5 videos 📅 2025-08-01 09:00:00 America/New_York
1:43
2025-08-01 09:20:57
3:21:34
2025-08-01 09:23:06
3:24:40
2025-08-01 13:02:23
52:46
2025-08-02 09:03:25
4:52:32
2025-08-02 09:56:41

Visit the Kali Linux Intermediate course recordings page

                WEBVTT

00:00:00.110 --> 00:00:01.370
at our own leisure.

00:00:02.110 --> 00:00:02.530
Okay, good.

00:00:03.810 --> 00:00:04.210
Interesting.

00:00:04.370 --> 00:00:08.130
So, Roger, now, this is going to be a data subrecording that's happening

00:00:08.130 --> 00:00:10.010
that is being stored on reference machines.

00:00:10.530 --> 00:00:13.750
We can also include Zoom share.

00:00:15.190 --> 00:00:16.510
Yes, it could be Zoom share.

00:00:16.730 --> 00:00:19.710
Anything that happens directly on his local workstation.

00:00:19.710 --> 00:00:24.650
The only correction I'll have to say is the recording is not actually happening.

00:00:25.450 --> 00:00:27.070
It's not being stored on his machine.

00:00:27.270 --> 00:00:28.410
It's being stored on our servers.

00:00:29.790 --> 00:00:30.030
Okay.

00:00:30.110 --> 00:00:35.310
So, I don't have to do anything in my Zoom for recordings, that's what I was just looking at.

00:00:36.590 --> 00:00:41.850
I don't know, I mean, you can duplicate recordings if you want, I just don't know how much resources are going to take.

00:00:43.180 --> 00:00:44.220
I'll let you do it.

00:00:46.730 --> 00:00:49.170
So, yeah, let the desktop run the show, I guess.

00:00:49.850 --> 00:00:50.850
Run the show with the desktop.

00:00:53.670 --> 00:00:54.590
Okay, ready?

00:00:57.410 --> 00:01:04.570
So, Rander, you're going to stay here for, I guess, when it's comfortable.

00:01:04.570 --> 00:01:20.450
I'm going to leave you my mobile number with both of you, if you run into any issues, call

00:01:20.450 --> 00:01:21.450
me.

00:01:21.450 --> 00:01:22.450
Okay.

00:01:22.450 --> 00:01:27.790
It's 860-478-7278.

00:01:27.790 --> 00:01:30.200
Okay.

00:01:30.200 --> 00:01:50.360
good luck for the training again any issues let there are my test noise brother is not on

00:01:50.360 --> 00:02:02.000
all righty then okay thank you all thank you very much so just before you guys start if you look at

00:02:02.000 --> 00:02:08.410
the top right in your screen I just sent the message to our little chat window so if there's

00:02:08.410 --> 00:02:13.350
any real like issues there you could always copy and paste or messaging through there but i'll have

00:02:13.350 --> 00:02:20.290
you guys open for a bit i'll watch for a watch for a bit and then uh i'll meet myself and then

00:02:20.290 --> 00:02:24.970
if everything looks like it's moving smoothly then i'll end up hitting the call okay but if

00:02:24.970 --> 00:02:32.830
you could always message me through there yes sir good luck thank you good morning donna how are

00:02:32.830 --> 00:02:39.970
you. Good morning, Dr. West. A lot of technology going on there. Yeah, yeah, we got some stuff

00:02:39.970 --> 00:02:47.630
going on here. What about this week in the world? Holy smokes. Man, this world is crazy, isn't it?

00:02:48.470 --> 00:02:54.510
Yeah, the NNSA got hacked on Monday, the Windows server. Crazy, right? Through the back door,

00:02:54.650 --> 00:03:01.910
the DLL file, SharePoint. Yeah, there is one government agency that I know of that surprised

00:03:01.910 --> 00:03:09.030
me um they're getting rid of all of its windows stuff thank god and all right um windows needs to

00:03:09.030 --> 00:03:17.750
be bulldozed windows have some serious issues so let me put this over here and so you know linux got

00:03:17.750 --> 00:03:25.350
hacked as well the cheroot there and the vms have new four new cves it's crazy right and i wrote a

00:03:25.350 --> 00:03:31.910
paper like how vms are going to have security how security layers layers of defense are going to

00:03:31.910 --> 00:03:39.350
apply to vm it's already happened it doesn't exactly because we we we use linux to hack into

00:03:39.350 --> 00:03:45.750
windows systems and now if they go from windows to linux it's just going to make it easier it just

00:03:45.750 --> 00:03:52.470
doesn't matter whatever the world decides to go to an organization the the bad guys have a way in

00:03:52.470 --> 00:04:02.640
if we if we screw up our defense in depth our um hardening and we lapse for a day that's it

00:04:02.640 --> 00:04:12.380
because everything is automated today yes right yes and you know on the 19th a new ios patch

00:04:12.380 --> 00:04:19.280
came out for apple with 24 new cbes i don't know you're probably an android guy

00:04:19.280 --> 00:04:30.640
yes me yeah i i just that i just saved it saved the number okay thank you oh okay bye

00:04:30.640 --> 00:04:41.660
that was managed okay i'm back my niche good yeah so yeah anyway so times are getting it's

00:04:41.660 --> 00:04:49.420
getting harder and harder to be a human so how do we protect ourselves that's a great question

00:04:49.420 --> 00:04:51.260
And it's a great question.

00:04:53.480 --> 00:05:00.160
And you don't tell people, hey, I'm protected because you'll be the new target.

00:05:01.120 --> 00:05:01.720
Exactly.

00:05:01.940 --> 00:05:05.640
They will somehow, someway get in if they're not already in already.

00:05:08.990 --> 00:05:09.590
All right, then.

00:05:09.590 --> 00:05:16.990
So have you done, Donna, have you done any pen testing at all in your life?

00:05:16.990 --> 00:05:33.380
I've been in cyber labs where we use Wireshark and we use all the tools, but it is not extensive enough to walk away with any knowledge because you have to move on to the next lab so fast.

00:05:33.380 --> 00:05:46.920
You can't lose time. So you don't have time to piddle around with each type of software you get introduced to because in the next lab, you're teaching yourself a whole new platform of software.

00:05:46.920 --> 00:05:53.720
so you just got to keep moving forward so yes and no you know yes i have but not extensively

00:05:53.720 --> 00:06:02.980
okay so the one of one of my goals when i teach pen testing is to teach people how to think

00:06:02.980 --> 00:06:10.940
so that you can do it on your own immediately right and what that's a little bit of a process

00:06:10.940 --> 00:06:17.040
for us, but it's going to be fun. First thing I do in every pen test course that I teach

00:06:17.040 --> 00:06:28.320
is I teach, I show this. All right. So we're going to have the orange jumpsuit discussion

00:06:28.320 --> 00:06:37.200
because I teach a lot of teenagers, even military and adults, and the boys and the girls,

00:06:37.340 --> 00:06:43.240
especially the boys, they are big on, I just want to attack and get inside the network.

00:06:43.960 --> 00:06:50.600
wait a minute do you know what penetration testing really is you know i'm putting on my

00:06:50.600 --> 00:06:56.920
sizzle hat i'm putting on my sock manager hat i'm even putting on my special agent hat um

00:06:57.800 --> 00:07:03.880
we don't brag because we got into an organization when we actually hack into an organization

00:07:03.880 --> 00:07:16.760
successfully that is not a good day tracking in my mind red team is really blue i've actually had

00:07:16.760 --> 00:07:23.320
that discussion at um illinois institute of technology a few years ago red team is really

00:07:23.320 --> 00:07:34.020
blue. Why? Because we write reports at the end of a penetration test. In order to conduct

00:07:34.020 --> 00:07:43.900
a penetration test, we must have written permission. We need to understand the scope of the pen

00:07:43.900 --> 00:07:50.380
test. There are a whole lot of other things we should do too. Let me see. I want to say

00:07:50.380 --> 00:07:59.320
i have some of this stuff written out report writing and post-test actions okay um i actually

00:07:59.320 --> 00:08:07.840
went through the ec council's c pent course certified penetrate that's their top dog

00:08:07.840 --> 00:08:12.180
penetration testing course it hit me upside the head i learned so much

00:08:12.180 --> 00:08:18.480
can you look at my test because i plan on testing for that i missed the first part

00:08:18.480 --> 00:08:25.020
i said do you think it's a worthy certification then because i plan on testing through the ec

00:08:25.020 --> 00:08:37.440
council for peh oh yeah yeah check uh peh oh okay so look at this so i'm gonna show and tell and

00:08:37.440 --> 00:08:45.740
you're going to do in town so i think that's a low number but that's um now when you ask that

00:08:45.740 --> 00:08:54.080
question um whether it's worth or what the value is of something that is a relative statement it

00:08:54.080 --> 00:09:00.780
really depends on what you consider valuable some people think money is of value and oh my god yeah

00:09:00.780 --> 00:09:05.840
and then there are other people who are like um no it's very valuable to make sure my organization

00:09:05.840 --> 00:09:15.920
is safe that these people are safe so um this is probably not accurate in in because where i

00:09:16.720 --> 00:09:23.360
live in virginia i would argue that that could probably be twice as much and just to show you

00:09:23.360 --> 00:09:37.460
an example the GWAP certification through sans usually pays double I've seen double this amount

00:09:37.460 --> 00:09:48.840
it's pro I haven't looked here in a long time but there was a link that literally showed it paid

00:09:48.840 --> 00:09:58.120
about 205 000 a year depends on your experience depends on who you know etc etc with that

00:09:58.120 --> 00:10:06.440
with that said there are a lot of um pen test certifications

00:10:08.440 --> 00:10:15.400
let me try to break it down and categorize them in two categories for you yeah i know these okay i

00:10:15.400 --> 00:10:17.260
I know where you're going. I get it.

00:10:17.660 --> 00:10:22.340
So we have theory tests where you have to memorize and hopefully get the answer correct.

00:10:22.880 --> 00:10:24.760
And then we have the practical side.

00:10:25.720 --> 00:10:31.060
All the CompTIA tests are the memorizing and then all the practical is why I'm here.

00:10:31.500 --> 00:10:36.680
Correct. So what we're going to do, as a matter of fact, let's work and talk simultaneously.

00:10:37.380 --> 00:10:40.160
Can you please open up your terminal?

00:10:40.160 --> 00:10:45.720
you have things to do in front of me that go along with what we just need to do if we were

00:10:45.720 --> 00:10:51.100
doing the job. And we can talk at the same time because some things will require you maybe to

00:10:51.100 --> 00:10:56.540
install stuff. And I want to show you how as well. And I'm also going off about a little

00:10:56.540 --> 00:11:03.340
cheat sheet here. I'm going to give you, I'm going to do my best to give you exactly what

00:11:03.340 --> 00:11:13.000
you ask for so how do i get into my screen oh the desktop because i see your screen now i see you

00:11:13.000 --> 00:11:18.360
your face and your your screen i can't get into mine seems like so you're going to have to work

00:11:18.360 --> 00:11:29.980
on your computer do you have two screens on one i have one oh oh okay so so that's the thing i

00:11:29.980 --> 00:11:44.740
minimize uh pull up your one screen and then um did you see the desktop yet

00:11:46.420 --> 00:11:52.020
i see yeah i see the desktop but i don't have it's under your control i can't get it

00:11:52.660 --> 00:12:00.420
how do i get it no no no no um minimize this screen and pull up your the desktop

00:12:00.420 --> 00:12:18.520
okay there we go okay now yes now open up a terminal uh you can either right click and click

00:12:18.520 --> 00:12:25.240
open terminal or you can click on the little black box next to firefox up there right there

00:12:25.240 --> 00:12:36.240
yay now i just can't see it i'm gonna go big all right i'm here okay so you won't be able to see

00:12:36.240 --> 00:12:44.080
the zoom screen, you can see your personal screen. Yeah, I can hear you. That's okay. Okay.

00:12:44.800 --> 00:12:49.620
If we had, that's what I was going through earlier. So I have two, I have three, three

00:12:49.620 --> 00:12:55.560
screens. One where I see you, one where I can see the desktop and I have another one where I can see

00:12:55.560 --> 00:13:02.600
my desktop as well. So what I would like for you to do is make this screen larger, right? The

00:13:02.600 --> 00:13:14.190
terminal so I want you to press control shift plus plus plus make sure you're

00:13:14.190 --> 00:13:20.790
inside the terminal otherwise it won't work yeah I'm up to 150% you want bigger

00:13:20.790 --> 00:13:31.050
oh I didn't see any change on my end are you not change at all I did control

00:13:31.050 --> 00:13:52.000
now control shift plus plus plus hey there you go beautiful yay good now do you know how to

00:13:52.000 --> 00:14:01.550
update your terminal i believe i did that um but let's uh let's go through it okay so check this

00:14:01.550 --> 00:14:09.310
out in this world when or if you don't know anything the foundation for success is research

00:14:09.310 --> 00:14:16.230
most of the actual hackers that i know that have actually been arrested that i and i just know

00:14:16.230 --> 00:14:25.230
real live hackers they never sat in any class they didn't pick up a book they just started

00:14:25.230 --> 00:14:32.670
googling and trying stuff i learned a lot about that so you're going to type um sudo do you know

00:14:32.670 --> 00:14:44.030
what sudo means yes okay can you tell me at least two definitions or acronyms um it is just um an

00:14:44.030 --> 00:14:54.240
administration file to get to wake up the terminal okay so what does s-u-d-o mean it is a root

00:14:54.240 --> 00:14:59.040
command not that like the literal letters what does pseudo mean

00:15:01.760 --> 00:15:14.880
question ah okay so go ahead and type pseudo we're going to find out in a minute space apt space

00:15:16.880 --> 00:15:26.440
update press enter yay so what we're doing is we're updating all of the different packages

00:15:26.440 --> 00:15:32.440
and programs within the terminal so if we're going to do an actual live pin test we definitely need to

00:15:32.440 --> 00:15:40.600
make sure we have the latest packages so this is a mandatory thing that every pin tester needs to do

00:15:40.600 --> 00:15:47.000
every security administrator needs to do so this is something um uh that you want to write down

00:15:47.000 --> 00:15:53.960
someplace in your notes the what are you using to take notes i have a notebook right here how

00:15:53.960 --> 00:16:02.760
about digital notes um i memorize it usually okay i'm going to show you something okay

00:16:04.680 --> 00:16:15.880
all right by the way hit the up arrow one time backspace and erase date the backspace button

00:16:15.880 --> 00:16:25.960
erase the word date type in the word grade g-r-a-d-e space tack y or dash y

00:16:27.720 --> 00:16:35.320
dash y press enter there you go after you do an update you must do an upgrade they come together

00:16:35.320 --> 00:16:43.320
as a package okay so i know your hand written notes are going to be fantastic but the reason

00:16:43.320 --> 00:16:51.080
why i want to show you how to take digital notes is because as a pen tester is much faster manual

00:16:51.080 --> 00:16:57.960
pen testing is something that a lot of pen testers really don't do unless they absolutely have to

00:16:59.160 --> 00:17:05.400
they're going to um do automated pen test we're going to learn manual pen tests because that's

00:17:05.400 --> 00:17:11.480
the foundation before you get to all that those fancy tools that are out there um there are

00:17:11.480 --> 00:17:15.960
organizations out there that they will sell you these tools and they're upwards of twenty five

00:17:15.960 --> 00:17:23.000
thousand dollars or more and then what the pen test the dark side community or the really good

00:17:23.000 --> 00:17:29.720
pen testers is they make their own tools they go to python they start making the whole bunch

00:17:29.720 --> 00:17:38.330
of different tools and they just go off and they just save the world and look at this this upgrade

00:17:38.330 --> 00:17:47.530
takes a while. So it's a good idea that is really good that we're showing this. When this finishes,

00:17:47.670 --> 00:17:54.310
I'm going to show you something. Feel free to either type the question or ask questions so that

00:17:54.310 --> 00:18:01.630
you have full understanding for anything. Okay? Yes, sir. Fantastic. All right. So when we open

00:18:01.630 --> 00:18:06.690
up, you're going to do a brand new pen test and we're actually about to do some actual work.

00:18:06.690 --> 00:18:16.310
remember pseudo apt update so i'm going to kind of help you out a little bit i'm going to google

00:18:16.310 --> 00:18:22.830
can you see it no you don't see my screen anymore okay because you're on your terminal

00:18:22.830 --> 00:18:32.310
let me see mine okay so then let's do this then oh good click on the firefox icon

00:18:33.250 --> 00:18:47.460
Yeah, you got ambitious. You got a lot of them click either. Yeah. Yeah. Yeah. Yeah. Yeah. Go ahead and close one of

00:18:50.420 --> 00:18:52.420
Blue X in the top right

00:18:52.420 --> 00:18:55.320
Oh, but it's like oh, there we go. There you go

00:18:56.480 --> 00:19:00.740
Now go inside the browser of that Firefox

00:19:08.820 --> 00:19:10.820
Just click in the browser. Don't worry about anything else

00:19:16.050 --> 00:19:19.050
There you go. And you're gonna type a simple question

00:19:19.050 --> 00:19:30.360
question what does pseudo mean in linux you you put it on chat it's fine too and uh what does

00:19:30.360 --> 00:19:42.260
pseudo mean in linux okay now i'm gonna let you turn user do i should have known that or

00:19:44.020 --> 00:19:50.980
substitute user do yes so it's just something that you should know as a uh cyber security

00:19:50.980 --> 00:19:57.380
professional doing pen testing right so we're adding bullets to the things that you'll learn

00:19:57.380 --> 00:20:25.590
now i need you to type in what does apt mean in linux so now i would like for you to read

00:20:25.590 --> 00:20:33.910
the command to me with the translation that you just learned pseudo apt um update what does that

00:20:33.910 --> 00:20:42.870
mean so it is uh super user do for advanced tool package uh updating the software packages that are

00:20:42.870 --> 00:20:49.910
already on cali right so the literal translation is super user do advanced package tool update and yes

00:20:49.910 --> 00:20:55.670
you just finished it off with the end fantastic and then of course the upgrade uh we the reason

00:20:55.670 --> 00:21:02.550
why we put the dash y on it in is because we're telling the program yes in advance because when

00:21:02.550 --> 00:21:08.230
we do the upgrade it'll ask do you want to continue with this installation you have a choice yes or no

00:21:09.670 --> 00:21:18.870
okay so that's basic scripting right um so now i want to go back to the terminal

00:21:18.870 --> 00:21:34.580
click on a terminal right behind it let me know when you're there hit the up arrow press press

00:21:34.580 --> 00:21:46.870
ctrl a what happened when you did that it's the upgrade feature no press press ctrl e now and

00:21:46.870 --> 00:21:59.340
watch watch the cursor now press ctrl a again move the cursor back and forth right so a brings it to

00:21:59.340 --> 00:22:06.620
the beginning e brings it to the end now i want you to use the arrow and put it on top of the a for

00:22:06.620 --> 00:22:23.430
apt one two three four five arrow it's not loading the cursor the arrow the arrow there you go got it

00:22:23.430 --> 00:22:33.110
type in the word full f-u-l-l no i'm sorry backspace that put the full on top of the u for upgrade

00:22:34.950 --> 00:22:39.590
use the arrow key the mouse won't work so you got to use the arrow key because you're in linux

00:22:39.590 --> 00:22:47.370
now put a dash full dash upgrade no space oh

00:22:47.370 --> 00:22:58.970
right but no space no space so take the goal um put the cursor is that i can't see like uh

00:22:58.970 --> 00:23:09.870
i can't hang on now i lost it oh you can't see like your terminal so this is what we'll do i'll

00:23:09.870 --> 00:23:16.710
stop sharing you share your terminal and I'll work from here stop share you go

00:23:16.710 --> 00:23:22.110
ahead and share go actually I don't think that's gonna work either because

00:23:22.110 --> 00:23:31.770
you still need to be typing on your desktop right my desktop so this okay

00:23:31.770 --> 00:23:40.810
so where's hi hi again share where's my screen um hold on um let me share god let me share my screen

00:23:40.810 --> 00:23:58.300
again i i i think i see what's going on here screen three share okay um i'm thinking okay

00:23:58.300 --> 00:24:04.380
so there i was but it disappeared and um i'm gonna hit share no but i already did

00:24:06.140 --> 00:24:11.660
all right so do you see me do you see my screen that i was now now now i see your screen let's

00:24:11.660 --> 00:24:19.020
work it like that and i'm gonna move mine over here so i can see both screens you're gonna do

00:24:19.020 --> 00:24:33.140
all the work okay yeah now good now take the space out of full or after you just had a little

00:24:33.140 --> 00:24:40.980
bit mm-hmm uh dana your um your browser windows very zoomed in if you hold control and use your

00:24:40.980 --> 00:24:58.550
mouse wheel to scroll down okay so can you guide me to where my screen went oh you went back pretty

00:24:58.550 --> 00:25:04.500
It's probably the desktop, right?

