If this stuff fascinates you and you're a solid software developer and you'd be interested in having this be your full-time job for awhile and you're willing to sink a little bit of your own time into ramping up, give us a ping. We'll help you get there. This page has a lot of info on how we recruit. We're getting pretty good at turning systems programmers into breakers, and we love hiring from HN: http://www.matasan…
I wish you guys had openings in the DC area. I've been interested in this stuff since college, when I would try reverse engineering using Fravia+'s tutorials. That's how I learned assembly programming.
So You Want To Be A Breaker, Part 1: Web Security
41–50 of 86 posts
Re: So You Want To Be A Breaker, Part 1: Web Security
#42Is "Breaker" in the title a Dark Tower reference?
Re: So You Want To Be A Breaker, Part 1: Web Security
#43If this stuff fascinates you and you're a solid software developer and you'd be interested in having this be your full-time job for awhile and you're willing to sink a little bit of your own time into ramping up, give us a ping. We'll help you get there. This page has a lot of info on how we recruit. We're getting pretty good at turning systems programmers into breakers, and we love hiring from HN: http://www.matasan…
Is the work at Matasano (and security consulting in general) mostly attacking web apps? How often do you get to use tools such as IDA Pro to reverse binaries? Either way, it must be fun doing that full time. Nothing in the world comes quite close to the feeling of breaking someone's system. The building excitement and anticipation as you realise you might just have found a place where they don't properly encode one p…
That's mostly just an artifact of the fact that so much software over the past ten years is web-based. I'd say maybe 80% of the client work I've done has been web-based (with maybe 10-15% non-web application, and the remainder network stuff).
But it's not the same everywhere. I would posit that one of the differentiators is the size of the company (i.e.: bigger security firms probably do more web-based stuff than more boutique places, mostly due to the clients that big firms service).
At the last place I worked, I ran a 10-person consulting division, and it was maybe 50/50 web app/non web-app testing. We were eventually acquired by a giant telco (two actually), and fast-forward a couple years, and the now 200-person consulting division is mostly doing PCI-related web-app testing (I have since left, although I think I stayed longer than I should have).
The larger the company, the larger your clients (generally), and the less agility of your sales process (ie: sales people tend to have a much easier time selling web application testing, as there is a huge number of clients who need it, and it's easy to put together statements of work around it).
So my advice, if you're interested in the more interesting types of security work, is to look for a small-to-medium-sized place. Actually, regardless of the type of security work you're interested in, I'd recommend a smaller firm. I've worked at enough of both to think that there's a certain size (either of head count or revenue) where you start to do less interesting work.
Re: So You Want To Be A Breaker, Part 1: Web Security
#44If this stuff fascinates you and you're a solid software developer and you'd be interested in having this be your full-time job for awhile and you're willing to sink a little bit of your own time into ramping up, give us a ping. We'll help you get there. This page has a lot of info on how we recruit. We're getting pretty good at turning systems programmers into breakers, and we love hiring from HN: http://www.matasan…
If I get in touch, would you point me towards some resources even if it won't lead to employment?
Re: So You Want To Be A Breaker, Part 1: Web Security
#45If this stuff fascinates you and you're a solid software developer and you'd be interested in having this be your full-time job for awhile and you're willing to sink a little bit of your own time into ramping up, give us a ping. We'll help you get there. This page has a lot of info on how we recruit. We're getting pretty good at turning systems programmers into breakers, and we love hiring from HN: http://www.matasan…
I think that's the area it's hard to break if you're already engulfed into security. I've been in architecture, research and pentesting across a lot of shops but I've always felt like minimum viable exploitation was all most places were after.
Fast forward years and you end up in something you don't feel like you've transitioned into something deeper. Sure, you can go there on your own but it has limited viability unless you're path forward is Pwn2Own or bounties in general.
I'd love to work for the Matasanos of the world but feel like I may be locked out based on the initial hurdle of being more proficient in code as a first class skill vs having a more honed skilkset in finding flaws on the systems as a whole. Also tracking the relevant things within the security landscape is a skill in and of itself and since most orgs don't understand how to find and cultivate that talent it open the doors foe the Risk.IO of the world.
