Showing posts with label penetration testing. Show all posts
Showing posts with label penetration testing. Show all posts

Sunday, January 29, 2017

is a career in cyber security right for me

If you have been contemplating a a Career in Cyber Security, or a Change to Cyber Security, you've probably asked yourself at least once, "Is a Career in Cyber Security right for me?". You're not a lone. In fact, I'd wager to say that if someone hasn't asked themselves this question, then they need to investigate why they haven't before anything else.

The problem is that a lot of people of our nature come to this cross roads out of shear curiosity. "I'm good at computers, should I start Cyber Security?". Something must have inspired you in order to bring yourself to that question. Let me try and help you to decide.

Cyber Security is not as easy as the movies or Youtube videos glorify it. You don't simply enter in an IP address and click a few buttons and own a network; that's not how it works at all. A lot of people who jump into cyber security tend to be rather impatient by nature, and want to "download" every bit of knowledge in the blink of an eye. That's also not how this works, let me explain;

More times than not, you'll find yourself getting nothing but false positives during an active Penetration Test Engagement. That wears quickly on someones Patience, I know that first hand. However, one of the most important skills to have is patience. Because a lack of patience will lead to mistakes, and mistakes cost money. So if you have a short temper and no patience, Cyber Security may not be the best career choice, until you develop those skills.

You have to realize a few things about this career.

1. It takes time to become proficient and professional.
2. Again, Patience is key
3. Get used to long hours, and lots of reading and writing (logs, reports, etc)
4. Did I mention patience???

At PentesterUniversity.org we offer affordable courses that allow students to learn at their own pace, what ever that may be. I have found this is key to less stress in students, allowing them to understand, learn and retain the information easier. So no matter if you sign up for our online school, or choose to self learn, make sure you give yourself enough time to fully understand the information presented to you. Don't burn yourself out trying to learn it all at once.

Wednesday, January 18, 2017

Cyber Security in 2017

         I've been spending a lot of time on sites like www.quora.com answering questions people have about Cyber Security. And I have noticed a few questions seem to keep coming up. So that got me thinking, What's the outlook for Cyber Security Professionals, or aspiring professionals in 2017?

If 2017 is anything like 2016, the future is bright, very bright. In 2016 essentially, everyone and everything got hacked, right? Leaked emails from simple phishing attacks, This site and that site Hacked, this database compromised, that database compromised. User information leaked from here, and there. Old people, young people, military, government, websites, data centers, EVERYTHING WAS COMPROMISED at some point. Kind of crazy, right?

There is a major shortage in skilled Cyber Security / Penetration Tester Professionals. More over, companies, even smaller companies are starting to finally see the light; No matter how big or small they are, they need Network Security, and they need it yesterday.

This works out great for our students in our online school PentesterUniversity.org as they are now in high demand more so than ever before. They know it too! We have seen a massive influx of new enrollments in 2017 so far, and we are very excited to get them going onto one of the Hottest, most Explosive career paths of this decade.

So what does 2017 hold for Cyber Security? Definitely more Job Creation, and Certainly many more major breaches I am sure.




Monday, January 16, 2017

2017 - New Year New You.

Hello Everyone,

2017 is upon us, and with the new year, it got me thinking. You know, many people make silly new year resolutions, like "Lose 10 lbs" "Eat Healthier" "Quit smoking" etc, but rarely does anyone say "Make More Money" or "Change careers to something I am passionate about".

Sadly, most people lack the drive or ambition to keep their resolutions, and they fall by the wayside.

Did you know that Cyber Security Professionals are estimated to make an average of $80-100k+ this year alone?

If 2016 should have Taught us anything at all, it's that Cyber Security professionals are needed now more so than ever before. WE are and will continue to be in high demand for decades to come.

I'm so glad that I finally started the online school www.PentesterUniversity.org and I want to help you get into the trade. So, use promo code "pre10" at check out to save 10% off our already super low course prices.

Are you ready to enter one of the most popular, highly sought after trades? If so be sure to use the promo code above and check us out!

I look forward to seeing you there!

Best Regards,
AfterBurn


Sunday, August 28, 2016

PentesterUniversity Updates!

Hey Everyone,

So I wanted to give everyone an update on our online school dubbed "PentesterUniversity" ™, which you can see HERE. I'm so excited! That being said, I've been working on creating course content and building my new Foldable desk area. I wanted to share some pictures with everyone so you can see what the work area looks like right now.

Here is the desk folded down for work. You can see my laptop, and of course my brand new Blue Yeti microphone with windscreen! Yes, I know the laptop is missing a mouse button lol.

A better shot from the distance. I plan to add storage hooks above the desk for my laptop, and a pocket for my charger, wires, etc. Also, the microphone will be going on a foldable mic stand that will be attached to the wall on the right.

