[Boards: 3 / a / aco / adv / an / asp / b / biz / c / cgl / ck / cm / co / d / diy / e / fa / fit / g / gd / gif / h / hc / his / hm / hr / i / ic / int / jp / k / lgbt / lit / m / mlp / mu / n / news / o / out / p / po / pol / qa / r / r9k / s / s4s / sci / soc / sp / t / tg / toy / trash / trv / tv / u / v / vg / vp / vr / w / wg / wsg / wsr / x / y ] [Home]
4chanarchives logo
Ask a tipsy penetration tester/SOC analyst (Hacking but without
Images are sometimes not shown due to bandwidth/network limitations. Refreshing the page usually helps.
The stories and information posted here are artistic works of fiction and falsehood.
Only a fool would take anything posted here as fact.
You are currently reading a thread in /b/ - Random

Thread replies: 226
Thread images: 39
Ask a tipsy penetration tester/SOC analyst (Hacking but without all the teenage edge) anything ...
>>
best auditing tool?
best way to send someone account info?
>>
>>674795403
Why are You here NewFag?



▲ ▲
>>
>>674795403
Welcome newfag
>>▲
>▲ ▲
>>
>>674795857
>>674795989

ok

>>674795586

Nessus is the best scanning tool but it costs money. OpenVAS is a free alternative but its annoying how long it takes to start and do scans.

If by account info you mean credentials, end to end encrypted chat. XMPP and OTR is a favourite of mine.
>>
File: 1445289914749.jpg (58 KB, 540x531) Image search: [Google]
1445289914749.jpg
58 KB, 540x531
>>674795403
Why arent you using terminator with green font colors? We're hackers, we use black terminals with green font colors.
>>
>>674797568

It's such a cliche man.

I use different foreground colours for the text when I'm dealing with different VM's/physical machines but I avoid green as its such a huge cliche.
>>
>>674795403
>without teenage edge
>announces being tipsy
kek/10
>>
Have you written anything cool or are you a professional kali skiddie?
>>
>>674797776

I'm being paid to hack into corporate networks for financial companies all day. I deserve a drink at the weekend.
>>
File: 807-1.jpg (60 KB, 294x183) Image search: [Google]
807-1.jpg
60 KB, 294x183
>>674797765
Terminator is still a way better xterm emulator than the default.
>>
>>674795403
I've got a shitload of books on a shitload of abstract topics related to security, any idea where I can find more practical books about specific programs or ideas?
>>
>>674797957

I thought you meant a movie reference. I use terminator all the time. I like the vertical split function.

>>674797827

Most of the projects I've written are used internally and never see the light of day.

I've got a bunch of 0days (Nothing big tbh) I'm going to release through the company.

It's in our plan to begin releasing open source software.
>>
do you run kali as your main operating system and tell all your friends(if you have any) that you don't use windows but use a hacker operating system that they wouldn't be able to use. Also do you sit on your os and only use like 3 tools from your library and look for simple SQLi so you can post your l33t defaces?
>>
How did you start learning?

Also, how did you get noticed to do the job you do now?
>>
>>674798270
Any experience with openWRT? I want to start an army of routers.
>>
File: 1457725957948.gif (145 KB, 561x461) Image search: [Google]
1457725957948.gif
145 KB, 561x461
>>674798325
Topkek

I like you're sarcasm /bro
Never change
>>
>>674798718
yeah only my friends call me sarcasm tho
>>
Had any legal run ins with the corps you got paid to test?
>>
>>674795403
Dude literally what the fuck. Your pic is like a root shell executing packetmanager installation? Why the fuck would you even want to do that
>>
>>674798579
From netstat commands and reading books on windows live and MSN messenger. Also, yahoo chat rooms were helpful.
>>
File: 1458244041168.jpg (193 KB, 940x940) Image search: [Google]
1458244041168.jpg
193 KB, 940x940
>>674798937
Yea. I fucked up. Case in point.
>>
Do you know how to spoof the data on an SD card for a CPAP machine so it says it's being used when it's not? It would have to be undetectable.
>>
Am I an idiot for targeting Reverse Engineering/Low Level Exploitation instead of generic pentesting skills? All this metasploit shit is boring. Researching and reversing malware is much more fun and appears to pay much more.
>>
>>674799447
Reverse engineering is literally the basic step for pentesting
>>
>>674797568
>terminator
>not konsole

Fucking pleb
>>
hey bro, I once pulled off an SQLi into putins personal email IP address and from there managed to get into Russias central mainframe and spoof the inter molecular packer reader to access specific secrets held on various darkweb servers, so my question. Whats the most badass thing you've done?
>>
>>674799843
>Konsole
>Not MATE-terminal

:^)
>>
>>674795403
>how can i get the link to download this? http://cymatics.fm/animals-for-serum-gold-edition/
A dl link looks like this
>http://cymatics.fm/wp-content/uploads/2016/02/Cymatics-Animals-for-Serum-Demo.zip
so i figured it would be
http://cymatics.fm/wp-content/uploads/2016/02/Cymatics-Animals-for-Serum-Gold-Edition.zip but it gives me a 404
>>
>>674798325

No we use windows as the main OS and VM's. As much as people dislike windows, it's still the best workstation OS out there for a corporate environment.

