David Bombal

David Bombal
undefined
Apr 25, 2022 • 1h 13min

#373: OSINT: You can't hide // Your privacy is dead // Best resources to get started

You cannot hide. Your privacy is over. Want to learn OSINT? Want to learn how easy it is to find information online? Time to learn Open Source Intelligence from the best. I think I'll move to a cave :( OSINT Curious is a registered, non-profit 501(c)(3) organization with the United States IRS (EIN: 84-2781099); and accepts Patreon donations from individuals and sponsors. If you are a sponsor, please contact them if you want to work with them: https://osintcurio.us/funding/ // The OSINT Curious Project // YouTube: https://www.youtube.com/c/TheOSINTCur... Twitter: https://twitter.com/osintcurious LinkedIn: https://www.linkedin.com/company/the-... Website: https://osintcurio.us Public, OSINT-focused Discord: https://iam.osintcurio.us/discord Sponsor personally or through your company: https://osintcurio.us/funding/ // Websites mentioned // OSINT games: https://www.osint.games/ OSINT Framework: osintframework.de OSINT Training: myosint.training Fitness app Strava lights up staff at military bases: https://www.bbc.co.uk/news/technology... https://www.theguardian.com/world/201... // David's SOCIAL // Discord: https://discord.com/invite/usKSyzb Twitter: https://www.twitter.com/davidbombal Instagram: https://www.instagram.com/davidbombal LinkedIn: https://www.linkedin.com/in/davidbombal Facebook: https://www.facebook.com/davidbombal.co TikTok: http://tiktok.com/@davidbombal YouTube: https://www.youtube.com/davidbombal // Lisette SOCIAL // Twitter: https://twitter.com/technisette Personal website: https://technisette.com // Steven Harris SOCIAL // Twitter: https://twitter.com/nixintel LinkedIn: https://www.linkedin.com/in/steven-ha... Personal website: https://nixintel.info/ SANS SEC487 OSINT Courses Steven teaches - https://www.sans.org/profiles/steven-... // Micah Hoffman SOCIAL // Twitter: https://twitter.com/webbreacher LinkedIn: https://www.linkedin.com/in/micahhoff... Personal website: https://webbreacher.com Micah's OSINT Training Courses: https://myosint.training Micah's OSINT CTF Platform: https://osint.games // BOOKS MENTIONED // 1. Hack The World With OSINT – Chris Kubeka: https://amzn.to/3xM61I1 2. Open Source Intelligence Techniques (Ninth Ed) - Michal Bazzel: https://amzn.to/3Lb7MSX // MY STUFF // https://www.amazon.com/shop/davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com osint osint curious google dorks dorks google osintgram osint framework osint tools osint tv osint ukraine osint tutorial osint course osint instagram osint framework tutorial cyber security information security open-source intelligence open source intelligence sans institute cybersecurity training cyber security training information security training what is osint open source artificial intelligence cyber hack privacy nsa oscp ceh Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel! #osint #cyber #privacy
undefined
Apr 25, 2022 • 18min

#372: Hacking networks with Python // Creating malicious packets and breaking TCP/IP rules

