diff --git a/.gitattributes b/.gitattributes index a6344aac8c09253b3b630fb776ae94478aa0275b..781751064c5b7d25795701f8db6c7131a394e321 100644 --- a/.gitattributes +++ b/.gitattributes @@ -33,3 +33,35 @@ saved_model/**/* filter=lfs diff=lfs merge=lfs -text *.zip filter=lfs diff=lfs merge=lfs -text *.zst filter=lfs diff=lfs merge=lfs -text *tfevents* filter=lfs diff=lfs merge=lfs -text +01[[:space:]]-[[:space:]]Introduction/001[[:space:]]Course[[:space:]]Layout.mp4 filter=lfs diff=lfs merge=lfs -text +01[[:space:]]-[[:space:]]Introduction/002[[:space:]]30[[:space:]]Day[[:space:]]Study[[:space:]]Plan.mp4 filter=lfs diff=lfs merge=lfs -text +01[[:space:]]-[[:space:]]Introduction/003[[:space:]]Exam[[:space:]]Information.mp4 filter=lfs diff=lfs merge=lfs -text +01[[:space:]]-[[:space:]]Introduction/005[[:space:]]30-Day-study-Plan.pdf filter=lfs diff=lfs merge=lfs -text +01[[:space:]]-[[:space:]]Introduction/004[[:space:]]Exam[[:space:]]Domains.mp4 filter=lfs diff=lfs merge=lfs -text +01[[:space:]]-[[:space:]]Introduction/005[[:space:]]Course-Notes.pdf filter=lfs diff=lfs merge=lfs -text +01[[:space:]]-[[:space:]]Introduction/005[[:space:]]Security-Last-Minute-Cram-Guide.pdf filter=lfs diff=lfs merge=lfs -text +01[[:space:]]-[[:space:]]Introduction/005[[:space:]]comptia-security-sy0-701-exam-objectives-5-0.pdf filter=lfs diff=lfs merge=lfs -text +02[[:space:]]-[[:space:]]Lesson[[:space:]]1[[:space:]]IT[[:space:]]Security[[:space:]]Fundamentals/001[[:space:]]Introduction[[:space:]]IT[[:space:]]Security[[:space:]]Fundamentals[[:space:]]OB[[:space:]]1.2.mp4 filter=lfs diff=lfs merge=lfs -text +02[[:space:]]-[[:space:]]Lesson[[:space:]]1[[:space:]]IT[[:space:]]Security[[:space:]]Fundamentals/002[[:space:]]CIA[[:space:]]Triad[[:space:]]OB[[:space:]]1.2.mp4 filter=lfs diff=lfs merge=lfs -text +02[[:space:]]-[[:space:]]Lesson[[:space:]]1[[:space:]]IT[[:space:]]Security[[:space:]]Fundamentals/003[[:space:]]Confidentiality[[:space:]]OB[[:space:]]1.2.mp4 filter=lfs diff=lfs merge=lfs -text +02[[:space:]]-[[:space:]]Lesson[[:space:]]1[[:space:]]IT[[:space:]]Security[[:space:]]Fundamentals/004[[:space:]]Integrity[[:space:]]OB[[:space:]]1.2.mp4 filter=lfs diff=lfs merge=lfs -text +02[[:space:]]-[[:space:]]Lesson[[:space:]]1[[:space:]]IT[[:space:]]Security[[:space:]]Fundamentals/006[[:space:]]DAD[[:space:]]Triade[[:space:]]OB[[:space:]]1.2.mp4 filter=lfs diff=lfs merge=lfs -text +02[[:space:]]-[[:space:]]Lesson[[:space:]]1[[:space:]]IT[[:space:]]Security[[:space:]]Fundamentals/005[[:space:]]Availability[[:space:]]OB[[:space:]]1.2.mp4 filter=lfs diff=lfs merge=lfs -text +02[[:space:]]-[[:space:]]Lesson[[:space:]]1[[:space:]]IT[[:space:]]Security[[:space:]]Fundamentals/008[[:space:]]Non-Repudiation[[:space:]]OB[[:space:]]1.2.mp4 filter=lfs diff=lfs merge=lfs -text +02[[:space:]]-[[:space:]]Lesson[[:space:]]1[[:space:]]IT[[:space:]]Security[[:space:]]Fundamentals/007[[:space:]]Zero[[:space:]]Trust[[:space:]]OB[[:space:]]1.2.mp4 filter=lfs diff=lfs merge=lfs -text +02[[:space:]]-[[:space:]]Lesson[[:space:]]1[[:space:]]IT[[:space:]]Security[[:space:]]Fundamentals/009[[:space:]]Authentication[[:space:]]OB[[:space:]]1.2.mp4 filter=lfs diff=lfs merge=lfs -text +02[[:space:]]-[[:space:]]Lesson[[:space:]]1[[:space:]]IT[[:space:]]Security[[:space:]]Fundamentals/010[[:space:]]Authorization[[:space:]]OB[[:space:]]1.2.mp4 filter=lfs diff=lfs merge=lfs -text +02[[:space:]]-[[:space:]]Lesson[[:space:]]1[[:space:]]IT[[:space:]]Security[[:space:]]Fundamentals/012[[:space:]]Accountability[[:space:]]OB[[:space:]]1.2.mp4 filter=lfs diff=lfs merge=lfs -text +02[[:space:]]-[[:space:]]Lesson[[:space:]]1[[:space:]]IT[[:space:]]Security[[:space:]]Fundamentals/011[[:space:]]Accounting[[:space:]]OB[[:space:]]1.2.mp4 filter=lfs diff=lfs merge=lfs -text +02[[:space:]]-[[:space:]]Lesson[[:space:]]1[[:space:]]IT[[:space:]]Security[[:space:]]Fundamentals/013[[:space:]]Gap[[:space:]]analysis[[:space:]]OB[[:space:]]1.2.mp4 filter=lfs diff=lfs merge=lfs -text +03[[:space:]]-[[:space:]]Security[[:space:]]Controls[[:space:]]Categories[[:space:]]and[[:space:]]Types/002[[:space:]]Control[[:space:]]Types[[:space:]]OB[[:space:]]1.1.mp4 filter=lfs diff=lfs merge=lfs -text +03[[:space:]]-[[:space:]]Security[[:space:]]Controls[[:space:]]Categories[[:space:]]and[[:space:]]Types/001[[:space:]]Control[[:space:]]Categories[[:space:]]OB[[:space:]]1.1.mp4 filter=lfs diff=lfs merge=lfs -text +03[[:space:]]-[[:space:]]Security[[:space:]]Controls[[:space:]]Categories[[:space:]]and[[:space:]]Types/003[[:space:]]Defense[[:space:]]in[[:space:]]Depth[[:space:]]OB[[:space:]]1.1.mp4 filter=lfs diff=lfs merge=lfs -text +04[[:space:]]-[[:space:]]Threats/002[[:space:]]Threats[[:space:]]OB[[:space:]]2.1.mp4 filter=lfs diff=lfs merge=lfs -text +04[[:space:]]-[[:space:]]Threats/001[[:space:]]Threats[[:space:]]Motivation[[:space:]]OB[[:space:]]2.1.mp4 filter=lfs diff=lfs merge=lfs -text +04[[:space:]]-[[:space:]]Threats/003[[:space:]]Attributes[[:space:]]of[[:space:]]Actors[[:space:]]OB[[:space:]]2.1.mp4 filter=lfs diff=lfs merge=lfs -text +04[[:space:]]-[[:space:]]Threats/005[[:space:]]Unskilled[[:space:]]Attacker[[:space:]]OB[[:space:]]2.1.mp4 filter=lfs diff=lfs merge=lfs -text +04[[:space:]]-[[:space:]]Threats/004[[:space:]]Nation-state[[:space:]]OB[[:space:]]2.1.mp4 filter=lfs diff=lfs merge=lfs -text +04[[:space:]]-[[:space:]]Threats/006[[:space:]]Hacktivist[[:space:]]OB[[:space:]]2.1.mp4 filter=lfs diff=lfs merge=lfs -text +04[[:space:]]-[[:space:]]Threats/007[[:space:]]Organized[[:space:]]Crime[[:space:]]OB[[:space:]]2.1.mp4 filter=lfs diff=lfs merge=lfs -text +04[[:space:]]-[[:space:]]Threats/008[[:space:]]Shadow[[:space:]]IT[[:space:]]OB[[:space:]]2.1.mp4 filter=lfs diff=lfs merge=lfs -text diff --git a/01 - Introduction/001 Course Layout.mp4 b/01 - Introduction/001 Course Layout.mp4 new file mode 100644 index 0000000000000000000000000000000000000000..c0729eb03e5482f7e3eb100d85883ac778383ed1 --- /dev/null +++ b/01 - Introduction/001 Course Layout.mp4 @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:40ca94e4c14019c5944b32c20151709a537d7010d2fe6498f765fe9261e30d31 +size 175684496 diff --git a/01 - Introduction/001 Course Layout_en.srt b/01 - Introduction/001 