>>674798991

All the procedures are explained. It's possible during a penetration test or a vuinerability test it could make services crash so we have non-invasive and invasive procedures. If it's a 24/7 mission critical system we'll image the box and test it in a VM.

>>674798579

Started off as a skid (Like everyone does), always taken an interest in it. My degree was in forensics but forensics and security go hand in hand. I've ran a botnet empire before, made a ton of money off it but decided to go into the industry as its a in demand career path right now. I never disclosed my past and I don't plan to.

>>674799070

First pic from google. I could of picked a better one.

>>674799241

The snoring detector machines? Why would you need to spoof that?
>>
>>674800230
what did you search on google for that to be the first image?
>>
>>674800604

OpenVas terminal.

I hate that software, takes forever to load and causes way too much noise.
>>
>>674799925
this....
top kek
>>
>>674800230
Because I drive a truck. I used to sleep 5 hours a night. Now with the CPAP machine I sleep maybe 3. They're worried I might fall asleep while driving. I need to show use to pass my DOT physical. I might be able to mechanically spoof if with a water column.
>>
>>674800737
OP is confirmed liar guys, just googled it and its 7th result on google image, DON'T TRUST ANYTHING THIS GUY SAYS as most likely a fabrication.
>>
Studying security at uni. One of my assignments is to info gather a system for vulnerabilities. I only have access to Nessus on uni workstation which is inconvenient. Will openvas do the job because I can't really afford to shell out for my own copy of Nessus.
>>
>>674799995
i now realise i'm stupid and you're not related to what i'm looking for
>>
>>674798652
Web standards have you covered for anything router related; https://github.com/mandatoryprogrammer/sonar.js
>>
>>674800980
>>674800230
>>
skid spotted
>>
>>674800991

There basically the same thing but nessus went the commercial path and OpenVAS remains free. OpenVAS will find like 90% of what nessus finds. If its a lab exercise it will pick up the vulnerabilities.

>>674798652

Use binwalk to reverse engineer the firmware if you want to poke into it. If your planning to turn them into a botnet, alot of routers use different architectures so thats gonna be the challenge.
>>
>>674801722

so much edge
>>
>>674798325
>>674800980
Love how this guy avoids the REAL questions and answers these bullshit questions no one cares about.
>>
>>674800980

Never knew 4chan was taken that seriously. le redditor.
>>
>>674801989

I've answered both you moron. Go back to wearing your mask and trying to "Smash" the state by DDoSing a website nobody reads.
>>
File: fag.jpg (118 KB, 400x400) Image search: [Google]
fag.jpg
118 KB, 400x400
>>674802117
<
>>
>>674801989
He never answered mines either>>674799925
>>
Salary? Don't you dare pull that "private information" bullshit, we are on 4chan
>>
>>674799925

Had sex in the missionary position
>>
>>674802842

Enough to live comfortably. I run things on the side so I'm doing pretty well for myself.
>>
>>674802862
more like fapped in your room while your mom was hoovering nextdoor
>>
do you do web stuff?

I'm trying to start my own business renting gameservers on a linux box and I'm scared shitless of problems that might come up.

I can't afford hiring someone to do pentesting

what should I do?
>>
>>674804210
dont start your own business in something you know nothing about. Retard.
>>
>>674801850
prove you're not a skid
>>
How old are you and how old were you when you started to earn as a pentester?
>>
>>674804842

I've recently started. I've been interested in IT security since I was a kid (I started out as a skiddie, every security, whether doing it pro, being a hacktivist or doing it for financial gain starts that way. Nobody jumped into it as a expert in every aspect) I don't want to disclose my pay but it's good and it can reach huge amounts if you specialize in certain areas.

>>674804712
How exactly
>>
>>674805198
skid
>>
>>674805198
post a pic of you on trumps email account. Pussy.
>>
>>674804486
kek so by your logic everyone who ever hosts anything is an expert in security