Learn the basics of how to use Python and Scapy to create malicious or dodgy packets and send those into networks. Who knows what's going to happen when packets are created like these. Also learn that what they teach you about the TCP/IP model in the CCNA course isn't necessarily true in the real world. You need to learn to code! Learn Python. Learn Networking. You are going to be very powerful and very scary if you combine knowledge of networking with Python scripting! But, do good. Learn to code. Learn Linux. Learn Networking. // Menu // 00:00 - Coming up 00:28 - Introduction 01:00 - How to generate dodgy packets with Scapy 01:14 - TCP/IP model 01:25 - Protocol data units 01:46 - OSI model video 02:12 - Importing Scapy into Python 04:25 - Spoof mac address 06:18 - Sending traffic into the network 08:52 - Sending weird packets 11:43 - "Advanced stuff" 15:11 - In the real world 17:17 - Conclusion The OSI Model is a lie: https://youtu.be/apr63p7K_3A Scapy documentation: https://scapy.net/ Playlist: https://davidbombal.wiki/scapy // SCAPY RESOURCES // Website: https://scapy.net/ Documentation: https://scapy.readthedocs.io/en/latest/ // SCAPY INSTALLATION // sudo apt update sudo apt install python3-pip sudo pip3 install scapy // SOCIAL // Discord: https://discord.com/invite/usKSyzb Twitter: https://www.twitter.com/davidbombal Instagram: https://www.instagram.com/davidbombal LinkedIn: https://www.linkedin.com/in/davidbombal Facebook: https://www.facebook.com/davidbombal.co TikTok: http://tiktok.com/@davidbombal YouTube: https://www.youtube.com/davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com python scapy kali linux kali kali linux python osi model tcp tcp ip tcp/ip tcp ip model python scapy ccna ccnp ccie cisco routers ccna 200-301 python scripts linux kali kali linux 2022 kali linux 2021 oscp ceh security+ pentest+ Disclaimer: This video is for educational purposes only. I own all equipment used for this demonstration. No actual attack took place on any websites. Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel! #python #hacking #cyber
undefined
Apr 19, 2022 • 1h 6min

#371: Hacking Power Plants and Industrial Control Systems (Scada) // Ukraine Russia Cyberwar

This is my second interview with the professional hacker Occupy The Web. In this video we discuss OSINT and hacking industrial control systems (ICS) using SCADA (supervisory control and data acquisition). Jump to 33:40 for scada discussions. Disclaimer: The opinions expressed by Occupy The Web in this interview are his own. // Previous video // OTW video 1: https://youtu.be/GudY7XYouRk // David's SOCIAL // Discord: https://discord.com/invite/usKSyzb Twitter: https://www.twitter.com/davidbombal Instagram: https://www.instagram.com/davidbombal LinkedIn: https://www.linkedin.com/in/davidbombal Facebook: https://www.facebook.com/davidbombal.co TikTok: http://tiktok.com/@davidbombal YouTube: https://www.youtube.com/davidbombal // Occupy The Web social // Twitter: https://twitter.com/three_cube // Occupy The Web books // Linux Basics for Hackers: https://amzn.to/3JlAQXe Getting Started Becoming a Master Hacker: https://amzn.to/3qCQbvh // Occupy The Web Website / Hackers Arise Website // Website: https://www.hackers-arise.com/ Using OSINT to find Yachts: https://davidbombal.wiki/osintyachts Can the CIA or other Intelligence Agencies Track My Every Move: https://davidbombal.wiki/ciaphonestra... SCADA Hacking: The Key Differences between Security of SCADA and Traditional IT systems https://davidbombal.wiki/scada1 SCADA Hacking: Finding SCADA Systems using Shodan https://davidbombal.wiki/scada2 Shodan: Using Shodan to Find Vulnerable Russian SCADA/ICS Sites https://davidbombal.wiki/shodan SCADA Hacking: The Most Important SCADA/ICS Attacks in History https://www.hackers-arise.com/post/sc... SCADA Hacking: SCADA/ICS Protocols (Profinet/Profibus) https://www.hackers-arise.com/post/20... Lots of Scada content: https://www.hackers-arise.com/scada-h... // In the News // Feds Uncover a ‘Swiss Army Knife’ for Hacking Industrial Control Systems: https://www.wired.com/story/pipedream... Ukrainian power grid 'lucky' to withstand Russian cyber-attack: https://www.bbc.co.uk/news/technology... An Unprecedented Look at Stuxnet, the World's First Digital Weapon https://www.wired.com/2014/11/countdo... // Other books // The Linux Command Line: https://amzn.to/3ihGP3j How Linux Works: https://amzn.to/3qeCHoY // MY STUFF // https://www.amazon.com/shop/davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel!
undefined
Apr 19, 2022 • 27min

