SlideShare a Scribd company logo
1 of 38
Download to read offline
Kids...
How I met your m... data
2
x00 - whoami
33 years old
I Do: Pentester, Exploit development, CTF player
I like: Malware Analysis and Bug hunting
Since 03/04 (Arroba, HxC, Yashira, forohack admin, Hackthebox leet …)
Targets: Government, hospital, casino, construction comp, wholesale,
financial stuff
No wireless, car/hardware hacking, no fb/ig
eJPTv1, LPIC-1, SPSE, SLAE, OSCP, CRTP
Youtube channel: @Mr.RedSmasher
3
4
5
Pentester
6
x01 – what I do
Penetration testing is...
https://suntechnologies.com/service/security-testing/
7
x01 – what I do
Penetration testing is...
https://suntechnologies.com/service/security-testing/
8
x02 – Intelligence Gathering
Intelligence recon --> Open-source Intelligence --> OSINT
Public sources to get info from people, companies, usernames, etc.
Passive (semi)
9
x02 – Intelligence Gathering
https://webbreacher.com/2018/07/12/osint-map/
10
x02 – Intelligence Gathering
Companies
Military/Government
Researchers/Detectives
...
Bad guys
Good Guys
11
x03 – Objectives
- Spear Phishing [ Smishing / Vishing ]
- Profiling
- Technologies, leaks, etc.
12
x04 – My process
From company to:
Partners
Others companies
Files
Apps
Employees
Dev? IT?
Email
Social network
Hobbies
Family
Birthdate, etc.
Breach
13
x04 – My process
From company to:
Partners
Others companies
Files
Apps
Employees
Dev? IT?
Email
Social network
Hobbies
Family
Birthdate, etc.
Breach
14
x04 – My process Email
15
x04 – My process Email
16
x04 – My process Email
17
x04 – My process Email
18
Linked for the win
19
x04 – My process Email
20
x04 – My process Email
21
x04 – My process Email
22
x04 – My process Email
23
x04 – My process
From company to:
Partners
Others companies
Files
Apps
Employees
Dev? IT?
Email
Social network
Hobbies
Family
Birthdate, etc.
Breach
24
x04 – My process
From company to:
Partners
Others companies
Files
Apps
Employees
Dev? IT?
Email
Social network
Hobbies
Family
Birthdate, etc.
Breach
25
x04 – My process
26
x04 – My process
27
x04 – My process
From company to:
Partners
Others companies
Files
Apps
Employees
Dev? IT?
Email
Social network
Hobbies
Family
Birthdate, etc.
Breach
28
x04 – My process
From company to:
Partners
Others companies
Files
Apps
Employees
Dev? IT?
Email
Social network
Hobbies
Family
Birthdate, etc.
Breach
29
x04 – My process
30
x05 – More things you can do
31
x05 – More things you can do
32
x05 – More things you can do
33
x06 – The dark side
34
x06 – The dark side
35
x07 – There’s awesome people too
36
37
x07 – Pendings
AI and sock puppets
ChatGPT
I‘ve been pwn
Wifi APs location
ATV passwd
Tools like Shodan, Maltego, SF, etc.
...
38
x08 – More info at
https://www.youtube.com/@Mr.RedSmasher
https://www.youtube.com/@OSINTDojo
https://www.tracelabs.org/
https://medium.com/the-first-digit/osint-how-to-find-information-on-
anyone-5029a3c7fd56

More Related Content

Similar to How I met your m... data

Lessons v on fraud awareness (digital forensics) [autosaved]
Lessons v on fraud awareness   (digital forensics) [autosaved]Lessons v on fraud awareness   (digital forensics) [autosaved]
Lessons v on fraud awareness (digital forensics) [autosaved]
Kolluru N Rao
 

Similar to How I met your m... data (20)

Texas Bitcoin Conference: Are Privacy Coins Private Enough?
Texas Bitcoin Conference: Are Privacy Coins Private Enough?Texas Bitcoin Conference: Are Privacy Coins Private Enough?
Texas Bitcoin Conference: Are Privacy Coins Private Enough?
 
Threat Hunting with Splunk Hands-on
Threat Hunting with Splunk Hands-onThreat Hunting with Splunk Hands-on
Threat Hunting with Splunk Hands-on
 
Why do women love chasing down bad guys?
Why do women love chasing down bad guys? Why do women love chasing down bad guys?
Why do women love chasing down bad guys?
 
