David Bombal

David Bombal
undefined
May 28, 2022 • 35min

#380: FREE CCNA 200-301 course // Complete unlimited 2022 course

You can get access to a full FREE CCNA course today. If you cannot afford to buy IT training, here's your opportunity. No need to pay for IT training. You can change your life with this free training. Use the links below to get free access. // MENU // 00:00 ▶️ The Catalyst That Opened Up Many Opportunities 00:32 ▶️ You Can Help Me Improve My Video Quality 01:57 ▶️ Introduction//Welcome, Jeremy! 02:38 ▶️ Free CCNA Course 04:09 ▶️ Why Pay If It's Free? 05:37 ▶️ How We Make Free Content 06:20 ▶️ Thank You! 06:52 ▶️ Jeremy's Journey To CCNA 07:21 ▶️ Comment If You Want Guitar Lessons! 08:03 ▶️ Going to Japan 08:38 ▶️ Discovering IT 09:08 ▶️ Finding Networking//Network Chuck//David Bombal 10:19 ▶️ Give Back to the Community 11:22 ▶️ Studying CCNA Part-Time 12:21 ▶️ Experience Varies//Everything Changes 12:55 ▶️ How Jeremy Got His First Networking Job 15:08 ▶️ How to Get a Job With No Experience 15:24 ▶️ Being Multilingual 15:48 ▶️ Getting CCNA & CCNP Certifications 16:25 ▶️ Building a Portfolio 16:57 ▶️ Job Requirements//Apply Anyway 17:26 ▶️ Soft Skills Are More Important 18:05 ▶️ If Jeremy Didn't Start His YouTube Channel 18:42 ▶️ Impostor Syndrome//Keep On Learning 19:52 ▶️ Starting Broad and Narrowing It Down 21:03 ▶️ Study Like A Mad Man! 21:57 ▶️ Where Soft Skills Come Into Play 23:00 ▶️ Japan//Culture Shock 23:49 ▶️ Is CCNA a Good Career Choice? 25:50 ▶️ Applying For Jobs//Worst Thing That Could Happen 26:57 ▶️ Don't Burn Bridges//Networking With People 28:36 ▶️ Don't Be Shy To Say You Don't Know 29:15 ▶️ Google-fu//Google is a Skill 30:39 ▶️ Jeremy'sITLab//CCNP Course When? 31:41 ▶️ Final Thoughts//Networking Is Awesome 33:11 ▶️ Networking Gives You a Solid Foundation For IT 33:55 ▶️ CCNA Opened Doors For David Bombal 34:28 ▶️ Networking Isn't Going Away Any Time Soon 34:58 ▶️ Thanks, Jeremy! // Paid and FREE course links // Want to support us? Buy the course from Udemy here: https://davidbombal.wiki/ccnaudemy Or get the course for free (limited) on davidbombal.com - register here: https://davidbombal.wiki/freeccnadavid If the above link doesn't work, try this one: https://courses.davidbombal.com/p/com... Or watch for free on YouTube here: https://davidbombal.wiki/freeccnayoutube // David Bombal Memberships // Free: https://courses.davidbombal.com/p/dav... All-Inclusive Membership (includes Boson ExSim and NetSim): https://courses.davidbombal.com/p/all... // David's SOCIAL // Discord: https://discord.com/invite/usKSyzb Twitter: https://www.twitter.com/davidbombal Instagram: https://www.instagram.com/davidbombal LinkedIn: https://www.linkedin.com/in/davidbombal Facebook: https://www.facebook.com/davidbombal.co TikTok: http://tiktok.com/@davidbombal YouTube: https://www.youtube.com/davidbombal // Jeremy's SOCIAL // Twitter: https://twitter.com/jeremysitlab YouTube: https://www.youtube.com/c/JeremysITLab Website: https://www.jeremysitlab.com/ LinkedIn: https://www.linkedin.com/in/jeremypmc... Discord: https://discord.com/invite/pkBYDnqFD9 // MY STUFF // https://www.amazon.com/shop/davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com ccna ccna 200-301 200-301 free ccna free ccna course free ccna training new ccna cisco ccna ccna course ccna certification ccna training packet tracer ccna full course new ccna ccna exam ccna study ccna 200-301 full course ccna jeremy jeremy ccna cisco training ccna 200-301 course ccna 2020 network engineer free lab ccna course for beginners ccna security free cisco ccna fundamentals ccna full course 2022 ccna tutorial ccna networking jeremys it lab jeremys it lab playlist Jeremy McDowell #ccna #cisco #200301
undefined
May 16, 2022 • 1h 12min

