0:00 Introduction 1:24 The Story 2:35 Starting the VM & Setting up the AttackBox 4:39 Exploring the Application Functionality 5:59 Code Review! 7:25 Race Condition Explained 9:59 Threads vs Last-Byte Sync 17:23 Last-Byte Sync in Action! 18:21 Solving the Day Using Last-Byte Sync 19:58 Outro
0:00 Introduction 1:24 The Story 2:35 Starting the VM & Setting up the AttackBox 4:39 Exploring the Application Functionality 5:59 Code Review! 7:25 Race Condition Explained 9:59 Threads vs Last-Byte Sync 17:23 Last-Byte Sync in Action! 18:21 Solving the Day Using Last-Byte Sync 19:58 Outro
00:00 Introduction to the CVE Program Crisis 01:03 Pete Allor: Background and Experience 01:41 Understanding CVEs and Their Importance 03:02 The Structure and Governance of the CVE Program 05:47 The CVE Foundation's Multi-Stakeholder Funding Model 07:27 Addressing Global Vulnerability Management 11:17 Challenges and Future Directions for the CVE Program 21:45 The Role of CNAs and Ensuring Quality 31:01 Balancing Speed and Accuracy in Vulnerability Disclosure 33:15 Outro
0:00 Intro 1:01 What motivated you to get into Cybersecurity, or pentesting specifically, and does this job feel any different to the ones you've had before? 2:27 Do you think you were able to bring skills from previous roles across into Cybersecurity that perhaps are harder to develop for those of us whose entire careers were in tech? 6:41 Of bootcamps, networking, free training, CTFs, certs, which do you think had the most immediate return on investment, and which was more of a slow burner? 12:37 Can you describe how the NetSPI U program works, your experiences, and how it prepared you for your pentesting career? 17:47 What were some of the challenges you faced when you transitioned from the training program into performing actual pentests for customers? 21:10 What sparked your interest in mainframe hacking, and why is it such a unique area in cybersecurity? 26:18 How would you recommend someone interested in mainframe hacking get started? 28:29 What first made you think about giving talks at cons, and how did you approach your first talk? 35:24 How can the industry and community get better at making women and minorities feel more welcome? 37:59 What keeps you motivated and excited about working in Cybersecurity today and do you have any long term goals in the industry? 41:14 Outro
0:00 Introduction 1:20 How hard was it to transition from Rocket Network Engineering to Rocket Cybersecurity? 4:30 What does a day in the life of a rocket cybersecurity expert actually look like? 9:08 What is the difference between a rocket network engineer and a regular network engineer? 11:46 Does the rocket use military grade encryption to communicate with the ground? 15:32 So what cybersecurity tools do you use in your like everyday work life? 20:28 What are your strategies when it comes to interviews? 21:05 Do you have any feelings on that? 27:02 What's the biggest misconception people have about being a rocket network engineer? 30:39 Can you explain the difference between Zero Day and Zero-G exploits? 33:03 What advice do you have for people interested in getting into Rocket Cybersecurity? 38:57 Outro 39:53 Extras
0:00 Introduction 0:48 What motivated you to transition into cybersecurity, and what skills from your previous vocations do you feel most helped? 2:17 Do you feel like getting a degree gave you any kind of edge when trying to find your first Cybersecurity role? 4:56 Which cert do you consider the most valuable for newcomers to get, and on a personal level, which cert did you most enjoy getting? 8:43 Do you have any advice on how people starting out with zero certs should craft a path forwards? 12:44 Do you feel like streaming can help develop certain soft skills given you are presenting to an audience? 15:55 How can people best learn the soft skills required to perform various roles in the industry? 20:06 What is it about CVEs that you think can give candidates that extra sparkle? 26:37 Are most of your tools created out of necessity, and what motivates you to develop them further and maintain them? 31:37 Do you have a favorite success story from a student you can share? 34:33 With the rise of AI, how do you see the Cybersecurity threat landscape changing, and do you think aspiring professionals should be studying AI for this purpose? 36:10 Outro
Follow @trshpuppy on YouTube and X: https://x.com/trshpuppy
0:00 Intro 1:13 Bring a laptop with your tools ready to go 2:15 Bring cash, snacks, & a water bottle 4:04 Don't try to see everything 5:57 Hacker Tracker! 6:54 Say hi to people, especially your role models 8:12 Stay at a hotel close to the venue 10:05 Bring a little piece of yourself to give to others 12:46 Pack a really good pair of shoes and comfy socks 14:06 Hack at least ONE thing! 15:45 Plan for plan changes 17:34 Outro
Join the Hack Smarter community: hacksmarter.org Listen to Tyler's OSCP rap song: https://is.gd/oscprap
0:00 Introduction 0:43 Can you share your journey and what motivated such a significant career change from pastor to pentester? 9:42 What are some tips you can give to improve communication skills? 15:51 Is the OSCP still "necessary" for a career in pentesting? 20:20 What is your method for approaching CVE hunting as a complete beginner? 25:47 How important is contributing to open source for Cybersecurity newbies? 32:35 How does the Hack Smarter community work, success stories, and future plans? 37:20 What are your views on "cybersecurity bootcamps" that sometimes charge several thousand dollars? 45:41 Do you think your off-the-cuff content is what a lot of your viewers respond to? 50:22 How much do you recommend platforms like TryHackMe to newcomers in the industry? 53:39 Were you ever tempted to use the hacker name "ThePentestingPastor"?
