

David Bombal
David Bombal
Want to learn about IT? Want to get ahead in your career? Well, this is the right place!
On this channel, I discuss Python, Ethical Hacking, Networking, Network Automation, CCNA, Virtualization and other IT related topics.
This YouTube channel has new videos every week! Subscribe for technical, detailed, no fluff content.
David’s details:
Discord: https://discord.com/invite/usKSyzb
Twitter: https://www.twitter.com/davidbombal
Instagram: https://www.instagram.com/davidbombal
LinkedIn: https://www.linkedin.com/in/davidbombal
Facebook: https://www.facebook.com/davidbombal.co
Website: http://www.davidbombal.com
YouTube: https://www.youtube.com/davidbombal
All the best!
David
On this channel, I discuss Python, Ethical Hacking, Networking, Network Automation, CCNA, Virtualization and other IT related topics.
This YouTube channel has new videos every week! Subscribe for technical, detailed, no fluff content.
David’s details:
Discord: https://discord.com/invite/usKSyzb
Twitter: https://www.twitter.com/davidbombal
Instagram: https://www.instagram.com/davidbombal
LinkedIn: https://www.linkedin.com/in/davidbombal
Facebook: https://www.facebook.com/davidbombal.co
Website: http://www.davidbombal.com
YouTube: https://www.youtube.com/davidbombal
All the best!
David
Episodes
Mentioned books

Apr 25, 2022 • 1h 13min
#373: OSINT: You can't hide // Your privacy is dead // Best resources to get started
You cannot hide. Your privacy is over. Want to learn OSINT? Want to learn how easy it is to find information online? Time to learn Open Source Intelligence from the best.
I think I'll move to a cave :(
OSINT Curious is a registered, non-profit 501(c)(3) organization with the United States IRS (EIN: 84-2781099); and accepts Patreon donations from individuals and sponsors. If you are a sponsor, please contact them if you want to work with them: https://osintcurio.us/funding/
// The OSINT Curious Project //
YouTube: https://www.youtube.com/c/TheOSINTCur...
Twitter: https://twitter.com/osintcurious
LinkedIn: https://www.linkedin.com/company/the-...
Website: https://osintcurio.us
Public, OSINT-focused Discord: https://iam.osintcurio.us/discord
Sponsor personally or through your company: https://osintcurio.us/funding/
// Websites mentioned //
OSINT games: https://www.osint.games/
OSINT Framework: osintframework.de
OSINT Training: myosint.training
Fitness app Strava lights up staff at military bases:
https://www.bbc.co.uk/news/technology...
https://www.theguardian.com/world/201...
// David's SOCIAL //
Discord: https://discord.com/invite/usKSyzb
Twitter: https://www.twitter.com/davidbombal
Instagram: https://www.instagram.com/davidbombal
LinkedIn: https://www.linkedin.com/in/davidbombal
Facebook: https://www.facebook.com/davidbombal.co
TikTok: http://tiktok.com/@davidbombal
YouTube: https://www.youtube.com/davidbombal
// Lisette SOCIAL //
Twitter: https://twitter.com/technisette
Personal website: https://technisette.com
// Steven Harris SOCIAL //
Twitter: https://twitter.com/nixintel
LinkedIn: https://www.linkedin.com/in/steven-ha...
Personal website: https://nixintel.info/
SANS SEC487 OSINT Courses Steven teaches - https://www.sans.org/profiles/steven-...
// Micah Hoffman SOCIAL //
Twitter: https://twitter.com/webbreacher
LinkedIn: https://www.linkedin.com/in/micahhoff...
Personal website: https://webbreacher.com
Micah's OSINT Training Courses: https://myosint.training
Micah's OSINT CTF Platform: https://osint.games
// BOOKS MENTIONED //
1. Hack The World With OSINT – Chris Kubeka: https://amzn.to/3xM61I1
2. Open Source Intelligence Techniques (Ninth Ed) - Michal Bazzel: https://amzn.to/3Lb7MSX
// MY STUFF //
https://www.amazon.com/shop/davidbombal
// SPONSORS //
Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com
osint
osint curious
google dorks
dorks
google
osintgram
osint framework
osint tools
osint tv
osint ukraine
osint tutorial
osint course
osint instagram
osint framework tutorial
cyber security
information security
open-source intelligence
open source intelligence
sans institute
cybersecurity training
cyber security training
information security training
what is osint
open source artificial intelligence
cyber
hack
privacy
nsa
oscp
ceh
Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel!
