SlideShare une entreprise Scribd logo
1  sur  12
Adam Compton – Senior Security Consultant
Learning From Mistakes -
They Will Happen
Learning from Mistakes – They Will Happen
• Who am I?
• Simple answer:
• Father/Husband/Son/Brother
• Programmer/Pentester/Researcher
• Hillybilly
Me Me Me…
Learning from Mistakes – They Will Happen
“I have not failed. I've just found
10,000 ways that won't work.”
- Thomas Edison
Learning from Mistakes – They Will Happen
“The only real mistake is the
one from which we learn
nothing.”
- Henry Ford
Learning from Mistakes – They Will Happen
• /bin/sh used to truncate commands after a certain length
• AAA.BBB.237.0/24 != AAA.BBB.2
• Nmap used to auto-append implied CIDR notation
• AAA.BBB.2 -> AAA.BBB.2.0/24
• AAA.BBB.2.0/24 != AAA>BBB.237.0/24
Watch those octets
Learning from Mistakes – They Will Happen
“You build on failure. You use it as a stepping stone.
Close the door on the past. You don't try to forget the
mistakes, but you don't dwell on it. You don't let it have
any of your energy, or any of your time, or any of your
space.”
- Johnny Cash
Learning from Mistakes – They Will Happen
“Success is not final, failure is
not fatal: it is the courage to
continue that counts.”
- Winston Churchill
Learning from Mistakes – They Will Happen
“A person who never made a mistake
never tried anything new.”
- Albert Einstein
Learning from Mistakes – They Will Happen
“Mistakes are a part of being human.
Appreciate your mistakes for what they are:
precious life lessons that can only be learned
the hard way.
“Unless it's a fatal mistake, which, at least,
others can learn from.”
- Al Franken
On a different engagement, Cheap Pentests R
Us was contracted to perform an electronic
Social Engineering engagement consisting of
just phishing emails.
copy-n-paste campaign
scenario 1 - no success (servers not turned on)
scenario 2 - limited success (wrong company
name and logo)
Learning from Mistakes – They Will Happen
“Our greatest glory is not in
never failing, but in rising
every time we fail.”
- Confucius
Learning from Mistakes – They Will Happen
• Always double check everything
• If something does not feel right, it probably isn’t
• Never rely on just one access vector
• It is okay to make mistakes
Takeaways
Learning from Mistakes – They Will Happen
adam_compton@rapid7.com
@tatanus
Questions ? Comments ? Thoughts ? Stories ?

Contenu connexe

Tendances

Pre-production documents
Pre-production documentsPre-production documents
Pre-production documentsMrsGainsford
 
My Heroes Are Imposters Too (200OK Lightning Talk)
My Heroes Are Imposters Too (200OK Lightning Talk)My Heroes Are Imposters Too (200OK Lightning Talk)
My Heroes Are Imposters Too (200OK Lightning Talk)Jacob Herrington
 
231 brian g. newsletter
231 brian g. newsletter231 brian g. newsletter
231 brian g. newsletterellenquilt
 

Tendances (6)

Pre-production documents
Pre-production documentsPre-production documents
Pre-production documents
 
08
0808
08
 
The Elements of Scaling
The Elements of ScalingThe Elements of Scaling
The Elements of Scaling
 
My Heroes Are Imposters Too (200OK Lightning Talk)
My Heroes Are Imposters Too (200OK Lightning Talk)My Heroes Are Imposters Too (200OK Lightning Talk)
My Heroes Are Imposters Too (200OK Lightning Talk)
 
231 brian g. newsletter
231 brian g. newsletter231 brian g. newsletter
231 brian g. newsletter
 
Be Bop7
Be Bop7Be Bop7
Be Bop7
 

Similaire à Infosec Europe 17 - PentestFails

2018 HackerHalted - Hillbilly Storytime - Pentest Fails
2018 HackerHalted - Hillbilly Storytime - Pentest Fails2018 HackerHalted - Hillbilly Storytime - Pentest Fails
2018 HackerHalted - Hillbilly Storytime - Pentest FailsAdam Compton
 