#379: WiFi Has Changed Is UniFi Better Than Cisco

Is UniFi better than Cisco? What's great about UniFi and what's not? Tom Lawrence tells us his thoughts about UniFi WiFi, switches, routing and other products. For Transparency: Both Ubiquity and Cisco have given me products. Ubiquity have never paid me money for any video (but Cisco have sponsored videos in the past). // MENU // 00:00 ▶️ Cisco licenses are a nightmare 01:00 ▶️ Tom Lawrence & Unifi 03:12 ▶️ Difference between Unifi & Ubiquiti 05:56 ▶️ Tailored for WISP 07:08 ▶️ Cisco Business 09:08 ▶️ Configuring Unifi switches & access points 10:09 ▶️ Terrible Unifi support 11:51 ▶️ Making money resetting to default 12:10 ▶️ Do the devices have CLI? 13:09 ▶️ Web-browser on Unifi devices 13:30 ▶️ Unifi Controller 16:28 ▶️ Unifi Consoles 18:05 ▶️ Unifi Routing 21:16 ▶️ Do the switches support routing? 22:59 ▶️ Unifi switches as layer 2 switches 24:12 ▶️ Unifi USG 26:46 ▶️ Pros and Cons of Unifi 33:49 ▶️ Buggy Ubiquiti software 35:52 ▶️ Confidence in Unifi 37:44 ▶️ Access Points rule of thumb 38:42 ▶️ Advantages of Ubiquiti 43:17 ▶️ "The world is changing" 45:13 ▶️ Running the controller without a Unifi account 47:19 ▶️ Vlans & Routing 50:23 ▶️ Unifi Switches 54:23 ▶️ Unifi 6 Access Points 57:43 ▶️ Recommended products 01:01:56 ▶️ Unifi firmware updates 01:02:55 ▶️ Inexpensive options 01:05:04 ▶️ Third-party support 01:06:12 ▶️ Unifi 6 Long Range 01:07:22 ▶️ Unifi Camera 01:10:42 ▶️ Closing thoughts and recommendations 01:11:26 ▶️ Conclusion // Videos mentioned // Hackersploit: https://youtu.be/yYY5mJoUZjU Eric: https://youtu.be/cMR19vkNqS8 // Books Mentioned // Privilege Escalation Techniques: https://amzn.to/3FUDcLO Mastering Python Networking: https://amzn.to/3MkaZQN // David's SOCIAL // Discord: https://discord.com/invite/usKSyzb Twitter: https://www.twitter.com/davidbombal Instagram: https://www.instagram.com/davidbombal LinkedIn: https://www.linkedin.com/in/davidbombal Facebook: https://www.facebook.com/davidbombal.co TikTok: http://tiktok.com/@davidbombal YouTube: https://www.youtube.com/davidbombal // Tom's SOCIAL // Twitter: https://twitter.com/TomLawrenceTech YouTube: https://www.youtube.com/user/TheTeckn... Website: https://lawrencesystems.com/ LinkedIn: https://www.linkedin.com/in/lawrences... Instagram: https://www.instagram.com/lawrencesys... // MY STUFF // https://www.amazon.com/shop/davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com wifi ubiquiti unifi ubiquiti networks ubiquiti unifi unifi dream machine unifi dream machine pro cisco vs ubiquiti access point dream machine pro unifi alternative unifi controller dream machine unifi udm unifi dream machine unifi dream machine review best wifi unifi switch unifi controller setup unifi controller linux unifi controller mac ubiquiti unifi setup unifi protect app unifi vs pfsense unifi vs omada unifi vs meraki unifi vs mikrotik unifi vs cisco cisco wifi tom lawrence lawrence systems lawrence unifi unifi tom lawrence unifi lawrence #unifi #ubiquiti #wifi
undefined
May 16, 2022 • 24min

#378: They said this doesn't work 🤣 Hacking networks with VLAN hopping and Python