#osint #cyber #privacy

Apr 25, 2022 • 18min
#372: Hacking networks with Python // Creating malicious packets and breaking TCP/IP rules
Learn the basics of how to use Python and Scapy to create malicious or dodgy packets and send those into networks. Who knows what's going to happen when packets are created like these. Also learn that what they teach you about the TCP/IP model in the CCNA course isn't necessarily true in the real world.
You need to learn to code! Learn Python. Learn Networking. You are going to be very powerful and very scary if you combine knowledge of networking with Python scripting! But, do good.
Learn to code. Learn Linux. Learn Networking.
// Menu //
00:00 - Coming up
00:28 - Introduction
01:00 - How to generate dodgy packets with Scapy
01:14 - TCP/IP model
01:25 - Protocol data units
01:46 - OSI model video
02:12 - Importing Scapy into Python
04:25 - Spoof mac address
06:18 - Sending traffic into the network
08:52 - Sending weird packets
11:43 - "Advanced stuff"
15:11 - In the real world
17:17 - Conclusion
The OSI Model is a lie: https://youtu.be/apr63p7K_3A
Scapy documentation: https://scapy.net/
Playlist: https://davidbombal.wiki/scapy
// SCAPY RESOURCES //
Website: https://scapy.net/
Documentation: https://scapy.readthedocs.io/en/latest/
// SCAPY INSTALLATION //
sudo apt update
sudo apt install python3-pip
sudo pip3 install scapy
// SOCIAL //
Discord: https://discord.com/invite/usKSyzb
Twitter: https://www.twitter.com/davidbombal
Instagram: https://www.instagram.com/davidbombal
LinkedIn: https://www.linkedin.com/in/davidbombal
Facebook: https://www.facebook.com/davidbombal.co
TikTok: http://tiktok.com/@davidbombal
YouTube: https://www.youtube.com/davidbombal
// SPONSORS //
Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com
python
scapy
kali linux
kali
kali linux python
osi model
tcp
tcp ip
tcp/ip
tcp ip model
python scapy
ccna
ccnp
ccie
cisco routers
ccna 200-301
python scripts
linux
kali
kali linux 2022
kali linux 2021
oscp
ceh
security+
pentest+
Disclaimer: This video is for educational purposes only. I own all equipment used for this demonstration. No actual attack took place on any websites.
Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel!
#python #hacking #cyber

Apr 19, 2022 • 1h 6min
#371: Hacking Power Plants and Industrial Control Systems (Scada) // Ukraine Russia Cyberwar
This is my second interview with the professional hacker Occupy The Web. In this video we discuss OSINT and hacking industrial control systems (ICS) using SCADA (supervisory control and data acquisition).
Jump to 33:40 for scada discussions.
Disclaimer: The opinions expressed by Occupy The Web in this interview are his own.
// Previous video //
OTW video 1: https://youtu.be/GudY7XYouRk
// David's SOCIAL //
Discord: https://discord.com/invite/usKSyzb
Twitter: https://www.twitter.com/davidbombal
Instagram: https://www.instagram.com/davidbombal
LinkedIn: https://www.linkedin.com/in/davidbombal
Facebook: https://www.facebook.com/davidbombal.co
TikTok: http://tiktok.com/@davidbombal
YouTube: https://www.youtube.com/davidbombal
// Occupy The Web social //
Twitter: https://twitter.com/three_cube
// Occupy The Web books //
Linux Basics for Hackers: https://amzn.to/3JlAQXe
Getting Started Becoming a Master Hacker: https://amzn.to/3qCQbvh
// Occupy The Web Website / Hackers Arise Website //
Website: https://www.hackers-arise.com/
Using OSINT to find Yachts: https://davidbombal.wiki/osintyachts
Can the CIA or other Intelligence Agencies Track My Every Move: https://davidbombal.wiki/ciaphonestra...
SCADA Hacking: The Key Differences between Security of SCADA and Traditional IT systems
https://davidbombal.wiki/scada1
SCADA Hacking: Finding SCADA Systems using Shodan
https://davidbombal.wiki/scada2
Shodan: Using Shodan to Find Vulnerable Russian SCADA/ICS Sites
https://davidbombal.wiki/shodan
SCADA Hacking: The Most Important SCADA/ICS Attacks in History
https://www.hackers-arise.com/post/sc...
