SlideShare a Scribd company logo
1 of 15
The Hitchhiker’s Guide to Galactic
Pentest Fails: Step 1 - Don’t Panic.
• Who/What am I?
• Simple answer:
• Father/Husband/Son/Brother
• Programmer/Pentester/Researcher
• Hillbilly
Me Me Me…
“The only real mistake is the one
from which we learn nothing.”
- Henry Ford
• /bin/sh used to truncate commands at a certain point.
• AAA.BBB.237.0/24 != AAA.BBB.2
• Nmap used to auto appent implied CIDR notation
• AAA.BBB.2 =>AAA.BBB.2.0/24
• AAA.BBB.2.0/24 != AAA.BBB.237.0/24
Watch those octets….
“I have not failed. I've just found
10,000 ways that won't work.”
-Thomas Edison
“You build on failure.You use it as a stepping stone.
Close the door on the past.You don't try to forget
the mistakes, but you don't dwell on it.You don't let
it have any of your energy, or any of your time, or
any of your space.”
- Johnny Cash
“Success is not final, failure is not
fatal: it is the courage to continue
that counts.”
-Winston Churchill
“A person who never made a mistake never tried
anything new.”
- Albert Einstein
“It is fine to celebrate success, but it
is more important to heed the
lessons of failure.”
- Bill Gates
“I thank God for my failures. Maybe not at the time
but after some reflection. I never feel like a failure
just because something I tried has failed.”
- Dolly Parton
• Always Double Check Everything
• If Something Does Not Feel Right, It Probably Isn’t
• Never Rely On Just One AccessVector
• Understand/UpdateYourTools
Lessons Learned
“Our greatest glory is not in never
failing, but in rising every time we
fail.”
- Confucius
¿Questions? ¿Comments? ¿Requests?
Contact Info:
• adam.compton@trustedsec.com
• adam.compton@gmail.com
• @tatanus
• https://www.hillbillystorytime.com
• https://youtube.com/hillbillystorytime
THANK YOU
www.hackerhalted.com 15

More Related Content

More from Adam Compton

Becoming a Pentester
Becoming a PentesterBecoming a Pentester
Becoming a PentesterAdam Compton
 
A HillyBilly's Guide to Staying Anonymous Online - SecureWV
A HillyBilly's Guide to Staying Anonymous Online - SecureWVA HillyBilly's Guide to Staying Anonymous Online - SecureWV
A HillyBilly's Guide to Staying Anonymous Online - SecureWVAdam Compton
 
BSidesKnoxville 2019 - Unix: The Other White Meat
BSidesKnoxville 2019 - Unix: The Other White MeatBSidesKnoxville 2019 - Unix: The Other White Meat
BSidesKnoxville 2019 - Unix: The Other White MeatAdam Compton
 
Bsides Knoxville - OSINT
Bsides Knoxville - OSINTBsides Knoxville - OSINT
Bsides Knoxville - OSINTAdam Compton
 
Bsides Knoxville - APT2
Bsides Knoxville - APT2Bsides Knoxville - APT2
Bsides Knoxville - APT2Adam Compton
 

More from Adam Compton (9)

Becoming a Pentester
Becoming a PentesterBecoming a Pentester
Becoming a Pentester
 
A HillyBilly's Guide to Staying Anonymous Online - SecureWV
A HillyBilly's Guide to Staying Anonymous Online - SecureWVA HillyBilly's Guide to Staying Anonymous Online - SecureWV
A HillyBilly's Guide to Staying Anonymous Online - SecureWV
 
BSidesKnoxville 2019 - Unix: The Other White Meat
BSidesKnoxville 2019 - Unix: The Other White MeatBSidesKnoxville 2019 - Unix: The Other White Meat
BSidesKnoxville 2019 - Unix: The Other White Meat
 
