our consul…

We work with lots of startups. We work with big companies, too, but that work is disproportionately with big west coast tech companies. The "east coast" BigCo work we do touches on trading protocols and order routing systems, which is fun for a lot of other reasons (wider application domain for findings, extremely high impact, complicated systems with message-oriented middleware, non-web inputs).

We do zero government work.

I don't feel like we're along in appsec shops for having this mix. I think one possible difference is between pure appsec shops like us, iSec Partners, IOActive, and Stach & Liu, versus general security practices. The work at general security practices might be more of a drag.

It's also the case that network security, being a race to the bottom (with Nessus and Metasploit "scanner jockies" and the like) is actively trying to push up into appsec. Maybe the web appsec work at a place like that is boring? We take it pretty seriously.

We avoid tools like sqlmap.

I'm answering this on the off chance that the conversation is a good glimpse into the working life of an appsec pentester (since that's what Cody's writing about).

Post reply on HN