X: https://x.com/0xTib3rius Bluesky: https://bsky.app/profile/tib3rius.bsky.social Twitch: twitch.tv/0xTib3rius InfoSec Exchange: https://infosec.exchange/@tib3rius LinkedIn: linkedin.com/in/tib3rius Courses: courses.tib3rius.com Udemy: udemy.com/user/tib3rius Discord: discord.com/invite/4qrvKMh TikTok: tiktok.com/@0xtib3rius Instagram: instagram.com/0xtib3rius Threads: threads.net/@0xtib3rius Facebook: facebook.com/0xTib3riusCyber Mentoring Monday!Tib3rius2025-02-04 | Easy boxes, beginner friendly content, come hack & learn with us!Cyber Mentoring Monday! OMG WERE SO BACK.Tib3rius2025-01-28 | Let's hack some boxes and see if I can still hack boxes.PROGAMERS: Super Mario Party JamboreeTib3rius2025-01-23 | Tib3rius plays Super Mario Party Jamboree with endingwithali, lowlevel, and John Hammond!Getting Into Cybersecurity - An Interview with Tanya Janca!Tib3rius2025-01-22 | "Getting Into Cybersecurity" is a series where Tib3rius interviews several people about breaking into the industry. In this episode, Tanya Janca, aka SheHacksPurple shares her extraordinary career journey from software developer to international authority on software security.
Please note, this video is not financially sponsored by Tanya or Semgrep, however Tanya kindly gave me a preview copy of her new book in advance of this interview. I am obliged to disclose this and mark the video as containing a paid promotion.
0:00 Introduction 1:21 How did you get introduced to cybersecurity and what motivated you to transition into cybersecurity itself? 7:09 Have you encountered security-resistant developers and what advice would you give to try and encourage them? 17:33 Do you think we'll see an increasing number of software vulnerabilities linked back to AI, or is AI going to end up a net good? 25:32 Can you share how your own mentors influenced your career journey and how people looking for mentors can find them? 44:06 How much of the storytelling approach do you attribute to the success of your 1st book? Did you tweak anything for the sequel? 49:46 Which section of your book did you find harder to write? And which one did you have more fun writing? 57:33 Is the new book still written with "previous" (dev) Tanya in mind? 1:02:13 What advice do you have for developers looking to enter the actual cybersecurity industry itself? 1:10:11 Do you worry there's more of a focus on profit over investing in security programs at major companies? 1:19:07 Outro
0:00 Introduction 1:16 The Story 2:21 Starting the VM 3:01 Identifying the Hash 4:06 Using Name-That-Hash to Identify the Hash 4:58 Cracking the Hash using John The Ripper 6:47 Extracting the Password Hash from the PDF 8:02 Cracking the Extracted Hash 9:43 Unlocking the PDF using the Cracked Password 10:41 Outro
Monday, Dec 23 @ 4pm UTC - TryHackMe AoC Video! Monday, Dec 23 @ 9pm UTC - Content Creator Christmas Party (Twitch, YouTube, X) Tuesday, Dec 24 @ 7pm UTC - HUGE Giveaway (Twitch ONLY!)
Monday, Dec 23 @ 4pm UTC - TryHackMe AoC Video! Monday, Dec 23 @ 9pm UTC - Content Creator Christmas Party (Twitch, YouTube, X) Tuesday, Dec 24 @ 7pm UTC - HUGE Giveaway (Twitch ONLY!)
Including how not to approach the room, and a brief overview of the code behind it.
0:00 Introduction 1:10 Starting "Lesson Learned?" 3:04 How Not To Solve The Room 4:58 The Intended Solution 7:26 Using Hydra To Enumerate Usernames 10:44 Bypassing The Login Using SQL Injection 12:24 Source Code Review 16:07 Outro
Coffin: https://x.com/coffinxp7 Richard Moore: https://x.com/moore_rich
0:00 Introduction 0:23 Why OR 1=1 is Bad 2:42 Safe OR-Based Payloads for MySQL? 4:51 Explaining Why It Works 7:27 Safe OR-Based Payloads for Postgres, Oracle, and SQLite! 9:09 My Challenge to You! 9:53 Outro
0:00 Introduction 2:04 What are Symlinks? 5:27 Exploiting Symlinks 7:16 Cheesing "The London Bridge" PrivEsc with Symlinks 14:23 Protect Against Symlink Cheese! 16:14 Outro
0:00 Introduction 0:51 New Intruder Layout! 4:19 Match & Replace Bambdas! 5:54 Adding new headers using Bambdas 6:51 Adding multiple headers at once using Bambdas 8:29 Updating JSON parameters dynamically using Bambdas 11:33 Adding random data to a parameter using Bambdas 13:11 Scanning SOAP APIs in Burp! 14:30 Outro