Welcome, Guest: Register On Nairaland / LOGIN! / Trending / Recent / New
Stats: 3,153,504 members, 7,819,828 topics. Date: Tuesday, 07 May 2024 at 01:48 AM

EvilSec's Posts

Nairaland Forum / EvilSec's Profile / EvilSec's Posts

(1) (2) (3) (4) (5) (6) (7) (8) (9) (10) (of 11 pages)

Programming / Re: Here's What Nairaland Looked Like In 2005 by EvilSec: 7:47pm On Jul 09, 2020
continuation...

1 Share

Programming / Re: Here's What Nairaland Looked Like In 2005 by EvilSec: 7:45pm On Jul 09, 2020
Continuation

Programming / Here's What Nairaland Looked Like In 2005 by EvilSec: 7:44pm On Jul 09, 2020
I was bored earlier, so I went back in time to grab screenshots and show nairalanders what this site looked like from when it was created in 2005 till now. Drop your comments if you think it's UI went through any major changes.

Here's the order of the pictures sorted according to year:
2005
2006
2007
2008
2010
2011
2012
2013
2014
2020

2 Likes 3 Shares

Programming / Let's Stop Talking About Password Strength by EvilSec: 2:01pm On Jul 09, 2020
Near the top of most security recommendations is to use "strong passwords". We need to stop doing this.

Yes, weak passwords can be a problem. If a website gets hacked, weak passwords are easier to crack. It's not that this is wrong advice.

On the other hand, it's not particularly good advice, either. It's far down the list of important advice that people need to remember. "Weak passwords" are nowhere near the risk of "password reuse". When your Facebook or email account gets hacked, it's because you used the same password across many websites, not because you used a weak password.

Important websites, where the strength of your password matters, already take care of the problem. They use strong, salted hashes on the backend to protect the password. On the frontend, they force passwords to be a certain length and a certain complexity. Maybe the better advice is to not trust any website that doesn't enforce stronger passwords (minimum of 8 characters consisting of both letters and non-letters).

To some extent, this "strong password" advice has become obsolete. A decade ago, websites had poor protection (MD5 hashes) and no enforcement of complexity, so it was up to the user to choose strong passwords. Now that important websites have changed their behavour, such as using bcrypt, there is less onus on the user.


But the real issue here is that "strong password" advice reflects the evil, authoritarian impulses of the infosec community. Instead of measuring insecurity in terms of costs vs. benefits, risks vs. rewards, we insist that it's an issue of moral weakness. We pretend that flaws happen because people are greedy, lazy, and ignorant. We pretend that security is its own goal, a benefit we should achieve, rather than a cost we must endure.

We like giving moral advice because it's easy: just be "stronger". Discussing "password reuse" is more complicated, forcing us discuss password managers, writing down passwords on paper, that it's okay to reuse passwords for crappy websites you don't care about, and so on.

What I'm trying to say is that the moral weakness here is us. Rather then give pertinent advice we give lazy advice. We give the advice that victim shames them for being weak while pretending that we are strong.

So stop telling people to use strong passwords. It's crass advice on your part and largely unhelpful for your audience, distracting them from the more important things.

28 Likes 6 Shares

Programming / Re: Mummy Lied To Me. by EvilSec: 11:14pm On Jul 06, 2020
mentro:
MUMMY LIED TO ME

8 November 2019|Artificial Inteligence, Inside Life, Master Classes

I was born in Yaba. Luckily, it wasn’t on the left side, my mum told me. But then, looking back she didn't tell me everything about life. And my dad? Perhaps he just wanted me to find out. Thank goodness I did. Or did I?



“Be a medical doctor so that you can make me proud”

“Opeyemi, I want you to be a lawyer"

"Opeyemi make me proud so that when people ask who that engineer is, I can say he is my boy.”

Or what would Musa not see at the gate? I saw it all.

