I took the Computer Security and Internet Security courses from Professor Du at Syracuse University, years ago. Both courses had end projects that required extending a kernel and userspace to implement security functionality.
At that time, we had the option to work with MINIX. Here are the MINIX Role-based Access Control and Firewall Labs:
Professor Du's materials are also packaged for self-learners and other teachers to use, as the open source SEED project. A few of the current SEED projects are implementation-exercises similar to the above two labs.
I'm going to assume you're interested in network penetration testing in large traditional-IT enterprises:
It's very common for folks to enter the security testing field mid-career with a background in something else. This is almost preferable. The domain knowledge you have from your other experiences will serve you well when trying to understand [and find] security issues in related areas.
1. A potential path forward: Don't try to sell yourself as a penetration tester. Sell yourself as a developer who can support penetration testers/red teamers.
Modern ethical hacking requires a lot of coding to write new tools and customize existing ones. Even if you don't know much about how to get domain admin, escalate privileges, etc.--you can provide a lot of value just by the ability to ferret through MSDN and turn around C or .NET code that reproduces someone else's research or techniques for a team's internal use.
Rewriting existing stuff is really important as a lot of defenses are developed and tuned to public POCs or samples without much imagination for how the technique can vary with a little effort.
2. The Red Team Ops and Adversary Simulation community has a great culture of open research and code. Contribute to an existing project or start your own collection of interesting stuff to demonstate you have the chops to contribute as a developer.
3. If you're looking for the right "foot in the door" qualification, get the Offensive Security Certified Professional (OSCP) certification. It's hands-on and very well respected by the practitioners in this field. While the course will not turn you into a penetration tester, it demonstrates you can tackle the types of technical problems and concepts required to succeed in this work.
When I was in high school and early on in college--I didn't enjoy math. I always thought of math as the drone of memorizing formulas and plug+chug.
I later took a class that used a textbook, Laboratories in Mathematical Experimentation. The book and that class were the first time math became play for me. A big part of that class was digging into graph theory.
I launched Feedback Army on HN in 2008. It's consistently paid my part of my Washington, DC rent for years. I gave some details about how I marketed it on its blog and in the side projects book someone put together awhile ago. Sadly, I can't find a link to the side projects book or I'd post it here.
I owe a lot to Feedback Army. It was the first thing I made where I made money without putting an hourly value on a unit of my time. I learned to think of my business as a system for fulfilling what I promised and collecting money from customers. This side project was a great way to cut my teeth on some business and service fundamentals.
I am a one-man shop and sell software in the enterprise space. I also have competitors and while I see my product as very different, a lot of my work goes into educating my market about why.
Most of my customers are household names and they're not averse to dealing with my one-man shop. It doesn't even come up. Their staff wants my software and they work their process to buy it. That's it.
I have not had to answer any of these objections (thankfully). I'd probably pass on the customer if they came up.
Re: CS Secret Handshake--years ago, I found the Programming Interviews Exposed book. I own the first edition. It's a lot of concise explanations of different Computer Science topics. The authors focus on things that are likely to come up in an interview. The book provides a few tricks and an orientation to topics that are worth looking at further.
I've lived in DC for nearly five years and I run a software company here. Here are my thoughts:
1. The quality of life here is very high. I believe this is probably one of the best places in the US for young professionals (its reputation hasn't caught up with it yet).
* We have a strong bike sharing program and decent biking infrastructure. I'm not a biker and I use this most days now.
* I recently got rid of my car. I simply didn't need it. I can walk in four directions to neighborhoods with great restaurants. I also have several grocery stores within walking distance.
* The North West part of the city is very clean.
* I don't own a car. So long as I live here--I will not need a car.
* When I want to go running, Rock Creek Park is nearby. Same for the National Mall. If I want to go Kayaking on the Potomac, it's a longer walk, but I can hit a Dept. of Parks and Recreation boathouse and get a kayak.
* DC has a short-ish winter. We get one and it gets cold. Some days we get snow the city doesn't know what to do with. Overall though, January and February are the worst of it. Sometimes we get hints of Spring in March. April, Spring is usually here full bore. Spring and Fall here are beautiful. I'm from MI and I lived in Syracuse, NY. I judge weather through this lens.
2. DC is very expensive. I incorporated in DC and I suspect the city took a cue from the Spanish government in terms of forms and prerequisite forms and licenses one must acquire to start a business. They claim they're pro-startup. I don't see it. I just see a bureaucracy that nickels and dimes small businesses. Taxes are high too.
3. For my sector (cyber security) and the types of customers I have; DC is the perfect home base. I'm close to my customers and potential strategic partners. We even have a cyber security related accelerator in Northern Virginia. I see the concentration of folks and businesses in my industry as a big plus.
4. I travel a lot for my business. If I need to go to NYC--I take the Accela and I'm there in three hours. If I need to get into the suburbs of MD, I use the MARC train. If I need to fly, I have three airports to choose from. The closest airport (Reagan) is a 15-20 minute cab ride.
5. We have had a massive growth of startup and coworking spaces in the past two years. I don't know where they all came from--but it's insane. If you're looking for semi-affordable office space co-located around other startups--you'll find something here, probably walking distance from where you live.
6. DC benefits from a flood of ambitious folks who want to change the world and start their career here. When I moved here, I expected a scene of lawyers, lobbyists, politicians, and their hanger-ons. It's not like that at all here. This is a very ambitious city with people who work very hard to make things happen. I like its energy and this is probably where I will stay.
SPF only checks the message envelope. His target's email provider may not correlate the MAIL FROM statement in the envelope with the From header inside of the message content. Some large webmail providers will use this mismatch as a cue to send a file to the spam folder.
Delivering a targeted phish requires situational awareness, but it's quite feasible to pull off something convincing.
