How to make Millions $$$ hacking zero days?

  Рет қаралды 142,567

David Bombal

David Bombal

Күн бұрын

Пікірлер: 179
@_JohnHammond
@_JohnHammond Жыл бұрын
You got STEPHEN SIMS to join the party here!??!? JEALOUS! Great stuff as always!!
@davidbombal
@davidbombal Жыл бұрын
lol... great to see you here John! We need to talk and get you back on the channel!
@macktheripper7454
@macktheripper7454 Жыл бұрын
What he says about sacrifice is totally right. I wake up at 5am, workout and then study for at least 2 hours before running my business. I’m tired a lot but I’ve completed 3 courses in a little over a year. Starting an api hacking course in January. 💪 thanks for another great video David
@ochiojie
@ochiojie Жыл бұрын
Hey bro! Did you have previous experience with APIs before starting API hacking?
@macktheripper7454
@macktheripper7454 Жыл бұрын
@@ochiojie nope, not at all. Websites and network based hacking mainly
@corail53
@corail53 Жыл бұрын
That sounds more like a luxury than a sacrifice. Waking at 5 am is not a special feat and having 2 hours of spare time to be able to study before work is a luxury most don't have.
@ochiojie
@ochiojie Жыл бұрын
@@macktheripper7454 I was thinking of starting it but thought I had to have some previous knowledge thanks man. Also I apologize for responding late.
@macktheripper7454
@macktheripper7454 Жыл бұрын
@corail53 it's not a luxury. I have my own business, I'm just efficient at running it.
@iamwithyou1184
@iamwithyou1184 Жыл бұрын
My request Stephen to complete playlist on Exploit development from beginners to pro level and thanks to David it's an awesome session
@jamesrobertson2712
@jamesrobertson2712 Жыл бұрын
Absolutely fantastic video. I have calculated it will probably take me about 750 years to get anywhere near the level of knowledge displayed here. Either way, I have started writing that Windows driver, using Kernel-Mode Driver Framework (KMDF)...which I had to google.
@robd.2466
@robd.2466 Жыл бұрын
Tremendous interview, David. Thank you for these. Incredibly interesting and informative.
@cybercashz
@cybercashz Жыл бұрын
I don't know how you do it , I just searched for exploit development thought would be good for my skill set and you just released this video. I love your content helped me alot in my work I really wish you grow more and keep bringing this amazing content. Bless you!!!
@ashwanthbalajir5153
@ashwanthbalajir5153 Жыл бұрын
This is what I am waiting for. Thanks David
@davidbombal
@davidbombal Жыл бұрын
Very happy to hear that!
@sudhanshusingh-yo6nc
@sudhanshusingh-yo6nc Жыл бұрын
@@davidbombal i want learn exploit development in free can you give me roadmap and platform
@graham-moss
@graham-moss Жыл бұрын
Love hearing about the more advanced stuff. Having a roadmap is very helpful even if you end up taking a different path. Just knowing how to get started is a huge help.
@Naath000
@Naath000 Жыл бұрын
thank you david sir for taking stephen sir interview that interview helped me to clearify most of the things for better future
@davidbombal
@davidbombal Жыл бұрын
You're welcome! And I'm very happy to that that!