My entire studies, from primary to secondary, were all about what my parent wanted for me. Nobody asked me what I wanted for myself. Did they think that I was too young and naive? Although to be fair, if they had asked me I would have said I wanted to be a Pilot. But at least, mummy should have asked the world what they wanted or needed in me.

Or how would you explain it? My primary school did not have a computer, my secondary school did not have a computer room, yet the world needed programmers, the world needed software developers, the world needed system engineers. The world was moving fast, but nobody told me.

I know you are reading this, but please let me ask. Did anybody tell you? Did you find out by yourself? I am asking because I think I was left out, left without the skills needed in my generation. In a world where ignorance is no excuse, who can I blame?

One day I decided to find out for myself. I went online to a website, continue reading from this link.


https://rainigeria.com/news-%26-events/f/mummy-lied-to-me
This writeup is a great read.
Nairaland / General / Re: SCAM ALERT!!! Please Help by EvilSec: 2:42pm On Jul 02, 2020
rasheedatt:
I don't know what is wrong with my account anytime I received money or save I get debited instantly.

I have been to my bank so many times but they do assure me that they will rectify it and nothing will be done.

I have lost almost 70k since last year how can I get my money back?

I went to the bank last week ' I was told that my account was being used to purchase things online how could this be?

I have never purchased anything online
I wonder how the scammer know when I receive money before instant withdrawal.

please what can I do? They have finished my savings am left with nothing and am tired of going to uba.
Please help they have ruined my life I can't use my account anymore.
Am still in debt because I was transferred 30k to give to someone and it's all gone please has anyone experienced this before?
What can I do am in trouble now.
Go peep at your account statement. You'll find what has been swallowing your money.

1 Like

Programming / Re: I Have Switched To Vim As My Primary Editor, You Should Too by EvilSec: 11:41am On Jul 02, 2020
melodyogonna:
I'm now one week into using Vim as my editor, I added something new yesterday, the sidebar file explorer ���
Vim is pretty cool and has a ton of amazing easter eggs. I once found an editor configuration that vim doesn't have. I asked on the mailing list if they could add it and they lectured me on how options are bad... in vim?! �

2 Likes

Programming / Re: What They Taught You About The OSI Model Was A Lie by EvilSec: 5:44pm On Jul 01, 2020
SegFault:

Wow a hacker. First time seeing one.
That can't be true.

2 Likes

Programming / Re: What They Taught You About The OSI Model Was A Lie by EvilSec: 4:56pm On Jul 01, 2020
stanliwise:
The group isn’t active any more like b4 o. How you come dey roll na. How is coding
Sadly, I barely code anymore these days... What about you?

1 Like

Programming / Is Public Wifi Still Safe In 2020? by EvilSec: 3:50pm On Jul 01, 2020
I'm going to rebut almost all articles that claims you shouldn't connect to Public WiFi. The short answer is, Yes, it is okay to use public WiFi, it is not extremely dangerous. Instead, companies who want to sell you something hype the danger.

A decade ago, public WiFi was extremely dangerous, as demonstrated with "sidejacking", etc. These days, major websites have their act together, and HTTPS is secure -- as long as you don't bypass HTTPS warnings. It's not perfectly "safe", of course, it's just that it's not particularly dangerous vs. all your other online activities. Moreover, it's often not an option: these days, you have to connect to the Internet, and through your mobile phone is not always an option for travelers. Now, "open" WiFi is stupid, like that in airport lounges that still require a password to be entered in a landing page. Such things should always be WPA2 encrypted. It's only marginal protection, of course, but will stop a lot of passive eavesdropping.

Also protip: If you don't entrust your employees to pay attention to HTTPS errors, then you can force them through a VPN. So while public WiFi is mostly safe, you can make it still safer.

3 Likes

Programming / Re: What They Taught You About The OSI Model Was A Lie by EvilSec: 3:16pm On Jul 01, 2020
stanliwise:
EvilSec where did you run to? Miss alot o. Haba, the only hacker I know.
Hahaha! Stanliwise the badass coder!
Took some time off bro... I also lost your number a long time ago, is that your group still up?