00:25:04.500 --> 00:25:08.500
Yeah, go to the desktop login.

00:25:08.500 --> 00:25:15.260
I think you can back to the middle tab of your browser window.

00:25:15.260 --> 00:25:19.260
So this is the Zoom call.

00:25:19.260 --> 00:25:23.260
Go to the one that says the desktop participant join.

00:25:23.260 --> 00:25:27.260
You can close that.

00:25:27.260 --> 00:25:29.260
Don't close the Zoom window.

00:25:29.260 --> 00:25:34.020
I've got two of them up. All right, so...

00:25:34.020 --> 00:25:38.020
Okay, so if you could just...

00:25:38.020 --> 00:25:46.740
The one that says desktop login here, if you look at the top of your browser tab.

00:25:46.740 --> 00:25:47.740
Yes.

00:25:47.740 --> 00:25:54.740
So the top that says desktop login here at the very, very top of the browser window.

00:25:54.740 --> 00:26:00.700
Or you could hit...

00:26:00.700 --> 00:26:02.700
Here, okay, so...

00:26:02.700 --> 00:26:06.700
Oh, so the tab itself. So you're currently in this tab, I want you to go to the third tab.

00:26:06.700 --> 00:26:30.820
Yeah, it's just cute.

00:26:30.820 --> 00:26:33.820
So your mouse is, are you having issues with your mouse right now?

00:26:33.820 --> 00:26:38.820
Yeah, it is just acting bizarre, so I don't know.

00:26:38.820 --> 00:26:41.820
You can do control three.

00:26:41.820 --> 00:26:43.820
Okay, so you see it?

00:26:43.820 --> 00:26:49.820
Yeah, if you could log, I guess you could log back in or you could hit forward.

00:26:49.820 --> 00:26:51.820
It looks like you went back a few times.

00:26:51.820 --> 00:26:53.820
But yeah, you log back in, yeah.

00:26:53.820 --> 00:27:20.600
The course itself, it says organization course thing, yeah, right here.

00:27:20.600 --> 00:27:35.720
so now i'm closing up the space there you go hit the backspace again hit backspace twice

00:27:37.560 --> 00:27:49.880
now put a dash now put a dash uh now press uh enter i'm just gonna keep this screen here so

00:27:49.880 --> 00:27:58.040
and not mess around with it okay i'm ready all right now um there are various types of uh thanks

00:27:58.040 --> 00:28:05.720
roger there are various types of um commands you're going to need to find a list of update

00:28:05.720 --> 00:28:13.960
and upgrade commands for kali linux can you go to um firefox right there in your tab and let's find

00:28:13.960 --> 00:28:25.210
that can i look at can i use chat gpt um yes you can um when you when it comes to research

00:28:26.170 --> 00:28:30.650
if you're in an environment let's say you work in a sock and you're a pen tester there

00:28:31.370 --> 00:28:39.850
they may not have chat gpt so i want you to when you do research google it click on images

00:28:39.850 --> 00:28:49.830
videos and um of course ai software are excellent resources and there's more that you can add for

00:28:49.830 --> 00:28:56.810
that so go ahead can you yes you can you can research it any way you can but i'm going to

00:28:56.810 --> 00:29:03.390
show you why you want to do it the way i in a minute as soon as you find that all right so

00:29:03.390 --> 00:29:10.430
what are upgrade commands for linux is what you wanted me to ask i'm asking google cali linux

00:29:11.470 --> 00:29:20.430
just type in cali cali linux update and upgrade commands list or commands you want the list

00:29:20.430 --> 00:29:26.270
you want the list i want the list yeah well i have the brain all over the place i just okay

00:29:26.270 --> 00:29:36.610
i have it okay fantastic okay how many do you see a lot yeah well yeah so these are things that

00:29:36.610 --> 00:29:41.450
you are expected to know if you're going to be pen testing in the real world and i just wanted to

00:29:41.450 --> 00:29:51.650
show you uh i wanted to show you what they are um if you don't mind can you copy the list if it's

00:29:51.650 --> 00:29:57.390
small enough put it inside the chat so i can see your list i'm a little bit disadvantaged because

00:29:57.390 --> 00:30:14.410
i can't see the screen the way i normally could dr weston you can also open up one note in

00:30:14.410 --> 00:30:25.340
in uh your desktop here so yes i know yeah display yeah okay i um i actually want to get her to

00:30:25.340 --> 00:30:28.220
do it i have a reason

00:30:28.220 --> 00:30:33.800
okay no worries okay well thanks i'm gonna close this

00:30:33.800 --> 00:30:41.080
um donna did you put um do you do you know where the chat is or you don't know

00:30:41.080 --> 00:30:47.420
the same list i have a broken up um like a bunch of different commands so i'm gonna do

00:30:47.420 --> 00:30:52.300
use that and go to firefox is there a url that you can put in there

00:30:52.300 --> 00:31:01.800
um it's it's a lot quicker that way i can just click on it

00:31:01.800 --> 00:31:09.360
no i don't okay here we go i'm going to show you

00:31:09.360 --> 00:31:13.540
something okay yeah i'm gonna um

00:31:13.540 --> 00:31:23.680
okay let's come over here that's what i hate google never gives you a list of

00:31:23.680 --> 00:31:30.640
anything it's just a convoluted nightmare so i don't have a list i have a bunch of commands um

00:31:31.280 --> 00:31:43.470
this is in gpt right oh my god i got it all right okay let's see i got a copy

00:31:45.310 --> 00:32:04.860
best way to do this is here oh i can't type okay let's do it this way it's just that i can't see

00:32:04.860 --> 00:32:22.510
the screen minus a little bit tiny too all right so maximize your screen again

00:32:23.310 --> 00:32:33.420
if you remember that x that i told you to click but then i keep and you can always escape out of

00:32:33.420 --> 00:32:46.620
here to go back okay like you want this one how's that oh that's fantastic oh that looks like the

00:32:46.620 --> 00:32:57.160
the whole directory um um then updates command line guide I'll just Google that

00:32:57.160 --> 00:33:12.460
is a big man that's with Linux blog and then I'll get this I have the URL now oh yeah that's

00:33:12.460 --> 00:33:22.920
I mean, that's, you know, a bunch of different packages that are actually updated on that particular update.

00:33:22.920 --> 00:33:30.360
But underneath it, you know, we are. OK.

00:33:30.360 --> 00:33:40.360
OK, so depending on the flavor of Linux that you're using, by the way, Kali Linux is a Debian, D-E-B-I-A-N flavor.

00:33:40.360 --> 00:33:45.360
They use the APT or advanced package to command.

00:33:45.360 --> 00:33:55.400
command so that's why we type in sudo apt update or upgrade or full upgrade etc okay but if you're

00:33:55.400 --> 00:34:01.860
actually using a tool such as uh debian on ubuntu use the same but if you're using something like

00:34:01.860 --> 00:34:11.540
like red hat or fedora then they're going to use the dnf command to replace apt we cool

00:34:12.480 --> 00:34:13.900
Yep, I'm with you.

00:34:13.900 --> 00:34:22.560
And if we're using BlackArch Linux or Arch Linux, we'll replace APT or DNF with Pac-Man.

00:34:22.980 --> 00:34:37.300
So it behooves us to understand and know the flavor of Linux that we're using so that we can actually apply the appropriate package tool upgrade feature.

00:34:40.150 --> 00:34:40.570
Yes, sir.

00:34:40.850 --> 00:34:41.870
Okay, good, good, good, good.

00:34:41.870 --> 00:34:47.680
Okay, so now, do you know how to find your IP address?

00:34:51.430 --> 00:34:52.470
Not exactly.

00:34:52.990 --> 00:34:55.010
Okay, just type in the word.

00:34:55.530 --> 00:34:56.990
So, okay, hold on.

00:34:57.770 --> 00:34:58.910
Let me show you this real quick.

00:34:58.990 --> 00:35:00.070
I've got to show you this.

00:35:01.130 --> 00:35:02.550
How do I show you this?

00:35:02.730 --> 00:35:06.250
Because I need to, I can't show you on this screen because it's too small.

00:35:07.470 --> 00:35:11.170
So I'm going to need you to just find the stop share button, stop sharing.

00:35:11.170 --> 00:35:13.910
I'm going to share my screen real quick, and it will come back.

00:35:15.490 --> 00:35:29.610
Fantastic. So, I'm going to share my screen. Hit the share button. Share screen three. Share. Okay. Can you see my screen?

00:35:30.530 --> 00:35:30.950
Yes, sir.

00:35:30.950 --> 00:35:35.990
All right. I'm going to come back over here and I'm going to type pen test.

00:35:36.350 --> 00:35:45.870
Today, we're going to do several pen tests and we're going to be a little bit aggressive with it because I want to make sure we can get in all the boxes.

00:35:46.590 --> 00:35:59.270
But I want to answer all your questions. What I want you to do is to look at, say, some of the previous pen tests that I've done in my life.

00:35:59.270 --> 00:36:12.540
um this is actually info set prep which is oscp certification and look at how i took my notes

00:36:12.540 --> 00:36:24.780
it's a little tiny on purpose but i can make it bigger so i documented the project or the task

00:36:24.780 --> 00:36:34.420
the objective um i documented the actions or the screenshots the commands the basic information

00:36:34.420 --> 00:36:41.080
and definitions and what I learned. Because remember, we are actually testing someone's

00:36:41.080 --> 00:36:51.200
security defenses, hence penetration tests. In other words, back in the day, I used to

00:36:51.200 --> 00:37:01.720
do pen tests, physical pen tests of the airport. This is before 9-11. And I'm looking around to

00:37:01.720 --> 00:37:08.280
study how these people would leave the door and they would close really slow and then i would walk

00:37:08.280 --> 00:37:13.940
over there real quick and and i would drop something and leave it like a little hard item

00:37:13.940 --> 00:37:21.420
and then i walked back over and push it with my foot and when someone left and they closed the door

00:37:21.420 --> 00:37:26.620
it wouldn't close all the way and then i walked over and said oh man what's this and i picked it

00:37:26.620 --> 00:37:33.420
and walked inside and i got in the airport very successful right um it was it's crazy right it's

00:37:33.420 --> 00:37:41.420
that that is um an example of how we get in we sit on the side and we look at

00:37:42.940 --> 00:37:50.540
um we look for vulnerabilities right when i'm sitting on the side i'm information gathering

00:37:51.160 --> 00:37:55.240
So I'm sure, are you familiar with the penetration testing step?

00:37:55.260 --> 00:37:57.740
Well, recon being the first one, like you're saying.

00:37:57.960 --> 00:37:58.240
Right?

00:37:58.640 --> 00:38:03.360
So reconnaissance, information gathering, they kind of fall in the same boat.

00:38:04.460 --> 00:38:10.340
There's passive information gathering and then active information gathering.

00:38:11.280 --> 00:38:15.440
You know, passive, I was just sitting on the side, hanging out and taking notes, right?

00:38:15.880 --> 00:38:19.140
Active is when I'm starting to actually start to touch and feel.

00:38:19.140 --> 00:38:25.220
you know maybe i'm looking for hey this door is unlocked you know that type of thing and if i

00:38:25.220 --> 00:38:29.560
walked in and someone saw me hey man this door was unlocked i was just trying to let somebody know

00:38:29.560 --> 00:38:36.940
but i was really trying to get in so if i got busted i had to come up with a tagline to get

00:38:36.940 --> 00:38:47.500
out of the situation okay um so yes um when i i need to show you how to take these notes

00:38:47.500 --> 00:38:56.810
like this. Today, we're going to do it the hands-on way. Then tomorrow, we'll start to

00:38:56.810 --> 00:39:04.190
use different tools to take notes for us. You need to understand the basics from the beginning.

00:39:04.790 --> 00:39:11.790
These are a variety of different pen tests. And I can show you how to do this in your OneNote.

00:39:13.370 --> 00:39:19.930
Or I can even show you myself. And I'll add a page real quick. And I'll just put

00:39:19.930 --> 00:39:29.530
um donna pen test let me show you how to use one though okay and i'm just gonna say uh

00:39:31.850 --> 00:39:42.250
project name tab it over commands tab i'm saying these words on purpose right um

00:39:42.250 --> 00:39:59.490
screenshots tab analysis tab lessons learned then I'm going to press enter to give me a new line

00:39:59.490 --> 00:40:11.190
and let's say today we're going to do basic pen testing tab and then I'll come over to lessons

00:40:11.190 --> 00:40:23.260
learn press enter and then i'll put in um let me see um information gathering or reconnaissance

00:40:25.260 --> 00:40:33.640
you can spell that right and fix that even before i do that i'm gonna i'm gonna i'm doing this on

00:40:33.640 --> 00:40:42.200
purpose i'm gonna go to table and i'm gonna add a row below so if i missed something i can just

00:40:42.200 --> 00:40:49.720
put in here let me see um rigid for written permission and maybe i'll add another line

00:40:51.400 --> 00:41:03.000
below and say uh scope of work i can go on and on right as i continue here then i can talk about um

00:41:03.000 --> 00:41:22.900
um, denumeration, uh, maybe, uh, exploit, uh, oh, enter exploitation, um, um, um, whatever

00:41:22.900 --> 00:41:36.400
our phases are, so let me see, phase, pen test, pen test, let me go to Google, because

00:41:36.400 --> 00:41:49.970
i don't know where i have it move this here up there pen test uh i don't know if it's phases or

00:41:51.090 --> 00:41:56.930
i don't know why i asked the word for the day so here we go reconnaissance scanning

00:41:57.970 --> 00:42:03.970
vulnerability analysis exploitation post exploitation and reporting

00:42:03.970 --> 00:42:12.030
depending on the certification you're learning the names or the the phases will be slightly

00:42:12.030 --> 00:42:21.450
different ceh is different from pentest plus both of them are different from c pent they may be

00:42:21.450 --> 00:42:29.090
slightly different from oscp do you understand yes fantastic i just want to make sure you

00:42:29.930 --> 00:42:30.890
Why is that over there?

00:42:31.050 --> 00:42:34.430
I just want to make sure you understand that there are some differences.

00:42:34.950 --> 00:42:37.510
We adapt and overcome no matter what they are.

00:42:39.130 --> 00:42:39.470
We do.

00:42:39.910 --> 00:42:42.250
So now we have that.

00:42:42.370 --> 00:42:44.970
I'll come back to my OneNote really quickly.

00:42:47.230 --> 00:42:47.790
Commands.

00:42:47.790 --> 00:42:51.890
Let's just say, let me add a new line.

00:42:52.810 --> 00:42:55.210
Table, insert below.

00:42:55.970 --> 00:42:56.150
Right?

00:42:56.290 --> 00:42:56.710
Let me see.

00:42:58.470 --> 00:42:58.990
Update.

00:42:59.730 --> 00:43:06.770
and upgrade commands this is just an example not exactly like it belongs here but i'm going to type

00:43:06.770 --> 00:43:17.970
sudo apt update you can even combine the commands two ampersigns sudo apt upgrade tag y

00:43:19.170 --> 00:43:26.530
right stress this out if i need to i come here and i'm actually on my terminal on my computer

00:43:26.530 --> 00:43:34.500
now on purpose because i want to make sure it's big enough so you can see it so if i type my command

00:43:34.500 --> 00:43:43.940
apt update control e press enter it goes through its process and now okay i see what i need to see

00:43:43.940 --> 00:43:54.340
i go back to my one note screenshots go to insert screen clipping highlight what i need

00:43:54.340 --> 00:44:11.120
let it go this is the old-school manual pen testing right analysis I upgraded

00:44:11.120 --> 00:44:29.780
the machine I updated and upgraded I'll say Linux to ensure all packages were

00:44:29.780 --> 00:44:45.230
are ready for the pen test see how that works yep fantastic i'm hoping that this is helpful

00:44:45.230 --> 00:44:53.750
for you because when i teach my students um do you see how many pen tests i have here

00:44:53.750 --> 00:45:02.450
and actually it's not a lot there i have a lot of tests here where i make them take notes from the

00:45:02.450 --> 00:45:09.150
beginning because everyone wants to pen test but no one wants to take notes so

00:45:09.150 --> 00:45:14.610
let's just I like I like how yours is in block format the old school because we

00:45:14.610 --> 00:45:20.070
just got out of operating systems where we had to APA report our screenshots and

00:45:20.070 --> 00:45:26.010
it's a drag because this is the real way to do it right so check this out let's

00:45:26.010 --> 00:45:33.270
just say, I'm going to type Splunk. This is when I installed Splunk Soar. I have screenshots

00:45:33.270 --> 00:45:42.630
galore, everything that I do. Sometimes I've installed Splunk Enterprise. Any and everything

00:45:42.630 --> 00:45:51.270
that I do, let me see. Go off to the SOC, take screenshots of the work, have the answers.

00:45:51.270 --> 00:46:04.870
As a SOC manager, you must take digital notes while doing the work, period, is for your report.

00:46:04.870 --> 00:46:06.270
Because of the timestamp, yes.

00:46:06.710 --> 00:46:08.030
All kinds of reasons.

00:46:08.970 --> 00:46:14.730
In one note, I taught within the Alabama Cybersecurity Fellowship.

00:46:17.790 --> 00:46:20.730
I'm able to share this with the team so I can keep up.

00:46:21.230 --> 00:46:23.110
I gave them all their tasks.

00:46:23.570 --> 00:46:30.790
I'll put an example. These are all the people that are here. I have a whole bunch of different

00:46:30.790 --> 00:46:39.870
tasks here. Look at the screenshots of all the work they've done. Why did I do this? Because

00:46:39.870 --> 00:46:47.070
when I was the SOC manager and the CISO in the government, we had OneNote. That's one.

00:46:47.810 --> 00:46:54.690
Two is OneNote, I had the ability to sync books and share them with my team.

00:46:55.350 --> 00:47:04.970
When I was off site and needed an update, I could pick up my government phone on my laptop and I can actually scroll in and see who did what worked.

00:47:05.970 --> 00:47:12.950
Because the goal for me when I teach students is to turn schoolwork into work.