@davidbombal
@davidbombal Жыл бұрын
It's possible to earn millions of dollars finding zero days and vulnerabilities in software. But, are you prepared to put in the work? Browser Exploitation Introduction: kzbin.info/www/bejne/mJTRh2Sal8t-mac Introduction to Buffer Overflows: kzbin.info/www/bejne/enmmpqmDm6x_ibc Modern Windows Kernel Exploitation: kzbin.info/www/bejne/pJLYcp9-jdeef80 Linux Heap Exploitation: kzbin.info/www/bejne/mn6noHZvedGJsKM Modern Binary/Patch Diffing: kzbin.info/www/bejne/bpu5gKmGfJmHoKM Crypto and Blockchain Hacks: kzbin.info/www/bejne/r2atoJqKnNWjY9U My apologies for some of the technical issues in this interview. Zoom is a nightmare :( // MENU // 00:00 - Coming up 00:53 - Stephen Sims introduction & Sans course 03:28 - Stephen's KZbin channel // Off By One Security 07:56 - Growing up with computers 08:57 - Getting involved with Sans courses // Impressed by instructors 09:52 - "The Golden Age of Hacking" // Bill Gates changed the game 15:44 - Making money from Zero-Days // Ethical and Unethical methods, zerodium.com & safety tips 32:56 - How to get started 46:53 - Opportunities in Crypto 50:26 - Windows vs. iOS vs. Linux 53:47 - Which programming language to start with 56:22 - Recommended Sans courses 01:02:04 - Recommended CTF programs & events 01:04:06 - Recommended books 01:08:23 - The Vergilius project 01:10:25 - Connect with Stephen Sims 01:12:24 - Conclusion // Stephen's Social // Twitter: twitter.com/Steph3nSims KZbin Live: www.youtube.com/@OffByOneSecurity/streams KZbin videos: www.youtube.com/@OffByOneSecurity/videos E-mail: Stephen(at)deadlisting.com // Stephen's courses // SANS Course sans.org. www.sans.org/cyber-security-courses/ - Advanced exploit development for penetration testers course - Advanced penetration testing, exploit writing, and ethical hacking (GXPN) - ARM Exploit Development // Books discussed // Grey Hat Hacking: amzn.to/3B1FeIK Hacking: The art of Exploitation: amzn.to/3Us9Uts The Shellcoder’s Handbook: amzn.to/3VqUEhY Linkers & Loaders: amzn.to/3itqtbe // Websites discussed // Zerodium: zerodium.com/ Corelan Cybersecurity Research: www.corelan.be/ Shellphish: github.com/suljot/shellphish Vergilius Project: www.vergiliusproject.com/ // David's Social // Discord: discord.gg/davidbombal Twitter: twitter.com/davidbombal Instagram: instagram.com/davidbombal LinkedIn: www.linkedin.com/in/davidbombal Facebook: facebook.com/davidbombal.co TikTok: tiktok.com/@davidbombal KZbin Main Channel: kzbin.info KZbin Tech Channel: kzbin.info/door/ZTIRrENWr_rjVoA7BcUE_A KZbin Clips Channel: kzbin.info/door/bY5wGxQgIiAeMdNkW5wM6Q KZbin Shorts Channel: kzbin.info/door/EyCubIF0e8MYi1jkgVepKg Apple Podcast: davidbombal.wiki/applepodcast Spotify Podcast: open.spotify.com/show/3f6k6gERfuriI96efWWLQQ
@Blackibangalore
@Blackibangalore Жыл бұрын
Please share where we can find free classes and books to study sir@ @davidbombal
@PortSwigger-ho3ye
@PortSwigger-ho3ye Жыл бұрын
thanks for posting such a precious content
@decoder6878
@decoder6878 Жыл бұрын
Thanks a lot David and Stephen for this wonderful discussion. I'm very interested in binary exploration and was looking forward more details on related platforms. This was very helpful.
@ANTGPRO
@ANTGPRO Жыл бұрын
Great topic, David. Thanks!
@davidbombal
@davidbombal Жыл бұрын
You're welcome! Glad you enjoyed the video :)
@kevinnevs2666
@kevinnevs2666 Жыл бұрын
Loved this video. Very inspirational & informative. Thank you David.
@ali_linux5097
@ali_linux5097 Жыл бұрын
The Best Videos on youtube Thx David for Your Time Giving to us 💖💖💖
Жыл бұрын
When I hear these topics if feel there's an entire universe to discover in a digital realm. One can only learn and specialize a certain direction and still be memorized of the vastness of knowledge, tools, techniques available.
@nathanchan1900
@nathanchan1900 Жыл бұрын
Thanks for initiating the talk with Steven. Now, to find some good zero-days for ZDI.
@mukbangheat3080
@mukbangheat3080 Жыл бұрын
awesome content as always, keep what you're doing. thanks David
@ThatNiceDutchGuy
@ThatNiceDutchGuy Жыл бұрын
Setting a reasonable goal and path towards it, execute and stick to it. It does sound rather easy, however it is not. Great podcast, as always! Thank you for sharing.