SecureWV - APT2
SecureWV - APT2SecureWV - APT2
SecureWV - APT2
 
HackCon - SPF
HackCon - SPFHackCon - SPF
HackCon - SPF
 
DerbyCon - Legion
DerbyCon - LegionDerbyCon - Legion
DerbyCon - Legion
 
DerbyCon - APT2
DerbyCon - APT2DerbyCon - APT2
DerbyCon - APT2
 
Bsides Knoxville - OSINT
Bsides Knoxville - OSINTBsides Knoxville - OSINT
Bsides Knoxville - OSINT
 
Bsides Knoxville - APT2
Bsides Knoxville - APT2Bsides Knoxville - APT2
Bsides Knoxville - APT2
 

Recently uploaded

Work Experience-Dalton Park.pptxfvvvvvvv
Work Experience-Dalton Park.pptxfvvvvvvvWork Experience-Dalton Park.pptxfvvvvvvv
Work Experience-Dalton Park.pptxfvvvvvvvLewisJB
 
Heart Disease Prediction using machine learning.pptx
Heart Disease Prediction using machine learning.pptxHeart Disease Prediction using machine learning.pptx
Heart Disease Prediction using machine learning.pptxPoojaBan
 
Biology for Computer Engineers Course Handout.pptx
Biology for Computer Engineers Course Handout.pptxBiology for Computer Engineers Course Handout.pptx
Biology for Computer Engineers Course Handout.pptxDeepakSakkari2
 
Introduction-To-Agricultural-Surveillance-Rover.pptx
Introduction-To-Agricultural-Surveillance-Rover.pptxIntroduction-To-Agricultural-Surveillance-Rover.pptx
Introduction-To-Agricultural-Surveillance-Rover.pptxk795866
 
Why does (not) Kafka need fsync: Eliminating tail latency spikes caused by fsync
Why does (not) Kafka need fsync: Eliminating tail latency spikes caused by fsyncWhy does (not) Kafka need fsync: Eliminating tail latency spikes caused by fsync
Why does (not) Kafka need fsync: Eliminating tail latency spikes caused by fsyncssuser2ae721
 
Correctly Loading Incremental Data at Scale
Correctly Loading Incremental Data at ScaleCorrectly Loading Incremental Data at Scale
Correctly Loading Incremental Data at ScaleAlluxio, Inc.
 
Gfe Mayur Vihar Call Girls Service WhatsApp -> 9999965857 Available 24x7 ^ De...
Gfe Mayur Vihar Call Girls Service WhatsApp -> 9999965857 Available 24x7 ^ De...Gfe Mayur Vihar Call Girls Service WhatsApp -> 9999965857 Available 24x7 ^ De...
Gfe Mayur Vihar Call Girls Service WhatsApp -> 9999965857 Available 24x7 ^ De...srsj9000
 
An experimental study in using natural admixture as an alternative for chemic...
An experimental study in using natural admixture as an alternative for chemic...An experimental study in using natural admixture as an alternative for chemic...
An experimental study in using natural admixture as an alternative for chemic...Chandu841456
 
UNIT III ANALOG ELECTRONICS (BASIC ELECTRONICS)
UNIT III ANALOG ELECTRONICS (BASIC ELECTRONICS)UNIT III ANALOG ELECTRONICS (BASIC ELECTRONICS)
UNIT III ANALOG ELECTRONICS (BASIC ELECTRONICS)Dr SOUNDIRARAJ N
 
An introduction to Semiconductor and its types.pptx
An introduction to Semiconductor and its types.pptxAn introduction to Semiconductor and its types.pptx
An introduction to Semiconductor and its types.pptxPurva Nikam
 
computer application and construction management
computer application and construction managementcomputer application and construction management
computer application and construction managementMariconPadriquez1
 
Architect Hassan Khalil Portfolio for 2024
Architect Hassan Khalil Portfolio for 2024Architect Hassan Khalil Portfolio for 2024
Architect Hassan Khalil Portfolio for 2024hassan khalil
 