#370: I do read your comments. Interview: Another POV Russia Ukraine

I interview a Russian about the effects of the anonymous hacks on Russian life. This interview is a response to the Occupy The Web interview posted on my channel. What do you think? Disclaimer: The opinions expressed by Timur in this interview are his own. // MENU // 00:00 ▶️ Coming up 00:40 ▶️ Introduction 02:38 ▶️ What's actually happening in Russia? 05:16 ▶️ Websites that are taken down 06:58 ▶️ Doing more harm than good? 08:30 ▶️ Blocked media platforms 12:01 ▶️ The struggles 16:02 ▶️ Hackerone 18:58 ▶️ IT hysteria 21:23 ▶️ One of the lucky ones 22:20 ▶️ Message to the world 24:12 ▶️ Important message 26:18 ▶️ Conclusion Occupy the Web interview: https://youtu.be/GudY7XYouRk Hacker X arrested in Mexico: https://youtu.be/bHBBtsG8qak // David's SOCIAL // Discord: https://discord.com/invite/usKSyzb Twitter: https://www.twitter.com/davidbombal Instagram: https://www.instagram.com/davidbombal LinkedIn: https://www.linkedin.com/in/davidbombal Facebook: https://www.facebook.com/davidbombal.co TikTok: http://tiktok.com/@davidbombal YouTube: https://www.youtube.com/davidbombal // Timur social // Hackerone: http://hackerone.com/irisrumtub Twitter: https://twitter.com/irisrumtub // Occupy The Web books // Linux Basics for Hackers: https://amzn.to/3JlAQXe Getting Started Becoming a Master Hacker: https://amzn.to/3qCQbvh // MY STUFF // https://www.amazon.com/shop/davidbombal Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel! ukraine russa occupytheweb occupy the web hackers arise hackersarise proxy proxy chains ddos ukraine war cybersecurity ukraine cyber attack russia ukraine news russia vs ukraine cyberwar russian invasion russia ukraine crisis ukraine crisis cyber security cyberwarfare putin cyber attack cyber war russia cyberwar russia cyber attack cyberwar against russia cyber security news ukraine war ukraine cyber attack today russians cybernews ukraine 2022 ukraine news russia ukraine conflict anonymous #ukraine #russia #cyberwar
undefined
Apr 19, 2022 • 1h 19min

#369: Computer Science isn't programming! // How to become a Master Programmer // Featuring Dr Chuck

