Forum Replies Created

Page 5 of 7
  • Christophe

    Administrator
    May 20, 2021 at 4:08 pm in reply to: Howdy, folks. My name is Randy

    Welcome, and thank you for supporting us by purchasing our course!

    I (and I know many others) struggle with similar issues when learning, so you’re not alone! There have been a few things that have helped me stick to my learning goals without getting too distracted:

    1- Create a schedule and stick to it as best you can

    Literally add it to a calendar that will remind you repeatedly. I’ll set an obnoxious amount of reminders because otherwise I’ll see one of the notifications and forget about it seconds later.

    2- Find one or more study partners

    It’s like going to the gym and exercising. Most of us are far more likely to go and stick to our program if we have someone else going with us too. Otherwise we feel like we’re letting them down. Find someone who’s dedicated to learning and who will show up, and add them to those calendar invites you created

    3- I’d like to eventually have a more formal way of doing this, but for now I’m more than happy to help you stick to your learning schedule if you want

    Let me know what your timeline looks like and what your goals are, as well as which courses you’re going after, and I’ll send you reminders over time and/or ask you questions to make sure you’re progressing 🙂

    Hope this helps, and again, welcome to the community! Thrilled to have you here.

  • Christophe

    Administrator
    May 17, 2021 at 4:22 pm in reply to: Common mistakes when using tools ?

    Some ideas:

    • Before using tools against production applications, make sure you understand how they work. For example, sqlmap can be potentially destructive, so if you just point & shoot at a target and do damage, that could end up being a bad day for everyone
    • Another recent example with linPEAS. The tool was modified before the test taker took the exam, and there was an added feature they weren’t aware of that broke the exam’s rules. This is important in the real world too because it could lead to legal problems
    • Just because an automated tool doesn’t find anything doesn’t mean there’s nothing there. Sometimes tools don’t find what manual can
  • Christophe

    Administrator
    May 17, 2021 at 4:14 pm in reply to: Updating Commix ?

    Hey Anthony,

    1- To update commix and other tools + Parrot OS, check out the documentation here. They offer 3 methods under “How do I upgrade my system.” Let us know if that doesn’t work!

    2- In terms of which version you should use, that is up to you. The latest versions will typically have more features and hopefully be more stable. If the versions are close to one another, though, unless there was a big change, they should be similar and return similar results.

  • Christophe

    Administrator
    May 17, 2021 at 3:58 pm in reply to: SQLMap issue ?

    Would you be able to share the full command you’re using and what it returns back? Feel free to upload a screenshot

  • Christophe

    Administrator
    May 11, 2021 at 7:04 pm in reply to: Artificial Intelligence replacing us ?

    My take on it is that the viewpoint that AI will replace the need for ethical hackers completely is exaggerated and unrealistic. While there definitely are lots of jobs that will be displaced by AI over the coming years, many jobs will end up being enhanced by AI, not necessarily replaced.

    It’s kind of like when automated scanning tools were first coming out. A lot of people selling those tools were promising that they would replace the need for manual intervention. That’s never been the case and I don’t think it ever will be. They do help find certain things that humans would take far longer to find, and they help fix low-hanging fruit. But you still need people to go in and do their thing.

    So yes, I do think AI will greatly enhance certain areas of our field, but I don’t think it will replace the need for human ethical hackers — definitely not in the near future.

  • Christophe

    Administrator
    May 4, 2021 at 4:15 pm in reply to: Follow up to previous question.

    There are a few differences between purchasing from Udemy and purchasing from Cybr directly.

    1- Udemy takes a significant percentage of the sale (64%), while authors only make 37% (after all fees). So purchasing from Cybr directly is a huge help!

    2- While I do my best to keep both of the courses up to date, I prioritize fixing and updating the course on Cybr first. So anytime I add new content or make any modifications, they will apply to the course on Cybr before they are also applied to the Udemy course

    3- You can purchase bundles on Cybr that include the course + the ebook version of the course. This is not available on Udemy. Even the free ebook downloads are not available there.

    4- Lessons on the Cybr platform include the written lesson in addition to the video lesson, whereas on Udemy you will only get access to the video lessons.

    5- There are other restrictions on Udemy that don’t exist on the Cybr platform, that I think long-term will make learning cybersecurity a lot more fun here!

    In any case, because you already purchased the course there, I’ve given you access to it here as well, so there is no need to purchase it twice!

  • Christophe

    Administrator
    May 4, 2021 at 4:07 pm in reply to: POC templates ?

    I haven’t gone through all of this yet, but it looks like it might be an excellent resource for what you’re asking about: https://github.com/rmusser01/Infosec_Reference/blob/master/Draft/Docs_and_Reports.md

  • Christophe

    Administrator
    May 4, 2021 at 4:04 pm in reply to: Already paid XSS course on Udemy.