SCADA Hacking: SCADA/ICS Protocols (Profinet/Profibus)
https://www.hackers-arise.com/post/20...
Lots of Scada content:
https://www.hackers-arise.com/scada-h...
// In the News //
Feds Uncover a ‘Swiss Army Knife’ for Hacking Industrial Control Systems: https://www.wired.com/story/pipedream...
Ukrainian power grid 'lucky' to withstand Russian cyber-attack:
https://www.bbc.co.uk/news/technology...
An Unprecedented Look at Stuxnet, the World's First Digital Weapon
https://www.wired.com/2014/11/countdo...
// Other books //
The Linux Command Line: https://amzn.to/3ihGP3j
How Linux Works: https://amzn.to/3qeCHoY
// MY STUFF //
https://www.amazon.com/shop/davidbombal
// SPONSORS //
Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com
Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel!

Apr 19, 2022 • 27min
#370: I do read your comments. Interview: Another POV Russia Ukraine
I interview a Russian about the effects of the anonymous hacks on Russian life. This interview is a response to the Occupy The Web interview posted on my channel. What do you think?
Disclaimer: The opinions expressed by Timur in this interview are his own.
// MENU //
00:00 ▶️ Coming up
00:40 ▶️ Introduction
02:38 ▶️ What's actually happening in Russia?
05:16 ▶️ Websites that are taken down
06:58 ▶️ Doing more harm than good?
08:30 ▶️ Blocked media platforms
12:01 ▶️ The struggles
16:02 ▶️ Hackerone
18:58 ▶️ IT hysteria
21:23 ▶️ One of the lucky ones
22:20 ▶️ Message to the world
24:12 ▶️ Important message
26:18 ▶️ Conclusion
Occupy the Web interview: https://youtu.be/GudY7XYouRk
Hacker X arrested in Mexico: https://youtu.be/bHBBtsG8qak
// David's SOCIAL //
Discord: https://discord.com/invite/usKSyzb
Twitter: https://www.twitter.com/davidbombal
Instagram: https://www.instagram.com/davidbombal
LinkedIn: https://www.linkedin.com/in/davidbombal
Facebook: https://www.facebook.com/davidbombal.co
TikTok: http://tiktok.com/@davidbombal
YouTube: https://www.youtube.com/davidbombal
// Timur social //
Hackerone: http://hackerone.com/irisrumtub
Twitter: https://twitter.com/irisrumtub
// Occupy The Web books //
Linux Basics for Hackers: https://amzn.to/3JlAQXe
Getting Started Becoming a Master Hacker: https://amzn.to/3qCQbvh
// MY STUFF //
https://www.amazon.com/shop/davidbombal
Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel!
ukraine
russa
occupytheweb
occupy the web
hackers arise
hackersarise
proxy
proxy chains
ddos
ukraine war
cybersecurity
ukraine cyber attack
russia ukraine news
russia vs ukraine
cyberwar
russian invasion
russia ukraine crisis
ukraine crisis
cyber security
cyberwarfare
putin
cyber attack
cyber war
russia cyberwar
russia cyber attack
cyberwar against russia
cyber security news
ukraine war
ukraine cyber attack today
russians
cybernews
ukraine 2022
ukraine news
russia ukraine conflict
anonymous
#ukraine #russia #cyberwar

Apr 19, 2022 • 1h 19min
#369: Computer Science isn't programming! // How to become a Master Programmer // Featuring Dr Chuck
Is computer science the path to become a master programmer? Dr Chuck says there is a better way - and you can get it for free! He also shares his vision on how to become a master programmer - this also includes mentorship.
FREE course links below :)
// MENU //
00:00 ▶️ Introduction
01:30 ▶️ Cisco Certs as the Standard and Why Programming Doesn't Have an Equivalent
04:33 ▶️ Computer Science As the Way to Get Into Programming
09:37 ▶️ Computer Science Doesn't Make You a Master Programmer
11:25 ▶️ Why The System is Broken
14:20 ▶️ The Role of Universities in the Future of Education
22:08 ▶️ The First Half of the Path to Master Programmer
24:00 ▶️ The Second Half of the Path to Master Programmer
26:26 ▶️ What Is a Master Programmer?
