offensive operations - sploitlab · •passive (osint) • search engines (google dorks) • web...

60
@johnhsawyer [email protected] Offensive Operations John H. Sawyer Senior Managing Consultant InGuardians, Inc. Bryce Lay - Comsys

Upload: vuongtu

Post on 09-Apr-2018

235 views

Category:

Documents


6 download

TRANSCRIPT

Page 1: Offensive Operations - SploitLab · •Passive (OSINT) • Search Engines (Google Dorks) • Web archives • Newsgroups ... –Lowes/Home depot craft time! • Other methods of access

@johnhsawyer [email protected]

OffensiveOperationsJohnH.Sawyer

SeniorManagingConsultantInGuardians,Inc.

BryceLay- Comsys

Page 2: Offensive Operations - SploitLab · •Passive (OSINT) • Search Engines (Google Dorks) • Web archives • Newsgroups ... –Lowes/Home depot craft time! • Other methods of access

@johnhsawyer [email protected]

WorkshopAgenda• Administrivia• IntroductiontoPenetrationTesting

• Reconnaissance• Physical• SocialEngineering• PostExploitation

Page 3: Offensive Operations - SploitLab · •Passive (OSINT) • Search Engines (Google Dorks) • Web archives • Newsgroups ... –Lowes/Home depot craft time! • Other methods of access

@johnhsawyer [email protected]

PurposeofthisWorkshop• Introductiontopenetrationtesting– Securityprofessionalsfocusedondefense– Systemsadministrators– Developers

• Hands-onwithCobaltStrikeandoffensivePowershelltools

• HaveFun!!

Page 4: Offensive Operations - SploitLab · •Passive (OSINT) • Search Engines (Google Dorks) • Web archives • Newsgroups ... –Lowes/Home depot craft time! • Other methods of access

@johnhsawyer [email protected]

WhoAmI?• InGuardiansSeniorManagingConsultant

– RedTeamOperator/PenetrationTester– SocialEngineering– Web,Mobile,andDesktopApps– IncidentResponse&Forensics

• DarkReadingandInformationWeekauthorandspeaker• Infosec VolunteerandMentor• DEFCON14/15CapturetheFlag(1@stplace)

Page 5: Offensive Operations - SploitLab · •Passive (OSINT) • Search Engines (Google Dorks) • Web archives • Newsgroups ... –Lowes/Home depot craft time! • Other methods of access

@johnhsawyer [email protected]

MyAwesomeEmployer• InGuardians,Inc.(formerlyIntelGuardians)• Founded2003byMikePoor,EdSkoudis,JayBeale,Jimmy

Alderson,andBobHillery• Ifit’ssecurity-related,wedoit.

– RedTeamAssessments– PenetrationTesting

• Network,Web,Mobile,Wireless,Hardware,People,andPhysical– IncidentResponseManagementandDigitalForensics

Page 6: Offensive Operations - SploitLab · •Passive (OSINT) • Search Engines (Google Dorks) • Web archives • Newsgroups ... –Lowes/Home depot craft time! • Other methods of access

@johnhsawyer [email protected]

ThankYou• MyWifeandfamily• BryceLay– ComSys• InteropTeam• InGuardians• UBM,DarkReading,andTimWilson

Page 7: Offensive Operations - SploitLab · •Passive (OSINT) • Search Engines (Google Dorks) • Web archives • Newsgroups ... –Lowes/Home depot craft time! • Other methods of access

@johnhsawyer [email protected]

PENETRATIONTESTINGIntroductionto

Page 8: Offensive Operations - SploitLab · •Passive (OSINT) • Search Engines (Google Dorks) • Web archives • Newsgroups ... –Lowes/Home depot craft time! • Other methods of access

@johnhsawyer [email protected]

VulnerabilityAssessment• “Avulnerabilityassessmentistheprocessofidentifying,quantifying,andprioritizing(orranking)thevulnerabilitiesinasystem.”

• Source:Wikipedia

• Whatabout..– Validation– Risktothebusiness

Page 9: Offensive Operations - SploitLab · •Passive (OSINT) • Search Engines (Google Dorks) • Web archives • Newsgroups ... –Lowes/Home depot craft time! • Other methods of access

@johnhsawyer [email protected]

PenetrationTest• “Apenetrationtest,ortheshortformpentest,isanattack

onacomputersystemwiththeintentionoffindingsecurityweaknesses,potentiallygainingaccesstoit,itsfunctionalityanddata.”