2 Likes

Programming / Re: Thread closed by EvilSec: 10:51am On Jul 01, 2020
MetasP:
Am not a noob
I just hav a few problems for example web delivery
you know it's about something shady when you get quotes from accounts created 2 days ago.
How about you use your real account "franklyn4" xD

1 Like

Programming / What They Taught You About The OSI Model Was A Lie by EvilSec: 10:26am On Jul 01, 2020
So let's discuss the "OSI Model". There's no such thing. What they taught you is a lie, and they knew it was a lie, and they didn't care, because they are jerks. You know what REALLY happened when the kid pointed out the king was wearing no clothes? The kid was punished. Nobody cared. And the king went on wearing the same thing, which everyone agreed was made from the finest of cloth.

The OSI Model was created by international standards organization for an alternative internet that was too complicated to ever work, and which never worked, and which never came to pass. Sure, when they created the OSI Model, the Internet layered model already existed, so they made sure to include today's Internet as part of their model. But the focus and intent of the OSI's efforts was on dumb networking concepts that worked differently from the Internet. OSI wanted a "connection-oriented network layer", one that worked like the telephone system, where every switch in between the ends knows about the connection. The Internet is based on a "connectionless network layer". Likewise, the big standards bodies wanted a slightly different way of how Ethernet should work, with an LLC layer on top of Ethernet. That never came to pass. Well, an LLC layer exists in WiFi packets, but as a vestigial stub like an appendix. So layers 1 - 4 are at least a semblance of reality, incorporating Ethernet and TCP/IP, but it's layers 5 - 6 where is goes off the rails. There's no Session or Presentation Layer in modern networks. Sure, the concepts exist, but not as layers, and not with the functionality those layers envisioned.

For example, the Session Layer wanted "synchronization points" to synchronize transactions. Their model never worked, and how synchronization happens on the Internet is vastly more complex, with pretty much everybody designing their own method. Another example, is how Google does Paxos synchronization at scale is a big reason for their success. It's an incredibly tough problem for which it's impractical to create a standard. In any case, you wouldn't want it as a "layer". Sure, HTTP has "session cookies" and SSL has a "session" concept, but that doesn't make these "session layer" protocols.

The OSI Presentation Layer (layer 6) is even more stupider. It was based on dumb terminals connected to mainframes. It was laughably out-of-date before it was even created. Back then, terminals needed to negotiate control codes and character sets. It's not simply "dumb terminals", it's the fact most everyone was still stuck on the concept that computer networks were for human-computer communications, rather than computer-computer communications. The OSI Model they teach is a retconned (retroactive continuity) one that just teaches the TCP/IP model and calls it the OSI Model, and does major handwaving over the non-existent Session and Presentation layers.

I suppose "OSI Model" can be justified if everyone taught the same thing, if it were all based on the same specification. But it isn't. Everyone makes up their own version, like which where to put SSL. (The correct answer is "Transport Layer", btw). As for the popular question "in which layer does encryption belong?", the correct answer is "all the layers". And then some.

2 Likes

Programming / Re: I Build Game Awsome Income by EvilSec: 9:03pm On Jun 30, 2020
MetasP:

Bro pls reply ur mail. I seek ur help pls. I got some problems with a certain infiltration
What infiltration?
Phones / Re: India Bans 59 Chinese Mobile Apps (Full List) by EvilSec: 10:34am On Jun 30, 2020
Incase you're wondering why TikTok took the lead of the most toxic app ever, A guy on reddit reversed engineered TikTok... Here’s what he found on the data it collects on you.
It’s far worse than just stealing what’s on your clipboard:

4 Likes 2 Shares

Programming / Re: I Build Game Awsome Income by EvilSec: 11:04am On Jun 29, 2020
valzey:

Thought as much. I've used unity but I just tried their demo game development and gave up. I can manage the code but can't say much for modelling, story, sound....etc alone. I'll prefer to work with a team on game development.
This is true. Game dev is only interesting as a team.