Don't believe what you read online. VLAN hopping is possible and I'm going to show you how :) I'll also show you have to mitigate these types of attacks. Boson Bombal 8 Weeks to CCNA: https://davidbombal.wiki/bosonbombal // MENU // 00:00 ▶️ Messing With The Network 00:51 ▶️ Intro to VLAN Hopping 01:20 ▶️ VLAN Test Setup 2:35 ▶️ Starting Wireshark Captures//Filtering for ICMP 3:30 ▶️ Python Script Explained 4:13 ▶️ Windows 11 Network Setup 4:52 ▶️ VLAN Configuration Diagram 5:02 ▶️ Python Script Explained Continued 5:17 ▶️ Test 01 - Running the script in Kali Linux 5:51 ▶️ Examining ICMP Packets in Wireshark 6:46 ▶️ Examining Network Setup with PuTTY 8:29 ▶️ Why the script doesn't work 8:44 ▶️ Test 02 - One More Time 9:30 ▶️ How to make it work 10:21 ▶️ Test 03 - Running the modified script 10:40 ▶️ The Trick Step by Step 11:31 ▶️ Test 04 - I'll Do That Again 12:46 ▶️ Test 05 - Let's Try That Again 15:44 ▶️ How To Mitigate VLAN Hopping 17:26 ▶️ Test 06 - After Implementing Mitigation 18:09 ▶️ Don't Use VLAN 1 18:22 ▶️ Changing the Native VLAN 19:22 ▶️ Test 07 - After Changing Native VLAN 19:45 ▶️ Test 08 - After Changing Native VLAN 19:58 ▶️ Again, Don't Use VLAN 1! 21:00 ▶️ Looking At The Modified Python Script 21:55 ▶️ Changing the Python Script to Target New VLAN Config 23:04 ▶️ Stacking Multiple Packets // TAP used // Dualcomm ETAP-2003 10/100/1000Base-T TAP :https://amzn.to/3we7mGI // Script // Github: https://github.com/davidbombal/scapy/... // Previous videos // Previous video: https://youtu.be/CIWD9fYmDig Playlist: https://davidbombal.wiki/scapy // SCAPY RESOURCES // Website: https://scapy.net/ Documentation: https://scapy.readthedocs.io/en/latest/ // SCAPY INSTALLATION // sudo apt update sudo apt install python3-pip sudo pip3 install scapy // David's SOCIAL // Discord: https://discord.com/invite/usKSyzb Twitter: https://www.twitter.com/davidbombal Instagram: https://www.instagram.com/davidbombal LinkedIn: https://www.linkedin.com/in/davidbombal Facebook: https://www.facebook.com/davidbombal.co TikTok: http://tiktok.com/@davidbombal YouTube: https://www.youtube.com/davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com python cisco vlan hopping vlan hopping python python hacking hacking kali linux vlan hopping kali vlan hopping attack vlan hopping attack explained vlan hopping mitigation vlan hopping explained vlan hopping example vlan hopping cisco vlan hopping tool 802.1Q dot1q vlan tagging vlan tag stacking scapy scapy python python scapy scapy in python scapy python3 kali linux scapy scapy kali linux python hacking scapy python tutorial scapy tutorial scapy python pcap scapy packet crafting scapy python 3 cyber security vlan hopping double tagging hacking cisco ethical hacking kali kali linux python python scapy ccna ccnp ccie cisco routers cisco switches ccna 200-301 python scripts linux kali kali linux 2022 kali linux 2021 oscp ceh security+ Disclaimer: This video is for educational purposes only. I own all equipment used for this demonstration. No actual attack took place on any websites. Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel! #python # #hacking #cyber
undefined
May 11, 2022 • 53min

#377: Hacking CCTV And IP Cameras Are You Safe?

