David Bombal

David Bombal

By David BombalTechnology
Download on the App Store

David Bombal episodes

  • #401: Bug Bounty bootcamp // Get paid to hack websites like Uber, PayPal, TikTok and more
    How to get experience with no experience? Have a look at bug bounty programs. Vickie Li demos Insecure Direct Object References (IDOR) and tells us how to get into bug bounty. We also discuss why her book Bug Bounty Bootcamp is a fantastic book to buy if you want to get into bug bounty. Get real world experience today.
    // MENU //
    00:00 - In plain text!
    00:24 - Introducing//Vickie Li
    00:58 - Part 1//The Interview
    01:01 - Origin//Bug Bounty Bootcamp
    03:37 - What are Bug Bounty Programmes?
    05:26 - Part Time Bug Hunting?
    05:44 - Easy Way to Get Experience
    07:45 - Which Bug Bounty Programmes for Beginners?
    10:51 - Beginners//Don't Compete with Pros
    13:15 - Duplicates as Valid Experience
    14:23 - What You Need to Start
    14:59 - Linux//Do You Need It?
    15:55 - Automate!//Which Programming Language?
    18:03 - Beginner Friendly Vulnerabilities
    21:17 - Part 2//Exploiting IDOR Vulnerability Demo
    21:24 - What is IDOR?
    22:51 - PortSwigger IDOR Lab
    24:05 - Live Chat IDOR
    24:48 - View transcript
    25:12 - Burp Suite Intercept
    26:05 - What to Look For//IDs Aren't Always Obvious
    26:56 - Burp Suite//Looking Through Headers
    27:56 - Burp Suite//Repeater
    28:30 - Testing View Transcript Again
    29:18 - GET Request//Identifying Exploitable Endpoint
    30:26 - Modifying GET Request
    31:35 - Finding the right headers to modify
    33:47 - Why the first attempt didn't work
    34:09 - IRL//What You Would Do
    34:23 - Password in Live Chat Transcript
    35:40 - How to Prevent IDORs
    36:01 - IDORs//Worth Pursuing?
    39:57 - Bug Bounties//How to Start
    41:21 - Learn More!//Vickie's Blog
    41:38 - Follow Vickie's Twitter!
    41:52 - Thank You & Closing
    // Books //
    Bug Bounty Bootcamp: https://amzn.to/3K2YDeJ
    The Web Application Hacker's Handbook: https://amzn.to/3IZ2RTr
    Hacking API’s by Corey J Ball: https://amzn.to/3JOJG0E
    Alice and Bob learn application security by Tanya Janca: https://amzn.to/3oMyMij
    Automate the boring stuff with Python: https://amzn.to/3N2QuYu
    // Videos mentioned //
    Nahamsec: https://youtu.be/9vaEwycet90
    Corey Ball: https://youtu.be/CkVvB5woQRM
    Tanya Janca: https://youtu.be/nyhytT2tRN0
    Al Sweigart: https://youtu.be/7iBqoc-DzTQ
    // Vickie's social media //
    Twitter: https://twitter.com/vickieli7
    Website: https://vickieli.dev/
    YouTube: https://www.youtube.com/channel/UCjQH...
    Medium: https://vickieli.medium.com/
    // Connect with David //
    Discord: https://discord.com/invite/usKSyzb
    Twitter: https://www.twitter.com/davidbombal
    Instagram: https://www.instagram.com/davidbombal
    LinkedIn: https://www.linkedin.com/in/davidbombal
    Facebook: https://www.facebook.com/davidbombal.co
    TikTok: http://tiktok.com/@davidbombal
    YouTube: https://www.youtube.com/davidbombal
    // Platforms mentioned //
    HackerOne: https://www.hackerone.com/
    bugcrowd: https://www.bugcrowd.com/
    Intigriti: https://www.intigriti.com/
    Huntr: https://huntr.dev/
    // Connect with Nahamsec //
    Twitter: https://twitter.com/nahamsec
    YouTube: https://www.youtube.com/c/nahamsec
    Github: https://github.com/nahamsec/Resources...
    Discord: https://discord.com/invite/ysndAm8
    Instagram: https://www.instagram.com/nahamsec/
    LinkedIn: https://www.linkedin.com/in/nahamsec/
    Twitch: https://www.twitch.tv/nahamsec
    Website: https://nahamsec.com/
    // MY STUFF //
    Monitor: https://amzn.to/3yyF74Y
    More stuff: https://www.amazon.com/shop/davidbombal
    // SPONSORS //
    Interested in sponsoring my videos? Reach out to my team here: [email protected]
    Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel!
    Disclaimer: This video is for educational purposes only.
    #python #hack #xss
    43 min
  • #400: Free AppSec courses! #1 reason for hacks :(
    #1 reason for data breaches is insecure software. Software badly needs to be made more secure - lots of opportunities here to either hack applications or help application developers secure them. Learn application security (appsec) for free with shehackspurple.
    // MENU //
    00:00 - Let's start with a bang!
    00:28 - Introduction//Tanya Janca
    03:48 - What is CIA?
    07:05 - Why Purple & What Big News?