31:36 ▶️ David and Dr Chuck's Experiences with Programming Courses at University
36:32 ▶️ Brief Overview of the Origin of Computer Science and What Went Wrong
44:02 ▶️ When Dr Chuck Teaches Recursion
44:56 ▶️ But Doesn't the System Actually Work? Just look at Google and Facebook
45:38 ▶️ The Idea for Google Wasn't Good Enough for a PhD
48:47 ▶️ How to Fix the System
50:43 ▶️ The Last Nut to Crack
54:22 ▶️ Open Source's Role
56:44 ▶️ You Can't Apply Until You Have Run the Gauntlet
1:00:34 ▶️ You Can Start Now
1:01:08 ▶️ The Value of Mentors
1:04:15 ▶️ The Problem with Online Platforms
1:05:37 ▶️ Why Cisco is the Standard in Networking
1:08:15 ▶️ Every Course Dr Chuck Teaches Requires Him to Write Code
1:09:29 ▶️ Quick Summary for the Plan for the Master Programmer
1:11:53 ▶️ What's the Cost Going to Be?
1:15:09 ▶️ Education Is For Everybody, Not Just the Rich
1:16:36 ▶️ Final Thoughts
1:18:33 ▶️ Thanks, Dr Chuck!
// MY STUFF //
https://www.amazon.com/shop/davidbombal
// SOCIAL //
Discord: https://discord.com/invite/usKSyzb
Twitter: https://www.twitter.com/davidbombal
Instagram: https://www.instagram.com/davidbombal
LinkedIn: https://www.linkedin.com/in/davidbombal
Facebook: https://www.facebook.com/davidbombal.co
TikTok: http://tiktok.com/@davidbombal
YouTube: https://www.youtube.com/davidbombal
// Dr Chuck social //
Website: https://www.dr-chuck.com/
Twitter: https://twitter.com/drchuck/
YouTube: https://www.youtube.com/user/csev
Coursera: https://www.coursera.org/instructor/d...
// Python for Everybody //
Free Python course on Coursera: https://www.coursera.org/specializati...
YouTube: https://youtu.be/8DvywoWv6fI
Python for Everybody: https://www.py4e.com/
Free Python Book: http://do1.dr-chuck.com/pythonlearn/E...
Dr Chuck's Website: https://www.dr-chuck.com/
Free Python Book options: https://www.py4e.com/book
// Django for Everybody //
Website: https://www.dj4e.com/
Coursera: https://www.coursera.org/specializati...
YouTube: https://youtu.be/o0XbHvKxw7Y
// Web Applications for Everybody //
YouTube: https://youtu.be/xr6uZDRTna0
Website: https://www.wa4e.com/
Coursera: https://www.coursera.org/specializati...
// Internet History //
Coursera: https://www.coursera.org/learn/intern...
YouTube: https://youtu.be/47NRaBVxgVM
// SPONSORS //
Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com
python
python course
python for beginners
master programmer
dr chuck
dr chuck master programmer
python mentorship
google code interview
google interview
computer science
python best course
dr chuck python
dr chuck python course
learn to code
software development
software developer
computer science
software engineer
software engineering
how to learn programming
free python course
free python course online
free python class
free python tutorial
free python training
how to learn to code
coding tutorials
how to code
learning to code
learn to code for free
learn to code python
python jobs
coding bootcamp
google code interview
python for beginners
python full course
python tutorial
python projects
python basic tutorial
python programming
python interview questions
python course
python basics
open source
#python #programming #drchuck

Apr 10, 2022 • 1h 7min
#368: Hacking Linux // Linux Privilege escalation // Featuring HackerSploit
So you think Linux is secure? In this video we'll escalate our privileges on Linux to become root.
// MENU //
0:00:00 ▶️ Introduction
0:01:15 ▶️ Jump to the demo
0:01:38 ▶️ About Alexis, background and experience
0:07:38 ▶️ Starting HackerSploit
0:08:47 ▶️ Alexis and Linux
0:11:03 ▶️ Which is the preferred Linux distribution?