Course Layout_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..902a39e10dbcdbb2bc43070f331765b75b1557cd --- /dev/null +++ b/01 - Introduction/001 Course Layout_en.srt @@ -0,0 +1,660 @@ +1 +00:00:00,000 --> 00:00:05,000 +Okay, before we dive into the material, I want to go over the actual interface that you're going to + +2 +00:00:05,000 --> 00:00:10,000 +be using to navigate this course, how the courses laid out, what should you be expecting at the end + +3 +00:00:10,000 --> 00:00:14,000 +of every lecture and all the resources that's available to you? + +4 +00:00:14,000 --> 00:00:15,000 +Let's get started. + +5 +00:00:15,000 --> 00:00:18,000 +Now the first thing I want to mention is the layout of this course. + +6 +00:00:18,000 --> 00:00:24,000 +So if you're watching this on the Udemy platform, you're very, very familiar with the layout of this + +7 +00:00:24,000 --> 00:00:27,000 +particular class or the Udemy interface. + +8 +00:00:27,000 --> 00:00:35,000 +In other words, so what it is is that the course is separated into 27 sections sections, the first + +9 +00:00:35,000 --> 00:00:41,000 +one being the introduction all the way to section 25 covers all the exam topics. + +10 +00:00:41,000 --> 00:00:43,000 +Section 26 is called labs. + +11 +00:00:43,000 --> 00:00:48,000 +Labs are going to allow you to practice what I have been talking about for 25 sections or. + +12 +00:00:48,000 --> 00:00:52,000 +And then finally the last one at the bottom says Mock exam. + +13 +00:00:52,000 --> 00:00:55,000 +I know I'm blocking my camera here, seems to be blocking it. + +14 +00:00:55,000 --> 00:01:01,000 +Um, there's one mock exam in this course that you guys should be taking when you finish the entire + +15 +00:01:01,000 --> 00:01:02,000 +course. + +16 +00:01:02,000 --> 00:01:04,000 +Now let's take a look at one of these sections. + +17 +00:01:04,000 --> 00:01:11,000 +So these sections are basically labeled with some kind of security topics like section nine is secure + +18 +00:01:11,000 --> 00:01:11,000 +and IT assets. + +19 +00:01:11,000 --> 00:01:13,000 +Section 11 security principles. + +20 +00:01:13,000 --> 00:01:15,000 +Section 12 data protection. + +21 +00:01:15,000 --> 00:01:20,000 +Every time you open a section, you're going to find a series of lectures next to the name of every + +22 +00:01:20,000 --> 00:01:21,000 +lecture. + +23 +00:01:21,000 --> 00:01:23,000 +You're going to see something that says OB and then a number. + +24 +00:01:24,000 --> 00:01:28,000 +This refers to the exam objectives that is coming from. + +25 +00:01:28,000 --> 00:01:33,000 +And I'll explain to you guys in a few minutes what exactly are those exam objectives? + +26 +00:01:34,000 --> 00:01:38,000 +At the end of every single one of the sections, you're going to have what's called a quick quiz. + +27 +00:01:38,000 --> 00:01:44,000 +This is five questions that basically tested your knowledge on those particular topics that you just + +28 +00:01:44,000 --> 00:01:45,000 +learned about in the section. + +29 +00:01:45,000 --> 00:01:49,000 +So every one of the sections have a quick quiz located there. + +30 +00:01:50,000 --> 00:01:52,000 +Um, so keep that in mind. + +31 +00:01:52,000 --> 00:01:57,000 +Every single lecture has a number that comes after it. + +32 +00:01:57,000 --> 00:01:59,000 +That number is the exam objectives. + +33 +00:01:59,000 --> 00:02:02,000 +For example cryptography is objective 1.4. + +34 +00:02:02,000 --> 00:02:04,000 +So that's how this is laid out. + +35 +00:02:04,000 --> 00:02:07,000 +And you just basically click on it and it plays a video for you and you just watch it. + +36 +00:02:08,000 --> 00:02:10,000 +Now what are the resources that comes with it? + +37 +00:02:10,000 --> 00:02:15,000 +If there's one thing I did in this course is that I'm going to be giving you guys tons of resources + +38 +00:02:15,000 --> 00:02:16,000 +that comes with it. + +39 +00:02:16,000 --> 00:02:19,000 +So let's go to the resource section and see what they are. + +40 +00:02:19,000 --> 00:02:23,000 +So in it it's in the introduction. + +41 +00:02:23,000 --> 00:02:27,000 +And number three says course objectives notes and Cram Guide download. + +42 +00:02:27,000 --> 00:02:29,000 +Now you just got to click on this. + +43 +00:02:29,000 --> 00:02:30,000 +Click on every one of them. + +44 +00:02:30,000 --> 00:02:32,000 +There's four things to download and just download it. + +45 +00:02:32,000 --> 00:02:35,000 +They're all PDFs and let's go through what they are. + +46 +00:02:36,000 --> 00:02:41,000 +So the first one up that you should be getting is this CompTIA Security+ exam objectives now. + +47 +00:02:42,000 --> 00:02:44,000 +This CompTIA Security+. + +48 +00:02:44,000 --> 00:02:46,000 +I've already downloaded it. + +49 +00:02:46,000 --> 00:02:50,000 +This is the exam objectives that this entire course is based on. + +50 +00:02:50,000 --> 00:02:59,000 +You guys are studying for Sio 701 or the 701 series of exam, and all the topics that I cover in this + +51 +00:02:59,000 --> 00:02:59,000 +course. + +52 +00:02:59,000 --> 00:03:00,000 +This is where I got it from. + +53 +00:03:00,000 --> 00:03:05,000 +CompTIA publishers publishes this document absolutely free. + +54 +00:03:05,000 --> 00:03:06,000 +You don't have to download it here. + +55 +00:03:06,000 --> 00:03:08,000 +You could download it from Comptia's website. + +56 +00:03:08,000 --> 00:03:10,000 +If you notice I covered some of this already. + +57 +00:03:11,000 --> 00:03:13,000 +We talked about the exam stats. + +58 +00:03:13,000 --> 00:03:15,000 +We talked about the domains that it has. + +59 +00:03:15,000 --> 00:03:20,000 +But if I scroll down, you'll notice that it covers a lot more stuff. + +60 +00:03:20,000 --> 00:03:27,000 +For example, in domain 1.0, general security concepts, it's that itself is broken down into four + +61 +00:03:27,000 --> 00:03:33,000 +sections into 1.1, 1.2, 1.3 and 1.4. + +62 +00:03:33,000 --> 00:03:36,000 +If you remember when we looked at cryptography. + +63 +00:03:38,000 --> 00:03:45,000 +This is a three hour and 35 minute lesson, and in this one you have a 30 lectures actually. + +64 +00:03:45,000 --> 00:03:49,000 +And