    Nope! Great question. There is no need to purchase it again on here. I was able to find your purchase on Udemy so I’m giving your account access on here now :-). Anyone else in a similar position and reading this please reach out on the Forums, on Discord, or on Udemy and I’ll be glad to do the same!

    Thanks for your support ❤

  • Christophe

    Administrator
    April 28, 2021 at 6:53 pm in reply to: Manual vs Automation ?

    Ironically, I’ve seen the “Real hackers don’t use Kali Linux” that @jfernandez mentioned and I’ve seen the exact opposite said too! I’ve seen answers on StackOverflow say “You have no business using Kali unless you already know what you’re doing.” So according to this, nobody should ever use Kali

    🤣

    Also @Bludger the cool thing with you is that you’re even building some of your own tools. Yeah, they may not be as advanced as some of the other tools out there, but you’re learning a s*** ton by doing that, so keep it up

  • Christophe

    Administrator
    April 27, 2021 at 10:40 pm in reply to: Manual vs Automation ?

    I would actually disagree with this to some degree:

    “The best hackers in the world take pride in hunting manually with the use of automation as a last resort”

    One of the top hunters on HackerOne (aka todayisnew) who’s earned $1m+ in bounties so far is known for his use and reliance on automation. The thing is, when you’re doing that sort of bug bounty hunting, one strategy is to look at it as a numbers game. Yes, finding a $10,000 critical vulnerability would be AMAZING. But wouldn’t it be just as amazing to find 40 $250 bugs while you sleep from automation? Tools can be great enhancers that work with/for you, not necessarily a last resort.

    The reason why I think people say what you wrote is that beginners do tend to rely heavily on tools at the expense of learning. After all, it can be much easier to type in a simple command that is well documented than to manually try to find something. Except, a lot of times, relying on tools like that doesn’t teach you how it really works. For example, let’s say that you need to be able to bypass a WAF. You go to Google and search for “WAF bypass tool github” and you download the tool to run it. The tool comes back empty and can’t find a way to bypass the WAF for whatever reason. You shake your head and either try a different tool or declare that the application is un-hackable and move on to the next.

    Except maybe the WAF bypass tool you were using hasn’t been updated in 4 years. Or maybe you didn’t use it properly. Maybe you can’t use them in the environment you have access to. Or whatever the reason is, sometimes you need to be able to roll up your sleeves and do things the hard way in order to find a bypass, or at the very least, confirm that you’re not able to find a successful bypass when talking to your client. Except, because you’ve relied on tools exclusively to do this in the past, you don’t have a clue how to even approach this manually.

    Another relevant example…I’m bug hunting some GraphQL endpoints right now, and I tried using a tool but it kept erroring out on me. I haven’t figured out why it errors out yet, but I’m not going to let that prevent me from manually going after the endpoints. I could have thrown my hands up in the air and blamed the author of that tool instead, but that’s not a winning strategy. You have to be able to persist, especially when things don’t work your way.

    TL;DR: I believe both have a place. Don’t let naysayers get in your head and make you feel bad for using tools. But don’t rely exclusively on tools to get the job done either.

    All of this is just my opinion in a sea of other opinions on the subject, so I’d love to hear other viewpoints from the community!

  • Christophe

    Administrator
    April 27, 2021 at 10:25 pm in reply to: Time Management

    That one is tough to answer because the answer is: as much time as you can! Lol

    Everyone’s time availability will be different at any given moment in time, so you gotta find what balance works for you. But this (bug hunting) is definitely an area where more time = more experience = getting better, especially when you’re first getting started. There’s simply no other way around it.

    So, my recommendation would be to try and dedicate a certain amount of time per week (since some days might be more hectic), and try to stick to that schedule as best you can. Definitely limit distractions while you’re in the zone.

    Not sure if this helps, but hope it does!

  • Christophe

    Administrator
    May 20, 2021 at 4:12 pm in reply to: What’s your biggest issue in cybersecurity right now?

    I hear ya. As someone who started out in cybersecurity and then moved to other areas only to come back a few years later, I’ve experienced the same. That’s part of why this community even exists: to welcome you back with open arms 🙂

  • Christophe

    Administrator
    May 4, 2021 at 3:59 pm in reply to: What content would you like to see from Cybr next?

    Awesome, thanks 🙂

  • Christophe

    Administrator
    May 4, 2021 at 3:59 pm in reply to: What content would you like to see from Cybr next?

    I think we could have either a general “writing effective POCs” short course, instead of making it specific except for some examples, or a first section that explains a structure and then different sections for some of the top vuln categories with examples? That way it’s not just one or another

  • Christophe

    Administrator
    May 3, 2021 at 5:01 pm in reply to: What content would you like to see from Cybr next?

    Awesome, thanks! Great suggestion

Page 5 of 7