Revisiting the BlackHat BCard hack of 2018
hackaday.com
Revisiting the BlackHat BCard hack of 2018
1–6 of 6 posts
Re: Revisiting the BlackHat BCard hack of 2018
#2>Using Burp Suite, the task would take about six hours.
I really don't think you should be using Burp Suite for this number of requests. IME You're begging for a crash.
Re: Revisiting the BlackHat BCard hack of 2018
#3Anyways, as long as humans are writing code and organizations function the way they do today these exploits are going to continue happening.
Re: Revisiting the BlackHat BCard hack of 2018
#4I remember when I was a kid and thought that hacking was this intense activity of "breaking in". Movies like Hackers really captured my imagination. Some vulnerabilities and hacks truly are incredible like Stuxnet[0]. However, after creating software for many companies for many years you start to realize that most of the "hacks" were just someone not being careful enough. A PM dropped the ball on a project, security…
That's indicative of a bad/dry trainer. A good trainer should easily be able to captivate the room with interesting anecdotes, war stories and general humor while teaching good, factual, actionable information.
Security should be fun, especially when you're coming from a developer perspective and you get to break everything instead of fixing it for once.
It's a real shame you had that experience, because the world really needs more security oriented developers.
Re: Revisiting the BlackHat BCard hack of 2018
#5Re: Revisiting the BlackHat BCard hack of 2018
#6I remember when I was a kid and thought that hacking was this intense activity of "breaking in". Movies like Hackers really captured my imagination. Some vulnerabilities and hacks truly are incredible like Stuxnet[0]. However, after creating software for many companies for many years you start to realize that most of the "hacks" were just someone not being careful enough. A PM dropped the ball on a project, security…
> One of the companies I worked at hired security experts to train us how to write more secure code and you wouldn't believe how bored the room looked. That's indicative of a bad/dry trainer. A good trainer should easily be able to captivate the room with interesting anecdotes, war stories and general humor while teaching good, factual, actionable information. Security should be fun, especially when you're coming fro…
I just think the audience wasn’t into learning. That might have been a culture problem at that company. It is hard to imagine something similar happening where I’m at now.
Also not sure why you got downvoted. I think it was a fair response.