5 videos 📅 2025-08-01 09:00:00 America/New_York
1:43
2025-08-01 09:20:57
3:21:34
2025-08-01 09:23:06
3:24:40
2025-08-01 13:02:23
52:46
2025-08-02 09:03:25
4:52:32
2025-08-02 09:56:41

Visit the Kali Linux Intermediate course recordings page

                WEBVTT

00:00:00.620 --> 00:00:06.630
Can you see it now same thing? Okay, well, you know what?

00:00:08.490 --> 00:00:12.570
I don't know what happened to our oh

00:00:13.690 --> 00:00:15.690
I I know what's happening

00:00:16.150 --> 00:00:20.750
the software is showing the desktop specifically and

00:00:21.370 --> 00:00:26.350
I don't seem to can't I can't show you what I want to show you. That's great. It's okay

00:00:28.270 --> 00:00:34.050
All right, let me just minimize let's keep going you you almost stop sharing and you continue to share your screen

00:00:34.050 --> 00:00:39.070
because i want to see i want to finish you through and get you through everything else and hopefully

00:00:39.070 --> 00:00:47.040
you are learning how to create your profiles go ahead and show that one note again i can show the

00:00:47.040 --> 00:00:53.580
one note but i don't know what happened to my whole entire desktop i mean i i got the one note right

00:00:53.580 --> 00:01:01.360
here there it is you see this yeah you do okay probably have to connect again maybe i don't know

00:01:01.360 --> 00:01:06.880
probably have to connect again it probably timed out because we are uh we were on lunch well i was

00:01:06.880 --> 00:01:19.600
away i wasn't even on lunch so i probably want to click on connecting yeah um well you click on

00:01:19.600 --> 00:01:32.050
connect yep there we go uh-huh and go ahead and allow it okay so let's go where all the steps you

00:01:32.050 --> 00:01:40.270
you had before that's what i mean they're gone as soon as he left they all went away

00:01:40.270 --> 00:01:46.990
get out of here unless my clipboard is down here no mine's gone too

00:01:46.990 --> 00:01:54.710
because let's do it again real quick come on let's say we can do it again real quick that's what we

00:01:54.710 --> 00:02:01.030
have no choice but it's gonna all right it'll work out i'll show you you can um i want this

00:02:01.030 --> 00:02:07.090
time when we do it i want you to see my screen so we'll do it together so you can probably

00:02:07.090 --> 00:02:11.490
minimize your screen and we'll split screens and show it together you know what i mean

00:02:11.490 --> 00:02:18.830
now go back to that screen you were on the desktop uh what is it like at the bottom corner you gotta

00:02:18.830 --> 00:02:28.300
So my Zoom is on top.

00:02:29.300 --> 00:02:34.640
Documentation, users, Wesley, FPS.

00:02:37.340 --> 00:02:39.180
How do you use that?

00:02:40.520 --> 00:02:43.300
Go back to the, it's whatever it is, it's on the desktop.

00:02:43.820 --> 00:02:44.580
There's nowhere else.

00:02:45.060 --> 00:02:46.320
Go back to the desktop.

00:02:47.480 --> 00:02:48.320
I'm trying.

00:02:48.560 --> 00:02:50.600
It's right straight up next to Zoom.

00:02:52.910 --> 00:02:53.330
There you go.

00:02:53.330 --> 00:02:58.510
So now there's something in there that needs to be minimized so you can see my screen simultaneously

00:03:00.650 --> 00:03:04.410
Users Roger Wesley Donna

00:03:06.610 --> 00:03:09.890
Documentation

00:03:09.890 --> 00:03:16.030
Maybe just stop that maybe it's the green the green arrow to the left. Maybe it's pointing to the right

00:03:16.910 --> 00:03:21.090
I'm here if you guys need any help right. How do we get to share both screens now?

00:03:21.090 --> 00:03:30.130
okay you are on your current desktop anna uh if you just press escape escape he said that earlier

00:03:30.930 --> 00:03:42.290
i did i hit it click it okay that's okay did you i see okay go back to cali linux

00:03:42.290 --> 00:03:48.290
intermediate tab the one beside the desktop yeah go to the training room

00:03:48.290 --> 00:04:04.340
training all right painting room we're all learning here thank you roger so roger check

00:04:04.340 --> 00:04:13.220
this out everything that we typed before is gone uh wait wait wait wait wait that donna

00:04:14.340 --> 00:04:23.200
at the top you see the the terminal the number two can you click on that number two uh terminal

00:04:23.200 --> 00:04:32.140
at the top of your screen the little black box different desktop so on your screen on the on the

00:04:32.140 --> 00:04:38.860
right side right right next to firefox to the right of that is the the little terminal and

00:04:38.860 --> 00:04:45.900
the number i don't have an interactive screen anymore oh i did try to click on that okay go

00:04:45.900 --> 00:04:53.980
back to the kali desktop the other tab yeah yes sir i just i just clicked interactive oh

00:04:55.100 --> 00:05:01.900
no no that's a different go back to one and i see the terminal as there's two terminals there

00:05:02.700 --> 00:05:07.980
far right right i'm a far right just before that's left go to the right other right right

00:05:07.980 --> 00:05:15.020
there right there click on the first one or actually could have been the one that said pen

00:05:15.020 --> 00:05:24.940
testing there you go you have two terminals open so let me close one yes close the first one

00:05:26.060 --> 00:05:33.410
all right back to the shadows thanks sir thank you okay now let's go back to that that one note

00:05:38.930 --> 00:05:41.730
okay let me move you to the bigger screen because i can't see that

00:05:44.210 --> 00:05:50.850
all right let me bring over my one note so we can bang this out

00:05:52.450 --> 00:06:03.270
and let's do one of these there we go there we go okay so now we were exploitation we were doing

00:06:03.270 --> 00:06:11.830
that then we were going to numerate into the machine and we're going to do so we did ipa and

00:06:11.830 --> 00:06:22.200
map now i know why i was where i was so let me pull that back up again that's crazy and this one

00:06:22.200 --> 00:06:36.800
right here okay okay almost there we did i know what it is but i just want to find it first

00:06:37.680 --> 00:06:45.730
then we did search exploit yeah that was a good feature so go ahead and where it says enumeration

00:06:45.730 --> 00:07:16.710
exploitation type search exploit base capital p ro capital ftpd all capital letters pd space capital

00:07:16.710 --> 00:07:32.000
d space 1.3.3 c right there there are alternatives to all this stuff so it's just gonna come up in

00:07:32.000 --> 00:07:46.240
time go to lessons learned press enter um you know what copy and paste enumeration and exploration

00:07:46.960 --> 00:08:08.740
exploitation and put it here seriously yeah you you could have copied the whole thing i could have

00:08:08.740 --> 00:08:22.850
typed it by now oh my god let's just type it put it slash exploitation and where it says exploitation

00:08:22.850 --> 00:08:32.550
i want you to just type that to um um research no take that out type research

00:08:34.150 --> 00:08:42.070
research here yeah the whole thing oh the whole thing out highlight the word exploitation and

00:08:42.070 --> 00:08:57.350
then type over that's the fastest way okay now in the commands box right there you're going to type

00:08:57.350 --> 00:09:05.600
msf console right here um m the letter m is a michael sf console

00:09:07.360 --> 00:09:30.760
um so press enter now i want you to hit the tab key good now type in um search space

00:09:30.760 --> 00:09:46.110
pro ftpd 1.3.3 c again because you're doing that within MSF console that's why we indented it same

00:09:46.110 --> 00:10:08.780
thing you typed above capital letters and everything enter right and then you're going to type use space

00:10:08.780 --> 00:10:36.060
zero enter type options enter set set space our host space was it 10.0.3.16

00:10:36.060 --> 00:11:06.430
and press enter show space payloads enter set space payload space number four take that s off

00:11:06.430 --> 00:11:21.250
for payloads because we want a one payload no no no put that s back on payloads which one

00:11:21.250 --> 00:11:29.130
the one you get payloads here show payloads with an s okay right that way you get to see all of

00:11:29.130 --> 00:11:36.930
them and then you're going to set one payload which is number four press enter then type in

00:11:36.930 --> 00:11:53.490
options. Press enter. Then we're going to set the L host. And the L host was your personal IP address,

00:11:53.490 --> 00:12:09.450
which was 10.0.3.15. Press enter. Then we're going to run it. Are you in a little case letter

00:12:09.450 --> 00:12:33.390
run, but run. Okay. Now we're going to press the tab key again. Type who am I? Once it shows you

00:12:33.390 --> 00:12:42.490
that your route you're in so now don't do it don't do it uh uh press press enter yes press enter

00:12:42.490 --> 00:13:06.320
type cd space forward slash root cd space what forward slash root okay

00:13:06.320 --> 00:13:42.360
Okay. Now, that's it. Take that C out. Then backspace up. Backspace. There you go. Put the T back. Now, where it says find my IP. Screenshots. Click in that box. Right there. Now, I want you to, where is the, just click minimize, click minimize right there. Fantastic.

00:13:42.360 --> 00:13:50.900
Now, on the left side, oh, there it is. Now, we see that. We got the screen we want. Now,

00:13:50.900 --> 00:13:57.130
go back to the one note at the bottom. Click the N at the bottom. That's how you're going to get

00:13:57.130 --> 00:14:07.240
back and forth, okay? Click on insert top left next to home. Now, go all the way to the right

00:14:07.240 --> 00:14:19.300
to the three dots. Click screen clipping. Fantastic. Now, see where it says IPA and above it says

00:14:19.300 --> 00:14:25.140
basically i need you to highlight from the top left to the bottom right corner uh-oh you did

00:14:25.140 --> 00:14:33.220
something else yeah let's go what am i clicking screen clipping okay see now it lights my screen

00:14:33.220 --> 00:14:38.340
up that's good that's good okay okay highlight from ipa all the way down to the bottom right

00:14:39.380 --> 00:14:44.660
start at the top left use your mouse so i'm on the left side because i can't see it you don't

00:14:44.660 --> 00:14:51.220
have a mouse is well it's no i don't have a mouse but the thing is my screen's blanked out so i'm

00:14:51.220 --> 00:14:58.740
i'm on the left hand side right scroll down a little bit more a little bit more go go go up go

00:14:58.740 --> 00:15:06.020
up a little bit more go to the left okay go to the right just turn it on the edge on the inside got it

00:15:06.740 --> 00:15:16.740
oh okay go to click on the three dots again top right screen clipping go to that same spot

00:15:17.780 --> 00:15:26.500
go above that um maybe it's the program okay wait i'm gonna do the same thing

00:15:26.500 --> 00:15:32.260
okay screen clipping we're going back here you should be able to highlight that left click and

00:15:32.260 --> 00:15:38.740
drag the whole thing it pulls this back up but i see so that's that's that's something with the

00:15:38.740 --> 00:15:43.860
desktop i guess was having so let's do this click on print screen do you have print screen on your

00:15:43.860 --> 00:16:01.250
computer i don't have a printer but i have control p um try control p how's that okay right click that

00:16:01.250 --> 00:16:14.850
copy it i don't like it but go to your one note paste it it's the photo where's the photo just

00:16:17.780 --> 00:16:29.800
probably the one in the middle see that's not the photo so type control z okay good let's let's go

00:16:29.800 --> 00:16:39.800
back just go back there's more back to the dots yeah just no no no no no no uh no left click on

00:16:39.800 --> 00:16:49.320
that um left click that on unhighlight that it's crazy left left click left click left

00:16:50.280 --> 00:16:57.960
can you bring my food i did if you there you go now you did now i see it now i need you to find the

00:16:57.960 --> 00:17:07.880
prt str button on your computer usually at the top right someplace print screen yes hit it

00:17:13.350 --> 00:17:24.230
now highlight that whole caption okay you printed it but it didn't it didn't get the whole thing

00:17:24.230 --> 00:17:32.500
go to your one note so i want you to get above that so you can get there you go go you don't

00:17:32.500 --> 00:17:38.660
need that extra space so don't let it go when you do it i want you to get it clean

00:17:40.660 --> 00:17:53.540
it's above that's just the one below it hey right here can you give me something to drink

00:17:53.540 --> 00:17:58.300
thank you that's my granddaughter she's getting she's bringing me food

00:17:58.300 --> 00:18:11.360
yay all right right screen oh come on okay there you go that's what it does by the way

00:18:11.360 --> 00:18:16.880
there you go okay keep going to the right you got stuck yeah don't miss anything yeah

00:18:16.880 --> 00:18:32.450
there you go let it go now what now let it go and then go to your one note but i'm on the blank

00:18:32.450 --> 00:18:41.550
screen um hold on it looks like it didn't capture let me see right click and paste there you go

00:18:42.510 --> 00:18:50.270
thank god yay right let's keep going okay now go to the far right and make that wider

00:18:51.790 --> 00:18:58.590
far right go back to the one note drag it to the right there you go no no not that one

00:18:58.590 --> 00:19:15.110
bring that control z now grab that line outside of that line outside of what not that one the one

00:19:15.110 --> 00:19:24.240
outside of it that's the inside line grab the outside line that that that right there yeah

00:19:24.240 --> 00:19:32.330
there you go that's fine that's what i was looking for keep going more yeah doesn't go any

00:19:32.330 --> 00:19:36.890
on okay that's fine fine at least we had that now click on the screenshot you did

00:19:39.240 --> 00:19:45.560
now grab the bottom right corner with the left click and make it smaller

00:19:46.840 --> 00:19:55.860
it's smaller go ahead and grab it again no not that not that middle not the middle

00:19:56.500 --> 00:20:02.420
the right one you want to keep the dimensions on purpose grab the right one bottom right

00:20:02.420 --> 00:20:06.500
same button make it smaller there you go there you go keep going keep going keep going

00:20:06.900 --> 00:20:22.820
Stop right there. Now, make that wider. Go to the outside. No, no, no, no. No, no, not that one. Go. Yeah. The line outside of there's only one. But there's only one line. I'm telling you.

00:20:22.820 --> 00:20:36.650
no i see it just that's okay make it wider yeah good now make capitalize that l and learned

00:20:42.150 --> 00:20:50.970
good highlight that whole top header of just lesson learned yeah the lesson learned go to

00:20:50.970 --> 00:20:59.050
the left all the way to the left all of the the tops all the way all the way just the header

00:20:59.050 --> 00:21:05.530
not that extra stuff okay you you highlighted extra stuff the august first so just highlight

00:21:05.530 --> 00:21:21.800
project two lessons learned how do i undo it okay uh-huh there you go type control b good now type

00:21:21.800 --> 00:21:28.520
uh go to home the home tab at the top left next to insert

00:21:28.520 --> 00:21:44.580
yes and then go to next you see the star on the right when you see the star go to the one left of

00:21:44.580 --> 00:21:55.960
it just go over one two three four five six go to the one left of it that's right go to the one left

00:21:55.960 --> 00:22:06.120
go to the one left of it yes that the one left go left go left go left go left right there click

00:22:06.120 --> 00:22:16.010
that drop down hit center there you go there you go all right making it pretty now go to um pseudo

00:22:16.010 --> 00:22:29.560
net discovery click in the screenshots box make sure you click in the box if you don't click on

00:22:29.560 --> 00:22:38.030
the box you're gonna have issues go back to the one note it's very specific click in okay find

00:22:38.030 --> 00:22:47.710
target ip screenshots find target ip now let's try this one more time go to insert there's no

00:22:47.710 --> 00:22:54.860
reason why this shouldn't be working click on the three dots on the top right click screen clipping

00:22:57.860 --> 00:22:59.800
And now I need you.

00:22:59.880 --> 00:23:00.420
Wait, wait, wait, wait.

00:23:00.640 --> 00:23:01.460
Where is the.

00:23:03.620 --> 00:23:04.460
It's above.

00:23:04.920 --> 00:23:05.560
Okay, left click.

00:23:05.640 --> 00:23:06.160
Just left click.

00:23:07.260 --> 00:23:08.440
See how it's highlighted?

00:23:08.700 --> 00:23:10.140
We got to get remove the highlights.

00:23:11.940 --> 00:23:12.680
Remove that.

00:23:15.740 --> 00:23:16.180
Good.

00:23:16.180 --> 00:23:19.300
Now, the pseudo ARP scan is the one on the top left.

00:23:19.400 --> 00:23:20.000
Do you remember?

00:23:21.460 --> 00:23:24.320
Where it says currently scanning all the way down to unknown vendor.

00:23:31.440 --> 00:23:32.300
No, that's not it.

00:23:32.600 --> 00:23:33.420
The top left.

00:23:33.760 --> 00:23:34.560
Like above that.

00:23:35.760 --> 00:23:36.240
Left.

