Joe (GonzoSec) 🇺🇸🇺🇦 (@jsark983) 's Twitter Profile
Joe (GonzoSec) 🇺🇸🇺🇦

@jsark983

OSCP, CRTO, GCPN, GWAPT, MS in InfoSec. Fortunate pen tester... just learning all the things! And the obligatory: my views don’t equal my employer’s...

ID: 985310997622808578

linkhttp://www.gonzosec.com calendar_today15-04-2018 00:17:02

2,2K Tweet

875 Takipçi

723 Takip Edilen

Joe (GonzoSec) 🇺🇸🇺🇦 (@jsark983) 's Twitter Profile Photo

Apple being Apple: Check out the new iPhone 17 pro! It has a better camera and faster chip. We’ve innovated literally nothing, but drop another $1K with us thanks!

Joe (GonzoSec) 🇺🇸🇺🇦 (@jsark983) 's Twitter Profile Photo

You find out a pentester has made 4 separate findings because they ran NXC and found petitpotam, printerbug, mseven and dfscoerce on a DC. 4 findings or 1?

Joe (GonzoSec) 🇺🇸🇺🇦 (@jsark983) 's Twitter Profile Photo

Agreed, and we have a large client base, but many of that base doesn’t have a fleshed out AI product to test yet. We do ask, but slow going…

Joe (GonzoSec) 🇺🇸🇺🇦 (@jsark983) 's Twitter Profile Photo

Latest checkup on what industry leaders are telling those outta school, etc who want to pentest as a career? What’s the advice you’re giving these days given the misinformation so many have heard around lavish promises of a tech career?

Joe (GonzoSec) 🇺🇸🇺🇦 (@jsark983) 's Twitter Profile Photo

CTFs are fun and all, but we have created what feels like an entire cohort of security folk that have adopted that mindset and use it when performing the real work. All that matters in “prod” is proving risk to clients. Prove why what you found matters or it didn’t happen.

Joe (GonzoSec) 🇺🇸🇺🇦 (@jsark983) 's Twitter Profile Photo

The crucial things you to jam into the heads of your mentees: 1. No stupid questions except the one you’ve asked 17 times and has been answered. 2. You’ll never learn all this overnight 3. Speak up when you need help 4. It’s never as bad as you think

Joe (GonzoSec) 🇺🇸🇺🇦 (@jsark983) 's Twitter Profile Photo

One of the worst things in this industry is when a client signs up after having a prior vendor for years who never did/found much. We come along asking for things they’ve never been asked before, find more than the last vendor, etc. Who you think gets the client wrath here?

Joe (GonzoSec) 🇺🇸🇺🇦 (@jsark983) 's Twitter Profile Photo

FUD: someone is going to hack your WiFi to determine when you’re home to then rob you in the physical realm. Someone provide me data showing this is happening on a scale where your average person should even consider it a risk and I’ll go F myself.