Live data from Hacker News

How to learn hacking

fsecurify.com

21–30 of 46 posts

Re: How to learn hacking

#21
post #9
post #3

I find it deeply disappointing that this totally skips some very important parts, namely attitude, motivation and ethics. (Except for so-called "Ethical Hacking". On the other hand, what should one expect from the blog of a security company?) I recommend the all-time classic "How To Become A Hacker" by Eric S. Raymond: http://www.catb.org/esr/faqs/hacker-howto.html

ESR is a racist and a misogynist. And that document might as well be called "how to be ESR".

That's true, but the bigger problem with the document is that ESR's role in "hacking" is largely "making things to assign CVEs to".

Re: How to learn hacking

#23
Unrelated: It's not cool to put all the logos of companies just because you found some low sev bug there, not even saying the name is kinda similar to known security corp F-Secure...

Re: How to learn hacking

#24
post #14

If people actually care about this topic, and want to see someone doing a genuinely good job, check out LiveOverflow. Some other posters here will make fun of his dubstep intro music, green on black terminal text intro with the Rabbit, but he admitted in his first QA it was tongue and cheek. His subreddit: https://reddit.com/r/liveoverflow His YouTube channel: https://www.youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w…

Thank you so much! I have also recently started building https://liveoverflow.com , which might have a better structure than a YouTube channel or subreddit. Also some people may have actually seen a video of mine, because my most popular video so far is the DirtyCow video which got referenced by news sites and on the dirtycow github repository. My personal recommendation is to checkout the AngularJS Sandbox bypass se…

Thank you for the videos. They are such a valuable thing for infosec students. Please keep up the excellent work.

Re: How to learn hacking

#25
post #24

Earlier quoted context omitted.

Thank you so much! I have also recently started building https://liveoverflow.com , which might have a better structure than a YouTube channel or subreddit. Also some people may have actually seen a video of mine, because my most popular video so far is the DirtyCow video which got referenced by news sites and on the dirtycow github repository. My personal recommendation is to checkout the AngularJS Sandbox bypass se…

Thank you for the videos. They are such a valuable thing for infosec students. Please keep up the excellent work.

If you have feedback from infosec students, or topics that would benefit students, please contact me :)

Re: How to learn hacking

#26
post #12
post #9

Earlier quoted context omitted.

ESR is a racist and a misogynist. And that document might as well be called "how to be ESR".

Not to mention violently right-wing and believes he was, for a short period, a god[1] >.> [1]: http://www.catb.org/~esr/writings/dancing.html

Just read the linked post in full and that's an awfully reductive comment on the experiences he describes there. I suggest taking a more intellectually honest look at that writing (not to defend any of his other writing or views, which I haven't read).

Re: How to learn hacking

#27

As a junior security employee, I am still trying to figure out where to take my career. I have thought about various different paths: pentesting, development (JS, C, python, exploit...), reverse-engineering, web-app hacking, network-engineering and I cannot for the life of me decide where to focus my studies. I have reservations about pentesting because For example, I think a lot of it is unskilled work (e.g., pressi…

> I have reservations about pentesting because For example, I think a lot of it is unskilled work (e.g., pressing scan on nessus, clicking exploit on Burp) or work which will be automated in the near future

My job title is "Penetration tester" but I don't fall into that category. That's why I often refer to it as doing "application security analysis/audits". My current job is to do black/white box testing of single applications - and not a huge organisations where you just phish some employees. I have not worked for other companies, but as far as I can tell, many "penetration testing jobs" are actually what I do.

It's fun, challenging and very technical. And obviously no scanners are used - I have never in my career used nessus or any other click2exploit tool.

Re: How to learn hacking

#28
post #3

I find it deeply disappointing that this totally skips some very important parts, namely attitude, motivation and ethics. (Except for so-called "Ethical Hacking". On the other hand, what should one expect from the blog of a security company?) I recommend the all-time classic "How To Become A Hacker" by Eric S. Raymond: http://www.catb.org/esr/faqs/hacker-howto.html

Except all this has in common with the original post is the word 'hack'. Actually what you've posted is quite clearly against what the original post is about.

> There is another group of people who loudly call themselves hackers, but aren't. These are people (mainly adolescent males) who get a kick out of breaking into computers and phreaking the phone system. Real hackers call these people ‘crackers’ and want nothing to do with them. Real hackers mostly think crackers are lazy, irresponsible, and not very bright, and object that being able to break security doesn't make you a hacker any more than being able to hotwire cars makes you an automotive engineer. Unfortunately, many journalists and writers have been fooled into using the word ‘hacker’ to describe crackers; this irritates real hackers no end.

Re: How to learn hacking

#29
post #3

I find it deeply disappointing that this totally skips some very important parts, namely attitude, motivation and ethics. (Except for so-called "Ethical Hacking". On the other hand, what should one expect from the blog of a security company?) I recommend the all-time classic "How To Become A Hacker" by Eric S. Raymond: http://www.catb.org/esr/faqs/hacker-howto.html

Apologies if you find it disappointing. The people who daily ask me questions about hacking are mostly interested in "Getting a swag from Google" part and I was a little bit inclined to give resources to such people. It is by no means a thorough guide covering everything. It's just a start for people wanting to learn some stuff. I found these resources to be quite good.

Best Regards.

Re: How to learn hacking

#30

So what's the business of this company and its CEO? Other than trying to collect subscribers to his blog. Also really confusing name considering there's the Finnish security company called F-Secure who also have a technical blog: https://labsblog.f-secure.com/ And now also run a security course in Helsinki University: http://mooc.fi/courses/2016/cybersecurity/

If you think I am trying to collect subscribers, I have removed the "Subscribe to us" text from the post. F stands for my name and I liked the domain.

There is no business of this company. All I do is learn stuff, try to come up with good articles and post them. I plan to convert it into a proper company once my studies are over. I am just a student at the moment.

Hope everything is good now.

Best Regards.

Post reply on HN