    11:17 - Free Secure Code Courses?
    13:00 - Where to contact Tanya
    13:37 - Number One Reason for Data Breaches
    18:42 - How Tanya Started Out
    25:19 - What is DevOps?
    34:26 - The Systems Development Life Cycle
    39:47 - Why Shock and Awe Doesn't Work
    45:24 - Secure Code As a Job?
    48:41 - Jobs and Free Training?
    50:38 - Get Involved with the Hacking Community!
    53:37 - log4j//What Happened?
    01:01:17 - Thank You & Final Thoughts
    // FREE COURSES //
    Website: https://community.wehackpurple.com/
    All Free courses: https://community.wehackpurple.com/al...
    Secure Coding: https://community.wehackpurple.com/co...
    API Security Mini Course: https://community.wehackpurple.com/co...
    Infrastructure as Code Mini-Course: https://community.wehackpurple.com/co...
    Azure Cloud Security: https://community.wehackpurple.com/co...
    Application Security Foundations Level 1: https://community.wehackpurple.com/co...
    Application Security Foundations Level 2: https://community.wehackpurple.com/co...
    Application Security Foundations Level 3: https://community.wehackpurple.com/co...
    Running DAST in a CI/CD, Successfully: https://community.wehackpurple.com/co...
    Scale Your Team Mini-Course: https://community.wehackpurple.com/co...
    // BOOKS //
    The Web Application Hacker’s Handbook - Ed by Dufydd Stuttard and Marcus Pinto: https://amzn.to/3vBzfHX
    Alice and Bob learn application security by Tanya Janca: https://amzn.to/3oMyMij
    // Tanya SOCIAL //
    YouTube: https://www.youtube.com/c/SheHacksPurple
    Twitter: https://twitter.com/shehackspurple
    LinkedIn: https://www.linkedin.com/in/tanya-janca/
    Blog: https://shehackspurple.ca/
    // David SOCIAL //
    Discord: https://discord.com/invite/usKSyzb
    Twitter: https://www.twitter.com/davidbombal
    Instagram: https://www.instagram.com/davidbombal
    LinkedIn: https://www.linkedin.com/in/davidbombal
    Facebook: https://www.facebook.com/davidbombal.co
    TikTok: http://tiktok.com/@davidbombal
    YouTube: https://www.youtube.com/davidbombal
    // MY STUFF //
    https://www.amazon.com/shop/davidbombal
    // SPONSORS //
    Interested in sponsoring my videos? Reach out to my team here: [email protected]
    app
    appsec
    owasp
    application security
    python
    javascript
    java
    c
    c++
    swift
    php
    golang
    go
    rust
    kotlin
    typescript
    dart
    software
    hack software
    application hacking
    secure apps
    Disclaimer: This video is for educational purposes only. I own all equipment used for this demonstration. No actual attack took place on any websites.
    Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel!
    #hack #app #appsec
    1 hr 4 min
  • #399: Free API Hacking course!
    I interview Corey Ball who wrote the book "Hacking APIs" and he tells us about his book and the free training he is making available. This is a cool announcement :)
    // MENU //
    00:00 - Why talk about pentesting at all?
    00:21 - Welcome//Corey
    00:48 - What is an API and Why Care?
    01:52 - Free API Hacking Course!
    02:11 - Overview//Course
    02:28 - Do I Need the Book to do the Course?
    02:39 - Pre-reqs for Course
    03:07 - Cert//When?
    03:22 - Hacking APIs//Origin Story
    05:34 - The Start//USPS Data Leak
    07:31 - OWASP Top 10 Explained
    07:49 - API1//Broken Object Level Authorization
    08:46 - Testing for BOLA
    09:59 - API2//Broken User Authentication
    10:35 - Leaked API Keys on GitHub?
    10:59 - API3//Excessive Data Exposure
    12:05 - API9//Improper Asset Management
    13:53 - The World is Running on APIs
    14:53 - Who is this Book For?
    16:19 - Set Up Hacking Lab
    17:47 - You Just Need a Laptop to Start Hacking!
    17:52 - Free API Hacking Tools
    20:14 - What is Kiterunner
    20:47 - Gobuster vs Kiterunner
    21:51 - Free Wordlists!
    22:05 - What is fuzzing and free fuzzing tool
    23:17 - More Tools?
    23:47 - How To Find APIs
    25:02 - Using nmap to find APIs?
    26:09 - Hacking APIs as your start in hacking
    28:09 - Difference//REST//GraphQL
    29:07 - Learn REST or GraphQL?
    31:07 - Take a University Course?
    31:44 - Hacking Certifications//Worth It?
    33:42 - Being Hacked//How Corey Started
    36:31 - Corey's OSCP Experience
    38:09 - Hacking APIs As An Alternative Path
    38:41 - Resources to Start With
    39:26 - Ten Years of Experience?
    39:52 - Huge Demand for Hacking APIs
