Security systems can have vulnerabilities that can be exploited, emphasizing the need for robust testing.
Adult websites need to prioritize security to protect user privacy and financial information.
Deep dives
Unveiling Parking Garage Secrets
The speaker recounts their experience working the overnight shift at a company with assigned parking spots for management. They discovered that the parking garage had a sensor that would lift the gate for cars trying to exit. Using this knowledge, they found a way to trick the sensor and gain access to the garage without a special badge. They used a skateboard, a shoe, and a car to successfully navigate the gate. This experience led them to reflect on the vulnerabilities of security systems and the motivation to explore and learn new things.
From Fake IDs to Ethical Hacking
The speaker shares their journey from purchasing a fake ID to exploring the Shadow Crew forum, an early darknet site. Intrigued by the process, they learned to create high-quality fake IDs for themselves and friends. However, the site soon shut down, causing them to panic and dispose of all evidence. This close call prompted a change of path. They pursued a career in computer security, eventually becoming a skilled penetration tester for major companies. They discuss the importance of compliance testing, the thrill of hacking, and the ethical responsibilities of their profession.
Discovering Vulnerabilities in a Banking App
The speaker shares their experience conducting a penetration test on a large bank's mobile banking app. They outline their reconnaissance methods, which entailed identifying all publicly accessible web servers and domains associated with the bank. During the test, they discovered several critical security flaws, including weak password policies, hardcoded credentials, and an open AWS storage bucket containing millions of checks images. They were able to reset passwords, gain administrative access, and view customer data. The speaker emphasizes the importance of addressing these vulnerabilities to protect user privacy and financial information.
Testing Security of an Adult Website
The speaker recounts a unique penetration testing engagement involving an adult website. They were tasked with compromising specific user accounts, uncovering security flaws, and protecting sensitive content. Through weak password policies, password reset vulnerabilities, and SQL injection, they successfully gained unauthorized access to user accounts and discovered an open AWS storage bucket containing credit card and transaction data. The speaker highlights the criticality of securing adult websites to safeguard both user privacy and financial information.
Join us as we sit down with Jason Haddix (https://twitter.com/Jhaddix), a renowned penetration tester who has made a name for himself by uncovering vulnerabilities in some of the world’s biggest companies. In this episode, Jason shares his funny and enlightening stories about breaking into buildings and computers, and talks about the time he discovered a major security flaw in a popular mobile banking app.
Sponsors
Support for this show comes from Linode. Linode supplies you with virtual servers. Visit linode.com/darknet and get a special offer.
Support for this show comes from Arctic Wolf. Arctic Wolf is the industry leader in security operations solutions, delivering 24x7 monitoring, assessment, and response through our patented Concierge Security model. They work with your existing tools and become an extension of your existing IT team. Visit arcticwolf.com/darknet to learn more.
Get the Snipd podcast app
Unlock the knowledge in podcasts with the podcast player of the future.
AI-powered podcast player
Listen to all your favourite podcasts with AI-powered features
Discover highlights
Listen to the best highlights from the podcasts you love and dive into the full episode
Save any moment
Hear something you like? Tap your headphones to save it with AI-generated key takeaways
Share & Export
Send highlights to Twitter, WhatsApp or export them to Notion, Readwise & more
AI-powered podcast player
Listen to all your favourite podcasts with AI-powered features
Discover highlights
Listen to the best highlights from the podcasts you love and dive into the full episode