0:12:01 ▶️ Recommended Linux distribution for beginners
0:12:33 ▶️ LinuxJourney.com
0:12:01 ▶️ Favourite hacking distribution
0:13:51 ▶️ The PenTester Framework
0:15:21 ▶️ Best method to install a distribution
0:16:46 ▶️ Recommendations
0:18:29 ▶️ Recommended distribution for real-world pentesting
0:21:44 ▶️ Starting YouTube channel
0:22:18 ▶️ Windows vs MacOS vs Linux
0:23:30 ▶️ Recommended laptop
0:27:16 ▶️ Other advice
0:28:38 ▶️ Recommended certifications
0:30:46 ▶️ Recommended pre-requisite skills
0:33:13 ▶️ HackerSploit Linux Essential for Hackers
0:34:01 ▶️ HackerSploit Windows
0:34:26 ▶️ HackerSploit Networking Fundamentals
0:35:11 ▶️ Get your fundamentals right
0:35:29 ▶️ Dirty Pipe exploit presentation
0:43:52 ▶️ Dirty Pipe exploit demo
0:55:14 ▶️ Exploit 1
0:57:03 ▶️ Exploit 2
1:00:23 ▶️ Learning how to change scripts
1:02:14 ▶️ Recommended script language
1:04:00 ▶️ Thoughts on Golang
1:04:44 ▶️ Recommendations for learning languages
1:05:41 ▶️ Closing thoughts
// HackerSploit Linux exploit scripts //
Dirty Pipe Github page: https://github.com/AlexisAhmed/CVE-20...
Dirty Pipe Blog: https://dirtypipe.cm4all.com/
CVE details: https://cve.mitre.org/cgi-bin/cvename...
// Hackersploit Videos //
Pentesters Framework: https://www.youtube.com/watch?v=Bx3RL...
Linux for hackers: https://www.youtube.com/watch?v=T0Db6...
Windows for hackers:
Nmap series: https://www.youtube.com/watch?v=5MTZd...
Linux exploitation: https://www.youtube.com/watch?v=i-dQw...
Windows exploitation: https://www.youtube.com/watch?v=Bzmlj...
// Books //
Privilege Escalation Techniques: https://amzn.to/3xcPHjf
Automate the boring the stuff with Python: https://amzn.to/3LQA5Gl
// MY STUFF //
https://www.amazon.com/shop/davidbombal
// SOCIAL //
Discord: https://discord.com/invite/usKSyzb
Twitter: https://www.twitter.com/davidbombal
Instagram: https://www.instagram.com/davidbombal
LinkedIn: https://www.linkedin.com/in/davidbombal
Facebook: https://www.facebook.com/davidbombal.co
TikTok: http://tiktok.com/@davidbombal
YouTube: https://www.youtube.com/davidbombal
// HackerSploit //
LinkedIn: https://www.linkedin.com/in/alexisahmed/
YouTube: https://www.youtube.com/c/HackerSploit
Twitter: https://twitter.com/HackerSploit
Academy: https://hackersploit.academy/
// SPONSORS //
Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com
linux
kali linux
kali linux hack
linux hacking
hacker
linux exploit
linux privilege escalation
linux hack
linux dirty pipe
linux dirty pipe explained
linux dirty pipe cve
linux dirty pipe exploit
linux privilege escalation
ethical hacking
linux priv esc
priv escalation linux
hackersploit
hacking
linux exploit
linux dirty pipe
dirty pipe linux
dirty pipe cve
linux vulnerability
linux security
linux exploits
linux kernel
linux kernel vulnerablity
dirty pipe vulnerability
#linux #linuxhack #hacking

Apr 4, 2022 • 1h 3min
#367: Troubleshooting slow networks with Wireshark // wireshark filters // Wireshark performance
You are guilty until proven innocent! The network is slow! But is it actually a network issue? Or is it an application issue. Chris Greer explains.
