Hey all!
Reaching out with a few questions, and a warning about me: I’m very new to this field. In my 40s, quietly getting a bachelor’s in cybersecurity and information assurance in preparation for a hard career change.
Anything I ask is pure ignorance, with the idea that a) I’m willing to eat some shit right now and, b) any helpful information is appreciated.
To be clear, I’m interested in ethical hacking and educating myself through accessing or manipulating my own various devices to understand what can be done and how.
Realizing how green I am, I trust no on and nothing. Online or in person. Or via mail.
That said, I have to start somewhere, and this community seems like a (relatively) safe place. My goal is to not only be able to do, but understand things. I’m not even clear on what my career goals are yet, in part because I don’t understand my options and places where I might excel. That said, some sort of pen testing seems to make sense, based on my background.
I bought a new Alienware laptop for school and beyond, based on a few suggestions. Happy to share the machine’s details if helpful. I’m also a longtime Mac user, so overcoming that. (I only do schoolwork on the PC.) It’s both fun and helpful of school to play around on the side.
With that all in mind, here is my question: I just purchased the following off of eBay and I’m not clear about what to do and/or not to do to keep this as a clean and secure, from set-up to use.
- New LG Nexus 5X - H790 - 32GB - (Unlocked) 4G LTE GSM Android Smartphone
- 3 Months Service, Mint Mobile Prepaid SIM Card with Unlimited DATA, Talk, Text
- Silicon Power 1TB Superior Micro SDXC UHS-I (U3), V30 4K A2

My first thought since I am buying them secondhand from eBay is to not assume they are clean and wipe them. Is that close? What else? I’m also curious if/how I might use the VPN I already use might further help with security.
Other tools I’m curious in learning more about: FlipperZero, Chameleon Ultra, Rubber Ducky, ESP32 kit, Hacker RF1, Alfa adapter, Stingbox
Open to any thoughts, experience, or suggestions around those.
Happy to answer any questions, and I’m grateful in advance for any help!

  • XmentalX@alien.topB
    link
    fedilink
    English
    arrow-up
    1
    ·
    1 year ago

    The sim card cant store more than contacts on it so theres very little in the way of risk there. The SD card format it, the phone wipe it and start fresh.

    You are overthinking this.

    • m3ga_dr00g@alien.topOPB
      link
      fedilink
      English
      arrow-up
      1
      ·
      1 year ago

      Thanks! I realize ALL I do not know and am trying to learn (not just “do”), so I am trying to think through each piece and each move so I understand what and why I’m doing each step.

  • fluor1te@alien.topB
    link
    fedilink
    English
    arrow-up
    1
    ·
    1 year ago

    >sim

    if it even has a sim card I doubt it would be useful, you can just get a new one from your new carrier. every used phone I bought came without a sim card.

    >SD Card

    just write a new partition table to it. or zero it out if you really want with DBAN or something, but this is totally unnecessary. a new partition table will wipe everything on it.

    >phone

    just do a factory reset from recovery mode. if you’re extra paranoid, flash it with the current official ROM for the phone.