TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

The tragedy of low-level exploitation

66 pointsby abhaynayar10 months ago

6 comments

tptacek10 months ago
This is a pretty great post. One of its subtexts is the cliche of people taking jobs in offensive security and complaining that all they get to work on are web apps --- web apps are where all the money is, and where most new software is built. Another interesting subtext: there's a whole variety of low-level targets where modern exploit development techniques would come into play, but since there's no market for those vulnerabilities, there aren't many opportunities to get paid to develop the exploits; all the action is in browsers and mobile operating systems, where competition is incredibly fierce.
guardiangod10 months ago
&gt;low-level exploitation is rarely needed in cybersecurity<p>Sadly that&#x27;s true. I am transferring from a low level pentester to web app security engineer. That&#x27;s where all the jobs are. People don&#x27;t really care how much you know about low level.
abhaynayar10 months ago
Also, video going over the blog post by the author: <a href="https:&#x2F;&#x2F;www.youtube.com&#x2F;watch?v=58fwUXvhO3c" rel="nofollow">https:&#x2F;&#x2F;www.youtube.com&#x2F;watch?v=58fwUXvhO3c</a>
armitron10 months ago
Mark Dowd&#x27;s 2023 presentation &quot;Inside The Zero Day Market&quot; [0] is extremely informative and a must read for everyone interested in a low-level exploitation career.<p>[0] <a href="https:&#x2F;&#x2F;github.com&#x2F;mdowd79&#x2F;presentations&#x2F;blob&#x2F;main&#x2F;bluehat2023-mdowd-final.pdf">https:&#x2F;&#x2F;github.com&#x2F;mdowd79&#x2F;presentations&#x2F;blob&#x2F;main&#x2F;bluehat20...</a>
评论 #41168759 未加载
rapjr910 months ago
He left out education. Become a computer scientist and do research in exploits and you&#x27;re getting paid to create exploits. There are lots of profs doing it, I&#x27;ve known some of them, they call it research. Companies don&#x27;t usually pay for general research in exploits, but universities do.
atemerev10 months ago
You can sell low-level exploits quite profitably. You don’t need to make it, like, an official employment. If you can find gold, why be employed in a gold-mining company for a salary if you can just sell your findings?
评论 #41165852 未加载