    40:25 - The Course is Completely Free
    40:47- Breaking Barriers!
    41:37 - Thank You & Final Words
    // Free API hacking course //
    APIsec Certified Expert Course: https://university.apisec.ai/
    // Defcon Workshop notes //
    https://sway.office.com/HVrL2AXUlWGNDHqy
    // Books //
    Hacking API’s by Corey J Ball: https://amzn.to/3JOJG0E
    Bug Bounty Bootcamp Vickie Li: https://amzn.to/3SPCtBF
    // YouTube channels mentioned //
    InsiderPHD: https://www.youtube.com/c/InsiderPhD
    IppSec: https://www.youtube.com/c/ippsec/videos
    // Corey SOCIAL //
    LinkedIn: https://www.linkedin.com/in/coreyjball/
    Twitter: https://twitter.com/hAPI_hacker
    // David SOCIAL //
    Discord: https://discord.com/invite/usKSyzb
    Twitter: https://www.twitter.com/davidbombal
    Instagram: https://www.instagram.com/davidbombal
    LinkedIn: https://www.linkedin.com/in/davidbombal
    Facebook: https://www.facebook.com/davidbombal.co
    TikTok: http://tiktok.com/@davidbombal
    YouTube: https://www.youtube.com/davidbombal
    // MY STUFF //
    https://www.amazon.com/shop/davidbombal
    // SPONSORS //
    Interested in sponsoring my videos? Reach out to my team here: [email protected]
    hacking api
    api
    api hacking
    api hacking tutorial
    api hacking bug bounty
    api hacking 101
    api hacking full course
    api hacking tools
    api hacking alissa knight
    api hacking with postman
    api hacking for beginners
    api hacker
    api hacking demo
    api hacking kali linux
    api hacking course
    api hacking insiderphd
    hacking an api
    hack api
    owasp api top 10
    bug bounty
    hacking apis no starch press
    hacking api no starch
    hacking apis pdf
    hacking api book
    hacking apis corey ball
    corey ball hacking apis
    reverse engineering
    private api
    apis for beginners
    rest api
    hacking api with postman
    reverse engineering for beginners
    hacking api key
    what is an api
    rest apis with postman for absolute beginners
    rest api explained
    #api #hack #hacking
    43 min
  • #398: Learn AI for Free! Computerphile explains hype vs reality and how to get started.
    AI just become Sentient? And will it take your job? Or is AI just a fantastic opportunity for you to get a better job? In this interview with Dr Michael Pound we discuss hype vs reality and get a quick start guide on how to learn AI.
    // MENU //
    00:00 - Coming Up
    00:45 - Intro
    01:10 - Michael Pound introduction
    02:49 - Will AI take our jobs?
    04:55 - What is LaMDA?
    08:38 - Can Python functions get lonely?
    11:26 - The definition of "sentience"
    11:59 - AI vs Machine Learning
    18:48 - Neural Networks
    19:49 - Malware example
    21:59 - Stochastic Gradient Descent
    22:30 - Supervised learning
    23:45 - Unsupervised learning
    26:03 - Reinforcement learning
    27:35 - Are the robots taking over?
    30:14 - What is AI really good at?
    33:28 - Definition of Deep Learning
    35:37 - Neural Networks
    36:53 - What to learn
    40:50 - Using PyTorch
    43:52 - Google colab
    44:48 - Study recommendations
    46:16 - The demand for AI skills
    48:15 - Teaching cyber security
    50:06 - Final Advice
    55:09 - Conclusion
    // Video mentions //
    ComputerPhile (lambda is not sentient): https://youtu.be/iBouACLc-hw
    Data Analysis Playlist: https://www.youtube.com/watch?v=NxYEz...
    Neural Networks Playlist: https://www.youtube.com/watch?v=py5by...
    Computer Vision Playlist: https://www.youtube.com/watch?v=C_zFh...
    // BOOK //
    Deep learning by Ian Goodfellow, Yoshua Bengio and Aaron Courville: https://amzn.to/3vmu4LP
    // COURSE //
    AI For Everyone by Andrew Ng: https://www.coursera.org/learn/ai-for...
    // PyTorch //
    Github: https://github.com/pytorch
    Website: https://pytorch.org/
    Documentation: https://ai.facebook.com/tools/pytorch/
    // Mike SOCIAL //
    Twitter: https://twitter.com/_mikepound
    YouTube: https://www.youtube.com/user/Computer...
    Website: https://www.nottingham.ac.uk/research...
    // David SOCIAL //
    Discord: https://discord.com/invite/usKSyzb
    Twitter: https://www.twitter.com/davidbombal
    Instagram: https://www.instagram.com/davidbombal
    LinkedIn: https://www.linkedin.com/in/davidbombal
    Facebook: https://www.facebook.com/davidbombal.co
    TikTok: http://tiktok.com/@davidbombal
    YouTube: https://www.youtube.com/davidbombal
    // MY STUFF //
    https://www.amazon.com/shop/davidbombal