Bsides LV - Hillbilly Storytime - Pentest Fails
Bsides LV - Hillbilly Storytime - Pentest FailsBsides LV - Hillbilly Storytime - Pentest Fails
Bsides LV - Hillbilly Storytime - Pentest FailsAdam Compton
 
2018 DerbyCon - Hillbilly Storytime - Pentest Fails
2018 DerbyCon - Hillbilly Storytime - Pentest Fails2018 DerbyCon - Hillbilly Storytime - Pentest Fails
2018 DerbyCon - Hillbilly Storytime - Pentest FailsAdam Compton
 
Bsides Nashville - PentestFails
Bsides Nashville - PentestFailsBsides Nashville - PentestFails
Bsides Nashville - PentestFailsAdam Compton
 
Bsides Knoxville - PentestFails
Bsides Knoxville - PentestFailsBsides Knoxville - PentestFails
Bsides Knoxville - PentestFailsAdam Compton
 
SecureWV - PentestFails
SecureWV - PentestFailsSecureWV - PentestFails
SecureWV - PentestFailsAdam Compton
 
Ten Principles as the Essence of Process Consultation
Ten Principles as the Essence of Process ConsultationTen Principles as the Essence of Process Consultation
Ten Principles as the Essence of Process ConsultationRichard Fajardo, MA, LPC, NCC
 
Edison's work habits and thinking about failure.pptx
Edison's work habits and thinking about failure.pptxEdison's work habits and thinking about failure.pptx
Edison's work habits and thinking about failure.pptxYastee Shah
 
10 questions developers should ask themselves.
10 questions developers should ask themselves.10 questions developers should ask themselves.
10 questions developers should ask themselves.Stephen Young
 

Similaire à Infosec Europe 17 - PentestFails (9)

2018 HackerHalted - Hillbilly Storytime - Pentest Fails
2018 HackerHalted - Hillbilly Storytime - Pentest Fails2018 HackerHalted - Hillbilly Storytime - Pentest Fails
2018 HackerHalted - Hillbilly Storytime - Pentest Fails
 
Bsides LV - Hillbilly Storytime - Pentest Fails
Bsides LV - Hillbilly Storytime - Pentest FailsBsides LV - Hillbilly Storytime - Pentest Fails
Bsides LV - Hillbilly Storytime - Pentest Fails
 
2018 DerbyCon - Hillbilly Storytime - Pentest Fails
2018 DerbyCon - Hillbilly Storytime - Pentest Fails2018 DerbyCon - Hillbilly Storytime - Pentest Fails
2018 DerbyCon - Hillbilly Storytime - Pentest Fails
 
Bsides Nashville - PentestFails
Bsides Nashville - PentestFailsBsides Nashville - PentestFails
Bsides Nashville - PentestFails
 
Bsides Knoxville - PentestFails
Bsides Knoxville - PentestFailsBsides Knoxville - PentestFails
Bsides Knoxville - PentestFails
 
SecureWV - PentestFails
SecureWV - PentestFailsSecureWV - PentestFails
SecureWV - PentestFails
 
Ten Principles as the Essence of Process Consultation
Ten Principles as the Essence of Process ConsultationTen Principles as the Essence of Process Consultation
Ten Principles as the Essence of Process Consultation
 
Edison's work habits and thinking about failure.pptx
Edison's work habits and thinking about failure.pptxEdison's work habits and thinking about failure.pptx
Edison's work habits and thinking about failure.pptx
 
10 questions developers should ask themselves.
10 questions developers should ask themselves.10 questions developers should ask themselves.
10 questions developers should ask themselves.
 