Sure, I've done some reverse engineering, lots of (easy) pentesting and am proficient in Python. I've designed many F100 systems as it pertains to the security construct, yet I can't see a path forward to digging in deeper with those like Matasano. So @tptacek, any advice? The money is excellent on this side of the fence, but the real challenges are, seemingly, few and far between.
Edit: I need to stop writing posts from phone/tablet (spelling).
Re: So You Want To Be A Breaker, Part 1: Web Security
#46Earlier quoted context omitted.
So kind of like a magic 8 ball variant of ab? You know I'm rather surprised there aren't more open source tools like Burp and that it is so expensive.
I meant expensive for somebody who is new to the topic and just wants to play with it. Its an inertia thing.
Re: So You Want To Be A Breaker, Part 1: Web Security
#47Re: So You Want To Be A Breaker, Part 1: Web Security
#48If this stuff fascinates you and you're a solid software developer and you'd be interested in having this be your full-time job for awhile and you're willing to sink a little bit of your own time into ramping up, give us a ping. We'll help you get there. This page has a lot of info on how we recruit. We're getting pretty good at turning systems programmers into breakers, and we love hiring from HN: http://www.matasan…
#1 Lack of honesty. Seriously, they promised releasing those crypto challenges publicly 2 years ago (Blackhat 11: Crypto for Pentesters) and never done so: https://twitter.com/matasano/status/101714851633700864. And now they're using them as a recruiting tool.
#2 Lack of humility: Matasano guys seem to disregard common tools like Burp scanner or Sqlmap. It's fine to cherry-pick tools to suite your needs; but if you choose to disregard them completely just because you feel they're associated with "Security Rookies" then you're more than likely to miss something, consequently disservice your client (they expect you, as a consultant, to find the most vulnerabilities regardless of tools used). Matasano may have better fuzzer/scanner, but since they don't publicly release them, I found that going around and bashing other security tools to position themselves higher than their competitors is a sign of arrogance.
Go work for other companies, I don't want you HN people turn out to be like them!
For those of you who emailed sean at matasano dot com but haven't received any response, go play with Trustwave crypto challeges: https://github.com/SpiderLabs/CryptOMG - And yes they don't have BS subscription model.
Re: So You Want To Be A Breaker, Part 1: Web Security
#49If this stuff fascinates you and you're a solid software developer and you'd be interested in having this be your full-time job for awhile and you're willing to sink a little bit of your own time into ramping up, give us a ping. We'll help you get there. This page has a lot of info on how we recruit. We're getting pretty good at turning systems programmers into breakers, and we love hiring from HN: http://www.matasan…
DON'T WORK FOR MATASANO!!! Reasons below: #1 Lack of honesty. Seriously, they promised releasing those crypto challenges publicly 2 years ago (Blackhat 11: Crypto for Pentesters) and never done so: https://twitter.com/matasano/status/101714851633700864 . And now they're using them as a recruiting tool. #2 Lack of humility: Matasano guys seem to disregard common tools like Burp scanner or Sqlmap. It's fine to cherry-p…
Re: So You Want To Be A Breaker, Part 1: Web Security
#50Earlier quoted context omitted.
DON'T WORK FOR MATASANO!!! Reasons below: #1 Lack of honesty. Seriously, they promised releasing those crypto challenges publicly 2 years ago (Blackhat 11: Crypto for Pentesters) and never done so: https://twitter.com/matasano/status/101714851633700864 . And now they're using them as a recruiting tool. #2 Lack of humility: Matasano guys seem to disregard common tools like Burp scanner or Sqlmap. It's fine to cherry-p…
So, I'm ex-Matasano and now work for Accuvant LABS (a competitor). While I'd love to snag awesome people to join up on my side, I completely disagree here. Matasano is a great company and they do do good work. #1 they should remedy for sure, but #2 I disagree with -- they hold the same opinion I've found in other high-end consulting shops, just more vocally.
"I wish Burp didn't have a Scanner. I might pay $25 more for a branded version of Burp that specifically didn't have that feature, so I could reassure clients I wasn't ever using it."
Tell me, how do you expect to find MOST instances of SQL Injection or XSS without using tools? Do you manually tamper with every cookie parameters? Unless Matasano has better tools and release them publicly, then I am interested in hearing about them.