    // SPONSORS //
    Interested in sponsoring my videos? Reach out to my team here: [email protected]
    lamda
    python
    neural network
    ai
    machine learning
    deep learning
    sentient
    google ai
    mike pound
    michael pound
    dr michael pound
    computerphile
    artificial intelligence
    google ai sentient
    google ai lamda
    google ai sentient conversation
    google ai alive
    ai jobs
    Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel!
    #ai #computerphile #lamda
    56 min
  • #397: Hack Wifi from $1.80
    Which adapters are the best for WiFi hacking? Kody of Null Byte and Hak5 fame gives us his advice on what to buy. You can purchase a monster antenna like the Tube U, or something smaller like the AWUS036NHA or WEMOS D1 Mini or WiFi Nugget. Lots of options for different price points.
    // MENU //
    00:00 - What Kind of Interview is This?
    00:24 - Introducing//Kody Kinzie
    01:17 - Null Byte//What Happened?
    03:17 - Hacking With Friends//SecurityFWD
    04:03 - Kody's Project//The WiFi Nugget
    07:04 - It Looks Like A Lightsaber//Best Alfa WiFi Adapter?
    08:48 - Hacking from the Hollywood Sign
    10:37 - Small WiFi Adapters//The NEH or the NHA?
    12:08 - Favourite OS//Kali Linux or?
    13:15 - Difference//Pi vs Microcontrollers
    15:28 - WiFi Hacking//What is a WiFi Nugget?
    19:55 - Flashing Hacking Tools On the Nugget
    26:22 - Why Hardware is Hard
    28:33 - Difference//USB vs WiFi Nugget
    32:13 - Flashing via Browser?
    34:51 - Getting Started with Microcontrollers
    37:52 - CircuitPython instead of Ardruino
    39:47 - Which Nugget to Pick
    41:32 - Where to Buy the Nugget
    43:58 - Join the Community//Where to Learn From Kody
    48:24 - Thank Tou & Closing Thoughts
    50:06 - Being a Beginner
    51:10 - Always Learn//If You Think You Know Everything
    51:47 - Don't Make It Your Entire Identity
    52:54 - Rising Above the Haters as a Content Creator
    53:51 - End//There's Always a Kid Better Than You
    Recommended Adapters:
    Alfa Tube U: https://amzn.to/3Q8Togp
    Alfa AWUS036NHA: https://amzn.to/3wnyVen
    Alfa AWUS036ACM: https://amzn.to/3fCL4WT
    Alfa AWUS036ACH: https://amzn.to/3rLAjny or https://amzn.to/2PxkkMV
    // Kody SOCIAL //
    Twitter: https://twitter.com/KodyKinzie
    YouTube: https://www.youtube.com/SecurityFWD
    Buy Kody's Cool products: https://retia.io/
    Kody's Udemy's classes:
    Advanced Ethical Wi-Fi Hacking with the ESP8266 Deauther: https://www.udemy.com/course/deauther/
    Digispark: https://www.udemy.com/course/digispark/
    // David SOCIAL //
    Discord: https://discord.com/invite/usKSyzb
    Twitter: https://www.twitter.com/davidbombal
    Instagram: https://www.instagram.com/davidbombal
    LinkedIn: https://www.linkedin.com/in/davidbombal
    Facebook: https://www.facebook.com/davidbombal.co
    TikTok: http://tiktok.com/@davidbombal
    YouTube: https://www.youtube.com/davidbombal
    // MY STUFF //
    https://www.amazon.com/shop/davidbombal
    // SPONSORS //
    Interested in sponsoring my videos? Reach out to my team here: [email protected]
    wifi
    wifi kali linux
    kody
    nullbyte
    kody kinzie
    best wifi adapter for kali linux
    kali linux wifi
    wifi kali
    kali wifi
    parrot os
    parrot os wifi
    best wifi adapters
    best wifi hacking adapters
    best cybersecurity certs
    cybersecurity
    cybersecurity careers
    ceh
    oscp
    itprotv
    ine
    ejpt
    elearn securtiy
    oscp certification
    ctf for beginners
    Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel!
    #wifi #hacking #kalilinux
    55 min
  • #396: The Internet just changed.
    You better be aware of what just changed on the Internet. TCP is being replaced with QUIC. UDP is being used more and more instead of TCP. This affects your firewalls. It affects a lot of your network troubleshooting. HTTP/3 has been standardized. Everything is encrypted with QUIC - welcome to the new world of network troubleshooting and security.
    // MENU //
    00:00 - The Problem with TCP
    00:12 - Introducing//Robin Marx
    02:12 - Clean Ship, Clean House//RFCs
    03:25 - HTTP Semantics//QUIC//HTTP/3
    04:17 - Why the Hell Do We Need HTTP/3?
    05:05 - Why QUIC?
    08:35 - QUIC & TLS Integration
    10:02 - Why Use UDP?
    13:50 - Replacing TCP with QUIC
    14:28 - Summary So Far
    15:22 - Stream Multiplexing
    15:40 - Head-of-line blocking
    18:40 - Why This Slows Things Down