fuck off m8, I'm a backend web developer, you can't do them all
>>
>>674805470
fucking dumb ass can only do one thing at a time, you struggle when typing and speaking aswell? typical American.
>>
>>674795403
How much anal penetration do you get?
>>
File: Snapchat-7330603566791977060.jpg (92 KB, 540x960) Image search: [Google]
Snapchat-7330603566791977060.jpg
92 KB, 540x960
I have my sec+ and my csx, does that make me hardcore? Also mirin?
>>
>>674805376
Well I strongly disagree with that, I only use tools 90% of the time.
>>674805451
Sorry I actually work for his private security team and so I am unable to do that.
>>674805470
Yeah you seem like the sorta guy that likes the backend. (most probably all male in your case)
>>674806292
It varys depending on my mood, sometimes I can act out my erotic homosexual fantasy's using gay pron but sometimes I just gotta let it all out over a guys face.
>>
>>674795403
Would you suggest me lo learn Linux OP ? I want to know if that will help with all this hacking thing, Im a noob on this subject.
>>
>>674807241
Linux is simple, you don't learn linux, you learn command line you fucking scrub. Go fuck yourself and stay on windows 10 you dumb ass little bitch. This threads over guys, Iv drunk my 4 beers much quicker than usual (5 hours) and im pretty drunk so im gonna call it a night and go jack off to some gay porn.
>>
Let's say you have a CS degree, are capable to program and know a bit of stuff here and there.
What would you suggest to someone to get the needed knowledge and into the industry for your kind of work?
>>
>>674795403
>Kali Linux
>omg im such a hacker
back to /g/, friend.
>>
File: 1458402976562s.jpg (8 KB, 250x247) Image search: [Google]
1458402976562s.jpg
8 KB, 250x247
je voudrais le basil meme
>>
What's your major? Where did you grad from?
>>
>>674807241
>learn Linux
a myth
there is no learning linux

you learn Bash
>>
>>674800230
is your online handle rexas?
>>
>>674808959
>what are architectures
>what are interfaces
>>
>>674810017
your mom,son.
>>
>>674795403
why r u tipsy fipsy
>>
>>674807711
>>674810431
refer to my post there, Iv just finished up my beers. 5% beer btw incase yous think im a pussy.
>>
>>674810742
br0, after a night out my piss is probably over 5%.
>>
>>674810742
5%...
in germany each beer has about 8% minimum
nigger.
>>
>>674795403
are you the hacker they call 4chan guy ive heard about in the news?
>>
>>674800980
He said he took the image from google. Doesn't prove he's lying. Probably is, but doesn't prove it.
>>
>>674810017
those are both non-issues
if you need to sit down and learn an interface that's fucking sad
>>
File: retardposter.png (7 KB, 225x225) Image search: [Google]
retardposter.png
7 KB, 225x225
>>674811312
Are they all as retarded in Germany aswell? Seems Hitlers attempt to make the Aryan race didn't work too well on your guys, probably all those immigrants fucking your wives will make up for it tho.
>>
>>674795403
Have you ever attempted to hack into a Google Chromebook? They just raised to offer to $100,000 for anyone who can do it. So it must be pretty goddamn secure. I know it's not a network, but do you know how to tap into operating systems? http://www.usnews.com/news/articles/2016-03-17/google-offers-100k-reward-for-hacking-chromebook
>>
>>674800230
>>674811629
Actually he says he took it the first image from google image, so maybe you should get your shit straight before you step up here with some weak shit trying to be some sorta homosexual whiteknight.
>>
>>674811823
>still hanging and going on about something which was literally 71 years ago. Stay salty USA.
Nice stereotyping. I'd even bet my ass that most of you aren't even able to speak more than 1 language at all. GG.

In the city where I'm living there are no immig. seen. Nice bait tho. Enjoy your 5% boy
>>
>>674795403
hey OP can you hacks my friend? XD he is a nigger
>>
>>674812146
Watch out guys! Bad ass alert!
>>
>>674812344

Lol you fucking eunuch!
>>
>>674812465
yeah you mayaswell just type out "sorry guys I was an idiot" typing badass alert with no original content or points to continue the argument just makes you seem desperate and a complete dumbass.
>>
>>674812344
These dumb ass europoors think speaking another language makes them more intelligent when they are taught other languages at a younger age because their country is cucked as fuck and forced to speak a language that isn't theirs.
>>
>>674812861
Why? Are you the dipshit who replied to my post saying
>He said he took the image from google
with a response that says
>Actually he says he took it the first image >from google image
Not only a /b/tard bad ass, but also a dumbass.
>>
>>674795403
where is a good place to start for a beginner in penetration testing
>>
>>674813680
Well first off, no one replied to your post saying that so get your shit straight son.

as to your second comment it dosn't make any sense and unless I had a similar mental illness to you I couldn't decipher it.
>>
osi model anyone?
>>
>>674813734

amsterdam
>>
File: Capture.jpg (78 KB, 800x552) Image search: [Google]
Capture.jpg
78 KB, 800x552
>>674814105
Are you really this stupid?
>>
>>674813734
ur anus
>>
kali linux is for skids i'm sure you enjoy all your frameworks and tools using that shit.
>>
>>674814623
>>674814472
thanks ill start right now
>>
>>674800980
>>674814609
retard
>>
What do you think of Brian Krebs?
>>
>>674814822

be safe. small steps.
>>
>>674815166

He knows his stuff but is playing a dangerous game pissing off criminal groups.

