You are viewing a single comment's thread.

view the rest of the comments →

cnp4500 ago

I hope you find support help promptly.

I just wanted to say I cringed when I saw the job description, which was masterfully written, but gives hackers a clear picture of your current setup. I would have rather seen this job description on a recruitment website without the mention of Voat, than out in the open here. But I understand you have your reasons for also posting it here.

Good luck on your search and thanks for all your recent hard work. I expect Voat will be targeted more often as we get closer to November 3rd, 2020.

Commie_Meta ago

gives hackers a clear picture of your current setup

Hiding the architecture doesn't make it much more secure. Network intrusion starts with fingerprinting: testing the target's responses to find subtle differences that tell which OS and software are running. Then every known attack is used to try to break in. Tests are also launched against every known IP address to find a way into the target's network: routers, firewalls, database servers, UPSes, surveillance cameras, etc.

Attackers commonly use fuzzers: software that tries millions of weird random mutations of the requests, hoping to find one that produces an unusual response. Fuzzers are great for finding subtle bugs in input processing -- they come up with off-the-wall ideas that humans would not think to try.

Finally, attackers manually look at the HTML/JavaScript and try to exploit form fields. They send characters you should be filtering out and see if you are. They combine fields from multiple forms and see if you try to handle them both at the same time and break something.

The most important part of software security is getting it right. A determined adversary can find flaws of great subtlety and obscurity. Ideally you should be able to give the adversary every possible type of help except the passwords and nothing bad happens.

cnp4500 ago

Thanks for the explanation. I’m glad I’m retired now and no longer in the business.

Pudge76 ago

Those with nefarious intentions may just fall into a...T...R...A...P...The higher powers are with us!!!

cnp4500 ago

Good point. Never let it be said that hackers and those on the Left are as smart as a bag of hammers.

Pudge76 ago

Lol...right?