Is your CCTV secured? Are your IP cameras safe? Too easy to hack? This is my third interview with the professional hacker Occupy The Web. In this video, we discuss hacking CCTV, IP cameras and SCADA (supervisory control and data acquisition). // MENU // 00:00 ▶️ It Didn't Stop Us! 00:43 ▶️ YouTube Is Not Realistic 02:58 ▶️ Hacking Is Boring? 04:12 ▶️ In An Alternative Universe 04:35 ▶️ High vs Low Value Targets 07:09 ▶️ Hacking Ukraine CCTV Cameras 08:04 ▶️ Why Aren't Cameras Well Protected? 10:48 ▶️ Why Hack Ukraine CCTV Cameras? 12:45 ▶️ Finding Online Systems Anywhere In The World 14:47 ▶️ Don't Cameras Have Passwords? 17:36 ▶️ Hack My Spouse//The Most Common Request 19:30 ▶️ Convert Tools To Cyrillic? 20:20 ▶️ Remote Camera Hacking 20:56 ▶️ Camera Hacking Summary 21:13 ▶️ Dictionary Attack or Brute Force for Remote Hacking? 22:32 ▶️ Remote Hacking Takes Teamwork 22:52 ▶️ Cameras Blocking Login Attempts 23:23 ▶️ Bad Practices//How To Secure CCTV Cameras 24:42 ▶️ Don't Be An Easy Target! 25:43 ▶️ Basic Security To Have On Your Systems 28:42 ▶️ Users Aren't The Flaw! 30:07 ▶️ Russia SCADA Attacks 30:38 ▶️ SCADA Swiss Army Knife 31:21 ▶️ Stealing Schneider Password Hashes 33:40 ▶️ DDoSing SCADA Systems Is Deadly 36:53 ▶️ Russian Hackers//Overrated? 40:22 ▶️ SCADA Malware Used On Ukraine Systems 42:54 ▶️ Warning//Russia Coming After Hackers 44:16 ▶️ Phishing Attempts on OTW 45:07 ▶️ How To Protect Yourself 46:00 ▶️ Social Engineering//Most Major Hacks 47:46 ▶️ Social Engineering//Pentesting 49:11 ▶️ SCADA Malware//Stuxnet 50:56 ▶️ SCADA Malware//Triton 51:25 ▶️ Bhopal Disaster//What Could Happen 52:39 ▶️ Future Videos//Leave A Comment! // Previous videos // OTW video 1: https://youtu.be/GudY7XYouRk OTW video 2: https://youtu.be/uXbGQiXsRes // David's SOCIAL // Discord: https://discord.com/invite/usKSyzb Twitter: https://www.twitter.com/davidbombal Instagram: https://www.instagram.com/davidbombal LinkedIn: https://www.linkedin.com/in/davidbombal Facebook: https://www.facebook.com/davidbombal.co TikTok: http://tiktok.com/@davidbombal YouTube: https://www.youtube.com/davidbombal // Occupy The Web social // Twitter: https://twitter.com/three_cube // Occupy The Web books // Linux Basics for Hackers: https://amzn.to/3JlAQXe Getting Started Becoming a Master Hacker: https://amzn.to/3qCQbvh // Occupy The Web Website / Hackers Arise Website // Website: https://www.hackers-arise.com/ Shodan: https://www.hackers-arise.com/shodan Webcams: https://www.hackers-arise.com/how-to-... Ukraine Cameras: https://www.hackers-arise.com/post/we... SCADA Hacking: The Key Differences between Security of SCADA and Traditional IT systems https://davidbombal.wiki/scada1 SCADA Hacking: Finding SCADA Systems using Shodan https://davidbombal.wiki/scada2 Shodan: Using Shodan to Find Vulnerable Russian SCADA/ICS Sites https://davidbombal.wiki/shodan SCADA Hacking: The Most Important SCADA/ICS Attacks in History https://www.hackers-arise.com/post/sc... SCADA Hacking: SCADA/ICS Protocols (Profinet/Profibus) https://www.hackers-arise.com/post/20... Lots of Scada content: https://www.hackers-arise.com/scada-h... // In the News // Feds Uncover a ‘Swiss Army Knife’ for Hacking Industrial Control Systems: https://www.wired.com/story/pipedream... Ukrainian power grid 'lucky' to withstand Russian cyber-attack: https://www.bbc.co.uk/news/technology... An Unprecedented Look at Stuxnet, the World's First Digital Weapon https://www.wired.com/2014/11/countdo... // Other books // The Linux Command Line: https://amzn.to/3ihGP3j How Linux Works: https://amzn.to/3qeCHoY // MY STUFF // https://www.amazon.com/shop/davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel!
undefined
May 11, 2022 • 1h 7min