Apparently the local PD won't deploy SWAT teams to his house anymore, due to all the skiddies trying to swat him.
>>
>>674814704

Yeah okay lets act all edgy and spend months developing inhouse tools when there are tools already there that will do the job.
>>
>>674815496
That Russian guy who tried to have him arrested on drug charges got arrested himself and apologized to Krebs via a letter from prison.
lel

Other question, how easy is it to spy on someone's Whatsapp/Telegram/Viber if you can't get physical access to his phone?
>>
>>674808959
So in order words, is it recommendable to learn bashs commands?
>>
>>674813734

Learn how to use all the tools in kali and learn about the concept of basic security. It doesn't matter if you can learn how to fuzz to find buffer overflows if you don't understand why locking your machine when your away from your desk is important.
>>
File: 1445639117536.jpg (20 KB, 200x200) Image search: [Google]
1445639117536.jpg
20 KB, 200x200
>>674812344

>still hanging on to leddit memes from 2014
>le salty

ugh
>>
>>674807241

It's the go to operating system in this field and is the go to in many others involving IT. Learning shell scripting will prepare you for other languages.
>>
>>674795403
I know my fair share around programming. Currently have a job in shitty aspnet mvc.

Anyhow, where should i start, which book should i get or how do i get into proper pentesting.
>>
File: Fotolia_26095109_S.jpg (38 KB, 600x406) Image search: [Google]
Fotolia_26095109_S.jpg
38 KB, 600x406
>>674795403
Sup OP, srs questiun: Three hole mask or cyclops?
>>
>>674815781

I'm not sure about viber but Whatsapp and Telegram apparently use end to end encryption. You'd need physical or remote access to the phone. MITM attacks will be useless against end to end unless you just want stats on how often the two targets talk to each other.
>>
For someone who is just starting to know about hacking and shit. Which forum o page do you recommend?
>>
File: pcshrooms.jpg (85 KB, 844x633) Image search: [Google]
pcshrooms.jpg
85 KB, 844x633
What are the best resources to start learning about penetration testing, iyo? I'm intereste din the subject
>>
>>674816255

Learn what all the tools do in kali linux. Setup VM's and test the tools out on them. Make sure you understand what the tools are doing. Don't just use metasploit to attack a target, experiment with netcat and scapy so you understand how the exploits work yourself.

Once you know enough, go for job interviews in junior roles. You'll get the job if you can show you have knowledge of the concepts, the burecreacy part comes as part of on the job training.
>>
>>674816630
>>674816599

See this >>674816793
>>
>>674816479
Ok thanks.
I am wondering how my third world gov spies on the citizens whatsapp/telegram conversations, and I know for a fact they actually can do it.
Ever heard of Hacking Team tools they were offering? Were they any useful for this stuff?

Actually, would appreciate if you told me anything relevant to spying on whatsapp/telegram conversations of a target you only have their number and know where they live in and what nr they use.

Much appreciated man!
>>
>>674806503
sec+? oh, so you know how to turn off automatic updates? good jahb
>>
>>674816793
Do you need to know programming for this?
>>
>>674817025
Ecuador?
>>
>>674815626
worked for me for years
>>
>>674800922
>>674816793
I always thought Kali was a meme.

Anyhow, i'm running arch now on my notebook and would like to stick to the environment. I have a lot of experience with EL but i just despise ubuntu. Should i get started with kali or is installing an alternative fine, i mean, i'd rather not use a distro at all but i guess i'll need to.

Beside that, last question, currently i have a BCM43412 equipped. Should i get my hands on a proper WiFi card and will my GTX735M do fine on bruteforcing or should i just get myself a second laptop altogether; if so, which?
>>
>>674817025

Governments are banning apps like WhatsApp and Telegram for a reason. End to end encryption fucks up government survillence programs. They might have the resources to crack a few conversations but if all communicatons used it, they'd be fucked.

Even with end to end, government agencies can determine how often two targets are communicating with each other. All of chatter can be correlated together. So if a terrorist cell is about to attack, they can determine that there is alot more talk within a short period than normal.
>>
just need golang compiler and a text editor
>>
Is it possible to find a picture that was deleted or set to private on facebook a couple years back
>>
>>674795403
what kind of disambler do you use?
>>
>>674817456
Knowing how to program is an advantage as you'll see how a program is built and know your way around better. For basic tier pentesting it's not needed though.

I'd at least learn python or something so you can write customized scripts for more advanced applications
>>
Whats the best way to get into someone's email?
>>
>>674817481
no, a Balkan shithole.
>>674817665
Okay thanks. What if the phone target of the number is using an old outdated Android and Whatsapp version?
How would you go to spy on a target's Whatsapp if someone offered you money upfront to do it? Suppose you only know the target's whatsapp and real number.
>>
>>674817751
Wayback Archive is basically your only shot.
>>
>>674817456

It's not neccessary but if you want to pass the hardest certifications, your gonna have to program your own scripts while doing the tests. They'll pick exploits where there is no known POC scripts out there. They are the hardest certs to get, if you got one of the certs, you'd constantly have work.

