EsoOnce I wentinto i t andcybersecurity, I neverlookedbackand I'veneverbeenhappieronthedaytoday I am a seniorsecurityengineer.
I'm also a businessowneratTCMSecurity.
Sobeforethat, I was a seniorpenetrationtesterdoingpenetration, testinganethicalhacking.
I branchedoutandstartedmyownbusiness, focusingonethicalhacking, trainingandstudentdevelopment s Sonow I'm doingthatfulltime, alongwith a jobas a seniorsecurityengineer.
Sowe'regoingtowrite, Ah, basicbashscriptandthenwe'llimproveuponitandthen I'llshowyousomefourloops, someotherlogicalscriptingideasandthenwe'llkindofputthattogetherandhopefullycometo a nicecompletionwhenit's allsaidanddone.
Sowithallthisbeingsaid, I amexcitedtohaveyouinthecoursewithme.
I lookforwardtoteachingyouandlet's goaheadandstartwithinstallingBMwhereallright, thefirstthingthatwe'regoingtoneedtodoistoinstallsoftwarecalledthe M WearWorkstationPlayer.
NowwehavetwowaystorunKallieLennox.
WecaneitherrunKallieLennoxthrough a virtualmachineorweaken.
Stallitasanoperatingsystemon a harddriveforthiscourseandthislesson, we'regonnabeusing a virtualmachineandpreferablywe'regonnabeusingbeingwhereworkstationplayer.
IfyoucometoCalidotorgoandyoulookattheaboutus, itprovides a littlebitofinformationaboutwhothecoredeveloperswereandsomeofthemoderators.
Butbasicallywhatitisis, uh, itfollowedup a toolcalledordistributioncalledBacktrack s O thenewThenewtoolisCallieLennix.
Nowtherearealternativesoutthere.
Oneofthealternativesrightnowiscalledparrot s.
Ifyougoto a parentsecdotorGEandyoulookintowhatisparent, youcanseethattheyhavedifferentdistributionsandtheytalkaboutwhyparentsdifferent, buttheydohave a pentestdistributionhere.
Soforthiscourse, we'regoingtobeusingCallieLennox.
But I alwaysdoliketointroducethealternatives.
Um, CallieLennoxisprobablymorepopularatthispoint.
Parrotosiskindofonthenewerside.
Somepeoplearestartingtogetbehinditandlikingit.
But I wouldsayCalliestilldominates.
Thethirdoptionisthatyousetupyourowndistributionsoyouhaven't a lessthatyoulike, andthenyouinstallthetoolsontheOSthatyoulikeandyouhaveyourowncustombuild.
I wanttogototheCaliLennoxcustomimagedownloadspage, and I'llshowyouWhyhere.
Sothisisthatoffensivedashsecuritydotcom.
Makesurethat's theoneyou'refallingalongwith.
Andifyouscrolldownjust a bit, youseethatthey'reprovidingusof'emwereimagesandvirtualboximagestorememberwhen I toldyouthatvirtualboxisanoptionifyouchosethatoption.
Sofromhere, wecanactuallynavigatoallthesefoldershere, andwecanputfilesinthere, takefoulsoutanythingthatwecandoand a graphicpointofview.
Wecanalsodofromthiscommandlinepointofviewaswell.
Soaswelearn, we'regoingtoget a littlelessrelyingonthegraphicalinterfaceandmoreontheterminalsideofthings, however, doknowthattherearewaystodo a lotofthingsfrom a graphicalside.
Ifyoustill I meanthatthatinteractionwiththemachineandyoudon't wanttobecompletelykeyboardoriented.
Therearealsotoolsonthesideoverhere.
IfweLook, we'vegot a leafpads.
A leafpadisjustlike a notepad, right?
Or, youknow, justyournotebook.
Hereyoucantakesomequicknotes.
Saveitout.
Shouldbeprettyfamiliarforyouaswell.
EsoThey'vegotfireFoxthatusedtobecallediceweasel.
Andthat's justyourWebbrowser.
DownherearesomeofthetoolsthatyoumayuseNow.
BurbSuiteis a verypopulartoolforWebapplicationpenetrationtesting.
We'renotgettingintoanyofthesetoolsatthemoment, but I willcoverwhat a coupleofthemdosoagain.
BurbSweets, a Webapplicationpenetrationtestingtool.
IfyouevergetintoWebapp, orifyouevengetintosomebasicpentesting, chancesareyou'regoingtostartusingburbsweeton a prettyregularbasis.
Overhereis N map.
Nowthisisthegraphicalversionof a toolcalledendmap, andyouwillbeusingandmapprettyreligiouslywhenyou'redoingpentesting.
Soifyoulike a visualviewofdoingscanningsoandmapis a networkmapper, itallowsyoutoscanmachinesforopenports.
Ah, andforvulnerabilities.
Soifyouwantthatin a moreof a visualtypeofyou a graphicalinterfacetypeyou, thenyouhaveZenmapas a feature.
Andifyou'rebecoming a pentester, you'reworkingonit, youknow, justjust, um, youknow, lookat a toolanddosomeresearchonit.
SayyouwanttoknowwhatthisMacchangeris.
Itmightbeobviousitmightnotbeobvious, right?
S o.
MaybeyougoGooglewhatMacchangeordoeshowtouseitwiththesintaxesandthenyouplayaroundwiththat, take a newtooleveryday, figureoutsomethingthatyoucandowithit, howtouseit, whatitdoes.
ButsoCallieLennoxis a distributionfullofusefultoolsonit.
Eventuallyinyourcareer, yousay, Hey, I want, uh I wanttolearnallthesethingsfirst.
Andthenonce I learnedwhattools I reallylikeThenmaybeyoumovetoyourowndistributionthatyoucreateyourselfandyouspendthatupeverytimeinsteadofhavingallthesetoolsbuiltinbutas a baseOSassomethingthatyoucanlearnfromandstartwith.
Soifwewantedtogotodesktop, wecouldwecouldhit l s nowandseewhat's inthere.
Wewantedtogobackwards.
WecouldOkay, nowwe'rebackinourourrootfolder.
Andyoucanalsotellwhereyou'reatyourpresident.
Workingdirectorysitsrighthere.
Right.
Sothislittle a tildeisactuallyyourhomefolderandyoucanseethatwe'reindesktop.
SoifwewantedtogobackintoourdesktopinsteadoftypingSoyouwantedtogotomusicfromyourdesktopinsteadofgoingroutemusic, whichwillwork, youcouldalsojustsay I wanttogomusic, andthatwillputyouthereaswellandnoticeyoudon't needtheleadingforwardslashwhenyouusethe a toldup.