Is computer science the path to become a master programmer? Dr Chuck says there is a better way - and you can get it for free! He also shares his vision on how to become a master programmer - this also includes mentorship. FREE course links below :) // MENU // 00:00 ▶️ Introduction 01:30 ▶️ Cisco Certs as the Standard and Why Programming Doesn't Have an Equivalent 04:33 ▶️ Computer Science As the Way to Get Into Programming 09:37 ▶️ Computer Science Doesn't Make You a Master Programmer 11:25 ▶️ Why The System is Broken 14:20 ▶️ The Role of Universities in the Future of Education 22:08 ▶️ The First Half of the Path to Master Programmer 24:00 ▶️ The Second Half of the Path to Master Programmer 26:26 ▶️ What Is a Master Programmer? 31:36 ▶️ David and Dr Chuck's Experiences with Programming Courses at University 36:32 ▶️ Brief Overview of the Origin of Computer Science and What Went Wrong 44:02 ▶️ When Dr Chuck Teaches Recursion 44:56 ▶️ But Doesn't the System Actually Work? Just look at Google and Facebook 45:38 ▶️ The Idea for Google Wasn't Good Enough for a PhD 48:47 ▶️ How to Fix the System 50:43 ▶️ The Last Nut to Crack 54:22 ▶️ Open Source's Role 56:44 ▶️ You Can't Apply Until You Have Run the Gauntlet 1:00:34 ▶️ You Can Start Now 1:01:08 ▶️ The Value of Mentors 1:04:15 ▶️ The Problem with Online Platforms 1:05:37 ▶️ Why Cisco is the Standard in Networking 1:08:15 ▶️ Every Course Dr Chuck Teaches Requires Him to Write Code 1:09:29 ▶️ Quick Summary for the Plan for the Master Programmer 1:11:53 ▶️ What's the Cost Going to Be? 1:15:09 ▶️ Education Is For Everybody, Not Just the Rich 1:16:36 ▶️ Final Thoughts 1:18:33 ▶️ Thanks, Dr Chuck! // MY STUFF // https://www.amazon.com/shop/davidbombal // SOCIAL // Discord: https://discord.com/invite/usKSyzb Twitter: https://www.twitter.com/davidbombal Instagram: https://www.instagram.com/davidbombal LinkedIn: https://www.linkedin.com/in/davidbombal Facebook: https://www.facebook.com/davidbombal.co TikTok: http://tiktok.com/@davidbombal YouTube: https://www.youtube.com/davidbombal // Dr Chuck social // Website: https://www.dr-chuck.com/ Twitter: https://twitter.com/drchuck/ YouTube: https://www.youtube.com/user/csev Coursera: https://www.coursera.org/instructor/d... // Python for Everybody // Free Python course on Coursera: https://www.coursera.org/specializati... YouTube: https://youtu.be/8DvywoWv6fI Python for Everybody: https://www.py4e.com/ Free Python Book: http://do1.dr-chuck.com/pythonlearn/E... Dr Chuck's Website: https://www.dr-chuck.com/ Free Python Book options: https://www.py4e.com/book // Django for Everybody // Website: https://www.dj4e.com/ Coursera: https://www.coursera.org/specializati... YouTube: https://youtu.be/o0XbHvKxw7Y // Web Applications for Everybody // YouTube: https://youtu.be/xr6uZDRTna0 Website: https://www.wa4e.com/ Coursera: https://www.coursera.org/specializati... // Internet History // Coursera: https://www.coursera.org/learn/intern... YouTube: https://youtu.be/47NRaBVxgVM // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com python python course python for beginners master programmer dr chuck dr chuck master programmer python mentorship google code interview google interview computer science python best course dr chuck python dr chuck python course learn to code software development software developer computer science software engineer software engineering how to learn programming free python course free python course online free python class free python tutorial free python training how to learn to code coding tutorials how to code learning to code learn to code for free learn to code python python jobs coding bootcamp google code interview python for beginners python full course python tutorial python projects python basic tutorial python programming python interview questions python course python basics open source #python #programming #drchuck
undefined
Apr 10, 2022 • 1h 7min