@CyberDevilSec
@CyberDevilSec Жыл бұрын
I feel like he's my lost brother We have a lot in common. I look almost identical to him. Green gray blue eyes stretch etc. Secondly i relate to him because I was basically born with a computer and always had a curiosity. And I also have the exact same black guitar 😁🎸 Rock on brother 🤘🤘I hope I can speak with you
@emmetgwilliam6527
@emmetgwilliam6527 Жыл бұрын
Thanks for the good video on exploits and vulnerability’s I’ve tested a few vulnerabilities before
@davidbombal
@davidbombal Жыл бұрын
You're welcome! Stephen has amazing content on his KZbin channel.
@vardhangoud8851
@vardhangoud8851 Жыл бұрын
Here is the Game changer content🔥
@davidbombal
@davidbombal Жыл бұрын
Hope you enjoy the video Vardhan! Also check out the amazing training that Stephen has on his KZbin channel.
@vardhangoud8851
@vardhangoud8851 Жыл бұрын
@@davidbombal In previous video in my comment, one fraud replayed me with ur name like you won something prize Dm in telegram. I just ignored the message
@ayushmishra5410
@ayushmishra5410 Жыл бұрын
(@@davidbombal) my chipset supports monitor mode but airodump-ng doesn't show any targets , Anyone knows how to fix ?
@ranjanadissanayaka5390
@ranjanadissanayaka5390 Жыл бұрын
Amazing video... Thanks for both of you.
@PeterAdiSaputro
@PeterAdiSaputro Жыл бұрын
Advanced knowledges beyond what I've learned and knew so far. Need to learn a lot more.
@rhinofart89
@rhinofart89 Жыл бұрын
SANS is the country club in the world of cybersecurity. I’d literally have to pay 1/3 of my yearly salary to take a 6 day course. SANS in essence is saying you must already be successful to be successful in cybersecurity.
@rhinofart89
@rhinofart89 Жыл бұрын
Will definitely be subscribing to his KZbin channel though.
@gilbertohernandez9223
@gilbertohernandez9223 Жыл бұрын
We need this guy back asap
@user-uk5qk1zo4k
@user-uk5qk1zo4k Жыл бұрын
Thanks for this one, was looking for ages how to start with a clear roadmap, would be nice to have him back to discuss malwares like Shikitega or eternal blue etc
@ragnarok55
@ragnarok55 Жыл бұрын
20 years experience guy said you can't be a expert in every subject 👍 but my KZbin feed destructed myself to learn everything 😂
@davidroach112
@davidroach112 Жыл бұрын
Took a Sans class taught by Mr. Simms. The guy is legit.
@skytechbits
@skytechbits Жыл бұрын
I know what the benefit to a company like Verisign would have by buying those exploits that way. They sell SSL certificates which effects every website everywhere. It is a benefit for them to accept top bug bounty finds than to pay employees to look around for such problems that need fixed. Then directly talking to their clients and the corporations who advocates SSL certificates which are becoming a standard. They can go out of business if their SSL become useless. MS now controls hardware with TPM which is their security key.
@AMCSec
@AMCSec Жыл бұрын
My mind in frazzled 😵‍💫 great video!
@timcyb
@timcyb Жыл бұрын
Thanks for the amazing contents
@fsydlx4546
@fsydlx4546 Жыл бұрын
Thank You David!
@davidbombal
@davidbombal Жыл бұрын
You're welcome!
@CyberDevilSec
@CyberDevilSec Жыл бұрын
Awesome stuff David as always 🔥
@davidbombal
@davidbombal Жыл бұрын
Thank you! You're welcome :)
@CyberDevilSec
@CyberDevilSec Жыл бұрын
@@davidbombal I do my best 😃
@cipi5
@cipi5 Жыл бұрын
oh snaps! i love exploit dev training! thanks david!
@fernandopierola
@fernandopierola Жыл бұрын
Amazing Video David and Stephens!!! Thanks so so much
@jaiminpatel2784
@jaiminpatel2784 Жыл бұрын
Thank you sir!