Software and Systems Engineering Standards: Verification and Validation of Sy...
Software and Systems Engineering Standards: Verification and Validation of Sy...Software and Systems Engineering Standards: Verification and Validation of Sy...
Software and Systems Engineering Standards: Verification and Validation of Sy...VICTOR MAESTRE RAMIREZ
 
IVE Industry Focused Event - Defence Sector 2024
IVE Industry Focused Event - Defence Sector 2024IVE Industry Focused Event - Defence Sector 2024
IVE Industry Focused Event - Defence Sector 2024Mark Billinghurst
 
Call Us ≽ 8377877756 ≼ Call Girls In Shastri Nagar (Delhi)
Call Us ≽ 8377877756 ≼ Call Girls In Shastri Nagar (Delhi)Call Us ≽ 8377877756 ≼ Call Girls In Shastri Nagar (Delhi)
Call Us ≽ 8377877756 ≼ Call Girls In Shastri Nagar (Delhi)dollysharma2066
 
Call Girls Narol 7397865700 Independent Call Girls
Call Girls Narol 7397865700 Independent Call GirlsCall Girls Narol 7397865700 Independent Call Girls
Call Girls Narol 7397865700 Independent Call Girlsssuser7cb4ff
 

Recently uploaded (20)

Work Experience-Dalton Park.pptxfvvvvvvv
Work Experience-Dalton Park.pptxfvvvvvvvWork Experience-Dalton Park.pptxfvvvvvvv
Work Experience-Dalton Park.pptxfvvvvvvv
 
Design and analysis of solar grass cutter.pdf
Design and analysis of solar grass cutter.pdfDesign and analysis of solar grass cutter.pdf
Design and analysis of solar grass cutter.pdf
 
Heart Disease Prediction using machine learning.pptx
Heart Disease Prediction using machine learning.pptxHeart Disease Prediction using machine learning.pptx
Heart Disease Prediction using machine learning.pptx
 
Biology for Computer Engineers Course Handout.pptx
Biology for Computer Engineers Course Handout.pptxBiology for Computer Engineers Course Handout.pptx
Biology for Computer Engineers Course Handout.pptx
 
Introduction-To-Agricultural-Surveillance-Rover.pptx
Introduction-To-Agricultural-Surveillance-Rover.pptxIntroduction-To-Agricultural-Surveillance-Rover.pptx
Introduction-To-Agricultural-Surveillance-Rover.pptx
 
Exploring_Network_Security_with_JA3_by_Rakesh Seal.pptx
Exploring_Network_Security_with_JA3_by_Rakesh Seal.pptxExploring_Network_Security_with_JA3_by_Rakesh Seal.pptx
Exploring_Network_Security_with_JA3_by_Rakesh Seal.pptx
 
Why does (not) Kafka need fsync: Eliminating tail latency spikes caused by fsync
Why does (not) Kafka need fsync: Eliminating tail latency spikes caused by fsyncWhy does (not) Kafka need fsync: Eliminating tail latency spikes caused by fsync
Why does (not) Kafka need fsync: Eliminating tail latency spikes caused by fsync
 
Correctly Loading Incremental Data at Scale
Correctly Loading Incremental Data at ScaleCorrectly Loading Incremental Data at Scale
Correctly Loading Incremental Data at Scale
 
Gfe Mayur Vihar Call Girls Service WhatsApp -> 9999965857 Available 24x7 ^ De...
Gfe Mayur Vihar Call Girls Service WhatsApp -> 9999965857 Available 24x7 ^ De...Gfe Mayur Vihar Call Girls Service WhatsApp -> 9999965857 Available 24x7 ^ De...
Gfe Mayur Vihar Call Girls Service WhatsApp -> 9999965857 Available 24x7 ^ De...
 
An experimental study in using natural admixture as an alternative for chemic...
An experimental study in using natural admixture as an alternative for chemic...An experimental study in using natural admixture as an alternative for chemic...
An experimental study in using natural admixture as an alternative for chemic...
 
