Live data from Hacker News

Pwn.college

pwn.college

21–30 of 36 posts

Re: Pwn.college

#24
Looks good but if I may add a suggestion is to remove the slides from google docs. Maybe let us download them locally?

1. Corp VPN's will block google docs very regularly 2. Some people refuse to use google services 3. It shouldn't take you to a different domain to read the learning material

Re: Pwn.college

#25
post #16

Another software exploit thing that appears to be entirely Linux centered. Nothing against it but this doesn't even touch "core cybersecurity concepts". As crappy as it is, a security+ will teach you more infosec than knowing how to write kernel rootkits and create rop gadgets in your sleep. Case in point: most "advanced" attackers (except the "equation group" lol) very very rarely use a zero day, A majority of attac…

We must have a different definition of advanced attackers because I can think of numerous countries that use zero days. A handful more that use COTS malware (i.e. NSO) that employs zero days.

Re: Pwn.college

#26
Gotta be a bit less cheap and solve your ssl problems if you want people to take you seriously when it comes to security... Use cloudflare or routepath.app.

Re: Pwn.college

#27
post #15

Earlier quoted context omitted.

> could be also sold as a cloud-based research platform for vuln developers You'd have a tough time getting any public Cloud provider to allow you to run known vulnerable software, on purpose, on their network and then exposing it to the Internet. If you kept it under a decent amount of network security and heavily restricted access it might work. I would suspect you'd need permission to set this up, though.

True. I think the biggest buyer of this would be gov institutions that are constantly looking for building their offensive capabilities (mainly around exploit dev) but find it hard to get new recruits trained up. The alternatives are mostly instructor-led training which is good but combined with this type of platform + remote assistance via chat etc could scale things up.

Yeah.

I'm just in the beginning phases of learning pen testing. I want to move from DevOps to DevSecOps to PT.

I'm keen to see what labs exist out there already and how I can build my own complex labs (consisting of complete virtual networks) that I can hack against. A real wargame.

Re: Pwn.college

#29
post #25
post #16

Another software exploit thing that appears to be entirely Linux centered. Nothing against it but this doesn't even touch "core cybersecurity concepts". As crappy as it is, a security+ will teach you more infosec than knowing how to write kernel rootkits and create rop gadgets in your sleep. Case in point: most "advanced" attackers (except the "equation group" lol) very very rarely use a zero day, A majority of attac…

We must have a different definition of advanced attackers because I can think of numerous countries that use zero days. A handful more that use COTS malware (i.e. NSO) that employs zero days.

There are far more advanced hacking groups than there are nation states. There are likely more criminal hacking groups in each individual country than there are nation states.

Re: Pwn.college

#30
post #25

Earlier quoted context omitted.

We must have a different definition of advanced attackers because I can think of numerous countries that use zero days. A handful more that use COTS malware (i.e. NSO) that employs zero days.

There are far more advanced hacking groups than there are nation states. There are likely more criminal hacking groups in each individual country than there are nation states.

There are many criminal groups, but few are advanced. It takes investment and large teams to get full chain zero days. Most criminal groups will implement n days, but they are not coming up with Eternal Blue, you know? They are just grabbing it and hitting unpatched machines. It is skilled for sure, but it is not my definition of advanced threats.

If you have some examples of criminal groups using zero days in hard targets, I'm very interested. From what I see, no one's mobile phones are getting hit with ransomware via fresh vulns. That behavior is generally reserved for nation states with the ability (financial and legal) to purchase the exploits.

Post reply on HN