you notice this is all objective 1.4, 1.41.4. + +65 +00:03:49,000 --> 00:03:50,000 +What am I referring to these things? + +66 +00:03:50,000 --> 00:03:56,000 +1.4 if I look at the next section social engineering. + +67 +00:03:56,000 --> 00:03:59,000 +Social engineering is objective 2.2. + +68 +00:03:59,000 --> 00:04:04,000 +So if I look back here and I look at 2.2, here it is social engineering. + +69 +00:04:04,000 --> 00:04:10,000 +So when you look at every lecture those numbers refers to this document, these things. + +70 +00:04:10,000 --> 00:04:12,000 +This is the exam objective. + +71 +00:04:12,000 --> 00:04:18,000 +Now what's good about the exam objective is that every single one of your questions will come from these + +72 +00:04:18,000 --> 00:04:19,000 +exam objectives. + +73 +00:04:19,000 --> 00:04:26,000 +No question should or would actually come from something outside of these objectives. + +74 +00:04:26,000 --> 00:04:31,000 +If you want to test something that is foreign all right. + +75 +00:04:31,000 --> 00:04:33,000 +They wouldn't put it on this exam. + +76 +00:04:33,000 --> 00:04:35,000 +They wouldn't put it on this security+ test. + +77 +00:04:35,000 --> 00:04:38,000 +Because technically speaking, they could only test you. + +78 +00:04:38,000 --> 00:04:40,000 +What's on this exam objectives. + +79 +00:04:40,000 --> 00:04:43,000 +Now it's from this objective that I create the other guides. + +80 +00:04:43,000 --> 00:04:43,000 +All right. + +81 +00:04:43,000 --> 00:04:44,000 +And I'll show you what I mean. + +82 +00:04:45,000 --> 00:04:48,000 +So make sure you download this and just give a quick review to this. + +83 +00:04:49,000 --> 00:04:52,000 +The other one here I have is going to be. + +84 +00:04:53,000 --> 00:04:54,000 +Course notes. + +85 +00:04:54,000 --> 00:04:55,000 +Now this is really good. + +86 +00:04:55,000 --> 00:04:57,000 +You guys are going to love this one. + +87 +00:04:57,000 --> 00:04:58,000 +Course notes. + +88 +00:04:58,000 --> 00:05:02,000 +Course notes are every single text. + +89 +00:05:02,000 --> 00:05:06,000 +So when I'm presenting you see me point on this section over here. + +90 +00:05:06,000 --> 00:05:08,000 +And you notice that they're text that appears here. + +91 +00:05:08,000 --> 00:05:10,000 +And I explained the text and we talk about it. + +92 +00:05:10,000 --> 00:05:13,000 +And I tell you what you need to know for your exam and so on and so on. + +93 +00:05:13,000 --> 00:05:15,000 +Those texts is this course notes. + +94 +00:05:15,000 --> 00:05:17,000 +Now it is a lot. + +95 +00:05:17,000 --> 00:05:21,000 +It is 850 pages of notes. + +96 +00:05:21,000 --> 00:05:28,000 +As you can see, this is a great set of tools that or I should say content that you can use just to + +97 +00:05:28,000 --> 00:05:28,000 +study. + +98 +00:05:28,000 --> 00:05:32,000 +If you don't like me, you don't like the way I sound is Andrew, you're too ugly. + +99 +00:05:32,000 --> 00:05:34,000 +You need to get some hair on your head. + +100 +00:05:34,000 --> 00:05:35,000 +Basically, you can read this. + +101 +00:05:35,000 --> 00:05:39,000 +I mean, whatever I'm covering is going to be here, so make sure to review this. + +102 +00:05:39,000 --> 00:05:40,000 +This is a great thing. + +103 +00:05:40,000 --> 00:05:41,000 +It's 850. + +104 +00:05:41,000 --> 00:05:47,000 +And every single text that I'm going to be covering, every single text that you see on the right side + +105 +00:05:47,000 --> 00:05:50,000 +of me as I'm teaching is in that PDF. + +106 +00:05:50,000 --> 00:05:55,000 +If you think that's pretty cool, I got something even cooler for you that I'm really proud about because + +107 +00:05:55,000 --> 00:05:56,000 +I think it's pretty cool. + +108 +00:05:58,000 --> 00:06:02,000 +That's going to be this thing, the security plus the last minute cram guide. + +109 +00:06:02,000 --> 00:06:09,000 +So the last minute cram guide is actually a book that I sell on Amazon. + +110 +00:06:10,000 --> 00:06:18,000 +Um, and this particular book, basically it's 84 pages and it explains every single one of the exam + +111 +00:06:18,000 --> 00:06:19,000 +objectives for you. + +112 +00:06:20,000 --> 00:06:23,000 +So here's what I did I took the exam objectives. + +113 +00:06:24,000 --> 00:06:24,000 +All right. + +114 +00:06:24,000 --> 00:06:30,000 +If you remember, there's five domains and I explained every single one. + +115 +00:06:30,000 --> 00:06:31,000 +So here's objective 1.1. + +116 +00:06:32,000 --> 00:06:37,000 +And technical security controls managerial security controls operations security physical security controls. + +117 +00:06:37,000 --> 00:06:39,000 +And I explained every single one there. + +118 +00:06:39,000 --> 00:06:42,000 +So if you look at the exam objectives. + +119 +00:06:44,000 --> 00:06:45,000 +Where is it. + +120 +00:06:45,000 --> 00:06:51,000 +Let's say one okay so 1.1 categories technical managerial operational physical. + +121 +00:06:51,000 --> 00:06:54,000 +If you notice in my cram guide. + +122 +00:06:56,000 --> 00:06:57,000 +Where is my gram guide? + +123 +00:06:58,000 --> 00:07:00,000 +Here we go in my gram guide. + +124 +00:07:00,000 --> 00:07:02,000 +I explain it to you just like that. + +125 +00:07:03,000 --> 00:07:04,000 +You see this? + +126 +00:07:04,000 --> 00:07:09,000 +Technical, managerial, physical, operational. + +127 +00:07:09,000 --> 00:07:10,000 +All explained there. + +128 +00:07:10,000 --> 00:07:11,000 +All right. + +129 +00:07:11,000 --> 00:07:15,000 +Preventative deterrent, detective corrective. + +130 +00:07:15,000 --> 00:07:17,000 +I just explained that. + +131 +00:07:17,000 --> 00:07:19,000 +And if you look in your exam objectives, that's the way you see it. + +132 +00:07:19,000 --> 00:07:21,000 +So this guide is absolutely amazing. + +133 +00:07:21,000 --> 00:07:25,000 +This guide explains every single thing you need to know to pass your test. + +134 +00:07:25,000 --> 00:07:27,000 +Now, I took this exam. + +135 +00:07:27,000 --> 00:07:30,000 +I'm one of the few teachers that actually takes the test that they teach. + +136 +00:07:30,000 --> 00:07:31,000 +Oddly enough. + +137 +00:07:31,000 --> 00:07:37,000 +Now on this