Honeypot 101 (slide share)
Honeypot 101 (slide share)Honeypot 101 (slide share)
Honeypot 101 (slide share)
 
Cyber Security Awareness Program.pptx
Cyber Security Awareness Program.pptxCyber Security Awareness Program.pptx
Cyber Security Awareness Program.pptx
 
Espiando redes de microblogging Navaja Negra 2017
Espiando redes de microblogging Navaja Negra 2017Espiando redes de microblogging Navaja Negra 2017
Espiando redes de microblogging Navaja Negra 2017
 
Ethical Hacking - A Need To Know.pptx
Ethical Hacking - A Need To Know.pptxEthical Hacking - A Need To Know.pptx
Ethical Hacking - A Need To Know.pptx
 
Honeypot Project
Honeypot ProjectHoneypot Project
Honeypot Project
 
Seminar Report on Honeypot
Seminar Report on HoneypotSeminar Report on Honeypot
Seminar Report on Honeypot
 
News Bytes - December 2010
News Bytes - December 2010News Bytes - December 2010
News Bytes - December 2010
 
Unit-2 ICS.ppt
Unit-2 ICS.pptUnit-2 ICS.ppt
Unit-2 ICS.ppt
 
Hacking Presentation
Hacking PresentationHacking Presentation
Hacking Presentation
 
Cybercrime (Computer Hacking)
Cybercrime (Computer Hacking)Cybercrime (Computer Hacking)
Cybercrime (Computer Hacking)
 
Ethical Hacking Overview
Ethical Hacking OverviewEthical Hacking Overview
Ethical Hacking Overview
 
Alfonso Muñoz y Miguel Hernandez - Playing with mastodon for fun and profit [...
Alfonso Muñoz y Miguel Hernandez - Playing with mastodon for fun and profit [...Alfonso Muñoz y Miguel Hernandez - Playing with mastodon for fun and profit [...
Alfonso Muñoz y Miguel Hernandez - Playing with mastodon for fun and profit [...
 
Introduction to ethical hacking
Introduction to ethical hackingIntroduction to ethical hacking
Introduction to ethical hacking
 
DEFCON 23 - Patrick Mcneil and Owen - sorry wrong number
DEFCON 23 - Patrick Mcneil and Owen - sorry wrong numberDEFCON 23 - Patrick Mcneil and Owen - sorry wrong number
DEFCON 23 - Patrick Mcneil and Owen - sorry wrong number
 
Honeypots
HoneypotsHoneypots
Honeypots
 
Lessons v on fraud awareness (digital forensics) [autosaved]
Lessons v on fraud awareness   (digital forensics) [autosaved]Lessons v on fraud awareness   (digital forensics) [autosaved]
Lessons v on fraud awareness (digital forensics) [autosaved]
 
Lessons v on fraud awareness (digital forensics)
Lessons v on fraud awareness   (digital forensics)Lessons v on fraud awareness   (digital forensics)
Lessons v on fraud awareness (digital forensics)
 

Recently uploaded

+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
?#DUbAI#??##{{(☎️+971_581248768%)**%*]'#abortion pills for sale in dubai@
 
Architecting Cloud Native Applications
Architecting Cloud Native ApplicationsArchitecting Cloud Native Applications
Architecting Cloud Native Applications
WSO2
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Safe Software
 

Recently uploaded (20)

Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost SavingRepurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
 
FWD Group - Insurer Innovation Award 2024
FWD Group - Insurer Innovation Award 2024FWD Group - Insurer Innovation Award 2024
FWD Group - Insurer Innovation Award 2024
 
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
 
Manulife - Insurer Transformation Award 2024
Manulife - Insurer Transformation Award 2024Manulife - Insurer Transformation Award 2024
Manulife - Insurer Transformation Award 2024
 
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
 
Real Time Object Detection Using Open CV
Real Time Object Detection Using Open CVReal Time Object Detection Using Open CV
Real Time Object Detection Using Open CV
 
AWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of Terraform
 
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ..."I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...
 