00:23:37.280 --> 00:23:43.180
You were there just above the one above. Yeah, I mean, I just don't see it because it's so tiny

00:23:43.180 --> 00:23:46.800
I don't so do a control shift plus plus plus and make it bigger

00:23:47.240 --> 00:24:03.000
Yes, it's the one above it go up not there go to the right there terminal above it

00:24:04.120 --> 00:24:09.300
Right there. That's the ARP scan stuff right now. Don't do anything

00:24:10.600 --> 00:24:20.460
Stay there click on the one note now three dot screen clipping

00:24:21.160 --> 00:24:29.720
highlight that section yes yes you're doing it you're doing it keep going the whole thing

00:24:29.720 --> 00:24:36.620
let it go see how that works voila that's so easy yes now see what it says screen clipping

00:24:36.620 --> 00:24:42.620
taken on a date yeah you can keep it or not that's up to you but i just say highlight it and take it

00:24:42.620 --> 00:25:06.590
out highlight the empty space and everything on up oh god press delete yeah press there's

00:25:07.390 --> 00:25:15.070
now press press backspace press backspace to get good now go above it to the screenshots

00:25:15.070 --> 00:25:25.600
above that picture put the cursor above that press backspace yes you're getting it

00:25:25.600 --> 00:25:32.040
right we're trying to make it perfect trying to make it clean i want you to look good so far from

00:25:32.040 --> 00:25:38.280
perfect when it comes from this i hate this stuff so this is fantastic i understand yes i understand

00:25:38.280 --> 00:25:55.440
now yeah i need you to click on the image for net discover so click on the image i know but

00:25:55.440 --> 00:26:03.650
what box is it going in no i want you to click on the image for net discover click on the image

00:26:03.650 --> 00:26:13.950
which is which is above that see above that click the image yes now use the right arrow and press

00:26:13.950 --> 00:26:29.440
right no no press the arrow on the keyboard press that no you you clicked off click on the image

00:26:29.440 --> 00:26:42.510
again yes use the right arrow and press it one time to the right to the right press okay got it

00:26:42.510 --> 00:26:50.030
now hold on let's see here okay we've got a click on it click on the image again

00:26:51.550 --> 00:27:06.910
click on image image image right there right here um press enter okay good now hit the down arrow

00:27:09.380 --> 00:27:20.210
hit it down hit the down arrow again okay it's not doing it oh i know what above the image click

00:27:20.210 --> 00:27:29.620
there okay we're going to do it the opposite way we're going to fix it go to insert and the three

00:27:29.620 --> 00:27:41.310
dots screen clipping uh-oh wait we don't have our arp scan so click it again just left click it

00:27:43.230 --> 00:27:50.380
just left click it on our go back to the terminal scroll all the way to the top where you got that

00:27:50.380 --> 00:28:01.200
arc scan now that's the left side i need you to be on the right terminal

00:28:01.200 --> 00:28:08.680
and scroll yeah that's the right scroll all the way to the top because we did our art scan on this

00:28:08.680 --> 00:28:17.200
side no stop doing that because you're doing stuff in the bottom go to the bottom right corner

00:28:17.200 --> 00:28:27.730
and grab the scroll bar and go to the top mm-hmm i got it let me just okay now i'm highlighting

00:28:27.730 --> 00:28:38.020
this scan mm-hmm you're going back to one the art come on now screen clipping oh put the um

00:28:38.020 --> 00:28:48.000
yeah screen clipping the three dots screen clipping now you're going to highlight the art

00:28:48.000 --> 00:28:57.760
scan in the output and highlight everything that's fun yeah but make sure you grab it on the left so

00:28:57.760 --> 00:29:00.880
you can get everything because underneath that you're gonna be cutting stuff off you don't want

00:29:00.880 --> 00:29:06.480
to cut anything off there you go there you go get everything underneath underneath go to the go to

00:29:06.480 --> 00:29:13.280
the left some you go no you're going too far you're going too far go up go up go up go to

00:29:14.320 --> 00:29:20.560
get everything go down to the right a little bit dude oh it's going too far go to don't go past

00:29:20.560 --> 00:29:27.440
student look at the scans look at the command go to the right right there right yes let it go got

00:29:27.440 --> 00:29:39.100
i just let it go getting the dialogue so i get it i got it i understand now what now

00:29:41.980 --> 00:29:52.560
backspace all that other stuff you don't need just press the back just there you go

00:29:53.520 --> 00:30:02.510
leave a space in between the two images now copy that first image

00:30:02.510 --> 00:30:18.730
that i'm sorry click on the second image click second image right click cut good above that first

00:30:18.730 --> 00:30:30.440
image click above that one no stay in the same box we're talking about i'm like yes control v

00:30:30.440 --> 00:30:38.560
control v to paste there you go now we cleaned it up now underneath that take that space out

00:30:44.160 --> 00:30:56.800
no type ctrl z underneath the second image backspace there you go got it now click inside the

00:30:56.800 --> 00:31:04.720
box go back to one note or the terminal like inside what box this one the watch the box you're

00:31:04.720 --> 00:31:12.940
already in now click on the end for window now let's find the ping that you did which is right

00:31:12.940 --> 00:31:22.300
there on the left oh the ping is on the left you see the ping command and the ip you type

00:31:23.500 --> 00:31:28.380
yeah okay so now we need the command and the output and i don't see all that

00:31:30.060 --> 00:31:41.360
so left click one time go go back to the command now scroll don't don't do anything uh i didn't

00:31:41.360 --> 00:31:47.810
touch it believe me this is what it does scroll down a little bit at the top trying

00:31:48.610 --> 00:31:55.090
because we want to see the whole pain command to verify remember you have to prove what you've done

00:31:55.090 --> 00:32:01.250
i know but i don't have 45 screens when i'm doing it so i get it i don't know how to

00:32:02.450 --> 00:32:09.890
i don't know how it's not moving it is just not moving i know what you want but it's not moving

00:32:09.890 --> 00:32:17.010
so okay so hold on click it left look um we're gonna overcome we don't yeah just grab that

00:32:17.730 --> 00:32:23.330
grab that bar and go down this doesn't move no click that bar in the middle and make it blue

00:32:25.010 --> 00:32:29.730
go to the right bar in the middle you have two terminals go to the middle bar

00:32:29.730 --> 00:32:34.690
a little scroll bar in the middle i don't see a middle bar it's all this down here

00:32:34.690 --> 00:32:42.290
no no no they'll go to the one in the top right top right so let's pause you have a left and a

00:32:42.290 --> 00:32:48.530
right terminal right and they're stacked on top of each other with no divisionary lines

00:32:48.530 --> 00:32:54.770
i see the line i'm looking right at it close that you want to put your arrow on it and show me

00:32:54.770 --> 00:33:02.050
i was trying to figure out where my arrow was too um um which one is the arrow because i can get

00:33:02.050 --> 00:33:07.970
there if i know like uh i mean i know what i'm supposed to do it's just that i it's not moving

00:33:08.530 --> 00:33:15.090
and so all this garbage is just stuck together and um it doesn't move look i just tried to move

00:33:15.090 --> 00:33:20.450
it this is the scroll bar i know what a scroll bar can you use two fingers and scroll up and

00:33:20.450 --> 00:33:26.450
down on it if you have touch screen no because it's microsoft it sucks

00:33:32.370 --> 00:33:39.490
well there's the ping right there another thing you could do is just hover over that scroll bar

00:33:40.690 --> 00:33:44.450
use your left hand to press the track pad down and use your right hand

00:33:45.250 --> 00:33:51.410
to use the and scroll with the right hand can you show me how to move this terminal up

00:33:52.290 --> 00:33:59.730
because my screen is just not like i have it it i have three terminals going it seems like

00:34:00.930 --> 00:34:07.810
then that's three window panes yeah um three window panes and um the one on top the one

00:34:07.810 --> 00:34:20.350
on the top left is stuck to help you out a bit uh press f11 11. well that didn't work uh on the

00:34:20.350 --> 00:34:26.990
left side of this uh browser window you see that little green bar with the dots and arrows

00:34:28.670 --> 00:34:35.550
it's about the middle of the page but on the left side like this right here no no no the browser

00:34:35.550 --> 00:34:43.470
window so further left you should see a little green box there around the middle of the page

00:34:45.150 --> 00:34:51.710
to the left the key moves into the left where's the arrow in the zoom yeah click that

00:34:52.430 --> 00:34:57.070
the side control bar okay and you see the one that looks like a maximize window it's the middle

00:34:57.070 --> 00:35:09.950
button so now you have full this is full screen now you should be able to click into there yeah

00:35:10.030 --> 00:35:26.400
Okay, so hover over that scroll bar again, and make sure that it's...

00:35:26.400 --> 00:35:26.860
That's fine.

00:35:27.500 --> 00:35:28.700
Yeah, just hover over it.

00:35:29.160 --> 00:35:29.440
Yeah.

00:35:30.380 --> 00:35:33.980
Use your left hand to press down on the trackpad.

00:35:36.550 --> 00:35:39.610
You're currently in a mode that will split it around.

00:35:40.230 --> 00:35:42.950
You've got to get over that little tiny bar.

00:35:43.870 --> 00:35:46.830
When it highlights blue, you're doing well.

00:35:47.130 --> 00:35:48.330
You just got to go to the right a little bit.

00:35:48.350 --> 00:35:49.230
I just saw it, blue.

00:35:51.420 --> 00:35:52.440
It's a sweet spot.

00:35:52.440 --> 00:35:58.040
a little bit frustrating i guess yeah and if it's not an active window it just highlights like a

00:35:58.040 --> 00:36:13.860
lighter white i don't see the color change at all right here i'm hovering left hand

00:36:13.860 --> 00:36:20.500
left hand here's my right yeah and push down pushing and then use your right hand to scroll

00:36:24.090 --> 00:36:32.170
the blue but that's the top of the page i've been at the top of the page dr west no scroll down

00:36:32.170 --> 00:36:38.010
that is the top of the page no no no no okay now i'm scrolling down there must be a delay

00:36:38.010 --> 00:36:42.730
scroll down until you see the scroll down until you see the ping command and the output

00:36:45.060 --> 00:36:49.220
look at your commands on the left you see ping 10.0 it's all right there

00:36:49.220 --> 00:36:56.260
here it is right good that's good enough right there that's good now click on your one note

00:36:56.260 --> 00:37:06.760
but no it's gone this ship oh

00:37:11.640 --> 00:37:17.720
okay escape okay go back to that green box

00:37:19.720 --> 00:37:25.720
green box you mean my screen share box or no the clipboard on the side

00:37:25.720 --> 00:37:33.960
and then click the middle button again yes oh voila got it i know where we're going with this

00:37:33.960 --> 00:37:43.640
fantastic now screenshot it yeah i hope to there you go before you're outside the

00:37:51.590 --> 00:38:13.300
good now backspace that screen clipping yeah and let's get the f-ping one to put another one

00:38:13.300 --> 00:38:17.300
below it right you would have done well if you would have kept that space you could have put

00:38:17.300 --> 00:38:26.900
it underneath it yes below it yeah do i need to you need to i can just i can just paste it uh

00:38:28.340 --> 00:38:33.940
we'll see no there's nothing you don't have anything highlighted there's no f ping showing

00:38:33.940 --> 00:38:46.130
so um go back to the um go back to the terminal i didn't mean screen clipping

00:38:46.130 --> 00:38:54.630
left click stay there go back to the terminal now click on now scroll down until you see f

00:38:54.630 --> 00:39:00.690
ping type and the output of it being alive and i'm on the left hand side right right underneath

00:39:00.690 --> 00:39:11.440
pink you're in the same space you just were in you type f ping underneath make sure you go down

00:39:11.440 --> 00:39:24.630
i just saw it you you okay oh i keep keep going down just make sure you see f ping i'll let you

00:39:24.630 --> 00:39:34.490
there it is right now go to the one note okay now somehow some way you got to get underneath

00:39:34.490 --> 00:39:56.840
that paint okay so let me help you triple left click right there stop don't highlight anything

00:39:56.840 --> 00:40:09.580
just go one two three on top of the word screen clipping one two three okay no no put it on top

00:40:09.580 --> 00:40:20.710
of the word screen and click left top left left left one one two three press delete thank you

00:40:20.710 --> 00:40:33.260
how do i undo that ctrl z z there good so now on the right side of that press enter right side of

00:40:33.260 --> 00:40:42.700
that stream ping click there press down go get that f ping and put it underneath it cut that

00:40:42.700 --> 00:41:01.780
right click and cut it put it underneath it fantastic now i'm just gotta get a space between

00:41:01.780 --> 00:41:22.490
make a space click the one above it and press enter um or space or right click out of it um

00:41:24.010 --> 00:41:28.010
okay let's do it together let's let's put you back where you were at the top

00:41:31.530 --> 00:41:41.370
above that above that image the top press delete press delete that's done all right now click on

00:41:41.370 --> 00:42:04.250
the um press the right arrow press enter okay um okay next time we do it let's try to keep a space

00:42:04.250 --> 00:42:10.010
a line in between even every image it's cleaner that way i don't want you to be like where is it

00:42:10.010 --> 00:42:16.090
i want you to be able to find it we'll fix that but because i'm not sure whether hit the up arrow

00:42:20.210 --> 00:42:21.330
Hit the up arrow again.

00:42:21.510 --> 00:42:22.230
Oh, what'd you do?

00:42:22.470 --> 00:42:23.250
No, no, no, no, no.

00:42:23.390 --> 00:42:23.810
Undo.

00:42:23.910 --> 00:42:24.510
Control Z.

00:42:24.650 --> 00:42:27.650
Don't do anything extra because I want to make sure we're on the same page.

00:42:28.650 --> 00:42:29.470
Hit the up arrow.

00:42:29.910 --> 00:42:32.250
Okay, now, what'd you do?

00:42:32.510 --> 00:42:33.990
I keep seeing stuff in and out.

00:42:33.990 --> 00:42:34.490
Hit the up arrow.

00:42:34.630 --> 00:42:35.510
Stay in one place.

00:42:35.510 --> 00:42:35.950
Hit the up arrow.

00:42:36.730 --> 00:42:36.930
Okay.

00:42:37.770 --> 00:42:38.590
Don't do anything.

00:42:39.030 --> 00:42:40.570
Hit the down arrow.

00:42:41.710 --> 00:42:42.470
Down arrow.

00:42:43.610 --> 00:42:44.670
Press space.

00:42:46.330 --> 00:42:46.770
Space.

00:42:47.950 --> 00:42:49.010
That didn't do anything, huh?

00:42:49.010 --> 00:42:56.050
press enter oh you did something else never mind let's forget about it that's a bigger image

00:42:57.810 --> 00:43:09.650
click the bigger image press the right arrow is it i know right i had to do that before too

00:43:12.300 --> 00:43:14.700
what happens if you hit enter yeah hit enter

00:43:16.460 --> 00:43:25.340
the white bars go away okay yeah we got to fix that later we'll we just did it i don't know

00:43:25.340 --> 00:43:40.120
that one's a hit the left arrow oh hit the smaller image hit the left arrow it's crazy right

00:43:40.120 --> 00:43:47.460
okay how about if we just delete it and do it again i mean that's that's one way

00:43:47.460 --> 00:43:57.290
do a do a cut don't delete it leave it no no no no don't don't go back you just you did

00:43:57.290 --> 00:44:05.530
something good go back to the go back go back there press enter press enter enter now press

00:44:05.530 --> 00:44:14.150
control v control v done yeah thank you we don't let computers beat us okay donna

00:44:14.150 --> 00:44:22.130
we always win fantastic good job now click on vulnerability underneath it click on the section

00:44:22.130 --> 00:44:31.060
good go to um the one note click one note at the bottom so the terminal opens up again

00:44:31.060 --> 00:44:39.820
now we need to look for your first nmap scan and it should be i think on the left side

00:44:39.820 --> 00:44:52.880
you may have to scroll down on the top left you went too far look at your very first look for

00:44:52.880 --> 00:45:12.640
your very first one your very first one was just nmap space ip address after the f ping good now

00:45:12.640 --> 00:45:14.440
make sure you go down and get the entire

00:45:14.440 --> 00:45:16.480
thing. You got... No, no, no. Go back.

00:45:16.800 --> 00:45:18.700
You can jump too fast. It slipped. It wasn't

00:45:18.700 --> 00:45:20.200
me. It wasn't me, but it was.

00:45:20.300 --> 00:45:22.180
Make sure you see the entire thing.

00:45:25.920 --> 00:45:27.480
Okay. You're going

00:45:27.480 --> 00:45:29.740
too far now. You went like three more commands, I think.

00:45:30.620 --> 00:45:31.500
So in map...

00:45:31.500 --> 00:45:33.440
There it is. Fantastic. Now you can go to

00:45:33.440 --> 00:45:37.520
OneNote and screen with it. I get it.

00:45:37.720 --> 00:45:38.500
Believe me.

00:45:40.180 --> 00:45:41.700
It just takes forever

00:45:41.700 --> 00:45:43.480
and a day. Only

00:45:43.480 --> 00:45:44.460
because you're new to it.

00:45:45.720 --> 00:45:47.020
It's just...

00:45:47.020 --> 00:45:49.640
Because I fly through this thing so fast, you go like this.

00:45:50.040 --> 00:45:53.240
Yeah, you know, it's just another thing to learn.

00:45:53.440 --> 00:45:53.880
That's it.

00:45:53.960 --> 00:45:54.340
That's it.

00:45:59.060 --> 00:46:01.020
Now, make sure you get all of the commands.

00:46:01.840 --> 00:46:03.320
It looks like you copied that one twice.

00:46:03.500 --> 00:46:04.360
You only need one.

00:46:08.160 --> 00:46:08.560
Yeah.

00:46:09.600 --> 00:46:11.340
Remember, I'm trying to teach you something.

00:46:11.340 --> 00:46:15.540
When you triple left click, that whole line lines up.

00:46:15.620 --> 00:46:17.860
You press backspace or delete, and it's done.

00:46:18.420 --> 00:46:23.700
Press enter so you can keep a space in between for future images.

00:46:24.440 --> 00:46:31.640
No, I did triple backspace. I did two. I did three clicks in the backspace. There must be

00:46:31.640 --> 00:46:33.840
You you you did

00:46:33.840 --> 00:46:42.820
Control there you go. Okay now and that's there. No, no, no, no, no, no, no, no, no, no, no. Press

00:46:42.820 --> 00:46:43.620
enter

00:46:43.620 --> 00:46:46.680
There must be a delay

00:46:46.680 --> 00:46:49.120
So we i'm gonna have to speak

00:46:49.120 --> 00:46:53.400
I just pressed enter there's something but no you did that's where we want to be

00:46:53.400 --> 00:47:06.800
now go to one note and click the image icon at the bottom now go back to the terminal

00:47:06.800 --> 00:47:15.720
do i want to click screenshot no no you want to click the one note icon at the bottom which

00:47:15.720 --> 00:47:26.310
takes you back to terminal find the second command find the second command you want the

00:47:26.310 --> 00:47:33.590
second nmap command that's what you want i want it yes i want the second nmap command

00:47:33.590 --> 00:47:37.430
I feel like I'm looking at it. Isn't this it? No, it's at the top

00:47:38.070 --> 00:47:40.070
Scroll down to the second command

00:47:40.490 --> 00:47:43.190
There it is. I want just there you go. See how you see it

00:47:43.930 --> 00:47:46.270
Now at the bottom move that down

00:47:49.400 --> 00:47:56.200
No, don't rid of it yet. That's good. I know but that way I can actually see what I'm doing

00:47:56.200 --> 00:48:01.640
Okay, now this is the exact reason why we do this at the same time

00:48:02.600 --> 00:48:07.640
and that's why we're going to need multiple screens at some point otherwise i'll pull it back up

00:48:08.520 --> 00:48:18.400
okay scroll down to your um second in maps command and it starts right there with the

00:48:18.400 --> 00:48:23.520
attack capital a scroll down a little bit more to get it clean you want to get it clean

00:48:24.480 --> 00:48:35.320
right there okay yes now go to your one note okay put the image you got it where you need to be

00:48:35.320 --> 00:49:06.310
insert screen clipping highlight that entire thing right now do your best to not cut off

00:49:06.310 --> 00:49:22.640
basic pen testing anymore see at the very top you okay i retake it no no no no i'm just letting you

00:49:22.640 --> 00:49:30.560
know now triple left click the word screen clipping taken in the date triple left click

00:49:30.560 --> 00:49:42.730
don't highlight it just go one two three that okay now you did some more but but i just when i'm saying

00:49:42.730 --> 00:49:50.770
i'm saying now go to the one above it triple left click screen clipping three it takes a while for

00:49:50.770 --> 00:49:57.710
it to click up yes i see something's going on three now what that must that looks like two

00:49:57.710 --> 00:50:07.890
no no no don't do anything extra we're going to get this we're going oh one no no no no no no no

00:50:07.890 --> 00:50:13.290
it didn't work it didn't work it did work because you did it before you did it before

00:50:13.290 --> 00:50:21.510
we're going to remember remember press delete remember we don't let the computer beat us

00:50:22.070 --> 00:50:28.390
now backspace until you go right back up make it clean yay backspace again right there

00:50:29.830 --> 00:50:39.560
okay uh go down to the third command now put the cursor where it needs to be good now um go back to

00:50:39.560 --> 00:50:48.930
click on the one note the bottom right corner you have to get it in place before you click screen

00:50:48.930 --> 00:51:13.140
clipping there you go go ahead to the one right underneath it yes don't highlight anything just

00:51:13.140 --> 00:51:25.680
go back to the one note now screen clipping highlight everything

00:51:28.800 --> 00:51:36.480
don't miss a thing keep going down go back up there you go go up you don't need that bottom portion

00:51:37.120 --> 00:51:51.280
okay one two three delete good just take out a little extra spacing and you're good

00:51:51.280 --> 00:52:03.830
go to the one above it and take out that one space there you go now go back down to the bottom