particular exam, they're going to acronym you to death. + +138 +00:07:37,000 --> 00:07:42,000 +There's tons of acronym on the Security Plus exam, and they don't explain them on the test. + +139 +00:07:42,000 --> 00:07:43,000 +They'll just say SLA. + +140 +00:07:43,000 --> 00:07:44,000 +You better know what it means. + +141 +00:07:44,000 --> 00:07:49,000 +So what I did was I went to the exam objectives and they actually give you a list of the acronyms. + +142 +00:07:49,000 --> 00:07:53,000 +And I put it into my document and I explained every one for you. + +143 +00:07:53,000 --> 00:07:55,000 +So at the end of this cram guide. + +144 +00:07:56,000 --> 00:07:59,000 +You have all these acronyms and you're probably saying, oh my God, that is a lot. + +145 +00:07:59,000 --> 00:08:02,000 +Yeah, I didn't even realize there were so many acronyms. + +146 +00:08:03,000 --> 00:08:03,000 +It's a lot. + +147 +00:08:04,000 --> 00:08:04,000 +It's a lot. + +148 +00:08:04,000 --> 00:08:06,000 +So you got you want to make sure you review this. + +149 +00:08:06,000 --> 00:08:07,000 +You know what these acronyms are. + +150 +00:08:07,000 --> 00:08:09,000 +Because these acronyms could pop up on your exam. + +151 +00:08:09,000 --> 00:08:11,000 +And if you don't know what they mean, you're not going to get the question right. + +152 +00:08:11,000 --> 00:08:13,000 +So it's quite a lot. + +153 +00:08:13,000 --> 00:08:16,000 +And trust me, as you go through the course I'm basically going to cover all of them. + +154 +00:08:16,000 --> 00:08:19,000 +So by the time you come to the cram guide, you're probably going to know it. + +155 +00:08:19,000 --> 00:08:22,000 +So this is absolutely free of charge for you guys. + +156 +00:08:22,000 --> 00:08:26,000 +I do charge a price on Amazon for this free of charge just for taking my course. + +157 +00:08:26,000 --> 00:08:29,000 +Now the last thing is going to be the study plan. + +158 +00:08:29,000 --> 00:08:31,000 +Now I'm going to do another video on the study plan. + +159 +00:08:32,000 --> 00:08:34,000 +How do you pass your exam in 30 days? + +160 +00:08:34,000 --> 00:08:35,000 +This is the plan for it. + +161 +00:08:35,000 --> 00:08:38,000 +I'm going to do a whole video on it, uh, right after this. + +162 +00:08:39,000 --> 00:08:39,000 +Okay. + +163 +00:08:39,000 --> 00:08:41,000 +So that is everything you need to know. + +164 +00:08:41,000 --> 00:08:43,000 +How is the course laid out? + +165 +00:08:43,000 --> 00:08:48,000 +And of course, all the amazing resources that I'm going to be giving you to pass your test. + diff --git a/01 - Introduction/002 30 Day Study Plan.mp4 b/01 - Introduction/002 30 Day Study Plan.mp4 new file mode 100644 index 0000000000000000000000000000000000000000..52cf387a36501b637ee7e1179f0724bacda913a0 --- /dev/null +++ b/01 - Introduction/002 30 Day Study Plan.mp4 @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:46213b5af735d10f09bf5b8ec1fd92c5e832ed74fabfb214a4f1b8f8e550e689 +size 296593312 diff --git a/01 - Introduction/002 30 Day Study Plan_en.srt b/01 - Introduction/002 30 Day Study Plan_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..03c0f45098e0bedb73ef89627db135e9381209dc --- /dev/null +++ b/01 - Introduction/002 30 Day Study Plan_en.srt @@ -0,0 +1,704 @@ +1 +00:00:00,000 --> 00:00:01,000 +Let me ask you guys a question. + +2 +00:00:02,000 --> 00:00:09,000 +If I told you that if you study for just two hours a day, you can be security+ certified in less than + +3 +00:00:09,000 --> 00:00:10,000 +30 days. + +4 +00:00:10,000 --> 00:00:11,000 +Would you believe me? + +5 +00:00:11,000 --> 00:00:16,000 +Well, what if I give you an actual document that gives you the layout for that and tell you what you + +6 +00:00:16,000 --> 00:00:20,000 +need to study every single day for 30 days? + +7 +00:00:20,000 --> 00:00:23,000 +You just got to put in about two hours of work. + +8 +00:00:23,000 --> 00:00:29,000 +If you can put in two hours of work for 30 days, actually more like 28 days, you're going to actually + +9 +00:00:29,000 --> 00:00:31,000 +pass your security plus exam. + +10 +00:00:31,000 --> 00:00:35,000 +My study plan has helped thousands of students pass their exam on the first try. + +11 +00:00:35,000 --> 00:00:38,000 +And in this course, I'm going to give you that study plan free of charge. + +12 +00:00:38,000 --> 00:00:42,000 +All you got to do is just follow it, follow it and actually apply it. + +13 +00:00:42,000 --> 00:00:43,000 +And you're going to pass your exam. + +14 +00:00:43,000 --> 00:00:47,000 +Let's take a look at what it is now in the course. + +15 +00:00:47,000 --> 00:00:49,000 +Go to the introduction section of the course. + +16 +00:00:49,000 --> 00:00:54,000 +And in one of those you're going to find course objectives notes and Cram Guide download. + +17 +00:00:54,000 --> 00:00:57,000 +One of the download is called a 30 day study plan. + +18 +00:00:57,000 --> 00:01:01,000 +So I want to review that study plan with you now when you download this. + +19 +00:01:03,000 --> 00:01:04,000 +It should open this up. + +20 +00:01:04,000 --> 00:01:05,000 +So here it is. + +21 +00:01:05,000 --> 00:01:10,000 +So this 30 day study plan is what I wrote that helps my students to pass. + +22 +00:01:10,000 --> 00:01:18,000 +And you should be studying about two hours a day to actually get it done within 30 days. + +23 +00:01:18,000 --> 00:01:21,000 +Now this plan is designed to take 1 to 2 months. + +24 +00:01:21,000 --> 00:01:21,000 +You're saying. + +25 +00:01:21,000 --> 00:01:22,000 +But you just said 30 days. + +26 +00:01:22,000 --> 00:01:25,000 +Well, you you may not study every day. + +27 +00:01:25,000 --> 00:01:28,000 +You may study for six days a week, six days a week. + +28 +00:01:29,000 --> 00:01:31,000 +Over 30 days, about five weeks or so. + +29 +00:01:31,000 --> 00:01:32,000 +So keep that in mind. + +30 +00:01:32,000 --> 00:01:34,000 +You may not study every single day. + +31 +00:01:34,000 --> 00:01:36,000 +So that's why I didn't name it Monday through Friday. + +32 +00:01:36,000 --> 00:01:38,000 +I just put day one, day two, day three. + +33 +00:01:38,000 --> 00:01:42,000 +Now, if you're good and you're really into