1 Like

Programming / Re: I Build Game Awsome Income by EvilSec: 2:52pm On Jun 28, 2020
valzey:
Which Gaming Engine are you using?
That's Unity

1 Like 1 Share

Programming / Re: Why Do Self Taught Programmers Over Exaggerate by EvilSec: 7:17am On Jun 28, 2020
lawrenzooo:
You would not blame those self thought developers. I have see CS graduates that don't know how to boot a computer let alone program. Majority of our graduates are just paper graduates ( it cut across all fields) and its not there fault most of the time as our educational institutions are not helping matters when it come to practical. back then in school in my department we had over 200 computers in our lab but there was never power for us to use the computers.
EvilSec:

While new students might not realize this, "computer science" does not teach how to code. Instead, it teaches lots of useful information that coders might need, like O(n) or OS fundamentals.

To learn to code, the best route is self study rather than CS or any other major. There’s probably no other skill for which there is so much freely available high-quality learning material online.

2 Likes 2 Shares

Programming / Re: A Thread For Tutorial On Python Programming by EvilSec: 8:33am On Jun 27, 2020
Lolo24:
If you can write a book on python please send me a message
Why would anyone want to write a book on python when there's a shit ton of books on python already?
Well unless you're willing to shake a bag of coin xD.

3 Likes 1 Share

Technology Market / Re: RC Planes For Sale by EvilSec: 6:09pm On May 03, 2020
RCDIY:


I'll advise you don't buy on AliExpress except you're prepared to spend a lot on clearing it when it arrives Lagos. It'd most likely be detained by customs/DSS.

I can set it up complete with a flight controller to make flying easy like flying on a simulator.

Let's discuss on WhatsApp.
Hi! Just sent you an email, let's talk.

1 Like

Programming / Re: Have Never Heard About HACKING, Dont We Have Serious HACKERS ? by EvilSec: 6:05pm On May 03, 2020
Bahat:


I stopped doing bugs and others when It's not turning productive for me if you have a group you can share me the link to join while I soak myseld in some of your works and probably do something when I'm free
Don't have a group... I might have to create one though, but I'm not sure if people would be interested.

3 Likes 1 Share

Programming / Re: Have Never Heard About HACKING, Dont We Have Serious HACKERS ? by EvilSec: 5:35pm On May 03, 2020
Bahat:


I'm also into Linux reverse engineering sometimes does windows reversing, I love checking and following research papers. Not bug hunting asit doesn't payhere been doing web/mobile based this days . Do we have good bug bounty around in Nigeria
Reversing linux execs is a lotta fun... I'm getting into into binary exploitation soon.
Btw, we don't have bug bounty programs in Nigeria. I work at hackerone and bugcrowd.

4 Likes

Programming / Re: Have Never Heard About HACKING, Dont We Have Serious HACKERS ? by EvilSec: 5:27pm On May 03, 2020
Bahat:


Hmm that's great and good news what do you do to be precise
I'm a bug bounty hunter, I also reverse malware when I'm bored... What's the good news?

3 Likes 1 Share

Programming / Re: Have Never Heard About HACKING, Dont We Have Serious HACKERS ? by EvilSec: 5:23pm On May 03, 2020
Bahat:


This is good news. Let's make a telegram group to make learning and discussion swift there we can show and teach new skill to members. What type of vuln and what's the risk level have you tried to exploit it? Did the exploit work out?
One is a crit and the other two is medium severity... XSS, CSRF and Open Redirect... Exploit works out great btw, wrote a PoC for them all.