// MENU //
00:00 ▶️ Introduction
00:35 ▶️ Wireshark filters introduction
02:20 ▶️ Regular IP filter
05:28 ▶️ Common filters
07:10 ▶️ Operators in filters
08:19 ▶️ Where to get the filter Power Point
08:55 ▶️ Filter shortcuts
11:20 ▶️ Filter buttons
12:10 ▶️ TCP analysis flags
15:16 ▶️ Filter buttons (cont'd)
17:15 ▶️ TCP reset
18:35 ▶️ How to apply filter as display filter
20:08 ▶️ Experience vs Theory
22:19 ▶️ Special filters
29:00 ▶️ Time filters
38:22 ▶️ Consulting scenario
49:45 ▶️ HTTPS consulting scenario
55:33 ▶️ Other filters
56:46 ▶️ How to simplify p-caps
59:29 ▶️ Signature filters
01:01:39 ▶️ Quick recap
01:02:16 ▶️ Conclusion
// MY STUFF //
https://www.amazon.com/shop/davidbombal
// SOCIAL //
Discord: https://discord.com/invite/usKSyzb
Twitter: https://www.twitter.com/davidbombal
Instagram: https://www.instagram.com/davidbombal
LinkedIn: https://www.linkedin.com/in/davidbombal
Facebook: https://www.facebook.com/davidbombal.co
TikTok: http://tiktok.com/@davidbombal
YouTube: https://www.youtube.com/davidbombal
//CHRIS GREER //
LinkedIn: https://www.linkedin.com/in/cgreer/
YouTube: https://www.youtube.com/c/ChrisGreer
Twitter: https://twitter.com/packetpioneer
Pluralsight: TCP Analysis Course: https://davidbombal.wiki/tcpwireshark
// SPONSORS //
Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com
wireshark
packet analysis
wireshark installation
wireshark filters
wireshark how to find ip address
wireshark http
wireshark ip address
wireshark wifi sniffing
wireshark tutorial
tcp analysis
packet analysis
free wireshark tutorial
tcp handshake
wireshark training
chris greer,
roubleshooting with wireshark
troubleshooting slow networks
network troubleshooting
packet capture
tcp reset
tcp connections
network protocols
packet capture using wireshark
Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel!
#wireshark #wiresharkfilters #networktroubleshooting

Apr 4, 2022 • 57min
#366: Hacking PayPal and TikTok (legally) // Featuring Ben Sadeghipour Nahamsec
Want to hack companies like PayPal and TikTok? What about the Department of Defense? Lots of companies that you can hack legally - and get paid doing it! This is a practical guide on how to get started hacking today.
// MENU //
00:00 ▶️ Introduction
00:17 ▶️ Who is Nahamsec?
01:18 ▶️ Different Bug Bounty Platforms
01:40 ▶️ Why Nahamsec Prefers These Platforms
02:34 ▶️ Intigriti Quick Overview
02:58 ▶️ Bugcrowd Quick Overview
03:25 ▶️ Hackerone Quick Overview
04:01 ▶️ What is Bug Bounty?
04:57 ▶️ Non-Monetary Rewards: Nahamsec's Red Bull Hack
05:57 ▶️ The Lyft, Snapchat and Undisclosed Travel Company Hack
07:02 ▶️ Interface Walkthrough
08:45 ▶️ Scope
10:18 ▶️ Top Hacker Profiles on Bug Bounty Programmes
11:04 ▶️ Profile Hacktivity Feed
13:54 ▶️ Using the site wide hacktivity feed to learn from previous bug bounties
15:31 ▶️ Getting Started: hacker101
17:24 ▶️ Getting Started: hackerone
20:58 ▶️ Submitting/Writing a Report
29:23 ▶️ Report Terminology
31:06 ▶️ How to Find a Company's Websites
33:05 ▶️ Nahamsec's Approach: Certificate Transparency
36:30 ▶️ Why NahamSec Prefers Dev Sites
38:05 ▶️ How to Find a Website's SSL Certificate
41:21 ▶️ Targeting a Company' Main Website vs Targeting Subdomains
42:25 ▶️ Researching a Company's Assets
43:43 ▶️ If You're New to the Bug Bounty Thing
47:40 ▶️ Ways to Learn
49:18 ▶️ Books to Help You Get Started Hacking
53:49 ▶️ Online Resources to Help You Get Started
55:28 ▶️ Final Advice
// Connect with David //
Discord: https://discord.com/invite/usKSyzb
Twitter: https://www.twitter.com/davidbombal
Instagram: https://www.instagram.com/davidbombal
LinkedIn: https://www.linkedin.com/in/davidbombal
Facebook: https://www.facebook.com/davidbombal.co
TikTok: http://tiktok.com/@davidbombal
YouTube: https://www.youtube.com/davidbombal
// Connect with Nahamsec //
Twitter: https://twitter.com/nahamsec
YouTube: https://www.youtube.com/c/nahamsec