#376: VPN slow? Network nightmares? How TCP really works: MTU vs MSS

Wireshark TCP Deep Dive continues: You need to understand this - whats the difference between Maximum Transmission Unit (MTU) vs Maximum Segment Size (MSS). // MENU // 00:00 ▶️ Coming Up 00:25 ▶️ Intro 00:32 ▶️ Chris introduction 00:47 ▶️ Topic: Maximum Segment Size (MSS) 01:27 ▶️ Explaining Maximum Transmission Unit (MTU) 08:42 ▶️ Interface layout 10:25 ▶️ David Bombal "War Story" 12:00 ▶️ Wireshark demo 13:26 ▶️ Increasing the MTU on your device for larger connections 16:27 ▶️ Difference between MTU and MSS 19:36 ▶️ Wireshark demo (cont'd) 24:58 ▶️ Using Path MTU Discovery 27:02 ▶️ Ping and Wireshark demo 33:32 ▶️ Cool trick for Mac system 35:08 ▶️ TCP/MSS Clamping 38:21 ▶️ Chris Greer "War Story" 51:09 ▶️ What happens if you can't capture a server 55:08 ▶️ MSS Adjustment commands 56:55 ▶️ Tunnel Path MTU Discovery 57:40 ▶️ Figuring out 1432 01:02:52 ▶️ Conclusion 01:04:48 ▶️ "Cool features" in Wireshark Previous video: https://youtu.be/rmFX1V49K8U // Wireshark PCAP files // MTU PCAP: https://github.com/packetpioneer/yout... War Story PCAP Client: https://github.com/packetpioneer/yout... War Story PCAP Server: https://github.com/packetpioneer/yout... Special “Thumbs Up” and “Subscribe” PCAP: https://github.com/packetpioneer/yout... // VLAD SOCIAL // Twitter: https://twitter.com/Packet_vlad PMTUD Blog: http://www.packettrain.net/2016/09/21... Thanks Vladimir Gerasimov! // GOOD READING // Network Implications of PMTUD: https://www.ipspace.net/kb/Internet/P... Path MTU Discovery: https://www.ipspace.net/kb/Internet/P... Resolve IPv4 Fragmentation, MTU, MSS, and PMTUD Issues with GRE and IPsec: https://www.cisco.com/c/en/us/support... Configuring TCP MSS Adjustment: https://www.cisco.com/c/en/us/td/docs... Ethernet MTU and TCP MSS Adjustment Concept for PPPoE Connections: https://www.cisco.com/c/en/us/support... // MY STUFF // https://www.amazon.com/shop/davidbombal // David SOCIAL // Discord: https://discord.com/invite/usKSyzb Twitter: https://www.twitter.com/davidbombal Instagram: https://www.instagram.com/davidbombal LinkedIn: https://www.linkedin.com/in/davidbombal Facebook: https://www.facebook.com/davidbombal.co TikTok: http://tiktok.com/@davidbombal YouTube: https://www.youtube.com/davidbombal // Chris SOCIAL // Udemy course: https://davidbombal.wiki/chriswireshark LinkedIn: https://www.linkedin.com/in/cgreer/ YouTube: https://www.youtube.com/c/ChrisGreer Twitter: https://twitter.com/packetpioneer // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com tcp mss mtu tcp/ip tcp ip ipv4 wireshark icmp slow icmp dropped packets wireshark tutorial wireshark training packet analysis packet capture tcp handshake tcp analysis tcp connections chris greer wireshark chris greer chris greer wireshark wireshark chris transport control protocol how tcp works tcp/ip transport protocol packet network mtu maximum transmission unit tcp mss maximum segment size free wireshark tutorial network troubleshooting tcp/ip analysis wireshark mtu wireshark mss ipsec gre mpls tunnels troubleshoot slow network troubleshooting slow networks troubleshoot slow internet Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel! #wireshark #tcp #mtu
undefined
May 5, 2022 • 1h 8min

#375: Hacking APIs and Cars: You need to learn this in 2022!