I run a business selling penetration testing software that I develop. It's completely bootstrapped. I do very little services work (I actively send this type of stuff to friend's companies). Right now, it's just me, although that's probably going to change. By most of my own definitions and the one you posted here... it's successful.
How did I get started on this? Sort of by accident.
I was working for Automattic after an acqui-hire thing. After a year there, I found that I missed working in security. I found a full-scope penetration testing gig three blocks from my apartment.
In my spare time, I started to tinker with a few ideas and released them as an open source project. Said project saw a lot of interest within the hacker community very quickly. I didn't expect this. Folks formed an opinion on it pretty quickly. Some people hate it. Others love it. Of those who know it, very few are in-between.
I left my pen testing job with a decent amount of money saved up. I didn't know exactly what I would go and do afterwards. I spent some time tinkering with Android, just for giggles.
I was very reluctant to start a business that used my "successful?" open source project. Partially because it leverages another open source project owned by another company.
I was at a conference in 2011 and someone from a US government agency asked if I was selling anything. I said no. He said that was too bad, because he had end of year money, and he liked my open source stuff. It was then that I decided to look at expanding my open source kit into a commercial product.
April will mark the two year anniversary of my first customer. My customers are well known organizations and they trust my software to assess how well they protect their networks. I'm constantly in awe of this.
Working as an engineer, I'd probably pull a similar salary between a company like Apple or a high-end consulting firm. The profit per employee between these firms is drastically different though. We're not paid in proportion to the value we generate. We're paid in terms of market forces with a slight bump if our company especially values us. We don't see the upside of our efforts, the companies we work for do.
I work in the security industry. Quite a few folks in this industry will quit their job to just go learn. They then jump back into a job once they get the skills they wanted. They do it out of passion for the work. I've made a sustainable business model out of my work. I don't talk to that piece, but I try to reflect on why I (and my friends who take a hiatus) are more productive when we're free of a normal workplace.
On HN, we're well acquainted with the benefits of working on our own. In the security industry, this isn't a common mindset yet.
A browser pivot is a way to inherit a user's identity by forcing their browser to fulfill requests for an attacker. This attack gets cookies, session cookies, HTTP authentication, and even SSL sessions authenticated with a client SSL cert.
(1) Social engineering is a key component of several high profile intrusions that happen today. The best way to help an organization understand their ability to detect, mitigate, and/or contain this type of attack is to do it.
(1a) Statements, such as "it requires social engineering" [it's not a valid vector] represent a dated understanding of hacker tactics and part of my work is to help folks with your view move their understanding forward. Usually the conversation is not a response to an adversarial comment like yours.
(2) Cobalt Strike builds on something called the Metasploit Framework. The Metasploit Framework is the largest open source collection of safe exploits. My product addresses gaps in this kit for executing attacks that mimic those high profile intrusions mentioned a moment ago. A successful operation requires more than an email with something bad attached.
(2a) Cobalt Strike's open source little sister is Armitage. A popular user interface and collaboration tool for the aforementioned "better and powerful and safer open source alternative to run exploits". I'm the developer of Armitage as well.
I'll answer to unzip. In the post, I'm using a Linux distribution called Kali Linux. Kali is the successor to BackTrack Linux. Most people who use my software, use it with Kali Linux.
Kali is a distribution with a focus on offensive security. Most tools require root to run. It's very rare to find a Kali user who uses sudo and works from a non-root account. root for all actions is normal.
Some people may use Kali day to day, but it's built to do a job.
I didn't call out Kali specifically, but all of my screenshots show Kali's default window manager theme. I don't know if my audience earns the "hacker" badge by your standards... but I suspect most of them recognize Kali from a distance.
I look at this as knowing my audience. I sell software for penetration tests and red team assessments (e.g., to hack into stuff; not check a box). The people who use my software easily have the skill set to do what I wrote about and defeat any anti-piracy measure I come up with. What to do? I think it's best to be very customer friendly, trust my audience, and make light of the 1337 cr4x0r who thinks they won a game I won't bother to play.
@valleyer: He "signed up" for a trial and emailed me for help. But, when he asked for help, he provided the tar command he typed and the output of the tar command.
He changed the tar command he typed to make it look like he was trying to install my trial.
The output of tar told a different story though. The cracked trial was distributed as a .tgz with a space in it. Because this guy didn't know to put quotes around the filename, tar gave him an error he didn't know how to interpret.
He left the output untouched, and I was able to determine the name of the file he was trying to extract, google it, and strongly conclude he was asking for support for a cracked version of my software.
I read shadowOfShadow's comment the same way you do. (for others reading this): in the comments section, I reproduce an exchange (anonymized, of course) I had with someone complaining about my support--when they were trying to install a cracked version of my software. This exchange is what led to the blog post linked here.
After I wrote that blog post, I also added the ability to tunnel traffic through Beacon when its checking in several times each second. Recently, I added the ability for it to download a large file, a piece at a time, with each checkin. The size of the piece depends on the data channel (DNS vs. HTTP). It's all encrypted too.
Cobalt Strike is a commercial tool, so it better include the bells and whistles. The OP does a good job of showing code that anyone can play with, right now.
Dan Kaminsky's BlackHat presentations on OzymanDNS are excellent as well.
At that time, we had the option to work with MINIX. Here are the MINIX Role-based Access Control and Firewall Labs:
https://web.ecs.syr.edu/~wedu/seed/Labs_12.04/System/RBAC_Ca... https://web.ecs.syr.edu/~wedu/seed/Labs_12.04/Networking/Fir...
Professor Du's materials are also packaged for self-learners and other teachers to use, as the open source SEED project. A few of the current SEED projects are implementation-exercises similar to the above two labs.
https://seedsecuritylabs.org/
I highly recommend the above resources.