#368: Hacking Linux // Linux Privilege escalation // Featuring HackerSploit

So you think Linux is secure? In this video we'll escalate our privileges on Linux to become root. // MENU // 0:00:00 ▶️ Introduction 0:01:15 ▶️ Jump to the demo 0:01:38 ▶️ About Alexis, background and experience 0:07:38 ▶️ Starting HackerSploit 0:08:47 ▶️ Alexis and Linux 0:11:03 ▶️ Which is the preferred Linux distribution? 0:12:01 ▶️ Recommended Linux distribution for beginners 0:12:33 ▶️ LinuxJourney.com 0:12:01 ▶️ Favourite hacking distribution 0:13:51 ▶️ The PenTester Framework 0:15:21 ▶️ Best method to install a distribution 0:16:46 ▶️ Recommendations 0:18:29 ▶️ Recommended distribution for real-world pentesting 0:21:44 ▶️ Starting YouTube channel 0:22:18 ▶️ Windows vs MacOS vs Linux 0:23:30 ▶️ Recommended laptop 0:27:16 ▶️ Other advice 0:28:38 ▶️ Recommended certifications 0:30:46 ▶️ Recommended pre-requisite skills 0:33:13 ▶️ HackerSploit Linux Essential for Hackers 0:34:01 ▶️ HackerSploit Windows 0:34:26 ▶️ HackerSploit Networking Fundamentals 0:35:11 ▶️ Get your fundamentals right 0:35:29 ▶️ Dirty Pipe exploit presentation 0:43:52 ▶️ Dirty Pipe exploit demo 0:55:14 ▶️ Exploit 1 0:57:03 ▶️ Exploit 2 1:00:23 ▶️ Learning how to change scripts 1:02:14 ▶️ Recommended script language 1:04:00 ▶️ Thoughts on Golang 1:04:44 ▶️ Recommendations for learning languages 1:05:41 ▶️ Closing thoughts // HackerSploit Linux exploit scripts // Dirty Pipe Github page: https://github.com/AlexisAhmed/CVE-20... Dirty Pipe Blog: https://dirtypipe.cm4all.com/ CVE details: https://cve.mitre.org/cgi-bin/cvename... // Hackersploit Videos // Pentesters Framework: https://www.youtube.com/watch?v=Bx3RL... Linux for hackers: https://www.youtube.com/watch?v=T0Db6... Windows for hackers: Nmap series: https://www.youtube.com/watch?v=5MTZd... Linux exploitation: https://www.youtube.com/watch?v=i-dQw... Windows exploitation: https://www.youtube.com/watch?v=Bzmlj... // Books // Privilege Escalation Techniques: https://amzn.to/3xcPHjf Automate the boring the stuff with Python: https://amzn.to/3LQA5Gl // MY STUFF // https://www.amazon.com/shop/davidbombal // SOCIAL // Discord: https://discord.com/invite/usKSyzb Twitter: https://www.twitter.com/davidbombal Instagram: https://www.instagram.com/davidbombal LinkedIn: https://www.linkedin.com/in/davidbombal Facebook: https://www.facebook.com/davidbombal.co TikTok: http://tiktok.com/@davidbombal YouTube: https://www.youtube.com/davidbombal // HackerSploit // LinkedIn: https://www.linkedin.com/in/alexisahmed/ YouTube: https://www.youtube.com/c/HackerSploit Twitter: https://twitter.com/HackerSploit Academy: https://hackersploit.academy/ // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com linux kali linux kali linux hack linux hacking hacker linux exploit linux privilege escalation linux hack linux dirty pipe linux dirty pipe explained linux dirty pipe cve linux dirty pipe exploit linux privilege escalation ethical hacking linux priv esc priv escalation linux hackersploit hacking linux exploit linux dirty pipe dirty pipe linux dirty pipe cve linux vulnerability linux security linux exploits linux kernel linux kernel vulnerablity dirty pipe vulnerability #linux #linuxhack #hacking
undefined
Apr 4, 2022 • 1h 3min

#367: Troubleshooting slow networks with Wireshark // wireshark filters // Wireshark performance

You are guilty until proven innocent! The network is slow! But is it actually a network issue? Or is it an application issue. Chris Greer explains. // MENU // 00:00 ▶️ Introduction 00:35 ▶️ Wireshark filters introduction 02:20 ▶️ Regular IP filter 05:28 ▶️ Common filters 07:10 ▶️ Operators in filters 08:19 ▶️ Where to get the filter Power Point 08:55 ▶️ Filter shortcuts 11:20 ▶️ Filter buttons 12:10 ▶️ TCP analysis flags 15:16 ▶️ Filter buttons (cont'd) 17:15 ▶️ TCP reset 18:35 ▶️ How to apply filter as display filter 20:08 ▶️ Experience vs Theory 22:19 ▶️ Special filters 29:00 ▶️ Time filters 38:22 ▶️ Consulting scenario 49:45 ▶️ HTTPS consulting scenario 55:33 ▶️ Other filters 56:46 ▶️ How to simplify p-caps 59:29 ▶️ Signature filters 01:01:39 ▶️ Quick recap 01:02:16 ▶️ Conclusion // MY STUFF // https://www.amazon.com/shop/davidbombal // SOCIAL // Discord: https://discord.com/invite/usKSyzb Twitter: https://www.twitter.com/davidbombal Instagram: https://www.instagram.com/davidbombal LinkedIn: https://www.linkedin.com/in/davidbombal Facebook: https://www.facebook.com/davidbombal.co TikTok: http://tiktok.com/@davidbombal YouTube: https://www.youtube.com/davidbombal //CHRIS GREER // LinkedIn: https://www.linkedin.com/in/cgreer/ YouTube: https://www.youtube.com/c/ChrisGreer Twitter: https://twitter.com/packetpioneer Pluralsight: TCP Analysis Course: https://davidbombal.wiki/tcpwireshark // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com wireshark packet analysis wireshark installation wireshark filters wireshark how to find ip address wireshark http wireshark ip address wireshark wifi sniffing wireshark tutorial tcp analysis packet analysis free wireshark tutorial tcp handshake wireshark training chris greer, roubleshooting with wireshark troubleshooting slow networks network troubleshooting packet capture tcp reset tcp connections network protocols packet capture using wireshark Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel! #wireshark #wiresharkfilters #networktroubleshooting
undefined
Apr 4, 2022 • 57min