>>674817584

Everyone in the industry uses the kali distribution because it has all the tools ready to go. When your doing this work in a corporate environment, its not worth recreating the wheel to score ego points. I know kali is debian based so it's similar to ubuntu. I don't know much about using graphic cards to crack hashes as where I work we have multiple data centres we can use as resources for stuff like that.
>>
>>674818060
Guess their password (so not bruteforce but bruteforce with human logic), spoof a password reset mail, phishing, MITM if not TLS/SSL.

If you're on a school, MITM is easy on android devices connected to eduroam (user's fault, accepting any cert)
>>
>>674818142
Am I supposed to just copy and paste the facebook url? I do it but it cant find anything
>>
>>674795403
Bet you're one faggot skid that works for Rapid7. You can suck HD Moore's skid cock.

You guys are never be ahead of us. Fuck the whitehats.

Keep making your teewls with Ruby/Python/Perl and your automated scanners.

Let the big boys do all thr damage and take the money while you guys pretend to be elite.
>>
>>674818139

Stagefright exploit for android phones. A new concept came out today that works on old versions of android (You'd be suprised how many people don't upgrade) iPhones are difficult. The 0day exploits for iPhones can reach upto $500,000 if you get in contact with a company that sells them to government agencies.
>>
newfags..........
>>
>>674818445
Well i didn't mean to reinvent the wheel, i just wondered if blackarch was a fine distro.

However if Kali is not Ubuntu but Debian based i'll just get that.
>>
is it require to know a lot of assembly or you just need to know the basics for hacking?
>>
File: tumblr_nm35uwgSvA1ro5wqbo1_500.jpg (70 KB, 500x500) Image search: [Google]
tumblr_nm35uwgSvA1ro5wqbo1_500.jpg
70 KB, 500x500
>>
File: 1457662401320.jpg (28 KB, 480x480) Image search: [Google]
1457662401320.jpg
28 KB, 480x480
>>
File: BIMKPv6.jpg (133 KB, 1254x622) Image search: [Google]
BIMKPv6.jpg
133 KB, 1254x622
>>674818538

So much edge it burns. If you was as badass as you say you are, that far ahead. Basic OPSEC rules you don't post it on 4chan of all places.
>>
File: image_24.jpg (67 KB, 640x632) Image search: [Google]
image_24.jpg
67 KB, 640x632
>>
>>674795403
How do you not spend your entire life giggling if your job title is "penetration tester"
>>
>>674818997

Assembly knowledge is handy if your into fuzzing (Discovering buffer overflows via a bruteforce like method) or if your reverse engineering malware. Its not required but knowledge of that is a speciality and its one of the areas that pays alot.
>>
>>674819471
good to know, thanks anon
>>
>>674819166
>Anonymous imageboard
>USING VPN
>tunneling through my own3d boxes (which are shared by many bot herders)

Talk to me about OPSec when you actually have to use OPSEC kid.


Also anyone can be anything here. So I may be lying and you can too. There is no proof of anything.

This further proves you are one complete skid. Fucktards like you, HDM, Mutts and all the faggot ass who want to make shit mainstream are the cancer that ruins hacking.

Thats why you guys keep costantly getting owned. And companies will continue to get owned you filthy piece of shit.
>>
>>674819240

I think the whole industry is ran by 4channers. "Splunk" is a startup that just collects logfiles and the security industry uses them alot, that's just asking for jokes to be made.
>>
Another question, dear OP.
Thanks for the Android follow up answers. Appreciated.

Any way to login to my friend's Gmail without triggering Google to send a fucking sms code to his assigned nr? I am using same city VPN IP as his, but apparently Google catches me.
I have the password, email, dob and some other info but can't get past sms code.
>>674818842
>>
>>674819707

We make alot money than you. I don't give a fuck what you think.
>>
>>674795403
>>674795403
OP I am considering starting an personal information acquisition campaign. And another simply fraudulent website. My idea is to mail out 10s of thousands of emails from an email address claiming to be a bank and that there has been a security leak that they need to send the passwords through the email to make sure there accounts didn't get hacked. this will continue for years will you help me do this.
>>
File: feelsgood.jpg (21 KB, 396x385) Image search: [Google]
feelsgood.jpg
21 KB, 396x385
>>674818482

maybe an odd request, but do you have any contact (steam)? I'd like to be able to ask some more questions in the future
>>
>>674819920
Yup, kk kid. Keep making your muhnies and thinking you are elite.

Let us work with our 0days and shit you only dream to ever find.

Back when you were still sucking cock, we were coding with our commodore 64 and owning.

Play with cancer Kali or cancer backtrack. Fucktard.