00:47:12.950 --> 00:47:22.710
when you we get out of the everyone wants to be shown how to do it i want my students to show me

00:47:22.710 --> 00:47:29.450
how to do it i'll sit here like this and say what are you thinking this is what i'm thinking

00:47:29.450 --> 00:47:34.190
and then you're going to research it and you're going to do it i have a whole formal process

00:47:34.190 --> 00:47:41.970
that has nothing to do with no prob outside of here but what i need you to do is to actually

00:47:41.970 --> 00:47:48.130
do that here on your one note so i would actually

00:47:48.130 --> 00:47:57.730
i think what i'm going to do right now is not share my screen and i want you to make

00:47:57.730 --> 00:48:04.120
your screen full let me see if i can do that how do i do that

00:48:04.120 --> 00:48:13.360
so the bottom at the bottom right of her uh team you can hit the x

00:48:13.360 --> 00:48:15.380
or you can pop it out

00:48:15.380 --> 00:48:17.400
of her pain or my pain

00:48:17.400 --> 00:48:19.060
I want to not share my screen

00:48:19.060 --> 00:48:21.300
yeah you can just

00:48:21.300 --> 00:48:23.160
see her screen is that what you want to share

00:48:23.160 --> 00:48:25.180
her screen okay alright

00:48:25.180 --> 00:48:27.060
I got you so I'll make her screen

00:48:27.060 --> 00:48:30.230
uh oh bigger

00:48:30.230 --> 00:48:32.470
can you pop it up you can make that you can maximize

00:48:32.470 --> 00:48:34.610
your screen now okay well can she

00:48:34.610 --> 00:48:36.270
see her screen big like this

00:48:36.270 --> 00:48:38.630
she could do that too

00:48:38.630 --> 00:48:40.550
um Donna are you

00:48:40.550 --> 00:48:42.450
able to maximize your screen via

00:48:42.450 --> 00:48:43.910
the X at the bottom of your pain

00:48:48.490 --> 00:48:58.140
no because it's like it's on his screen now so maybe i can oh yeah okay so yeah it's on dr wess's

00:48:58.140 --> 00:49:06.740
so i need it to flip back to mine and then i can hit the x yeah how about now i mean i'm still seeing

00:49:06.740 --> 00:49:17.130
yours but um i just i just clicked on the word interactive there we go now something's happening

00:49:17.130 --> 00:49:24.970
i did something because what i'm seeing is just the zoom link

00:49:26.170 --> 00:49:31.930
same so i see yeah okay so you you just see the zoom link i don't know so you gotta just minimize

00:49:31.930 --> 00:49:40.810
minimize zoom and go back to the desktop yeah yeah and then i can shrink it with control

00:49:42.570 --> 00:49:51.270
how do i shrink how do i shrink the size the size of the browser or the journal

00:49:51.270 --> 00:49:56.710
Okay, that's all right. I'll use it like this. All right. I'm ready. Thank you. Can you just click on

00:49:56.710 --> 00:50:01.090
If you click on a full screen will that make will that take over my screen?

00:50:01.210 --> 00:50:05.310
So that's what I'm hoping it would do. I have a full screen right now. You do

00:50:05.310 --> 00:50:07.670
Okay, that's fine

00:50:07.670 --> 00:50:12.270
I got it now long as she has a full screen. I'm good

00:50:12.270 --> 00:50:15.510
Okay, let's get into this pen test, right?

00:50:16.410 --> 00:50:18.450
Um, one of the things that

00:50:18.450 --> 00:50:26.050
uh using update update updating kali linux so you kind of have that cheat sheet you know how to do

00:50:26.050 --> 00:50:32.770
that and you've also a chat gpt-ing it i want to make sure you understand that can you yes i

00:50:32.770 --> 00:50:38.130
understand can you show or tell me how to install kali linux from scratch if you have to do this in

00:50:38.130 --> 00:50:48.000
the real world well yeah i would i would uh create a new vm and put um kali in it okay it's not

00:50:48.000 --> 00:50:56.400
really i mean so you know how to do that yes sir okay um i have written instructions on how to do

00:50:56.400 --> 00:51:02.320
that with my screenshots that's why i asked but you can google them anyway so we we are covering

00:51:02.320 --> 00:51:10.000
the introduction portion um i i have cali already on a virtual machine and i have parrot already on

00:51:10.000 --> 00:51:19.520
a virtual machine fantastic um okay um by the way in the in the if you want to sit for a ceh exam

00:51:19.520 --> 00:51:27.520
or any ec council exam they require you to use parrot security versus um cali lennox that was

00:51:27.520 --> 00:51:33.040
a new change a few years ago so it's a really good idea to learn how to do installations

00:51:33.040 --> 00:51:38.880
you know um like um on this machine right here can you install steam locomotive real quick

00:51:38.880 --> 00:51:47.960
do you know how to do that um no because no this is good i mean i know that you type it in and hit

00:51:47.960 --> 00:51:53.960
yes but i don't know like how you we're going to get you to know it that's fantastic let's do it

00:51:53.960 --> 00:52:05.750
click on our firefox real quick and i want you to type that question how to install steam locomotive

00:52:05.750 --> 00:52:35.520
on cali linux just so you know this is all pin testing even these installations to install steam

00:52:35.520 --> 00:52:46.420
locomotive calendar which is a debian ppt scroll down show more okay do you see that command right

00:52:46.420 --> 00:52:59.280
there sudo apt install sl yes sir go ahead and type that in case sensitive so make sure it's not

00:52:59.280 --> 00:53:12.130
capitalized i see that sudo now i lost my firefox case um go ahead get it yeah i don't i don't have

00:53:12.130 --> 00:53:31.760
I lost my firebox oh sure apt space install space SL got it enter okay something is happening it

00:53:31.760 --> 00:53:40.880
looks like it's actually working okay now type SL in period let me enter SL enter yes there you go

00:53:40.880 --> 00:53:49.680
you just install steam locomotor um not terribly difficult to do is it you just need to know how

00:53:49.680 --> 00:53:58.180
you can also uninstall it or remove it by just replacing install with remove so these are

00:53:58.180 --> 00:54:03.180
basic things that you're going to know you may find yourself in a situation you're doing a pen

00:54:03.180 --> 00:54:09.820
test and you have to install something you need to know how to do that right yes i do it's just that

00:54:09.820 --> 00:54:16.020
we can we keep switching back between linux commands like i go to fedora i have one then

00:54:16.020 --> 00:54:21.120
i go to ubuntu i have another then i go back to cali i have another so i don't have them

00:54:21.120 --> 00:54:27.160
committed to memory so i always pull up the list good the cheat sheet yeah don't worry about

00:54:27.160 --> 00:54:35.380
committing it to memory the muscle memory will come the foundation the the basement of a house

00:54:35.380 --> 00:54:44.180
right is to research it period yeah right in in time oh yeah you're going to memorize it you're

00:54:44.180 --> 00:54:51.960
going to spit it out just like i'm doing it um what i try not to do um the my methodology of teaching

00:54:51.960 --> 00:54:59.040
is you do the work you're going to teach me and uh i'm going to learn from what you do and teach

00:54:59.040 --> 00:55:08.480
then i'm going to do the same thing so um now i want you to install rig well go ahead and do it

00:55:08.480 --> 00:55:35.380
rig rig and looks like you do the command how do you run rig how do i run a rig no how do you run

00:55:35.380 --> 00:55:43.940
what you just installed yes no look at what's happening what did you do with the steam locomotive

00:55:50.150 --> 00:55:57.830
that's the steam locomotive now i want you to run rig i gotta type in rig there you go i got it

00:55:57.830 --> 00:56:09.350
yes sir fantastic okay now i want you to show i'm going to show you another way to install a command

00:56:09.350 --> 00:56:23.960
okay type in tl dr it may not work press enter okay see it and that's why see what it says teal

00:56:23.960 --> 00:56:35.200
deer just type in the word teal deer not the apt stuff oh keep it together type what you see

00:56:35.200 --> 00:56:52.490
remember the words are together backspace third line till till deer press enter oh it didn't work

00:56:52.490 --> 00:57:05.690
yeah okay type in type in um pac-man p-a-c-m-a-n press enter oh see that that's what i was trying

00:57:05.690 --> 00:57:19.740
show you is asking you a question say yes yes say yes read it make sure you read it yes okay

00:57:20.620 --> 00:57:27.900
the lesson here is to make sure we always read the outputs so as pen testers we need to read the

00:57:27.900 --> 00:57:39.820
inputs and read the outputs now type pac-man press enter oh it failed could not create the database

00:57:39.820 --> 00:57:46.380
probably because we're on this particular lesson here but that's okay so now hit the up arrow twice

00:57:49.900 --> 00:58:15.900
press ctrl a type sudo base apt space install space enter you'll be coming a master at installing

00:58:15.900 --> 00:58:27.640
stuff now i want you to go ahead type q deer see what does all right now type tldr press enter

00:58:27.640 --> 00:58:34.600
okay that is the command right there that's the shortcut so now hit the up arrow one time space

00:58:36.120 --> 00:58:48.520
and type um sl enter okay see the error message um run tldr space tac tac

00:58:48.520 --> 00:59:00.290
update to download the cache. So go ahead and type that. Hopefully this works. Okay. Now hit

00:59:00.290 --> 00:59:12.810
the up arrow twice. Press enter. Yes. Yes. Have you ever heard of TLDR or TLDR, which means too

00:59:12.810 --> 00:59:22.460
long, don't read? Oh, TLDR means too long, don't read. So when you're typing an email to somebody,

00:59:22.460 --> 00:59:26.240
you expect them to read a book or do you expect them to read a little caption

00:59:26.240 --> 00:59:33.820
and book I like it okay so now the reason why the TLDR is there is because I want

00:59:33.820 --> 00:59:43.200
you to type man space SL and press enter enter now that's the manual man is short

00:59:43.200 --> 00:59:47.960
for manual you don't understand a normal command you can type this and then you

00:59:47.960 --> 01:00:00.970
hit the down arrow keep going down until until it gets to the end is that the end yes sir okay good

01:00:00.970 --> 01:00:10.730
now go all the way back up hit the up arrow right so this is actually a short one but the sl was

01:00:10.730 --> 01:00:18.730
created because sometimes we want to type ls for list and sl sometimes we we kind of invert it um

01:00:18.730 --> 01:00:23.690
and it'll show the manual will show you any command all right they give you a

01:00:23.690 --> 01:00:32.190
synopsis of how to use it press q let me give you a longer one type man man space

01:00:33.310 --> 01:00:43.310
uh something longer um uh dir press directory yes okay see how much content is there

01:00:43.310 --> 01:00:56.810
hit the down arrow that's a lot right that is a lot okay press q okay let's i hope it's short

01:00:56.810 --> 01:01:09.050
type tldr space dir enter there you go it's a shortened synopsis of the same thing from

01:01:09.050 --> 01:01:19.810
from the the help or the manual have you ever used these before yes good in lab yeah okay so there's

01:01:19.810 --> 01:01:25.950
a reason why we want to use these things, right? Of course, you know how to use DIR space tag tag

01:01:25.950 --> 01:01:36.800
help or even DIR space tag H. The key here is I'm just trying to show you some things you may

01:01:36.800 --> 01:01:40.480
have to do as a pen tester. You may not understand something, you can do it. Have you

01:01:40.480 --> 01:01:59.710
ever used april probe before not sure type in um a apr pos a p a p r o p o s press enter

01:01:59.710 --> 01:02:09.660
okay now hit the up arrow space um type in like dir press enter

01:02:09.660 --> 01:02:19.620
whoo look at all those directories right it's crazy right now in order to truly learn this

01:02:19.620 --> 01:02:28.570
you'll have to go to firefox right up there at the top and open up a new tab

01:02:28.570 --> 01:02:37.150
plus on the top like top top left plus sign right there

01:02:37.150 --> 01:02:51.490
okay type in april pro a-p-r-o-p-o-s space geeks for geeks oh i love geeks for geeks i do too

01:02:51.490 --> 01:02:59.570
press enter see what it says april command in linux with examples

01:02:59.570 --> 01:03:09.770
yeah click on that we pin testers sometimes need examples right before chat gpt was google right

01:03:09.770 --> 01:03:20.020
and yeah so if you went through this entire thing you can teach yourself everything about april po

01:03:20.020 --> 01:03:26.400
and be like let me continue my pen test all right i'm trying to show you some things that you may

01:03:26.400 --> 01:03:34.930
actually need during the pen testing you understand got it okay so there's more than

01:03:34.930 --> 01:03:41.290
just google we don't just google stuff we also don't just chat gpt stuff we use everything

01:03:41.290 --> 01:03:50.330
scroll to the top again scroll to the top no no don't take that away just scroll to the top of the

01:03:50.330 --> 01:04:03.630
page oh good now click the back button just one time now i want you to click on images

01:04:03.630 --> 01:04:13.020
tons of articles that will teach you everything you need to go to quickly learn april pro and

01:04:13.020 --> 01:04:24.640
continue with your pen text click on videos right i don't see a whole bunch of articles on that but

01:04:24.640 --> 01:04:30.640
sometimes they are then you have on the more and it has a drop down click on the drop down on the

01:04:30.640 --> 01:04:40.910
far right next to more that's tools go to more next to news this to the left the word more

01:04:40.910 --> 01:04:46.170
thing is there's something blocking right here and you still have to go left go left

01:04:46.170 --> 01:04:59.930
you have go back to videos all of this is research stuff that we have to use

01:04:59.930 --> 01:05:08.310
versus ignore you understand yes there you go that's all I want to show you so

01:05:08.310 --> 01:05:12.910
that we can make sure that when we now the really cool thing is if you had your

01:05:12.910 --> 01:05:17.870
one note open you can copy those videos and place them there and keep them for life

01:05:19.390 --> 01:05:30.360
so now i want you to go to youtube real quick and hopefully what i want to show you is there

01:05:32.120 --> 01:05:43.370
click on youtube.com and in the search bar i want you to type marie m-a-r-i-e

01:05:45.450 --> 01:06:10.750
space forleo f-o-r-l-e-o f-o-r-l-e-o l-e-o o-r-l-e-o space psa press enter right now that 52 second video

01:06:12.590 --> 01:06:22.810
i need you to click on it and actually listen to it watch it and listen to it wow i want you

01:06:22.810 --> 01:06:31.050
to sign in to confirm you're not a bot i just hate it okay hold on i don't know why uh because

01:06:31.050 --> 01:06:40.700
you're in your cali um worst cases i can show you over here okay to watch it somewhere else

01:06:41.340 --> 01:06:46.860
um that's fine go ahead then okay i'll watch it on uh just open up a new tab

01:06:47.580 --> 01:06:57.040
got it on your host machine and then you can come back to it all right got it okay

01:06:58.240 --> 01:07:02.400
you want me to watch it right now watch it this seconds because only 52 seconds

01:07:02.400 --> 01:08:03.950
i can't see it but go ahead and watch it what questions do you have from that simple sarcastic

01:08:03.950 --> 01:08:14.250
relatively funny video none okay i i look up everything that's i mean i spend my whole life

01:08:14.250 --> 01:08:22.490
looking stuff up all day long so i concur i get it fantastic so if you're ever so the way pen tests

01:08:22.490 --> 01:08:30.010
happen in the government is something in a whole bunch but in the government my pen tester worked

01:08:30.010 --> 01:08:38.600
alone but on occasion he worked with a team they um they obtained written permission

01:08:38.600 --> 01:08:46.560
They understood the scope. We had a get out of jail free person just in case we saw something

01:08:46.560 --> 01:08:55.380
we weren't supposed to see. We reported it immediately. We conducted all of our vulnerability

01:08:55.380 --> 01:09:03.760
scans. We followed the whole process from the very beginning. When I meet you, I'm taking notes

01:09:03.760 --> 01:09:11.600
because i'm writing a report i am writing a report off of actual things that's done not memory

01:09:13.200 --> 01:09:21.920
our great memories lack when it comes to documenting exactly what happened step by step

01:09:24.080 --> 01:09:30.880
okay why because we want to get paid as pen testers right especially if you're a contracting

01:09:30.880 --> 01:09:35.680
company we need to document everything just in case for some reason they say the government says

01:09:36.240 --> 01:09:40.720
well why didn't you document everything is and why didn't you show us this and why didn't you

01:09:40.720 --> 01:09:45.040
show us that when you think that's important and then they'll twist it and make you feel like you're

01:09:45.040 --> 01:09:53.760
a criminal and they may even be interested in prosecuting you definitely not paying you and

01:09:53.760 --> 01:09:59.280
then they go well you know you're really not what we wanted so that's why we take notes from the

01:09:59.280 --> 01:10:07.280
beginning because in the end we don't want to have to go back i teach my analyst that from the very

01:10:07.280 --> 01:10:15.440
beginning we also need to know our commands right type the um type the word history in your um

01:10:17.760 --> 01:10:25.980
and you've typed this command before i presume yes fantastic so that'll show you all the commands

01:10:25.980 --> 01:10:32.380
that were typed into this in this shell when you were here now what we need to do my original

01:10:32.380 --> 01:10:42.080
question is can you tell me what your ip address is on this machine oh i can find it yeah of course

01:10:42.080 --> 01:10:50.560
do you know the command no okay no i what without not looking it up no fantastic so type in find it

01:10:51.440 --> 01:10:55.680
i i believe you i know you will i'm not worried because we've done some exercises

01:10:56.560 --> 01:11:03.600
by the way um i'm sorry type in um man space rig i wanted to show you what that was

01:11:05.890 --> 01:11:13.170
have you ever heard of the random identity generator no but now you have i was just

01:11:13.170 --> 01:11:29.180
it's a random identity generator okay go ahead and press q and type in man space sl press it

01:11:29.180 --> 01:11:34.380
it displays animations aimed to correct users who actively enter sl instead of lx

01:11:37.020 --> 01:11:50.560
i want you to get into uh custom to manning or reviewing the manual for all commands okay press q

01:11:52.080 --> 01:12:04.430
um okay um you familiar with pwd press are you familiar with this or is this the first time

01:12:04.430 --> 01:12:20.720
password no good guess though um it's actually i want you to man it it was right at the top

01:12:20.720 --> 01:12:32.350
don't skip what was at the top now that's where it tells you what it is print name of current

01:12:32.350 --> 01:12:44.160
working directory i got it shows you where you are go ahead and cue it okay um right now do you see

01:12:44.160 --> 01:12:52.510
that tilde at the end that little tilde in the little brackets yes okay it's showing you that

01:12:52.510 --> 01:13:01.830
That's usually the top of the directory, but your home directory is you're in slash home slash student.

01:13:03.470 --> 01:13:05.570
Do you know how to maneuver in Linux?

01:13:05.790 --> 01:13:08.270
I don't think you do because of what you said, but I'm asking.

01:13:09.410 --> 01:13:10.110
Probably not.

01:13:10.250 --> 01:13:11.110
Okay, this is going to be.

01:13:11.150 --> 01:13:12.770
I mean, let's do it.

01:13:12.930 --> 01:13:14.630
Let's do a little crash course.

01:13:14.710 --> 01:13:15.210
It's going to be fun.

01:13:15.610 --> 01:13:15.890
Okay.

01:13:16.470 --> 01:13:18.030
Now you are in home.

01:13:18.810 --> 01:13:19.950
You're in the student.