You need to learn how to hack APIs in 2022. This is the future battlefront! Ignore this at your own peril. // MENU // 00:00 ▶️ Coming up 00:44 ▶️ Intro 00:53 ▶️ Alissa Knight introduction and background 02:36 ▶️ Published author and filmmaker 03:30 ▶️ Alissa Knight YouTube channel 05:02 ▶️ Book on API hacking 06:05 ▶️ The definition of hacking 10:25 ▶️ How to approach hacking 14:10 ▶️ The importance of learning 16:07 ▶️ How to start hacking APIs 22:54 ▶️ "The Desire" 25:35 ▶️ Recommended certifications 28:35 ▶️ Understanding Networking fundamentals 30:04 ▶️ Do you have to be a programmer to hack? 33:09 ▶️ Mastering tools 34:33 ▶️ Hacking APIs 38:43 ▶️ Shift left security, shield right 40:15 ▶️ Bank app developed by marketing team 42:51 ▶️ Smart phone takeover 45:10 ▶️ How to learn to hack APIs 48:11 ▶️ Process on how to hack APIs 55:05 ▶️ Implementing authorization and authentication 56:43 ▶️ APIs in nuclear plant systems 58:52 ▶️ Wifi pineapple 01:01:23 ▶️ Securing APIs in cars 01:03:18 ▶️ "Exciting times" 01:05:45 ▶️ Conclusion Nahamsec Interview: https://youtu.be/Y2Y4Sk0PswU // David's SOCIAL // Discord: https://discord.com/invite/usKSyzb Twitter: https://www.twitter.com/davidbombal Instagram: https://www.instagram.com/davidbombal LinkedIn: https://www.linkedin.com/in/davidbombal Facebook: https://www.facebook.com/davidbombal.co TikTok: http://tiktok.com/@davidbombal YouTube: https://www.youtube.com/davidbombal // Alissa's SOCIAL // Twitter: https://twitter.com/alissaknight YouTube: https://www.youtube.com/alissaknight Instagram: https://www.instagram.com/alissaknight/ LinkedIn: https://www.linkedin.com/in/alissakni... Website: https://www.alissaknight.com/ Hacking Bank APIs: https://davidbombal.wiki/hackingbankapis // Katie Paxton-Fear // YouTube: https://www.youtube.com/c/InsiderPhD Twitter: https://twitter.com/insiderphd // David Sopas // Twitter: https://twitter.com/dsopas Github API mindmap: https://github.com/dsopas/MindAPI // Hyperfocus daily task sheet // Alissa Knight's Daily Task Sheet: https://davidbombal.wiki/dailytasks // BOOKS // Hacking Connected Cars - Alissa Knight: https://amzn.to/3Ke00GO Hyper Focus - Chris Bailey: https://amzn.to/3vAocxO Self Journal by BestSelf: https://amzn.to/3ks1BhK Hacking APIs - Corey Ball: https://amzn.to/37PUwoI The Official (ISC)2 CISSP CBK Reference: https://amzn.to/3vxzjJ2 // MY STUFF // https://www.amazon.com/shop/davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com api apis postman burpsuite hacking hacking cars hacking connected cars hacking api cyber security information security sans institute cybersecurity training cyber security training information security training cyber hack privacy nsa oscp ceh Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel! #hacking #infosec #cyber
undefined
May 2, 2022 • 35min

#374: Website Hacking Demos using Cross-Site Scripting (XSS) - it's just too easy!

It's just too easy to attack websites using Cross Site Scripting (XSS). The XSS Rat demonstrates XSS attacks. XSS Rat explains and demos cross-site scripting (xss) attacks. // MENU // 00:00 ▶️ We are taking over the world! 00:16 ▶️ Introducing//XSS Rat//Wesley 01:28 ▶️ What is XSS/ Cross Site Scripting? 02:59 ▶️ Types of XSS 05:15 ▶️ Reflected XSS 06:22 ▶️ Example of data sanitization 07:35 ▶️ Circumventing filtering with the img tag 11:01 ▶️ Sending a Reflected XSS Attack to Someone 12:01 ▶️ Using HTML comments as an attack vector 13:49 ▶️ Using single quotes to break out of the input tag 15:14 ▶️ Don't use alert() to test for XSS 17:33 ▶️ What you can do with Reflected XSS 19:26 ▶️ Stored XSS 20:31 ▶️ Using comments for XSS 21:05 ▶️ Example #1 of Stored XSS on Twitter 21:42 ▶️ Example #2 of Stored XSS 22:12 -▶️ The answer to the ultimate question of life, the universe, and everything. 22:56 ▶️ Stored vs Reflected XSS 24:22 ▶️ AngularJS/Client Side Template Injection 25:06 ▶️ Don't use JavaScript? 26:09 ▶️ Where to learn more//XSS Survival Guide 27:04 ▶️ DOM Based XSS 29:36 ▶️ List of DOM sinks 30:12 ▶️ jQuery DOM sinks 32:15 ▶️ XSS Rat Live Training 33:00 ▶️ Support XSS Rat//Wesley 34:06 ▶️ Closing//Thanks, Wesley! // Demo Sites // XSS Labs: https://hackxpert.com/labs/RXSS/GET/ Labs site: https://hackxpert.com/labs Rat Site: https://hackxpert.com/ratsite // David's SOCIAL // Discord: https://discord.com/invite/usKSyzb Twitter: https://www.twitter.com/davidbombal Instagram: https://www.instagram.com/davidbombal LinkedIn: https://www.linkedin.com/in/davidbombal Facebook: https://www.facebook.com/davidbombal.co TikTok: http://tiktok.com/@davidbombal YouTube: https://www.youtube.com/davidbombal // XSS Rat SOCIAL // Twitter: https://twitter.com/theXSSrat YouTube: youtube.com/c/TheXSSrat Website: https://thexssrat.podia.com/ // XSS Rat's Udemy course // XSS Survival Guide: https://www.udemy.com/course/xss-surv... // XSS Rat's courses and bootcamps // https://thexssrat.podia.com/ // MY STUFF // https://www.amazon.com/shop/davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com xss cross site scripting portswigger ajax jscript javascript xss attack xss video tutorial xss attack tutorial xss explained xss attack example xss bug bounty xss tutorial xss vulnerability xss vs csrf attack xss example xsser xsssa facebook xsssa kali linux penetration testing ethical hacking bug bounty cross site scripting cross-site scripting red teaming cyber security kali linux install kali linux 2022 ethical hacker course ethical hacker javascript ajax jquery node js node js hacking portswigger Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel! #xss #javascript #hacking
undefined
Apr 25, 2022 • 1h 13min