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
 
Data Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonData Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt Robison
 
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWEREMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
 
Architecting Cloud Native Applications
Architecting Cloud Native ApplicationsArchitecting Cloud Native Applications
Architecting Cloud Native Applications
 
presentation ICT roal in 21st century education
presentation ICT roal in 21st century educationpresentation ICT roal in 21st century education
presentation ICT roal in 21st century education
 
Automating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps ScriptAutomating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps Script
 
A Beginners Guide to Building a RAG App Using Open Source Milvus
A Beginners Guide to Building a RAG App Using Open Source MilvusA Beginners Guide to Building a RAG App Using Open Source Milvus
A Beginners Guide to Building a RAG App Using Open Source Milvus
 
A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
 
Ransomware_Q4_2023. The report. [EN].pdf
Ransomware_Q4_2023. The report. [EN].pdfRansomware_Q4_2023. The report. [EN].pdf
Ransomware_Q4_2023. The report. [EN].pdf
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024
 
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
 

How I met your m... data

  • 1. Kids... How I met your m... data
  • 2. 2 x00 - whoami 33 years old I Do: Pentester, Exploit development, CTF player I like: Malware Analysis and Bug hunting Since 03/04 (Arroba, HxC, Yashira, forohack admin, Hackthebox leet …) Targets: Government, hospital, casino, construction comp, wholesale, financial stuff No wireless, car/hardware hacking, no fb/ig eJPTv1, LPIC-1, SPSE, SLAE, OSCP, CRTP Youtube channel: @Mr.RedSmasher
  • 3. 3
  • 4. 4
  • 6. 6 x01 – what I do Penetration testing is... https://suntechnologies.com/service/security-testing/
  • 7. 7 x01 – what I do Penetration testing is... https://suntechnologies.com/service/security-testing/
  • 8. 8 x02 – Intelligence Gathering Intelligence recon --> Open-source Intelligence --> OSINT Public sources to get info from people, companies, usernames, etc. Passive (semi)
  • 9. 9 x02 – Intelligence Gathering https://webbreacher.com/2018/07/12/osint-map/
  • 10. 10 x02 – Intelligence Gathering Companies Military/Government Researchers/Detectives ... Bad guys Good Guys
  • 11. 11 x03 – Objectives - Spear Phishing [ Smishing / Vishing ] - Profiling - Technologies, leaks, etc.
  • 12. 12 x04 – My process From company to: Partners Others companies Files Apps Employees Dev? IT? Email Social network Hobbies Family Birthdate, etc. Breach
  • 13. 13 x04 – My process From company to: Partners Others companies Files Apps Employees Dev? IT? Email Social network Hobbies Family Birthdate, etc. Breach
  • 14. 14 x04 – My process Email
  • 15. 15 x04 – My process Email
  • 16. 16 x04 – My process Email
  • 17. 17 x04 – My process Email
  • 19. 19 x04 – My process Email
  • 20. 20 x04 – My process Email
  • 21. 21 x04 – My process Email
  • 22. 22 x04 – My process Email
  • 23. 23 x04 – My process From company to: Partners Others companies Files Apps Employees Dev? IT? Email Social network Hobbies Family Birthdate, etc. Breach
  • 24. 24 x04 – My process From company to: Partners Others companies Files Apps Employees Dev? IT? Email Social network Hobbies Family Birthdate, etc. Breach
  • 25. 25 x04 – My process
  • 26. 26 x04 – My process
  • 27. 27 x04 – My process From company to: Partners Others companies Files Apps Employees Dev? IT? Email Social network Hobbies Family Birthdate, etc. Breach
  • 28. 28 x04 – My process From company to: Partners Others companies Files Apps Employees Dev? IT? Email Social network Hobbies Family Birthdate, etc. Breach
  • 29. 29 x04 – My process
  • 30. 30 x05 – More things you can do
  • 31. 31 x05 – More things you can do
  • 32. 32 x05 – More things you can do
  • 33. 33 x06 – The dark side
  • 34. 34 x06 – The dark side
  • 35. 35 x07 – There’s awesome people too
  • 36. 36
  • 37. 37 x07 – Pendings AI and sock puppets ChatGPT I‘ve been pwn Wifi APs location ATV passwd Tools like Shodan, Maltego, SF, etc. ...
  • 38. 38 x08 – More info at https://www.youtube.com/@Mr.RedSmasher https://www.youtube.com/@OSINTDojo https://www.tracelabs.org/ https://medium.com/the-first-digit/osint-how-to-find-information-on- anyone-5029a3c7fd56