• Source:Wikipedia

• Mimicrealattackers• Showrealriskofvulnerabilities

Page 10: Offensive Operations - SploitLab · •Passive (OSINT) • Search Engines (Google Dorks) • Web archives • Newsgroups ... –Lowes/Home depot craft time! • Other methods of access

@johnhsawyer [email protected]

EvolutionofPenetrationTesting• AttackProcess• Recon• Scan• Gainaccess• Maintainaccess• Covertracks

• Pentest Methodology• Preparation• Recon• Scan• Exploit• Analysis• Report

Page 11: Offensive Operations - SploitLab · •Passive (OSINT) • Search Engines (Google Dorks) • Web archives • Newsgroups ... –Lowes/Home depot craft time! • Other methods of access

@johnhsawyer [email protected]

PenetrationTestingExecutionStd.• Pre-engagementinteractions• Intelligencegathering• Threatmodeling• Exploitation• Postexploitation• Reporting

Page 12: Offensive Operations - SploitLab · •Passive (OSINT) • Search Engines (Google Dorks) • Web archives • Newsgroups ... –Lowes/Home depot craft time! • Other methods of access

@johnhsawyer [email protected]

TypesofPenetrationTesting• Network

– Internal– External

• Application– Web– Mobile– Desktop

• Physical

• SocialEngineering– Email– Phone– Other(Social,In-person)

• Wireless– WiFi– OtherRF

• Hardware

Page 13: Offensive Operations - SploitLab · •Passive (OSINT) • Search Engines (Google Dorks) • Web archives • Newsgroups ... –Lowes/Home depot craft time! • Other methods of access

@johnhsawyer [email protected]

RedTeaming• Militaryorigins– practiceofviewingaproblemfromanadversaryorcompetitor'sperspective

• Long-term,persistentoperations– Monthstoyears

• Full-scope– Physical,socialengineering,web,mobile,wireless

Page 14: Offensive Operations - SploitLab · •Passive (OSINT) • Search Engines (Google Dorks) • Web archives • Newsgroups ... –Lowes/Home depot craft time! • Other methods of access

@johnhsawyer [email protected]

OffensiveTraits• Passion• Curiosity• Experience• Adaptability• Communication• Notafraidoffailure

• Diversebackground– sysadmin,developer,networkengineer

Page 15: Offensive Operations - SploitLab · •Passive (OSINT) • Search Engines (Google Dorks) • Web archives • Newsgroups ... –Lowes/Home depot craft time! • Other methods of access

@johnhsawyer [email protected]

LegalIssues• Jobdescription• Writtenpermission• Scope• RulesofEngagement

Page 16: Offensive Operations - SploitLab · •Passive (OSINT) • Search Engines (Google Dorks) • Web archives • Newsgroups ... –Lowes/Home depot craft time! • Other methods of access

@johnhsawyer [email protected]

Risks• DenialofService

– Networkcongestion/saturation– Serviceresourceexhaustion– Crash(BSOD,Segfault)

• Datacorruption• Datadestruction• Angrypeople

– Sysadmins,users,HR,Legal

Page 17: Offensive Operations - SploitLab · •Passive (OSINT) • Search Engines (Google Dorks) • Web archives • Newsgroups ... –Lowes/Home depot craft time! • Other methods of access

@johnhsawyer [email protected]

RECONNAISSANCEIntelligenceGathering

Page 18: Offensive Operations - SploitLab · •Passive (OSINT) • Search Engines (Google Dorks) • Web archives • Newsgroups ... –Lowes/Home depot craft time! • Other methods of access

@johnhsawyer [email protected]

Reconnaissance• Passive(OSINT)• SearchEngines(GoogleDorks)• Webarchives• Newsgroups,GoogleGroups• Whois,Robtex,CentralOps• Shodan,Censys,Netcraft• Socialnetworks• Pwnedlist,Breachalarm

• Active• Nmap• DNSinterrogation• Nessus,Nexpose,Metasploit• Arachni,Burp,wpscan• FOCA,metagoofil• Anythingthatactivelytouches

thetargetnetwork

Page 19: Offensive Operations - SploitLab · •Passive (OSINT) • Search Engines (Google Dorks) • Web archives • Newsgroups ... –Lowes/Home depot craft time! • Other methods of access

@johnhsawyer [email protected]

SearchEngines• “GoogleDorks”• BishopFoxSearchDiggity– GoogleDiggity,BingDiggity,BingLinkFromDomainDiggity– CodeSearchDiggity,DLPDiggity,FlashDiggity– MalwareDiggity,PortScanDiggity,SHODANDiggity– BingBinaryMalwareSearch,andNotInMyBackYard Diggity.