00:52:03.830 --> 00:52:13.100
underneath that image press enter you're where you need to be get the last screenshot you see

00:52:13.100 --> 00:52:23.850
the command that you got to get there you go yep that's the command we got to find

00:52:23.850 --> 00:53:04.310
you were just there too it looked like i see the the bpn max cat the cat command

00:53:04.310 --> 00:53:14.580
is that the one i want yes right here but i gotta move up there you go just scroll down

00:53:14.580 --> 00:53:27.900
ever so slowly until you get there that's up go down yes go up a little bit

00:53:27.900 --> 00:53:41.750
that's that's not it there right there oh go above that because that's the cat don't have any room

00:53:41.750 --> 00:53:56.230
just go up a little right oh okay oh we don't need the cat go above that

00:53:56.230 --> 00:54:20.980
we want the command that you type the nmap scan command okay just scroll down a little bit

00:54:20.980 --> 00:54:42.220
keep going you passed it but i tell you what this is what we're going to do scroll all the

00:54:42.220 --> 00:54:49.140
it down to the bottom oh man i gotta find it now is that is that not it that is not it stop stop stop

00:54:49.140 --> 00:54:55.660
stop but it's after that so i want you to remember we did everything in an order you did everything

00:54:55.660 --> 00:55:01.480
in an order look at the command before you move i want you to look before you do i'm looking okay

00:55:01.480 --> 00:55:08.660
there it is right there do you see it it's on the left i'm looking right there i know but it's like

00:55:08.660 --> 00:55:22.290
just go complete so it's um underneath it what is underneath what ah there it is i got it i have

00:55:22.290 --> 00:55:30.410
the answer so scroll down just put that in map thing to the top and i'll i'll tell you exactly

00:55:30.410 --> 00:55:48.530
what you did scroll down don't highlight we don't highlight your thing okay hold on hold on right

00:55:48.530 --> 00:55:54.650
there stop you just had it get the in map thing at the top of the screen and you'll be good

00:55:54.650 --> 00:56:12.400
i got it so then do this let's do this it just keeps flipping and as soon as i move it i'm going

00:56:12.400 --> 00:56:19.000
to try to help you i have options to show you on the left side press ctrl shift plus plus plus let's

00:56:19.000 --> 00:56:34.940
make it bigger control shift plus plus plus plus plus okay now make that thing wider move that

00:56:34.940 --> 00:56:44.400
centerpiece to the right yes let's give us some real estate so we can see now i'm looking for

00:56:44.400 --> 00:56:54.680
that in map scan that command scroll up until you find it just you gotta go to the right a little

00:56:54.680 --> 00:57:03.600
bit there you go click on that yeah yeah go slow till you get there right there stop right here

00:57:03.600 --> 00:57:13.020
hold on yes now go to one note now you're gonna highlight scroll down you gotta scroll down get

00:57:13.020 --> 00:57:24.880
the spot first right there good now now three dots now screen clipping now i want you to

00:57:24.880 --> 00:57:36.620
highlight from the end map scan all the way down to the cat scan scan to the cat scan to the end

00:57:36.620 --> 00:57:42.540
of the cat highlight that you got to do the screen clipping first because it's not doing anything

00:57:42.540 --> 00:58:01.700
all the way down to go up go up a little bit you're getting that blue let it go good now uh erase

00:58:01.700 --> 00:58:19.210
delete that there you go one more again do it again okay um go uh scroll up a little bit and

00:58:19.210 --> 00:58:27.540
go to that second section where the commands were back into the end section where the commands were

00:58:27.540 --> 00:58:36.500
yeah go back into the the end map section now after bbp end map scan text press enter

00:58:36.500 --> 00:58:56.940
and type cat cat cat you got a backspace so you can bring your numbers back space

00:58:56.940 --> 00:59:16.930
bp in map scan dot txt the only thing is see your first one you see if um your first command

00:59:16.930 --> 00:59:29.150
doesn't have a number one by it so go up top and put one period one period space one period

00:59:29.150 --> 00:59:39.890
space. There you go. Fixed. Now, if you study those images line by line, you'll see exactly what

00:59:39.890 --> 00:59:52.020
you did. Do you see that? I'm going to give you some more. Go back up. Something didn't look clear

00:59:52.020 --> 00:59:59.240
to me. I want to make sure it's clear to you forever. Okay. Right back up. Now, I want you

00:59:59.240 --> 01:00:04.600
to grab that line between the nmap scans and the images and make it a little wider so that you can

01:00:04.600 --> 01:00:12.280
see all the commands on one line grab that line between the nmap scan and the images correct that

01:00:12.280 --> 01:00:21.800
let's straight up and down vertical line the table line make the second column wider go back go back

01:00:21.800 --> 01:00:27.480
up don't go anywhere make the second column right there wipe me down there you go keep going keep

01:00:27.480 --> 01:00:34.760
going yeah keep going until the whole line is on one line keep going there you go now go to the

01:00:34.760 --> 01:00:44.850
left now and bring it to the edge of text bring that same line back to the left bring that same

01:00:44.850 --> 01:01:05.270
line back to the left yes just don't um there you go right there a little bit more that's good

01:01:05.270 --> 01:01:13.330
that's good but see you see how easier that is to read that's important to me and i think that's

01:01:13.330 --> 01:01:36.360
important to you i'll go down to the next section all right now find the search boy outcome hit first

01:01:37.640 --> 01:01:46.210
go back did we do that we did it on the right see it on the right right over there

01:01:47.570 --> 01:01:56.920
it's at the bottom on the right let me make this bigger so i can see oh my god

01:01:56.920 --> 01:02:18.990
there you go you don't copy remember just go to i'm not trying to i'm not trying to

01:02:18.990 --> 01:02:27.390
go to one note at the bottom

01:02:27.390 --> 01:03:16.110
good hold on left left left make sure you're on top of the the words and not to the left of the

01:03:16.110 --> 01:03:23.950
words. It won't work that way. There you go. Now, right-click that image, that search

01:03:23.950 --> 01:03:32.520
point image. Click search point. And cut it. Because it doesn't belong there. It belongs

01:03:32.520 --> 01:03:42.770
in the column, the row underneath it. Paste it. Control V. Or do that. Clean up your spacing

01:03:42.770 --> 01:04:07.410
above it undo undo that control thing okay click on that image and just delete it okay good okay go

01:04:07.410 --> 01:04:16.480
to the left and let's see what the next column is in the next row rather msf console we're getting

01:04:16.480 --> 01:04:34.600
near the end yay okay go back to the terminal when you get that chance all right we did msf console

01:04:34.600 --> 01:04:56.920
on the right make sure you catch it from the beginning where it says msf console

01:04:56.920 --> 01:05:24.710
you cannot move this thing underneath search boy you went too far so maybe there go up a little

01:05:24.710 --> 01:05:31.830
bit it'll be at the very beginning msf console with the msf6 and there you go right there right there

01:05:33.590 --> 01:05:41.650
copy that entire thing notice how the commands are in blue so that's going to be hopefully helpful

01:05:41.650 --> 01:05:53.410
to you so you can copy that whole thing starting here i mean i see this you want this blue image

01:05:53.410 --> 01:05:57.730
copy click on that left click real quick because you got to get you got to get rid of some stuff

01:05:58.770 --> 01:06:08.500
go back to the terminal just click on the one note at the bottom now my pictures our pictures

01:06:08.500 --> 01:06:14.980
our videos are in the way you need to move them pictures to the left here it is i got it there

01:06:14.980 --> 01:06:23.730
you go now go back you always start with the command okay i understand that fantastic

01:06:43.650 --> 01:06:51.570
you just can't maneuver quickly at all go slow well you just did it what happened yeah but it

01:06:51.570 --> 01:07:05.320
just popped up again i can't help it oh okay going in make sure you left click and not right click

01:07:05.320 --> 01:07:19.220
that'll do something too go to the left you don't need that extra stuff on the right

01:07:19.220 --> 01:07:31.060
you don't need that there you go let it go okay stop staying on the edge and get in the middle

01:07:31.060 --> 01:07:36.980
of those sentence now left click there you go delete it won't work if you stay on the left edge

01:07:38.500 --> 01:07:48.070
okay now keep you know don't don't um what's happening here scroll down i see something wrong

01:07:48.790 --> 01:07:55.830
there you go now click on the image and just cut it right click cut it put it down at the bottom

01:07:56.950 --> 01:08:03.680
put it where it needs to be i'm gonna need to teach you your shortcuts because they're

01:08:03.680 --> 01:08:11.280
much faster control v to paste it okay now look at your look at your list over there

01:08:11.280 --> 01:08:25.700
your bullets on the left the next command is what use zero yeah go find it after your next

01:08:25.700 --> 01:08:47.460
command is search um pro f whatever next command is what my next command is oh okay yes click on

01:08:47.460 --> 01:08:57.120
the one note image icon at the bottom it takes you back and forth like that on one note uh-oh trying

01:08:57.120 --> 01:09:02.080
to get back to the terminal oh yeah you close the terminal somehow that's all there it is there you

01:09:02.080 --> 01:09:19.650
go there we go click there it goes as long as it's blue fantastic there it is msf search see it

01:09:19.650 --> 01:09:28.130
right there yeah now you could possibly get almost so i see the search command and then you got the

01:09:28.130 --> 01:10:02.690
use zero see if you can capture both of those at the same time away too wide too wide on the right

01:10:02.690 --> 01:10:12.630
can i fix it this way yeah right click it go to crop uh-oh

01:10:14.550 --> 01:10:21.190
uh actually i don't see props no i don't see crop um

01:10:23.110 --> 01:10:32.790
um yeah so you might have to redo it just redo it just delete click on the image press delete

01:10:32.790 --> 01:10:54.210
wait click on the three dots screen clipping okay just get the search void just get the search

01:10:54.210 --> 01:11:05.560
void yeah we keep everything clean there you go now input the uh u0 scroll down though when you

01:11:05.560 --> 01:11:44.070
get there you can get rid of that little little image click it press delete remember click in the

01:11:44.070 --> 01:11:52.310
middle of the sentence not on the edges one two three delete two three delete and you may have

01:11:52.310 --> 01:12:05.920
to talk it one two three delete yeah two three delete fantastic let's go get the use command

01:12:06.560 --> 01:12:08.960
let's get it let's get her get her done

01:12:11.360 --> 01:12:23.540
okay hold on i don't see everything do you i did go back and scroll down a little bit more there you

01:12:23.540 --> 01:12:41.120
go there we go keep going okay that was perfect what you just did right that right there good good

01:12:41.120 --> 01:12:50.400
good good get all that you want um in fact that's u0 that's export so just get the u0 portion

01:12:53.590 --> 01:13:12.930
which is about halfway through the page i mean you gotta do it again that's all now you see how

01:13:12.930 --> 01:13:18.770
you can't see u0 i will let that go you can't see okay okay i haven't left it out can i go up

01:13:18.770 --> 01:13:23.250
because it's no i can't come up to the top oh but i have it like off so i can start over right

01:13:24.610 --> 01:13:30.770
no not because you you're checking the spot right on it versus above it click above it

01:13:37.490 --> 01:14:04.230
yeah you click right on it let it go again don't don't even try just delete it off highlight all

01:14:04.230 --> 01:14:29.110
that and delete it fast okay we got you zero right we got you zero happening we got you zero

01:14:29.990 --> 01:14:36.310
so next one is you got u0 you have options look at your image you got going nowhere

01:14:37.990 --> 01:14:42.870
let's see what way okay let's set the our holes right you got options there too

01:15:20.200 --> 01:15:27.000
right there set our host show payloads right there good you can get all that in one scoop

01:15:28.760 --> 01:17:00.770
all the way down the options again you're starting to get the hang of it yay you get everything

01:17:02.450 --> 01:17:03.530
Oh, you're working on it.

01:17:03.570 --> 01:17:03.750
Okay.

01:17:05.110 --> 01:17:06.270
You're starting to get it.

01:17:06.590 --> 01:17:10.750
There's nothing to get.

01:17:10.850 --> 01:17:12.150
It's copy and pasting.

01:17:12.990 --> 01:17:13.690
You know?

01:17:13.930 --> 01:17:15.410
You're learning how to copy and paste.

01:17:15.870 --> 01:17:17.210
You're showing people's work.

01:17:18.310 --> 01:17:19.250
I certainly am.

01:17:19.250 --> 01:17:21.770
This is what every pen tester hates.

01:17:22.250 --> 01:17:26.070
It's just that I'm used to OneDrive.

01:17:26.410 --> 01:17:28.910
It's just we use something totally different.

01:17:29.350 --> 01:17:29.730
Mm-hmm.

01:17:29.730 --> 01:17:33.090
So it's just, you know, working out the kinks.

01:17:33.950 --> 01:17:34.830
I won't lie to you.

01:17:34.830 --> 01:17:37.430
If I can show you about five more different editors

01:17:37.430 --> 01:17:38.610
and you'll be stressed out.

01:17:40.190 --> 01:17:42.970
So I'm on our host now to payloads.

01:17:43.070 --> 01:17:44.610
Now I lost my screen.

01:17:45.050 --> 01:17:46.790
Let me see if I can find it.

01:17:47.130 --> 01:17:47.670
There we go.

01:17:48.070 --> 01:17:48.550
There you go.

01:17:48.610 --> 01:17:49.050
All right.

01:17:50.350 --> 01:18:26.500
So now we're kind of lost.

01:18:28.020 --> 01:18:28.800
Okay, hold on.

01:18:29.640 --> 01:18:30.180
Hold on, hold on.

01:18:30.240 --> 01:18:30.540
Go back.

01:18:31.140 --> 01:18:33.700
Let me see, and then I'll tell you where you should be.

01:18:34.940 --> 01:18:38.340
Your last command was set payload for an option.

01:18:38.660 --> 01:18:47.700
exploit okay your last commands was set payload for in options yeah so now you

01:18:47.700 --> 01:18:51.340
got to go to set the L host so scroll back down get the cursor where it needs

01:18:51.340 --> 01:19:06.480
to be put it inside there set payload for right good now go now click on the

01:19:06.480 --> 01:19:10.800
the one note the bottom right corner again takes you right back to the

01:19:10.800 --> 01:19:21.360
terminal let's scroll hold on right there there you are now i have to go back then go back three

01:19:21.360 --> 01:19:35.060
dots screen clipping get her done oh you got a lot of extra stuff in there okay and then let it go

01:19:52.980 --> 01:20:00.080
go back to your window or the command prompt scroll all the way down to the bottom get everything

01:20:00.080 --> 01:20:09.420
oh you did because it said closed see the sessions closed yes guess what you finished

01:20:09.420 --> 01:20:20.480
hallelujah okay now but now this okay wait this one's stuck okay i can't move on notebook

01:20:20.480 --> 01:20:29.330
um close it and open it right back up again minimize it or close it actually close it

01:20:29.330 --> 01:20:36.170
i heard you say close it you want it completely shut down um won't i lose all my

01:20:36.170 --> 01:20:46.180
it stays automatically it should save automatically so close it let's reopen it

01:20:46.180 --> 01:21:15.370
find it just by there it is hopefully it'll be blank trust me yeah yeah i'm going to untitled

01:21:15.370 --> 01:21:30.780
now click on basic pen test scroll down to the bottom yeah look how pretty that is and you

01:21:30.780 --> 01:21:35.740
wanted me to send you mine it's pretty dr west it's beautiful and you did the work

01:21:35.740 --> 01:21:41.640
um donna i i i hate to say this but i don't give anybody my notes

01:21:41.640 --> 01:21:47.060
i always politely have them do it so they can get that muscle memory

01:21:47.060 --> 01:21:51.740
you learned a lot through everything that you did well and everything that you didn't do well

01:21:51.740 --> 01:22:01.500
at the first time yes and you know how to overcome it patience and um a little bit of skill here and

01:22:01.500 --> 01:22:20.800
there now your lessons learned you got a whole column over there by the way you

01:22:20.800 --> 01:22:36.950
see what says this PC notebook name yes go back there put Donna Abbey's Donna

01:22:36.950 --> 01:23:13.700
Abbey's cybersecurity portfolio save it share it again what happened just share

01:23:13.700 --> 01:23:25.170
it again i don't have share now say what happened to it probably have to go find zoom and then click

01:23:25.170 --> 01:24:12.910
on share okay did i lose you i'm still here just don't see you uh sharing the screen yet

01:24:12.910 --> 01:24:28.110
i did what happened i don't know i don't see it at all i don't see uh i see there i'm resharing

01:24:28.110 --> 01:25:03.460
there you go it's coming up now it's coming up okay so now um okay let's fill in the gaps

01:25:06.530 --> 01:25:14.960
you ready i don't know where my cali screen went but yes i'm back to notebook okay now you see the

01:25:14.960 --> 01:25:30.290
word objective underneath project looks crazy right so let's fix that and all the words underneath it

01:25:30.290 --> 01:25:39.010
two go to the right keep going just until it's right there good perfect let it go okay now um

01:25:39.570 --> 01:25:44.130
the command section scroll down in the command section let me see if there's a really long command

01:25:50.140 --> 01:25:58.880
there's one there was okay good go back up that's all i need to see scroll back up all the way to

01:25:58.880 --> 01:26:10.620
the top okay the word analysis let's make that one word and first is analysis and then i ask

01:26:10.620 --> 01:26:16.540
Uh-uh. Scroll back up. Scroll back up.

01:26:16.760 --> 01:26:19.320
I don't know where you... I don't know what you're talking about.

01:26:19.560 --> 01:26:20.440
So analysis.

01:26:20.840 --> 01:26:21.960
Do you see the word analysis?

01:26:21.960 --> 01:26:25.270
Oh, way over. You're back to the header.

01:26:25.850 --> 01:26:26.630
Yeah, make the header.

01:26:26.690 --> 01:26:27.950
Okay, the header.

01:26:28.530 --> 01:26:29.430
Make the header make sense.

01:26:29.450 --> 01:26:30.710
Yes, sir. I'm here.

01:26:32.610 --> 01:26:32.890
Okay.

01:26:33.170 --> 01:26:34.370
Okay. Fantastic.

01:26:35.050 --> 01:26:37.790
Now, scroll to the left.

01:26:39.530 --> 01:26:40.010
Left.

01:26:41.270 --> 01:26:41.710
Left.

01:26:42.550 --> 01:26:43.530
Here it is.

