Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
raffi
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
1.
▲
by
raffi
5y ago
I took the Computer Security and Internet Security courses from Professor Du at Syracuse University, years ago. Both courses had end projects that required extending a kernel and userspace to implement security functionality. At that time,
2.
▲
by
raffi
5y ago
I'm going to assume you're interested in network penetration testing in large traditional-IT enterprises: It's very common for folks to enter the security testing field mid-career with a background in something else. This is
3.
▲
by
raffi
11y ago
When I was in high school and early on in college--I didn't enjoy math. I always thought of math as the drone of memorizing formulas and plug+chug. I later took a class that used a textbook, Laboratories in Mathematical Experimentation
4.
▲
by
raffi
12y ago
I launched Feedback Army on HN in 2008. It's consistently paid my part of my Washington, DC rent for years. I gave some details about how I marketed it on its blog and in the side projects book someone put together awhile ago. Sadly, I
5.
▲
by
raffi
12y ago
I am a one-man shop and sell software in the enterprise space. I also have competitors and while I see my product as very different, a lot of my work goes into educating my market about why. Most of my customers are household names and they
6.
▲
by
raffi
12y ago
Re: CS Secret Handshake--years ago, I found the Programming Interviews Exposed book. I own the first edition. It's a lot of concise explanations of different Computer Science topics. The authors focus on things that are likely to come
7.
▲
by
raffi
12y ago
I've lived in DC for nearly five years and I run a software company here. Here are my thoughts: 1. The quality of life here is very high. I believe this is probably one of the best places in the US for young professionals (its reputati
8.
▲
by
raffi
12y ago
SPF only checks the message envelope. His target's email provider may not correlate the MAIL FROM statement in the envelope with the From header inside of the message content. Some large webmail providers will use this mismatch as a cu
9.
▲
User Account Control – What Penetration Testers Should Know
(blog.strategiccyber.com)
2 points
by
raffi
13y ago
|
0 comments
10.
▲
by
raffi
13y ago
I run a business selling penetration testing software that I develop. It's completely bootstrapped. I do very little services work (I actively send this type of stuff to friend's companies). Right now, it's just me, although
11.
▲
Man-in-the-Browser Session Stealing
(blog.strategiccyber.com)
2 points
by
raffi
13y ago
|
0 comments
12.
▲
by
raffi
13y ago
> Value gets us paid. Working as an engineer, I'd probably pull a similar salary between a company like Apple or a high-end consulting firm. The profit per employee between these firms is drastically different though. We're not
13.
▲
by
raffi
13y ago
I work in the security industry. Quite a few folks in this industry will quit their job to just go learn. They then jump back into a job once they get the skills they wanted. They do it out of passion for the work. I've made a sustaina
14.
▲
I was most productive--when I was unemployed
(blog.strategiccyber.com)
1 points
by
raffi
13y ago
|
2 comments
15.
▲
Tradecraft - Free Red Team (Hacking) Operations Course
(youtube.com)
1 points
by
raffi
13y ago
|
0 comments
16.
▲
The ACE Problem Solving Method (I use this)
(blog.strategiccyber.com)
1 points
by
raffi
13y ago
|
0 comments
17.
▲
Email Delivery - What Penetration Testers Should Know
(blog.strategiccyber.com)
3 points
by
raffi
13y ago
|
0 comments
18.
▲
by
raffi
13y ago
A browser pivot is a way to inherit a user's identity by forcing their browser to fulfill requests for an attacker. This attack gets cookies, session cookies, HTTP authentication, and even SSL sessions authenticated with a client SSL c
19.
▲
Browser Pivoting (FU2FA)
(youtube.com)
1 points
by
raffi
13y ago
|
1 comments
20.
▲
Browser Pivoting (A way to get past two-factor auth)
(blog.strategiccyber.com)
1 points
by
raffi
13y ago
|
0 comments
21.
▲
by
raffi
13y ago
(1) Social engineering is a key component of several high profile intrusions that happen today. The best way to help an organization understand their ability to detect, mitigate, and/or contain this type of attack is to do it. https:&
22.
▲
by
raffi
13y ago
I'll answer to unzip. In the post, I'm using a Linux distribution called Kali Linux. Kali is the successor to BackTrack Linux. Most people who use my software, use it with Kali Linux. Kali is a distribution with a focus on offensi
23.
▲
by
raffi
13y ago
I look at this as knowing my audience. I sell software for penetration tests and red team assessments (e.g., to hack into stuff; not check a box). The people who use my software easily have the skill set to do what I wrote about and defeat
24.
▲
by
raffi
13y ago
@valleyer: He "signed up" for a trial and emailed me for help. But, when he asked for help, he provided the tar command he typed and the output of the tar command. He changed the tar command he typed to make it look like he was tr
25.
▲
by
raffi
13y ago
I read shadowOfShadow's comment the same way you do. (for others reading this): in the comments section, I reproduce an exchange (anonymized, of course) I had with someone complaining about my support--when they were trying to install
26.
▲
by
raffi
13y ago
My startup creates software for use in penetration tests and red team assessments. I distribute backdoors and I'm quite aware of it. :) I wrote this post to show how to use my software to backdoor a pirated copy of my software.
27.
▲
How to crack my software and add a back door
(blog.strategiccyber.com)
177 points
by
raffi
13y ago
|
55 comments
28.
▲
by
raffi
13y ago
I've watched his series Connections about three times over. It's excellent and well worth your time.
29.
▲
How to Inject Shellcode from Java
(blog.strategiccyber.com)
1 points
by
raffi
13y ago
|
0 comments
30.
▲
by
raffi
13y ago
After I wrote that blog post, I also added the ability to tunnel traffic through Beacon when its checking in several times each second. Recently, I added the ability for it to download a large file, a piece at a time, with each checkin. The
More ›