it, you can get this done in less than a month. + +34 +00:01:42,000 --> 00:01:48,000 +But if your schedule doesn't allow it, and sometimes you just need time to just relax a little bit, + +35 +00:01:48,000 --> 00:01:52,000 +maybe study for six days a week or five days at a minimum and just get it over with. + +36 +00:01:52,000 --> 00:01:53,000 +Let me tell you guys something. + +37 +00:01:54,000 --> 00:01:58,000 +I believe in six weeks you better be certified fully. + +38 +00:01:58,000 --> 00:02:00,000 +Most of you should do this in less than a month. + +39 +00:02:00,000 --> 00:02:02,000 +Okay, keep that in mind. + +40 +00:02:02,000 --> 00:02:05,000 +So let's go back here. + +41 +00:02:05,000 --> 00:02:07,000 +You notice the first day of studying. + +42 +00:02:07,000 --> 00:02:09,000 +What are you doing on the first day of studying? + +43 +00:02:09,000 --> 00:02:12,000 +You're registering for the actual test. + +44 +00:02:12,000 --> 00:02:14,000 +In 30 days from now. + +45 +00:02:14,000 --> 00:02:15,000 +This is a must do. + +46 +00:02:15,000 --> 00:02:16,000 +I put it as a must do. + +47 +00:02:16,000 --> 00:02:17,000 +What do you mean by that? + +48 +00:02:18,000 --> 00:02:19,000 +Let me tell you guys something. + +49 +00:02:19,000 --> 00:02:20,000 +I'm a slacker. + +50 +00:02:20,000 --> 00:02:22,000 +But I got 66 certifications. + +51 +00:02:22,000 --> 00:02:24,000 +I've taken over 100 exams. + +52 +00:02:24,000 --> 00:02:25,000 +No, I didn't fail a lot. + +53 +00:02:25,000 --> 00:02:28,000 +It's just that some exams needs multiple. + +54 +00:02:28,000 --> 00:02:30,000 +Some certifications needs multiple exams. + +55 +00:02:30,000 --> 00:02:32,000 +Like the Omcs needed seven exams. + +56 +00:02:32,000 --> 00:02:36,000 +Now here's what I believe. + +57 +00:02:36,000 --> 00:02:38,000 +I don't trust myself. + +58 +00:02:38,000 --> 00:02:39,000 +Do you trust yourself? + +59 +00:02:39,000 --> 00:02:40,000 +I don't trust myself. + +60 +00:02:40,000 --> 00:02:42,000 +I work better when I'm under pressure. + +61 +00:02:42,000 --> 00:02:44,000 +So here's what I'm going to do. + +62 +00:02:44,000 --> 00:02:50,000 +Anytime I want to take a certification exam, I actually go and schedule it before I actually study + +63 +00:02:50,000 --> 00:02:51,000 +for it. + +64 +00:02:51,000 --> 00:02:53,000 +Yeah, it sounds crazy, but it's true. + +65 +00:02:53,000 --> 00:02:55,000 +And I want you guys to do the same. + +66 +00:02:55,000 --> 00:02:56,000 +Here's what I want you guys to do. + +67 +00:02:56,000 --> 00:02:59,000 +If you're watching this video, you're already enrolled in the course. + +68 +00:02:59,000 --> 00:03:00,000 +Here's what here's what you're going to do. + +69 +00:03:00,000 --> 00:03:06,000 +Go right now to Pearson Vue Vue e.com okay here's what you do. + +70 +00:03:06,000 --> 00:03:11,000 +You go to view vue.com and what you're going to do. + +71 +00:03:11,000 --> 00:03:12,000 +You're going to search for CompTIA. + +72 +00:03:13,000 --> 00:03:15,000 +And you're going to have to pay the fee for the exam here. + +73 +00:03:15,000 --> 00:03:17,000 +Because this is where it gets serious. + +74 +00:03:18,000 --> 00:03:22,000 +If you have a login, if you've taken a previous CompTIA go ahead and log in. + +75 +00:03:23,000 --> 00:03:25,000 +Uh, if not just click log in anyhow. + +76 +00:03:25,000 --> 00:03:27,000 +And uh you can go ahead and sign up. + +77 +00:03:27,000 --> 00:03:29,000 +Now make make an account with them. + +78 +00:03:29,000 --> 00:03:32,000 +Follow your on screen directions from here. + +79 +00:03:32,000 --> 00:03:36,000 +And you can then select the 701 when you're doing the 701 exam. + +80 +00:03:36,000 --> 00:03:38,000 +And I want you guys to do this. + +81 +00:03:38,000 --> 00:03:41,000 +Ask yourself how many days can you commit. + +82 +00:03:41,000 --> 00:03:44,000 +Can you commit six days a week? + +83 +00:03:44,000 --> 00:03:47,000 +Well, Andrew said it's going to take me about 30 days. + +84 +00:03:47,000 --> 00:03:49,000 +The study plan is actually 28 days. + +85 +00:03:49,000 --> 00:03:49,000 +All right. + +86 +00:03:49,000 --> 00:03:54,000 +I say 30 days because maybe you're not going to commit every day. + +87 +00:03:54,000 --> 00:03:58,000 +So I actually lay it out over 28 day period. + +88 +00:03:58,000 --> 00:04:00,000 +So maybe you want to schedule it from four weeks from now. + +89 +00:04:00,000 --> 00:04:03,000 +Or if your schedule is really busy, schedule it for five weeks from now. + +90 +00:04:03,000 --> 00:04:06,000 +But I want you to schedule it. + +91 +00:04:06,000 --> 00:04:13,000 +If you don't schedule this exam right now, you are not going to study as much as you want. + +92 +00:04:13,000 --> 00:04:16,000 +The exam is not reality until you actually pay for it. + +93 +00:04:17,000 --> 00:04:18,000 +Go and pay for it and schedule it. + +94 +00:04:18,000 --> 00:04:22,000 +The worst case scenario, I promise you, is you're not going to fail. + +95 +00:04:22,000 --> 00:04:25,000 +Worst case scenario is if you can't stick to my study plan. + +96 +00:04:25,000 --> 00:04:27,000 +Because things happen in life. + +97 +00:04:27,000 --> 00:04:28,000 +You lose your job. + +98 +00:04:28,000 --> 00:04:35,000 +Something bad happened with the family, you know, whatever it is, uh, you can just reschedule it, + +99 +00:04:35,000 --> 00:04:35,000 +all right? + +100 +00:04:35,000 --> 00:04:36,000 +You can just reschedule it. + +101 +00:04:36,000 --> 00:04:39,000 +They're going to charge you a fee of about 20, $30, I believe. + +102 +00:04:39,000 --> 00:04:40,000 +It's not a lot. + +103 +00:04:40,000 --> 00:04:41,000 +They're going to charge you a little fee. + +104 +00:04:41,000 --> 00:04:46,000 +Consider it the tax you have to pay because you don't want to take it right away because you were slacking + +105 +00:04:46,000 --> 00:04:47,000 +off or whatever it was. + +106 +00:04:47,000 --> 00:04:49,000 +So schedule it. + +107 +00:04:49,000 --> 00:04:50,000 +This will force you to study. + +108 +00:04:50,000 --> 00:04:54,000 +This will push you to study, because then you're always going to say to yourself. + +109 +00:04:55,000 --> 00:04:55,000 +I'm going to start. + +110 +00:04:55,000 --> 00:04:56,000 +I'm tired today. + +111 +00:04:56,000 --> 00:04:59,000 +I'm going to study tomorrow and I'm going to study four hours tomorrow, Andrew said. + +112 +00:04:59,000 --> 00:05:03,000 +Study two, I'm gonna study four hours and the tomorrow comes on study six hours. + +113 +00:05:03,000 --> 00:05:04,000 +And then you know what? + +114 +00:05:04,000 --> 00:05:05,000 +On this weekend I'm going to put extra time. + +115 +00:05:05,000 --> 00:05:08,000 +You never get around to it before, you know, two months, three months go by. + +116 +00:05:08,000 --> 00:05:09,000 +You're not certified this way. + +117 +00:05:09,000 --> 00:05:11,000 +I guarantee you're going to take your test. + +118 +00:05:11,000 --> 00:05:12,000 +So please schedule your exam. + +119 +00:05:12,000 --> 00:05:14,000 +I always do it. + +120 +00:05:14,000 --> 00:05:16,000 +Quick tip or quick thing about me. + +121 +00:05:16,000 --> 00:05:17,000 +What? + +122 +00:05:17,000 --> 00:05:18,000 +I want to take an exam. + +123 +00:05:18,000 --> 00:05:23,000 +I would schedule the exam before I even buy the book or before I even before I buy the book, or before + +124 +00:05:23,000 --> 00:05:25,000 +I even know what what is on that test. + +125 +00:05:25,000 --> 00:05:27,000 +I go ahead and I schedule it that way. + +126 +00:05:27,000 --> 00:05:29,000 +I'm forced to actually do it. + +127 +00:05:30,000 --> 00:05:32,000 +And then you just follow the study plan. + +128 +00:05:32,000 --> 00:05:34,000 +So here we go. + +129 +00:05:34,000 --> 00:05:35,000 +Section two. + +130 +00:05:35,000 --> 00:05:39,000 +So day one every day is about two hours of work. + +131 +00:05:39,000 --> 00:05:43,000 +So you notice they want I got you doing section two, three and four. + +132 +00:05:43,000 --> 00:05:44,000 +So let's take a look at that. + +133 +00:05:44,000 --> 00:05:49,000 +So section two 41 minutes three 14 minutes for 40 minutes. + +134 +00:05:49,000 --> 00:05:52,000 +So combined these are about two hours. + +135 +00:05:53,000 --> 00:05:57,000 +Uh section one day two you're doing two sections. + +136 +00:05:57,000 --> 00:06:00,000 +Sections five and six vulnerabilities and signs of attacks. + +137 +00:06:00,000 --> 00:06:03,000 +So vulnerabilities uh signs of attack. + +138 +00:06:04,000 --> 00:06:06,000 +So this one's going to be a little bit longer, right. + +139 +00:06:06,000 --> 00:06:10,000 +It's going to come out to close to 2.5 hours I believe. + +140 +00:06:11,000 --> 00:06:13,000 +And then section day three and four. + +141 +00:06:13,000 --> 00:06:16,000 +Cryptography is tough, so I actually broke it into two days for you. + +142 +00:06:16,000 --> 00:06:18,000 +Uh, and then this this keeps on going. + +143 +00:06:18,000 --> 00:06:20,000 +You just follow the entire. + +144 +00:06:20,000 --> 00:06:23,000 +Just keep following this, keep on going through with it. + +145 +00:06:23,000 --> 00:06:29,000 +And now coming down towards the end of it, you'll notice the 19. + +146 +00:06:29,000 --> 00:06:31,000 +I got the mock exam in the course. + +147 +00:06:32,000 --> 00:06:32,000 +All right. + +148 +00:06:32,000 --> 00:06:35,000 +Now the mock exam I'm talking about is in this course. + +149 +00:06:35,000 --> 00:06:36,000 +It's at the bottom here. + +150 +00:06:36,000 --> 00:06:37,000 +Mock exam. + +151 +00:06:37,000 --> 00:06:39,000 +In this particular course. + +152 +00:06:39,000 --> 00:06:41,000 +So you do this one. + +153 +00:06:41,000 --> 00:06:45,000 +Now remember there is another course on Udemy that is mock exams. + +154 +00:06:45,000 --> 00:06:47,000 +Get that course from me. + +155 +00:06:47,000 --> 00:06:48,000 +That's also my course. + +156 +00:06:48,000 --> 00:06:49,000 +Make sure it comes from me. + +157 +00:06:49,000 --> 00:06:52,000 +It's the um security plus practice and there's six of them there. + +158 +00:06:52,000 --> 00:06:53,000 +Notice I have one. + +159 +00:06:53,000 --> 00:06:54,000 +You doing one every day. + +160 +00:06:55,000 --> 00:06:58,000 +Because they take 90 minutes and you're going to want to review what you get wrong. + +161 +00:06:58,000 --> 00:07:00,000 +So there you go with the two hours. + +162 +00:07:00,000 --> 00:07:04,000 +And then day 2627 you're reviewing the cramped the last minute guide. + +163 +00:07:05,000 --> 00:07:07,000 +Now I just spoke about the last minute guide. + +164 +00:07:08,000 --> 00:07:11,000 +The last minute guide, if you forgot was this download. + +165 +00:07:11,000 --> 00:07:19,000 +And inside of this download you have every single one of the exam objectives that's covered. + +166 +00:07:19,000 --> 00:07:22,000 +And you have the acronym list that you want to do a quick review on. + +167 +00:07:22,000 --> 00:07:25,000 +So all the exam objectives and the acronym list. + +168 +00:07:27,000 --> 00:07:31,000 +I give you two days to review this, to do maybe 40 page, 40 pages, and then day 28, take the test + +169 +00:07:31,000 --> 00:07:32,000 +and get it over with. + +170 +00:07:33,000 --> 00:07:36,000 +So this is follow the study plan the way you see it. + +171 +00:07:36,000 --> 00:07:41,000 +And if you can do that you're going to ace your exam I promise you. + +172 +00:07:41,000 --> 00:07:41,000 +All right. + +173 +00:07:41,000 --> 00:07:46,000 +Tons of my students, thousands of my students have used this study plan from my previous one. + +174 +00:07:46,000 --> 00:07:48,000 +When I teach the live class, I give them all this. + +175 +00:07:48,000 --> 00:07:51,000 +I didn't use to do it before my e-learning class, but now it's here. + +176 +00:07:51,000 --> 00:07:57,000 +So do this and I guarantee you you are going to ace your exam on the first try. + diff --git a/01 - Introduction/003 Exam Information.mp4 b/01 - Introduction/003 Exam Information.mp4 new file mode 100644 index 0000000000000000000000000000000000000000..977c719ffba31784e5958969a9c9fe63c3655807 --- /dev/null +++ b/01 - Introduction/003 Exam Information.mp4 @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:ad2492a214f6c9acd6fe654f163609569083986724d8f6219cab527675a298ea +size 174300628 diff --git a/01 - Introduction/003 Exam Information_en.srt b/01 - Introduction/003 Exam