    19:29 - How QUIC Does It Differently
    20:58 - TCP vs QUIC//Packet Handling
    23:11 - HTTP/3 Prioritization
    25:25 - Stats//QUIC Isn't Going Anywhere
    26:30 - Firewalls are almost useless
    27:20 - Firewalls Blocking QUIC?
    28:04 - QUIC & Other Protocols?
    29:20 - IPv4 & IPv6//Different for QUIC?
    29:54 - Challenges for QUIC's Growth
    30:43 - Connection Migration
    33:33 - What About Hackers?
    36:32 - How Do I Get To Use QUIC?
    38:28 - Large Companies Adopting QUIC
    39:09 - The Internet is Too Centralized?
    40:02 - Header Compression
    41:55 - Server Push
    43:47 - Practical Examples with Wireshark
    50:34 - Thank You & How to Contact Robin
    // Robin SOCIAL //
    Twitter: https://twitter.com/programmingart
    LinkedIn: https://www.linkedin.com/in/rmarx/
    YouTube: https://www.youtube.com/channel/UCyqP...
    // Robin's Blog articles //
    HTTP3 core concepts Part 1: https://www.smashingmagazine.com/2021...
    HTTP3 core concepts Part 2: https://www.smashingmagazine.com/2021...
    HTTP3 core concepts Part 3: https://www.smashingmagazine.com/2021...
    // Chris Greer Videos //
    HTTPS Decryption with Wireshark: https://youtu.be/GMNOT1aZmD8
    Decrypting TLS, HTTP/2 and QUIC with Wireshark: https://youtu.be/yodDbgoCnLM
    // David SOCIAL //
    Discord: https://discord.com/invite/usKSyzb
    Twitter: https://www.twitter.com/davidbombal
    Instagram: https://www.instagram.com/davidbombal
    LinkedIn: https://www.linkedin.com/in/davidbombal
    Facebook: https://www.facebook.com/davidbombal.co
    TikTok: http://tiktok.com/@davidbombal
    YouTube: https://www.youtube.com/davidbombal
    // MY STUFF //
    https://www.amazon.com/shop/davidbombal
    // SPONSORS //
    Interested in sponsoring my videos? Reach out to my team here: [email protected]
    http
    https
    quic
    tcp
    udp
    http/1
    http/2
    http/3
    wireshark
    firewall
    firewall quic
    quic firewall
    http/3 firewall
    #http3 #quic #tcp
    53 min
  • #395: What you need to learn in 2022? Top 3 hot trends.
    You want to ride waves. You want to learn the hot new topics to get ahead - especially if you are starting out. Don't focus on the stuff of yesterday. Focus on the new opportunities. Ben Sadeghipour (NahamSec) shares his suggestions about what to learn and then tells us about one that is gaining a lot of momentum in 2022.
    // MENU //
    00:00 - Coming Up
    00:29 - Intro
    00:34 - The next big thing
    02:09 - Opportunities in Web3
    03:59 - Ride the wave
    06:07 - Attack Vector & Attack Surface Management
    11:39 - Going digital and digital assets
    14:14 - NahamSec "Under 10 Minutes" series
    15:51 - Patches that are still vulnerable
    18:20 - APIs are the future
    21:16 - Shodan demo
    30:24 - The security issue
    31:38 - Shodan vs ASM
    32:38 - Out of scope assets
    35:12 - NahamSec and Hadrian
    38:12 - Will automation take over?
    39:13 - ASM vs Inventory Management
    40:49 - Getting more information about ASM
    44:21 - Covering APIs on NahamSec YouTube
    45:31 - Conclusion
    Previous video: https://youtu.be/9vaEwycet90
    // Connect with David //
    Discord: https://discord.com/invite/usKSyzb
    Twitter: https://www.twitter.com/davidbombal
    Instagram: https://www.instagram.com/davidbombal
    LinkedIn: https://www.linkedin.com/in/davidbombal
    Facebook: https://www.facebook.com/davidbombal.co
    TikTok: http://tiktok.com/@davidbombal
    YouTube: https://www.youtube.com/davidbombal
    // Connect with NahamSec //
    Twitter: https://twitter.com/nahamsec
    YouTube: https://www.youtube.com/c/nahamsec
    Github: https://github.com/nahamsec/Resources...
    Discord: https://discord.com/invite/ysndAm8
    Instagram: https://www.instagram.com/nahamsec/
    LinkedIn: https://www.linkedin.com/in/nahamsec/
    Twitch: https://www.twitch.tv/nahamsec
    Website: https://nahamsec.com/
    // Nahamsec's Udemy Course//
    Udemy: https://www.udemy.com/course/intro-to...
    // MY STUFF //
    https://www.amazon.com/shop/davidbombal
    // SPONSORS //
    Interested in sponsoring my videos? Reach out to my team here: [email protected]
    hack
    hacker
    shodan
    cyber
    hacking
    cybersecurity
    asm
    rsa
    attack surface management
    attack vector
    attack surface monitoring
    attack surface reduction
    bitcoin
    api
    apis
    postman
    hacking
    hacking api
    cyber security
    information security
    sans institute