Github: https://github.com/nahamsec/Resources-for-Beginner-Bug-Bounty-Hunters
Discord: https://discord.com/invite/ysndAm8
Instagram: https://www.instagram.com/nahamsec/
LinkedIn: https://www.linkedin.com/in/nahamsec/
Twitch: https://www.twitch.tv/nahamsec
Website: https://nahamsec.com/
// Nahamsec's Udemy Course//
Udemy: https://www.udemy.com/course/intro-to-bug-bounty-by-nahamsec/
// Sites //
Hackerone: https://www.hackerone.com/
Bugcrowd: https://bugcrowd.com/programs
Intigriti: https://www.intigriti.com/
// Book's recommended //
Bug Bounty Bootcamp: https://amzn.to/3K2YDeJ
Real-World Bug Hunting: https://amzn.to/3wTF9FN
Android Hacker's Handbook: https://amzn.to/3uMc509
The Web Application Hacker's Handbook: https://amzn.to/3IZ2RTr
Black Hat Python: https://amzn.to/3JYIZAV
Black Hat Python (2nd edition): https://amzn.to/379WcIV
// Creator's mentioned //
Nahamsec: https://www.youtube.com/c/Nahamsec
STÖK: https://www.youtube.com/c/STOKfredrik
LiveOverflow: https://www.youtube.com/c/LiveOverflow
Farah Hawa: https://www.youtube.com/c/FarahHawa
InsiderPhD: https://www.youtube.com/c/InsiderPhD
The Cyber Mentor: https://www.youtube.com/c/TheCyberMentor
// MY STUFF //
Monitor: https://amzn.to/3yyF74Y
More stuff: https://www.amazon.com/shop/davidbombal
// SPONSORS //
Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com
bug bounty
bugbounty
hackerone
hacking
Ben Sadeghipour
NahamSec
nahamsec
cyber
security
bug bounties
ethical hacking
bug bounty hunting
burp suite
ethical hacker
pentest certificate
red teaming
bug bounty tips
bug bounty for beginners
bug bounty course
pentest basics
bugcrowd
bugbounty
hack
bugs
hackerone
bugcrowd
Intigriti
Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel!
#buybounty #hacking #hack

Mar 31, 2022 • 57min
#365: Real World Talks: pfsense firewalls for home and business? // Featuring Tom Lawrence
Real World Talks: pfsense firewalls for home and business? // Featuring Tom Lawrence
Are pfsense firewalls any good for home or business? Which businesses are supported by pfsense? What are the advantages and disadvantages of using pfsense? How big can they go? Lots of questions! Fortunately Tom answers these and many more in this video.
// MENU //
00:00 ▶️ Introduction
01:29 ▶️ What pfSense is and Tom's experience with pfSense
03:43 ▶️ Tom and Open Source
04:38 ▶️ The benefit of pfSense being Open Source
05:21 ▶️ Systems Tom has deployed with pfSense
07:22 ▶️ pfSense licensing cost
09:09 ▶️ Using pfSense at home
11:45 ▶️ Virtualization
12:28 ▶️ Raspberry Pi support
13:02 ▶️ Virtualization vs hardware
14:37 ▶️ Tom's recommendation for small/medium businesses
19:43 ▶️ pfSense actual cost (pfSense vs pfSense+)
22:22 ▶️ Reasons not to use pfSense
24:45 ▶️ Tom's biggest pfSense deployment
26:07 ▶️ pfSense above 10G
27:11 ▶️ pfSense and VPN
28:32 ▶️ Handling lots of VPN connections
29:29 ▶️ Advice for starting a consulting business
31:09 ▶️ Technical skills vs sales skills
32:22 ▶️ The benefit of having sales skills
35:58 ▶️ It's about the customer, not the product you use
38:02 ▶️ How Tom got his first customers
40:21 ▶️ Why Tom has a YouTube channel
43:46 ▶️ This video is not sponsored by a VPN company
43:53 ▶️ Skills to learn in 2022 to get started
48:13 ▶️ Story 1 - Hacked client
49:10 ▶️ Story 2 - That will never happen in the real world
51:28 ▶️ Story 3- We've all done it
52:40 ▶️ Final advice
54:15 ▶️ Networking with people
// David's SOCIAL //
Discord: https://discord.com/invite/usKSyzb
Twitter: https://www.twitter.com/davidbombal
Instagram: https://www.instagram.com/davidbombal
LinkedIn: https://www.linkedin.com/in/davidbombal
Facebook: https://www.facebook.com/davidbombal.co
TikTok: http://tiktok.com/@davidbombal
YouTube: https://www.youtube.com/davidbombal
// Tom's SOCIAL //
Twitter: https://twitter.com/TomLawrenceTech
YouTube: https://www.youtube.com/user/TheTeckn...