Underneath. I used a 1x6 header that I screwed to the studs in the wall. Then a piano hinge for the hinging, and I custom made legs that went on foldable locking leg brackets I got from Amazon. The desk material is 3/4 Mellamine.

Here is the desk with the legs folded in, and the desk folded down. Frees up tons of floor space this way.


So, I'm finally going to have a comfortable space to work from, so I can create more awesome content for the school.

Now, the big question is; How much is the school going to cost? Here's what I am thinking, and please, I welcome your feedback. I'm going to do two pricing models that I think will suit most users.

We are going to have a lot of courses. Network Security Beginner-Advanced, Linux classes, Networking Classes, Web Pentest classes, WiFi Pentest classes, etc.


Monthly Subscription:

For everyone who signs up for a free registration from now until I release the first class will only pay $49.99 per month, and after release anyone who signs up will pay $59.99 per month. You can take as many classes as you want, and take as long as you want to complete them.

Per Class:

Each class will vary in a flat fee price from $99-$299+. You will be able to study at your own pace, and take as long as you need to complete it. Price stays the same.

Also, we are going to have quizzes, private student forums where you can contact me and others directly, email support with me, and much more! I wanted to be fair on the pricing because I want to be able to teach anyone, no matter their budgets. This is a rapidly growing industry, and we are in very high demand, which means we command a very high salary for our skill.

So, now that I'm all set up, please feel free to send me any feedback in the comments section below and of course sign up for an account at PentesterUniversity ™  so you can get that special discount for pre-registration!

-AfterBurn
 

Sunday, August 14, 2016

NetSecNow University!

Hey Guys,

I'm very excited to announce the very first stages of FINALLY opening our online school, dubbed "Pentester University". I've struggled over the last almost year trying to find a suitable platform to host and manage the Online School. Until now!

If you recall about a year ago I sent out a poll to see if any of our user base would be interested in attending our classes, and I was shocked to see the overwhelming support for it!

I've settled on a platform that I feel is very much inline with the schools needs. Focusing on security, ease of use, ease of management, and deployment.


Classes will range in price ($20-$60) per class, or subscription. I'm still debating on what pricing model to use, but I'm more concerned right now with creating content.

Our classes online will very much differ from our Youtube Channel (NetSecNow), in that it will be much more organized, streamlined, and detailed. But you can count on the same style of teaching you've all come to appreciate, and the same level of care, and professionalism with an easy to understand teaching method.

In addition to our Penetration Testing Classes, we will create other classes that students can enroll in, such as Linux Fundamentals, Web Pentesting, Networking Fundamentals, and much more.

The Link (for now) will be HERE, and you can certainly sign up for FREE Account right now. Everyone who signs up for a free account now will get a special discount coupon for the classes!

Once interest grows, and students become active and once content is published, we will be migrating www.learnnetsec.com to be the schools flagship domain.

I'm thinking about running a special, or presale for anyone who follows this blog, so if you are interested please comment below.

Thursday, October 8, 2015

Updates

Hey Guys,

I know I haven't made a video in a couple of weeks. I lost a very close family member about 1.5 weeks ago, and it crushed me. But as time is passing, I'm starting to get back to normal.

Prior to that happening, I decided that I was very fed up at my job, and promptly quit. I was hoping to quit anyway to focus more on this project, but perhaps I should have planned better lol. So now, this project, it's growth etc is solely dependent upon donations, to which every single one I appreciate.

I have a few projects in the works, and hopefully able to get at least one of them off the ground. One of which is our very own Online School. I'm very excited about that!

Yesterday I finally released my 1.2 Million Unique Word password list. You can find that HERE if you missed it. 

I also appreciate the feedback, and we are growing tremendously, 20,300 Youtube subscribers -- I can't even believe it, so awesome!

Well I won't take up any more of your time, and I appreciate everyone and everything with this project. Enjoy your day and thanks for reading! 


Stay Tuned,

AfterBurn

Wednesday, October 7, 2015

1.2 Million Unique Passwords List

Hey Guys,

I Have created a brand new 1,290,141 Unique (No duplicates) Custom password list. Combines the most common passwords that have been hacked from 2012-2015, and a ton of custom passwords I've created and used over the years, even recently. The list requires a donation, to which you choose how much or how little. Most people donate $5.00 USD. After the donation, you should be redirected to the direct download. If there is an issue, kindly send me an email with your PayPal confirmation number or email address and I will personally send you a copy.

This literally took me hours and hours to compile, de-duplicate, and package. Once you check out with paypal, it will direct you to a download. Please keep that in mind!

Thanks! And as always, Enjoy!