Information_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..81bc70f8890c1289c14d19aecaf83e5436da1c87 --- /dev/null +++ b/01 - Introduction/003 Exam Information_en.srt @@ -0,0 +1,568 @@ +1 +00:00:00,000 --> 00:00:05,000 +The Security+ certification is offered by a company called CompTIA, which stands for Comp. + +2 +00:00:05,000 --> 00:00:10,000 +It stands for the Computer to Technology Industry Association. + +3 +00:00:10,000 --> 00:00:14,000 +Now CompTIA has been around for about, I think three decades now. + +4 +00:00:14,000 --> 00:00:18,000 +And their most famous certification is the A+ certification. + +5 +00:00:18,000 --> 00:00:22,000 +Now, their second most famous is probably going to be Network+ or Security+. + +6 +00:00:22,000 --> 00:00:25,000 +And I think Security+ is more famous now. + +7 +00:00:25,000 --> 00:00:29,000 +So if you want to become Security+ certified, I'm going to walk you through some of the things you + +8 +00:00:29,000 --> 00:00:30,000 +have to do in this video. + +9 +00:00:30,000 --> 00:00:35,000 +And one good thing is that you only have to take one exam in order to be certified. + +10 +00:00:35,000 --> 00:00:39,000 +You just got to pass one certification exam. + +11 +00:00:39,000 --> 00:00:42,000 +And let's take a look at the stats on this exam. + +12 +00:00:42,000 --> 00:00:47,000 +Now, this particular course is designed to help you pass the CIO 701. + +13 +00:00:47,000 --> 00:00:52,000 +You want to make sure that you know this particular number as that's the exam you're taking. + +14 +00:00:52,000 --> 00:00:55,000 +Depending on when you're watching this video and when you're taking this course. + +15 +00:00:55,000 --> 00:00:59,000 +As this video is being made, there is a 601 exam or the older exam. + +16 +00:00:59,000 --> 00:01:04,000 +So this course is for this current, this newer exam I should say 701. + +17 +00:01:04,000 --> 00:01:06,000 +So remember that's the exam you're taking. + +18 +00:01:06,000 --> 00:01:06,000 +Why. + +19 +00:01:06,000 --> 00:01:11,000 +Because when you go to register and at the end of this video I'll talk about where to register for the + +20 +00:01:11,000 --> 00:01:12,000 +exam. + +21 +00:01:12,000 --> 00:01:17,000 +Now when you're ready to register for the exam you're going to make sure you select this exam. + +22 +00:01:17,000 --> 00:01:23,000 +Now the exam is 90 minutes in duration, as you can see here with a maximum of 90 questions. + +23 +00:01:23,000 --> 00:01:26,000 +Now, I did take this exam a few days after it came out. + +24 +00:01:26,000 --> 00:01:29,000 +I think it came out like November 6th, 2023. + +25 +00:01:29,000 --> 00:01:32,000 +I took it like November 8th or November 9th I did. + +26 +00:01:32,000 --> 00:01:36,000 +I'm going to do a video on that on the YouTube channel that talks about my experience. + +27 +00:01:36,000 --> 00:01:38,000 +Now in my exam, I got 77 questions. + +28 +00:01:38,000 --> 00:01:43,000 +So some of you guys may get less than 90 questions or up to 90 questions. + +29 +00:01:43,000 --> 00:01:46,000 +So keep that in mind maximum of 90 questions. + +30 +00:01:46,000 --> 00:01:50,000 +Now keep in mind that you're probably going to get a lot less, maybe 80 something questions or the + +31 +00:01:50,000 --> 00:01:52,000 +late 70 questions. + +32 +00:01:52,000 --> 00:01:54,000 +Now your exam have three types of question. + +33 +00:01:54,000 --> 00:01:59,000 +What's called multiple choice drag and drop, and performance based or simulation based questions. + +34 +00:01:59,000 --> 00:02:02,000 +These here are pretty simple multiple choice questions. + +35 +00:02:02,000 --> 00:02:05,000 +You're just going to choose one of those choices that is there. + +36 +00:02:05,000 --> 00:02:07,000 +Some of the questions is going to have you choose MultiChoice. + +37 +00:02:07,000 --> 00:02:10,000 +So it's going to say choose two or choose three. + +38 +00:02:10,000 --> 00:02:12,000 +They never do choose all or choose many. + +39 +00:02:12,000 --> 00:02:15,000 +They'll just say uh, choose two or choose three. + +40 +00:02:15,000 --> 00:02:16,000 +You're not going to get a lot of those. + +41 +00:02:16,000 --> 00:02:18,000 +So let's say the test had 90 questions. + +42 +00:02:19,000 --> 00:02:22,000 +I'm telling you guys, 80 of them is going to be choose one answer. + +43 +00:02:22,000 --> 00:02:25,000 +Maybe three, 4 or 5 of them is going to be multi choice. + +44 +00:02:25,000 --> 00:02:30,000 +And you're probably going to get as soon as the exam begins, you're going to get a drag and drop or + +45 +00:02:30,000 --> 00:02:31,000 +a performance based simulator. + +46 +00:02:31,000 --> 00:02:37,000 +Now again it depends when you're watching this video I did get a drag and drop questions where you had + +47 +00:02:37,000 --> 00:02:40,000 +to match attacks to how to mitigate this attack. + +48 +00:02:40,000 --> 00:02:41,000 +So to give you a scenario. + +49 +00:02:41,000 --> 00:02:42,000 +And they said, what attack is this? + +50 +00:02:42,000 --> 00:02:44,000 +And you had to match it to that. + +51 +00:02:44,000 --> 00:02:45,000 +And then how would you fix that attack. + +52 +00:02:45,000 --> 00:02:47,000 +That's basically a drag and drop. + +53 +00:02:47,000 --> 00:02:51,000 +The other one you're going to have is sometimes you get a performance based simulator where you may + +54 +00:02:51,000 --> 00:02:57,000 +have to read some kind of text file and decode what that says. + +55 +00:02:57,000 --> 00:02:58,000 +Is this machine hacked? + +56 +00:02:58,000 --> 00:02:59,000 +Is it good? + +57 +00:02:59,000 --> 00:03:01,000 +Here is the log files that go with that. + +58 +00:03:01,000 --> 00:03:03,000 +So that's what this is. + +59 +00:03:03,000 --> 00:03:05,000 +Now these are pretty they're pretty simple in my opinion. + +60 +00:03:05,000 --> 00:03:07,000 +Especially if you do some of the labs. + +61 +00:03:07,000 --> 00:03:08,000 +They're pretty simple. + +62 +00:03:08,000 --> 00:03:14,000 +The drag and drop to me is even more simple that you just have to know, uh, know how to fix problems + +63 +00:03:14,000 --> 00:03:16,000 +or know how to resolve a particular attack. + +64 +00:03:16,000 --> 00:03:20,000 +Now, this