@davidbombal
@davidbombal Жыл бұрын
You are welcome!
@Z0nd4
@Z0nd4 Жыл бұрын
Amazing, OMG. Awesome content David, thank you very much! I have met these spectacular professionals thanks to your channel
@PortSwigger-ho3ye
@PortSwigger-ho3ye Жыл бұрын
your content is always FIRE Sir!
@Kodlak15
@Kodlak15 Жыл бұрын
I find this stuff fascinating. Thank you for the talk, appreciate you and your content!
@itzdm0r3
@itzdm0r3 10 ай бұрын
Stephen's SANS class sound pretty cool, also good talk!
@lunhamegenogueira1969
@lunhamegenogueira1969 Жыл бұрын
This was a great talk! Thanks for bringing another guru to light lol! Much appreciated!
@DevilsReject765
@DevilsReject765 Жыл бұрын
Thanks David 😊
@davidbombal
@davidbombal Жыл бұрын
You're welcome!
@prodigyprogrammer3187
@prodigyprogrammer3187 Жыл бұрын
Exactly what i wanted
@davidbombal
@davidbombal Жыл бұрын
Very happy to hear that!
@alisenjary
@alisenjary Жыл бұрын
Thank you 🌹
@davidbombal
@davidbombal Жыл бұрын
You’re welcome 😊
@ojochegbe_
@ojochegbe_ Жыл бұрын
Thanks David 🖤❤️
@davidbombal
@davidbombal Жыл бұрын
You're welcome!
@davidrobertson1980
@davidrobertson1980 Жыл бұрын
Good Onya David, you're a ledge ;) and many thanks to Stephen
@PhilosophyEpochs
@PhilosophyEpochs Жыл бұрын
love your content sir
@davidbombal
@davidbombal Жыл бұрын
Thank you!
@rickrick444x
@rickrick444x Жыл бұрын
I like your friend skill that behind the curtain and love your videos also 😍😍😍 I m a c.s.e student really want to learn how to work on language but never understand R.I.P mostly one flaw is Indian teachers 😔 they are followed books not any practicals but now a days study is different I m fast a learner in computing and electronics but when I studied my time is bad I have no teacher like today 😔.
@miresoman1769
@miresoman1769 Жыл бұрын
your english is lit
@notorioussil7646
@notorioussil7646 Жыл бұрын
very very good and interesting interview. Top notch stuff!!
@Chrisnakano
@Chrisnakano Жыл бұрын
Most people are taught that "you only need a good job to become rich". These billionaires are operating on a whole other playbook that many don't even know exists.
@xavierclifford174
@xavierclifford174 Жыл бұрын
@johnnie9888
@johnnie9888 Жыл бұрын
@hakem739
@hakem739 Жыл бұрын
Thank you. I love your channel
@nitinjangra653
@nitinjangra653 Жыл бұрын
Thanku sir
@davidbombal
@davidbombal Жыл бұрын
You're welcome!
@red-zi7fg
@red-zi7fg Жыл бұрын
David interviewing Matchbox 20 :)
@willredmambo3777
@willredmambo3777 Жыл бұрын
Awesome stuff
@davidbombal
@davidbombal Жыл бұрын
Thank you!
@izzy9ish
@izzy9ish Жыл бұрын
🔥🔥🔥🔥 Content keep them videos coming 🎥
@davidbombal
@davidbombal Жыл бұрын
Thank you! Lots of great content coming soon :)
@stephenrankin3941
@stephenrankin3941 Жыл бұрын
hey David, how would you rate hack the box academy? I've been considering going for their bug bounty hunter course, I'm just wo dering if my time would be better spent somewhere else.