#366: Hacking PayPal and TikTok (legally) // Featuring Ben Sadeghipour Nahamsec

Want to hack companies like PayPal and TikTok? What about the Department of Defense? Lots of companies that you can hack legally - and get paid doing it! This is a practical guide on how to get started hacking today. // MENU // 00:00 ▶️ Introduction 00:17 ▶️ Who is Nahamsec? 01:18 ▶️ Different Bug Bounty Platforms 01:40 ▶️ Why Nahamsec Prefers These Platforms 02:34 ▶️ Intigriti Quick Overview 02:58 ▶️ Bugcrowd Quick Overview 03:25 ▶️ Hackerone Quick Overview 04:01 ▶️ What is Bug Bounty? 04:57 ▶️ Non-Monetary Rewards: Nahamsec's Red Bull Hack 05:57 ▶️ The Lyft, Snapchat and Undisclosed Travel Company Hack 07:02 ▶️ Interface Walkthrough 08:45 ▶️ Scope 10:18 ▶️ Top Hacker Profiles on Bug Bounty Programmes 11:04 ▶️ Profile Hacktivity Feed 13:54 ▶️ Using the site wide hacktivity feed to learn from previous bug bounties 15:31 ▶️ Getting Started: hacker101 17:24 ▶️ Getting Started: hackerone 20:58 ▶️ Submitting/Writing a Report 29:23 ▶️ Report Terminology 31:06 ▶️ How to Find a Company's Websites 33:05 ▶️ Nahamsec's Approach: Certificate Transparency 36:30 ▶️ Why NahamSec Prefers Dev Sites 38:05 ▶️ How to Find a Website's SSL Certificate 41:21 ▶️ Targeting a Company' Main Website vs Targeting Subdomains 42:25 ▶️ Researching a Company's Assets 43:43 ▶️ If You're New to the Bug Bounty Thing 47:40 ▶️ Ways to Learn 49:18 ▶️ Books to Help You Get Started Hacking 53:49 ▶️ Online Resources to Help You Get Started 55:28 ▶️ Final Advice // Connect with David // Discord: https://discord.com/invite/usKSyzb Twitter: https://www.twitter.com/davidbombal Instagram: https://www.instagram.com/davidbombal LinkedIn: https://www.linkedin.com/in/davidbombal Facebook: https://www.facebook.com/davidbombal.co TikTok: http://tiktok.com/@davidbombal YouTube: https://www.youtube.com/davidbombal // Connect with Nahamsec // Twitter: https://twitter.com/nahamsec YouTube: https://www.youtube.com/c/nahamsec Github: https://github.com/nahamsec/Resources-for-Beginner-Bug-Bounty-Hunters Discord: https://discord.com/invite/ysndAm8 Instagram: https://www.instagram.com/nahamsec/ LinkedIn: https://www.linkedin.com/in/nahamsec/ Twitch: https://www.twitch.tv/nahamsec Website: https://nahamsec.com/ // Nahamsec's Udemy Course// Udemy: https://www.udemy.com/course/intro-to-bug-bounty-by-nahamsec/ // Sites // Hackerone: https://www.hackerone.com/ Bugcrowd: https://bugcrowd.com/programs Intigriti: https://www.intigriti.com/ // Book's recommended // Bug Bounty Bootcamp: https://amzn.to/3K2YDeJ Real-World Bug Hunting: https://amzn.to/3wTF9FN Android Hacker's Handbook: https://amzn.to/3uMc509 The Web Application Hacker's Handbook: https://amzn.to/3IZ2RTr Black Hat Python: https://amzn.to/3JYIZAV Black Hat Python (2nd edition): https://amzn.to/379WcIV // Creator's mentioned // Nahamsec: https://www.youtube.com/c/Nahamsec STÖK: https://www.youtube.com/c/STOKfredrik LiveOverflow: https://www.youtube.com/c/LiveOverflow Farah Hawa: https://www.youtube.com/c/FarahHawa InsiderPhD: https://www.youtube.com/c/InsiderPhD The Cyber Mentor: https://www.youtube.com/c/TheCyberMentor // MY STUFF // Monitor: https://amzn.to/3yyF74Y More stuff: https://www.amazon.com/shop/davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com bug bounty bugbounty hackerone hacking Ben Sadeghipour NahamSec nahamsec cyber security bug bounties ethical hacking bug bounty hunting burp suite ethical hacker pentest certificate red teaming bug bounty tips bug bounty for beginners bug bounty course pentest basics bugcrowd bugbounty hack bugs hackerone bugcrowd Intigriti Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel! #buybounty #hacking #hack
undefined
Mar 31, 2022 • 57min