01:13:19.950 --> 01:13:32.860
uh type in who am i all one word oh should have known that and this is what we pentesters do

01:13:32.860 --> 01:13:41.260
right and who are you which is the before that little at insignia or that little asterisk in

01:13:41.260 --> 01:13:47.420
the middle you're a student that's the student the host name i'm not the host name that's the user

01:13:47.420 --> 01:13:53.260
of this particular linux terminal if you type in a name host name what's going to come up you have

01:13:53.260 --> 01:14:08.940
any idea? Can I type it? Go ahead. Press enter. Uh-oh. Type it all as one word. Cali. That's the

01:14:08.940 --> 01:14:19.620
password. Well, no. That's the system. The system name. So you have student at Cali. So when you type

01:14:19.620 --> 01:14:23.780
who am I, it's going to tell you the user that you're using. Something you need to know when

01:14:23.780 --> 01:14:27.980
you're doing pen testing. When you type host name, it's going to tell you the after the Adam

01:14:27.980 --> 01:14:34.700
insignia which is the name of the computer which is your operating system there you go fantastic

01:14:34.700 --> 01:14:40.140
okay and i'm actually looking at this list so now we're going to maneuver i would like for you to

01:14:40.140 --> 01:14:57.950
take type in cd which is change directory space dot dot press enter now type pwd you just at the

01:14:57.950 --> 01:15:05.950
top when you type pwd you are in slash home slash student you understand now you went back up you

01:15:05.950 --> 01:15:15.150
went up a directory from cd space dot dot to the home directory okay now pwd is one way to check

01:15:15.150 --> 01:15:22.350
but if you type the words ls and enter it will show you the different directories that are actually

01:15:22.350 --> 01:15:35.310
there now i would like for you to and listen to what i say change directory to student all right

01:15:35.310 --> 01:15:47.820
type pwd yay type list press enter yay that's what's inside student all right very similar to

01:15:47.820 --> 01:15:55.580
windows the only thing is when you do cd dot dot you do cd dot dot in windows and linux you do cd

01:15:55.580 --> 01:16:06.100
space dot dot that's just one way there's a whole bunch of ways now i'd like for you to cd space dot

01:16:06.100 --> 01:16:21.220
dot enter type cd space dot dot again enter you went all the way up to the root directory now

01:16:21.220 --> 01:16:35.600
type ls type pwd do you see where you are that forward slash dictates the tip top of the you're

01:16:35.600 --> 01:16:44.240
a ceo of now the company and everyone underneath you is apps boots xc etc etc the home directory

01:16:44.240 --> 01:16:49.060
i would like for you to change directory now all of these directories have meaning

01:16:49.060 --> 01:16:54.360
that's a google search we don't really have a whole lot of time to go through all that

01:16:54.360 --> 01:17:00.920
but these you need to know how to maneuver to these directories so i would like for you to go

01:17:00.920 --> 01:17:11.980
to the home directory. Don't type CD though. Just type the word home. Enter. That's another way to

01:17:11.980 --> 01:17:18.580
do it. Change directory does work, but I'm trying to show you multiple ways to do it. All right.

01:17:18.580 --> 01:17:26.080
Type list, LS. Okay. I want you to make a directory. Do you know how to do that?

01:17:26.080 --> 01:17:39.100
um i've made them before yes mkdir mkdir space and put donna enter

01:17:39.100 --> 01:17:45.140
uh-oh permission denied when that happens i want you to hit the up arrow

01:17:45.140 --> 01:17:50.460
control a whoops

01:17:50.460 --> 01:18:03.590
type sudo press enter type list and overcome your problem

01:18:03.850 --> 01:18:10.730
if you copy and paste this in the chat gpt if you do a search why didn't mkdr work it says

01:18:10.730 --> 01:18:15.290
can i create directory permission denied because you don't have enough administrative privileges

01:18:15.290 --> 01:18:23.630
right right so since you already created donna you don't need to do it again because it says

01:18:23.630 --> 01:18:29.850
the file exists yeah okay that's good though we i love it when you make mistakes or people

01:18:29.850 --> 01:18:33.550
make mistakes because then we go oh okay i know not to do that again we learn a lesson

01:18:33.550 --> 01:18:39.930
How do I un-make a mistake in this process, in this language?

01:18:40.450 --> 01:18:41.790
How do I un-make a mistake?

01:18:42.190 --> 01:18:43.990
You don't exactly un-make a mistake.

01:18:44.130 --> 01:18:45.170
You just learn from it.

01:18:45.590 --> 01:18:46.770
Learn what not to do.

01:18:47.590 --> 01:18:51.050
If it's something that's running, then maybe you want to stop it.

01:18:51.150 --> 01:18:53.130
But I'll show you that because we're going to do that in a minute.

01:18:54.290 --> 01:18:54.550
Okay.

01:18:55.350 --> 01:18:55.850
Let's see here.

01:18:55.990 --> 01:18:56.990
Customize the word panel.

01:18:56.990 --> 01:19:02.530
So normally when I do pen testing, I like to make directories for what I'm going to do.

01:19:02.530 --> 01:19:16.330
So now I want you to remove the directory that you just made type RMDIR, RM, not E, not RM.

01:19:16.610 --> 01:19:17.110
Yeah, RM.

01:19:17.110 --> 01:19:18.190
I gotcha, I gotcha.

01:19:19.410 --> 01:19:20.130
And remove Donna.

01:19:22.550 --> 01:19:25.910
Type LSD, uh-oh, uh-oh, same reason.

01:19:26.190 --> 01:19:26.730
What do we do?

01:19:26.870 --> 01:19:27.590
How do we fix it?

01:19:29.860 --> 01:19:30.740
Change directory.

01:19:31.720 --> 01:19:33.300
How do we, look at what it says.

01:19:33.400 --> 01:19:35.000
We read the output all the time, right?

01:19:35.000 --> 01:19:43.080
fail to remove so we have to do r m d i r again nope backspace you didn't read the whole thing

01:19:43.080 --> 01:19:48.200
to me i was waiting for you to get those last two words to remove donna permission denied so i have

01:19:48.200 --> 01:19:58.040
to do control a pseudo r m d i r and then rewrite my name do or you can hit the up arrow

01:19:58.040 --> 01:20:14.490
and do the same thing but yes control a control a pseudo enter now let's check it yay now go back

01:20:14.490 --> 01:20:33.400
into student change directory back in the student okay now now i want you to create a directory

01:20:33.400 --> 01:20:43.880
i want you to make a directory and call it basic pen testing put a underscore okay never mind that's

01:20:43.880 --> 01:20:50.520
fine too if you wanted to make um uh two words you would have to put an underscore between the

01:20:50.520 --> 01:21:01.580
word basic just throwing that out there press enter do a list there it is right there see

01:21:01.580 --> 01:21:13.260
basic pen testing now let's change directory to basic pen testing okay stop right there don't type

01:21:13.260 --> 01:21:31.500
anymore press the tab key yay press enter autofill wonderful dragon can now i want you to now open up

01:21:31.500 --> 01:21:45.400
your virtual box you may have to click on the dragon at the top left yeah right by the way

01:21:45.400 --> 01:21:51.080
there's 600 plus different tools you see it reconnaissance all the way down the surfaces

01:21:51.080 --> 01:21:57.210
and other tools type in virtual box go ahead and click on it

01:22:00.410 --> 01:22:04.170
you got your virtual box inside of the linux terminal isn't that cool

01:22:05.530 --> 01:22:14.330
yes now in the real world you're going to use a um a vpn to make sure people don't know who you

01:22:14.330 --> 01:22:20.570
are when you're hacking into a system legally because we don't do that illegally orange jumpsuit

01:22:20.570 --> 01:22:28.410
right ask what vpn you guys use because i think there are a lot of them are garbage so you you

01:22:29.690 --> 01:22:36.570
with a lot of things they don't what what should i use it's really up to you that's a personal

01:22:36.570 --> 01:22:42.570
question that's almost like what shirt should i wear today which shoes should i wear but the

01:22:42.570 --> 01:22:49.770
government will do research and they'll they'll have recommended ones that they use the pen testers

01:22:49.770 --> 01:22:55.290
will do research they may use something totally different in the end of the day though a government

01:22:55.290 --> 01:23:02.650
agency is still probably going to want to whitelist your ip so that you can actually

01:23:02.650 --> 01:23:13.930
have permission to do the work the um government pen tests um are very much controlled they want to

01:23:13.930 --> 01:23:19.450
know everything you're doing so there's no getting around it but you still want

01:23:19.450 --> 01:23:28.430
to whitelist a IP via your VPN maybe a different country or a country in the

01:23:28.430 --> 01:23:36.930
US but it's not actually your house you understand yes because we can reverse

01:23:36.930 --> 01:23:42.810
IP all kinds of stuff now we do you know you already know how to install stuff

01:23:42.810 --> 01:23:52.570
i'm not worried csec is actually basic pen testing one right so i'd like for you

01:23:52.570 --> 01:23:58.810
uh-oh it says can't all right just go ahead and close that can't enumerate i just powered it up

01:23:58.810 --> 01:24:04.010
no no no no no no that little orange on the right the little orange auto capture

01:24:04.010 --> 01:24:12.330
keyboard yeah go ahead and click x on the far right no no no no no no no cancel cancel hit cancel

01:24:12.810 --> 01:24:21.590
yeah well okay yeah yeah yeah knowing yeah click that X before up every time

01:24:21.590 --> 01:24:28.670
you see it just get rid of it they do now go ahead and click that same thing

01:24:28.670 --> 01:24:33.650
and it's taking its time so let's wait it out in summary what's happening now

01:24:33.650 --> 01:24:41.630
is you're opening up a pen test a vulnerable pen testing machine and it

01:24:41.630 --> 01:24:45.630
It looks like it's Marlin Spikes machine.

01:24:45.630 --> 01:24:49.630
Got it. So the scenario is this.

01:24:49.630 --> 01:24:58.630
Donna, you've been hired to conduct a penetration test of a specific IP address, a specific computer, right?

01:24:58.630 --> 01:25:05.630
You are going to be like, OK, what are the rules of engagement?

01:25:05.630 --> 01:25:28.070
What is the scope of this pen test? You're going to be writing it all down, right? You're going to present your legal certifications, your authority, your company, your NDA, all of your attorney's documents. You all are going to be talking. This is business, right?

01:25:28.070 --> 01:25:37.970
you are going to um document the ip address you're going to find out is this more of something

01:25:37.970 --> 01:25:43.230
we work together like a white box type pen test or is it something with black box where i'm just

01:25:43.230 --> 01:25:49.430
going to do whatever and get in any way i i can since this is one ip address it's going to be more

01:25:49.430 --> 01:25:55.870
white so you're going to kind of work together um or you may work individually in the room and

01:25:55.870 --> 01:26:04.410
if you need me, just come get me. If you see something that is a different IP address,

01:26:04.830 --> 01:26:09.410
well, that's like, instead of walking to my house, then you walk into my neighbor's house.

01:26:09.790 --> 01:26:15.490
That's a problem. So you want to report that, hey, there's another IP address here.

01:26:15.990 --> 01:26:24.070
It's not within my written scope. You understand? Yes. Fantastic. Because you're a consultant.

01:26:24.830 --> 01:26:26.790
You're a cybersecurity professional.

01:26:27.030 --> 01:26:28.890
You're not there to break into their systems.

01:26:29.230 --> 01:26:32.250
You're there just to test their security and make recommendations.

01:26:33.250 --> 01:26:35.370
It will be in the form of a report.

01:26:35.370 --> 01:26:37.910
You need total documentation.

01:26:38.890 --> 01:26:40.910
And you have lots of documents.

01:26:40.990 --> 01:26:41.890
You got Adratus.

01:26:41.950 --> 01:26:43.010
You got Cherry Tree.

01:26:43.370 --> 01:26:44.470
You have OneNote.

01:26:44.730 --> 01:26:47.970
You have all these different documents where you can document this stuff.

01:26:50.400 --> 01:26:50.700
Okay.

01:26:51.980 --> 01:26:54.080
You want to make sure you have insurance.

01:26:54.080 --> 01:27:00.480
because um you make a mistake they they don't care how much money you have don't have they just

01:27:00.480 --> 01:27:06.760
want theirs right end of the day we want to make sure that they don't prosecute you and we want to

01:27:06.760 --> 01:27:13.200
show them and give them uh well researched and experienced recommendations that are not just

01:27:13.200 --> 01:27:21.900
google and chat gpt based you need to go over you okay go ahead ask the question how much liability

01:27:21.900 --> 01:27:29.580
insurance are you indicating that what is normal that's consult that's an attorney question and

01:27:29.580 --> 01:27:36.940
and it could be very simple just saying you know you make mistakes yeah okay i understand

01:27:36.940 --> 01:27:45.500
now let's just say you have written permission you have all that stuff covered all the business

01:27:45.500 --> 01:27:50.380
stuff is covered you are in the mix you are now here you're going to conduct the pen test

01:27:50.380 --> 01:27:57.260
okay marlin spike you the machine is running meaning that they just put you on the network

01:27:57.260 --> 01:28:01.740
now i need you to minimize that machine because it's running

01:28:01.740 --> 01:28:16.020
uh-huh you look top right two clicks over from the blue x don't click the blue x two clicks to the

01:28:16.020 --> 01:28:28.410
left go to the left two times two bullets two circles nothing there go don't log out

01:28:28.410 --> 01:28:31.850
okay

01:28:31.850 --> 01:28:33.490
go ahead

01:28:33.490 --> 01:28:36.170
where is it

01:28:36.170 --> 01:28:37.010
I'm going to tell you

01:28:37.010 --> 01:28:39.070
I got you

01:28:39.070 --> 01:28:40.890
you see the blue X right

01:28:40.890 --> 01:28:44.250
go two buttons to the left

01:28:44.250 --> 01:28:46.530
there you go

01:28:46.530 --> 01:28:49.130
done

01:28:49.130 --> 01:28:50.870
that's minimized right

01:28:50.870 --> 01:28:53.970
now if you were doing this

01:28:53.970 --> 01:28:56.110
in Kali Linux there's a whole process

01:28:56.110 --> 01:28:58.090
for this doing a break or something

01:28:58.090 --> 01:28:59.050
or when we come back

01:28:59.050 --> 01:29:02.170
sometime this afternoon I'll show you how

01:29:02.170 --> 01:29:10.090
to do it inside of the virtual box right I do it all the time now you can minimize your virtual

01:29:10.090 --> 01:29:27.410
machine same way that no no no go back see the blue X go to the left go you know go to the top

01:29:27.410 --> 01:29:33.350
and click on the virtual machine I want you to see you see the blue X on the top I can't see

01:29:33.350 --> 01:29:41.350
that though? Can you see where I just can't see it? No idea. What's in the way? Nevermind. I just

01:29:41.350 --> 01:29:47.650
moved it with my finger. That'll never happen again. That's good. These are called lessons

01:29:47.650 --> 01:30:00.360
learned. You're learning tons of lessons. Now I would like for you to, okay, we're thinking, right?

01:30:00.360 --> 01:30:10.820
we are actually on the the network of that company okay i need you to type ip space a

01:30:10.820 --> 01:30:24.640
on the on the terminal press enter okay now ipa is short for ip address

01:30:24.640 --> 01:30:42.580
as a matter of fact type ip space address see what is your ip address of this um linux computer

01:30:42.580 --> 01:30:52.060
do you know the IP address is one zero point one zero zero point zero point four

01:30:52.060 --> 01:31:01.560
it's actually going to be number two which has ETH zero the ethel that is ten point zero point

01:31:01.560 --> 01:31:07.500
three point one five yes ten does it I feel that fifteen right so I always look at the ethel ethel

01:31:07.500 --> 01:31:14.380
zero right right that's usually what it is first and of course the loop back address is the one at

01:31:14.380 --> 01:31:22.540
the top. 127.0.0.1, that's used for testing and it's not given out. And you have another

01:31:22.540 --> 01:31:29.100
interface called Edge Zero, right? But we're not worried about that. What we need to find out,

01:31:29.100 --> 01:31:37.460
though, is the IP address of Marlin Spike. They didn't give it to you. They just gave you a name

01:31:37.460 --> 01:31:43.600
and said, okay, you're a pen tester. How can you find it? What would you do?

01:31:44.880 --> 01:31:51.200
First of all, you will have already gone through this. You would have done, you go to the research

01:31:51.200 --> 01:31:59.840
and say how to find IP address of target machine in Kali Linux, right? Don't do it now. I'm going

01:31:59.840 --> 01:32:04.800
to fast track you through it and then you're going to do it for the rest of your life. So I'm

01:32:04.800 --> 01:32:12.640
to show you two commands one is you're going to type sudo super user do space net discover

01:32:14.480 --> 01:32:26.490
all one word press enter all right it is currently running an address resolution protocol request

01:32:27.370 --> 01:32:33.450
looking for an ip address it's going to show you the mac address the count the length the mac

01:32:33.450 --> 01:32:42.890
vendor or the host name it says 10.0.3.1 okay and it's going to take a sweet time running through

01:32:42.890 --> 01:32:54.780
this thing so what i want you to do is to right click in the terminal and i want you to split

01:32:54.780 --> 01:33:06.400
view left and right now each of these terminals run independent i'm going to give you another command

01:33:06.400 --> 01:33:17.440
it's as a matter of fact click on the left left terminal type control shift plus plus plus make

01:33:17.440 --> 01:33:35.960
it bigger just click inside the box control shift plus plus plus control shift plus plus plus on the

01:33:35.960 --> 01:33:45.670
keyboard not typing anything left click inside the box left click not right click left click

01:33:45.670 --> 01:33:53.270
left click now do it now control shift plus plus plus don't do anything else look like you're

01:33:53.270 --> 01:33:57.910
trying to do something there you go you're getting it there you go now i can see it

01:33:57.910 --> 01:34:07.460
on the right side do the same thing click in it and control shift plus plus plus there you go

01:34:07.460 --> 01:34:12.560
that's how you make it larger for your audience to see it you may be working with other pen testers

01:34:12.560 --> 01:34:17.620
hey this is what i did this is what i found out right you may be a excellent at reconnaissance

01:34:17.620 --> 01:34:23.060
or information gathering someone else on your team may be excellent at numeration or vulnerability

01:34:23.060 --> 01:34:32.740
scanning etc etc you see how that works yeah now here's a clue do you see that mac address

01:34:32.740 --> 01:34:43.350
that starts with 0800 i do good now i need you to go back to your click on your virtual box

01:34:43.350 --> 01:34:47.110
and now i need you to write click on settings because it's already highlighted blue

01:34:47.110 --> 01:35:03.530
go to network okay do you see where it says mac address 0800 blah blah blah

01:35:03.530 --> 01:35:14.690
yes does that mac address match the mac address on the left over there it does hey you just found

01:35:14.690 --> 01:35:26.780
the ip address of your target machine cool okay this is how that go ahead and click on okay

01:35:29.160 --> 01:35:37.420
and then minimize the virtual box now on the right side i'm going to show you another command

01:35:37.420 --> 01:35:44.540
now remember in your notes this is how do i find the ip address in the government or most

01:35:44.540 --> 01:35:49.020
organizations they're probably going to give you the ip address because they don't want you

01:35:49.020 --> 01:35:58.380
slipping around their whole network but if they don't um um these are some strategies to find it

01:35:58.380 --> 01:36:11.080
now i want you to type sudo space a r p all right press ctrl e hit the backspace

01:36:14.490 --> 01:36:27.800
press ctrl e press enter yes now this is the art skin hey doc control e what does that do for me

01:36:27.800 --> 01:36:36.630
okay what did that just do it so we we did it earlier we're going to do it again right this

01:36:36.630 --> 01:36:47.820
second because you're going to learn type in um type the word history press ctrl a uh-oh

01:36:48.380 --> 01:36:59.080
type the up arrow type ctrl a i have to type it or you're saying hit it hit control button

01:36:59.080 --> 01:37:05.720
and the letter a what happened with the cursor oh it brings it back to the beginning press ctrl

01:37:05.720 --> 01:37:14.920
in the letter e what did it do now there you go yeah fantastic so now hit the up arrow twice

01:37:15.560 --> 01:37:22.630
one yeah press enter go back down okay hit the up arrow until you get the pseudo art scan

01:37:25.110 --> 01:37:31.720
press enter fantastic now tomorrow you're going to be putting all this stuff in the notes because

01:37:31.720 --> 01:37:38.840
we got to write a report so guess what we did now just so you know on the left side

01:37:39.400 --> 01:37:48.360
the net discover is still running can you see that yes on the right side is done can you see that

01:37:49.640 --> 01:37:57.800
yes which one is faster the right side which one is more thorough the right side

01:37:59.320 --> 01:38:04.040
well they look about the same except the left side is still running right

01:38:04.040 --> 01:38:08.920
left side's more thorough because it's still running and it's yeah there you go you got the

01:38:08.920 --> 01:38:16.360
answers now so we want to be as thorough as we can but if we can also identify the target that we're

01:38:16.360 --> 01:38:24.440
looking for and you've verified it because you know what the mac address is inside virtual box

01:38:24.440 --> 01:38:31.800
you just didn't know the ip address now you know the the ip address of marlin spikes machine

01:38:34.780 --> 01:38:35.400
You got it?