@ghninoumehdi9516
@ghninoumehdi9516 Жыл бұрын
Thank you so much! This is very instructive
@AliRagabali
@AliRagabali 9 ай бұрын
Best video ever on the channel, thank you so much
@RoyalNatangwe
@RoyalNatangwe Жыл бұрын
just started my journey in C and Assembly but though this is good information🔥🔥🔥 it is a bit more oriented for intermediate users. wish he recommended books for complete beginners as the way he emphasised on starting with building blocks, books like Hacking the Art of Exploitation when I first bought it, I initially thought it's a complete book but it just made me realise how much I don't know, that I needed to search up more before I understood a certain complex topic.....but ey its life of refusing to be a script kiddie😂😂😂
@don156
@don156 Жыл бұрын
If you're just starting in C I think "C Programming Absolute Beginner's Guide" is a great place to start
@ArSiddharth
@ArSiddharth Жыл бұрын
will someone help me, my college website is using old version of php (php5) So what should I do, See also Exploits of the Exploits Database but they are many, There are many vulnerabilities from PHP 5 to the latest version
@ashace6092
@ashace6092 Жыл бұрын
Thank you
@davidbombal
@davidbombal Жыл бұрын
You're welcome! I hope the video helps you!
@patrickparson9628
@patrickparson9628 Жыл бұрын
Great work. Beautiful.
@hendahmed2408
@hendahmed2408 Жыл бұрын
is it still not working😢? iam starting my pentesting course, i have mac m1pro so u think i should seal it and buy windows?beacuse as you say some tools doesnt work?
@malua7021
@malua7021 Жыл бұрын
Nice David..
@brycegalbraith6375
@brycegalbraith6375 Жыл бұрын
Outstanding.
@Ghislo
@Ghislo Жыл бұрын
super inspiring omg thanks for this
@WarrenKirkpatrick
@WarrenKirkpatrick Жыл бұрын
Went to check the website out and the beginner course, the fundamentals, was like $7k… I mean wow..
@incognitohacks4850
@incognitohacks4850 Жыл бұрын
Would you recommend using a vm or an old laptop you found lying around for practice?
@johnhyhintchmn3674
@johnhyhintchmn3674 Жыл бұрын
Cant wait
@rev.kenshostad2888
@rev.kenshostad2888 11 ай бұрын
@41:00 Practice makes perfect... PERIOD... Time is the only REAL commodity we have, all have to start somewhere and once known practice practice practice...
@supriyoguha5421
@supriyoguha5421 Жыл бұрын
Amazing Content @David.....
@pradyumgupta9711
@pradyumgupta9711 8 ай бұрын
"litigation" is a word used a lot in this video, just wondering what that is exactly with respect to security. New in the industry.
@wingwing2683
@wingwing2683 7 ай бұрын
Thank you very much!
@Nigashm
@Nigashm Жыл бұрын
Thank you sir
@davidbombal
@davidbombal Жыл бұрын
You're welcome!
@jarsal_firahel
@jarsal_firahel Жыл бұрын
Hey David, would you do a video on browser fingerprinting ?
@AliYar-Khan
@AliYar-Khan Жыл бұрын
David you are love man ❤️😇
@MegaFeedee
@MegaFeedee Жыл бұрын
Thank you VERY much for this awesome content, David! . . . . . Corgee hacks you 2 please...
@C1t1z3n1
@C1t1z3n1 Жыл бұрын
Have him show us how to do a buffer overflow.
@zemourizemouri2406
@zemourizemouri2406 Жыл бұрын
Amazing video!!!
@privilegedesign8745
@privilegedesign8745 Жыл бұрын
I have it this PDF book but is really hard go with it when you have some knowledge I stopped for later I need more knowledge
@sudhanshusingh-yo6nc
@sudhanshusingh-yo6nc Жыл бұрын
i want learn exploit development can you help me
@NoName-ey9hy
@NoName-ey9hy Жыл бұрын
No fluff❤❤❤
@davidbombal
@davidbombal Жыл бұрын
Stephen has amazing content on his KZbin channel. Please go and subscribe :)
@yungdnny
@yungdnny Жыл бұрын
Are you really a hacker if your webcam isn't half frozen? (i'm just teasing bc linux seems to struggle with screen tearing so much and i thought it was my pc)
@elywacime5411
@elywacime5411 Жыл бұрын
Is that a Gibson in the background
@hackmedia7755
@hackmedia7755 Жыл бұрын
common lisp has a lot of advanced features and doesn't have many security vulnerabilities like many other languages.