If you have an adblocker script, or noscript type of plugin, please disable it before you click on the links, so you can be properly redirected. Thanks 

Check it out here: Download

Saturday, September 5, 2015

New Video: Installing and Configuring DVWA - Hacking websites

Hey Guys,

New Video up and running! Showing how to install and configure DVWA (Damn Vulnerable Web Application) for our upcoming videos on Web Pentesting / Website Hacking. Check it out and let me know what you think!

-AfterBurn


Wednesday, September 2, 2015

We're Back! New Script

Hey Guys,

So, like I mentioned in my latest video, I am indeed back, and I brought presents! I Created a basic script to help in being able to quick launch msfconsole (Metasploit) without having to remember all of the commands and services that are needed each and every time you go to use the framework. Check out our downloads page for a direct link to our sourceforge page.

Please leave me some feed back here or on twitter @LearnNetSec

Enjoy!

-AfterBurn

Tuesday, August 25, 2015

zscaler - Fake it till you make it?

So on the twitter sphere today, I saw a post about this website; http://securitypreview.zscaler.com/ which is supposed to be some "in the cloud" network security company, I guess? And their free check up script is supposed to do an "Automated Audit" on your system, via the web browser. I know right, silly to even type this, but that's the claim.

Well apparently some of us professionals in the know tried it out. And no matter your OS, Device, Browser, etc, we noticed that every single time on ANYTHING, this scan would tell you that you are Vulnerable to the "zbot Virus", which oddly enough, their company name also starts with a "z" as in "ZScaler" Twitter @zscaler. Coincidence? I think not. Scareware, I think yes.

Just imagine for a second, if you will, some overly zealous CEO of some small-medium corporation coming across this advertisement. He figures, sure, why not, I'll run a free scan! I'll show those over priced infosec companies, HA!

He then sees he's vulnerable to some erroneous "zbot" virus. "OH NO!" he exclaims, and promptly follows the companies call to action to sign up for their "service". Sigh.. we've all been saying this for years, this was bound to happen. but what Mr CEO Doesn't realize -- and it's our jobs to educate them on this -- is that Network Security auditing and/or Penetration Testing involves (should always) thinking outside the box. There is absolutely no "canned" or out of the box magic protection software/technology. It's not possible, and everyone who thinks that is just another foolish sheep.

Anyway, I know exactly nothing else about the above mentioned company, however, I do know that what they are doing is an underhanded, shady practice no different from any other traditional scareware tactics.

By the way, as I mentioned, it doesnt matter the platform you're on, they tell you that you are vulnerable to the zbot virus. I googled the zbot virus, and the only systems it can infect is

Trojan
Systems Affected:
Windows 2000, Windows 7, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP

Notice it doesn't say anything about Linux/Unix or android, mac, etc. Yet on all of those devices, it said I was vulnerable.

Reference

-AfterBurn

Monday, August 24, 2015

Updated 8-24-15

Hey Guys,

Just wanted to post an update as to what I am currently up to. First, I see Kali Linux 2.0 is out and that's exciting! I went ahead and ordered a new (to me) laptop, and that should be to me by the 29th. First thing will be installing Kali Linux 2.0. In reading the docs for Kali 2.0, I realized that there are some scripts I can write to certainly save some time, and make stuff easier for the Kali Community, to which I will do as soon as I install it. So keep an eye out for that.

I am searching through my old backups looking for data from the www.learnnetsec.com website. UGH, it may not be as easy as I thought to get the site back and going. But, that said, I want to make it bigger, better, more content, more hacker challenges, forums, learning portals, etc. So until then, this site is serving as the backup. Please subscribe to it. For now, the domain www.learnnetsec.com is forwarded to this one, until I get this resolved. 

I am very active on twitter again, so check me out there @LearnNetSec 

I am very excited to be back and at it again guys, honestly. I have found new software to edit videos on Linux, and of course its open source! So good bye windows! Once and for all! 

Stay Tuned, 

- AfterBurn

Thursday, June 13, 2013

Updates: New Stuff!

Hey Guys,

So, I have decided to bite the bullet and buy a real Domain Name! www.LearnNetSec.com  - was purchased today with some help from our ad's on the site and on youtube. This site here @blogspot will remain in use as we make a transition to the dedicated domain. I decided to do the dedicated domain so I can have more control over the overall website and blog content. I may also create a forum there for you guys to hang out, discuss, etc. I'd also like to get an IRC channel going but that is a lot of management (had one some years ago).

The second thing that is new, is that I finally joined us to Twitter today! I think twitter is a better avenue to give you guys updates than having to not only post it here, then facebook, and youtube. I have twitter linked with Youtube, so when new videos are uploaded I can quickly share them to twitter as well. So head on over to our Twitter Account HERE  and follow us for news, and updates there as well as the blog here.