• http://www.bishopfox.com/resources/tools/google-hacking-diggity/attack-tools/

Page 20: Offensive Operations - SploitLab · •Passive (OSINT) • Search Engines (Google Dorks) • Web archives • Newsgroups ... –Lowes/Home depot craft time! • Other methods of access

@johnhsawyer [email protected]

Shodan.io• “Shodan istheworld'sfirstsearchengineforInternet-connecteddevices.”

• http://www.shodanhq.com/help/filters– net,os,city,country,geo,hostname,port,before/after

Page 21: Offensive Operations - SploitLab · •Passive (OSINT) • Search Engines (Google Dorks) • Web archives • Newsgroups ... –Lowes/Home depot craft time! • Other methods of access

@johnhsawyer [email protected]

Shodan Tools• ManytoolsleverageShodan– Spiderfoot,Maltego,etc.

• Shodan API– Pythonandrubylibraries

• Metasploit shodan_search module

Page 22: Offensive Operations - SploitLab · •Passive (OSINT) • Search Engines (Google Dorks) • Web archives • Newsgroups ... –Lowes/Home depot craft time! • Other methods of access

@johnhsawyer [email protected]

Nmap• Networkportscanner• TCPandUDP• OSfingerprinting• Servicefingerprinting• Nmap ScriptingEngine– Advancedchecks– Vulnerabilitydetection

Page 23: Offensive Operations - SploitLab · •Passive (OSINT) • Search Engines (Google Dorks) • Web archives • Newsgroups ... –Lowes/Home depot craft time! • Other methods of access

@johnhsawyer [email protected]

Spiderfoot• Automatesmuchofthereconprocess• FreeandOpenSource• RunsunderLinuxandWindows

• cd/opt/spiderfoot• python./sf.py• http://127.0.0.1:5001

Page 24: Offensive Operations - SploitLab · •Passive (OSINT) • Search Engines (Google Dorks) • Web archives • Newsgroups ... –Lowes/Home depot craft time! • Other methods of access

@johnhsawyer [email protected]

Eyewitness• Screenshotsofwebapplications• Multipleformatimport(nmap,Nessus)• Serverheaders• PageSource• DefaultCreds• Alternatives– peepingtom,httpscreenshot,Spart

Page 25: Offensive Operations - SploitLab · •Passive (OSINT) • Search Engines (Google Dorks) • Web archives • Newsgroups ... –Lowes/Home depot craft time! • Other methods of access

@johnhsawyer [email protected]

SOCIALENGINEERINGBecausethereisnopatchforhuman…

Page 26: Offensive Operations - SploitLab · •Passive (OSINT) • Search Engines (Google Dorks) • Web archives • Newsgroups ... –Lowes/Home depot craft time! • Other methods of access

@johnhsawyer [email protected]

SocialEngineeringDefined• Theactofinfluencingsomeonetotakeanactionthatmayormaynotbeintheirbestinterest.

Page 27: Offensive Operations - SploitLab · •Passive (OSINT) • Search Engines (Google Dorks) • Web archives • Newsgroups ... –Lowes/Home depot craft time! • Other methods of access

@johnhsawyer [email protected]

ExampleCareers• Doctors• Therapists• Radiohosts• Schoolteachers• Counselors• Lawenforcement

Page 28: Offensive Operations - SploitLab · •Passive (OSINT) • Search Engines (Google Dorks) • Web archives • Newsgroups ... –Lowes/Home depot craft time! • Other methods of access

@johnhsawyer [email protected]

WhyDoesItWork?• Desiretobehelpful– ParAvion

• Tendencytotrustpeople• Fearofgettingintotrouble– Daisy

• Willingnesstocutcorners• http://www.social-engineer.org/framework

Page 29: Offensive Operations - SploitLab · •Passive (OSINT) • Search Engines (Google Dorks) • Web archives • Newsgroups ... –Lowes/Home depot craft time! • Other methods of access

@johnhsawyer [email protected]