Plus de Adam Compton

Becoming a Pentester
Becoming a PentesterBecoming a Pentester
Becoming a PentesterAdam Compton
 
A HillyBilly's Guide to Staying Anonymous Online - SecureWV
A HillyBilly's Guide to Staying Anonymous Online - SecureWVA HillyBilly's Guide to Staying Anonymous Online - SecureWV
A HillyBilly's Guide to Staying Anonymous Online - SecureWVAdam Compton
 
BSidesKnoxville 2019 - Unix: The Other White Meat
BSidesKnoxville 2019 - Unix: The Other White MeatBSidesKnoxville 2019 - Unix: The Other White Meat
BSidesKnoxville 2019 - Unix: The Other White MeatAdam Compton
 
Bsides Knoxville - OSINT
Bsides Knoxville - OSINTBsides Knoxville - OSINT
Bsides Knoxville - OSINTAdam Compton
 
Bsides Knoxville - APT2
Bsides Knoxville - APT2Bsides Knoxville - APT2
Bsides Knoxville - APT2Adam Compton
 

Plus de Adam Compton (9)

Becoming a Pentester
Becoming a PentesterBecoming a Pentester
Becoming a Pentester
 
A HillyBilly's Guide to Staying Anonymous Online - SecureWV
A HillyBilly's Guide to Staying Anonymous Online - SecureWVA HillyBilly's Guide to Staying Anonymous Online - SecureWV
A HillyBilly's Guide to Staying Anonymous Online - SecureWV
 
BSidesKnoxville 2019 - Unix: The Other White Meat
BSidesKnoxville 2019 - Unix: The Other White MeatBSidesKnoxville 2019 - Unix: The Other White Meat
BSidesKnoxville 2019 - Unix: The Other White Meat
 
SecureWV - APT2
SecureWV - APT2SecureWV - APT2
SecureWV - APT2
 
HackCon - SPF
HackCon - SPFHackCon - SPF
HackCon - SPF
 
DerbyCon - Legion
DerbyCon - LegionDerbyCon - Legion
DerbyCon - Legion
 
DerbyCon - APT2
DerbyCon - APT2DerbyCon - APT2
DerbyCon - APT2
 
Bsides Knoxville - OSINT
Bsides Knoxville - OSINTBsides Knoxville - OSINT
Bsides Knoxville - OSINT
 
Bsides Knoxville - APT2
Bsides Knoxville - APT2Bsides Knoxville - APT2
Bsides Knoxville - APT2
 

Dernier

20240508 QFM014 Elixir Reading List April 2024.pdf
20240508 QFM014 Elixir Reading List April 2024.pdf20240508 QFM014 Elixir Reading List April 2024.pdf
20240508 QFM014 Elixir Reading List April 2024.pdfMatthew Sinclair
 
"Boost Your Digital Presence: Partner with a Leading SEO Agency"
"Boost Your Digital Presence: Partner with a Leading SEO Agency""Boost Your Digital Presence: Partner with a Leading SEO Agency"
"Boost Your Digital Presence: Partner with a Leading SEO Agency"growthgrids
 
Microsoft Azure Arc Customer Deck Microsoft
Microsoft Azure Arc Customer Deck MicrosoftMicrosoft Azure Arc Customer Deck Microsoft
Microsoft Azure Arc Customer Deck MicrosoftAanSulistiyo
 
一比一原版(Curtin毕业证书)科廷大学毕业证原件一模一样
一比一原版(Curtin毕业证书)科廷大学毕业证原件一模一样一比一原版(Curtin毕业证书)科廷大学毕业证原件一模一样
一比一原版(Curtin毕业证书)科廷大学毕业证原件一模一样ayvbos
 
20240507 QFM013 Machine Intelligence Reading List April 2024.pdf
20240507 QFM013 Machine Intelligence Reading List April 2024.pdf20240507 QFM013 Machine Intelligence Reading List April 2024.pdf
20240507 QFM013 Machine Intelligence Reading List April 2024.pdfMatthew Sinclair
 
Story Board.pptxrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrr
Story Board.pptxrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrStory Board.pptxrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrr
Story Board.pptxrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrHenryBriggs2
 
Trump Diapers Over Dems t shirts Sweatshirt
Trump Diapers Over Dems t shirts SweatshirtTrump Diapers Over Dems t shirts Sweatshirt
Trump Diapers Over Dems t shirts Sweatshirtrahman018755
 
