When performing testing activities, whether it is web application penetration or usability testing, it is helpful to have example content to submit in web form fields. The same can be said for people trying to create sock-puppet or alias accounts on the Internet. We need to have sample/fake information so that we can set up... Continue Reading →
The Problem after a Raise
I spoke to a junior employee today. He was upset with his latest pay raise. It was smaller than he wanted and, as a result, he stopped putting in extra effort at work. No more going above and beyond, staying late, or trying hard. So I said to him, "Were you upset like this before... Continue Reading →
Offensive Interviews
Just a quick blurb that I've started a Github project called Offensive Interviews. The goal of this project is to open source many interview questions that can be used to screen offensive infosec practitioners (i.e., pentesters/red teamers). It is a collection of questions and scenarios that you can use to help screen candidates. Of course,... Continue Reading →
Complex Knowledge-based Password Reset Strings
With all of the data breaches recently, I urge everyone I know to use a password manager application like KeePass (http://keepass.info/) or LastPass (Yes I know they too got hacked) to store complex, long passwords. The benefit to using these apps is that you can make your responses to those knowledge-based password reset questions (e.g.,... Continue Reading →
Infosec Resumes: What do employers care about?
Ever wonder what hiring managers look for in "good" resumes? While I cannot speak for my employers, I can say that there are certain pieces of resumes that I care more (or less) about when I review them. Who I usually am looking to hire people that are computer-savvy. The positions I need filled are... Continue Reading →