01:38:36.280 --> 01:38:36.640
Yep.

01:38:37.180 --> 01:38:39.080
You will have to know these commands.

01:38:39.740 --> 01:38:42.960
These commands, if you're writing up notes, and I'll show you mine later,

01:38:42.960 --> 01:38:51.660
is how do I find the IP address from my, you're the attack machine,

01:38:52.200 --> 01:38:56.620
Marlin Spike is the target machine, and you're going to type

01:38:56.620 --> 01:39:03.060
sudo net discover or sudo arp scan, arp dash scan space dash L.

01:39:03.060 --> 01:39:08.840
You don't have to do both of them, but that also depends.

01:39:12.150 --> 01:39:13.430
Now, here's the thing.

01:39:14.350 --> 01:39:16.370
Underneath that, I want you to type man.

01:39:16.890 --> 01:39:23.360
Just backspace twice.

01:39:25.910 --> 01:39:32.670
Type man space ARP dash scan.

01:39:34.450 --> 01:39:36.390
Don't forget the dash.

01:39:36.530 --> 01:39:37.210
Okay, it came up.

01:39:37.370 --> 01:39:37.530
Okay.

01:39:37.530 --> 01:39:40.270
Do you know what ARP means?

01:39:43.020 --> 01:39:43.520
I did.

01:39:44.520 --> 01:39:48.560
Address, resolution, there you go.

01:39:49.300 --> 01:39:57.140
Send ARP request to target host, which is what you did, and display the responses.

01:39:58.140 --> 01:40:00.200
And then you have the synopsis.

01:40:00.200 --> 01:40:03.740
It says ARP-scan, options, and host.

01:40:04.160 --> 01:40:09.680
That's exactly what we did, minus the IP address for the host.

01:40:09.740 --> 01:40:10.980
We just put the dash L.

01:40:10.980 --> 01:40:19.500
If you scroll down, pardon me, it will show you what the dash L means, right?

01:40:19.800 --> 01:40:21.800
Eventually, press Q.

01:40:22.440 --> 01:40:23.620
You don't have to worry about it now.

01:40:24.320 --> 01:40:26.580
What's the other command I showed you?

01:40:29.750 --> 01:40:30.910
The other command.

01:40:31.430 --> 01:40:38.480
TLDR space ARP dash scan.

01:40:45.760 --> 01:40:48.320
Scan the current local network.

01:40:48.700 --> 01:40:51.300
That's what dash L means, local net.

01:40:51.300 --> 01:40:57.960
scan an ip network with a custom bit mask it shows you that etc

01:40:57.960 --> 01:41:09.830
so now when we're conducting this net discover and this address resolution scan

01:41:09.830 --> 01:41:20.910
we are um information gathering well we've transitioned from um passive to active

01:41:20.910 --> 01:41:30.670
yes sir if we were doing this passively we'd be on facebook google dorts and looking up the url

01:41:30.670 --> 01:41:36.010
looking up the company name and trying to find out stuff with random google searches you understand

01:41:36.010 --> 01:41:44.510
okay um once you start getting active that's when the orange jumpsuit is being sized for you

01:41:44.510 --> 01:41:53.050
yes that's why we have to have written permission to do these things now we know the ip address

01:41:53.050 --> 01:41:59.310
and we can be verified it with two different tools when i took the cpin course it said

01:41:59.310 --> 01:42:07.390
you don't have to know a hundred different tools to do this you just need to be really

01:42:07.390 --> 01:42:14.310
proficient at with at least two or three of them for each section pen testing is pen testing

01:42:14.310 --> 01:42:19.330
you have people who are mega mega advanced in pen testing they can write their own scripts

01:42:19.330 --> 01:42:25.090
and one day we will get there but in the meantime we're just going to do basic pen tests to

01:42:25.090 --> 01:42:32.390
understand what we are doing what are your favorite tools i have way too many i have so many notes it's

01:42:32.390 --> 01:42:42.510
not even funny i have eight years worth of notes but arp scan and net discover are givens in this

01:42:42.510 --> 01:42:53.260
community for information gathering when you're doing passive stuff okay okay now on the left side

01:42:53.260 --> 01:43:00.380
we want to stop that do you know how stop that command from running because it's running you

01:43:00.380 --> 01:43:12.570
see it changing yes um just a q go ahead and type q and see what it does nada well it looks

01:43:12.570 --> 01:43:22.090
it stopped it to me you can also press ctrl c all right so we stopped that fantastic now we're doing

01:43:22.090 --> 01:43:29.530
a basic pen testing we know the ip address let's verify we've already verified that we have

01:43:29.530 --> 01:43:32.890
connectivity but this is something that you may have to do in the future so i'm gonna show you

01:43:32.890 --> 01:43:39.850
right now what command do we type to verify connectivity from the attack machine to the target

01:43:39.850 --> 01:44:01.200
machine ping it go ahead ping it it's the tab make sure you type the uh ip right because that

01:44:01.200 --> 01:44:09.840
wasn't it ah so now this is this is what i do to myself so how do i back out so how do you stop

01:44:09.840 --> 01:44:24.510
it we just talked about it you control c there you go that's your answer hit no no hit the up

01:44:24.510 --> 01:44:37.190
arrow just change the zero to a three backspace keep backspacing change that three and the three

01:44:37.190 --> 01:44:47.750
got 16 oh yeah I see hello oh three put that back because it's not lit you see

01:44:47.750 --> 01:44:54.770
how it's not lit it's grade it's because you put the period three that there you

01:44:54.770 --> 01:45:06.340
go one six press enter okay lesson for you oh I wrote the wrong idea originally

01:45:06.340 --> 01:45:11.460
yes okay i got you i got you sorry but what do you what do you see happening right now

01:45:12.580 --> 01:45:24.450
sending pings um you essentially created a ping flood right to the icmp right but that's what a

01:45:24.450 --> 01:45:38.300
pink flood is right well how do you stop it you how do i stop it q control c q did that work before

01:45:38.300 --> 01:45:51.580
yes uh q did not work before ctrl c worked there you go so think ctrl c q doesn't always work

01:45:51.580 --> 01:45:57.820
and with some other ones it's going to be colon wq it's going to be the escape button

01:45:57.820 --> 01:46:03.820
so we have to learn which if there's a lot of different ways to stop it and if you get stuck

01:46:03.820 --> 01:46:08.380
you will google search it or research it how do i stop this command from running

01:46:08.380 --> 01:46:14.020
or you'll take a screenshot put it there how do i stop this in linux it'll tell you okay

01:46:14.020 --> 01:46:22.420
now that ping means that we have connectivity you have zero percent loss and 45 or receive

01:46:22.420 --> 01:46:36.080
you can hit the up arrow put a space dash c space

01:46:36.080 --> 01:46:45.900
uh-oh oh i didn't mean to do that hit the up arrow up space put put the number eight

01:46:45.900 --> 01:47:01.060
press enter one two three four five six seven eight nice you can also establish a count

01:47:01.060 --> 01:47:06.740
now if you man ping this all those are written in the instructions

01:47:06.740 --> 01:47:16.160
our issue is we fly through stuff fast we can't do that we have to take our time

01:47:16.160 --> 01:47:22.560
okay i understand gotta read the output why do you want to give it a ping count you just don't

01:47:22.560 --> 01:47:29.500
want to be because if you don't you don't want it correct because if you don't is it'll run forever

01:47:30.380 --> 01:47:36.540
yes so if someone has done this for the very first time they're like it's pinging now what

01:47:37.500 --> 01:47:42.940
it's still pinging and then uh an ignorant person would sit there and let them go like this

01:47:44.140 --> 01:47:49.900
and they'll just giggle at them right the thing is we are trying to i'm trying to make sure you

01:47:49.900 --> 01:47:58.300
understand not just oh that worked but when it doesn't work what do i do you understand yes

01:47:58.300 --> 01:48:05.860
now I want you to hit the up arrow twice three times there you go press

01:48:05.860 --> 01:48:16.880
ctrl a type the letter F press enter oh oh you press something else press in

01:48:16.880 --> 01:48:24.120
yeah look at what it said it's alive right f ping if you go on the right side

01:48:24.120 --> 01:48:36.600
and man f ping right side right terminal man f ping i could never mind i got it

01:48:39.640 --> 01:48:51.320
send icmp echo request package to network host it's just another command right yes go ahead and

01:48:51.320 --> 01:49:02.510
press q and now you don't have to worry about the ping flood did you see that yes if you f paint

01:49:02.510 --> 01:49:09.470
now if it wasn't up it'll say down or dead sometimes they'll say it's alive or it's up

01:49:11.310 --> 01:49:18.110
okay look at all this stuff that we need to screenshot and put inside of our report and if

01:49:18.110 --> 01:49:24.510
we were writing our report in tandem we could be doing that it's fantastic which we're going to do

01:49:24.510 --> 01:49:29.310
later today or tomorrow right now we're going to get through this pen test and i want you to

01:49:29.310 --> 01:49:37.960
understand the analogy you ask questions as you are doing on the left side the left terminal okay

01:49:37.960 --> 01:49:46.280
imagine now i'm at your house you're at the front door and you gave me authorization to conduct

01:49:46.920 --> 01:49:54.270
a test of your security defenses of your home as soon as you wrote the documentation

01:49:55.150 --> 01:50:00.990
and you signed it you know what i'm gonna say close your door and go back inside and sit down

01:50:00.990 --> 01:50:07.870
and live your life you know what i'm going to do i'm going to walk around your house

01:50:10.410 --> 01:50:18.330
for as many days and hours or weeks that i can what am i looking for when i'm walking around your

01:50:18.330 --> 01:50:30.030
house okay i'll go with cracks which is a synonym to weaknesses which is a synonym to

01:50:30.030 --> 01:50:40.790
to vulnerabilities. Fantastic. Well, walking around your house physically, if I saw a window

01:50:40.790 --> 01:50:50.310
crack like this, and I said nothing to you, at a time of my choosing, that may be my vector,

01:50:50.730 --> 01:50:57.710
my opening into your, my attack vector into your house. You understand that? And then you would

01:50:57.710 --> 01:51:03.330
feel terrible. What do you mean I had a crack in the door? Now, pen testers are not allowed to

01:51:03.330 --> 01:51:12.170
break stuff, right? We should not break stuff. A really good ethical hacker, a crack through the

01:51:12.170 --> 01:51:17.170
door or the little window, that's not breaking. If I physically broke it, I had to pay for it.

01:51:17.190 --> 01:51:23.530
I'm in trouble, but I'm just trying to get inside the house unscathed without you seeing it.

01:51:23.530 --> 01:51:37.830
If I also notice that that crack was on the second floor window of your home, say you're in a house, but there was a basement door crack like this, which one do I want to go in?

01:51:41.300 --> 01:51:41.700
Both.

01:51:42.580 --> 01:51:46.440
I want to go in both, but which one will I more likely go into?

01:51:47.560 --> 01:51:49.600
Well, basement because it's more.

01:51:49.960 --> 01:51:51.200
Because I'm not Spider-Man.

01:51:51.940 --> 01:51:52.460
Right?

01:51:52.540 --> 01:51:53.580
I can hurt myself.

01:51:53.580 --> 01:51:55.800
I can get caught.

01:51:56.280 --> 01:52:04.100
I could be seen. Neighbors may see me climbing to open up a window in Clural Inn. That's no bueno,

01:52:04.360 --> 01:52:11.240
right? But if I can go at the right time of day, two o'clock in the morning, and I can slip in

01:52:11.240 --> 01:52:15.920
through the door, I know you have no dogs, right? I'm doing reconnaissance of your house

01:52:15.920 --> 01:52:23.060
without you knowing. I'm watching. She doesn't have any dogs. She lives alone, or maybe she has a

01:52:23.060 --> 01:52:28.700
a significant other and some children. Whatever the case is, I saw all the lights go out at like

01:52:28.700 --> 01:52:34.500
11 o'clock every night. I'll watch you for a few days. I'm trying to think, and I'll make the team.

01:52:34.580 --> 01:52:39.940
Hey, team, this is what I've seen. You see my notes? What do you think the best time? Then

01:52:39.940 --> 01:52:46.240
she wakes up at this time. I didn't see any lights come on between 11 and 5 a.m., so she's probably

01:52:46.240 --> 01:52:52.760
in a deep sleep. You understand what I'm saying? You're putting a lot of thought in. How am I

01:52:52.760 --> 01:52:59.020
going to attack successfully this person? I get inside your house. I get on your computer. I got

01:52:59.020 --> 01:53:03.920
everything I need. I got your money. I got everything I need. If I'm looking for something

01:53:03.920 --> 01:53:11.460
else, I want a stolen artifact. I got everything I need. Your job is to always protect all of your

01:53:11.460 --> 01:53:17.700
gold, your intellectual property, whatever that is, your money, your information on your computer,

01:53:17.700 --> 01:53:21.500
your intellectual property, KFC's secret recipe,

01:53:21.880 --> 01:53:25.580
your social security number, your private pictures. You want to keep

01:53:25.580 --> 01:53:29.660
people out physically, logically, and that's going to

01:53:29.660 --> 01:53:32.320
constitute policies, some

01:53:32.320 --> 01:53:37.400
digital strongholds, maybe even

01:53:37.400 --> 01:53:41.040
physical strongholds. Did I say too much?

01:53:42.540 --> 01:53:45.900
No. Also, you need to monitor

01:53:45.900 --> 01:53:54.020
everything, physical and logical. What do we do to monitor our physical? We lock out doors.

01:53:54.020 --> 01:54:04.200
We have alarm systems. Maybe we have cameras, motion detectives. And hopefully they give us

01:54:04.200 --> 01:54:11.040
an indication that in real time that something's happening and we go execute our protections.

01:54:11.040 --> 01:54:14.560
What do we have in our homes logically?

01:54:15.800 --> 01:54:19.180
So ironically, as I show people how to build socks in their houses.

01:54:20.420 --> 01:54:22.100
I have a sock in my house.

01:54:22.860 --> 01:54:23.380
A router.

01:54:25.550 --> 01:54:29.910
Well, the router is going to allow me to network with you and other people in the world.

01:54:31.250 --> 01:54:34.950
I'm talking about security operations.

01:54:35.350 --> 01:54:36.610
I'll show you an image later.

01:54:37.390 --> 01:54:37.910
A sock.

01:54:37.930 --> 01:54:38.110
Okay.

01:54:38.710 --> 01:54:40.590
Being able to monitor your home.

01:54:40.590 --> 01:54:45.330
If someone broke into your digital space right now, what do you have to detect them?

01:54:48.430 --> 01:54:48.790
There you go.

01:54:48.810 --> 01:54:50.750
Just a few bells and whistles, not much.

01:54:50.910 --> 01:54:51.130
Right.

01:54:51.370 --> 01:54:52.570
Most people have nothing.

01:54:53.830 --> 01:54:54.590
And that's what I'm saying.

01:54:54.690 --> 01:54:56.310
That's a few bells and whistles, right?

01:54:56.830 --> 01:54:59.650
Specific is usually equates to nothing.

01:55:01.410 --> 01:55:03.670
Organizations will find a hacker.

01:55:04.950 --> 01:55:08.210
They will watch you, right?

01:55:08.390 --> 01:55:12.610
After a while, they'll try to zero in to find out where you are and they'll attack you.

01:55:12.890 --> 01:55:16.730
or they'll send the police after you if they can't then they'll block you

01:55:18.650 --> 01:55:21.210
your job though is to get inside this organization

01:55:22.970 --> 01:55:28.330
and show them all their flaws and make recommendations you understand and that's

01:55:28.330 --> 01:55:34.410
why we're talking about both sides and i'm going to show you an image that'll wrap it all up later

01:55:34.410 --> 01:55:40.730
on so here's the thing you now verify that you have connectivity to the target machine

01:55:40.730 --> 01:55:48.310
Now, I just discussed with you what I would do physically and digitally. I would do some sort of

01:55:48.310 --> 01:55:57.270
even more information gathering and reconnaissance of your home. I'm not just going to walk in

01:55:57.270 --> 01:56:05.430
through your door because I don't know what you may have, a shotgun, a pit bull, some ninjas behind

01:56:05.430 --> 01:56:10.790
the door and i walk in and get my head chopped off right why would i just when you think a special

01:56:10.790 --> 01:56:16.470
forces team they don't go behind enemy line and start stuff they try to be quiet and hush hush

01:56:16.470 --> 01:56:24.390
on it the command i want you to remember now is now it's time to do a network mapping scan

01:56:24.390 --> 01:56:31.990
of the ip address so let's do it um discover no sudo no net discover we did that already

01:56:31.990 --> 01:56:39.530
you're going to just type in map and you're going to in map that ip address

01:56:43.270 --> 01:56:54.490
press ctrl e now press enter thank you got it when you see something pops up then you can press

01:56:54.490 --> 01:57:04.330
ctrl e or you can just type it all in now starting in map version 7.95 the latest version you got

01:57:04.330 --> 01:57:11.850
the date and you got the time the nmap scanner port for that ip address the host is up virtually

01:57:11.850 --> 01:57:22.490
no latency there are 997 closed ports but there looks like there are three open ports

01:57:23.770 --> 01:57:32.970
so when you do an nmap scan of an ip address it shows the first used 1000 ports how you learn

01:57:32.970 --> 01:57:41.130
how to use in map is you google an in map cheat sheet so you can find out more or less information

01:57:41.130 --> 01:57:47.550
so i'll need you to go to firefox oh i have one somewhere i have a physical one can i get it

01:57:47.550 --> 01:57:52.650
yes but i want you to use a digital one purpose because i want to show you some more to add to

01:57:52.650 --> 01:57:59.270
your physical go into the firefox and then hit the plus sign or yeah go right there you're fine

01:57:59.270 --> 01:58:06.650
Click on that, type in map cheat sheet, and I specifically want you to use the one from Station X.

01:58:07.710 --> 01:58:09.650
Oh, I love Station X.

01:58:14.790 --> 01:58:15.570
My God.

01:58:20.250 --> 01:58:23.310
No, there we go, Station X.

01:58:25.820 --> 01:58:30.300
Okay, now, I want you to type Control F.

01:58:33.900 --> 01:58:35.220
No, on Station X.

01:58:35.260 --> 01:58:36.300
Just make sure you click on there.

01:58:37.500 --> 01:58:39.220
Type in Control the letter F.

01:58:39.600 --> 01:58:43.110
Where?

01:58:43.870 --> 01:58:44.550
Don't matter.

01:58:44.550 --> 01:58:45.650
Just click there.

