stringochars

- friends
25 link karma
1,062 comment karma
send messageredditor for
what's this?

TROPHY CASE

Question for all the pen. testers, security analysts, how do you like your job ? by i_shotin netsec

[–]stringochars 0 points1 point ago

Points well taken. The joy anonymity on the internet is that I'm allowed be brutally honest (with myself). I have a lot of friends in well paid professions, so my benchmarks are probably screwed up.

Question for all the pen. testers, security analysts, how do you like your job ? by i_shotin netsec

[–]stringochars 0 points1 point ago

For me it has been less about the training, but more related to getting involved in projects that have a security flavor, but are not sponsored by security. Being a consultant affords me this flexibility.

Well aware that 150k is a lot of money, as others have alluded to. My perspective comes from living in a big city, with friends in law, management consulting, and finance.

Question for all the pen. testers, security analysts, how do you like your job ? by i_shotin netsec

[–]stringochars 0 points1 point ago

That's a great point. I was thinking more in terms of general corporate America, with only a middling commitment to security.

Question for all the pen. testers, security analysts, how do you like your job ? by i_shotin netsec

[–]stringochars 3 points4 points ago

Interesting. Industry and location?

Question for all the pen. testers, security analysts, how do you like your job ? by i_shotin netsec

[–]stringochars 2 points3 points ago

Basic stuff. Lots of uses of host based proxies for web app hacking. Different SQL injection methods. Targeting MS SQL on non-standard ports (SQL Ping). Wardialing. How to google for for default passwords. Windows privilege escalation.

Basically 75% of internal pen tests for us came down to MSSQL having bad passwords (or blank for SA) and domain service accounts.

Question for all the pen. testers, security analysts, how do you like your job ? by i_shotin netsec

[–]stringochars 6 points7 points ago

Got lucky. A TA in college told me to go interview with a consulting firm that was recruiting on campus. His exact words: "They will pay you to learn how to hack." Total stroke of luck.

Kept me from becoming a help desk manager or something miserable.

Question for all the pen. testers, security analysts, how do you like your job ? by i_shotin netsec

[–]stringochars 5 points6 points ago

This jives with my experience. Security is also a somewhat limited career field, in that corporate full timers in security will not make more than 150k in the states, but I'm sure there are some exceptions.

I think it's been quite fun and interesting for 7 years, but to advance my career I've had to broaden my scope to include things like IT Ops and general infrastructure management.

Niece's computer doesn't connect to the internet. by KuloDiamondin talesfromtechsupport

[–]stringochars -1 points0 points ago

PureText is a handy little free utility that runs in the background. You can set a key combination (e.g. Win+V) to just paste plain text. I love it.

European Delivery Program: can anybody explain why one WOULDN'T want to do it? by mlorin BMW

[–]stringochars 2 points3 points ago

Because you are a cheap fsck like me, and prefer buying slightly used.

BMW lands two motors in Ward's top 10 Best Engines by ganeshtin BMW

[–]stringochars 1 point2 points ago

Love my N55!

Today, at the security checkpoint, the TSA agent did not accept the USA Passport Card and asked for a second form of picture ID. She said "these don't work here". by honore_ballsacin OperationGrabAss

[–]stringochars 0 points1 point ago

I used my Portsmouth Brewery Royal Pint ID card to fly a month ago when I lost my driver's license. It's completely up to the discretion of the TSA agent.

What do you use to watch your logs? by Revo84in sysadmin

[–]stringochars 1 point2 points ago

Deploying ArcSight for a client. Holy crap is it expensive.

ELI5: Why would Israel release over 1000 prisoners for 1 soldier? by EnsuingRequiemin explainlikeimfive

[–]stringochars 0 points1 point ago

Wow, that Ramallah lynching is horrific. I know it's one incident in a long and sad story, but that is really barbaric.

I'm tired of shallow casual games, are there any games with some depth? by LevantineKnightin ipad

[–]stringochars 1 point2 points ago

Damn it. Every day is a noob day for me.

I'm tired of shallow casual games, are there any games with some depth? by LevantineKnightin ipad

[–]stringochars 2 points3 points ago

Really? This game felt a bit repetitive. It was certainly gorgeous, but after a few hours, it felt like 6 or so different minigames strung together into a grinding experience.

I'm tired of shallow casual games, are there any games with some depth? by LevantineKnightin ipad

[–]stringochars 15 points16 points ago

Really? This game felt a bit repetitive. It was certainly gorgeous, but after a few hours, it felt like 6 or so different minigames strung together into a grinding experience.

I'm renting my Logan Square apartment by the day! Friends visiting and you don't want to host? Send them my way. by cajcin ChiList

[–]stringochars 0 points1 point ago

So where do you stay if someone rents it out? I'm curious how this model works.

Any thoughts on how to block specific AD users from accessing the internet? by its_my_namein networking

[–]stringochars 1 point2 points ago

Yikes, you should get those service accounts whittled down (in terms of privileges). They really shouldn't be DA. If someone gets access to a machine with a service account logged in, the could get DA pretty quickly.

Better buy: 328i or GTI by justsigneduptosayin BMW

[–]stringochars 1 point2 points ago

Drive them both; they are both great cars.

How to stop companies from spamming you by loki_racerin howto

[–]stringochars 2 points3 points ago

Many do block them, some don't. It's a decent tactic.

Civilization V Mobile out now (on 'feature phones') by Azuilin civ

[–]stringochars 2 points3 points ago

If a BlackBerry 8100 can run it, it's probably miserable.

Possibly moving to St. Louis. What to expect? by csguydnin StLouis

[–]stringochars 0 points1 point ago

Tech is strong everywhere right now, including St. Louis. I've was offered 2 jobs in InfoSec within days of moving to STL.

Possibly moving to St. Louis. What to expect? by csguydnin StLouis

[–]stringochars 0 points1 point ago

We pay $1500 for a totally updated 4br/2ba in Benton Park. Nice neighborhood.

IP management tool recommendations? by [deleted]in networking

[–]stringochars 4 points5 points ago

Infoblox? It's basically a swiss army knife

Curious how the St Louis smoking ban has affected your behavior. by mokshagrenin StLouis

[–]stringochars 0 points1 point ago

I guess I didn't realize there is a ban. I was in the Silver Ballroom last weekend, and it was full of smoke.

Smoking in bars sucks: my clothes stink and my head aches the next day. Bah.

view more: next