Joe (GonzoSec) ๐Ÿ‡บ๐Ÿ‡ธ๐Ÿ‡บ๐Ÿ‡ฆ (@jsark983) 's Twitter Profile
Joe (GonzoSec) ๐Ÿ‡บ๐Ÿ‡ธ๐Ÿ‡บ๐Ÿ‡ฆ

@jsark983

OSCP, CRTO, GCPN, GWAPT, MS in InfoSec. Fortunate pen tester... just learning all the things! And the obligatory: my views donโ€™t equal my employerโ€™s...

ID: 985310997622808578

linkhttp://www.gonzosec.com calendar_today15-04-2018 00:17:02

2,2K Tweet

875 Followers

723 Following

Joe (GonzoSec) ๐Ÿ‡บ๐Ÿ‡ธ๐Ÿ‡บ๐Ÿ‡ฆ (@jsark983) 's Twitter Profile Photo

Apple being Apple: Check out the new iPhone 17 pro! It has a better camera and faster chip. Weโ€™ve innovated literally nothing, but drop another $1K with us thanks!

Joe (GonzoSec) ๐Ÿ‡บ๐Ÿ‡ธ๐Ÿ‡บ๐Ÿ‡ฆ (@jsark983) 's Twitter Profile Photo

You find out a pentester has made 4 separate findings because they ran NXC and found petitpotam, printerbug, mseven and dfscoerce on a DC. 4 findings or 1?

Joe (GonzoSec) ๐Ÿ‡บ๐Ÿ‡ธ๐Ÿ‡บ๐Ÿ‡ฆ (@jsark983) 's Twitter Profile Photo

Agreed, and we have a large client base, but many of that base doesnโ€™t have a fleshed out AI product to test yet. We do ask, but slow goingโ€ฆ

Joe (GonzoSec) ๐Ÿ‡บ๐Ÿ‡ธ๐Ÿ‡บ๐Ÿ‡ฆ (@jsark983) 's Twitter Profile Photo

Latest checkup on what industry leaders are telling those outta school, etc who want to pentest as a career? Whatโ€™s the advice youโ€™re giving these days given the misinformation so many have heard around lavish promises of a tech career?

Joe (GonzoSec) ๐Ÿ‡บ๐Ÿ‡ธ๐Ÿ‡บ๐Ÿ‡ฆ (@jsark983) 's Twitter Profile Photo

CTFs are fun and all, but we have created what feels like an entire cohort of security folk that have adopted that mindset and use it when performing the real work. All that matters in โ€œprodโ€ is proving risk to clients. Prove why what you found matters or it didnโ€™t happen.

Joe (GonzoSec) ๐Ÿ‡บ๐Ÿ‡ธ๐Ÿ‡บ๐Ÿ‡ฆ (@jsark983) 's Twitter Profile Photo

The crucial things you to jam into the heads of your mentees: 1. No stupid questions except the one youโ€™ve asked 17 times and has been answered. 2. Youโ€™ll never learn all this overnight 3. Speak up when you need help 4. Itโ€™s never as bad as you think

Joe (GonzoSec) ๐Ÿ‡บ๐Ÿ‡ธ๐Ÿ‡บ๐Ÿ‡ฆ (@jsark983) 's Twitter Profile Photo

One of the worst things in this industry is when a client signs up after having a prior vendor for years who never did/found much. We come along asking for things theyโ€™ve never been asked before, find more than the last vendor, etc. Who you think gets the client wrath here?

Joe (GonzoSec) ๐Ÿ‡บ๐Ÿ‡ธ๐Ÿ‡บ๐Ÿ‡ฆ (@jsark983) 's Twitter Profile Photo

FUD: someone is going to hack your WiFi to determine when youโ€™re home to then rob you in the physical realm. Someone provide me data showing this is happening on a scale where your average person should even consider it a risk and Iโ€™ll go F myself.