Indian Escort in Abu DHabi 0508644382 Abu Dhabi Escorts
Indian Escort in Abu DHabi 0508644382 Abu Dhabi EscortsIndian Escort in Abu DHabi 0508644382 Abu Dhabi Escorts
Indian Escort in Abu DHabi 0508644382 Abu Dhabi EscortsMonica Sydney
 
哪里办理美国迈阿密大学毕业证(本硕)umiami在读证明存档可查
哪里办理美国迈阿密大学毕业证(本硕)umiami在读证明存档可查哪里办理美国迈阿密大学毕业证(本硕)umiami在读证明存档可查
哪里办理美国迈阿密大学毕业证(本硕)umiami在读证明存档可查ydyuyu
 
Nagercoil Escorts Service Girl ^ 9332606886, WhatsApp Anytime Nagercoil
Nagercoil Escorts Service Girl ^ 9332606886, WhatsApp Anytime NagercoilNagercoil Escorts Service Girl ^ 9332606886, WhatsApp Anytime Nagercoil
Nagercoil Escorts Service Girl ^ 9332606886, WhatsApp Anytime Nagercoilmeghakumariji156
 
best call girls in Hyderabad Finest Escorts Service 📞 9352988975 📞 Available ...
best call girls in Hyderabad Finest Escorts Service 📞 9352988975 📞 Available ...best call girls in Hyderabad Finest Escorts Service 📞 9352988975 📞 Available ...
best call girls in Hyderabad Finest Escorts Service 📞 9352988975 📞 Available ...kajalverma014
 
PowerDirector Explination Process...pptx
PowerDirector Explination Process...pptxPowerDirector Explination Process...pptx
PowerDirector Explination Process...pptxgalaxypingy
 
Best SEO Services Company in Dallas | Best SEO Agency Dallas
Best SEO Services Company in Dallas | Best SEO Agency DallasBest SEO Services Company in Dallas | Best SEO Agency Dallas
Best SEO Services Company in Dallas | Best SEO Agency DallasDigicorns Technologies
 
一比一原版(Offer)康考迪亚大学毕业证学位证靠谱定制
一比一原版(Offer)康考迪亚大学毕业证学位证靠谱定制一比一原版(Offer)康考迪亚大学毕业证学位证靠谱定制
一比一原版(Offer)康考迪亚大学毕业证学位证靠谱定制pxcywzqs
 
pdfcoffee.com_business-ethics-q3m7-pdf-free.pdf
pdfcoffee.com_business-ethics-q3m7-pdf-free.pdfpdfcoffee.com_business-ethics-q3m7-pdf-free.pdf
pdfcoffee.com_business-ethics-q3m7-pdf-free.pdfJOHNBEBONYAP1
 
一比一原版(Flinders毕业证书)弗林德斯大学毕业证原件一模一样
一比一原版(Flinders毕业证书)弗林德斯大学毕业证原件一模一样一比一原版(Flinders毕业证书)弗林德斯大学毕业证原件一模一样
一比一原版(Flinders毕业证书)弗林德斯大学毕业证原件一模一样ayvbos
 
75539-Cyber Security Challenges PPT.pptx
75539-Cyber Security Challenges PPT.pptx75539-Cyber Security Challenges PPT.pptx
75539-Cyber Security Challenges PPT.pptxAsmae Rabhi
 
Top profile Call Girls In Dindigul [ 7014168258 ] Call Me For Genuine Models ...
Top profile Call Girls In Dindigul [ 7014168258 ] Call Me For Genuine Models ...Top profile Call Girls In Dindigul [ 7014168258 ] Call Me For Genuine Models ...
Top profile Call Girls In Dindigul [ 7014168258 ] Call Me For Genuine Models ...gajnagarg
 
原版制作美国爱荷华大学毕业证(iowa毕业证书)学位证网上存档可查
原版制作美国爱荷华大学毕业证(iowa毕业证书)学位证网上存档可查原版制作美国爱荷华大学毕业证(iowa毕业证书)学位证网上存档可查
原版制作美国爱荷华大学毕业证(iowa毕业证书)学位证网上存档可查ydyuyu
 