01:26:43.530 --> 01:26:53.190
okay um written permission i want you now objective is first written permission is second

01:26:53.190 --> 01:27:10.410
now go to the right okay objective is first written permission you know what it's gonna

01:27:10.410 --> 01:27:25.240
be better go back to the left after the word objective put a colon space to learn basic

01:27:25.240 --> 01:27:49.130
pen testing and you don't have you can write it like a regular sentence command to learn basic

01:27:49.130 --> 01:28:08.710
pen testing commands and planning techniques oh i'm sorry commands comma planning techniques

01:28:08.710 --> 01:28:53.800
comma and metasport written permission colon enter one period all right what are the things that we

01:28:53.800 --> 01:29:08.360
discuss that you need to know are you asking me yes what are the things that we discuss that i need

01:29:08.360 --> 01:29:15.360
to know how about all of them too ambiguous trick question how about um are you talking about when i

01:29:15.360 --> 01:29:22.120
go into asking the computer for permissions no i'm talking about if you're talking to if you're

01:29:22.120 --> 01:29:25.700
talking if you're doing a pen test in the real world what are the things you need to have what

01:29:25.700 --> 01:29:34.440
are the things you need to know if you don't know okay i need a great computer i need some software

01:29:34.440 --> 01:29:39.640
and i need to know the ip addresses of the network and i need to know the commands to get there

01:29:39.640 --> 01:29:48.160
so what do we call all that stuff that's so just write this down there i mean it's like i know what

01:29:48.160 --> 01:29:53.120
the answer is probably i just don't know what you want to hear i don't know what you're go where

01:29:53.120 --> 01:29:58.560
you're going so so let me help you we're going to write this out write down rules of engagement

01:30:18.160 --> 01:30:26.130
enter okay right click engagement and you can fix it real quick

01:30:26.130 --> 01:30:57.340
Okay. Number two is going to be scope of work. Non-disclosure agreement. Well, when you found

01:30:57.340 --> 01:31:02.960
out a non-disclosure, do you have it written out by an attorney? Do you have, like, how does your

01:31:02.960 --> 01:31:10.340
non-disclosures look in the pen testing world? Yes. Along with your professional liability

01:31:10.340 --> 01:31:17.180
insurance, I'm sure you have to have disclosures that are pretty thorough. All right. Do you use

01:31:17.180 --> 01:31:26.580
chat gpt you'd use the am right show me your chat gpt i have answers i have answers to it show me

01:31:26.580 --> 01:31:49.090
the screen all right i'm here see she pops right up it's beautiful okay i don't see it though can i

01:31:49.090 --> 01:31:58.710
see it yeah oh it's on a different computer that means you won't be able to copy and paste it

01:31:58.710 --> 01:32:14.160
so um let me share my screen just gotta stop sharing your screen so i can share my screen

01:32:18.440 --> 01:32:21.960
Stop sharing gay. Yeah, I'm sharing my screen

01:32:22.760 --> 01:32:24.760
All right, here we go

01:32:24.920 --> 01:32:37.590
All right, so here we go. Mm-hmm. Look at this right here. I don't see you

01:32:39.310 --> 01:32:41.310
You don't see my screen at all

01:32:42.050 --> 01:32:51.470
No, there's some you still don't see it. I'm like sharing moving the mouse and everything

01:32:52.930 --> 01:32:54.930
Okay, you know

01:32:54.930 --> 01:33:30.640
back to zoom yeah yes you see this right here i see what your question was create your list

01:33:31.600 --> 01:33:42.220
and input this inside of your um in that section tell me when you're ready i want to show you

01:33:42.220 --> 01:33:55.200
something else okay yes sir i'm ready okay i want to show you this i want to put it in the chat for

01:33:55.200 --> 01:34:10.660
you. These are some examples of pen test reports. Have you ever seen these before? Okay. The pen test

01:34:10.660 --> 01:34:18.040
reports usually are written in a particular fashion where they have a table of contents with

01:34:18.040 --> 01:34:26.360
an executive summary, an introduction methodology scope, recommended further tests, threat modeling,

01:34:26.360 --> 01:34:33.620
rating methodology. It's really tiny. Is that a little bit better?

01:34:35.000 --> 01:34:37.020
Yes. See what I'm saying?

01:34:37.580 --> 01:35:00.560
So now I'm going to come back to chat. See how it's broken down?

01:35:01.900 --> 01:35:04.340
Yes, sir. You need this

01:35:04.340 --> 01:35:10.220
because I need you to know how to write a pen test report.

01:35:10.780 --> 01:35:36.230
Look at this right here. Did you see the prompt that I wrote?

01:35:45.750 --> 01:35:49.410
And then you can public reports. This will

01:35:49.410 --> 01:35:56.690
help you so that when you have to write a pen test report yourself, oh, you have to write a pen test

01:35:56.690 --> 01:36:03.370
report on this stuff. You have something to go by. I have confidence in you and faith in you.

01:36:03.370 --> 01:36:16.240
You'll do well. The thing is, I need to show you something else. Okay. You move this over here.

01:36:16.240 --> 01:36:24.880
the thing is i want you to practice that pen test as much as possible till you get it

01:36:24.880 --> 01:36:35.240
and you have all the question yes dr west yes that's so wonderful that i have these commands

01:36:35.240 --> 01:36:45.000
now and i know how to actually execute one yay how would you go about using nmaps to

01:36:45.000 --> 01:36:54.240
figure out the ip addresses all around you like can you just do a general scan of your environment

01:36:54.240 --> 01:37:07.090
you follow those commands you know that this stuff is not fake what we're doing this is all real

01:37:07.090 --> 01:37:14.650
so to answer your question look at this right here yeah i'm gonna crack open my power shell

01:37:14.650 --> 01:37:24.970
right this is on my host network right now i think i have nmap installed on my computer

01:37:24.970 --> 01:37:36.490
let me see ip config right and then my ip address is i guess yes that's how you pull up your ip on

01:37:36.490 --> 01:37:48.390
your operating system yes ip config yes my is running that that that is a very real commitment

01:37:48.390 --> 01:37:52.870
everything we did was not real it's not a game you have to figure it out but look at this right here

01:37:54.870 --> 01:37:59.990
what would you like to do right now remember now you don't want to end map scan somebody else's

01:37:59.990 --> 01:38:04.630
stuff in the real world because that's how you would end up wearing an orange jumpsuit

01:38:04.630 --> 01:38:11.170
right because i don't have permission written permission not verbal written in writing sanction

01:38:11.170 --> 01:38:18.850
right but let's just say but what we can legally do is we can actually pen test into our home

01:38:18.850 --> 01:38:25.990
networks to see what's vulnerable and then we can close it so um look at this right here

01:38:25.990 --> 01:38:44.300
What is the equivalent of a sudo arp-scan-l on my Windows computer?

01:38:45.300 --> 01:38:46.300
Do you understand the question?

01:38:47.100 --> 01:38:47.400
Yes.

01:38:47.480 --> 01:38:47.980
Press enter.

01:38:52.360 --> 01:38:55.520
Arp scan is arpa or get neighbor.

01:38:55.540 --> 01:38:56.260
I remember that.

01:38:57.460 --> 01:39:00.240
Pingsuite, install nmap.

01:39:00.240 --> 01:39:05.240
So I come back here and I do in ARP-A.

01:39:06.240 --> 01:39:09.400
Man, I can see all the computers on my network.

01:39:11.700 --> 01:39:17.260
The MAC addresses, all this stuff right here.

01:39:17.780 --> 01:39:20.180
173-0800, right?

01:39:21.160 --> 01:39:22.680
That must be a work computer.

01:39:23.100 --> 01:39:24.960
That's one of my virtual machine computers.

01:39:25.700 --> 01:39:26.200
Gotcha.

01:39:26.640 --> 01:39:31.620
So on the virtual machine, and this is a little bit of a process.

01:39:31.620 --> 01:39:45.500
let's just say let's see uh clear right i um i do my pseudo arp dash scan it shows me everything

01:39:45.500 --> 01:39:51.900
on my network i have quite a few things on my network because in my virtual machine here

01:39:51.900 --> 01:40:05.430
like and this is what i do with my business i teach people pen testing i teach them

01:40:05.430 --> 01:40:15.490
how to install sims and sock and incident response i teach them how to do networking

01:40:15.490 --> 01:40:20.790
even advanced networking where they can actually install stuff on their home networks

01:40:20.790 --> 01:40:28.650
and isolating uh networks um a lot of different flavors we work in security onion all that stuff

01:40:28.650 --> 01:40:33.070
windows administration i'm teaching windows as a matter of fact next week

01:40:33.070 --> 01:40:40.870
um teaching people how to do active directory and server stuff i have alien vault i have my

01:40:40.870 --> 01:40:48.430
home what can the parent do the parent can do everything see it here yeah i got it right there

01:40:48.430 --> 01:40:56.390
i also i also have thank you i have a mini eight sock which is this is a red blue team

01:40:56.390 --> 01:41:06.890
i teach so this this this attack windows 11 this attack computer can attack whatever it wants to

01:41:06.890 --> 01:41:13.130
this computer is a target this server is a target this ubuntu i like how you do that

01:41:13.130 --> 01:41:18.750
this make your own target yeah the ubuntu is a sock the pf sensor is a firewall

01:41:18.750 --> 01:41:25.170
and i'm trying i'm this machine is attacking these machines um this is what i was trying

01:41:25.170 --> 01:41:39.600
show you earlier now we can see some stuff um uh here this is my cyber security portfolio

01:41:39.600 --> 01:41:46.880
see here yes sir this is a snapshot of my life things i've done in my career

01:41:47.840 --> 01:41:53.840
there's my ai image look at that handsome guy i love that photo well thank you very

01:41:53.840 --> 01:41:58.560
down for there dr west hey i did not make it a friend of mine made it for me and i was mad at her

01:41:58.720 --> 01:42:00.500
But then I was like, that guy almost looks like me.

01:42:02.000 --> 01:42:03.120
You did a good job.

01:42:03.440 --> 01:42:04.480
I thought it was nice.

01:42:05.440 --> 01:42:14.000
So at the end of the day, what I'm trying to have you do is create all these things so that you can show off to the world what you know how to do.

01:42:15.380 --> 01:42:15.860
Right?

01:42:16.580 --> 01:42:21.560
The notes you're taking, you're going to be able to show them all the different projects you've done.

01:42:21.640 --> 01:42:23.180
I do a lot of things.

01:42:23.280 --> 01:42:23.420
See?

01:42:24.140 --> 01:42:27.160
Basic pen testing, installing stuff.

01:42:27.960 --> 01:42:39.900
you do a lot of things too you already app on um on um chat gpt so there are a suite of tools

01:42:39.900 --> 01:42:47.900
for you to do that all fall on this list you just need to understand why you're doing them

01:42:50.060 --> 01:42:56.780
why you're doing this stuff sorry to someone announce hey manish i just wanted to check in

01:42:56.780 --> 01:43:02.540
that everything is going as expected so um only donna can answer that question

01:43:03.900 --> 01:43:11.420
where we had a good day we're um yes we're having a good time and that's top held up wonderfully so

01:43:11.420 --> 01:43:19.100
thank you wonderful i was just checking in and making sure so it was great he was a godsend when

01:43:19.100 --> 01:43:26.140
we needed him just to be like you know lurking in the silence so thank you thank you very much

01:43:26.140 --> 01:43:31.660
no no no it is i will uh i will exit now but yeah you have you are in the right hand thank you so

01:43:31.660 --> 01:43:45.290
much bye-bye so so check this out um um do you know how to create hidden documents and be a bad

01:43:45.290 --> 01:43:56.340
person um no but i mean well we have done a little bit of um hidden files and linux and

01:43:56.340 --> 01:44:03.860
Can find them and I've been looking for my DLL because I have several DLL files. So I did money tag

01:44:04.500 --> 01:44:07.880
hidden for Windows and just trying to pull them up, but

01:44:09.100 --> 01:44:11.100
Yeah, so that's definitely a Windows thing

01:44:13.440 --> 01:44:16.220
But um, I want you to look at this list

01:44:17.220 --> 01:44:28.730
We have and I'm gonna put it in the chat. All right, here we go

01:44:28.730 --> 01:44:39.300
go too many characters hold on how many i'm gonna take out some words so this thing will fit

01:44:39.300 --> 01:44:48.890
and let me go all the way up to i want to show you how to get this stuff

01:44:48.890 --> 01:45:08.730
okay take a look at that list right there okay hold on i'm gonna give you a second part

01:45:08.730 --> 01:45:20.570
because between today and tomorrow i need to make sure that we get through everything or most

01:45:20.570 --> 01:45:27.990
of the stuff on this list we went through and by the way um i don't think we went through but

01:45:27.990 --> 01:45:38.310
in kali linux when i click on the dragon you will see all applications you'll see usual applications

01:45:38.310 --> 01:45:46.790
such as the reconnaissance commands the resource and development commands initial access all the

01:45:46.790 --> 01:46:00.000
way down to service and other tools, forensics, privilege escalation, et cetera. The best

01:46:00.000 --> 01:46:09.970
way to learn these commands is to do vulnerable hubs and to actually build walkthroughs yourself

01:46:09.970 --> 01:46:21.780
of you doing them and completing some projects and tasks. Let me give you an example. A

01:46:21.780 --> 01:46:29.420
student a student asked me a question they said doc do you know what a phishing attack is and my

01:46:29.420 --> 01:46:33.060
answer to the question was yeah so now we're looking at each other with an awkward look

01:46:33.060 --> 01:46:39.680
and they're like well can you explain it i said i can but you can also google it just as fast

01:46:39.680 --> 01:46:45.820
if you really want to know what a phishing attack is this is what i told the student

01:46:45.820 --> 01:46:53.940
you have two hours go ahead and build one here's the example i built this fishing attack

01:46:53.940 --> 01:47:02.700
i had them build a fishing attack i just guided them through and then we tested it and who are

01:47:02.700 --> 01:47:08.020
these people you're teaching dr west is this the marines they're like who gets to pick i mean who

01:47:08.020 --> 01:47:15.200
gets to learn that the fishing attacks is that a university what kids are these what students

01:47:15.200 --> 01:47:21.740
uh all the above literally including law enforcement intelligence community military

01:47:21.740 --> 01:47:26.940
because um nobaprov found me because i own a business and this is what i do i teach people

01:47:26.940 --> 01:47:34.460
hands-on cyber and i have a group of them a bunch of interns and everything um you should probably

01:47:34.460 --> 01:47:44.860
um if you want to learn more about me um poke around here on my linkedin well i um i know

01:47:44.860 --> 01:47:50.060
enough about you to know that you're the guy i want to learn from so thank you well thank you

01:47:50.860 --> 01:48:01.420
um the thing i appreciate that like um the thing is though the i try to add context to the content

01:48:03.100 --> 01:48:10.060
if that makes sense because organizations are dynamic if they ask you to do a penetration test

01:48:10.060 --> 01:48:23.980
You need to know those rules of engagement. You need to understand why you're doing it. When does it need to be done by? How much money is it going to be? What kind of stresses do you have to account for?

01:48:23.980 --> 01:48:33.760
um students look for step-by-step stuff and that's not the real world as a sizzle and a sock

01:48:33.760 --> 01:48:41.340
um i'm not going to have any steps for you to do incident response per se i'm expecting you to come

01:48:41.340 --> 01:48:50.660
in with some experience so this whole thing here is about being able to think your way through the

01:48:50.660 --> 01:48:59.380
problem so in your one note and now i'd like for you to share your screen because i want to recap

01:48:59.380 --> 01:49:04.820
this really quickly so you can write down these lessons go ahead and share your screen hopefully

01:49:04.820 --> 01:49:15.740
this will make sense what we do show me your one note can you see me i see you and i see i'm looking

01:49:15.740 --> 01:49:34.600
for that one note okay um highlight the word objective and bold it go back to the left because

01:49:34.600 --> 01:49:43.240
i don't see anything in the more it's on a project you mean we're back to this highlight that just

01:49:43.240 --> 01:50:03.130
click it once or twice bold do the same thing with written permission i want you to continue to add

01:50:03.130 --> 01:50:12.220
to that list because i want you to know what needs to happen now you've you understand the

01:50:12.220 --> 01:50:16.860
objective you understand the written permissions you have all the rules of engagement everything

01:50:16.860 --> 01:50:23.740
else is signed you're good to go you can start the pen test the first thing you're going to do and i

01:50:23.740 --> 01:50:30.860
want you to explain to me this nothing else explain this to me like you're doing it by yourself

01:50:30.860 --> 01:50:50.820
you ready i'm ready well um okay so i would go to my vm and um i would uh pull up kelly lennox

01:50:50.820 --> 01:50:55.860
and i would type in the commands that i learned but i would have to have a target

01:50:56.580 --> 01:51:02.420
so i would need a target and i would need written permission from the target i would need a scope

01:51:02.420 --> 01:51:09.620
of engagement i would have to do my disclosures and then to blow it up okay so we'll go from there

01:51:10.500 --> 01:51:17.780
we've gotten through all of that um you have your ip address okay you can start the pen test

01:51:17.780 --> 01:51:24.580
donna what are you going to do i'm i'm just someone on your team teach me how to do what

01:51:24.580 --> 01:51:32.140
i taught you oh well that's probably not going to happen today no it can't that's why i'm here

01:51:32.140 --> 01:51:37.420
i want to help each of these commands but i mean it's like i can't like talk without the notes

01:51:37.420 --> 01:51:40.860
yeah no read your notes that's what they i want you to go off the notes

01:51:42.700 --> 01:51:47.980
tell me what you did tell me what i should do you have it all written

01:51:49.580 --> 01:51:57.820
yeah so i'm gonna find the ip address by uh plugging it in ip address and um

01:51:57.820 --> 01:52:03.320
Um, so hold on, hold on, hold on, plug it into where a socket. We're going to plug it in.

01:52:03.920 --> 01:52:09.760
I'm going to put it. I'm going to plug it into the Cali command line. Okay. Hold on. Let's do this.

01:52:10.060 --> 01:52:13.760
This will be even better. I don't want to see your stuff. Go ahead and stop sharing.

01:52:17.880 --> 01:52:23.820
Stop sharing your whole screen. Keep your one note open. All right. Stop sharing your whole

01:52:23.820 --> 01:52:30.200
screen. Keep your one note open. Stop sharing. Okay. Fantastic. I'm going to share my screen.

01:52:30.200 --> 01:52:38.980
right right now i need you to be able to see your notes but i also need you to be able to see my

01:52:38.980 --> 01:52:56.500
screen you understand just put your notes on put your notes on one half and watch me type

01:52:56.500 --> 01:53:12.330
we are going to do this thing successful all right it is now 256 let me see what you can show me

01:53:12.330 --> 01:53:18.670
i showed you how to do basic pen testing today we've i understand objective i understand the

01:53:18.670 --> 01:53:23.190
written permission, rules of engagement, the scope. I got that. Now, I know the first thing

01:53:23.190 --> 01:53:32.630
you said I need to do is what? What do I type? Your IP address, the IP address that you're

01:53:32.630 --> 01:53:40.330
targeting. So now, hold on. You're talking to a real client and you're speaking generic,

01:53:40.530 --> 01:53:46.950
but you need to speak to me with specifics. I'm going to be typing. If I typed in what you said,

01:53:46.950 --> 01:53:56.930
i type the ip address you're gonna type ip and then the network address ip and then the network

01:53:56.930 --> 01:54:07.890
address or one zero point zero point three point one six i'm sorry be specific because i'm already

01:54:07.890 --> 01:54:13.850
doing most and i have more questions than i don't know what to do yet tell me what to type

01:54:13.850 --> 01:54:28.760
specifically i thought i would tell you the type ip and the address which is 1.0.0.1

01:54:29.320 --> 01:54:37.960
the network address i already said it uh-uh look at your look at your i got you i got you this is

01:54:37.960 --> 01:54:47.880
good look at your one note literally tell me the screenshot or the bullet what's the first command

01:54:47.880 --> 01:54:58.120
i'm supposed to type ipa like that we look for at the address going too fast going too fast you're

01:54:58.120 --> 01:55:05.160
not looking at what i'm doing i just i'm playing i can't go back and forth ah make it half the screen

01:55:05.160 --> 01:55:12.840
shrink it up you need to do adapt and overcome because you're talking to the client now

01:55:12.840 --> 01:55:19.220
and i'm okay so i will get there but will you tell me how to split my screen so i can do this

01:55:19.220 --> 01:55:26.860
with you just shrink your window and put it on one half of the screen um just size it i did size it

01:55:26.860 --> 01:55:33.900
but it's not that simple without this garbage on here so here here's my here's my let me shrink

01:55:33.900 --> 01:55:40.220
it and i'll just i'll do it like okay i'm with you can you see mine i cannot see yours yes i'm

01:55:40.220 --> 01:55:46.460
gonna minimize okay i'm gonna do this it's about like the size of you know i mean i need a microscope

01:55:46.460 --> 01:55:52.860
but no no no hold on hold on i'm gonna do this i can't see anything can you see can you see what

01:55:52.860 --> 01:56:03.780
i'm doing now i can see that you've typed ipa no i'm just making the screen work see how that works

01:56:03.780 --> 01:56:05.180
I don't know what you're talking about.