    cybersecurity training
    cyber security training
    information security training
    privacy
    nsa
    oscp
    ceh
    bug bounty
    bugbounty
    hackerone
    hacking
    Ben Sadeghipour
    NahamSec
    nahamsec
    cyber
    security
    bug bounties
    ethical hacking
    bug bounty hunting
    burp suite
    ethical hacker
    Disclaimer: This video is for educational purposes only.
    Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel!
    #cyber #hacking #jobs
    47 min
  • #394: Best Hacking Python Book?
    The difference between script kiddies and professionals is the difference between merely using other people's tools and writing your own. Charle Miller, from the foreword (1st edition).
    This is a great book if you want to learn Python for hacking and penetration testing. Sometimes the tools you want to use are not available on target systems and the only option is to use Python - so learn the tools and techniques you can use with Python in a pentest or ethical hacking situations.
    // MENU //
    00:00 - Coming up
    00:26 - Intro
    00:32 - Black Hat Python has been updated!
    02:52 - How Black Hat Python started
    07:00 - Why Python?
    08:26 - Justin Seitz's background
    10:33 - "Make it work."
    11:56 - Tim Arnold's background
    15:21 - Simple to read for everyone
    19:55 - Editor vs Integrated Development Environment (IDE)
    21:06 - Learn to debug!
    22:29 - Modules updated to Python 3
    24:28 - The Networking chapter
    27:09 - Favourite chapters
    28:17 - Inspirations for the chapters
    31:40 - You always learn
    33:13 - Choosing Developer or Hacker
    36:12 - Endless accessibility to learning material
    37:08 - Is it necessary to know programming?
    41:23 - Ruby knowledge for Metasploit
    42:27 - Will Golang replace Python?
    45:27 - Recommended coding languages
    46:40 - The story of Hunchly
    54:15 - From Pentester to OSINT
    56:44 - Justin Seitz's stories
    59:18 - How Hunchly works
    01:00:52 - Will A.I. replace humans?
    01:02:16 - Dark Web Mailing List
    01:05:38 - Tim Arnold's story
    01:09:02 - Advice for beginners
    01:17:53 - Conclusion
    // Buy the books //
    Black Hat Python: https://amzn.to/3yQIdTD
    Grey Hat Python: https://amzn.to/3NQcA0H
    // Justin's SOCIAL //
    Twitter: https://twitter.com/jms_dot_py
    E-mail: justin.seitz (at) hunch.ly
    Website: https://www.hunch.ly/
    // Tim's SOCIAL //
    E-mail: jtim.arnold(at)gmail.com
    // David's SOCIAL //
    Discord: https://discord.gg/davidbombal
    Twitter: https://www.twitter.com/davidbombal
    Instagram: https://www.instagram.com/davidbombal
    LinkedIn: https://www.linkedin.com/in/davidbombal
    Facebook: https://www.facebook.com/davidbombal.co
    TikTok: http://tiktok.com/@davidbombal
    YouTube Main Channel: https://www.youtube.com/davidbombal
    YouTube Tech Channel: https://youtube.com/channel/UCZTIRrEN...
    YouTube Clips Channel: https://www.youtube.com/channel/UCbY5...
    Apple Podcast: https://davidbombal.wiki/applepodcast
    // MY STUFF //
    https://www.amazon.com/shop/davidbombal
    // SPONSORS //
    Interested in sponsoring my videos? Reach out to my team here: [email protected]
    python
    black hat python
    no starch
    no starch press
    osint
    hack
    hacking
    pentesting
    ethical hacking
    penetration testing
    black hat python
    white hat python
    grey hat python
    gray hat python
    cyber security
    kali linux
    ethical hacking
    python programming
    penetration testing
    ethical hacker
    python for hacking
    python full course
    black hat book review
    how to hack
    cyber security course
    hacking books
    computer hacking
    learn black hat python
    python tutorial
    cyber security career
    cyber security analyst
    python hacker
    python hacking course
    python hacking tools
    scapy
    hack python code
    hack python book
    python hack wifi
    Disclaimer: This video is for educational purposes only.
    Please note that the links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel!
    #python #hacking #kalilinux
    1 hr 22 min
  • #393: 4th of July special: Path to Cybersecurity by Ex-NSA Hacker
    How to move into Cyber if you are a veteran.
    // Neal's Top 5 Resources //
    1) Onward to Opportunity: O2O
    Website: https://ivmf.syracuse.edu/programs/ca...
    Army Mil PDF: https://home.army.mil/bragg/applicati...
    2) VetSec:
    Website: https://veteransec.org/