#373: OSINT: You can't hide // Your privacy is dead // Best resources to get started

You cannot hide. Your privacy is over. Want to learn OSINT? Want to learn how easy it is to find information online? Time to learn Open Source Intelligence from the best. I think I'll move to a cave :( OSINT Curious is a registered, non-profit 501(c)(3) organization with the United States IRS (EIN: 84-2781099); and accepts Patreon donations from individuals and sponsors. If you are a sponsor, please contact them if you want to work with them: https://osintcurio.us/funding/ // The OSINT Curious Project // YouTube: https://www.youtube.com/c/TheOSINTCur... Twitter: https://twitter.com/osintcurious LinkedIn: https://www.linkedin.com/company/the-... Website: https://osintcurio.us Public, OSINT-focused Discord: https://iam.osintcurio.us/discord Sponsor personally or through your company: https://osintcurio.us/funding/ // Websites mentioned // OSINT games: https://www.osint.games/ OSINT Framework: osintframework.de OSINT Training: myosint.training Fitness app Strava lights up staff at military bases: https://www.bbc.co.uk/news/technology... https://www.theguardian.com/world/201... // David's SOCIAL // Discord: https://discord.com/invite/usKSyzb Twitter: https://www.twitter.com/davidbombal Instagram: https://www.instagram.com/davidbombal LinkedIn: https://www.linkedin.com/in/davidbombal Facebook: https://www.facebook.com/davidbombal.co TikTok: http://tiktok.com/@davidbombal YouTube: https://www.youtube.com/davidbombal // Lisette SOCIAL // Twitter: https://twitter.com/technisette Personal website: https://technisette.com // Steven Harris SOCIAL // Twitter: https://twitter.com/nixintel LinkedIn: https://www.linkedin.com/in/steven-ha... Personal website: https://nixintel.info/ SANS SEC487 OSINT Courses Steven teaches - https://www.sans.org/profiles/steven-... // Micah Hoffman SOCIAL // Twitter: https://twitter.com/webbreacher LinkedIn: https://www.linkedin.com/in/micahhoff... Personal website: https://webbreacher.com Micah's OSINT Training Courses: https://myosint.training Micah's OSINT CTF Platform: https://osint.games // BOOKS MENTIONED // 1. Hack The World With OSINT – Chris Kubeka: https://amzn.to/3xM61I1 2. Open Source Intelligence Techniques (Ninth Ed) - Michal Bazzel: https://amzn.to/3Lb7MSX // MY STUFF // https://www.amazon.com/shop/davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com osint osint curious google dorks dorks google osintgram osint framework osint tools osint tv osint ukraine osint tutorial osint course osint instagram osint framework tutorial cyber security information security open-source intelligence open source intelligence sans institute cybersecurity training cyber security training information security training what is osint open source artificial intelligence cyber hack privacy nsa oscp ceh Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel! #osint #cyber #privacy
undefined
Apr 25, 2022 • 18min

#372: Hacking networks with Python // Creating malicious packets and breaking TCP/IP rules

