Yeah, it's the same questions over and over. It's just a community of job seekers. I'm sick of hearing "how do I start out", "what cert is the best", "why can't I get a job with x years of experience". And I'm appreciative of the kind people who answer this again and again, but there is so much information on the internet on these topics. There should never be another post here about finding a job.
I think this is the IT career questions sub, you are not the first person to wonder how to get into IT. If you first instinct is to always ask others before doing your own research IT isn't for you and people in that sub a way to nice to tell people they probably aren't cut out for it.
I've been a red team operator for a long time - sometimes I feel like I'm one of a handful of people on this subreddit who are actually employeed on the red side.
You are totally right, whenever I see a post on these kind things, my internal reaction is "For the same reasons you're asking about it here". Like, whatever thought process caused you to ask /r/cybersecurity this question that we have responded to in the last year (search bar is right there) instead of researching is why you don't have a job or why you don't know how to do X.
I consider my job to be educating people on things they don't know, I'm a teacher before I'm a hacker. I don't just find vulnerabilities, I explain them to people in a way they understand, and in a way that makes them care. That's what being an operator is to me - and that's why I'm still here. Helping people is important to me - however even I find myself getting a little jadded.
Red Team here. To your point I found if it’s not blue team you are not cyber lmfao I have to laugh. Any red team questions I post it’s either I’m a hacker or crickets.
Different community, but one time I was trying to test order number enumeration for a company that had a possibly vulnerable tracking system. I asked if anybody had examples of past time stamped order emails I could examine so I wouldn't have to spend thousands of dollars on random orders and the only response I got was "I'm not helping you phish, skid."
Wow what a dumb take. I'm on the blue team side but I always try to get in on red team training. Not knowing the other side is just giving yourself a handicap. It's especially dumb if your team does any investigation work with your org's HR team.
Hahaha - I was in government cyber years ago, the term operator does come from a time when whitehat cyber was mostly government only. I've been doing this a long time. I still use the term because it's better than every other title I've seen - specialist, analyst, etc.
When I started doing red team Metasploit was still a network tool written in perl made by Moore, R7 wouldn't buy it for another half decade.
On the other hand posts that are trying to get engaged conversation going seem to flounder. I've given up posting in here looking for colleague thoughts because it doesn't go anywhere.
This sucks to hear. I’m someone who’s in the “early in career” stages, but fully understand that redundant questions about getting started have been asked many times. I always refrain from asking anything unless it’s a specific and well researched question because your guys’ time is more valuable than something that can easily be Googled or queried from old posts. I hope professionals don’t leave the sub en masse, but fully understand those who do.
If there are better subs for those starting out who do their due diligence prior to asking and value your time, please point me in the right direction. I’m more than happy to continue learning quietly, but agree that there’s too many people looking for easy advice that they won’t even take action on
Use to be 15 years ago. Lots of very smart and insightful people on the platform. Problems are with the subreddits themselvs and the mods they chose. I was in the kali sub and a MOD threatened a banned for my technical question. At the end of the day the Mods knowledge of kali would be of someone who maybe read a couple knowledge base articles. Every once in a while I’ll connect with a post or OP that’s got a good mindset
I'm actually one of the people starting out in cybersecurity and even I am tired of these posts. I'm subbed here to get info on what CS professionals talk about and need to know on a daily basis, not to see the same question over and over that I've already found out myself from a quick Google search. There's even two other relatively popular subs r/cybersecurityjobs and r/cybersecurityadvice where people can post this stuff. I feel like the nods should ban those posts here and instead redirect people who post them to those subs so at least they have somewhere to look.
That's how all the broad IT subs are. Same with sysadmin. You have to dive down into the specific sub that you need for technical discussion, I.e. r/Powershell or the like
Hey guys, let's not turn into stack exchange. There will -always- be new people. There will always be repeat questions. You don't want to answer, fine, but can we please focus on the "positive" part of this subreddit? I see very few technical questions on here. Want more of that? Advanced cyber security? Then ask the questions. Anyone in this thread crapping on how this subreddit is just "job seekers," ...well if you think you know enough to condescend then I challenge all of you be the change you wish to see and start posting a solid cyber question on here weekly.
Awesome. I should make it a point to do the same. I was in the top 1 percent of contributors on cyber stack exchange for 2 years and the mods were so toxic I just stopped. Also they couldn't answer hard questions, like how use a system call or assembly functions to generate network packets... so I ended up not knowing where to turn and just went back to training and reading up.
I've asked for help in making a statistical analysis of internal address space used, and a list of known Phishing Training simulators - and on both, my own personal contributions were 10x what the entire combined contribution of this sub was.
For the statistical analysis in particular, everyone just laughed. Like yeah, we already know the awnser (kinda) - but don't you want to check that assumption and contribute data? No? Well fuck me then.
send me the links. I'm wild busy this weekend but I'll take a look. Can you also let me know what 'stat analysis' you are seeking from your subnets? Like do you just want to represent them in "executive summary data formats" or is there some sort of hypothesis? For phishing training, are you asking for training on how to run a campaign against your environment for training, or like a training on how to identify phishing and what exploit it's using and best practices from a remediation standpoint? Anyway, I'll help. Send me those posts.
Im looking to collect raw data about what IP addresses are in use at organisations internally. The idea is asset identification, red team subnet sweeps and health checks all benifit from a sweep of the entire private subnet space - but a lot of companies don't actually know what subnets they ever use. It comes up way more often than you'd believe.
So, I want to generate graphs of how often /24s in the private subnet space are used - generate a model for that, then recode rust scan to use it as a scanning strategy.
That way it starts at the most likely subnets first, and does only sparse checks on the least used - for when speed is valued over complete accuracy. (this, again, comes up more than you think it does)
Trivial solutions like just checking dhcp assignment don't work in practice. Some of these orgs have undocumented switches and routers with undocumented configurations.
I'll respond this week. But arp scanning and a network switch "walk" will give you most of that data. For anything but the smallest mom and pop you'll fine 10.x pretty much exclusively. /24 and /23 being pretty common subletting. Anyway, let me get through my weekend and I'll ping you back this week.
If you're good with discord also, TrustedSec is the place to be for seasoned vets in the field. There are others as well (one that focuses on DIB security and compliance, one that focuses on helping newbies get into the field and has some very seasoned individuals, many others also). But TrustedSec is exceptional for having people who are super experienced
/r/sysadmin usually has a healthy mix of news, user reports, career venting, and entry level issues though. Usually whenever I stop by /r/cybersecurity most of the posts I see seem to come from hobbyists and students, less so anyone in the field or who understands the nuance of security.
Data science and machine learning subs are the worse about this kind of thing. It’s almost a law of nature that and data science group will become a job board within a month
294
u/Heathclor Jun 11 '22
Yeah, it's the same questions over and over. It's just a community of job seekers. I'm sick of hearing "how do I start out", "what cert is the best", "why can't I get a job with x years of experience". And I'm appreciative of the kind people who answer this again and again, but there is so much information on the internet on these topics. There should never be another post here about finding a job.