Power point inglese - educazione civica di Nuria Iuzzolino
Power point inglese - educazione civica di Nuria IuzzolinoPower point inglese - educazione civica di Nuria Iuzzolino
Power point inglese - educazione civica di Nuria Iuzzolinonuriaiuzzolino1
 

Dernier (20)

20240508 QFM014 Elixir Reading List April 2024.pdf
20240508 QFM014 Elixir Reading List April 2024.pdf20240508 QFM014 Elixir Reading List April 2024.pdf
20240508 QFM014 Elixir Reading List April 2024.pdf
 
"Boost Your Digital Presence: Partner with a Leading SEO Agency"
"Boost Your Digital Presence: Partner with a Leading SEO Agency""Boost Your Digital Presence: Partner with a Leading SEO Agency"
"Boost Your Digital Presence: Partner with a Leading SEO Agency"
 
Microsoft Azure Arc Customer Deck Microsoft
Microsoft Azure Arc Customer Deck MicrosoftMicrosoft Azure Arc Customer Deck Microsoft
Microsoft Azure Arc Customer Deck Microsoft
 
一比一原版(Curtin毕业证书)科廷大学毕业证原件一模一样
一比一原版(Curtin毕业证书)科廷大学毕业证原件一模一样一比一原版(Curtin毕业证书)科廷大学毕业证原件一模一样
一比一原版(Curtin毕业证书)科廷大学毕业证原件一模一样
 
20240507 QFM013 Machine Intelligence Reading List April 2024.pdf
20240507 QFM013 Machine Intelligence Reading List April 2024.pdf20240507 QFM013 Machine Intelligence Reading List April 2024.pdf
20240507 QFM013 Machine Intelligence Reading List April 2024.pdf
 
Story Board.pptxrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrr
Story Board.pptxrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrStory Board.pptxrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrr
Story Board.pptxrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrr
 
Trump Diapers Over Dems t shirts Sweatshirt
Trump Diapers Over Dems t shirts SweatshirtTrump Diapers Over Dems t shirts Sweatshirt
Trump Diapers Over Dems t shirts Sweatshirt
 
Indian Escort in Abu DHabi 0508644382 Abu Dhabi Escorts
Indian Escort in Abu DHabi 0508644382 Abu Dhabi EscortsIndian Escort in Abu DHabi 0508644382 Abu Dhabi Escorts
Indian Escort in Abu DHabi 0508644382 Abu Dhabi Escorts
 
哪里办理美国迈阿密大学毕业证(本硕)umiami在读证明存档可查
哪里办理美国迈阿密大学毕业证(本硕)umiami在读证明存档可查哪里办理美国迈阿密大学毕业证(本硕)umiami在读证明存档可查
哪里办理美国迈阿密大学毕业证(本硕)umiami在读证明存档可查
 
Nagercoil Escorts Service Girl ^ 9332606886, WhatsApp Anytime Nagercoil
Nagercoil Escorts Service Girl ^ 9332606886, WhatsApp Anytime NagercoilNagercoil Escorts Service Girl ^ 9332606886, WhatsApp Anytime Nagercoil
Nagercoil Escorts Service Girl ^ 9332606886, WhatsApp Anytime Nagercoil
 
best call girls in Hyderabad Finest Escorts Service 📞 9352988975 📞 Available ...
best call girls in Hyderabad Finest Escorts Service 📞 9352988975 📞 Available ...best call girls in Hyderabad Finest Escorts Service 📞 9352988975 📞 Available ...
best call girls in Hyderabad Finest Escorts Service 📞 9352988975 📞 Available ...
 