01:56:05.360 --> 01:56:05.600
Yeah.

01:56:06.320 --> 01:56:07.120
That's what I'm doing.

01:56:07.120 --> 01:56:09.720
But I have my notes blocking your screen, Doc.

01:56:09.800 --> 01:56:11.140
That's what I'm trying to say.

01:56:11.200 --> 01:56:12.540
If you want my notes there.

01:56:13.200 --> 01:56:14.480
I didn't split my screen.

01:56:14.600 --> 01:56:15.940
I just put them on the screen.

01:56:16.120 --> 01:56:20.340
So let's just keep going because this stuff, I mean, we only got an hour.

01:56:20.520 --> 01:56:21.300
So let's go.

01:56:21.700 --> 01:56:22.240
I'm with you.

01:56:22.300 --> 01:56:25.500
I have my notes, and I will read them to you if you want me to.

01:56:25.500 --> 01:56:29.420
But I also want you to see my screen because you're the, you're trained.

01:56:29.560 --> 01:56:30.320
I'm the client.

01:56:30.640 --> 01:56:31.720
I'm looking at it.

01:56:32.680 --> 01:56:32.900
Okay.

01:56:32.900 --> 01:56:40.020
So now, I also want you to be extremely specific and look at the outputs.

01:56:40.880 --> 01:56:43.880
So now, I don't know anything about this thing.

01:56:44.020 --> 01:56:44.840
That's the scenario.

01:56:46.120 --> 01:56:49.740
I need to do what you did by your notes.

01:56:50.320 --> 01:56:51.700
Go ahead and tell me what to do.

01:56:53.510 --> 01:56:59.530
Enter in small case, an I, a P, a space, and an A.

01:56:59.950 --> 01:57:00.350
Okay.

01:57:04.160 --> 01:57:12.880
so then your your next line make a note of the ip address that we're using i entered the i the p

01:57:12.880 --> 01:57:24.800
the space and the a what do i do now enter enter okay my ip address is which one the one under

01:57:24.800 --> 01:57:27.060
ETH 0

01:57:27.060 --> 01:57:28.260
ETH 0

01:57:28.260 --> 01:57:30.840
So is this one here

01:57:30.840 --> 01:57:31.460
Well that's

01:57:31.460 --> 01:57:35.100
Alright hang on I gotta go back

01:57:35.100 --> 01:57:36.380
Tell me again

01:57:36.380 --> 01:57:38.840
So yours is right here

01:57:38.840 --> 01:57:40.180
Right here

01:57:40.180 --> 01:57:44.360
So that's my IP address of what machine

01:57:44.360 --> 01:57:46.440
Of your machine

01:57:46.440 --> 01:57:47.360
Of the

01:57:47.360 --> 01:57:49.060
Of your

01:57:49.060 --> 01:57:50.700
Machine

01:57:50.700 --> 01:57:53.320
Which is my attack machine my Cali machine

01:57:53.320 --> 01:57:54.080
Is that what you mean

01:57:54.080 --> 01:57:58.140
Yeah, I guess. I don't know.

01:57:58.560 --> 01:58:02.520
Yes, it is. This is the attack machine, the Kali Linux machine.

01:58:03.140 --> 01:58:10.420
IP address is the same as ipconfig or even this is the old command, ifconfig.

01:58:12.310 --> 01:58:15.630
That's what we use in class, ifconfig.

01:58:15.890 --> 01:58:19.190
Right. Now, in the real world, we use any and everything.

01:58:20.290 --> 01:58:22.730
So I'm going to need you to learn more than one thing.

01:58:23.590 --> 01:58:24.230
I understand.

01:58:24.230 --> 01:58:26.370
I have config also is old school.

01:58:26.650 --> 01:58:28.130
Look at how white it is.

01:58:28.970 --> 01:58:30.390
You know, it's black and white.

01:58:31.010 --> 01:58:37.730
Whereas the IPA shows the color schema, which everyone seems to like.

01:58:38.710 --> 01:58:38.970
Yeah.

01:58:39.390 --> 01:58:40.490
Okay, I understand.

01:58:41.130 --> 01:58:44.690
I did the IP space A, which is short for what?

01:58:44.790 --> 01:58:45.270
Do you know?

01:58:48.520 --> 01:58:52.530
The A, I did know.

01:58:54.490 --> 01:58:56.030
How do I find it if I don't know?

01:58:56.450 --> 01:58:59.550
I don't know.

01:58:59.710 --> 01:59:01.090
I thought it was man something.

01:59:01.090 --> 01:59:11.480
but i was doing the ip scan right ipa man

01:59:11.480 --> 01:59:21.800
now take a look man for manual ip space a i'm trying to find out what ipa means

01:59:21.800 --> 01:59:36.890
so i type man ipa and it shows me this information here and an ipa is short for

01:59:36.890 --> 01:59:45.070
ip address which is written on your notes yeah so if you look at your notes you'll be able to see

01:59:45.070 --> 01:59:53.550
this right we have to find our ip address before we can attack a machine a target machine

01:59:53.550 --> 02:00:02.090
okay so that's what we did we found the ip address in linux with ipa or ip address

02:00:02.090 --> 02:00:13.190
now what's your next command on your window the next command is to do the pseudo so small case

02:00:13.190 --> 02:00:23.580
oh hold it that's not right so the next command is to do is great it's not filled out i just get

02:00:23.580 --> 02:00:33.630
you keep telling me that's the last command i type that's why it shows up i don't understand

02:00:33.630 --> 02:00:39.230
what you said okay so that don't worry about what you see there that's grayed out that's not

02:00:39.230 --> 02:00:55.600
that's the last command i typed so ignore that just tell me the command to type dash scan space

02:01:00.620 --> 02:01:09.610
then what enter okay talk to me with confidence you're gonna get it that's what i'm looking for

02:01:09.610 --> 02:01:16.250
i want you to tell me what to do okay something's wrong i don't see what i'm looking for right

02:01:16.250 --> 02:01:20.950
Can you tell me why I can't see what I'm looking for?

02:01:21.290 --> 02:01:22.910
Or what should I be looking for, rather?

02:01:24.270 --> 02:01:28.870
Were we supposed to enter a basic Kent testing with the IP number?

02:01:29.190 --> 02:01:32.970
So we are looking for the IP address.

02:01:33.250 --> 02:01:36.710
What do I need to do so that I can see that?

02:01:37.710 --> 02:01:38.870
A network scan.

02:01:39.390 --> 02:01:39.690
Okay.

02:01:39.690 --> 02:01:42.820
A discovery ping.

02:01:43.180 --> 02:01:43.860
How about this?

02:01:43.860 --> 02:01:49.520
When you first start this thing, you have to run a particular software first, right?

02:01:51.060 --> 02:01:53.320
Called VBOX.

02:01:54.840 --> 02:01:56.300
Right, VirtualBox.

02:01:56.380 --> 02:01:57.180
Start me off.

02:01:57.600 --> 02:01:58.100
What do I do?

02:01:59.180 --> 02:02:00.900
Boot up your VirtualBox.

02:02:01.160 --> 02:02:06.240
So, okay, here's my VirtualBox, one thing at a time, right?

02:02:06.300 --> 02:02:08.500
Because I'm an ignorant client and I don't know.

02:02:09.000 --> 02:02:10.340
Okay, now what do I do?

02:02:12.320 --> 02:02:13.760
You power up your VM.

02:02:14.000 --> 02:02:14.340
Okay.

02:02:14.340 --> 02:02:15.160
By hitting start.

02:02:15.240 --> 02:02:16.720
I'm powering up, okay?

02:02:21.200 --> 02:02:23.180
Close your mouse and your keyboard.

02:02:23.620 --> 02:02:24.040
Okay.

02:02:25.360 --> 02:02:26.540
It's coming open.

02:02:27.140 --> 02:02:31.160
We are doing this whole pen test thing.

02:02:31.400 --> 02:02:35.720
So I have to open my virtual box, make sure that VM is started,

02:02:35.720 --> 02:02:41.220
and then I have to find my IP address of my Kali Linux machine.

02:02:41.300 --> 02:02:47.610
Okay, I understand why I have to do all that, right?

02:02:47.670 --> 02:02:51.750
Because I know that this stuff is repeatable for almost every pen test,

02:02:51.750 --> 02:02:58.530
so i have to talk it through and get it right i'm i'm knocking on your door

02:02:58.530 --> 02:03:07.430
this thing says marlin spike let me minimize that minimize that

02:03:07.430 --> 02:03:17.650
okay i got my ip address of my my uh attack machine i'm now looking for the i i'm looking

02:03:17.650 --> 02:03:29.990
to see if i can connect to the um target machine so we got a ping so can but before i can ping i

02:03:29.990 --> 02:03:42.580
have to find the ip address of the target machine right true how do i find that look at your one

02:03:42.580 --> 02:03:49.700
note and just read it and go line by line you know so it's like a ping in the in the

02:03:49.700 --> 02:04:00.360
ip address or what did we do before the ping and the ip address i don't know which block that we're

02:04:00.360 --> 02:04:06.880
on because we've only covered two start at the top what's the very first command that i told you

02:04:06.880 --> 02:04:16.140
to do ip space a and after that underneath that it was ip adder ip address and then the second

02:04:16.140 --> 02:04:28.190
section underneath that what section is that is the um i don't have the i don't have the command

02:04:28.190 --> 02:04:36.430
it's uh just the ip addresses of the network do you have pseudo net discover in there anywhere

02:04:38.190 --> 02:04:48.640
well that's like way down no i don't okay then show me your document maybe we're missing something

02:04:48.640 --> 02:05:04.770
can you see it not yet i don't know how to show you there it is on my side um share screen click

02:05:04.770 --> 02:05:17.570
on share there you go it's coming open come on okay scroll to the top let me see this thing

02:05:17.570 --> 02:05:35.770
we're missing something and go to the left so i can see there you go right there that's what

02:05:35.770 --> 02:05:43.370
you're supposed to be reading so don't have to discover okay i want to stop sharing and i want

02:05:43.370 --> 02:05:51.880
to share my screen you're going to read from that and look at the images you understand and then the

02:05:51.880 --> 02:05:57.640
um as far as the scope goes that's what we need to do and you just probably have to make a little

02:05:57.640 --> 02:06:19.060
a lot smaller too whenever you can what am i doing okay um stop sharing so i can share my screen

02:06:19.060 --> 02:06:33.250
stop sharing okay somehow some way um i understand it's just that i was reading off the

02:06:33.250 --> 02:06:38.850
never mind i was reading off the screenshots and i didn't give the suit on that discover

02:06:38.850 --> 02:06:44.870
right but yeah it was a network scan i said we needed a network scan but i didn't see the command

02:06:44.870 --> 02:06:57.670
because my screen was so big we need to type in in small case the letters s udo space net net

02:06:57.670 --> 02:07:09.050
n-e-t discover one word enter and what does this do again this will show you all the things

02:07:09.050 --> 02:07:18.500
connected to the ip address ah okay oh wow i've got this address right here and i'm gonna

02:07:18.740 --> 02:07:22.540
right-click it, and split the terminal left and right.

02:07:22.860 --> 02:07:26.540
And you just said, if I type sudo arc-scan,

02:07:27.320 --> 02:07:29.440
it'll do the same thing.

02:07:32.860 --> 02:07:34.300
And much faster, too.

02:07:34.380 --> 02:07:34.800
Thank you.

02:07:35.220 --> 02:07:35.960
See that right there?

02:07:37.100 --> 02:07:37.620
Yes.

02:07:38.500 --> 02:07:42.840
I remember you told me earlier that this MAC address was somewhere, right?

02:07:46.000 --> 02:07:47.380
Where do I find that MAC address?

02:07:48.740 --> 02:07:49.500
Right there.

02:07:50.780 --> 02:07:51.140
Mm-mm.

02:07:51.600 --> 02:07:53.280
Where do I find that MAC address?

02:07:53.280 --> 02:08:02.750
on the network and the net card and how do i get to that through the back door

02:08:02.750 --> 02:08:16.800
i don't know ping it when i click on here and i go to settings go to network network

02:08:16.800 --> 02:08:23.600
there is the mac address that's how i know that this ip address is correct

02:08:23.600 --> 02:08:31.160
you may need to write that down someplace right so you're matching the ip address to the mac address

02:08:31.160 --> 02:08:38.160
to verify that it's the same number through the network caption on your vm right i'm matching this

02:08:38.160 --> 02:08:45.980
mac address to that network settings mac address and that's how i know the ip address because my

02:08:45.980 --> 02:08:53.820
IP address could be totally different from yours, especially if I change some other settings,

02:08:53.820 --> 02:09:03.700
which I have to show you after this. Okay. All right. How do I stop this? Because it's still

02:09:03.700 --> 02:09:15.480
running. Okay. Okay. Thank you very much. I appreciate that. Now, what do I do? I found

02:09:15.480 --> 02:09:24.320
the IP address. Now what? Found the IP address and I'll ping it to see if it's active. How do I

02:09:24.320 --> 02:09:36.220
ping it? I don't do this computer stuff. You type in the word P-I-N-G lowercase space and then the IP

02:09:36.220 --> 02:09:44.140
address one zero point zero point three point one six enter and it'll keep pinging how do i stop it

02:09:45.820 --> 02:09:59.340
q or ctrl c q didn't work ctrl c worked all right is there any other option i can do escape or exit

02:09:59.340 --> 02:10:06.220
maybe uh-uh i pinged it i stopped it is there any other way to ping this thing you can ask

02:10:06.220 --> 02:10:17.900
ping it how do i do that you type in lower case f p i n g space the same address one zero point

02:10:17.900 --> 02:10:25.100
zero point three point one six enter okay so i'm gonna hit the up arrow press the letter control a

02:10:25.100 --> 02:10:32.380
and control and then f and then press enter and it says it's alive is that good yes oh okay

02:10:32.380 --> 02:10:38.860
all right now um okay so that means i've verified connectivity between ping and fping

02:10:38.860 --> 02:10:45.740
and then fping is just the more advanced uh version of ping and it doesn't count forever

02:10:45.740 --> 02:10:54.380
okay i understand the difference now what do i do now you're gonna uh use nmap so you're going to

02:10:54.380 --> 02:11:03.020
go back to the command prompt line and type in lower case n m a p space and the same ip address

02:11:03.020 --> 02:11:11.340
one zero point zero point three point one six and enter okay oh what is that telling me there's a

02:11:11.340 --> 02:11:16.140
whole lot of stuff here i don't know what that means it's going to show you the open ports on

02:11:16.140 --> 02:11:28.040
that network okay what does this mean starting in map 7.95 that is the latest version of that oh

02:11:28.040 --> 02:11:32.520
okay that's the version thanks for explaining that to me and this says the scan report but

02:11:32.520 --> 02:11:40.760
there's no latency and it says 997 ports why is that well those are the ones that are closed

02:11:41.720 --> 02:11:50.040
so it's scanning the total ports on the network in this case it was a thousand ports 997 were closed

02:11:50.040 --> 02:11:56.920
three are showing open fantastic okay so it's actually the first used 1000 ports which could be

02:11:56.920 --> 02:12:05.240
any numbers in between okay okay so then from there then i have this mac address okay and i

02:12:05.240 --> 02:12:13.640
got this ip okay so i did the nmap scan uh i see these three ports are open so what's my what do

02:12:13.640 --> 02:12:28.470
i do next so next you want to type in on your command prompt line lowercase nmap the ip address

02:12:28.550 --> 02:12:37.130
That's 10.0.3.16, space, dash, capital A.

02:12:37.590 --> 02:12:38.350
Okay.

02:12:39.670 --> 02:12:40.830
And enter.

02:12:42.090 --> 02:12:42.530
Okay.

02:12:42.850 --> 02:12:44.230
What does that dash A mean?

02:12:46.450 --> 02:12:56.420
That dash A means that the question.

02:12:57.140 --> 02:13:06.330
So I remember you told me something earlier about going to this whole NMAP cheat sheet.

02:13:06.330 --> 02:13:18.640
is the list of the list okay i'm gonna type control f tack capital a right following your

02:13:18.640 --> 02:13:31.200
instructions right and close this the dash capital to a enter enter oh here it is right here let's

02:13:31.200 --> 02:13:40.280
move this over close that all this stuff in a way the dash capital A means enables OS detection

02:13:40.280 --> 02:13:49.440
version deception script scanning scanning and tracer route okay I got it that's what it does

02:13:49.440 --> 02:13:59.700
because what I noticed is when I did this it gave a lot more information than this first scan so this

02:13:59.700 --> 02:14:07.880
dash capital a is a keeper and i see much more information about these different ports it even

02:14:07.880 --> 02:14:14.040
gave them a service and the version the service and the version i got a whole bunch of stuff open

02:14:14.040 --> 02:14:23.430
oh man it says an apache ubuntu server is open that doesn't sound good okay so what do i do next

02:14:23.430 --> 02:14:38.090
so next you want to keep going with this and do another command with nmaps which is a small case

02:14:38.090 --> 02:14:56.710
nmap space the ip address 10.0.3.16 space dash capital a space dash p dash or tack i should

02:14:56.710 --> 02:15:13.490
start saying tack then why am i doing this i'm doing it but why what is the tack p deck let

02:15:13.490 --> 02:15:20.650
me search for it on this cheat sheet you gave me i'm searching i'm searching too hey

02:15:20.650 --> 02:15:25.890
Okay, so the TAC-B-TAC causes me to scan all ports.

02:15:27.090 --> 02:15:27.730
Yes.

02:15:27.910 --> 02:15:29.190
How many ports are there?

02:15:30.290 --> 02:15:32.910
65,535.

02:15:33.550 --> 02:15:33.930
Okay.

02:15:34.310 --> 02:15:36.850
I thought it was 36 because they count zero.

02:15:37.230 --> 02:15:40.950
Unless you're on chat, yes.

02:15:41.250 --> 02:15:42.450
Okay, just saying.

02:15:42.650 --> 02:15:43.090
You're right.

02:15:43.410 --> 02:15:46.330
All right, we're learning together, right?

02:15:46.890 --> 02:15:51.330
Okay, so I did this, and I scanned all the ports.