01:58:46.130 --> 01:58:50.370
Hit the control button and the letter close that that thing you're all

01:58:56.100 --> 01:58:58.900
Okay, and it came open. I think at the bottom left

01:59:00.040 --> 01:59:06.700
See what says specifies pro roundtrip. I don't know what that is, but a bottom left side left side bottom

01:59:08.160 --> 01:59:13.220
Specify right got it. So I want you to type in

01:59:17.570 --> 01:59:25.760
Time Tima like erase everything there highlight it all control a and press

01:59:26.720 --> 01:59:38.450
press delete type the word time press enter okay that table of contents close that it's in the way

01:59:41.000 --> 01:59:44.200
fantastic okay you type the word time did you see what came up

01:59:45.720 --> 01:59:55.430
no good go in the bottom left hit time again do you see the word time highlight yes right press enter

01:59:55.430 --> 02:00:02.550
again and you see it another time so then we we use this inside the sock to search for stuff

02:00:02.550 --> 02:00:13.750
on a page okay now um that's just an example let's see here um uh hit enter until you get

02:00:13.750 --> 02:00:24.020
the time and perform performance it's gonna be like see how it says nse scripts just scroll all

02:00:24.020 --> 02:00:35.810
the way down it'll be underneath there somewhere use the scroll bar if you have it there you go

02:00:36.370 --> 02:00:47.510
keep going keep going oh look at this right here this is interesting look firewall flash intrusion

02:00:47.510 --> 02:00:55.430
detection system evasion and spoofing you see how it has in map the um ip address in the dash f

02:00:56.630 --> 02:01:06.150
and the description requested scan including ping scans using tiny fragmented ip packets harder

02:01:06.150 --> 02:01:15.750
for packet filters in map is a very loud command you get on anybody's network and you type it

02:01:15.750 --> 02:01:21.910
minus home network and if they monitor the network like a security operation center style

02:01:21.910 --> 02:01:33.030
they're going to see you yes so pen testers create their own custom made in map scans to be hidden

02:01:33.030 --> 02:01:44.320
this cheat sheet is showing you some of the ways to hide it in the real world you don't want to get

02:01:44.320 --> 02:01:54.520
caught when you're doing a pen test you don't want to be seen this one cheat sheet has a bunch

02:01:54.520 --> 02:01:59.280
of different examples of how to do that keep scrolling down a little bit more it could be up

02:01:59.280 --> 02:02:11.640
but go down output scroll down helpful keep going i'm looking for a specific section i think it's

02:02:11.640 --> 02:02:17.710
near the top yeah scroll to the top it's like time and performance or something like that

02:02:17.710 --> 02:02:26.740
keep going keep going you you're going good with that speed before right there right there

02:02:26.740 --> 02:02:33.480
there you go look at how it says if you use the dash capital t and the number zero

02:02:33.480 --> 02:02:42.220
what does the description say and map the ip number paranoid intrusion detection system

02:02:42.220 --> 02:02:52.020
invasion yeah and the t1 is sneaky t2 is polite right then we got normal aggressive and insane

02:02:52.020 --> 02:02:59.140
nmap is insane on itself but if you put a dash t5 oh man you just begging to be caught

02:02:59.140 --> 02:03:06.910
you put the dash t0 you're like this i just don't want to get caught but keep this in mind

02:03:06.910 --> 02:03:15.360
it may take you five weeks before you get an answer if you don't have a super duper machine

02:03:15.360 --> 02:03:24.400
it may take forever you understand whereas for these vulnerable machines you can use the dash

02:03:24.400 --> 02:03:34.560
t5 and look at how it's written in the map the ip address space dash t5 right scroll scroll up a

02:03:34.560 --> 02:03:46.920
little bit more os detection so remote os detection is the attack capital o and fingerprinting right

02:03:46.920 --> 02:03:53.800
go up a little bit more you have the dash capital a scroll down one more the next section service

02:03:53.800 --> 02:04:00.920
and version detection enables os detection version detection script scanning and trace route

02:04:01.800 --> 02:04:09.210
so let's click on the terminal on the left hit the up arrow on the left one time

02:04:10.410 --> 02:04:20.000
put in a space tack capital a don't forget that oh tack means dash that's how we talk in cyber

02:04:20.000 --> 02:04:33.860
that's okay press enter now let's compare from the first in map scan to the second one notice

02:04:33.860 --> 02:04:44.490
how this one's taken a little bit look at all that information it gave you does that make your head

02:04:44.490 --> 02:04:54.630
hurt or what not yet good well Donna you are pen testing you are conducting vulnerability analysis

02:04:54.630 --> 02:05:00.630
of an IP address to see what's there to decide which one of these things I'm

02:05:00.630 --> 02:05:05.430
going to exploit which little window crack am I going to open am I going to

02:05:05.430 --> 02:05:10.830
do the second floor or the first one well there's more on the second floor than

02:05:10.830 --> 02:05:18.990
the first yes but getting up there is how do I get there and not be seen all

02:05:18.990 --> 02:05:23.630
these factors we call it common sense but it also to not everyone since it's

02:05:23.630 --> 02:05:31.550
common these are things that we need to know is first of all we don't want to get caught just don't

02:05:32.430 --> 02:05:40.350
secondly um how do i do this and get my information fast enough a lot of people in the pen test world

02:05:40.350 --> 02:05:48.830
like to in map and scan all 100 a whole 65 000 ports right let me show you that lesson now

02:05:49.950 --> 02:05:53.950
why would you want to do that though that's just way too many because because they don't know

02:05:53.950 --> 02:05:59.310
because all they want to do is find a flag i care less about a flag i'm talking about protecting

02:05:59.310 --> 02:06:04.750
your social security number and everyone else is on that home network your intellectual property

02:06:04.750 --> 02:06:09.870
and so forth that's what a flag represents in these boner hogs as long as you know that you're

02:06:09.870 --> 02:06:27.080
good hit the up arrow again hit a space dash p dash don't forget the dash dash p dash oh hold

02:06:27.080 --> 02:06:36.760
it dash p dash now hit enter again guess what you just added a new switch to the nmap the network

02:06:36.760 --> 02:06:43.880
mapping command and it's going to do an even more intrusive scan go back to the cheat sheet on your

02:06:43.880 --> 02:06:52.840
firefox go back to that cheat sheet in the firefox now i want you to do ctrl f and type dash p dash

02:06:52.840 --> 02:06:59.200
just go to the bottom left where it says time go back to firefox we were talking about firefox

02:06:59.200 --> 02:07:11.000
now oh i'm okay see where it says there you go type dash p dash there you go what are you doing

02:07:11.000 --> 02:07:19.180
scanning ports how many ports 65 000 or the ones that you picked to scan

02:07:19.180 --> 02:07:29.500
you can decide now now read the description what does it say uh specific target specific ports

02:07:29.500 --> 02:07:37.340
ranges or combinations of tcp and udp ports you're reading too much you have dash p dash

02:07:37.340 --> 02:07:46.380
highlighted in green right yes i do read that it scans all ports there you go oh all ports is what i

02:07:46.380 --> 02:07:57.400
want you to know so now we go back to the left just click in the box there you go starting in

02:07:57.400 --> 02:08:10.200
map 7.995 we scan a report for the ip virtually no latency not shown what's that number 65532

02:08:14.380 --> 02:08:27.720
you see that sure no okay go to the top of the in map scan in map 10.0 that 3.16 a dash p dash p

02:08:27.720 --> 02:08:32.040
yeah no i'm there okay put your cursor there and show me that you're there

02:08:33.160 --> 02:08:43.160
yeah now now go to the not shown there you go highlight the 655 532 oh i'm with you right

02:08:43.160 --> 02:08:47.880
the reason why you see that is because you put in the dash p dash

02:08:48.760 --> 02:08:54.680
yes because when you go go above it and look at the one above it post it up

02:08:56.520 --> 02:09:01.560
no no no scroll to the in map scan above it scroll up oh

02:09:03.560 --> 02:09:08.840
they go right there when you don't when you just put the dash oh you went too far

02:09:08.840 --> 02:09:22.070
go a little bit just a little bit go up a little bit just use the scroll bar

02:09:23.910 --> 02:09:27.590
there you go right there you see the in map scan you did before the um

02:09:28.630 --> 02:09:36.790
no i'm sorry you went down scroll up to the command you did before scroll don't don't type

02:09:36.790 --> 02:09:46.950
it in again just roll roll scroll the scroll let me go no just use the um no no no no you're you're

02:09:46.950 --> 02:09:55.910
typing the command so use the mouse and scroll to the command before the output before right here

02:09:56.550 --> 02:10:03.990
yeah i want you to show me the one before that scroll up go up use the cursor stuff whatever

02:10:03.990 --> 02:10:16.570
you've got to do to go up just click above left click right there do you have one of these on

02:10:16.570 --> 02:10:25.830
your mouse this thing right here i don't have a mouse okay can you swipe down a little bit or

02:10:25.830 --> 02:10:34.780
just so that you can see the command before it you just did it a second ago get the scroll bar

02:10:34.780 --> 02:10:40.140
it's like i'm so stuck use the scroll bar on the right use that scroll bar right there to the right

02:10:40.140 --> 02:10:47.900
right right there go up a little bit just go up a little bit there you go keep going keep going

02:10:47.900 --> 02:10:53.900
keep going keep going okay keep going keep going till you get to the command you type

02:10:53.900 --> 02:11:01.780
right there oh okay scroll down a little bit because i see the in map dash a i'm trying to

02:11:01.780 --> 02:11:10.340
get you to show that okay now scroll up again and just go slow until you get there

02:11:10.340 --> 02:11:18.410
no grab the um the bar like you did before you know what's happening is that my scroll

02:11:18.410 --> 02:11:24.890
it keeps getting hung up it will not scroll me all right so i'll go back down right there

02:11:24.890 --> 02:11:30.570
right there that's it that's it that's it that's it that's all i want you to do you just did it

02:11:30.570 --> 02:11:38.810
and it says um what am i looking for okay here's the question how many ports did both of those

02:11:38.810 --> 02:11:49.620
in map scans um how many ports did they scan well one of them was a thousand no 997 closed

02:11:49.620 --> 02:12:00.520
and three open no no no no no no add 997 plus three there you go that's the answer how many

02:12:04.520 --> 02:12:07.960
okay so let me say it again i want you to talk with confidence

02:12:07.960 --> 02:12:16.710
how many how many ports were scanned with both of those in map scans with both of them all the

02:12:16.710 --> 02:12:25.350
ports how about this in map 10.0.3.16 how many ports were scanned one thousand fantastic that's

02:12:25.350 --> 02:12:34.630
a great answer how many ports were open three how many points were closed 997. that's what

02:12:34.630 --> 02:12:42.210
So here's what. Those are test questions. If you decide to sit for a certification,

02:12:42.410 --> 02:12:48.430
those are test questions. I just wasn't. Yes, I understand.

02:12:48.430 --> 02:12:55.550
Now we did the dash capital A and we see what are the names of the three ports that are open?

02:13:00.130 --> 02:13:09.910
21, 22, and 80. And what is port 21? 21 is the TCP port.

02:13:10.490 --> 02:13:12.450
What does it say there for service?

02:13:13.110 --> 02:13:13.670
FTP.

02:13:14.090 --> 02:13:14.650
FTP.

02:13:15.230 --> 02:13:17.350
Which means what?

02:13:19.740 --> 02:13:21.540
FTP is...

02:13:21.540 --> 02:13:23.260
Go ahead and Google it if you don't know it.

02:13:23.940 --> 02:13:25.180
Yeah, I'm going to Google it.

02:13:25.260 --> 02:13:25.820
There you go.

02:13:26.280 --> 02:13:39.280
The protocol is file...

02:13:39.280 --> 02:13:40.380
Oh, I know this.

02:13:40.520 --> 02:13:41.400
See, that's the thing.

02:13:41.460 --> 02:13:42.160
I know this.

02:13:42.240 --> 02:13:47.020
It's just that file transfer protocol, port 21.

02:13:47.920 --> 02:13:48.500
Okay, good.

02:13:48.500 --> 02:13:50.360
So what does that infer?

02:13:50.360 --> 02:13:57.880
or what does that mean file transfer protocol what are you thinking it's the network file service

02:13:57.880 --> 02:14:07.560
which means what layman's terms how the network transfers files to the users which means that

02:14:07.560 --> 02:14:16.360
if i knew how ftp works i could potentially transfer files to or from the target machine

02:14:16.360 --> 02:14:24.280
you understand that that's how we dissect this when we see open ports right whereas if i walk

02:14:24.280 --> 02:14:30.040
around your house if i see that window cracked on the basement floor or the second floor i could

02:14:30.040 --> 02:14:39.560
potentially open the window and climb in or take stuff out you understand yes what is port 22

02:14:39.560 --> 02:14:53.240
422 is tcp ssh ssh which is soft shell which is a secure network which is secure secure shell

02:14:53.240 --> 02:15:00.760
right secure shell i mean secure shell yes right now so you can go ahead encrypt your message here

02:15:01.320 --> 02:15:08.840
which means that do you know how to use secure shell or ftp i've used that a lot in labs but i

02:15:08.840 --> 02:15:20.470
i mean do you remember what commands you type do i remember the commands you type you can say no

02:15:20.470 --> 02:15:27.190
i don't care no i don't know okay here it is it'll probably come back to me so here's the cool thing

02:15:27.190 --> 02:15:37.990
all you need is a username the service ftp or secure shell a password and then you can now

02:15:38.870 --> 02:15:46.550
send information back and forth or retrieve information do you understand that's how i

02:15:46.550 --> 02:15:58.630
will gain access to your intellectual property you understand now the last port port 80 what does that

02:15:58.630 --> 02:16:10.070
mean is the http port which means what http means just the the web pages you're pulling up no no

02:16:10.070 --> 02:16:34.950
H means this. T means that. T. Yes, yes, yes, it is. Hypertext transfer protocol. I knew you knew it. I did know that. I mean, I know them all. It's just that my, I don't know. It's just that my brain feels that this is new and it's not new. It's just that it's a new platform.

02:16:34.950 --> 02:16:40.230
so i get all i breathe like my brain pretends like it doesn't know that i know all this it's

02:16:40.230 --> 02:16:47.430
just not clicking on full cylinder and that's why we're taking our time so http hypertext transfer

02:16:47.430 --> 02:16:55.830
protocol and we see that's an apache 2.4.18 version right it says site doesn't have a title

02:16:56.630 --> 02:17:04.070
right they got the server header it's an ubuntu server wow we have all kinds of information that

02:17:04.070 --> 02:17:12.580
we gathered with that dash capital a we can see the difference between when we first did the um

02:17:14.340 --> 02:17:20.340
the first command which only gave us a few lines we did a dash capital a it gave us a lot more

02:17:20.340 --> 02:17:26.740
information right and we have to read every last line and then the bottom one with the tag the deck

02:17:26.740 --> 02:17:38.420
the tag the tack p dash is searched all 65 536 ports by the way the top port number is 65 535

02:17:39.140 --> 02:17:49.540
the bottom port number is zero that's what makes 65 536 ports you understand because computer starts

02:17:49.540 --> 02:17:57.540
with zero we humanoid starts with one we know zero is a uh uh nothing now i need you to scroll

02:17:57.540 --> 02:18:13.450
to the bottom on the left oh god the scroll yeah let's go down good so the the key here is when it

02:18:13.450 --> 02:18:21.370
highlights blue you're on top of it now i want you to hit the up oh i wanted you to hit the up arrow

02:18:21.370 --> 02:18:26.250
once i don't know what's going on here hit the upper one oh you gotta scroll down you way up

02:18:26.250 --> 02:18:37.740
there press the down arrow and go all the way down you're going down or up i'm down uh you can't be

02:18:37.740 --> 02:18:47.580
you can't don't hit the oh yeah hit the up arrow one time there you go stop okay space

02:18:47.580 --> 02:18:56.020
there's two ways to do this i want to show you the fast way the the greater than sign so shift

02:18:56.020 --> 02:19:16.190
and period space and i want you to type um basic pen testing in map scan dot txt that's a lot

02:19:16.190 --> 02:19:34.000
or you can put bp bp nmap scan dot txt yes or no all one word bp nmap scan dot txt all one word

02:19:34.000 --> 02:19:41.840
dot but don't forget the dot you need that dot that's the extension dot txt got it yes sir

02:19:41.840 --> 02:19:55.620
press enter it's it's thinking it's waiting it's doing it's making us wait what happened

02:19:55.620 --> 02:20:08.710
Okay, good. Now I want you to list everything that's there. Type ls and enter. Do you see

02:20:08.710 --> 02:20:21.540
that right there? Go ahead and open it. Do you know how to open it? Type cat for concatenate

02:20:21.540 --> 02:20:35.920
space type the letter b in the tab key press enter there you go you created a text file

02:20:35.920 --> 02:20:39.720
with all that stuff so now you can use that later for your documentation

02:20:39.720 --> 02:20:50.140
okay concat is concatenate which is how you open up a file from the terminal bad guys like to work

02:20:50.140 --> 02:20:56.820
in the terminal they more hidden that way so now we got that preserved you can do that for anything

02:20:56.820 --> 02:21:02.600
by the way yeah and i think the actual on that cheat sheet i think it shows you how to create

02:21:02.600 --> 02:21:10.400
a file i think it's the tack o capital n command that shows you how to do that you now have this

02:21:10.400 --> 02:21:17.160
data you take this data and you come back to the lab either by yourself or with the team and say

02:21:17.160 --> 02:21:24.820
hmm i need to learn how ftp works i need to learn how ssh works i need to learn how port 80 works

02:21:24.820 --> 02:21:31.840
Wait a minute. Port 80. Isn't that just the browser? Isn't that just the browser?

02:21:34.710 --> 02:21:36.750
Isn't it what just the browser? Port 80?

02:21:36.850 --> 02:21:37.250
Port 80.

02:21:38.830 --> 02:21:39.350
No.

02:21:39.830 --> 02:21:40.490
Yes, it is.

02:21:40.930 --> 02:21:41.970
Go to Firefox.

02:21:42.730 --> 02:21:43.430
Go to Firefox.

02:21:48.310 --> 02:21:53.850
Okay, open up a new tab and type in 10.0.3.16.

02:22:00.180 --> 02:22:00.720
Press enter.

02:22:03.400 --> 02:22:05.460
Okay, type it in the URL at the top.

02:22:17.530 --> 02:22:19.010
Look at the message. It works.

02:22:19.010 --> 02:22:30.500
it says this is the default page for the server that is not a good thing we should never be able

02:22:30.500 --> 02:22:37.180
to access a server but as a pen test you like this oh there's something going on here the web server

02:22:37.180 --> 02:22:43.780
software is running but no content has been added yet hmm what are some things we can do way too

02:22:43.780 --> 02:22:59.270
many one is right click that page click on view page source man okay all right i don't see anything

02:22:59.270 --> 02:23:11.010
here that's making me jump so i'll i can now close that you will you will look to the right

02:23:13.670 --> 02:23:22.070
is there something in the way yeah i got it okay now this is all stuff you should be documenting

02:23:22.070 --> 02:23:28.710
inside of your report right you're showing them like look should i be on your default web page

02:23:28.710 --> 02:23:35.670
for your server and they're going to buy this oh no no that's no bueno right

02:23:36.630 --> 02:23:40.630
what you can do now is you can check this for vulnerabilities

02:23:42.630 --> 02:23:49.910
but to fast track you through this particular pen test report we did the in map scan because bad

02:23:49.910 --> 02:23:54.790
guys don't have to physically do the tom cruise and the mission impossible and come in physically

02:23:54.790 --> 02:24:03.910
and go into your space they'll just try to hack into a server somewhere yeah web application

02:24:03.910 --> 02:24:09.270
pentest right there's just one version of pentesting there's so many different mobile all

02:24:09.270 --> 02:24:16.870
that stuff now you see that you're there's a default web page in the server what do you need

02:24:16.870 --> 02:24:24.470
now in a perfect where if there's some way you can find a username and a password you could probably

02:24:24.470 --> 02:24:33.030
get into that server and there's a clue since there's an ftp a file transfer um protocol there's

02:24:33.030 --> 02:24:40.950
probably a file over there i need to get it and then ssh if i can secure shell into it i could get

02:24:40.950 --> 02:24:48.630
all its secrets are you understanding yes so the game plan is all right team i went to port 80

02:24:48.630 --> 02:24:55.750
i see that there's a ubuntu server there we have ftp we got ssh ssh is stronger

02:24:55.750 --> 02:25:03.590
let's see if we can ftp into that ip and let's see what comes up so now on your terminal

02:25:03.590 --> 02:25:15.070
the bottom you're going to type ftp space the ip address 10.0.3.16

02:25:15.070 --> 02:25:32.030
and whoa connected pro tp whoa pro ftp and that was up there in the nmap scan too

02:25:32.030 --> 02:25:40.650
so you know what you should do on the right terminal we're going to type the word search

02:25:40.650 --> 02:25:58.140
exploit one word yes all one word space type in capital p pro ftpd capital p you're going to write

02:25:58.140 --> 02:26:22.430
write that word pro ftp d d d oh t pd space 1.3.3 c low kc let's oh press enter oh snap

02:26:23.630 --> 02:26:30.350
what did i just do what did you just do there are some there are some vulnerabilities there

02:26:30.350 --> 02:26:38.190
there. And NMAP told you that there are vulnerabilities there. There is a compromised

02:26:38.190 --> 02:26:45.210
backdoor store. You also did that FTP on the left. Now, that means that you would have to go

02:26:45.210 --> 02:26:52.170
to Geeks for Geeks to find examples of FTP. But where it says student, type the word anonymous on

02:26:52.170 --> 02:27:11.390
the left real quick a-n-n-o-n-y-m-o-u-s press enter it says anonymous login okay send your

02:27:11.390 --> 02:27:21.930
complete email address as your password just press enter on the left login failed 530 login incorrect

02:27:21.930 --> 02:27:27.890
guess what every time you get a failure every time you get an in map with some stuff you should

02:27:27.890 --> 02:27:34.890
be searching it. It just goes with the territory. You can't act like, oh, I know what that is.