PowerDirector Explination Process...pptx
PowerDirector Explination Process...pptxPowerDirector Explination Process...pptx
PowerDirector Explination Process...pptx
 
Best SEO Services Company in Dallas | Best SEO Agency Dallas
Best SEO Services Company in Dallas | Best SEO Agency DallasBest SEO Services Company in Dallas | Best SEO Agency Dallas
Best SEO Services Company in Dallas | Best SEO Agency Dallas
 
一比一原版(Offer)康考迪亚大学毕业证学位证靠谱定制
一比一原版(Offer)康考迪亚大学毕业证学位证靠谱定制一比一原版(Offer)康考迪亚大学毕业证学位证靠谱定制
一比一原版(Offer)康考迪亚大学毕业证学位证靠谱定制
 
pdfcoffee.com_business-ethics-q3m7-pdf-free.pdf
pdfcoffee.com_business-ethics-q3m7-pdf-free.pdfpdfcoffee.com_business-ethics-q3m7-pdf-free.pdf
pdfcoffee.com_business-ethics-q3m7-pdf-free.pdf
 
一比一原版(Flinders毕业证书)弗林德斯大学毕业证原件一模一样
一比一原版(Flinders毕业证书)弗林德斯大学毕业证原件一模一样一比一原版(Flinders毕业证书)弗林德斯大学毕业证原件一模一样
一比一原版(Flinders毕业证书)弗林德斯大学毕业证原件一模一样
 
75539-Cyber Security Challenges PPT.pptx
75539-Cyber Security Challenges PPT.pptx75539-Cyber Security Challenges PPT.pptx
75539-Cyber Security Challenges PPT.pptx
 
Top profile Call Girls In Dindigul [ 7014168258 ] Call Me For Genuine Models ...
Top profile Call Girls In Dindigul [ 7014168258 ] Call Me For Genuine Models ...Top profile Call Girls In Dindigul [ 7014168258 ] Call Me For Genuine Models ...
Top profile Call Girls In Dindigul [ 7014168258 ] Call Me For Genuine Models ...
 
原版制作美国爱荷华大学毕业证(iowa毕业证书)学位证网上存档可查
原版制作美国爱荷华大学毕业证(iowa毕业证书)学位证网上存档可查原版制作美国爱荷华大学毕业证(iowa毕业证书)学位证网上存档可查
原版制作美国爱荷华大学毕业证(iowa毕业证书)学位证网上存档可查
 
Power point inglese - educazione civica di Nuria Iuzzolino
Power point inglese - educazione civica di Nuria IuzzolinoPower point inglese - educazione civica di Nuria Iuzzolino
Power point inglese - educazione civica di Nuria Iuzzolino
 

Infosec Europe 17 - PentestFails

  • 1. Adam Compton – Senior Security Consultant Learning From Mistakes - They Will Happen
  • 2. Learning from Mistakes – They Will Happen • Who am I? • Simple answer: • Father/Husband/Son/Brother • Programmer/Pentester/Researcher • Hillybilly Me Me Me…
  • 3. Learning from Mistakes – They Will Happen “I have not failed. I've just found 10,000 ways that won't work.” - Thomas Edison
  • 4. Learning from Mistakes – They Will Happen “The only real mistake is the one from which we learn nothing.” - Henry Ford
  • 5. Learning from Mistakes – They Will Happen • /bin/sh used to truncate commands after a certain length • AAA.BBB.237.0/24 != AAA.BBB.2 • Nmap used to auto-append implied CIDR notation • AAA.BBB.2 -> AAA.BBB.2.0/24 • AAA.BBB.2.0/24 != AAA>BBB.237.0/24 Watch those octets
  • 6. Learning from Mistakes – They Will Happen “You build on failure. You use it as a stepping stone. Close the door on the past. You don't try to forget the mistakes, but you don't dwell on it. You don't let it have any of your energy, or any of your time, or any of your space.” - Johnny Cash
  • 7. Learning from Mistakes – They Will Happen “Success is not final, failure is not fatal: it is the courage to continue that counts.” - Winston Churchill
  • 8. Learning from Mistakes – They Will Happen “A person who never made a mistake never tried anything new.” - Albert Einstein
  • 9. Learning from Mistakes – They Will Happen “Mistakes are a part of being human. Appreciate your mistakes for what they are: precious life lessons that can only be learned the hard way. “Unless it's a fatal mistake, which, at least, others can learn from.” - Al Franken On a different engagement, Cheap Pentests R Us was contracted to perform an electronic Social Engineering engagement consisting of just phishing emails. copy-n-paste campaign scenario 1 - no success (servers not turned on) scenario 2 - limited success (wrong company name and logo)
  • 10. Learning from Mistakes – They Will Happen “Our greatest glory is not in never failing, but in rising every time we fail.” - Confucius
  • 11. Learning from Mistakes – They Will Happen • Always double check everything • If something does not feel right, it probably isn’t • Never rely on just one access vector • It is okay to make mistakes Takeaways
  • 12. Learning from Mistakes – They Will Happen adam_compton@rapid7.com @tatanus Questions ? Comments ? Thoughts ? Stories ?