02:15:51.330 --> 02:16:01.910
i didn't see anything different i still see three ports open should i do next well next you're gonna

02:16:01.910 --> 02:16:12.670
want to uh use nmap so back to your prompt line and lowercase nmap space the ip address

02:16:12.670 --> 02:16:21.870
one zero point zero point three point one six space tack capital a space tack p

02:16:23.470 --> 02:16:39.600
pack space greater than sign and then bp and map scan dot txt all lower case okay enter

02:16:39.600 --> 02:16:52.980
Sure. Why am I doing that? Well, because that's going to give you the MAC addresses

02:16:52.980 --> 02:17:06.390
and that's going to give you more information. Actually, so when I have this, I already got

02:17:06.390 --> 02:17:12.330
the more information, this greater than sign, doesn't that mean like to append the data inside

02:17:12.330 --> 02:17:21.910
of a text file yeah because we created that text file and uh now what do i do how do i check it

02:17:24.040 --> 02:17:31.880
you're going to use the cat command lowercase with the bp and map scan dot txt file

02:17:33.080 --> 02:17:38.040
okay how do i check it are there any other commands to check and see what i have in this

02:17:38.040 --> 02:17:46.760
this directory uh ls list it list it oh i see it right there now i can use that cat command right

02:17:49.030 --> 02:17:54.870
now you can use the cat command oh so all it did was show me that i took all that information and

02:17:54.870 --> 02:18:02.390
put it inside of a file just in case i want to look at it later okay i got it now what do i do

02:18:02.390 --> 02:18:17.270
You do something totally different, and you're going to search sploic, all lowercase one word, in your command prompt line.

02:18:17.710 --> 02:18:20.530
Before I do that, I'm just curious.

02:18:20.690 --> 02:18:23.550
It says port 21 is open, which is FTP.

02:18:24.750 --> 02:18:27.550
Port 22 is open, which is SSH.

02:18:28.330 --> 02:18:31.350
Port 80, is there a way to access port 80?

02:18:31.350 --> 02:18:46.840
Go through the HTTP, the right-click on these properties to look at the page.

02:18:47.580 --> 02:18:48.380
Hold on.

02:18:48.920 --> 02:18:49.800
I go to HTTP.

02:18:50.160 --> 02:18:50.980
How do I get that?

02:18:54.660 --> 02:18:56.460
Well, you want to check that port.

02:18:56.700 --> 02:19:05.100
So you're just going to open Firefox and plug in the IP address.

02:19:05.100 --> 02:19:17.440
okay so 10.0.3.16 and oh i got this you know what we should probably copy this and put it in our

02:19:17.440 --> 02:19:28.900
notes too just create a new row right underneath the inmap scan what do you think yeah that way we

02:19:28.900 --> 02:19:34.640
won't forget it no i think we should do that since we didn't do that the first time so now that i've

02:19:34.640 --> 02:19:42.040
done that now what's that thing you said search for it yeah now we're doing search flight and why

02:19:42.040 --> 02:19:53.670
am i doing this again what am i doing you are hang on let me get to the command you are trying to

02:19:53.670 --> 02:20:02.590
penetrate that ftp file okay well what am i searching for this for oh you're searching for um

02:20:02.590 --> 02:20:04.130
It's P-R-O.

02:20:04.330 --> 02:20:04.950
I got it.

02:20:05.050 --> 02:20:05.450
I typed it.

02:20:05.470 --> 02:20:08.300
Capital P, capital T.

02:20:08.980 --> 02:20:19.580
I mean, capital F, capital T, capital P, capital D, space, 1.3.3.3, lower C.

02:20:20.300 --> 02:20:20.600
Okay.

02:20:20.660 --> 02:20:21.140
I typed that.

02:20:21.200 --> 02:20:21.580
Now what?

02:20:22.800 --> 02:20:23.160
Enter.

02:20:24.040 --> 02:20:24.440
Okay.

02:20:25.320 --> 02:20:25.700
Oh.

02:20:25.700 --> 02:20:37.280
going to show you that exploit title and you know what medical exploit has to say about it

02:20:37.280 --> 02:20:44.400
in the sense that it is a good target or not okay i see that i'm looking at some stuff right here

02:20:44.400 --> 02:20:49.280
this is really interesting the first one says compromise the second one says back door

02:20:49.280 --> 02:20:56.000
not really sure what all that means yet but i see some stuff um shell codes no results so now

02:20:56.000 --> 02:21:07.390
what do I do? Well, now you're going to get back on your console. Okay. And you're going to do

02:21:07.390 --> 02:21:20.310
the MSF console, C-O-N-S-O-L-E. Okay. MSF console. I'm typing that in on the right.

02:21:20.990 --> 02:21:37.570
And what does that mean? Where am I going? What am I doing? Oh, it says metasploit.com.

02:21:37.570 --> 02:21:42.050
that's your shell

02:21:42.050 --> 02:21:44.850
2,529 exploits

02:21:44.850 --> 02:21:46.450
1302 auxiliary

02:21:46.450 --> 02:21:47.790
1431 post

02:21:47.790 --> 02:21:49.870
1669 payload

02:21:49.870 --> 02:21:51.590
wow this thing looks like a

02:21:51.590 --> 02:21:52.610
non-evasion

02:21:52.610 --> 02:21:54.950
this is like the hacking kingdom

02:21:54.950 --> 02:21:56.190
what do I do now

02:21:56.190 --> 02:22:01.310
well you're going to search the

02:22:01.310 --> 02:22:02.950
exploit title

02:22:02.950 --> 02:22:05.450
from the screenshot above

02:22:05.450 --> 02:22:07.350
which is capital P-R-O

02:22:07.350 --> 02:22:09.330
capital F-T

02:22:09.330 --> 02:22:22.910
pd space 1.3.3 small c okay i just typed in pro ftpd 1.3.c do i press enter or do i have to type

02:22:22.910 --> 02:22:39.840
something else press enter press enter okay says unknown what do i do now well what's your

02:22:39.840 --> 02:22:47.820
screenshot and your paperwork say i'm looking at it that's a good question it uh i mean so

02:22:47.820 --> 02:22:54.420
So I just, so, I mean, we have to look at the matching modules and we have to get to zero.

02:22:55.500 --> 02:22:57.440
Well, right now I see.

02:22:57.620 --> 02:22:58.740
Command is zero.

02:22:59.120 --> 02:23:00.440
Can you see my screen?

02:23:01.640 --> 02:23:03.880
Well, I'm looking at my notes, so no.

02:23:04.240 --> 02:23:06.320
So minimize that and look at what I type.

02:23:06.520 --> 02:23:06.700
Okay.

02:23:07.180 --> 02:23:09.480
So now I'm looking at your screen and.

02:23:10.660 --> 02:23:14.280
You said I have to search for ProLabs EPD 1.3.C.

02:23:14.340 --> 02:23:14.920
I wrote that.

02:23:16.060 --> 02:23:17.260
Use zero.

02:23:17.260 --> 02:23:20.280
So, capital U-S-E, or U-S-E.

02:23:20.440 --> 02:23:21.580
But I got this whole error.

02:23:21.760 --> 02:23:24.120
I can't move forward until I fix this error.

02:23:26.440 --> 02:23:27.300
Yeah, I see that.

02:23:28.100 --> 02:23:29.400
What does your image say?

02:23:30.220 --> 02:23:30.980
Let me see it.

02:23:31.380 --> 02:23:32.000
Let me look.

02:23:36.100 --> 02:23:38.020
Well, you were supposed to write search.

02:23:40.140 --> 02:23:41.020
I did search.

02:23:41.360 --> 02:23:41.880
Write where?

02:23:41.960 --> 02:23:42.480
Search where?

02:23:47.680 --> 02:23:48.280
FTPD.

02:23:48.820 --> 02:23:50.060
So, let's start over.

02:23:50.220 --> 02:23:55.640
You have to go to the command and apply and type in search, all in lowercase.

02:23:55.760 --> 02:23:56.640
Oh, I did it.

02:23:56.720 --> 02:23:56.980
Okay.

02:23:57.380 --> 02:24:08.680
you can't you can't see my screen yes i can now okay i typed in search right here the first time

02:24:08.680 --> 02:24:13.260
i didn't type search you said you wanted me to search and said that stuff but you didn't say

02:24:13.260 --> 02:24:25.460
type search so my bad my bad i just didn't know we want me to type now usc usc zero zero then what

02:24:25.460 --> 02:24:32.680
zero enter enter oh hey it came up with units ftp pro ftp dc in the back door

02:24:32.680 --> 02:24:47.290
now what do i do now now we're gonna uh go back to the command prompt and search options

02:24:47.290 --> 02:24:55.350
options so you're gonna type in options and enter okay option oh i have a lot of options here

02:24:55.350 --> 02:25:02.110
uh c host now we're gonna set the r host okay because this is our host yes so how do i set

02:25:02.110 --> 02:25:16.670
our host so you're gonna type in set set space space set capital r h o s t okay space yep and

02:25:16.670 --> 02:25:25.280
the ip address one zero point zero point three point one six okay and which what does our host

02:25:25.280 --> 02:25:44.610
mean host means um what i know this i know this in metasploit is for the remote host oh okay so

02:25:44.610 --> 02:25:49.490
i'm setting the remote host which means that my attack machine is the remote host

02:25:50.370 --> 02:25:57.090
okay and i'm trying to get in i said it now what's next now you're gonna ask

02:25:57.970 --> 02:26:05.410
for metasploit to show the payloads so you're going to type in show okay space payloads enter

02:26:06.050 --> 02:26:12.130
okay show payloads there's eight different payloads actually nine because it starts with zero

02:26:14.720 --> 02:26:23.440
wow i can add users i can add users i could do command shell the bind and then you said set payload

02:26:23.440 --> 02:26:34.720
four yeah so you're gonna look at payload four okay command unix reverse okay now what do i do

02:26:35.200 --> 02:26:43.250
and so did you set the payload payload is set you can't see my screen huh

02:26:44.210 --> 02:26:52.880
night well i just quit i can't see the writing it's so small so now you type in options enter

02:26:53.440 --> 02:27:01.470
options enter okay and then you're gonna set

02:27:03.070 --> 02:27:13.550
got a local host local host yeah which is um the ip address of your attack is the local host

02:27:14.270 --> 02:27:19.470
okay how do i set it so you're gonna type in s-c-t s-c-t

02:27:19.470 --> 02:27:33.470
base st okay yes your host ip which is one zero point zero point three point one five

02:27:33.470 --> 02:27:42.030
that we found during entering the ip command in the beginning ah i remember that the ipa for my

02:27:42.030 --> 02:27:48.970
address for my cali lettuce machine with the tack a command so then my attack machine is the local

02:27:48.970 --> 02:27:59.260
host your attack machine is the local host and the our host is your target okay a target machine i

02:27:59.260 --> 02:28:07.500
got it okay what's next so now you're gonna run over u n okay enter and then you're gonna check

02:28:08.300 --> 02:28:14.380
who are you well so you just run and enter and then you're gonna in the command prompt you're

02:28:14.380 --> 02:28:22.780
gonna write who am i enter okay it's man it's sending the back door command accepted the first

02:28:22.780 --> 02:28:30.940
client connection accepted the second one it echoed this thing here and writing socket a's and b's

02:28:30.940 --> 02:28:37.340
reading from socket a's and b's it's matching that b is input command shell one is open oh

02:28:38.300 --> 02:28:53.760
who am i it says root yes you want to be the root so then is it over no you have to type in

02:28:53.760 --> 02:29:07.040
your command prompt line cd space four space root the four slash like that four would be just the

02:29:07.040 --> 02:29:22.320
number four cd four root space cd space root cd space four space root like that yeah that looks

02:29:22.320 --> 02:29:41.340
good oh what's wrong with this picture says can't cd the four i thought it was this wrong command

02:29:41.340 --> 02:29:57.150
so i'm going to change that okay so it is a um yes so what does this mean now that means that you

02:29:57.150 --> 02:30:06.110
have full um control over what's happening on number four okay so that means am i in command

02:30:06.830 --> 02:30:13.790
and you can now command it whatever it is okay so i'm now into that machine it looks like

02:30:13.790 --> 02:30:22.350
which means that metasploit tool is awesome now i have experience on the command line

02:30:22.350 --> 02:30:28.990
i have experience with metasploit i have experience with all these other things

02:30:28.990 --> 02:30:41.480
this is really cool let me show you something else the ssh command let me see bandit zero at

02:30:41.480 --> 02:30:52.800
at banditoverthewire.labs.com, tag P2220.

02:30:52.800 --> 02:30:55.240
I think that's it.

02:30:55.240 --> 02:30:59.000
Could not resolve band name over.

02:30:59.000 --> 02:31:00.720
OK, that means I got to look it up.

02:31:00.720 --> 02:31:03.000
Let's look it up.

02:31:03.000 --> 02:31:03.840
Wow.

02:31:03.840 --> 02:31:07.810
Let's go here.

02:31:07.810 --> 02:31:09.170
Bandit over the wire.

02:31:09.170 --> 02:31:11.010
There you go.

02:31:11.010 --> 02:31:13.130
All right, let's go here.

02:31:14.570 --> 02:31:28.760
and we go to can't read me probably the first one bandit dot labs dot over the wire that work

02:31:28.760 --> 02:31:43.340
that's what it is so i come here do the control a thing bandit dot labs dot over the wire dot com

02:31:44.220 --> 02:32:00.600
enter could not resolve on the band lab maybe i have to go wrong to bring there okay so i'll do

02:32:00.600 --> 02:32:14.360
it from here what i'm trying to show you is how you use ssh ssh e enter see that right there as

02:32:14.360 --> 02:32:28.200
long as you know the username the url the port and the password which is bandit zero

02:32:28.200 --> 02:32:33.640
you can SSH into any server in the world from your command line.

02:32:35.600 --> 02:32:37.520
So you got to crack the password first.

02:32:37.760 --> 02:32:38.080
Correct.

02:32:38.440 --> 02:32:41.520
And that was what we were doing with basic pen testing one.

02:32:43.200 --> 02:32:46.360
More importantly, we were just getting inside of it first.

02:32:47.380 --> 02:32:50.560
Basic pen testing two, which we'll do tomorrow,

02:32:50.980 --> 02:32:53.680
we're going to crack into some stuff.

02:32:53.980 --> 02:32:55.880
We're going to crack some passwords.

02:32:56.620 --> 02:32:59.060
We're going to do some stuff that make you go,

02:32:59.060 --> 02:33:02.300
So, oh, and what happens is, host name is Gibson.

02:33:04.480 --> 02:33:09.720
So, okay.

02:33:09.920 --> 02:33:10.980
Hey, I found the password.

02:33:11.660 --> 02:33:13.440
The key here is this.

02:33:15.040 --> 02:33:19.780
Within Kali Linux, you have all these different tools.

02:33:20.900 --> 02:33:23.260
How did that password just pop up?

02:33:23.980 --> 02:33:31.120
Because this is one of those labs that I know of online that teaches you how to use SSH.

02:33:31.120 --> 02:33:35.800
It teaches you how to use Linux. It teaches you how to do pen testing.

02:33:37.300 --> 02:33:41.820
It's a lot like NCL, right? You ever did NCL before?

02:33:43.480 --> 02:33:45.520
Oh, yeah. Well, briefly.

02:33:46.240 --> 02:33:50.420
OK. Yes. Well, I've been doing it for the past eight to 10 years. I don't know how long it is.

02:33:50.800 --> 02:33:57.240
All I know is this is the password to the next level for Bandit 1.

02:33:57.240 --> 02:34:20.280
And the key here is, if you know how SSH works, the command, the username, the URL, the port, and then, of course, the password, FTP works very much the same.

02:34:21.940 --> 02:34:22.560
That's it.

02:34:23.680 --> 02:34:26.060
You can use the FTP command.

02:34:26.160 --> 02:34:26.460
Let me see.

02:34:26.660 --> 02:34:29.260
I don't remember the last time I used the FTP command on here.

02:34:29.260 --> 02:34:38.680
you can use that ftp command into a particular device or server and then now you can transfer

02:34:38.680 --> 02:34:47.320
files that's what we're going to do tomorrow there are all of these different tools

02:34:47.320 --> 02:34:53.280
and there's this is just one of like two million different ways to get inside of a machine

02:34:53.280 --> 02:35:05.980
yes there is a whole the next machine may not be the same it may it may be totally different

02:35:05.980 --> 02:35:19.760
we have these things to learn and let me show you this because i'm i just

02:35:19.760 --> 02:35:39.300
here are my steps on how to install virtualbox and ultimately how to install cali linux

02:35:39.300 --> 02:35:46.830
if you have it in writing you're a rock star if you don't have it in writing yet

02:35:46.830 --> 02:35:59.270
we need to make you a rock star you understand what i'm saying so i need another apa report on

02:35:59.270 --> 02:36:06.670
how to install the kali os that i did all summer so i can write it how about how about this but

02:36:06.670 --> 02:36:14.890
it's just like whatever right here's the thing see this right here and uh-oh here it is installing

02:36:14.890 --> 02:36:19.910
and configuring kali linux i just need to make sure you know how to do it you tell me you know

02:36:19.910 --> 02:36:28.150
do it you got thumbs up i can show you my vm no no no no i know how to do it can you install

02:36:29.190 --> 02:36:34.230
i did the parrot too carrot cali parrot do you have windows do you have ubuntu

02:36:36.870 --> 02:36:48.230
and i have fedora i have deleted from uh i had microsoft server 19 11 like we did all the servers

02:36:48.230 --> 02:36:59.750
and the windows but it all oh it's just it's just okay so good yeah you have purposely delete them

02:36:59.750 --> 02:37:05.110
it's good because they take up a lot of space but you have um network engineering skill

02:37:05.110 --> 02:37:14.130
so that's what virtualization is security engineering so um cali linux files and permissions

02:37:14.130 --> 02:37:21.350
right let me how does that happen close okay i was trying to figure out how that happened hold

02:37:21.350 --> 02:37:31.260
on one second do that again share three share customizing workspaces and panels

02:37:31.260 --> 02:37:42.140
on your um so you have one workspace here here's a second a third and a fourth workspace

02:37:42.140 --> 02:37:48.980
but we're in workspace one tracking i just want to make sure you knew it if you knew it that's

02:37:48.980 --> 02:37:56.580
fantastic there are also the root terminal emulator here powershell terminal you can

02:37:56.580 --> 02:38:06.610
also get to root by typing in sudo switch user right and it takes you to root but you don't

02:38:06.610 --> 02:38:16.000
have to type sudo all the time you type exit to get out of it the um where's that thing

02:38:16.000 --> 02:38:19.380
Come back here

02:38:19.380 --> 02:38:21.380
Creating directories and files

02:38:21.880 --> 02:38:25.260
This necessary when you're doing Linux pin testing

02:38:25.880 --> 02:38:27.880
You may have to see clear

02:38:28.180 --> 02:38:35.200
You may have to create a file. There are a variety of ways you could use the echo command the fastest ones to use touch and say

02:38:36.400 --> 02:38:39.100
Then in our text, right? I do a list

02:38:39.760 --> 02:38:41.760
Dana text is right there

02:38:41.980 --> 02:38:44.820
What I want to do from there. Maybe I want to put something in it

02:38:44.820 --> 02:38:57.660
um daniela text and she rocks right control d some dog ls yeah this is about the extent of where

02:38:57.660 --> 02:39:06.100
we got to in lab is creating text and files so yes i understand fantastic so we create these

02:39:06.100 --> 02:39:11.780
things so we can create reverse shells to send to people so that we can penetration test into

02:39:11.780 --> 02:39:17.300
their networks we create a bunch of different things to steal things to create back doors

02:39:17.940 --> 02:39:23.940
um these are the things that um we need to do finding local files and directories

02:39:24.500 --> 02:39:31.620
okay so we do a list we see what's there but if i do a list tag a for all hidden files

02:39:32.420 --> 02:39:37.620
it's going to show these directories here that's hidden if i do the the list portion

02:39:37.620 --> 02:39:46.720
it'll write it out as such so if you ever want to create something to be hidden touch dot dana

02:39:46.720 --> 02:39:57.380
dot txt enter ls and it doesn't show up does the dot dana dot text show up no if i type ls tag al

02:39:57.380 --> 02:40:08.380
then she shows up so when we get into a network we want to use this a this um all in the long

02:40:08.380 --> 02:40:15.330
list so we can see if there's anything hidden. If you want to hide something from somebody,

02:40:15.450 --> 02:40:24.720
that's just one way to do it. Is that cool? Yes. Commands in the man page, which is short for

02:40:24.720 --> 02:40:34.980
manual. So whenever you find yourself unsure, just stressed out, man, the command. Man rig.