#365: Real World Talks: pfsense firewalls for home and business? // Featuring Tom Lawrence

Real World Talks: pfsense firewalls for home and business? // Featuring Tom Lawrence Are pfsense firewalls any good for home or business? Which businesses are supported by pfsense? What are the advantages and disadvantages of using pfsense? How big can they go? Lots of questions! Fortunately Tom answers these and many more in this video. // MENU // 00:00 ▶️ Introduction 01:29 ▶️ What pfSense is and Tom's experience with pfSense 03:43 ▶️ Tom and Open Source 04:38 ▶️ The benefit of pfSense being Open Source 05:21 ▶️ Systems Tom has deployed with pfSense 07:22 ▶️ pfSense licensing cost 09:09 ▶️ Using pfSense at home 11:45 ▶️ Virtualization 12:28 ▶️ Raspberry Pi support 13:02 ▶️ Virtualization vs hardware 14:37 ▶️ Tom's recommendation for small/medium businesses 19:43 ▶️ pfSense actual cost (pfSense vs pfSense+) 22:22 ▶️ Reasons not to use pfSense 24:45 ▶️ Tom's biggest pfSense deployment 26:07 ▶️ pfSense above 10G 27:11 ▶️ pfSense and VPN 28:32 ▶️ Handling lots of VPN connections 29:29 ▶️ Advice for starting a consulting business 31:09 ▶️ Technical skills vs sales skills 32:22 ▶️ The benefit of having sales skills 35:58 ▶️ It's about the customer, not the product you use 38:02 ▶️ How Tom got his first customers 40:21 ▶️ Why Tom has a YouTube channel 43:46 ▶️ This video is not sponsored by a VPN company 43:53 ▶️ Skills to learn in 2022 to get started 48:13 ▶️ Story 1 - Hacked client 49:10 ▶️ Story 2 - That will never happen in the real world 51:28 ▶️ Story 3- We've all done it 52:40 ▶️ Final advice 54:15 ▶️ Networking with people // David's SOCIAL // Discord: https://discord.com/invite/usKSyzb Twitter: https://www.twitter.com/davidbombal Instagram: https://www.instagram.com/davidbombal LinkedIn: https://www.linkedin.com/in/davidbombal Facebook: https://www.facebook.com/davidbombal.co TikTok: http://tiktok.com/@davidbombal YouTube: https://www.youtube.com/davidbombal // Tom's SOCIAL // Twitter: https://twitter.com/TomLawrenceTech YouTube: https://www.youtube.com/user/TheTeckn... Website: https://lawrencesystems.com/ LinkedIn: https://www.linkedin.com/in/lawrences... Instagram: https://www.instagram.com/lawrencesys... // MY STUFF // https://www.amazon.com/shop/davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com pfsense pfsense router home router home networking open source router raspberry pi pi pfsense pi pfsense raspberry pi opensource linux router pfsense tutorial pfsense setup pfsense basics pfsense course Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel! #pfsense #linux #firewall
undefined
Mar 31, 2022 • 1h 6min