    LinkedIn: https://www.linkedin.com/company/vete...
    Twitter: https://twitter.com/veteransec
    3) With you With Me:
    Website: https://www.withyouwithme.com/
    4) Operation Code:
    Website: https://operationcode.org/
    5) Boots 2 Books:
    Website: https://www.boots2books.com/
    Montgomery GI Bill:
    https://www.va.gov/education/about-gi...
    // Recommended SANS courses //
    GIAC Exploit Researcher and Advanced Penetration Tester (GXPN): https://www.sans.org/cyber-security-c...
    GIAC Certified Incident Handler (GCIH): https://www.giac.org/certifications/c...
    GIAC Certified Forensic Analyst (GCFA): https://www.giac.org/certifications/c...
    GIAC Reverse Engineering Malware (GREM): https://www.sans.org/cyber-security-c...
    SANS DIFR: https://www.sans.org/digital-forensic...
    GIAC Information Security Professional (GISP): https://www.sans.org/cyber-security-c...
    GIAC Security Essentials (GSEC): https://www.giac.org/certifications/s...
    GIAC Systems and Network Auditor (GSNA): https://www.sans.org/cyber-security-c...
    // Hands on //
    Try Hack Me: https://tryhackme.com/
    Hack The Box: https://www.hackthebox.com/
    Security Blue Team: https://securityblue.team/
    Blue Team Labs Online: https://blueteamlabs.online/
    Cyber Defenders: www.cyberdefenders.org
    // Degrees //
    Neal recommends getting a business degree.
    // Sites referred to in the video //
    Transition assistance program TAP (Neal says this is not sufficient): https://www.dol.gov/agencies/vets/pro...
    Cyber Insecurity YouTube channel: https://www.youtube.com/c/CyberInsecu...
    Josh Mason’s LinkedIn: https://www.linkedin.com/in/joshuacmason
    Video Ex NSA Hacker tells us how to get into hacking https://youtu.be/SFbV7sTSAlA
    SANS: https://www.sans.org
    Neal’s discord server: https://www.twitch.tv/cyber_insecurity
    https://cyberinsecurity.tv/
    // Books //
    The Dichotomy of Leadership by Jocko Willink and Leif Babin https://amzn.to/3bRfFk0
    Extrene ownership How US Navy Seals Lead and Win Jocko Willink and Leiff Babin https://amzn.to/3P0Ac3H
    // Neal's SOCIAL //
    YouTube: https://www.youtube.com/c/cyberinsecu...
    LinkedIn: https://www.linkedin.com/in/nealbridges/
    Twitter: https://twitter.com/ITJunkie
    // Josh's SOCIAL //
    LinkedIn: https://www.linkedin.com/in/joshuacma...
    Twitter: https://twitter.com/Joshua17sc
    // David's SOCIAL //
    Discord: https://discord.gg/davidbombal
    Twitter: https://www.twitter.com/davidbombal
    Instagram: https://www.instagram.com/davidbombal
    LinkedIn: https://www.linkedin.com/in/davidbombal
    Facebook: https://www.facebook.com/davidbombal.co
    TikTok: http://tiktok.com/@davidbombal
    YouTube Main Channel: https://www.youtube.com/davidbombal
    YouTube Tech Channel: https://youtube.com/channel/UCZTIRrEN...
    YouTube Clips Channel: https://www.youtube.com/channel/UCbY5...
    Apple Podcast: https://davidbombal.wiki/applepodcast
    // MY STUFF //
    https://www.amazon.com/shop/davidbombal
    // SPONSORS //
    Interested in sponsoring my videos? Reach out to my team here: [email protected]
    cyber
    infosec
    vet
    veteran
    vet to cyber
    ethical hacker
    cybersecurity
    sans
    oscp
    comptia
    Disclaimer: This video is for educational purposes only.
    Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel!
    #cyber #vet #infosec
    1 hr 1 min
  • #392: OSINT tools to track you down. You cannot hide.
    Never post photos on social media if you want privacy. It's amazing how easy it is to find the location of photos posted on Facebook, Instagram, Flickr or other social media platforms.
    You cannot hide. Your privacy is over. Time to learn Open Source Intelligence from the best.
    OSINT Curious is a registered, non-profit 501(c)(3) organization with the United States IRS (EIN: 84-2781099); and accepts Patreon donations from individuals and sponsors. If you are a sponsor, please contact them if you want to work with them: https://osintcurio.us/funding/
    // MENU //
    00:00 - Let's Find Nessie!
    00:14 - The Art of Geolocation with OSINT Curious
    01:31 - Image 01//Egyptian Wall
    02:53 - Bing Reverse Image Search
    04:15 - Image Cleanup Tools
    05:17 - Removing David
    05:51 - Finding David with the Cleaned Up Image
    10:37 - Image 02//The Lighthouse
    11:32 - Bing Visual Search
    14:01 - Confirming the Location with 360 Photos
    16:46 - Results May Vary