Learn the basics of how to use Python and Scapy to create malicious or dodgy packets and send those into networks. Who knows what's going to happen when packets are created like these. Also learn that what they teach you about the TCP/IP model in the CCNA course isn't necessarily true in the real world. You need to learn to code! Learn Python. Learn Networking. You are going to be very powerful and very scary if you combine knowledge of networking with Python scripting! But, do good. Learn to code. Learn Linux. Learn Networking. // Menu // 00:00 - Coming up 00:28 - Introduction 01:00 - How to generate dodgy packets with Scapy 01:14 - TCP/IP model 01:25 - Protocol data units 01:46 - OSI model video 02:12 - Importing Scapy into Python 04:25 - Spoof mac address 06:18 - Sending traffic into the network 08:52 - Sending weird packets 11:43 - "Advanced stuff" 15:11 - In the real world 17:17 - Conclusion The OSI Model is a lie: https://youtu.be/apr63p7K_3A Scapy documentation: https://scapy.net/ Playlist: https://davidbombal.wiki/scapy // SCAPY RESOURCES // Website: https://scapy.net/ Documentation: https://scapy.readthedocs.io/en/latest/ // SCAPY INSTALLATION // sudo apt update sudo apt install python3-pip sudo pip3 install scapy // SOCIAL // Discord: https://discord.com/invite/usKSyzb Twitter: https://www.twitter.com/davidbombal Instagram: https://www.instagram.com/davidbombal LinkedIn: https://www.linkedin.com/in/davidbombal Facebook: https://www.facebook.com/davidbombal.co TikTok: http://tiktok.com/@davidbombal YouTube: https://www.youtube.com/davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com python scapy kali linux kali kali linux python osi model tcp tcp ip tcp/ip tcp ip model python scapy ccna ccnp ccie cisco routers ccna 200-301 python scripts linux kali kali linux 2022 kali linux 2021 oscp ceh security+ pentest+ Disclaimer: This video is for educational purposes only. I own all equipment used for this demonstration. No actual attack took place on any websites. Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel! #python #hacking #cyber
undefined
Apr 19, 2022 • 1h 6min

#371: Hacking Power Plants and Industrial Control Systems (Scada) // Ukraine Russia Cyberwar

This is my second interview with the professional hacker Occupy The Web. In this video we discuss OSINT and hacking industrial control systems (ICS) using SCADA (supervisory control and data acquisition). Jump to 33:40 for scada discussions. Disclaimer: The opinions expressed by Occupy The Web in this interview are his own. // Previous video // OTW video 1: https://youtu.be/GudY7XYouRk // David's SOCIAL // Discord: https://discord.com/invite/usKSyzb Twitter: https://www.twitter.com/davidbombal Instagram: https://www.instagram.com/davidbombal LinkedIn: https://www.linkedin.com/in/davidbombal Facebook: https://www.facebook.com/davidbombal.co TikTok: http://tiktok.com/@davidbombal YouTube: https://www.youtube.com/davidbombal // Occupy The Web social // Twitter: https://twitter.com/three_cube // Occupy The Web books // Linux Basics for Hackers: https://amzn.to/3JlAQXe Getting Started Becoming a Master Hacker: https://amzn.to/3qCQbvh // Occupy The Web Website / Hackers Arise Website // Website: https://www.hackers-arise.com/ Using OSINT to find Yachts: https://davidbombal.wiki/osintyachts Can the CIA or other Intelligence Agencies Track My Every Move: https://davidbombal.wiki/ciaphonestra... SCADA Hacking: The Key Differences between Security of SCADA and Traditional IT systems https://davidbombal.wiki/scada1 SCADA Hacking: Finding SCADA Systems using Shodan https://davidbombal.wiki/scada2 Shodan: Using Shodan to Find Vulnerable Russian SCADA/ICS Sites https://davidbombal.wiki/shodan SCADA Hacking: The Most Important SCADA/ICS Attacks in History https://www.hackers-arise.com/post/sc... SCADA Hacking: SCADA/ICS Protocols (Profinet/Profibus) https://www.hackers-arise.com/post/20... Lots of Scada content: https://www.hackers-arise.com/scada-h... // In the News // Feds Uncover a ‘Swiss Army Knife’ for Hacking Industrial Control Systems: https://www.wired.com/story/pipedream... Ukrainian power grid 'lucky' to withstand Russian cyber-attack: https://www.bbc.co.uk/news/technology... An Unprecedented Look at Stuxnet, the World's First Digital Weapon https://www.wired.com/2014/11/countdo... // Other books // The Linux Command Line: https://amzn.to/3ihGP3j How Linux Works: https://amzn.to/3qeCHoY // MY STUFF // https://www.amazon.com/shop/davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel!

The AI-powered Podcast Player

Save insights by tapping your headphones, chat with episodes, discover the best highlights - and more!
App store bannerPlay store banner
Get the app