>>I’ll tell you a story of when we were developing a product here States-side. We worked with one very gifted development team and we put all of our eggs into that basket. They were doing great work for us but…
I often right click where I want to click then left click out of the right click menu. It solves my subconscious desire to click, and lets my mind accept waiting. Plus, no negative effects, like going to the wrong link…
Yes the ones I know do it full time as their only income AFAIK. Most do live in low cost of living areas, none of them that I know are living in places like San Fran :)
Everyone is trying to get a piece of the pie :) trickiest thing right now is defining what an "asset" truly is. An asset could be ephemeral cloud infrastructure, an uncompiled piece of code, an API endpoint, a server, a…
I know a few folks who do full time between things like SynAck and BugCrowd. SynAck is the ideal model in my opinion for pivoting to full time vs part time as a professional bug bounty individual, although it takes a…
I am referring to a CIA (confidentiality, integrity, availability) related incident. Less so the availability. If an attack was truly motivated, the web stack / application stack is not how you compromise the system.…
>>Nobody is doing anything to try reduce or manage complexity so it's only getting worse. I disagree, I see a number of large corporations starting to standardize either 1) their entire development stack from IDE all…
>>1. Aside from: linux cmds, nmap, metasploit, sqlmap, mimikatz, kali's well known tools - what other tools are often used by pen testers ? I think those + your typical scanners (Nessus, Nexpose, etc). One gap I know…
>>I’ll tell you a story of when we were developing a product here States-side. We worked with one very gifted development team and we put all of our eggs into that basket. They were doing great work for us but…
I often right click where I want to click then left click out of the right click menu. It solves my subconscious desire to click, and lets my mind accept waiting. Plus, no negative effects, like going to the wrong link…
Yes the ones I know do it full time as their only income AFAIK. Most do live in low cost of living areas, none of them that I know are living in places like San Fran :)
Everyone is trying to get a piece of the pie :) trickiest thing right now is defining what an "asset" truly is. An asset could be ephemeral cloud infrastructure, an uncompiled piece of code, an API endpoint, a server, a…
I know a few folks who do full time between things like SynAck and BugCrowd. SynAck is the ideal model in my opinion for pivoting to full time vs part time as a professional bug bounty individual, although it takes a…
I am referring to a CIA (confidentiality, integrity, availability) related incident. Less so the availability. If an attack was truly motivated, the web stack / application stack is not how you compromise the system.…
>>Nobody is doing anything to try reduce or manage complexity so it's only getting worse. I disagree, I see a number of large corporations starting to standardize either 1) their entire development stack from IDE all…
>>1. Aside from: linux cmds, nmap, metasploit, sqlmap, mimikatz, kali's well known tools - what other tools are often used by pen testers ? I think those + your typical scanners (Nessus, Nexpose, etc). One gap I know…