#364: TLS Handshake Deep Dive and decryption with Wireshark // SSL Key Exchange Explained

Hacking the TLS Handshake and decryption with Wireshark // SSL Deep Dive 50,157 views Mar 25, 2022 Warning! We go deep in this video to explain how the TLS handshake is completed. Warning! This is a technical deep dive and covers a lot of detail including SSL decryption and discusses RSA, Public and Private Keys, symmetric key exchange and lots more. // Wireshark pcap // https://davidbombal.wiki/tlsedpcap // Ed's TLS course // https://davidbombal.wiki/edtls49 Use coupon code: "BombalTLS" to get for $49 // MENU // 00:00 ▶️ Introduction 02:11 ▶️ How SSL/TLS is shown in a browser 02:40 ▶️ Pre-Requisites 05:15 ▶️ Data Integrity/Hashing 06:27 ▶️ Potential Problems with Hashing/man in-the-middle attack 07:32 ▶️ Message Authentication Code 10:09 ▶️ Prerequisites continued 11:51 ▶️ Symmetric Encryption 12:45 ▶️ Asymmetric Encryption 17:00 ▶️ Private and Public Keys 20:05 ▶️ Signatures 21:55 ▶️ Protocols 22:50 ▶️ SSL/TLS Handshake, Client Hello and Server Hello 28:35 ▶️ Client Hello and Server Hello in Wireshark 34:09 ▶️ Certificate 35:12 ▶️ Server Done 35:35 ▶️ Server Hello, Certificate, Server Hello Done in Wireshark 36:51 ▶️ Client Key Exchange 50:26 ▶️ Client Key Exchange in Wireshark 51:39 ▶️ Client Change Cipher Spec and Finished/Encrypted Verification 54:08 ▶️ Server Change Cipher Spec and Finished/Encrypted 56:10 ▶️ SSL/TLS Handshake in Wireshark 57:44 ▶️ Decrypting a PreMaster Key with a Private Key in Wireshark 1:03:15 ▶️ Where to get in contact with Ed to learn more // David's SOCIAL // Discord: https://discord.com/invite/usKSyzb Twitter: https://www.twitter.com/davidbombal Instagram: https://www.instagram.com/davidbombal LinkedIn: https://www.linkedin.com/in/davidbombal Facebook: https://www.facebook.com/davidbombal.co TikTok: http://tiktok.com/@davidbombal YouTube: https://www.youtube.com/davidbombal // Ed's SOCIAL // Twitter: https://twitter.com/ed_pracnet YouTube: https://www.youtube.com/channel/UCKmU... // Ed's TLS course // https://davidbombal.wiki/edtls49 Use coupon code: "BombalTLS" to get for $49 // More detail on Ed's YouTube channel and website // Asymmetric Encryption explained from a Practical Perspective: https://www.practicalnetworking.net/p... RSA Algorithm: https://www.youtube.com/watch?v=Pq8gN... DH Algorithm: https://www.youtube.com/watch?v=KXq06... Practical TLS - Crypto & SSL/TLS foundation: https://www.youtube.com/playlist?list... // MY STUFF // https://www.amazon.com/shop/davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com tls tls decryption ssl crypto cryptography ssl decryption tls wireshark tls decryption wireshark tls tunnel tls handshake tlsp tls explained tls tunnel vpn tls protocol tls handshake explained tls 1.3 TLS Transport Layer Security Handshake TLS Handshake Crypto Cryptography security wireshark wireshark tutorial wireshark packet analysis tls decryption tls decryption wireshark tls 1.3 decryption tls decryption wireshark tls tunnel vpn free internet tls decryption palo alto Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel! #tls #ssl #wireshark

The AI-powered Podcast Player

Save insights by tapping your headphones, chat with episodes, discover the best highlights - and more!
App store bannerPlay store banner
Get the app