@hustle717
@hustle717 Жыл бұрын
KZbinr Jay Williams "Lets live life" recently had his page hacked, any tips on getting it back?
@Oswee
@Oswee Жыл бұрын
Don't worry. We have a ChatGPT now. You better pick carpentry. :D
@catoshyare969
@catoshyare969 Жыл бұрын
David we want you to make some videos of basics of Linux. help
@mujahidAli-eg8qh
@mujahidAli-eg8qh Жыл бұрын
That's Crazy bro
@davidbombal
@davidbombal Жыл бұрын
Hope you enjoy the video and learn a lot Mujahid! Also check out the amazing training that Stephen has on his KZbin channel.
@anishgoud651
@anishgoud651 Жыл бұрын
There is any certification for automotive cybersecurity ??
@guilherme5094
@guilherme5094 Жыл бұрын
👍👍!
@mohammadamiry7385
@mohammadamiry7385 Жыл бұрын
please make of iot full Introduction and about attacking and hacking it I need it for my monograph please
@rhinofart89
@rhinofart89 Жыл бұрын
Can he come back and talk about hooking system calls
@Sevo.yt.....
@Sevo.yt..... Жыл бұрын
My files are encrypted with ransomware can u help to decrypt them
@420yttsantsujzttad
@420yttsantsujzttad Жыл бұрын
Gud video 👍
@davidbombal
@davidbombal Жыл бұрын
Thank you!
@michaelnieves8087
@michaelnieves8087 8 ай бұрын
I can't find that book he mentioned "Journey Into Ring 0"
@PUITKH
@PUITKH Жыл бұрын
❤😊
@davidbombal
@davidbombal Жыл бұрын
Thank you!
@cdcrjp2nft867
@cdcrjp2nft867 Жыл бұрын
I been validating exploits on multiple platforms still no deal
@hawk__
@hawk__ Жыл бұрын
Hey david, it's shellphish - and not fishshell ;)
@SiamYaya-s4h
@SiamYaya-s4h Жыл бұрын
انا ارغب فى هذه البرمجة ولكن لا عرف عنها شي اني صفر هل ممكن ان اتبدي وكم مدة سياخذني
@bhagyalakshmi1053
@bhagyalakshmi1053 Жыл бұрын
Deck ,shell to open class
@MrCriistiano
@MrCriistiano Жыл бұрын
Vista was great and you can't change my mind
Is Skynet watching you already?
1:04:00
David Bombal
Рет қаралды 1,1 МЛН
Be Invisible Online and Hack like a Ghost
54:09
David Bombal
Рет қаралды 355 М.
pumpkins #shorts
00:39
Mr DegrEE
Рет қаралды 125 МЛН
啊?就这么水灵灵的穿上了?
00:18
一航1
Рет қаралды 77 МЛН
Сюрприз для Златы на день рождения
00:10
Victoria Portfolio
Рет қаралды 2,4 МЛН
Don't look down on anyone#devil  #lilith  #funny  #shorts
00:12
Devil Lilith
Рет қаралды 48 МЛН
2024 Roadmap to Master Hacker
54:38
David Bombal
Рет қаралды 187 М.
Ex-NSA hacker tells us how to get into hacking!
51:52
David Bombal
Рет қаралды 1,9 МЛН
What Does a Former Black Hat Hacker Carry Everyday?
27:05
Shawn Ryan Show
Рет қаралды 526 М.
Top Hacking Books for 2024 (plus Resources): FREE and Paid
59:45
David Bombal
Рет қаралды 151 М.
What's the Future of AI in Cybersecurity and Hacking (are we doomed)?
43:37
Edward Snowden: How Your Cell Phone Spies on You
24:16
JRE Clips
Рет қаралды 18 МЛН
Hackers Abuse Zero-Day Exploit for CrushFTP
31:49
John Hammond
Рет қаралды 69 М.
pumpkins #shorts
00:39
Mr DegrEE
Рет қаралды 125 МЛН