Alex the Entreprenerd on Freelancing, Business and Security Practices
Alex shares stories from his early career and freelancing days to how he got into web3. Giving business advice and an inside look on internal security practices.
0:00 private audits 3:09 business and client relations 9:51 Alex's early career 19:09 lessons from childhood mmorpgs 26:45 being a freelancer 29:38 starting in web3 41:47 audit contest burnout 46:19 learning and mentoring 55:24 web3 market outlook 1:02:50 BadgerDAO eBTC internal security practices ... https://www.youtube.com/watch?v=q9PgvDVNIn0
Looking through and reacting to the CONTI Ransomware Gang’s internal training doco. Real life Russian hacker’s playbook. Interesting techniques that Russian ransomware gangs use to avoid detection and deploy ransomware in a corporation's internal network.
References:
Leaked PDF: https://github.com/silence-is-best/files
Enumerate File Shares: https://github.com/SnaffCon/Snaffler
Working PrintNightmare Variation: https://github.com/GossiTheDog/SystemNightmare
Learn penetration testing: https://www.tryhackme.com
...
https://www.youtube.com/watch?v=6FwNpX7PpIM
My experience preparing for the OSCP exam.
I definitely over prepared for the exam in my case, however I don't regret it at all. There were a few factors to me putting it off for as long as I did.
I took some time off to prepare for and do a couple of Active Directory penetration tests under contract. Which was a great opportunity to learn more about AD attacks.
Also took time off to prepare for penetration testing interviews.
Another factor was, I was waiting for a job offer to come through which was offering to sponsor for my OSCP, however that didn't end up materializing. Afterwards when I was ready to sign up and pay for the OSCP exam myself, another job opportunity came through, so I put off the exam again.
I ended up landing that second job opportunity, so will be likely doing the exam next month, sponsored or not. Looking forward to it!
Learning Resources:
https://www.tryhackme.com/
https://www.hackthebox.eu/
https://www.offensive-security.com/labs/
https://www.virtualhackinglabs.com/
https://www.cyberseclabs.co.uk/
https://portswigger.net/web-security
...
https://www.youtube.com/watch?v=sn4bbfgptW8
Methodology on avoiding rabbit holes, going after low hanging fruit and finding the correct exploit quickly in the OSCP exam.
...
https://www.youtube.com/watch?v=lq0ErN2VIJQ
Digital nomad finds himself fleeing the war in Ukraine with his girlfriend.
JohnnyTime is blockchain security researcher, educator and content creator with over 10 years of experience working in tech and cybersecurity.
Full Podcast: https://www.youtube.com/watch?v=YCsfUrzrcgQ
...
https://www.youtube.com/watch?v=0kOehJ3V5bk
A review of the Privilege Escalation courses by Tib3rius on Udemy for OSCP preparation.
https://www.udemy.com/course/windows-privilege-escalation/
https://www.udemy.com/course/linux-privilege-escalation/
...
https://www.youtube.com/watch?v=YmnNUqrHL_A
What is it like to work as a penetration tester/ethical hacker. Day to day tasks, responsibilities, working from home and other random thoughts.
...
https://www.youtube.com/watch?v=1jFlClmG9Wg