SomeGuidelines• GoldenRule– Leavesomeonebetterforhavingmetyou

• Manipulation– Thinkscamandpickupartists– Leavepeoplefeeling“dirty”orcheated• ChrisandMichelesurvey

Page 30: Offensive Operations - SploitLab · •Passive (OSINT) • Search Engines (Google Dorks) • Web archives • Newsgroups ... –Lowes/Home depot craft time! • Other methods of access

@johnhsawyer [email protected]

SocialEngineeringMethodology• InformationGathering• PretextDevelopment• AttackPlanning• PerformAttacks• Reporting

Page 31: Offensive Operations - SploitLab · •Passive (OSINT) • Search Engines (Google Dorks) • Web archives • Newsgroups ... –Lowes/Home depot craft time! • Other methods of access

@johnhsawyer [email protected]

ElementsofaGoodPhish• Urgesrecipienttotakeaction• Targetsanemotionalresponse• Mimicscontentforatrustedsource• Spoofsthesourcetoappearlegitimate• Bypassesmailsecuritycontrols

– http://arstechnica.com/information-technology/2014/02/16/how-to-run-your-own-e-mail-server-with-your-own-domain-part-1/

Page 32: Offensive Operations - SploitLab · •Passive (OSINT) • Search Engines (Google Dorks) • Web archives • Newsgroups ... –Lowes/Home depot craft time! • Other methods of access

@johnhsawyer [email protected]

SomeReconTools• theharvester

– ThisisincludedontheVM• FOCA

– Windowsonly– Findsdocsandpulls

metadataincludingusernames,softwareversions,servers,networkshares.

• Maltego– Helpstoidentify

relationshipsbetweenhosts,networks,identitiesandmore.

• metagoofil– Metadatasearchand

extractor– Alittledatedbutstillvery

useful

Page 33: Offensive Operations - SploitLab · •Passive (OSINT) • Search Engines (Google Dorks) • Web archives • Newsgroups ... –Lowes/Home depot craft time! • Other methods of access

@johnhsawyer [email protected]

PHYSICALOliviaNewtonJohnwantstoget…

Page 34: Offensive Operations - SploitLab · •Passive (OSINT) • Search Engines (Google Dorks) • Web archives • Newsgroups ... –Lowes/Home depot craft time! • Other methods of access

@johnhsawyer [email protected]

Physical• Havingphysicalaccessrequireslittle/noexploitstocompromise

– Itisevenmorefunwhenitdoes!

• Thinkaboutwhatanattackercoulddoiftheyhavephysicalaccessto• areceptionist’sworkstation• anITstaffmember’sworkstation• anetworkcloset/IDF• yourdatacenter…• Physicalaccessisoftenconsidered“gameover”

Page 35: Offensive Operations - SploitLab · •Passive (OSINT) • Search Engines (Google Dorks) • Web archives • Newsgroups ... –Lowes/Home depot craft time! • Other methods of access

@johnhsawyer [email protected]

DressthePart• Backtopowersofobservation…byothers

– Howwillstaffperceiveyouintheorganization?• Howareotherdressed?

– Construction– FireExtinguisherinspection– Packagedelivery*– Repairtechnician*

• Casualofficeorprofessionaldress

Page 36: Offensive Operations - SploitLab · •Passive (OSINT) • Search Engines (Google Dorks) • Web archives • Newsgroups ... –Lowes/Home depot craft time! • Other methods of access

@johnhsawyer [email protected]

Tools• Few“technical”toolsexisthere

– Unlesswetalkprox/pinpad– Mostoccasionsdon’trequireanythingtechnical

• Mostpowerfultoolforthispartisyourbrain– Time,creativityandpatience– Thinkingoutsideofthebox– Hacking“hardware”fromthedumpster

• Howminorgapsinimplementationcanbeused

Page 37: Offensive Operations - SploitLab · •Passive (OSINT) • Search Engines (Google Dorks) • Web archives • Newsgroups ... –Lowes/Home depot craft time! • Other methods of access

@johnhsawyer [email protected]

RFIDTools&RubberDucky• https://proxmark3.com• https://www.bishopfox.com/resources/tools/rfid-hacking/attack-tools/

• http://hakshop.myshopify.com/products/usb-rubber-ducky-deluxe?variant=353378649

Page 38: Offensive Operations - SploitLab · •Passive (OSINT) • Search Engines (Google Dorks) • Web archives • Newsgroups ... –Lowes/Home depot craft time! • Other methods of access

@johnhsawyer [email protected]

PowersofObservation(1)• Observinghowphysicalsecuritysystemsareimplemented!• Observingthemovementsofothersperalongperiodoftime• Wheredocameraspoint?Aretheymonitoredactivelyor

reactively?• Howdodoorsunlockfromtheoutside?