UNIT III ANALOG ELECTRONICS (BASIC ELECTRONICS)
UNIT III ANALOG ELECTRONICS (BASIC ELECTRONICS)UNIT III ANALOG ELECTRONICS (BASIC ELECTRONICS)
UNIT III ANALOG ELECTRONICS (BASIC ELECTRONICS)
 
An introduction to Semiconductor and its types.pptx
An introduction to Semiconductor and its types.pptxAn introduction to Semiconductor and its types.pptx
An introduction to Semiconductor and its types.pptx
 
computer application and construction management
computer application and construction managementcomputer application and construction management
computer application and construction management
 
Architect Hassan Khalil Portfolio for 2024
Architect Hassan Khalil Portfolio for 2024Architect Hassan Khalil Portfolio for 2024
Architect Hassan Khalil Portfolio for 2024
 
Software and Systems Engineering Standards: Verification and Validation of Sy...
Software and Systems Engineering Standards: Verification and Validation of Sy...Software and Systems Engineering Standards: Verification and Validation of Sy...
Software and Systems Engineering Standards: Verification and Validation of Sy...
 
IVE Industry Focused Event - Defence Sector 2024
IVE Industry Focused Event - Defence Sector 2024IVE Industry Focused Event - Defence Sector 2024
IVE Industry Focused Event - Defence Sector 2024
 
Call Us ≽ 8377877756 ≼ Call Girls In Shastri Nagar (Delhi)
Call Us ≽ 8377877756 ≼ Call Girls In Shastri Nagar (Delhi)Call Us ≽ 8377877756 ≼ Call Girls In Shastri Nagar (Delhi)
Call Us ≽ 8377877756 ≼ Call Girls In Shastri Nagar (Delhi)
 
Call Girls Narol 7397865700 Independent Call Girls
Call Girls Narol 7397865700 Independent Call GirlsCall Girls Narol 7397865700 Independent Call Girls
Call Girls Narol 7397865700 Independent Call Girls
 
Call Us -/9953056974- Call Girls In Vikaspuri-/- Delhi NCR
Call Us -/9953056974- Call Girls In Vikaspuri-/- Delhi NCRCall Us -/9953056974- Call Girls In Vikaspuri-/- Delhi NCR
Call Us -/9953056974- Call Girls In Vikaspuri-/- Delhi NCR
 
POWER SYSTEMS-1 Complete notes examples
POWER SYSTEMS-1 Complete notes  examplesPOWER SYSTEMS-1 Complete notes  examples
POWER SYSTEMS-1 Complete notes examples
 

2018 HackerHalted - Hillbilly Storytime - Pentest Fails

  • 1. The Hitchhiker’s Guide to Galactic Pentest Fails: Step 1 - Don’t Panic.
  • 2. • Who/What am I? • Simple answer: • Father/Husband/Son/Brother • Programmer/Pentester/Researcher • Hillbilly Me Me Me…
  • 3. “The only real mistake is the one from which we learn nothing.” - Henry Ford
  • 4. • /bin/sh used to truncate commands at a certain point. • AAA.BBB.237.0/24 != AAA.BBB.2 • Nmap used to auto appent implied CIDR notation • AAA.BBB.2 =>AAA.BBB.2.0/24 • AAA.BBB.2.0/24 != AAA.BBB.237.0/24 Watch those octets….
  • 5. “I have not failed. I've just found 10,000 ways that won't work.” -Thomas Edison
  • 6. “You build on failure.You use it as a stepping stone. Close the door on the past.You don't try to forget the mistakes, but you don't dwell on it.You don't let it have any of your energy, or any of your time, or any of your space.” - Johnny Cash
  • 7. “Success is not final, failure is not fatal: it is the courage to continue that counts.” -Winston Churchill
  • 8. “A person who never made a mistake never tried anything new.” - Albert Einstein
  • 9. “It is fine to celebrate success, but it is more important to heed the lessons of failure.” - Bill Gates
  • 10. “I thank God for my failures. Maybe not at the time but after some reflection. I never feel like a failure just because something I tried has failed.” - Dolly Parton
  • 11. • Always Double Check Everything • If Something Does Not Feel Right, It Probably Isn’t • Never Rely On Just One AccessVector • Understand/UpdateYourTools Lessons Learned
  • 12. “Our greatest glory is not in never failing, but in rising every time we fail.” - Confucius
  • 14. Contact Info: • adam.compton@trustedsec.com • adam.compton@gmail.com • @tatanus • https://www.hillbillystorytime.com • https://youtube.com/hillbillystorytime THANK YOU