02:27:35.610 --> 02:27:43.290
Well, this is just a game. You literally do everything and document it. But it says FTP

02:27:43.290 --> 02:27:58.900
on the left. Well, hmm. Type in, who am I on the left? Invalid. Okay. Well, what else can we do?

02:27:58.900 --> 02:28:10.580
type in ls please log in with user and pass can't find bind or think you're already in use

02:28:10.580 --> 02:28:23.260
okay well we're getting close there's something there type in ls space dash al

02:28:23.260 --> 02:28:34.120
press enter please log in with user and pass okay type exit we've already expended our

02:28:34.760 --> 02:28:44.650
press the up arrow press enter type anonymous spell it right a n-o-n

02:28:46.650 --> 02:28:59.530
y-m-o-u-s press enter press enter type in um ls space tag al enter

02:29:01.210 --> 02:29:06.410
okay we're gonna have to figure that out that's okay though hold on one

02:29:07.130 --> 02:29:09.750
Segundo. Let's go here.

02:29:10.870 --> 02:29:11.390
Basic.

02:29:12.130 --> 02:29:17.610
All right, then.

02:29:19.350 --> 02:29:21.190
The SV gives you some good stuff, too.

02:29:24.380 --> 02:29:26.100
SV. What are you looking at?

02:29:26.420 --> 02:29:27.400
I'm looking at my notes.

02:29:28.980 --> 02:29:32.980
So now, that's the cool thing about this thing.

02:29:34.640 --> 02:29:36.840
Anonymous sometimes works.

02:29:37.200 --> 02:29:39.160
That is something for you to look up later.

02:29:39.560 --> 02:29:42.000
And I'll try to be here with you so we can look it up,

02:29:42.000 --> 02:29:43.760
because there's a reason for it.

02:29:43.760 --> 02:29:50.940
If it's telling you this area right here and you don't have the actual username and password, you won't be able to get the information, and that's fine.

02:29:51.240 --> 02:30:00.300
But the Pro FTPD shows you, when you did the search exploit, that there is a compromised source backdoor.

02:30:01.220 --> 02:30:08.300
Linux remote is a .txt file, and then there's the backdoor command execution where you can use Metasploit.

02:30:09.140 --> 02:30:11.000
So may I ask a question?

02:30:11.180 --> 02:30:11.400
Yes.

02:30:11.400 --> 02:30:15.400
We're on Cali, and so you just did a search exploit.

02:30:15.940 --> 02:30:21.400
So I don't have to, like, pull up the individual tool of Metasploit.

02:30:21.540 --> 02:30:26.080
I can just combine them on Cali with the proper command.

02:30:27.040 --> 02:30:32.080
Oh, that was – so you're going to have to use the individual tool for Metasploit,

02:30:32.140 --> 02:30:34.120
but what you want to do is search for vulnerabilities.

02:30:35.080 --> 02:30:37.660
You can search for vulnerabilities at the CVE website.

02:30:38.000 --> 02:30:39.220
You can search it on Google.

02:30:39.220 --> 02:30:46.280
the bottom line is you don't know you didn't know what pro ftpd was don't care what you use

02:30:46.280 --> 02:30:53.680
to research it once it shows you that there is a potential backdoor into that specific system

02:30:53.680 --> 02:31:00.300
now you have a choice you can do that whole remote code execution or you can use metasploit

02:31:00.300 --> 02:31:22.780
what you're going to do now is type msf console on the right press enter this is how you enter

02:31:22.780 --> 02:31:31.540
metasploit you're exploiting you decided to exploit the backdoor command execution what

02:31:31.540 --> 02:31:38.980
you would do is you will google search how to do that and google will give you steps on how to do

02:31:38.980 --> 02:31:45.780
that. Does that make sense? Yes. Okay. So for right now, what I'm going to do is I'm going to

02:31:45.780 --> 02:31:50.220
give you some steps just so that we can get it and then we'll reverse engineer it at the end.

02:31:51.760 --> 02:32:03.980
Now that you're in Metasploit, I want you to type search space pro FTPD, like it was typed,

02:32:04.500 --> 02:32:12.080
capital P. Yeah. R O. It's on the left side. See it written? I know. I got to find it. Okay.

02:32:12.300 --> 02:32:14.600
F-T-P-G.

02:32:14.960 --> 02:32:16.600
That's an R there, just so you know.

02:32:20.350 --> 02:32:21.730
T-T-P-G.

02:32:22.610 --> 02:32:23.310
Don't forget the capital.

02:32:26.940 --> 02:32:31.620
Space 1.3.3C.

02:32:33.720 --> 02:32:35.900
I'll say yes.

02:32:36.740 --> 02:32:37.360
Press enter.

02:32:38.500 --> 02:32:39.840
Oh, wow.

02:32:39.920 --> 02:32:40.860
Look at that right there.

02:32:41.680 --> 02:32:42.780
Look at the feedback.

02:32:42.780 --> 02:32:47.160
It's letting you know that it has a ranking of excellence.

02:32:47.160 --> 02:32:57.010
That should give you some confidence that you can actually pen test and create a backdoor into this system.

02:32:57.870 --> 02:32:58.770
Not that hard.

02:32:59.550 --> 02:32:59.970
Exactly.

02:33:00.290 --> 02:33:05.370
So now there is the use number is actually zero.

02:33:07.520 --> 02:33:10.860
See, it says number, name, disclosure, date, rank.

02:33:12.140 --> 02:33:13.620
The number is zero.

02:33:13.620 --> 02:33:20.340
So what you need to type is use, U-S-E, space, zero.

02:33:21.420 --> 02:33:21.740
Enter.

02:33:23.840 --> 02:33:24.240
Uh-oh.

02:33:24.520 --> 02:33:26.300
It's taking you into the back door.

02:33:28.580 --> 02:33:30.700
Now you want to type the word options.

02:33:34.000 --> 02:33:35.000
Make sure you spell it right.

02:33:36.520 --> 02:33:42.020
Okay.

02:33:42.260 --> 02:33:42.900
What's that say?

02:33:43.240 --> 02:33:44.380
It gives you a lot of heat.

02:33:45.660 --> 02:33:49.060
The C host, the proxies, those are a no.

02:33:49.380 --> 02:33:50.060
They're required.

02:33:50.160 --> 02:33:50.780
They're not required.

02:33:50.780 --> 02:33:56.460
There are hosts, and there are ports for port 21 are required.

02:33:57.540 --> 02:33:57.800
Okay.

02:33:57.800 --> 02:34:03.740
those are the remote hosts okay so now this is what we're going to do from here

02:34:03.740 --> 02:34:11.120
you're going to set the our host so that's what it's telling you to do type

02:34:11.120 --> 02:34:27.550
in sct space our host and what is your IP address for the remote host now no s on

02:34:27.550 --> 02:34:35.880
our host you want me to put the IP address with the IP address of the

02:34:35.880 --> 02:34:49.100
remote post. There you go. You got it. Press enter. It's set. Fantastic. Now you want to type the word

02:34:49.100 --> 02:35:12.520
show payload. Okay. Show payloads with an S. Put a space after the word show.

02:35:12.520 --> 02:35:25.490
Wow. Look at all these different ways you can actually create a backdoor into this machine.

02:35:26.050 --> 02:35:26.910
Isn't this exciting?

02:35:27.870 --> 02:35:28.390
Yes.

02:35:29.670 --> 02:35:30.030
OK.

02:35:30.370 --> 02:35:34.110
So we are looking at the numbers again and the names.

02:35:34.750 --> 02:35:37.090
We have to find something that's going to match,

02:35:37.150 --> 02:35:39.390
something that's going to work for this particular machine.

02:35:40.510 --> 02:35:41.610
So let me see here.

02:35:41.610 --> 02:35:43.710
Double, purl, this.

02:35:46.070 --> 02:35:53.010
The command Unix reverse should work, which is number four.

02:35:53.010 --> 02:36:09.110
so we want to set payload type in set space payload space four space four space four

02:36:09.110 --> 02:36:22.010
press enter okay that's the command unix linux reverse shell all right and it should come up

02:36:22.010 --> 02:36:31.990
that then we want to type the word options press enter oh snap we got a whole lot going on

02:36:31.990 --> 02:36:39.590
we got c host we have the r host is 10.0.3.16 that's what we want the target port is port 21

02:36:40.230 --> 02:36:50.920
the l host is required on port 444 so what we want to do now is we want to set the l host

02:36:50.920 --> 02:36:59.680
i need to look up lhost what is an lhost the uh local local host your machine for listening okay

02:36:59.680 --> 02:37:19.130
yeah so set got it type in set oh set okay space lhost now you got to remember space

02:37:19.130 --> 02:37:26.390
your ip address for the um the cali linux machine so this is what you're going to do

02:37:26.390 --> 02:37:30.770
On the left side, on the left terminal, right click.

02:37:31.970 --> 02:37:34.090
Split the terminal top and bottom.

02:37:36.420 --> 02:37:38.080
Type in IP space A.

02:37:42.150 --> 02:37:42.710
Press enter.

02:37:43.990 --> 02:37:45.350
What's your IP address?

02:37:45.490 --> 02:37:46.410
10.0.1.

02:37:46.870 --> 02:38:00.180
Type that in as your L host.

02:38:00.660 --> 02:38:04.580
Wrong time.

02:38:04.900 --> 02:38:05.200
Hello.

02:38:06.680 --> 02:38:09.420
Right.

02:38:09.580 --> 02:38:10.640
That's your listening machine.

02:38:10.920 --> 02:38:15.980
Press enter.

02:38:17.140 --> 02:38:17.700
Okay.

02:38:18.500 --> 02:38:20.340
Now, how are you feeling?

02:38:20.960 --> 02:38:31.810
okay let's run it type are you in press enter all right it's starting to

02:38:31.810 --> 02:38:41.290
listener sending backdoor commands saying that cool okay now okay we got

02:38:41.290 --> 02:38:50.210
these accepted it B is in okay let's see here session open one session is

02:38:50.210 --> 02:39:05.140
open it's created okay type in who am i oh you are root in the end of the day once you get root

02:39:05.140 --> 02:39:13.300
access that means you have admin access right that means you can do anything that you want to do

02:39:14.100 --> 02:39:26.790
okay now type um id enter verify you have root access as the user the uid

02:39:26.790 --> 02:39:39.990
root access in the group okay so now type in um change directory cd space slash root forward slash

02:39:39.990 --> 02:39:59.280
root press enter type ls type ls space tag al wow you got some heat in there right

02:39:59.280 --> 02:40:07.940
this is what you would do once you get into the machine guess what the goal was for basic

02:40:07.940 --> 02:40:17.160
pen testing the goal is to get in to the system and you're in and you've done it you tracking

02:40:17.160 --> 02:40:27.240
through a tv yes you just hacked into a machine and got root access if a bad guy can get root

02:40:27.240 --> 02:40:36.240
access into any machine life is not grand if there was data on that machine it would show up

02:40:36.240 --> 02:40:43.060
like that when you type the you go on the slash root and you type list and um now there's good

02:40:43.060 --> 02:40:51.240
data there the bash uh the dot bash rc the dot cache all that's the profile you would have to

02:40:51.240 --> 02:40:59.670
research all of that to see what they mean right when a person gets inside of a machine

02:40:59.670 --> 02:41:05.710
they want to find, get root access, and they want to find any and all data that they can.

02:41:07.650 --> 02:41:18.250
Usernames, passwords, all that. Now what you need to do is screenshot all of this process,

02:41:18.910 --> 02:41:24.010
and then I'm going to give you something. Go to Firefox right there.

02:41:27.100 --> 02:41:32.940
so screenshot what do how do i do that i'll show you in a minute go to firefox

02:41:33.820 --> 02:41:44.300
firefox um there we go open up a new open up a new tab yep and i want you to type in metasploit

02:41:45.660 --> 02:42:03.350
space tutorial press enter wow getting started with metasploit

02:42:04.150 --> 02:42:09.910
meta's play unleash free online ethical hacking course uh step-by-step guide

02:42:10.790 --> 02:42:16.230
click on the step-by-step guide let's see what that is that's the box i like that guy

02:42:16.950 --> 02:42:26.490
scroll down a little bit allow selection something use unnecessary cookies only whichever one gets

02:42:26.490 --> 02:42:35.990
rid of that cookie thing click on you click at the bottom it says use necessary cookies only

02:42:35.990 --> 02:42:48.800
on the far right just click the box use necessary cookies only on the right click

02:42:48.800 --> 02:43:08.150
that there you go now scroll to the top swipe it down scroll up to the top something

02:43:08.150 --> 02:43:25.780
a touchscreen straight out to the table of contents scroll down to the table of

02:43:25.780 --> 02:43:51.810
contents scroll down oh you went far down okay so here's how it is since the

02:43:51.810 --> 02:44:04.690
scroll bar is messing with you. This is just one of many resources that will show you how to use

02:44:04.690 --> 02:44:13.490
Metasploit. How many things can you do in Metasploit? Too many. Are we going to get it in two

02:44:13.490 --> 02:44:25.010
days probably not metasploit establishes a guaranteed tcp handshake and you can do the

02:44:25.010 --> 02:44:32.690
absolute most inside of someone else's machine by just following these steps that you actually did it

02:44:32.690 --> 02:44:38.610
and now you need to reverse engineer by reading the instructions go ahead and click the back

02:44:38.610 --> 02:44:49.140
button at the top left yes took it again okay click on the first one getting

02:44:49.140 --> 02:44:57.780
started metasploit for pen test okay rapid seven yes um everything you need

02:44:57.780 --> 02:45:06.720
is online there are even better or more maybe user-friendly metasploit tutorials

02:45:06.720 --> 02:45:11.280
where you literally go step by step by step by step by step by step you need to

02:45:11.280 --> 02:45:12.900
create that in your OneNote

02:45:12.900 --> 02:45:14.320
for yourself.

02:45:15.880 --> 02:45:17.360
So that when or if

02:45:17.360 --> 02:45:19.000
you ever have to do this

02:45:19.000 --> 02:45:21.180
by yourself, you know

02:45:21.180 --> 02:45:23.100
exactly what to do. You know what L hosts mean.

02:45:23.220 --> 02:45:25.160
You know what R hosts mean. You know how to set the

02:45:25.160 --> 02:45:27.220
options. You know how to run it. You know how to set the

02:45:27.220 --> 02:45:30.460
payloads. So now...

02:45:30.460 --> 02:45:32.440
Can we do a sample? Yes, we're going to do it.

02:45:32.440 --> 02:45:34.080
A status point? You just did it.

02:45:34.880 --> 02:45:36.500
But what we're going to do now is take notes.

02:45:38.240 --> 02:45:38.680
Go to

02:45:38.680 --> 02:45:40.440
your... Click on the

02:45:40.440 --> 02:45:44.940
terminal behind you. Scroll

02:45:44.940 --> 02:45:59.370
all the way up to the top on the left fantastic now go to your one note what is the one note i

02:45:59.370 --> 02:46:04.010
don't know what one note is we don't use it okay click on the dragon on the top left

02:46:05.050 --> 02:46:11.930
oh cali type in one note that's only because i installed it i installed it for you so you can

02:46:11.930 --> 02:46:20.490
have it you you click on the dragon again it was just there click on the dragon type one note

02:46:20.490 --> 02:46:23.170
see it right there

02:46:23.170 --> 02:46:30.590
fantastic

02:46:30.590 --> 02:46:33.890
I have to teach you how to take notes

02:46:33.890 --> 02:46:36.030
this is actually my OneNote

02:46:36.030 --> 02:46:37.730
right

02:46:37.730 --> 02:46:40.310
hold on a second

02:46:40.310 --> 02:46:42.150
close my OneNote

02:46:42.150 --> 02:46:47.450
what kind of computer are you using

02:46:47.450 --> 02:46:50.340
HP Envy

02:46:50.340 --> 02:46:53.260
but I have it all dismantled

02:46:53.260 --> 02:46:55.200
and like you know weirded out

02:46:55.200 --> 02:46:56.600
so I can get through the lab

02:46:56.600 --> 02:46:58.260
without any pop-ups

02:46:58.260 --> 02:47:12.850
so okay well my thing is i want to say um hp um can you go just do you have um a microsoft account

02:47:17.560 --> 02:47:29.300
do i have microsoft count and a microsoft account yeah oh i mean let's let's just take a look it's

02:47:29.300 --> 02:47:57.730
quick okay okay so go to um your host computer in the search bar and type one though and yes sir

02:47:57.730 --> 02:48:06.520
um are you able to share your screen where i can see that window on your host computer see it

02:48:07.480 --> 02:48:25.170
you're sharing the desktop window for the desktop can you minimize your screen minimize yeah

02:48:25.170 --> 02:48:49.490
minimize that um terminal okay it's not that um minimize your um minimize the desktop i can't

02:48:49.490 --> 02:48:57.090
even find that where to minimize it it's not the top right anywhere or bottom yeah i mean can you

02:48:57.090 --> 02:49:03.250
see where i'm supposed to minimize this because all i'm trying to do is see your host computer

02:49:04.450 --> 02:49:10.290
i know i'm trying to pull it up okay uh go to go to the zoom icon at the bottom

02:49:10.290 --> 02:49:12.830
Zoom icon. I'm there.

02:49:13.950 --> 02:49:16.270
Okay. Stop sharing.

02:49:17.690 --> 02:49:21.370
Stop sharing this one. Stop sharing. Let's just see what's going on.

02:49:33.150 --> 02:49:36.890
Let me know what's happening because I don't see anything. I don't see

02:49:36.890 --> 02:49:40.050
anything either. And I don't have, I don't

02:49:40.050 --> 02:49:47.120
let me just look for it. So it should be at the

02:49:47.120 --> 02:49:50.820
bottom. It should say Zoom. It does, but it doesn't pull up.

02:49:50.820 --> 02:49:54.880
It's just a Zoom page with nothing on it.

02:49:55.080 --> 02:49:59.920
And you don't see the stop share red button, the little hidden icon thing that dropped down before?

02:50:01.360 --> 02:50:03.100
No, because, oh, hold it.

02:50:03.180 --> 02:50:04.120
Let me get my profile.

02:50:04.460 --> 02:50:07.480
There you are.

02:50:07.780 --> 02:50:08.960
I see you now.

02:50:09.280 --> 02:50:11.660
But so this all got shut down.

02:50:12.440 --> 02:50:12.740
Okay.

02:50:13.440 --> 02:50:16.640
Do you have another screen by chance in your home?

02:50:18.960 --> 02:50:19.320
Yeah.

02:50:19.960 --> 02:50:20.200
Okay.

