Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
adricnet
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
by
adricnet
7y ago
Ange Albertini's work on collisions is pretty great and he makes lots of example images and illustrations. https://corkami.github.io/ In particular he works on/with the PoC||GTFO team and is responsible for the MD
2.
▲
by
adricnet
8y ago
Probably so, the Security Onion wiki has some recommendations for affordable taps: https://github.com/Security-Onion-Solutions/security-onion/w...
3.
▲
by
adricnet
8y ago
Thanks for the share this looks great! It aligns quite well with the study (in diagrams and commented assembly) of x86 in POC || GTFO starting in pocorgtfo04.pdf chapter 3 provided by Shikhin Sethi.
4.
▲
by
adricnet
8y ago
Thanks for the share. I enjoyed this article and may be able to put some of it to work. I don't quite understand all of the negative responses.
5.
▲
by
adricnet
9y ago
The Nature article and notebooks from a few years back are still pretty good for demos, though everything has updated since then , especially iPython -> Jupyter. https://www.nature.com/news/interactive-notebooks-shar
6.
▲
by
adricnet
9y ago
Over The Wire challenges are awesome. Bandit is very educational and easy to start. Others are quite a bit more challenging.
7.
▲
by
adricnet
9y ago
I do agree. That's actually part of why I called out the language: maintaining balance (as well as not cussing in front of the wrong people) are critical skills for security professionals and sorely lacking in many would-be candidates.
8.
▲
by
adricnet
9y ago
The advice is pretty good overall, but the excessive profanity is unprofessional and distracting. It is interesting that he values "SANS" certifications, but not the courses for them. Besides my own rambling[1] you might find thes
9.
▲
by
adricnet
9y ago
I found Tobias Klein's _A Bug Hunter's Diary_ to be quite readable and enlightening even if I couldn't follow all of the code. https://nostarch.com/bughunter
10.
▲
by
adricnet
9y ago
This mirror of a Purism blog post to his personal blog looks pretty interesting but I'm having trouble accessing it on homelinux or puri.sm domains due to reputation. Here's G cache: http://webcache.googleusercontent.c
11.
▲
by
adricnet
9y ago
Thank you for sharing this. It was interesting and a bit sad.
12.
▲
by
adricnet
9y ago
_The Week_ is quite good (US or UK). They have people read many of the things you don't have time to (including _The Economist_ :) ) and pull highlights from them across a broad range of topics.
13.
▲
by
adricnet
10y ago
This is an interesting and thought-provoking read. Thank you for posting it.
14.
▲
by
adricnet
10y ago
On Android or iOS or did you mean sign a source release ...? My guess is because of potential friction with reproducible building (for Android) and this for iOS: https://github.com/WhisperSystems/Signal-iOS/issues&
15.
▲
by
adricnet
10y ago
Yes, but that was consumer / education market gear first (iMac) as I recall. More or less back on topic ... I bought a HP Probook for my on-the-road studies/work last cycle because I needed a portable that I could do _work_ with a
16.
▲
by
adricnet
10y ago
In line with the principle of charity I'd like to point out that your declaration here that network IDS provides only "minor cost savings" is controversial to the point of almost being aggressive towards folks working in info
17.
▲
by
adricnet
10y ago
Speaking vaguely on purpose without sources (apologies), the folks who were concerned about weapons targeting a few decades back had no expectation that any part of the greater metropolitan Atlanta area would survive a nuclear strike. The h
18.
▲
by
adricnet
10y ago
Ah Inferno! Did anyone make any headway porting/redoing the browser plugin to Mozilla? There were some mumblings about GSoC for that not that long ago.
19.
▲
by
adricnet
11y ago
Only one of them requires readwrite system administrator privileges (eg sudo). apt-cache can be run by any user as it doesn't expose any secret data and can't be used to make changes. apt-get can install and uninstall software a
20.
▲
by
adricnet
11y ago
Thanks for sharing this! I could wish for some tool use (gdb) screenshots, though really the inspiration to learn is valuable enough. A next read in this vein might be Bug Hunter's Diary by Tobias Klein: https://www.nostarch
21.
▲
by
adricnet
11y ago
Keep please and thank you for working on this! This is much more readable on Android/Chrome Moto G, will try more later.
22.
▲
by
adricnet
11y ago
Neat, thanks for posting! Invisible Secrets [ http://www.east-tec.com/invisiblesecrets/ ] has a mode for this that works quite well on HTML source. Rendering is unchanged and you have to be looking at the source and look
23.
▲
by
adricnet
11y ago
I saw World Polio Day XKCD Comic, which wasn't the usual extra joke but is certainly accurate and appropriate an ALT tag. Possibly because I have a FireFox extension just for those, actually: http://piro.sakura.ne.jp/xu
24.
▲
by
adricnet
11y ago
The content is available after it is decrypted in a browser on a single host. If the streams are inspectable by network defenses they can be inspected at much more feasible scale allowing one device to protect 10,000s of hosts from the sa
25.
▲
by
adricnet
11y ago
Yes, especially when they seem to affect their applications. Automatic updates are easy (mostly). Healthy software and vulnerability management that doesn't damage productivity needlessly can be a lot of work. What do you test? The cla
26.
▲
by
adricnet
11y ago
This was an interesting and enjoyable quick read. Thanks for posting the link!
27.
▲
by
adricnet
11y ago
I was looking for these articles when I posted earlier, very nice tutorials for EG that data you want that is only presented as a Flash applet: https://www.propublica.org/nerds/item/doc-dollars-guides-col...
28.
▲
by
adricnet
11y ago
ProPublica has some great material on techniques for data journalism, including scraping and transforming unfriendly data formatting: https://www.propublica.org/nerds
29.
▲
by
adricnet
11y ago
Okay, so looking over the post they didn't feel like CVSS 2 was giving a clear indication of risk, and CVSS 3 isn't done yet and lacks perfection. That's sensible enough, I suppose. I hope they took more than a glance at what
30.
▲
by
adricnet
11y ago
I scanned this before coffee this morning and in short I'm not sure anyone else should read it in its present state. Although the author poses some interesting ideas the piece feels long and muddled and I'm not at all sure who the
More ›