Website: https://lawrencesystems.com/
LinkedIn: https://www.linkedin.com/in/lawrences...
Instagram: https://www.instagram.com/lawrencesys...
// MY STUFF //
https://www.amazon.com/shop/davidbombal
// SPONSORS //
Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com
pfsense
pfsense router
home router
home networking
open source router
raspberry pi
pi
pfsense pi
pfsense raspberry pi
opensource
linux router
pfsense tutorial
pfsense setup
pfsense basics
pfsense course
Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel!
#pfsense #linux #firewall

Mar 31, 2022 • 1h 6min
#364: TLS Handshake Deep Dive and decryption with Wireshark // SSL Key Exchange Explained
Hacking the TLS Handshake and decryption with Wireshark // SSL Deep Dive
50,157 views Mar 25, 2022 Warning! We go deep in this video to explain how the TLS handshake is completed. Warning! This is a technical deep dive and covers a lot of detail including SSL decryption and discusses RSA, Public and Private Keys, symmetric key exchange and lots more.
// Wireshark pcap //
https://davidbombal.wiki/tlsedpcap
// Ed's TLS course //
https://davidbombal.wiki/edtls49
Use coupon code: "BombalTLS" to get for $49
// MENU //
00:00 ▶️ Introduction
02:11 ▶️ How SSL/TLS is shown in a browser
02:40 ▶️ Pre-Requisites
05:15 ▶️ Data Integrity/Hashing
06:27 ▶️ Potential Problems with Hashing/man in-the-middle attack
07:32 ▶️ Message Authentication Code
10:09 ▶️ Prerequisites continued
11:51 ▶️ Symmetric Encryption
12:45 ▶️ Asymmetric Encryption
17:00 ▶️ Private and Public Keys
20:05 ▶️ Signatures
21:55 ▶️ Protocols
22:50 ▶️ SSL/TLS Handshake, Client Hello and Server Hello
28:35 ▶️ Client Hello and Server Hello in Wireshark
34:09 ▶️ Certificate
35:12 ▶️ Server Done
35:35 ▶️ Server Hello, Certificate, Server Hello Done in Wireshark
36:51 ▶️ Client Key Exchange
50:26 ▶️ Client Key Exchange in Wireshark
51:39 ▶️ Client Change Cipher Spec and Finished/Encrypted Verification
54:08 ▶️ Server Change Cipher Spec and Finished/Encrypted
56:10 ▶️ SSL/TLS Handshake in Wireshark
57:44 ▶️ Decrypting a PreMaster Key with a Private Key in Wireshark
1:03:15 ▶️ Where to get in contact with Ed to learn more
// David's SOCIAL //
Discord: https://discord.com/invite/usKSyzb
Twitter: https://www.twitter.com/davidbombal
Instagram: https://www.instagram.com/davidbombal
LinkedIn: https://www.linkedin.com/in/davidbombal
Facebook: https://www.facebook.com/davidbombal.co
TikTok: http://tiktok.com/@davidbombal
YouTube: https://www.youtube.com/davidbombal
// Ed's SOCIAL //
Twitter: https://twitter.com/ed_pracnet
YouTube: https://www.youtube.com/channel/UCKmU...
// Ed's TLS course //
https://davidbombal.wiki/edtls49
Use coupon code: "BombalTLS" to get for $49
// More detail on Ed's YouTube channel and website //
Asymmetric Encryption explained from a Practical Perspective:
https://www.practicalnetworking.net/p...
RSA Algorithm:
https://www.youtube.com/watch?v=Pq8gN...
DH Algorithm:
https://www.youtube.com/watch?v=KXq06...
Practical TLS - Crypto & SSL/TLS foundation:
https://www.youtube.com/playlist?list...
// MY STUFF //
https://www.amazon.com/shop/davidbombal
// SPONSORS //
Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com
tls
tls decryption
ssl
crypto
cryptography
ssl decryption
tls wireshark
tls decryption wireshark
tls tunnel
tls handshake
tlsp
tls explained
tls tunnel
vpn
tls protocol
tls handshake explained
tls 1.3
TLS
Transport Layer Security
Handshake
TLS Handshake
Crypto
Cryptography
security
wireshark
wireshark tutorial
wireshark packet analysis
tls decryption
tls decryption wireshark
tls 1.3 decryption
tls decryption wireshark
tls tunnel vpn free internet
tls decryption palo alto
Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel!
#tls #ssl #wireshark