Fuck whitehats, fuck full disclosure.
>>
>>674819918

I haven't got much experience with breaking into gmail accounts but I know facebook has a system set in place where it tracks the useragent the web browser sends during requests. You might want to find the targets useragent and spoof that if your using the same IP.
>>
>>674820365
Understandable. What else other than the agent should I spoof to make it look like it is the victim logging in and Google not catching something out of it and thus, asking for the fucking sms verification code?
>>
>>674820256
ok

>>674819931
Emails aren't the way to go. The entire IT industry has been fighting against email spam for decades. I've seen a server shutdown within 12 hours after sending out 1 million spam emails.
>>
File: 1458004693878_1.jpg (52 KB, 669x421) Image search: [Google]
1458004693878_1.jpg
52 KB, 669x421
>>
>>674820583

You'd need to mimic every HTTP header the legitimate client sends. That's all the webservers have to go by. Useragent would most likely be the biggest one.
>>
File: FB_IMG_1453478351157.jpg (42 KB, 720x579) Image search: [Google]
FB_IMG_1453478351157.jpg
42 KB, 720x579
>>
File: image_23.jpg (172 KB, 1000x800) Image search: [Google]
image_23.jpg
172 KB, 1000x800
>>674795403
>>
File: OPHouse.jpg (341 KB, 612x612) Image search: [Google]
OPHouse.jpg
341 KB, 612x612
>>
File: image_5.jpg (53 KB, 540x413) Image search: [Google]
image_5.jpg
53 KB, 540x413
>>
How to hack.... facebook???
>>
File: 1451327243772.png (1 MB, 1080x1920) Image search: [Google]
1451327243772.png
1 MB, 1080x1920
>>
>>674821238

"Forgot your password? Click here"
>>
>>674820121
Nah i don't have steam, skype or any IM really. Just hop on #uk on rizon and look for tauao, i'm usually around.

I'm not a hacker or pentester though, i just shared what i heard and learned. I'm here to learn too.
>>
>>674820874
Thanks.
What about Facebook? What are some up to date methods that still work on human stupidity? Phishing is kinda useless, considering FB's login alert security.
>>
File: Edgemaster.jpg (362 KB, 1920x1080) Image search: [Google]
Edgemaster.jpg
362 KB, 1920x1080
>>
>>674821389
btw i'm not now.
>>
>>674795403
Why use kali if youre gona use chrome? You know it has an easy dll exploit right?
>>
>>674821434
OMG, what a weirdo!! Telling my local police officer about this!!1
>>
>>674821596
runs chrome as root.

This is why OP is such a huge skid
>>
File: hackinginprogress.gif (3 MB, 320x180) Image search: [Google]
hackinginprogress.gif
3 MB, 320x180
>>674795403
When you finish up a test and the client asks you to omit findings from the test so they don't look incompetent, do you comply?

are you one of those john strand faggot flagwavers who will only use psexec or do you go full-exploit (e.g. execute overflows)?

when you walk into a client and you notice they have a fireeye box, and you ask them if the pentest they're getting is in response to a breach, are you ever actually surprised?

and finally, why the fuck are you using OpenVAS? It's a crashy piece of shit. Can't you do a pentest without an automated tool?
>>
File: a66.png (24 KB, 760x720) Image search: [Google]
a66.png
24 KB, 760x720
>>
>>674821663
Obviously boot as root user.. doesnt stop the illogic. Not only that you have to run java, impossable to keep your mac address spoofed. No logic
>>
>>674821832
My man, you are informed. Fuck OP and Fuck Full Disclosure
>>
>>674821955
this is why you are uninformed

you think you know exploits cause they have been published

we got exploits you barely dream about cuckhold and they are worth more than what fucking PWN2OWN pays. gtfo sage
>>
>>674821403

You'd have to deal with the facebook "Checkpoint" process.

It's been years since I've done it but they ask you to identify pictures of your friends with their names. You can find that out by looking at the profile via a sock account. Not very secure if you ask me.
>>
>>674821596
Every piece of software has an exploit. At any given time there's something like 40-60 unpatched exploits for browsers. It's not like you use kali for casual browsing.

And theres advantages to using chrome over iceweasle when you're using burpsuite pro.
>>
>>674822294
No im pointing out that running chrome makes your mac address impossable to spoof. Fuck exploits you stupid fucking pleb, you can get traced to your house and end up sucking bbd. Fucking idoit, underage b&
>>
File: 5jB3hfQ.jpg (65 KB, 527x544) Image search: [Google]
5jB3hfQ.jpg
65 KB, 527x544
>>674822628
>Stolen WiFi miles away
>spoofed MAC to evade ACL
>vPn
>SSH Tunneling to many victims i got owned.

Good luck raiding some clueless fuck. Bet you can't even tunnel.
>>
>>674821663

What OS runs chrome as root? Do you have any idea what your talking about? Back to hackforums for you.

>>674821832

We use nessus and if you knew anything about pentesting, we use that kind of software for scans. Pentests involve alot of manual work. No tool out there is going to get you into a workstation then root the domain controller in a automated sense.
>>
>>674822999
trips cheked
>>
what languages you programm?
and is math knowledge important?
>>
File: 1451411863848.jpg (114 KB, 312x455) Image search: [Google]
1451411863848.jpg
114 KB, 312x455
>>
>>674822999
CHEKEM
>>
>>674795403
How do you get contracts?
>>
>>674822628
You're talking about NIT's. It's the IP address exploit where it reports your actual IP to (most likely) an FBI server, although it can send other information about the interface, but i'm not sure if it can send a hardware address.