4 Likes 1 Share

Programming / Re: Have Never Heard About HACKING, Dont We Have Serious HACKERS ? by EvilSec: 5:06pm On May 03, 2020
Bahat:


I'm not sure about that but we can work on something meaningful we can make a telegram group to discuss and invite people
Sure we can! Was originally planning to open a thread where I disclose some of the vulns I've found on NL... I'm trying to show people how hacking works in the wild.
Most people think it's by sitting back, and running a bunch of automated tools then hope to find a crit.

3 Likes 1 Share

Programming / Re: Have Never Heard About HACKING, Dont We Have Serious HACKERS ? by EvilSec: 4:55pm On May 03, 2020
Bahat:
I wonder if there are even good hackers here in nairaland, when i mean hackers i am not saying script kiddies (Those that use tools of the community), i mean researcher, people who think, innovate on new ways of doing things, people who deals with computer internals, who use Unix,Linux,Bsd as their default operating system.

You up for a little challenge?

2 Likes 1 Share

Foreign Affairs / Re: Iran Reopens For Business As No End In Sight To Coronavirus Pandemic by EvilSec: 5:28pm On Apr 29, 2020
So basically Iran now runs on face masks, hand sanitizers, insha Allah and vibes.

4 Likes 1 Share

Programming / Re: Calculate Your Future Wealth With Python by EvilSec: 6:38pm On Apr 23, 2020
codeigniter:
hello guys, watch me write a python application that helps you to calculate your future wealth and lets you know what to do to stay wealthy.

If you like the video please subscribe and like, and if you don't, you can always dislike and tell me how to improve myself in the comment section.

Thanks for watching.


https://www.youtube.com/watch?v=88IMcQWdOIc
Awesome vid! Loved it.

1 Like

Programming / Re: LEARN ETHICAL HACKING,TIPS AND TRICKS by EvilSec: 8:37pm On Apr 16, 2020
nurain150:
Evilsec
I see you've registered on h1... Play a couple of CTF's to earn private invites, and shoot me a message if they're eligible for bounties/if the payouts are juicy and we hack 'em together.
Collabs are fun xD.

2 Likes 1 Share

Programming / Re: LEARN ETHICAL HACKING,TIPS AND TRICKS by EvilSec: 2:45pm On Apr 10, 2020
JayJayGee:

btw I recently started following you on here, cos you inspire me and you seem to know what you're doing.
So when I start up properly, I hope I can get you to mentor me
Thanks for the kind words cheesy
Do get in touch when you're ready.

4 Likes 1 Share

Programming / Re: LEARN ETHICAL HACKING,TIPS AND TRICKS by EvilSec: 10:37am On Apr 10, 2020
nurain150:
Let's talk a few about getting certified and getting a skills without any certification to show for it how does it feel? Too me hmmm fear ooo.Okay back to business
i haven't gotten any certification so far but am planning on getting as these courses are expensive.You know what I mean if you choose udemy or a dedicated trusted certification like Cisco or ceh ...hmm
I Think Google could be of help But let me discuss a few I know.
Kali Linux Certification - I think this guy's are up to issuing you cert on been a system administrator, learning how to use the harmmer and chisel of Kali Linux hacking tool.I mean who goes to a farm without hoe.
I think this the only certification I know that is for free there a ton lots out there feel free to use Google.Dont mind my typing habit anyways

The KLCP is not free, it costs a couple hundred quids.
Hey! I love your thread btw, if you ever wanna collab on a bug bounty program or need a CTF buddy, let me know.

1 Like

(1) (2) (3) (4) (5) (6) (7) (8) (9) (10) (of 11 pages)

(Go Up)

Sections: politics (1) business autos (1) jobs (1) career education (1) romance computers phones travel sports fashion health
religion celebs tv-movies music-radio literature webmasters programming techmarket

Links: (1) (2) (3) (4) (5) (6) (7) (8) (9) (10)

Nairaland - Copyright © 2005 - 2024 Oluwaseun Osewa. All rights reserved. See How To Advertise. 68
Disclaimer: Every Nairaland member is solely responsible for anything that he/she posts or uploads on Nairaland.