Blog

The three questions boards should ask to manage cyber risk

The three questions boards should ask to manage cyber risk

Posted on 2022-11-25by mattin Business Security


If you were a company director and you could ask three questions to judge the cyber security of the organisation, what would they be?

Continue reading
From SysAdmin to Pentester - Part 5 - OSCP vs PNPT

From SysAdmin to Pentester - Part 5 - OSCP vs PNPT

Posted on 2022-10-31by nathanin Certifications


Part 5 of the Sysadmin-to-Pentester series is a comparison between two entry level penetration testing certifications. Offensive Security’s Certified Professional (OSCP) and TCM Security’s Practical Network Penetration Tester (PNPT). While both have their merits, they focus on different elements and provide different experiences. Deciding which to go for can be a challenge.

Continue reading
From SysAdmin to Pentester - Part 4 - Tickets please

From SysAdmin to Pentester - Part 4 - Tickets please

Posted on 2022-10-24by nathanin Certifications


Part 4 of the Sysadmin-to-Pentester series is discusses offensive security foundation-level certifications. While not required to get a job in the infosec industry, there is no denying that certifications help your chances of landing your first role. Luckily for you, I have done quite a few so far, and can tell you which are worth your time (and which are not).

Continue reading
From SysAdmin to Pentester - Part 3 - How to stand out in a crowd of paper

From SysAdmin to Pentester - Part 3 - How to stand out in a crowd of paper

Posted on 2022-10-17by nathanin Industry


Part 3 of the Sysadmin-to-Pentester series is all about how to make your CV stand out from the crowd. Junior roles are rare with many many applications. Additionally, hacking skills don’t translate well to text. So how do we show we have more skill and drive to be a penetration tester than the other candidates, on paper? Well…

Continue reading
From SysAdmin to Pentester - Part 2 - Great expectations

From SysAdmin to Pentester - Part 2 - Great expectations

Posted on 2022-10-10by nathanin Industry


Part 2 of the Sysadmin-to-Pentester series is discusses the differences between the idea and the reality of being a penetration tester. The certifications and the industry paint a picture a little different from the reality. A better understanding and more preparation towards the roles requirements will help you to decide if this is the role for you and how to ace the interviews.

Continue reading
Active Directory Hacking Speedrun

Active Directory Hacking Speedrun

Posted on 2022-09-23by alexeiin Tools of the Trade


On Saturday 24th of September, I gave a presentation at CSECcon titled, “Active Directory Hacking Speedrun! 14 attacks in 30 minutes.” This post is here to provide some post-talk resources to those wanting to learn about any of these attacks, how they work and recreate them.

Continue reading
5 methods for Bypassing XSS Detection in WAFs

5 methods for Bypassing XSS Detection in WAFs

Posted on 2022-08-09by karelin Tools of the Trade


Ever since the 1990s, Cross-Site Scripting (XSS) vulnerabilities have plagued the world wide web. It’s been a difficult problem to solve because of the many ways that it can introduce itself in applications. This, and other application level attacks, contributed to the rise of Web Application Firewalls (WAFs). However, like any other solution that does not tackle the problem by its roots, it’s not ideal. Pentesters, red teamers, bug hunters and malicious actors alike have been playing cat and mouse with vendors to find ways around these additional defence mechanisms. In this post, we’ll be discussing a few fundamental techniques that you can use to bypass these firewalls.

Continue reading
We were vulnerable - how a security company could have vulns

We were vulnerable - how a security company could have vulns

Posted on 2022-06-22by alexeiin Volkis News


Well, it finally happened! We received the first submission to our Vulnerability Disclosure Program with actual possible impact. And, although it didn’t actually affect us or our clients in any way, it could have. So we awarded it a P3! But how could this happen? We’re security experts ourselves, so shouldn’t we have picked up on it? Well, as we always tell our clients, “security is hard” and no one is perfect.

Continue reading
Attack Surface Management - The importance of knowing what you have

Attack Surface Management - The importance of knowing what you have

Posted on 2022-05-18by Volkisin Business Security


Here’s the problem: technology is evolving rapidly, cloud adoption is at an all time high, development is faster than ever, infrastructure has become more dynamic, and security is struggling to keep up! The first step to regaining control: knowing what you have.

Continue reading