There's an exploit for that in every major browser, mostly around java exploits. But the exploit has to be sitting server-side.

There's a number of ways to avoid this, but #1 among them is never hack from home. Or at least using your own connection. I live in a hirise building in one of the 5 largest cities in the country and I have the pick of the litter of what wifi I want to use. Either a hacked/compromised one or one of a hundred different open wifi access points. Mac is changed every time, but it doesn't matter since I just bought an old laptop on craigslist for $50, took out the wireless card, and swapped them. Now even if they get the MAC, it'll go to a guy who said he sold the machine 2 years ago.. If they trace that to the email exchange, they'll find a connection to 10minuteemail.com.

There are ways to hide yourself completely. Good opsec breeds good behaviors.
>>
File: 1457272609741.jpg (125 KB, 720x722) Image search: [Google]
1457272609741.jpg
125 KB, 720x722
>>
what to ts3 server w/o permissions?
>>
File: PUNK.jpg (42 KB, 389x545) Image search: [Google]
PUNK.jpg
42 KB, 389x545
>>
>>674823509

General knowledge of C based languages is good enough. None of that hipster ruby on rails crap.

>>674823829

Marketing

>>674823876

This guy know's how the game is played. Hack on brother.

>>674823968

Offer the admin sexual services in exchange for kick permissions.
>>
File: 1.jpg (120 KB, 832x540) Image search: [Google]
1.jpg
120 KB, 832x540
Op here i can hack phones
>>
Do you need to have a lot of math knowledge?
>>
>>674824433
Since you're a hacker, do you go around hacking your friends facebook account and paypal accounts??
Even if you don't, do you even possess the skillsets to do such a things?

Like hacking emails and other things.
>>
>>674824697

Easily my favourite drug addicted business man but he speaks shit sometimes. He think's he's got a chance at the next election for presidency so that kind of explains the horseshit he keeps coming out with.
>>
>>674824433
Kicking permission is not the fun but will offer sexuals anyway
>>
>>674824824

Not so much. It'll help abit but the math behind encryption isn't that complicated compared to what physics scientists come up with.

>>674824918

I've done this once and I learnt my lesson. Everyone has vices and dark secrets, your better off not knowing.
>>
>>674823029
Screencap said openvas.

it looks like the skiddie is strong in you. using nessus in a pentest? trustwave did that shit in a pentest a company i was contracting for a few years back. Asked for raw data, got a bunch of .NSE files from their resident fucktard. I fired them on the spot. Using a scanner for an engagement is the height of stupidity. Why pay $30,000+ for the output from a $1500 piece of software.

"But we went in with manual tools later!" Bullshit. No genuine hacker worth his salt is going to kick off an attack against an organization using a fucking commercial scanner, setting off every fucking IDS/WAF they have. It's like the anonymous retards that fire off Accunetix and then load up havij when they finally find a Blind SQL injection.

I've been doing pentests since the late 90's. The CISSP fucktard invasion of the oughts have really made the business fucking cramped.
>>
File: 1456390267205.jpg (221 KB, 958x598) Image search: [Google]
1456390267205.jpg
221 KB, 958x598
OP here

My vice is sucking cock and pretending to be an elite hacker on 4chan, but i really just google shit cause you guys are all shit and cant even google
>>
>>674825221
My man, OP is a fucktard
>>
>>674825221

Your obviously talking shit. There are 15000 exploit POC's out there. Your expecting a security company to try every single one manually? You know why computers exist right, to automate manual tasks?

Come back to me after your first week of working in the IT industry.
>>
>>674825175
What does that even mean, I asked if you possess the skills to actually do them, not about your moral orientation HAHAHAHAHAA.

So it's still possible to hack facebook accounts of people and such?

What would you do? I bet all methods of injections have been patched, and social engineering isn't really hacking.

So what direction do you go? I seriously have no idea.
>>
File: 1454604164131.jpg (62 KB, 664x561) Image search: [Google]
1454604164131.jpg
62 KB, 664x561
>>674825790
OP, you're a piece of shit

You white hats are all like that (except maybe >>674825221 )

we on the otherside of things come up with shit while you faggots grab off the 1days or wait for your commercial scanners to pick that shit up.

i feel sorry for the people that have you a job. Seeing they pay shit ton of money for you to run tools even a 5 year old can. You can fight all you want here. But it is the truth.