– Howdotheyunlockfromthe inside?– Motionsensor?Capacitivetouchbar?– Whatsidearethehingeson?

Page 39: Offensive Operations - SploitLab · •Passive (OSINT) • Search Engines (Google Dorks) • Web archives • Newsgroups ... –Lowes/Home depot craft time! • Other methods of access

@johnhsawyer [email protected]

PowersofObservation(2)• Underdoorgaps?Gapsindoorframes?

– Whatcanweuseoutofthedumpster?– Lowes/Homedepotcrafttime!

• Othermethodsofaccess– Balconies– LoadingDocks

• Unmotivated/Laxbuildingsecurity• Whatdobadgeslooklike?Totheinternet!

Page 40: Offensive Operations - SploitLab · •Passive (OSINT) • Search Engines (Google Dorks) • Web archives • Newsgroups ... –Lowes/Home depot craft time! • Other methods of access

@johnhsawyer [email protected]

SocialEngineering• Thisisagameuntoitself– Somanysubtleties

• TL;DR,itisagameofconfidence– Actlikeyoubelong– Playthepart– “Hey,how’sitgoing?”

Page 41: Offensive Operations - SploitLab · •Passive (OSINT) • Search Engines (Google Dorks) • Web archives • Newsgroups ... –Lowes/Home depot craft time! • Other methods of access

@johnhsawyer [email protected]

Policies• Physicalsecuritydesignattimeofbuild– JustlikeDevOps,bakeinsecurity

• Tailgating• Reportingofsuspiciousactivity• Auditandobserveadherencetopolicy

Page 42: Offensive Operations - SploitLab · •Passive (OSINT) • Search Engines (Google Dorks) • Web archives • Newsgroups ... –Lowes/Home depot craft time! • Other methods of access

@johnhsawyer [email protected]

GETTINGAFOOTHOLDOMG!TheyopenedtheMACRO!!1!1!

Page 43: Offensive Operations - SploitLab · •Passive (OSINT) • Search Engines (Google Dorks) • Web archives • Newsgroups ... –Lowes/Home depot craft time! • Other methods of access

@johnhsawyer [email protected]

Responder• PassiveandActiverecon• Exploitation(LLMNR,NBT-NS,DNS,MDNS)

• Stealpasswordhashesandcrackwithjohn/hashcat

• https://github.com/lgandx/Responder-Windows

Page 44: Offensive Operations - SploitLab · •Passive (OSINT) • Search Engines (Google Dorks) • Web archives • Newsgroups ... –Lowes/Home depot craft time! • Other methods of access

@johnhsawyer [email protected]

Inveigh• LLMNR,mDNS,andNBNS

spoofer• Man-in-the-middletool• HTTP/HTTPS/Proxy

listeners• Slimmeddown,Powershell

versionofResponder

Page 45: Offensive Operations - SploitLab · •Passive (OSINT) • Search Engines (Google Dorks) • Web archives • Newsgroups ... –Lowes/Home depot craft time! • Other methods of access

@johnhsawyer [email protected]

PasswordCracking• CrackthehashescapturedfromResponderusing:– johntheripper– hashcat

Page 46: Offensive Operations - SploitLab · •Passive (OSINT) • Search Engines (Google Dorks) • Web archives • Newsgroups ... –Lowes/Home depot craft time! • Other methods of access

@johnhsawyer [email protected]

POWERSHELLIt’severywhereyouwanttobe…

Page 47: Offensive Operations - SploitLab · •Passive (OSINT) • Search Engines (Google Dorks) • Web archives • Newsgroups ... –Lowes/Home depot craft time! • Other methods of access

@johnhsawyer [email protected]

OffensivePowershell• Greatforbypassingantivirus

andapplicationwhitelisting• OncurrentWindows

workstationandserveroperatingsystems

• MoreoffensivetoolsareleveragingPowershell

• Thebadguysareusingit,too!

