Got a short story for the weekend!
How a Malicious pdf can Lead to a Full System Compromise.
Have a wonderful and informed weekend. Expect our (@ChelseaFC) comeback in the second leg 🙂↔️
@anyrun_app@Medium
https://t.co/AkE7yvndVE
Don’t quit your job because you want to learn Cybersecurity. Not everyone who starts a career in this field gets a job immediately. Cybersecurity is not a get-rich-quick scheme. it takes time, consistency, and effort to break in.
Early this year, I came across an Application Security role at an international company on LinkedIn. When I opened the job description, I saw that over 400 people had already applied, but I decided to take a chance anyway.
I made it through the first and second interview rounds. When I got to the third round (the second technical round), I was given several technical tasks to complete within a week.
Two out of the four tasks were secure code review challenges. I was only required to identify vulnerabilities, list them, and provide recommendations. But I knew I wasn’t the only strong candidate, and let’s be honest, being Nigerian, the odds weren’t exactly in my favour. So I knew I had to do something extraordinary.
Instead of doing it the traditional way, I built actual APIs using the vulnerable code they provided. Then I manually exploited each vulnerability exactly the way a real attacker would.
After that, I documented everything and wrote a near-perfect pentest report, screenshots, reproduction steps, impact, and recommendations included.
Then I took it a step further:
I rewrote the vulnerable code securely based on my own recommendations, rebuilt the APIs, and attempted to exploit them again using the same attack paths. Every attack failed, and I documented all of this in the same report to show clear before-and-after proof of remediation.
The crazy part is that, I completed everything in under 24 hours, even though I was given 7 days. I submitted the report with an email that ended with:
“…I hope this early submission won’t incur any penalties.” 😂
I made it to the 4th round (the 3rd technical round), and you could literally see the excitement on the interviewer’s face trying to figure out “who the hell is this guy?” 🤣🤣
Long story short, I made it to the final round, and I eventually got the offer letter.
I’ll attach a redacted version of my report and the GitHub repo link in the comments (PDF format), along with the code I wrote.
I hope this inspires someone out there to always go the extra mile. Be extraordinary in whatever you do.
Found a CVSS 9.9 critical, spent time validating it, only to get hit with a duplicate from 5 months ago that is still pending triage.
The turbulence of bug bounty is real. On to the next one💀
Microsoft reúne una excelente serie sobre #ActiveDirectory Hardening, con temas fundamentales para reducir la superficie de ataque:
✅ Deshabilitar NTLMv1
✅ Eliminar SMBv1
✅ Forzar LDAP Signing
✅ Implementar AES para Kerberos
✅ Configurar LDAP Channel Binding
✅ Forzar SMB Signing
✅ Aplicar Least Privilege
✅ Reducir y eliminar el uso de NTLM
⚠️ Hardening no significa aplicar una GPO y esperar lo mejor. Requiere inventario, auditoría, pruebas y validación de dependencias.
Una lectura imprescindible para cualquier administrador de Active Directory. 👇
https://t.co/1vpiTDL5Bu
I am living in my answered prayers. God has been so kind to me this year. I pray my company continues to grow and thrive. I’m enjoying this new season ❤️
“Dr Ireti, I want you to mentor me.”
No problem. Are you passionate about Cybersecurity and ready to put in the work?
If yes, applications open next month, apply ❤️💪