02:50:20.200 --> 02:50:20.820
I have a.

02:50:20.820 --> 02:50:26.820
yeah because if you can get another screen and hook this up all these problems go away

02:50:26.820 --> 02:50:34.850
oh it's gonna no i don't have another microsoft i have apple and it's not gonna go away it's

02:50:34.850 --> 02:50:40.650
gonna make it worse gotcha he's done no this is my only computer that i use for this stuff

02:50:40.650 --> 02:50:54.620
so do you have a smart television where you can cast stuff to it or even hdmi so no okay

02:50:54.620 --> 02:51:05.530
my network is the one i have this on okay meaning the other one is not my own i got you

02:51:05.530 --> 02:51:08.890
so let me let me share my screen with you let me just show you what i need you to do

02:51:10.170 --> 02:51:17.370
because this is a part of the lesson right uh report writing is something that we must do

02:51:17.370 --> 02:51:36.690
do. I'm going to share this thing. Can you see my screen? Yes. Fantastic. All right. So this is

02:51:36.690 --> 02:51:43.710
the basic pen testing that we just did. The Metasploit backdoor. I took a screenshot of the

02:51:43.710 --> 02:51:52.310
target. What I actually wanted your help with, I intentionally did not do this, is I documented the

02:51:52.310 --> 02:52:02.230
ip address i did the pseudo arp scan i got the output i ran my in map scan i did my search exploit

02:52:03.110 --> 02:52:12.870
i did my msf console i did my search on here for that i found what i needed right i'm using zero i

02:52:12.870 --> 02:52:18.710
have options all right it's showing me all these things right here that i can possibly do

02:52:18.710 --> 02:52:27.710
i set the r host i showed the payloads i selected number four that's what i wanted

02:52:27.710 --> 02:52:35.670
i did my options it put me right into the exploit unix ftp pro ftp

02:52:35.670 --> 02:52:41.630
right i mean i ain't gonna i've done some really advanced pen tests with metasploit

02:52:41.630 --> 02:52:43.770
And then I set the L host.

02:52:44.510 --> 02:52:46.270
I ran it, right?

02:52:47.210 --> 02:52:50.890
I think I had an error there, but I ran the thing.

02:52:51.850 --> 02:52:52.790
Who am I?

02:52:53.270 --> 02:52:53.930
See whatever.

02:52:54.310 --> 02:52:54.850
I run it.

02:52:55.190 --> 02:52:59.050
I really didn't have to do anything else because all I wanted to do was get into the machine.

02:52:59.610 --> 02:53:02.070
Once I was into the machine, I was good.

02:53:03.930 --> 02:53:07.390
The next pen test we want to do is going to become more advanced.

02:53:07.390 --> 02:53:18.900
now what i wanted you to do and i was going to help you with it is i want to show you how to

02:53:18.900 --> 02:53:28.670
write it like this you will never hurt see all these screenshots with my name on them

02:53:28.670 --> 02:53:38.360
because i'm trying to show you that i did it myself i have all my commands this will make

02:53:38.360 --> 02:53:46.820
things so much easier for you in the future when you're going to share that with me i'm going to

02:53:46.820 --> 02:53:53.780
show you how to do it. It doesn't take long. The only thing is you need to go to the search icon

02:53:53.780 --> 02:54:02.640
and type one note and open it. And then you're going to share it with whomever you want to.

02:54:03.080 --> 02:54:09.740
So I tell people all the time, I share things, lots of information, but not intellectual problems.

02:54:09.740 --> 02:54:13.620
I get it. But also too, is that so you can get that muscle memory.

02:54:13.620 --> 02:54:20.180
um by the way i just realized it's 12 18 we haven't taken a break and i apologize

02:54:20.180 --> 02:54:27.060
we can take a break anytime you need it but um i do need to take a break at 12 30 because i have

02:54:27.060 --> 02:54:33.900
somebody calling me do you um how long would you like to eat lunch 30 minutes an hour what do you

02:54:33.900 --> 02:54:42.280
want i i'm whatever you say okay i'm good with i don't need to eat i mean i'm i'll be back whenever

02:54:42.280 --> 02:54:49.300
you tell me to come back. Okay. Well, I only need to take a potty break and do a phone call,

02:54:49.500 --> 02:54:53.780
grab some lunch, and I can get back here as early as one o'clock if that's okay.

02:54:54.920 --> 02:55:00.340
Great. Fantastic. Well, in the meantime, let me get you started with this because I really want

02:55:00.340 --> 02:55:07.440
you to do it like this so you can show people it doesn't take long. It's just, I have to show you

02:55:07.440 --> 02:55:14.460
have so now i'm going to stop sharing and i want to show you how to get this one note we can do it

02:55:14.460 --> 02:55:20.080
in two places i just need to i need to see you i pulled it up but i don't know how to share it

02:55:20.080 --> 02:55:26.480
so if you see my image you should be able to share screen you have i see a share there you go

02:55:26.480 --> 02:55:35.760
now it's gonna pull share to microsoft outlook 365 i don't know just share the entire screen

02:55:35.760 --> 02:55:46.540
share entire notebook no entire screen that's not an option okay um what are the options

02:55:46.540 --> 02:55:55.820
the options are share notebook copy notebook email copy of page it's microsoft options it's not

02:55:55.820 --> 02:56:03.920
it's not on my zoom page okay well then just share it okay is that what you want uh something's

02:56:03.920 --> 02:56:12.290
happening yeah that's what i wanted now you're sharing the entire screen fantastic yes here we

02:56:12.290 --> 02:56:30.560
are yes okay here we go you ready type basic pen testing okay now um all right there i want you

02:56:30.560 --> 02:56:48.400
to put down my name dr wesley phillips w-e-s-l-e-y okay just put the uh s before the l and take that

02:56:48.400 --> 02:57:00.770
s out and wesley it's okay hey there you go now i want you to put down today's date august 1st

02:57:00.770 --> 02:57:13.040
2025 and you can put that right underneath my name when you get a chance just did this all

02:57:13.040 --> 02:57:20.800
summer my brain like okay i just gotta go back to school august 1st 2025 that i did reports all

02:57:20.800 --> 02:57:31.120
summer just fantastic now on the left where it says pen testing but click add page black

02:57:31.120 --> 02:57:40.880
add page good voila now you're gonna on underneath friday click there okay we're gonna make some

02:57:40.880 --> 02:57:46.400
magic happen okay you're gonna type i'm gonna read it to you we're not gonna make a mistake we're

02:57:46.400 --> 02:57:54.370
gonna go great type the word project but make sure you capitalize those because it's gonna be titles

02:57:54.370 --> 02:58:02.060
capital p in the word project hit the tab button fantastic type commands

02:58:08.260 --> 02:58:22.780
hmm you went to the other page okay that's okay now you're going to type um screenshots the tab

02:58:22.780 --> 02:58:41.310
button analysis the tab but one more time and type uh lessons learned like we need a long list

02:58:41.310 --> 02:59:05.660
for that box lessons learned press enter okay um you're gonna type objective okay

02:59:06.460 --> 02:59:13.180
on the under press the back backspace there you go put the cursor inside lessons learned

02:59:14.620 --> 02:59:20.700
underneath it press enter that's how you get a new line now you're going to type

02:59:21.340 --> 02:59:38.740
written permission okay we're going to fill in that information later put a right click

02:59:38.740 --> 02:59:50.640
in permission got an ion supposed within good put it in the lessons learn box press enter

02:59:51.440 --> 03:00:02.690
that's how you get a new line now you're going to type um find the target machine ip find target

03:00:02.690 --> 03:00:09.650
machine ip i just do target ip that's fine in the commands you're going to type

03:00:11.730 --> 03:00:28.320
sudo net discover sudo space net discover press enter as a matter of fact put the number one in

03:00:28.320 --> 03:00:41.390
front of sudo sudo one in front of in front of sudo put number one one period no no let's do it

03:00:41.390 --> 03:00:58.910
again one period space sudo put the cursor at the net discover press enter now you got a bullet

03:00:58.910 --> 03:01:12.080
two automatically now you're going to type pseudo space arp dash scan don't forget the dash

03:01:12.080 --> 03:01:23.540
otherwise you will not find it no no no space arp dash dash no go back go back oh

03:01:24.580 --> 03:01:41.920
arp dash no arp dash scan there you go space dash space okay dash l fantastic put the cursing lesson

03:01:41.920 --> 03:01:59.280
learn press enter now you want to write verify connectivity now commands number one period

03:01:59.280 --> 03:02:16.730
space ping press enter of course you'll ping the ip address you can put that in what yes you type

03:02:16.730 --> 03:02:34.180
it 10.0.3.16 i remember it yes enter what was the second command again f ping space 10.3

03:02:34.180 --> 03:03:10.010
0.3.16 okay go to lessons learned press enter okay um vulnerability scan on the end just right click

03:03:10.010 --> 03:03:21.820
and there you go there you go now press on one period space type in map space 10.0.3.16

03:03:21.820 --> 03:03:42.660
press enter, type in map space 10.0.3.16 space TAC capital A, I think what we did first,

03:03:42.660 --> 03:04:07.660
press enter type in map 10.0.3.16 space capital a space dash p dash or tack p tack yeah go ahead

03:04:07.660 --> 03:04:13.640
and press lessons learned press enter okay okay no no that's good go back to number four again

03:04:13.640 --> 03:04:27.660
you're right type in map space 10.3.16 space tack a space tack p

03:04:29.980 --> 03:04:37.340
capital a no same thing write the same thing you wrote we're adding space dash p dash

03:04:38.700 --> 03:04:45.020
capital a capital a write the same thing you did above that's what you said dash p dash

03:04:45.020 --> 03:04:58.040
Dash space, lowercase p, it makes a difference, dash space greater than sign, that's less

03:04:58.040 --> 03:05:20.270
than, space, I think we put bpnmapscan.txt, fantastic, go to lessons learned, press enter,

03:05:21.090 --> 03:05:28.030
there's so much more we can do, but let's get to where we need to be, we're going to,

03:05:28.030 --> 03:05:40.270
where is it? This is here. They move that. And here after we did that, the output of the scan

03:05:40.270 --> 03:05:55.820
is what we did next. So that was, oh, go to written permission lessons learned. Press enter.

03:05:56.180 --> 03:06:07.700
Oh, that didn't work. Backspace or control Z. Okay. Right. Click right there. Go to table.

03:06:10.580 --> 03:06:35.160
insert row below go up insert row below okay so um type find my ip address and you're going to

03:06:35.160 --> 03:06:50.220
type number one period space ip space address just so you know everything is always locating

03:06:50.220 --> 03:07:12.030
in linux unless it specifies it press enter or you can type ip space addr enter or you can type

03:07:12.030 --> 03:07:25.980
ip space a a small case a yeah i'm trying to do i don't have my caps on but it that's okay

03:07:25.980 --> 03:07:31.440
capitalizes i'm gonna go back and change all this i'm not worried as soon as you take your call

03:07:31.440 --> 03:07:36.620
i'm not even worried they didn't call yet so i'm gonna keep going now i need you to put the cursor

03:07:36.620 --> 03:07:46.000
down go press down arrow press backspace until you get back to the a there you go clean now see

03:07:46.000 --> 03:07:56.600
how clean that is now go to the lessons learn box no go to underneath vulnerability scan and we want

03:07:56.600 --> 03:08:27.100
to type um enumeration a slash exploitation okay now in the commands type one okay he's calling now

03:08:27.100 --> 03:08:33.100
So, um, put your screen, put your screenshots inside that, that box.

03:08:33.140 --> 03:08:33.440
Okay.

03:08:33.480 --> 03:08:34.480
Go to insert.

03:08:35.800 --> 03:08:36.320
All right.

03:08:36.360 --> 03:08:36.940
I'll be right back.

03:08:37.000 --> 03:08:37.380
We'll talk.

03:08:38.000 --> 03:08:38.600
All right.

03:08:38.660 --> 03:08:39.000
All right.

03:08:48.070 --> 03:08:48.470
Speaking.

03:08:50.670 --> 03:08:51.810
Pretty good news, Steve Perry.

03:08:56.120 --> 03:08:56.740
Yes, sir.

03:08:56.840 --> 03:08:58.260
I am busy, but it's a good time.

03:08:58.600 --> 03:09:12.940
About the opportunity.

03:09:13.420 --> 03:09:15.960
And if it aligns for you and it kind of makes sense,

03:09:16.060 --> 03:09:19.520
then we'll get into a little more about yourself and how you might align for

03:09:19.520 --> 03:09:20.320
this thing for us.

03:09:20.640 --> 03:09:21.480
Does that make sense?

03:09:21.700 --> 03:09:21.940
Sure.

03:09:21.940 --> 03:09:28.160
So, again, my name's Steve, and I work directly for ATEC.

03:09:28.400 --> 03:09:29.980
I'm the Talent Acquisition Director.

03:09:30.120 --> 03:09:36.000
And what we do at ATEC is really we're federal contractors with a focus on health IT.

03:09:36.360 --> 03:09:38.740
So we support companies.

03:09:39.580 --> 03:09:40.260
Are you still here?

03:09:48.520 --> 03:09:50.560
And it's really IT-focused.

03:09:51.280 --> 03:09:56.700
The opportunity that I'm looking at is an RFP, so I want to be very clear about that up front.

03:09:56.700 --> 03:10:03.780
um it's not the work that we want yet uh but we feel like we can position pretty well to it with

03:10:03.780 --> 03:13:17.420
our past performance is uh in contract actively teaching a penetration testing class and so

03:13:17.420 --> 03:13:24.420
that's and it was scheduled for today and tomorrow from nine to five five oh one i'm yours unless i

03:13:24.420 --> 03:13:29.260
can get out of here early which i doubt because uh people paid a lot of money to be in the course

03:13:29.260 --> 03:14:04.340
Yeah, I know you call that the craziest day in time. Normally, I'm totally available. But I'm just that I actually am teaching this course today. It's today and tomorrow and I'm available. I mean, I may be able to take a break at like 330 or something like that.

03:14:04.340 --> 03:14:10.000
But a lady that, I mean, these people are gung-ho with what I'm showing them.

03:14:10.480 --> 03:14:14.540
And it's a hands-on penetration testing course that I'm showing them.

03:14:15.060 --> 03:14:16.480
And you should see their faces.

03:14:16.700 --> 03:14:18.680
It's kind of like, I don't even know what to tell you.

03:14:19.360 --> 03:14:20.720
They are, like, excited.

03:14:21.140 --> 03:14:32.640
At least schedule something for you.

03:14:33.140 --> 03:14:34.420
All right, schedule that at 3.30.

03:14:34.460 --> 03:14:35.860
I'll see if I can get out of here.

03:14:36.080 --> 03:14:38.500
I mean, at least get on there.

03:14:41.240 --> 03:14:42.140
Yeah, exactly.

03:14:55.040 --> 03:14:55.560
Four is good.

03:14:55.600 --> 03:14:56.460
I can take a break at four.

03:14:56.460 --> 03:15:05.330
If you can

03:15:05.330 --> 03:15:09.010
I'm literally trying to send it to you now

03:15:09.010 --> 03:15:10.170
Don't go anywhere if you can

03:15:10.170 --> 03:15:12.850
I'm just trying to

03:15:12.850 --> 03:15:15.270
Where is my gmail

03:15:15.270 --> 03:15:20.780
And

03:15:20.780 --> 03:15:22.780
Steve Perry

03:15:22.780 --> 03:15:24.940
Famous name

03:15:24.940 --> 03:15:27.200
There you go, that's right

03:15:27.200 --> 03:15:30.200
As I get older, there's less people saying it

03:15:30.200 --> 03:15:32.080
That dude

03:15:32.080 --> 03:15:33.980
I happen to be a musician

03:15:33.980 --> 03:15:36.400
And he just sings his face off

03:15:36.400 --> 03:15:38.000
He does

03:15:38.000 --> 03:15:39.600
He doesn't that

03:15:39.600 --> 03:15:45.220
Definitely one of my favorite singers. So that I think now it's just something

03:15:45.220 --> 03:15:57.150
to that email. Now, if you need to redact anything, go ahead and do so.

03:15:58.310 --> 03:16:16.450
I want to give you the that's fine. You click on my portfolio, my cybersecurity portfolio,

03:16:16.450 --> 03:16:30.220
and you'll probably find it under certifications for this thing. And let me see if I can make four

03:16:30.220 --> 03:16:34.860
clockwork all right everybody take take a look at their resume real quick let me know if i have

03:16:34.860 --> 03:17:01.740
to change anything moved my eight stock cyber stuff that won't be a conflict anyway there's

03:17:01.740 --> 03:17:46.160
something that i mean i teach certification courses as well no i'm in my house teaching

03:18:52.510 --> 03:18:57.230
so much has happened in those past 27 minutes

03:18:57.230 --> 03:19:15.310
can you share yes i can um so um uh i uh this guy emailed me last night and he pretty much offered

03:19:15.310 --> 03:19:22.670
me a job and um i would be the the deputy chief information security officer for a government

03:19:22.670 --> 03:19:29.230
agency and um he's like i need to know something today because they want to interview you today and

03:19:29.230 --> 03:19:33.030
And I was like, he said, we have to have something in place by Monday again.

03:19:34.090 --> 03:19:35.330
I was like, that's fast.

03:19:35.390 --> 03:19:36.470
He's like, can you interview today?

03:19:36.550 --> 03:19:38.330
I said, man, I'm teaching a class right now.

03:19:39.130 --> 03:19:39.670
So I said, no.

03:19:39.670 --> 03:19:40.910
Don't let him pressure you.

03:19:41.010 --> 03:19:42.570
You just jack up the price.

03:19:42.750 --> 03:19:43.270
I did.

03:19:44.310 --> 03:19:44.630
Yes.

03:19:45.290 --> 03:19:46.770
Way to go, Dr. West.

03:19:46.830 --> 03:19:47.370
Thank you.

03:19:47.630 --> 03:19:49.170
So we'll see what happens.

03:19:49.170 --> 03:19:51.210
But I'm going to work that out.

03:19:51.430 --> 03:19:54.450
And I sent him a resume and a whole nine.

03:19:54.450 --> 03:19:59.490
And then I got some Chinese food ordered that's going to be delivered to me.

03:19:59.530 --> 03:20:00.630
I can't wait to get it.

03:20:01.690 --> 03:20:02.230
Oh, good.

03:20:02.770 --> 03:20:03.150
Yeah.

03:20:03.430 --> 03:20:08.310
But I'm also excited about what we're doing because I can see evidence of your work.

03:20:08.850 --> 03:20:10.290
This is repeatable stuff.

03:20:11.450 --> 03:20:11.690
Yeah.

03:20:12.090 --> 03:20:17.710
I'm better at just being in the lab with no interruptions, without all this nonsense

03:20:17.710 --> 03:20:22.230
popping up, without the split screen where I can really just go into it.

03:20:22.290 --> 03:20:22.510
Right.

03:20:22.510 --> 03:20:24.350
And I'm way better at that.

03:20:24.450 --> 03:20:31.970
than writing reports but when i write them they're perfect fantastic that's good i mean and

03:20:31.970 --> 03:20:38.530
that's just it so for me as a former sizzle who used to manage pen testers right and actually do

03:20:38.530 --> 03:20:45.650
internal teaching to all of the the soccer um you cannot you have to write a report otherwise you're

03:20:45.650 --> 03:20:52.290
going to get in trouble and um and so it's uh um let me show you something real quick

03:20:52.290 --> 03:21:01.760
oh am i i look like i am sharing i'm not sure share but um i don't see but let me

03:21:01.760 --> 03:21:07.280
reduce this okay i see two different desktops now okay so this is my

03:21:08.880 --> 03:21:11.520
okay so then that means you're still sharing your screen i guess

03:21:13.120 --> 03:21:17.920
yeah you're shut down it looks like yours is um black it just says dot