02:40:35.060 --> 02:40:40.120
How does rig work? Oh, that's the random identity generator. Holy smokes. I didn't even know there

02:40:40.120 --> 02:40:46.940
was such a thing you know so let me see rig enter brianna burnett and that's where she lives probably

02:40:46.940 --> 02:40:56.760
not a real person another rig ida garcia right another rig reina blanchard some pen testers use

02:40:56.760 --> 02:41:02.520
these things or they probably have their own schema so that they can keep up with who they are

02:41:02.520 --> 02:41:10.500
creating bad authors for or bad um they're creating say backdoor uh usernames so they

02:41:10.500 --> 02:41:16.800
can get into a system so whose names are these how is it i mean how is it generating names i mean

02:41:16.800 --> 02:41:23.900
it's the rig but what's the directory that's the program they created this random total random

02:41:23.900 --> 02:41:32.040
that's why that's why we had to that's why we installed it sudo apt install rig remember when

02:41:32.040 --> 02:41:38.920
did that yes but why what do we need a random directory for i i just chose a random um

02:41:40.840 --> 02:41:47.880
i just chose a random um command let's just show what you can pull up just to show what you can

02:41:47.880 --> 02:41:54.280
install what you can install i understand but look at this though because what your question is

02:41:54.280 --> 02:42:02.680
excellent look at this let me move this uh let me i think it's here this is the beauty of research

02:42:02.680 --> 02:42:13.380
being the cornerstone for everything we do cyber right what is the justification or what was the

02:42:13.380 --> 02:42:22.820
question you asked yeah i said why would you just install random uh well why would you install a

02:42:22.820 --> 02:42:31.620
random directory but it was i'll go with this one yeah why would you want to generate random names

02:42:33.060 --> 02:42:41.540
random identities and it's just to randomly penetrate somebody do you see the output

02:42:41.540 --> 02:42:47.940
a pincessor might install it for social yeah absolutely that's all it is it's not like

02:42:47.940 --> 02:42:56.500
okay a mandatory thing it's just a random fake identity i know and if you just send it off

02:42:56.500 --> 02:43:01.620
like in a fishing campaign or something you ain't got to worry about it as long as you have your

02:43:01.620 --> 02:43:06.900
notes someplace over here look at that random social security number and everything that's

02:43:06.900 --> 02:43:24.810
really crazy you understand yes now from here let me grab this and bring it over like this okay

02:43:25.370 --> 02:43:34.070
Linux files from permissions and hidden files right of course where we just were I did the list

02:43:34.070 --> 02:43:47.640
tag al these are the file permission do you know what these mean I read write read write and change

02:43:47.640 --> 02:43:56.280
what do you mean or who has permissions what is it it's saying who has permissions the directory

02:43:56.280 --> 02:44:02.180
okay so this is the directory this is read write execute for the user

02:44:02.180 --> 02:44:13.240
this is read no write but execution for the group and this is like anybody that happens to get on a

02:44:13.240 --> 02:44:19.000
network including hackers they'll have read capability no write capability and executable

02:44:19.000 --> 02:44:26.780
capability and all of this is for the root directory so do you know how to change the

02:44:26.780 --> 02:44:36.720
permissions for a file. Something that pen testers need to do. So I'm going to go change mod plus x

02:44:36.720 --> 02:44:47.420
dot dha dot text. See that? Hit the up arrow twice, press enter. And I just made this an

02:44:47.420 --> 02:44:55.160
executable for anybody that happens to touch this file because I did the plus x to make it an

02:44:55.160 --> 02:44:57.320
executable. All

02:44:57.320 --> 02:44:59.720
all

02:44:59.720 --> 02:45:02.480
the user, first three,

02:45:03.940 --> 02:45:05.280
the group,

02:45:05.280 --> 02:45:07.280
and even anyone else that happens to get on the

02:45:07.280 --> 02:45:09.380
network. Did you see how I did that?

02:45:11.640 --> 02:45:13.200
But I also don't want that.

02:45:13.260 --> 02:45:14.640
So I'm going to remove that thing.

02:45:21.140 --> 02:45:21.980
Ah, it's gone.

02:45:22.900 --> 02:45:24.840
The last thing we want is to

02:45:24.840 --> 02:45:26.820
have all these executable stuff on

02:45:26.820 --> 02:45:28.660
our network so Pentepsis can come in here and

02:45:28.660 --> 02:45:30.220
manipulate it and do what they want to do.

02:45:32.200 --> 02:45:32.620
You understand?

02:45:32.620 --> 02:45:42.360
yes all right then we have managing and killing linux processes check this out

02:45:42.360 --> 02:45:59.790
this is what's so fun about chat gpt show me real examples of how to bang manage and kill

02:45:59.790 --> 02:46:12.230
linux processes got it ps aux shows all running pro so we go right back here

02:46:12.230 --> 02:46:22.900
when all the process is running it shows what's root was cali as a pen tester you may have to

02:46:22.900 --> 02:46:29.600
shut down a process so you can execute your pen test this is how you search for a specific process

02:46:29.600 --> 02:46:38.800
copy i want to search for apache 2 i come in here and i paste it press enter and there it is

02:46:38.800 --> 02:46:45.500
and if i wanted to shut down that process then i could right understand the comments

02:46:45.500 --> 02:46:55.820
who owns the process a user pid the process id cd cpu usage memory the command used to start it

02:46:55.820 --> 02:47:05.120
you can list the hierarchical trees this process is hierarchically excuse me you can use the top

02:47:05.120 --> 02:47:17.020
or the htop command for real-time monitoring right so we come and see uh here top boom right

02:47:17.020 --> 02:47:21.440
now we're actually monitoring everything going on in the network see how it's flipping around

02:47:21.440 --> 02:47:29.180
there are 170 in total one running look at all the stuff that's sleeping

02:47:29.180 --> 02:47:42.200
nothing stopped no zombies here's the cpu usage the memory and the swap control c to stop that

02:47:42.200 --> 02:47:47.300
and there's htop which you have to install which i already had installed

02:47:47.300 --> 02:47:54.380
what's the difference it's colorful if you need to stop a process

02:47:54.380 --> 02:48:06.330
how do i install h top right here pseudo apt install h top or just type h top and it's going

02:48:06.330 --> 02:48:12.130
to ask you to install it do you see how i'm using google search or research or chat gpt to answer

02:48:12.130 --> 02:48:19.210
our questions to give you confidence because one day you won't be talking to me right right i want

02:48:19.210 --> 02:48:24.990
you to be able to go you know what i did learn some things because i did them how do you find

02:48:24.990 --> 02:48:33.480
a process and kill it so you find it and this is how you kill it you kill that process id number

02:48:35.240 --> 02:48:41.000
now be careful when you do that you may expose yourself you don't want to do that in your actual

02:48:41.000 --> 02:48:48.440
system here's how you force kill a stubborn process with attack nine command sig kill

02:48:50.040 --> 02:48:55.680
you see how this gives you all the information for you to try from there

02:48:57.680 --> 02:49:08.160
where is it it is here okay ctrl c to stop that ctrl c is to go to before q

02:49:10.280 --> 02:49:21.070
okay just so you know now from there where is it where'd it go here it is

02:49:22.990 --> 02:49:30.190
we just went through all of this we either did it or we did some now it's not everything

02:49:30.190 --> 02:49:36.790
can you remind me of what question you typed in to chat when you pulled up all those commands

02:49:36.790 --> 02:49:45.670
for which one the last one you just did for um psa ux here we go command what was the question

02:49:45.670 --> 02:49:52.210
it was exactly that question okay that's not it where is it

02:49:52.210 --> 02:50:13.220
it's um all right one of these things is a chat box oh here it is let's say so when i'm

02:50:13.220 --> 02:50:21.940
pen testing in real life show me real examples how to manage and kill process that's golden

02:50:21.940 --> 02:50:38.880
fantastic we got some gold going from here um we just did h top let's see

02:50:41.540 --> 02:50:43.000
I just typed in ATOP.

02:50:43.220 --> 02:50:44.500
I don't have it on my computer.

02:50:45.120 --> 02:50:46.420
Look at the question it's asking me.

02:50:46.540 --> 02:50:47.540
Do I want to install it?

02:50:47.620 --> 02:50:48.560
I'm going to say yes, okay?

02:50:49.180 --> 02:50:51.950
It's doing something.

02:50:54.070 --> 02:50:55.070
That's so easy.

02:50:55.530 --> 02:50:56.090
Doing something.

02:50:56.230 --> 02:50:56.850
Isn't that wonderful?

02:50:58.070 --> 02:51:05.940
And so, I mean, how does Callie know to pick the one with no bugs, no malware,

02:51:05.940 --> 02:51:11.500
and the most upgraded version of whatever software you're asking it to download?

02:51:12.040 --> 02:51:15.260
Because, you know, if you go to Google and try to pick one, good luck.

02:51:15.540 --> 02:51:24.360
yeah um how does cali know cali knows because it's all all that all uh it goes through the

02:51:24.360 --> 02:51:34.820
linux foundation before they push it out to the public thank you welcome okay cool you know they

02:51:34.820 --> 02:51:40.080
don't just randomly uh just let anything on there control you would think that but i just wondered

02:51:40.080 --> 02:51:50.580
what the process was oh wow look at the atop cool right pid sys cpu wow there's a whole lot of detail

02:51:50.580 --> 02:51:55.840
in here for all of us to be able to read and this thing is just going we see what's root what's cali

02:51:55.840 --> 02:52:12.270
right and if you ever get stuck you can always ask chat uh where is it how do i read um well

02:52:12.270 --> 02:52:24.080
let me see about what's the difference between a top and h top right oh a top h top

02:52:25.280 --> 02:52:38.400
and top wow he says try b top roger said try b top oh okay there you go i will try that hold on

02:52:38.400 --> 02:52:43.440
overview comparison and it's giving you everything you need to hold let me get the b top he's trying

02:52:43.440 --> 02:52:51.360
to give me what we call heat right which is something new b talk talk talk yes enter enter

02:52:53.520 --> 02:52:58.240
okay it's coming up we're about to get btop not sure what btop is but i'm gonna know what to

02:52:58.240 --> 02:53:04.720
happen today then i go to geeks for geeks and i learn it oh no service need to be restarted okay

02:53:04.720 --> 02:53:11.360
you talk oh we got a graphical look that's fantastic look at roger see that right there

02:53:11.360 --> 02:53:21.980
wow docker oh this is nice i mean like like real nice pro c look at this right here man btop

02:53:22.940 --> 02:53:28.700
let me see resource monitor that shows usage and stats for processor memory disk

02:53:31.020 --> 02:53:39.980
see how that works i'm gonna cue that tldr btop let me see if they have an entry for it it does

02:53:39.980 --> 02:53:49.980
tty mode um using 16 colors and tty friendly graphic symbols started oh man that's nice

02:53:49.980 --> 02:54:01.790
we love colors our eyes gravitate to them really well so now check this out um and it's all broken

02:54:01.790 --> 02:54:10.290
down for you which is nice let's come back over here oh this right here searching lines and head

02:54:10.290 --> 02:54:20.770
tells wc history persistence do you know how to do any of these things really not whoo okay

02:54:21.570 --> 02:54:40.550
one two three ctrl c right show me show me show me examples of these there you go head dash in the

02:54:40.550 --> 02:54:47.110
number of 10 etsy password it's going to show you the first example what i'm sorry what examples did

02:54:47.110 --> 02:54:55.350
we pull up show me example of these but what were these see it hadn't i know i have to catch that

02:54:55.350 --> 02:55:03.810
really quick searching lines head and tails word count history so this is going to show you the

02:55:03.810 --> 02:55:10.450
first 10 lines of the etsy password and you know what's an etsy password don't you yeah um

02:55:10.450 --> 02:55:19.880
um yeah uh we've used that but okay look look look look just showing you i want you to be

02:55:19.880 --> 02:55:26.840
confident and know how to find anything you need text file where each line represents a user account

02:55:28.200 --> 02:55:34.040
go for password but it no longer stores actual password it just has the password hashes

02:55:36.840 --> 02:55:43.220
if you didn't know that hopefully now you know that then when i come back up here

02:55:43.220 --> 02:55:53.940
here's the head first 10 lines here's the tail last lines however number you decide of a file

02:55:53.940 --> 02:56:00.020
of a direct whatever file really use case tell this the authorization law or off logs

02:56:00.740 --> 02:56:11.000
and var logs word count you do this it'll give you an actual count of how many uh lines words

02:56:11.000 --> 02:56:18.360
and bytes on this file you already did history we did that right when we know things we're like oh

02:56:18.360 --> 02:56:25.880
yeah i know that um but trust me when i say um these things come in handy with almost

02:56:25.880 --> 02:56:41.480
any and everything that you'll do in cyber in general you gotta learn them let's see here

02:56:41.480 --> 02:56:49.640
before i finish out these some of this information we already did we discussed didn't we rules of

02:56:49.640 --> 02:56:55.880
engagement standards we didn't discuss dns and route analysis but that's quick

02:56:57.240 --> 02:57:05.160
we did network import scanning we didn't do smb and osin analysis yet vulnerability scanning

02:57:05.160 --> 02:57:09.400
web application vulnerability scan i we have way too many things to do

02:57:11.160 --> 02:57:16.760
the same thing with the rest of these different here we did like a few of them we did it with in

02:57:16.760 --> 02:57:25.080
map we didn't do nse or nick those scans yet but it's coming tomorrow i showed you firewall and ids

02:57:25.080 --> 02:57:32.120
evasion but we didn't do it it was on that in map cheat sheet do you remember that yes okay and

02:57:32.120 --> 02:57:34.440
And then exploitation.

02:57:35.580 --> 02:57:42.480
And we didn't do SQL injection or blind SQL injection or outdated web application, the server takeout.

02:57:42.560 --> 02:57:43.780
But let me tell you, this is crazy.

02:57:44.680 --> 02:57:47.060
We did discuss penetration testing reports.

02:57:47.800 --> 02:57:48.720
We can do more.

02:57:49.940 --> 02:57:52.540
Engagement details, that's more.

02:57:53.920 --> 02:57:58.460
I'm trying to show you that I'm trying to adhere to what I was requested to do.

02:57:58.460 --> 02:58:03.580
and i want to make sure that we know how to do all these different things

02:58:03.580 --> 02:58:10.840
oh command line web downloader oh my god these are so many really cool things that you can do so

02:58:10.840 --> 02:58:17.560
be scripting and bash have you ever written a bash script yet i might have okay we'll do some

02:58:17.560 --> 02:58:24.700
tomorrow it'll be a whole lot of fun which one of these any one of them that you do you want to

02:58:24.700 --> 02:58:26.660
learn a little bit more about right now real quick.

02:58:27.700 --> 02:58:28.420
Metisploit.

02:58:29.300 --> 02:58:30.680
Okay, well, then you already got

02:58:30.680 --> 02:58:31.100
that.

02:58:32.900 --> 02:58:34.560
I want to know how you

02:58:34.560 --> 02:58:36.600
penetrate the network on a phone.

02:58:38.740 --> 02:58:40.600
Interestingly, let me show you

02:58:40.600 --> 02:58:40.980
this.

02:58:47.400 --> 02:58:49.360
There's some legalities with that, by the way.

02:58:50.300 --> 02:58:50.780
What's going on?

02:58:55.020 --> 02:59:08.180
Do you mind

02:59:08.180 --> 02:59:10.360
if we take a break, like 15 minutes?

02:59:12.040 --> 02:59:12.320
I got

02:59:12.320 --> 02:59:12.700
emergency.

02:59:14.380 --> 02:59:21.000
um five o'clock was the time i was told unless you want to finish a little earlier well i mean i'll

02:59:21.000 --> 02:59:26.840
i'll wait 15 minutes and we'll finish at five that's fine or what 5 15 or whatever just let me

02:59:26.840 --> 03:00:42.630
know okay sure i'll be right back okay yes how are you but you can call me wes okay you know it's

03:00:42.630 --> 03:00:48.630
funny i'm actually teaching a pen test class and i'm on camera so i was just doing it uh but all

03:00:48.630 --> 03:00:55.080
All right, I'll play nice.

03:00:55.080 --> 03:00:56.200
Okay, that's fine.

03:00:57.200 --> 03:00:58.500
Okay, I got you.

03:00:58.500 --> 03:01:02.560
I hear you all are scrambling.

03:01:02.560 --> 03:01:08.170
Yeah, no pressure.

03:01:08.170 --> 03:02:25.480
Okay, that sounds like job security.

03:02:26.680 --> 03:02:29.620
Sounds like job security, that's a lot of work to do.

03:02:30.540 --> 03:02:34.940
And yes, like me, it's like a CETA.

03:02:34.940 --> 03:02:36.760
Sounds like us.

03:02:36.760 --> 03:03:03.420
Okay. My name is Dr. Wesley Phillips. I am a cybersecurity professional as well for quite a few years. I served in the U.S. Marine Corps in the communications field. I did not want to go into cyber. I went into law enforcement, and my supervisor sent me to NSA after about four years of doing physical security and criminal investigations.