Then again, i really dont give a fuck a bout the whitehat, you guys are all a meme
>>
>>674826359

so much edge. do you have the mask and everything?
>>
>>674826638
not that guy but u shuld give it up OP ur a piece of shit these other anons proved it
>>
>>674815357
>>674814822
small steps and lots of lube
>>
File: n6aJmnN.jpg (101 KB, 680x540) Image search: [Google]
n6aJmnN.jpg
101 KB, 680x540
>>674826359
>>
>>674827013
thats OP lelelwlelelllelelele

Anonymous is full of whitehats being edgy and feds
>>
OP youre a faggot and to prove it
Ill challenge you to a CTF competiton. Deal?
>>
>>674827280
Not OP but I'd team up with you, im from PPP looking for some fun while we work on another ctf today
>>
File: hackin.gif (4 MB, 380x270) Image search: [Google]
hackin.gif
4 MB, 380x270
>>674825790
>check everyone manually

Nope. that's what banner checking and google is for. Light touches. Connect in using burpsuite, as you navigate it silently notifies you of potential holes and vulnerabilities. You connect in once, recon and then you research.

what benefit comes from blasting a customer with nessus? They likely bought a copy of that already.Costs ~$1500 per license. You come in "hey i'll do a pentest for you!", hit them with nessus? You're just exploiting the holes they already know about, and charging them $30,000 (or however much. some others charge $60,000 or more) for the privilege. You offer no expertise, no actual understanding of risk impact. You give them a laundry list of holes made up from nessus output and say "Hey, see you next year!"

Or maybe you do application pentesting. I can only imagine. Accunetix maybe, where it's so sloppy that it fills any database they have up with garbage (there's a reason it only costs $5000). Or maybe your firm went all out and got a copy of Appscan or Webinspect.

I'm sure you ran the bestest botnet in the whole wide world and you farmed all the BTC and stole all teh credit-kardz, but you're still a slack, know-nothing ripoff shit who fucks his clients over by using bare-minimum effort. You're a hack. And not in a good way.

Fortunately, most firms get wise to this form of bullshittery after being burned, and they don't call on you in the future. Fortunately for you, the industry is saturated with a whole host of know-nothings, so you're likely to have an undistinguished career if you're bright enough to keep your head down.
>>
>>674827507
Not bait, sure. Of course its not bait.
>>
>>674827851
Whatever then, back to working on the CTF we are on today I guess. This thread is cancer.
>>
>>674795403
whats the best way of logging all connections regardless of protocol, port, whatever, made by a particular application running on GNU/Linux?
>>
>>674828066
PPP arent even registered on bctf you fucking tard...
>>
how do you find " zero day's" , use your tools to search for them or you actually have to explore the code?
>>
>>674828255
not doing that ctf with PPP retard, going under another name with a few guys who are and others who are not in PPP.
>>
>>674819147
>that HP workstation
lucky little fuck
>>
what do you hack, websites?
>>
>>674828881
he tries to hack his pants. but since he's a skid, he cant even hack that
>>
File: 1331091660632.png (70 KB, 224x240) Image search: [Google]
1331091660632.png
70 KB, 224x240
What do you think about wikipedia?
>>
>>674808959
>implying bash is standard
>implying linux is an operating system
>implying anyone has ever sat down and learnt bash
>>
>>674829765
>>implying anyone has ever sat down and learnt bash

I'm gonna go out on a limb and say that Stéphane Chazelas and Chet Ramey might have.
>>
>>674829765
Bash is the standard shell. Its the best. Yeah, people take classes on shell scripting and spend a lot of time learning how to deal with bash. Linux is a kernel, but you seem like a pretentious faggot walking around saying "Linux/GNU".
>>
>>674795403
Do you enjoy this
http://frtyb.com/go/gQ0i_bAaEj/cheesepizza
>>
>>674795403
ok... wht is the ultimate good place to learn Kali?, probably you seen tons of videos on youtube, but they are capy and people only talk about wireshark, payloads etc... not actual ussefull stuff? have anything in hand? tutorialwise
>>
>>674830082
bash is an acquired skill, not learned

>>674830086
csh is standard not bash, and it's far from being the best. it's not fucking 2002 nigger. and yes I like to have my terminology right when I talk about technical subjects, and if you think that's being a pretentious faggot then you're just a fucking retard who doesn't understand the basic principles of communication
Thread replies: 226
Thread images: 39

banner
banner
[Boards: 3 / a / aco / adv / an / asp / b / biz / c / cgl / ck / cm / co / d / diy / e / fa / fit / g / gd / gif / h / hc / his / hm / hr / i / ic / int / jp / k / lgbt / lit / m / mlp / mu / n / news / o / out / p / po / pol / qa / r / r9k / s / s4s / sci / soc / sp / t / tg / toy / trash / trv / tv / u / v / vg / vp / vr / w / wg / wsg / wsr / x / y] [Home]

All trademarks and copyrights on this page are owned by their respective parties. Images uploaded are the responsibility of the Poster. Comments are owned by the Poster.
If a post contains personal/copyrighted/illegal content you can contact me at [email protected] with that post and thread number and it will be removed as soon as possible.
DMCA Content Takedown via dmca.com
All images are hosted on imgur.com, send takedown notices to them.
This is a 4chan archive - all of the content originated from them. If you need IP information for a Poster - you need to contact them. This website shows only archived content.