Getting in to hacking

I keep seeing folks in my place jumping on the cybersec team. Currently a rather bored oracle DBA so maybe a reskill in this direction (had some networky bits in the past) might be a plan.

What's the generally accepted qualification these days (and pointers to any study material maybe). Dunno if I've quite the interest from the other side to be effective at it beyond some simple understanding (packet amplification, various forms of "injection" attacks that I think are a bit old hat these days). But still...

Loads of excellent resources on Youtube, check out David Bombal, he interviews quite a few people who seem well versed in the field.
 
Playing Bandit?
If so, then Level 1 needs you to output dashed filename in the user home directory to get the password for Bandit2 user.
I didn't realise what you had to actually do with the password, realised who I was logged in and made it to level 5 before realising I had to do some actual work!
 
I spent quite a while playing with VHL/HTB/Tryhackme etc, did a bit over 100 boxes and was intending on doing OSCP and changing career at one point, then I got a pay rise in my current job and scrapped the idea of jumping ship.

It's well worth learning some pen-testing - it's actually got me out of a few scrapes at work where I managed to find a way to hop around the back and bring a failed site back up because of a misconfiguration. Also handy for rooting some devices where nobody knew the passwords. It completely changes your perspective on designing and deploying new environments. :)

Not sure I really have the enthusiasm to keep up with such a quickly changing landscape anymore though.
 
Does anyone remember what web site this is, if I try and describe it?

It was around 15-20 years ago and it wasn't quite 'hacking' as such, but you still needed to be fairly ok with computers. It had levels starting with level 1 and each level needed a password to get to the next level. So for level 1, all you had to do with view the page's source and somewhere in the HTML it said "EASY!" so that was the password. Then for level 2 and upwards it got harder. There was one particular level that was a large JPG or PNG image that appeared all-white to the naked eye. The solution was to load it up in an image editor (I used Paintshop Pro 7) and used some of the darkening tools such as brightness/contrast. Once the contrast was high enough, it would reveal some letters that you could see with the naked eye and that was the password for that level.
 
Does anyone remember what web site this is, if I try and describe it?

It was around 15-20 years ago and it wasn't quite 'hacking' as such, but you still needed to be fairly ok with computers. It had levels starting with level 1 and each level needed a password to get to the next level. So for level 1, all you had to do with view the page's source and somewhere in the HTML it said "EASY!" so that was the password. Then for level 2 and upwards it got harder. There was one particular level that was a large JPG or PNG image that appeared all-white to the naked eye. The solution was to load it up in an image editor (I used Paintshop Pro 7) and used some of the darkening tools such as brightness/contrast. Once the contrast was high enough, it would reveal some letters that you could see with the naked eye and that was the password for that level.
Yes I remember this as well but can't think of it's name. I'm sure there was a thread on here about it.
 
Endgame final boss:

denise_v5.png
 
I've heard that social engineering is the way these days.

It always starts with a good disguise. If you don't have facial hair, grow some. If you already have it, shave it off.

Next up, become a linguistic wizard. Enroll in every language class you can find. Go on city breaks immersing yourself in foreign culture until you start dreaming in multiple tongues.

Walk differently. An old technique is to put a pebble in one shoe. Alternatively walk sideways with a cane.

Feeling adventurous? Take a trip to Wonderland with a heroic dose of psychedelic substances. This will alter your personality and mannerisms to unrecognizable levels.

At this point you will need to hire a chaperone to do the talking for you, and possibly hold you upright.

Once you have done all this you would have all the tools at your disposal to infiltrate any organisation without them even knowing.
 
is that from mr robot or something? it looks like nonsense so I guess not?


AFAIK that show used real hacking/security tools and not CSI style screens

Most hacking is script kiddies, theres programmes that scan Ips for known vulnerabilities, totally legal on your own network.

wen you find one you get out the scripts and take it over.

back when I was into that stuff it was through some IIS exploit that let you inject code and upload an ftp daemon server with full root access.

this was like 15-20 years ago before windows updated itself and sys admins were lazy

The screenshot in Malevolence's post is simply ffmpeg converting a video (I use it all the time on my HTPC).
Doesn't appear to be anything to do with hacking.
 
telnet towel.blinkenlights.nl

in all reality tryhackme is a good start.
 
Last edited:
Back
Top Bottom