Page 48: Offensive Operations - SploitLab · •Passive (OSINT) • Search Engines (Google Dorks) • Web archives • Newsgroups ... –Lowes/Home depot craft time! • Other methods of access

@johnhsawyer [email protected]

Powershell ExecutionPolicy• ExecutionPolicy*IS*nota

securityfeature!!• 15waystobypass

Powershell executionpolicy– https://blog.netspi.com/15-

ways-to-bypass-the-powershell-execution-policy/

Page 49: Offensive Operations - SploitLab · •Passive (OSINT) • Search Engines (Google Dorks) • Web archives • Newsgroups ... –Lowes/Home depot craft time! • Other methods of access

@johnhsawyer [email protected]

Powershell Pwnage Must-Haves• Empire

– http://www.powershellempire.com

• Powersploit– https://github.com/PowerShell

Mafia/PowerSploit• BloodHound

– https://github.com/BloodHoundAD/BloodHound

• PowerUpSQL– https://github.com/NetSPI/Po

werUpSQL• MailSniper

– https://github.com/dafthack/MailSniper

• DomainPasswordSpray– https://github.com/dafthack/D

omainPasswordSpray

Page 50: Offensive Operations - SploitLab · •Passive (OSINT) • Search Engines (Google Dorks) • Web archives • Newsgroups ... –Lowes/Home depot craft time! • Other methods of access

@johnhsawyer [email protected]

COBALTSTRIKEPost-exploitationandC2excellence

Page 51: Offensive Operations - SploitLab · •Passive (OSINT) • Search Engines (Google Dorks) • Web archives • Newsgroups ... –Lowes/Home depot craft time! • Other methods of access

@johnhsawyer [email protected]

CobaltStrike• Post-exploitation• CommandandControl

(C2)• Flexibleprotocols• Powershell integration• Scriptable

Page 52: Offensive Operations - SploitLab · •Passive (OSINT) • Search Engines (Google Dorks) • Web archives • Newsgroups ... –Lowes/Home depot craft time! • Other methods of access

@johnhsawyer [email protected]

ListenersandPayloads

Page 53: Offensive Operations - SploitLab · •Passive (OSINT) • Search Engines (Google Dorks) • Web archives • Newsgroups ... –Lowes/Home depot craft time! • Other methods of access

@johnhsawyer [email protected]

MacrosfortheFoothold

Page 54: Offensive Operations - SploitLab · •Passive (OSINT) • Search Engines (Google Dorks) • Web archives • Newsgroups ... –Lowes/Home depot craft time! • Other methods of access

@johnhsawyer [email protected]

InjectingADCredstoAccessSysvol

Page 55: Offensive Operations - SploitLab · •Passive (OSINT) • Search Engines (Google Dorks) • Web archives • Newsgroups ... –Lowes/Home depot craft time! • Other methods of access

@johnhsawyer [email protected]

MovingLaterally:SMBBeacons

Page 56: Offensive Operations - SploitLab · •Passive (OSINT) • Search Engines (Google Dorks) • Web archives • Newsgroups ... –Lowes/Home depot craft time! • Other methods of access

@johnhsawyer [email protected]

Credentials

Page 57: Offensive Operations - SploitLab · •Passive (OSINT) • Search Engines (Google Dorks) • Web archives • Newsgroups ... –Lowes/Home depot craft time! • Other methods of access

@johnhsawyer [email protected]

Powershell Integration

Page 58: Offensive Operations - SploitLab · •Passive (OSINT) • Search Engines (Google Dorks) • Web archives • Newsgroups ... –Lowes/Home depot craft time! • Other methods of access

@johnhsawyer [email protected]

NEXTSTEPSWheretogofromhere…

Page 59: Offensive Operations - SploitLab · •Passive (OSINT) • Search Engines (Google Dorks) • Web archives • Newsgroups ... –Lowes/Home depot craft time! • Other methods of access

@johnhsawyer [email protected]

NextSteps• Buildyourownlab

– VMWare (ESXi),VirtualBox,Hyper-V,AWS,Docker– Vulnhub.com– Networkequipment(HWorSW)

• Certifications– OSCP– GPEN,GPWN,GXPN

• BugBountiesandCapturetheFlagevents

Page 60: Offensive Operations - SploitLab · •Passive (OSINT) • Search Engines (Google Dorks) • Web archives • Newsgroups ... –Lowes/Home depot craft time! • Other methods of access

@johnhsawyer [email protected]

ContactInformation• Contactinformation:

[email protected]@johnhsawyer352-389-4704

• Slides- https://www.sploitlab.com