03:03:04.300 --> 03:03:09.900
and um when i was at nsa i took the technical surveillance countermeasure program

03:03:09.900 --> 03:03:17.420
and i became an executive security agent who know who knew how to do stuff on the computer

03:03:17.980 --> 03:03:24.380
you know we didn't even call anything cyber back then aging myself um of uh if you if

03:03:24.380 --> 03:03:29.660
were to sum it up i guess you could say back then i was like an advanced threat hunter and

03:03:29.660 --> 03:03:37.420
a sock analyst and i was looking for terrorists and bad guys uh that were trying to attack and kill

03:03:37.420 --> 03:03:44.060
or harm the or steal information from the president of the united states and then fast

03:03:44.060 --> 03:03:50.220
forward from there when i retired from law enforcement i went into education and um i

03:03:50.220 --> 03:03:57.020
started teaching it and cyber courses or information system security i think that's what it was called

03:03:57.020 --> 03:04:02.380
back then and then i ended up taking over the program and incorporating certifications and

03:04:02.380 --> 03:04:10.060
hands-on projects within the schools and then um i don't know after about seven years of that i

03:04:10.060 --> 03:04:18.540
became a government contractor and i have held a variety of senior titles i was a stock manager at

03:04:18.540 --> 03:04:27.660
dcsa uh i was a cyber program manager of a postal service i was the uh chief security or information

03:04:27.660 --> 03:04:35.340
security officer with the big dissa managing the insider threat program i've managed large teams i

03:04:35.340 --> 03:04:42.060
think 62 was the largest i've had outside of law enforcement where i managed over 200 people

03:04:42.060 --> 03:04:53.660
overseas uh on various uh vip um missions i'll say but um pen testers sock analysts uh forensics

03:04:53.660 --> 03:05:01.060
people etc managed quite a few teams i lived through a few breaches that's that thing uh

03:05:01.060 --> 03:05:10.170
solar winds was was no joke when it happened and um yeah yeah that's great yeah and um working

03:05:10.170 --> 03:05:21.370
with mandiant and trying to clean it up and um just uh uh log for for log for j um all i can say

03:05:21.370 --> 03:05:27.050
is uh you know we we all do what we can when we have to deal with all these different things but

03:05:27.050 --> 03:05:36.570
i'm also a trainer i um um teach college but i was also teaching people how to do um pen testing and

03:05:36.570 --> 03:05:45.050
forensics and incident response how to write policy grc uh even dibble dabble in ai lately

03:05:46.730 --> 03:05:52.890
just trying to make sure that project management i'm trying to teach people how to do this stuff for

03:05:52.890 --> 03:05:58.570
real versus getting certified just just because you pass the test doesn't mean you actually know

03:05:58.570 --> 03:06:05.370
how to do the work um so i guess that's a snapshot of me professionally i have other things i could

03:06:05.370 --> 03:06:09.250
to say, but if you have any questions, feel free to ask.

03:06:12.160 --> 03:06:12.320
Try.

03:06:13.140 --> 03:06:13.580
Try.

03:06:16.960 --> 03:06:18.180
That is a fact.

03:06:19.140 --> 03:06:26.280
Well, having done that in the past, what we did that was relatively successful, and I say

03:06:26.280 --> 03:06:31.500
that with a grain of salt, because there's some people sometimes that just don't want

03:06:31.500 --> 03:06:33.280
to do, they want to push back.

03:06:34.340 --> 03:06:36.680
We get together in a room.

03:06:36.680 --> 03:06:44.200
we document the highlights, what's the goal, and then we brainstorm, we put together a plan of

03:06:44.200 --> 03:06:50.900
action, and then we do our best to get our counterparts to execute because it's all one

03:06:50.900 --> 03:06:56.820
mission, one fight. Now, that's my Marine Corps model, my law enforcement model. That's how we did

03:06:56.820 --> 03:07:03.360
it. In the government organizations that I've worked for, not everybody wants to do the latest

03:07:03.360 --> 03:07:09.480
policies. And some people are even willing to retire even before it happens on their watch.

03:07:09.980 --> 03:07:16.120
But in my experience, we get together, we got to get together in a room. And I actually don't

03:07:16.120 --> 03:07:21.820
really like to talk a lot because then everybody has a whole lot to say, but I write everything

03:07:21.820 --> 03:07:28.000
down. And I actually prefer to write it out in front of you. And we will brainstorm and figure

03:07:28.000 --> 03:07:33.760
are some ways forward before we decide as a team how to execute. Because if I don't have

03:07:33.760 --> 03:07:40.240
some coverage from on top, there's no telling what's going to happen from below. Oh yeah.

03:07:40.240 --> 03:07:51.460
I wrote a white paper and an email. I brought Splunk Soar to the insider threat community in

03:07:51.460 --> 03:08:01.320
DISA. They had a, they had, I got to watch what I say. But anyway, they had, they were using Splunk

03:08:01.320 --> 03:08:07.880
Enterprise. They were not using Splunk Enterprise security. And based on the work that we needed to

03:08:07.880 --> 03:08:15.940
do and the, I guess the rest, the threats and the risk that we needed to manage, I was able to

03:08:15.940 --> 03:08:22.980
speak to a few friends of mine at splunk um they were talking about buying splunk enterprise security

03:08:22.980 --> 03:08:28.900
and i brought them over and i convinced them to write uh to get sore and um the

03:08:30.980 --> 03:08:38.900
she was the gs15 but she was in the ses position uh my write-up made sense and um she actually did

03:08:38.900 --> 03:08:44.500
it and i don't think a lot of people really wanted to do that but in the end of the day that's what

03:08:44.500 --> 03:08:50.260
what we did. And everybody on the team was very happy. And I felt like I did something for once

03:08:50.260 --> 03:08:55.220
in my life. I have. I'm just trying to think. Yeah. So even way back in the Secret Service days,

03:08:55.640 --> 03:09:03.520
we had some old crazy antiquated equipment, legacy equipment, end of life. I'm talking about,

03:09:04.180 --> 03:09:09.580
you know, what is it? Five years? It ended 10 years prior. And then we were still using it.

03:09:09.580 --> 03:09:30.440
And we, I spoke to a lot of vendors. We spoke with the teams. We got together. We got the money, got the budget. I ended up spearheading the project myself. We installed a lot of different tools to protect the president of the United States.

03:09:30.440 --> 03:09:37.620
um i i can't be specific on what those tools were but they were information um technology related

03:09:37.620 --> 03:09:45.700
security related 100 and um we tested stuff in the lab you know we didn't have pre-prod back then

03:09:45.700 --> 03:09:53.560
um in fact in the secret service they was like just install it no we had to test it um um we

03:09:53.560 --> 03:10:00.420
tested it uh as much as we could we we probably had to test like uh 10 of the agency because

03:10:00.420 --> 03:10:04.540
before we could actually deploy it organization-wide.

03:10:04.540 --> 03:10:05.640
Thankfully, it worked out.

03:10:05.640 --> 03:10:08.740
We didn't have too many problems that we couldn't handle.

03:10:08.740 --> 03:10:10.800
And same thing, fast forward,

03:10:12.340 --> 03:10:15.780
changing over from a legacy system to a newer system,

03:10:15.780 --> 03:10:18.380
it just requires a lot of cooperation.

03:10:18.380 --> 03:10:21.100
You're gonna have different departments who have,

03:10:21.100 --> 03:10:23.180
well, we can't do that for this reason.

03:10:23.180 --> 03:10:25.220
And we can't do that for this reason.

03:10:25.220 --> 03:10:26.320
We have to document it all.

03:10:26.320 --> 03:10:28.900
We have to get approvals, get thumbs up,

03:10:28.900 --> 03:10:33.460
then we have to test it and uh in my experience a lot of people in the government are not exactly

03:10:33.460 --> 03:10:41.140
patient with that but um i want to say i probably rolled over at least five or six systems in my

03:10:41.140 --> 03:10:59.230
time okay so yes and so i had a lead ism he was an ato or grc guru um he made my life easier i was

03:10:59.230 --> 03:11:08.910
so happy that to hire him and then um we we had some resistance from the government because

03:11:10.350 --> 03:11:16.350
several of those systems should not have been in place they were end of life for a while and i

03:11:16.350 --> 03:11:24.510
hate to say it there were several systems that were not updated or patched um for embarrassing

03:11:24.510 --> 03:11:33.150
years where i'm speaking to the ao i was even speaking to oig about it and um in the end of

03:11:33.150 --> 03:11:39.230
the day if the government wanted to accept the risk for a particular system because it was

03:11:39.230 --> 03:11:49.070
political they just did so the positive stories i have is maybe four systems in these particular

03:11:49.070 --> 03:11:57.450
agencies that I'm thinking of that we were able to obtain ATO for. All I can say, it was a really

03:11:57.450 --> 03:12:09.210
long process and a unique culture and environment in the places where I worked because no one really

03:12:09.210 --> 03:12:17.630
wanted they didn't i don't think a lot of people understood risk management and um how it really

03:12:17.630 --> 03:12:25.650
works but um my team and i we were working in emas every day um i ended up training even the

03:12:25.650 --> 03:12:35.130
sock analysts to do grc because uh when i came on i um there was no one there to do gr uh iso

03:12:35.130 --> 03:12:43.370
work and then um i think within about six months or so i had four people and in that meantime

03:12:43.370 --> 03:12:48.010
everyone that was there that claimed to be cyber we all had to sit down and knuckle up and just um

03:12:48.730 --> 03:12:55.450
and go through emas and and go through the controls and uh work with the different teams

03:12:55.450 --> 03:13:03.610
and accomplish tasks to get systems uh keep systems or get their ato i've never lost an

03:13:03.610 --> 03:13:15.210
authority to operate but uh because of falling in the role of acting sizzle i almost did but i never

03:13:15.210 --> 03:13:25.200
did sorry for that long answer that sounds complicated gotcha yes well um i i consider

03:13:25.200 --> 03:13:34.720
myself to be a people person in general i usually get along with most people that i meet um uh for me

03:13:34.960 --> 03:13:41.740
is business first before we decide to earn a, you know, some sort of maybe a friendship or

03:13:41.740 --> 03:13:49.320
a true partnership. I'm trying to become his or her partner by documenting what is most important

03:13:49.320 --> 03:13:59.200
to you. What can I do? What is it that I need to do to make you happy? And then I document all that

03:13:59.200 --> 03:14:05.120
in front of them and then I just get to work. And then hopefully that respect will be earned

03:14:05.120 --> 03:14:11.640
even though I have years of experience. Years of experience does not automatically mean that I'm

03:14:11.640 --> 03:14:20.540
a right, a good fit for this particular office. But in my experience, if I can document and

03:14:20.540 --> 03:14:26.400
understand exactly what this individual needs, especially my supervisor or supervisors and my

03:14:26.400 --> 03:14:34.240
peers then we can go a long way especially when i start delivering yes sir okay so um

03:14:35.120 --> 03:14:38.240
let's see some places did not have tools believe it or not and i had to

03:14:39.920 --> 03:14:45.200
come to the old school uh excel spreadsheets and stuff like that but i've used

03:14:45.200 --> 03:14:53.280
microsoft project uh we use jira to display metrics and confluence um um

03:14:53.280 --> 03:15:02.690
um i um even traditional powerpoint because i i document everything i mean like i seriously

03:15:02.690 --> 03:15:08.830
document everything because i know i've seen too many people in my career get amnesia

03:15:08.830 --> 03:15:15.730
and um i'm big on the metrics and documenting what's happening i even create my own little

03:15:15.730 --> 03:15:24.230
metrics for my teams uh and i try to make sure that it's going to feed into the overall metrics

03:15:24.230 --> 03:15:33.230
for the supervisors so that they can obtain the money they need or get the services or

03:15:33.230 --> 03:15:39.830
whatever it is that they require. So it's just metrics because I'm a project management

03:15:39.830 --> 03:15:50.030
PMP fellow, but I just need to understand what story do you want to tell?

03:15:50.030 --> 03:15:57.510
uh what are the most important things you need and i'll ask questions do you have this do you

03:15:57.510 --> 03:16:02.650
have this and then i'll get with the team and put the charge on them i need to see something

03:16:02.650 --> 03:16:08.750
in writing solid that that can be presented when going forward because i hate looking like

03:16:08.750 --> 03:16:15.050
boo-boo the fool in front of managers and um and in front of all and um i used to brief the

03:16:15.050 --> 03:16:22.650
CISO, before I became one myself, every week. After two and a half years of working there,

03:16:23.650 --> 03:16:28.770
it felt really good for her to say, she said, Dr. Phillips, here's my personal number. Here's

03:16:28.770 --> 03:16:32.650
my personal email. Don't you give it out, but you've earned it. I don't give that stuff out.

03:16:33.190 --> 03:16:39.650
It was wonderful because she was a bear to me, but she made me better. Okay. A cybersecurity

03:16:39.650 --> 03:16:53.410
Security tactical plan? Yeah. Solar winds. So I was working with the Treasury and I can't

03:16:53.410 --> 03:17:02.530
say it was just me, but it was us. And we came up with a lot of plans that were not practiced.

03:17:02.530 --> 03:17:08.410
We talk about doing tabletop exercises, these government agencies, and all I have to say

03:17:08.410 --> 03:17:19.530
as we talk about it um when the that particular attack happened um we were coming up with some

03:17:19.530 --> 03:17:27.290
excellent ideas because the windows network was compromised the really cool thing about us was

03:17:27.290 --> 03:17:32.570
that we had a linux network that was totally separate from the windows network so that was a

03:17:32.570 --> 03:17:39.450
part of our intentional tactical plan you know if something were to breach and that worked but we

03:17:39.450 --> 03:17:46.170
also had other and i i'm i feel like i'm being vague because i can't really say what we did

03:17:46.170 --> 03:17:53.770
but we put together now i get this honest from u.s secret service that's all we did my entire career

03:17:53.770 --> 03:17:59.130
was if someone comes shooting from this way what are we going to do and what if they come from all

03:17:59.130 --> 03:18:04.410
sides what are we going to do um you know for the most part well i'll put it like this knocking off

03:18:04.410 --> 03:18:11.610
some wood my protectee always went back home and so did i and my friends but um in in the real world

03:18:11.610 --> 03:18:21.350
from a cyber securities perspective um some of these government agencies are different um we like

03:18:21.350 --> 03:18:27.350
uh like christopher said we we all think differently and and they don't really want to

03:18:27.350 --> 03:18:36.630
always listen but i am naturally a tactical guy um proactive i get it honest from secret service

03:18:36.630 --> 03:18:43.750
i am um a martial arts practitioner i get it honestly i have been in four shootings i did

03:18:43.750 --> 03:18:51.110
pretty good i got lucky but i also use my skills i have more fist fights you can shake a stick

03:18:51.110 --> 03:18:59.030
and i am not a violent person far from it um from cyber security drills i actually teach people how

03:18:59.030 --> 03:19:06.710
to build socks in their house trying to be proactive i have wazoo slunk um security onion

03:19:06.710 --> 03:19:12.790
in my house and when those knuckleheads in china and pakistan try to get into my house

03:19:12.790 --> 03:19:19.350
i could see them coming right and um i have no issues with i actually have chinese friends

03:19:19.350 --> 03:19:26.090
and Pakistani friends. But the bad guys, even the American bad guys, they get under my skin.

03:19:26.190 --> 03:19:33.050
And I'm big on being proactive. And that's all I want to document and do. Fantastic. Yes.

03:19:34.990 --> 03:19:43.350
I think I have. So this is a true to God, honest story is crazy. Have you all heard of Cyberary.it?

03:19:43.350 --> 03:19:50.930
I took a Cyberary.IT course with, I can't remember her name, but she was an awesome instructor.

03:19:51.370 --> 03:19:56.450
I wrote that on my resume. And when I applied to take the CISSP, they would not let me take

03:19:56.450 --> 03:20:01.550
the CISSP because they said, you probably have a job because you put that you have CISSP in your

03:20:01.550 --> 03:20:06.810
resume. And I said, no, where'd you get that from? I said, look at my resume. It says certificates.

03:20:06.810 --> 03:20:15.010
They gave me a certificate that says CISSP train. And I had a total other section that said

03:20:15.010 --> 03:20:22.270
certifications, CISM, et cetera. And ISC Square told me I can never sit for the CISSP.

03:20:24.210 --> 03:20:31.690
That's what I said. I have an SSCP, but what I also did was I've been crazy, right? I have

03:20:31.690 --> 03:20:37.550
all the other equivalents except for that because they will not let me take it.

03:20:37.550 --> 03:20:43.290
Can't make that up. And I tell that story to everyone. So I say, hey, if you finish a badge,

03:20:43.310 --> 03:20:52.790
I had a badge too. Don't even put it on your resume. It was crazy. So I'm told that you all

03:20:52.790 --> 03:21:00.730
need information by Monday. And I guess within the next two weeks or so, you'll probably hear

03:21:00.730 --> 03:21:11.410
something. I think the gentleman who called me gave me quite a bit of information. I think I have

03:21:11.410 --> 03:21:18.570
more detailed questions. When or if I am actually selected, I'll just come up with the questions of

03:21:18.570 --> 03:21:24.350
what exactly is it that you need? What can I do to give you what you want? How is the team? What's

03:21:24.350 --> 03:21:30.370
the culture like so i don't really have any overview questions right now um i'll just tell

03:21:30.370 --> 03:21:38.490
you this uh i work hard i play hard too but i work really hard um if you want uh someone to

03:21:38.490 --> 03:21:45.350
come in there and um get some results i feel like i'm your huckleberry i'll do what i can and then

03:21:45.350 --> 03:22:06.420
some so that's all that's my declaration if i'm selected i am tracking um i had been i was a cedar

03:22:07.380 --> 03:22:14.900
so it's a short story when i was hired i was hired as the cedar for the sizzle

03:22:14.900 --> 03:22:23.220
in dissa within three months he uh resigned his position and then i became the acting

03:22:23.220 --> 03:22:32.940
sizzle. Uh, I was a contractor and I was doing that job for two years and change. Um, I know

03:22:32.940 --> 03:22:41.880
more than I'm saying, but, um, uh, it felt really good to get so many people on my side and say,

03:22:41.880 --> 03:22:51.520
man, you are just doing the job. Um, they were, um, it was very unique. So, um, uh, I love the

03:22:51.520 --> 03:22:55.660
fact that even after he left, he called me and said, how are things going? I hear you're doing

03:22:55.660 --> 03:23:04.800
a great job. Yeah. I thank you very much because those are definitely big shoes to fill.

03:23:05.900 --> 03:23:13.840
There's no question. And I'm also grateful for Ms. Landro. She is the CISO at DCSA. I learned so

03:23:13.840 --> 03:23:18.680
much from her, the lady who I've earned her personal phone number and all that stuff.

03:23:18.680 --> 03:23:35.840
So anyway, I know you probably have some great applicants, but I feel like I'm a decent contender and I'm definitely looking forward to this opportunity and possibly even working with the teams and working with you, too.

03:23:36.100 --> 03:23:45.360
Y'all seem sharp already. Thank you. You, too. Now take care. Hey, Roger, you still there?

03:23:46.880 --> 03:23:49.260
Yeah, I'm still here. I am so sorry.

03:23:49.260 --> 03:23:53.600
Right. I actually had an emergency that happened, and I just finished taking care of it.

03:23:54.580 --> 03:23:55.060
Oh.

03:23:55.420 --> 03:23:57.560
I could see that she was looking not so happy.

03:23:58.820 --> 03:23:59.500
Oh, no.

03:24:00.040 --> 03:24:02.980
But what do you think about today?

03:24:03.240 --> 03:24:07.800
Well, it was – well, let's just stop the recording if it's recording.

03:24:08.300 --> 03:24:11.260
Okay. How do I do that? Just close it out?

03:24:11.260 --> 03:24:13.140
Go back to the training room.

03:24:13.260 --> 03:24:13.660
I'm here.

03:24:15.080 --> 03:24:18.840
And is the red button still pulsing or –

03:24:18.840 --> 03:24:20.080
in the bottom of the earth.

03:24:20.440 --> 03:24:20.700
It is.