I am also proud to announce that we have reached 100 subscribers to Youtube! Saturday the 15th will mark the first 30 day mark since this project was created. We have 8 videos on Youtube, so on the average that is 2 new videos a week! It's hard work, but It's totally worth it if you guys enjoy them and learn from the series. And by the looks of things, it seems you guys do!

So, a HUGE THANK YOU to everyone who has contributed to growing this project with me. If it weren't for you, we wouldn't be here at all!

Here's to the future! You guys Rock!

Updates: Next Week

Starting Next Week:


I am going to begin compiling the data for the presentation on "Phases of NetSec" which will discuss all of the details, steps, etc in Network Security Auditing and Penetration Testing. So far it's 13 slides of just talking points, so there is a lot of ground to cover. 

I am trying to figure out how to Produce the Video. Meaning it's obviously going to have to be done in parts since there is so much information to cover. 

While I am working on that, don't forget to check out the newest video:
Tor-Buddy Script Demo Tor + Proxychains + Anonymous DNS:
https://www.youtube.com/watch?v=AedFlLSmJf8

I will still be making Quick Vids based on your guys input on what you would like to learn in the interim. We have had 2 requests so far, 1 for nmap and one for VM-tools for kali linux. nmap will be included in the next video set: "Phases of NetSec".

Remember, please don't forget to like and share our videos, Facebook, and of course this very blog with all of your friends, family, and co-workers! Our presence on the web has been growing steadily, and that is great! The more people interested, the more creative I can be! 

Thanks Guys! See you in the next Video!

Tuesday, June 11, 2013

What's Up Next?

Hey Guys,

As I am sure most of you have already seen, I uploaded what was intended to be a new Video Intro last night that turned out to be more of a Trailer of what is to come in the next few videos. That Video is HERE in case you missed it.

We will be discussing the "Meat and Potatoes" of actually Hacking. Finally! But, it's way to much information to stuff in one video, even my infamous 45+ minute videos. We will start with an overview of what we are going to learn via Presentation slides and explaining each and every topic. Then we will move on to actually Hacking the Network. Explaining what to use, how, why, where, and when in great detail, as always. This is why it must be a multi-part video. We have a lot to cover!

Moving forward from that, we are going to go into Advanced Techniques, such as firewall/IDS/IPS evasion tactics, Packet Analysis, Reporting, Etc.

I will also be making a few videos in the interim, like, Building a real Virtual Lab using ProxMox (Free), Different types of attacks, like MITM, etc.

So Stay Tuned Guys! It's about to get really interesting!

New Trailer Uploaded!

Just a small taste of things to come in future Videos!




Update: New Intro

The New Video Intro:


Okay, Okay, so the new intro really didn't turn out to be a 3 minute or less intro like I planned, however it came out pretty awesome as a Trailer of things to come in the next few videos. It's basically me beating up some boxes on the LAN :-) Video link to follow post upload!

I do still think that the very beginning of the Trailer video has potential to be good footage for an intro to new videos. I just need to edit the intro start song to be 30 seconds but still sound good! I think I can, I think I can!

Rendering video now, and uploading soon!

Monday, June 10, 2013

It's Monday!

Hey Guys,

Hope you enjoyed your weekend. I apologize for making a post so late in the day, but, well, it's Manic Monday here!

The day is un-winding now. I am hoping to get the new intro done today/tonight. Then I want to move onto getting my virtual lab finished so we can resume Hacking the machines in there on the videos. I am going to redo the lab, because I want to further segment it, and put a Virtual Router/Firewall in place to simulate real world excersizes on how to perform firewall evasion.

I will also do a video on setting up your own Virtual Lab as has been requested by one of our members!

I am also thinking of creating a forum where we can ask questions, get help, etc. This idea I am not sure about quite yet.

Enough out of me! Back to work! :-)

EDIT:

I think what we are going to do is save the Virtual Firewall for the Advanced Video Tutorials.

I really want to get into showing you guys some examples of hacking machines. Then we will do a Virtual Lab setup, and then I will re-do the lab and setup the virtual firewall, fire it up on a Public IP, and show advanced techniques in terms of firewall evasion, etc.  

Saturday, June 8, 2013

Happy Saturday!

Hey Guys,

I hope you are enjoying your weekend so far! On Monday I am going to move forward with getting the rest of the Virtual Machines created and configured. I Have ran into a few snags, and that is to be expected since I have never used ProxMox to host VM's before. Since I am lacking the proper hardware to make windows play nicely in ProxMox, it's a bit challenging. I will however press on.

In the meantime, keep reading, and learning.

Do you guys have any suggestions for future videos? Let me know!

And as always Thank You for your feedback, and support! Keep sharing the videos, and our YouTube, facebook, and blog pages!