Editor's Notes

  1. Me? I have been around for a while… about 18 years or so in the InfoSec field. Over that time, I have been a programmer, researcher, and pentester (currently for TrustedSec). But most of all, I am a father, husband, son, and brother. As I am sure you know, especially as it is listed in your schedule and I placed it on the first slide, today I will be talking about mistakes, FAILS, and lessons learned.   What? I am not going to talk about some new exploit or some awesome new tool or something like that? Not this time.   In InfoSec, via social media, conference talks, colleagues, and the news, we hear a lot about new discoveries, new exploits, and new data leaks on a regular basis. But we typically do not hear about all the failed attempts and all the long hours that went into producing those awesome WINs.   Obviously, it is always fun to hear about those things, but at the same time it can be very discouraging, especially if you are one of the people who is not making the new discoveries or is simply prone to making lots of mistakes like I do.   My hope is that by bring stories of these difficulties and failures out into the open, it may help a few people learn that it is okay to make mistakes.
  2. When I first started in InfoSec, I had no idea of what I was doing.   1st day - build a lab 2nd week - go on an engagement (make mistakes) Usually paired with mentor took many months to feel competent   Over the years, I kept making mistakes and learning from them to become more proficient. Did I every stop making mistakes, of course not.
  3. ...  After it was all said and done, my boss and peers of course laughed about it a bit but no one tried to make me feel bad about it. The general response was that, we all make mistakes and it is fine. Just try to learn for them as to not make the same one again if possible. That stuck with me and has become a sort of life motto for me.   Enough of my life story, let’s laugh at and learn from some other people’s fails now shall we.
  4. Running a tool without understanding its issues Siet Cisco smart install exploit tool
  5. Talking about the customer in a restaurant.
  6. Let’s get Physical pen testing the wrong building locking ourselves out of the building on a physical Wrong door
  7. Pentesting when tired listening to the intern and closing out the only access we had
  8. On a different engagement, Cheap Pentests R Us was contracted to perform an electronic Social Engineering engagement consisting of just phishing emails.   copy-n-paste campaign scenario 1 - no success (servers not turned on) scenario 2 - limited success (wrong company name and logo) reports
  9. Network based web cameras…   I have some friends which work at another company,   One on particular internal engagement, they were targeting a university. --LEON On a different engagement, they were targeting a legal office’s Internet facing systems. --SCHOOL
  10. Always Double Check Everything If Something Does Not Feel Right, It Probably Isn’t Never Rely On Just One Access Vector Understand/Update your tools
  11. As anyone who knows me can attest to, I have made more mistakes than I can count.   Luckily I have slowly been learning from my mistakes and gradually I have been improving. I have made it a point to never let a mistake derail me.   Most mistakes I can shrug off and continue as normal. However, every once in a while, I will encounter a mistake/failure that it is so profound that it does stop me for me a bit. At those times, I stop, regroup, take it a step at a time and before I know it, I am back to fighting shape and on my way.   If you let them, fails and such will have a profoundly negative impact on you. Just remember that everyone makes mistakes. Just learn from them and try not to dwell to long on them.
  12. In closing, I would just like to repeat that mistakes do happen and that is ok.   It is a matter of how you deal with them and what you can learn from them that will determine how they affect you in the long run.   And if you are so inclined, please share your hard-earned lessons with others so that you can possibly help other to not make the same mistakes.   And Thank you.   Now, any questions?