Notes de l'éditeur

  1. Welcome. I hope everyone is ready to hear a few painful stories of how I ... and others have made humorous mistakes on pentests and learned something along the way.
  2. Me? I have been around for a while… about 18 years or so in the InfoSec field. Over that time, I have been a programmer, researcher, and pentester (currently for Rapid7). But most of all, I am a father, husband, son, and brother.
  3. As I hope you noticed on the schedule or because I placed it on the first slide, today I will be talking about mistakes, FAILS, and lessons learned.   What? I am not going to talk about some new exploit or some awesome new tool or something like that? Not this time. I have done that in the past an will likely do it again, but this time, I wanted to take on a different topic that is not often discussed.   In InfoSec, via social media, conference talks, colleagues, and the news, we hear a lot about new discoveries, new exploits, and new data leaks on a regular basis. But we typically do not hear about all the failed attempts and all the long hours that went into producing those awesome WINs.   Obviously, it is always fun to hear and talk about those things, but at the same time it can be very discouraging, especially if you are one of the people who is not always making the new discoveries or is simply prone to making lots of mistakes like I do.   My hope is that by bring stories of these difficulties and failures out into the open, it may help a few people learn that it is okay to make mistakes. Our director of research always says that it is the experience you build over time that matters, not that it just took you 2 hours to do something.
  4. When I first started in InfoSec, I had no idea of what I was doing.   1st day - build a lab 2nd week - go on an engagement (make mistakes) Usually paired with mentor took many months to feel competent   Over the years, I kept making mistakes and learning from them to become more proficient. Did I every stop making mistakes, of course not.
  5. ...  After it was all said and done, my boss and peers of course laughed about it a bit but no one tried to make me feel bad about it. The general response was that, we all make mistakes and it is fine. Just try to learn for them as to not make the same one again if possible. That stuck with me and has become a sort of life motto for me.   Enough of my life story, let’s laugh at and learn from some other people’s fails now shall we.
  6. Network based web cameras…   I have some friends which work at another company,   One on particular internal engagement, they were targeting a university. --LEON On a different engagement, they were targeting a legal office’s Internet facing systems. --SCHOOL
  7. Let’s get Physical pen testing the wrong building locking ourselves out of the building on a physical
  8. Pentesting when tired listening to the intern and closing out the only access we had
  9. phishing emails.   copy-n-paste campaign scenario 1 - no success (servers not turned on) scenario 2 - limited success (wrong company name and logo)
  10. As anyone who knows me can attest to, I have made more mistakes than I can count.   Luckily I have slowly been learning from my mistakes and gradually I have been improving. I have made it a point to never let a mistake derail me.   Most mistakes I can shrug off and continue as normal. However, every once in a while, I will encounter a mistake/failure that it is so profound that it does stop me for me a bit. At those times, I stop, regroup, take it a step at a time and before I know it, I am back to fighting shape and on my way.   If you let them, fails and such will have a profoundly negative impact on you. Just remember that everyone makes mistakes. Just learn from them and try not to dwell to long on them.
  11. Always Double Check Everything If Something Does Not Feel Right, It Probably Isn’t Never Rely On Just One Access Vector
  12. In closing, I would just like to repeat that mistakes do happen and that is ok.   It is a matter of how you deal with them and what you can learn from them that will determine how they affect you in the long run.   And if you are so inclined, please share your hard-earned lessons with others so that you can possibly help other to not make the same mistakes.   And Thank you.   Now, any questions?