MITA1 · 2019. 10. 28. · MITA1

60
Becoming a cybersecurity ethical hacker From Zero to Hero

Transcript of MITA1 · 2019. 10. 28. · MITA1

Page 1: MITA1 · 2019. 10. 28. · MITA1

Becoming a cybersecurity ethical hackerFrom Zero to Hero

Page 2: MITA1 · 2019. 10. 28. · MITA1

2

Geek

20 year of experience doing hacking

Authored tools / articles / books / etc

Speaker at conferences around the world

Volunteer at OWASP

Still getting the same thrill when compromising a host

CEO at SECFORCE

ME

Page 3: MITA1 · 2019. 10. 28. · MITA1

3

IT Security Consultancy – penetration testing

Highly specialised in offensive security

Teams located in London (UK), Greece and Malta

SECFORCE

Red Team Testing Penetration Testing

Page 4: MITA1 · 2019. 10. 28. · MITA1

Agenda0

Page 5: MITA1 · 2019. 10. 28. · MITA1

5

Offensive security career1

Agenda – from Zero to Hero

234

Technical skills

Mindset

Resources

5 Questions and answers

Page 6: MITA1 · 2019. 10. 28. · MITA1

Offensive Security1

Page 7: MITA1 · 2019. 10. 28. · MITA1

Who would like to be a hacker?

Page 8: MITA1 · 2019. 10. 28. · MITA1

8

Page 9: MITA1 · 2019. 10. 28. · MITA1

9

Page 10: MITA1 · 2019. 10. 28. · MITA1

10

Page 11: MITA1 · 2019. 10. 28. · MITA1

11

Page 12: MITA1 · 2019. 10. 28. · MITA1

Reality is quite different

Page 13: MITA1 · 2019. 10. 28. · MITA1

13Offensive Security Career

We work in a highly professional environmentWe focus on customer satisfactionWe follow due diligenceWe work hard to do a great jobEtc.

Page 14: MITA1 · 2019. 10. 28. · MITA1

14Offensive Security Career

Page 15: MITA1 · 2019. 10. 28. · MITA1

So, what do we do?

Page 16: MITA1 · 2019. 10. 28. · MITA1

16Penetration Testing

Page 17: MITA1 · 2019. 10. 28. · MITA1

17Penetration Testing

Page 18: MITA1 · 2019. 10. 28. · MITA1

My next move…

Page 19: MITA1 · 2019. 10. 28. · MITA1

19

Page 20: MITA1 · 2019. 10. 28. · MITA1

20How to become a hacker - requirements

1 – Technical Skills2 – Mindset

Page 21: MITA1 · 2019. 10. 28. · MITA1

Technical Skills2

Page 22: MITA1 · 2019. 10. 28. · MITA1

22Technical Skills

Page 23: MITA1 · 2019. 10. 28. · MITA1

23Why technical skills are necessary?

You will only be able to attack technology that you understandThe better you can use something, the better you will misuse itThe stronger your technical foundation, the easier it will be to build new knowledge

Page 24: MITA1 · 2019. 10. 28. · MITA1

24Technical pillars

Operating Systems Networking Applications Programming

Windows*nixActive DirectoryOS Security

TCP/IPISO layersNetwork layer attacks

Web/mobile technologiesApplication security

Scripting languages

Page 25: MITA1 · 2019. 10. 28. · MITA1

25Technical security

Infrastructure and application securitySpecific attacks to technologyAttacking techniques (bruteforcing, password cracking, memory manipulation, privilege escalation, etc.)Active Directory trust and policiesVulnerability research (fuzzing, etc.)Exploit writing

Memory layoutMemory corruption bypassetc

Page 26: MITA1 · 2019. 10. 28. · MITA1

Mindset3

Page 27: MITA1 · 2019. 10. 28. · MITA1

27Hacker’s mindset

Page 28: MITA1 · 2019. 10. 28. · MITA1

28Hacker’s mindset

Hacking is about using technology in unintended waysA hacker would not follow normal user rulesNatural ability to misuse software

Page 29: MITA1 · 2019. 10. 28. · MITA1

29Hacker Mindset

Page 30: MITA1 · 2019. 10. 28. · MITA1

30

Page 31: MITA1 · 2019. 10. 28. · MITA1

31

Link all nine dots4 lines or lessWithout lifting the (imaginary) pen or pencilWithout tracing the same line more than once

Think outside the box

Page 32: MITA1 · 2019. 10. 28. · MITA1

32Think outside the box

Page 33: MITA1 · 2019. 10. 28. · MITA1

33Motivation and passion

Sky is the limit – you will never learn it allThe best hackers I know are profoundly passionate about hackingBeing a great hacker requires A LOT of work. Only possible if you truly love itEven though it may be a 9 to 5 job, it is not. It is almost a lifestyle

Page 34: MITA1 · 2019. 10. 28. · MITA1

34Quick learner/researcher

Page 35: MITA1 · 2019. 10. 28. · MITA1

35Quick learner/researcher

Learn how to learnYou will need to solve new puzzles every dayIt is important to identify dead ends and rabbit holesYou may need to become an expert on something overnight

Page 36: MITA1 · 2019. 10. 28. · MITA1

36Determination

Page 37: MITA1 · 2019. 10. 28. · MITA1

37Determination

Talent will only take you so farPersevering on a problem will take you from there onwardsOf the hackers I know, the harder they tried, the luckier they became

Page 38: MITA1 · 2019. 10. 28. · MITA1

38In summary

Technical skillsOSNetworkApplicationCoding

MindsetOut of the box thinkingQuick learnerDetermination

Page 39: MITA1 · 2019. 10. 28. · MITA1

Resources4

Page 40: MITA1 · 2019. 10. 28. · MITA1

40Resources

BooksVideosWebsitesFormal education

Page 41: MITA1 · 2019. 10. 28. · MITA1

41Books

Page 42: MITA1 · 2019. 10. 28. · MITA1

42Books - advanced

Page 43: MITA1 · 2019. 10. 28. · MITA1

43Videos

Page 44: MITA1 · 2019. 10. 28. · MITA1

44Videos

Page 45: MITA1 · 2019. 10. 28. · MITA1

45Videos

Page 46: MITA1 · 2019. 10. 28. · MITA1

46Videos

Page 47: MITA1 · 2019. 10. 28. · MITA1

47Websites

Page 48: MITA1 · 2019. 10. 28. · MITA1

48Websites

Page 49: MITA1 · 2019. 10. 28. · MITA1

49Websites

Page 50: MITA1 · 2019. 10. 28. · MITA1

50Websites

Page 51: MITA1 · 2019. 10. 28. · MITA1

51Websites

Page 52: MITA1 · 2019. 10. 28. · MITA1

52Websites

Page 53: MITA1 · 2019. 10. 28. · MITA1

53Websites

Page 54: MITA1 · 2019. 10. 28. · MITA1

54Formal Education

Page 55: MITA1 · 2019. 10. 28. · MITA1

55Formal Education

Page 56: MITA1 · 2019. 10. 28. · MITA1

56Formal Education

Page 57: MITA1 · 2019. 10. 28. · MITA1

57Formal Education

Page 58: MITA1 · 2019. 10. 28. · MITA1

58

Page 59: MITA1 · 2019. 10. 28. · MITA1

Questions?5