    18:08 - Use Different Search Engines!
    18:45 - Add-on to Speed Up Image Searching
    22:56 - Image 03//Speed Test!
    25:10 - Image 04//The Bridge
    26:28 - Google Images vs Bing vs Yandex
    28:36 - Image 05//Nessie
    30:04 - Nessie in London?
    30:53 - Using Observational Techniques to Find Locations
    33:56 - Matching the Photo
    40:14 - Using Google Street View
    41:39 - Google Easter Egg
    43:11 - The Google Boat?
    44:58 - EXIF Data Tool//Finding Exact Location
    46:59 - Image 06//The Canal
    49:57 - Identifying Canal with Boat
    52:20 - The Canal in Google Street View
    53:33 - Cities vs Countryside
    55:51 - How to Get Good
    57:16 - More OSINT? Leave a Comment!
    Previous video: https://youtu.be/ImWJgDQ-_ek
    EXIF video: https://youtu.be/A_itRNhbgZk
    // The OSINT Curious Project //
    YouTube: https://www.youtube.com/c/TheOSINTCur...
    Twitter: https://twitter.com/osintcurious
    LinkedIn: https://www.linkedin.com/company/the-...
    Website: https://osintcurio.us
    Public, OSINT-focused Discord: https://iam.osintcurio.us/discord
    Sponsor personally or through your company: https://osintcurio.us/funding/
    // Websites mentioned //
    Remove Background: https://www.remove.bg/
    Cleanup Pictures: https://cleanup.pictures/
    Search by image: https://chrome.google.com/webstore/de...
    RevEye: https://chrome.google.com/webstore/de...
    // David's SOCIAL //
    Discord: https://discord.com/invite/usKSyzb
    Twitter: https://www.twitter.com/davidbombal
    Instagram: https://www.instagram.com/davidbombal
    LinkedIn: https://www.linkedin.com/in/davidbombal
    Facebook: https://www.facebook.com/davidbombal.co
    TikTok: http://tiktok.com/@davidbombal
    YouTube: https://www.youtube.com/davidbombal
    // Lisette's SOCIAL //
    Twitter: https://twitter.com/technisette
    Personal website: https://technisette.com
    // Steven's SOCIAL //
    Twitter: https://twitter.com/nixintel
    LinkedIn: https://www.linkedin.com/in/steven-ha...
    Personal website: https://nixintel.info/
    SANS SEC487 OSINT Courses Steven teaches - https://www.sans.org/profiles/steven-...
    // MY STUFF //
    https://www.amazon.com/shop/davidbombal
    // SPONSORS //
    Interested in sponsoring my videos? Reach out to my team here: [email protected]
    osint
    open-source intelligence
    open source intelligence tools
    osint curious
    geolocation
    geolocation game
    facebook
    instagram
    google
    bing
    yandex
    geolocation google
    geolocation bing
    you cannot hide
    social media
    warning about social media
    google dorks
    dorks
    google
    osintgram
    osint framework
    osint tools
    osint tv
    osint ukraine
    osint tutorial
    osint course
    osint instagram
    osint framework tutorial
    cyber security
    information security
    open-source intelligence
    open source intelligence
    sans institute
    cybersecurity training
    cyber security training
    information security training
    what is osint
    open source artificial intelligence
    cyber
    hack
    privacy
    nsa
    oscp
    ceh
    Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel!
    #osint #cyber #privacy
    58 min

About David Bombal

From the publisher's feed

Want to learn about IT? Want to get ahead in your career? Well, this is the right place!

More shows like David Bombal

Hacked by Hacked

Hacked

191 Listeners

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec by Jerry Bell and Andrew Kalat

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec

373 Listeners

Risky Business by Risky Business Media

Risky Business

375 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

653 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,028 Listeners

Smashing Security by Graham Cluley

Smashing Security

318 Listeners

Click Here by Recorded Future News

Click Here

421 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,054 Listeners

Cybersecurity Today by David Shipley

Cybersecurity Today

179 Listeners

Hacking Humans by N2K Networks

Hacking Humans

314 Listeners

CISO Series Podcast by David Spark, Mike Johnson, and Andy Ellis

CISO Series Podcast

191 Listeners

Defense in Depth by CISO Series

Defense in Depth

73 Listeners

Cybersecurity Headlines by CISO Series

Cybersecurity Headlines

138 Listeners

Risky Bulletin by Risky Business Media

Risky Bulletin

47 Listeners

Hacker And The Fed by Chris Tarbell & Hector Monsegur

Hacker And The Fed

168 Listeners