exam is pretty scary because of this right here. + +65 +00:03:20,000 --> 00:03:26,000 +You see, right here you need 750 out of 900 points. + +66 +00:03:26,000 --> 00:03:32,000 +Now that basically comes out to 83% is what you have to score on it. + +67 +00:03:32,000 --> 00:03:35,000 +Now, when I took this exam, I didn't find it difficult. + +68 +00:03:35,000 --> 00:03:38,000 +It was mostly just terminologies. + +69 +00:03:38,000 --> 00:03:39,000 +If you know the terminology. + +70 +00:03:39,000 --> 00:03:41,000 +This course comes with a study guide. + +71 +00:03:41,000 --> 00:03:43,000 +So make sure to review that study guide. + +72 +00:03:43,000 --> 00:03:47,000 +And I think you're going to be just fine as the course as the exam is basically just terminology off + +73 +00:03:47,000 --> 00:03:48,000 +of the objectives. + +74 +00:03:48,000 --> 00:03:52,000 +So if you know that I think you can accomplish this score pretty quick. + +75 +00:03:52,000 --> 00:03:56,000 +Now the question is where do you take this exam. + +76 +00:03:56,000 --> 00:04:00,000 +Now this exam is given at a company called Pearson Vue. + +77 +00:04:00,000 --> 00:04:04,000 +Now Pearson Vue administers the exam for CompTIA. + +78 +00:04:04,000 --> 00:04:08,000 +So I want you to hear these two terms CompTIA and Vue. + +79 +00:04:08,000 --> 00:04:10,000 +Vue Aecom I'm going to show you the website in a minute. + +80 +00:04:10,000 --> 00:04:11,000 +So. + +81 +00:04:12,000 --> 00:04:17,000 +CompTIA is the person, the company that's going to certify you okay. + +82 +00:04:17,000 --> 00:04:22,000 +They're the one that created the exam, the objectives and all that good stuff. + +83 +00:04:22,000 --> 00:04:25,000 +Pearson Vue is the people that administers the exam. + +84 +00:04:25,000 --> 00:04:29,000 +So when you're ready to take the test, you're going to want to go to Pearson Vue and take the test + +85 +00:04:29,000 --> 00:04:29,000 +with them. + +86 +00:04:29,000 --> 00:04:31,000 +How do you do that? + +87 +00:04:31,000 --> 00:04:32,000 +Well let's go. + +88 +00:04:32,000 --> 00:04:34,000 +I'm going to show you guys my desktop. + +89 +00:04:34,000 --> 00:04:35,000 +Here we are at my desktop. + +90 +00:04:35,000 --> 00:04:42,000 +I am going to go to Pearson Vue as soon as my browser opens up here at some point in the future. + +91 +00:04:43,000 --> 00:04:44,000 +All right. + +92 +00:04:45,000 --> 00:04:45,000 +Okay. + +93 +00:04:45,000 --> 00:04:47,000 +I'll open up on the other screen. + +94 +00:04:47,000 --> 00:04:47,000 +Okay. + +95 +00:04:47,000 --> 00:04:48,000 +So here we are at Pearson Vue. + +96 +00:04:48,000 --> 00:04:51,000 +So the website is just vue.com. + +97 +00:04:51,000 --> 00:04:56,000 +So we're going to go here and we're going to say let's type in CompTIA. + +98 +00:04:57,000 --> 00:05:00,000 +And this is how you're going to register for the test by the way. + +99 +00:05:00,000 --> 00:05:01,000 +You just go to CompTIA. + +100 +00:05:01,000 --> 00:05:07,000 +Now if you have taken a previous CompTIA exam you would say login okay. + +101 +00:05:07,000 --> 00:05:13,000 +If you have never, ever taken a comp t exam, you follow the on screen prompts here and you're going + +102 +00:05:13,000 --> 00:05:17,000 +to create an account on this website in order to. + +103 +00:05:17,000 --> 00:05:19,000 +So you you could just basically click login. + +104 +00:05:19,000 --> 00:05:21,000 +And then it's going to say, hey, don't have an account. + +105 +00:05:21,000 --> 00:05:22,000 +You can sign up. + +106 +00:05:22,000 --> 00:05:25,000 +If you don't have one, you can sign up for one right on their website. + +107 +00:05:25,000 --> 00:05:27,000 +Now where do you take the test? + +108 +00:05:27,000 --> 00:05:33,000 +Well, this exam is going to be given online at your home. + +109 +00:05:33,000 --> 00:05:36,000 +That's where I tell most people to take the test. + +110 +00:05:36,000 --> 00:05:40,000 +I don't recommend for you to take this exam at a testing center. + +111 +00:05:40,000 --> 00:05:44,000 +So when you register, you're going to have the chance to go to a Pearson Vue testing center in your + +112 +00:05:44,000 --> 00:05:47,000 +local neighborhood, and you can take the test there. + +113 +00:05:47,000 --> 00:05:48,000 +I'm not a fan of that. + +114 +00:05:48,000 --> 00:05:56,000 +The reason is because going to a testing center to take the exam is going to require you to travel to + +115 +00:05:56,000 --> 00:05:57,000 +the testing center. + +116 +00:05:57,000 --> 00:06:00,000 +You're going to have to make sure that you don't be late. + +117 +00:06:00,000 --> 00:06:02,000 +If not, you're going to forfeit the exam. + +118 +00:06:02,000 --> 00:06:04,000 +It's a pretty stressful environment. + +119 +00:06:04,000 --> 00:06:09,000 +Their chairs are uncomfortable, their computer sucks, their keyboard is nasty, their screen is too + +120 +00:06:09,000 --> 00:06:10,000 +small. + +121 +00:06:10,000 --> 00:06:11,000 +It's a lot of security. + +122 +00:06:11,000 --> 00:06:13,000 +They're going to pat you down. + +123 +00:06:13,000 --> 00:06:15,000 +They're going to put a metal detector against you. + +124 +00:06:15,000 --> 00:06:19,000 +They might hand scan you or take a biometric print of you. + +125 +00:06:19,000 --> 00:06:22,000 +It's pretty much it's pretty stressful environment. + +126 +00:06:22,000 --> 00:06:24,000 +If you do it at home, you're going to need two things. + +127 +00:06:24,000 --> 00:06:27,000 +You're going to microphone and you're going to need a webcam on your computer. + +128 +00:06:28,000 --> 00:06:30,000 +Technically three things because you need a quiet room. + +129 +00:06:30,000 --> 00:06:31,000 +If you got that, you're good. + +130 +00:06:31,000 --> 00:06:35,000 +If you have a laptop that comes with a built in micro camera, you're good. + +131 +00:06:35,000 --> 00:06:41,000 +You can also if you have a all laptops pretty much nowadays have a microphone built in, you're fine. + +132 +00:06:41,000 --> 00:06:46,000 +If not, you can just buy like a $50 webcam and just take the exam at home. + +133 +00:06:46,000 --> 00:06:49,000 +Basically, they're going to install a piece of software on your computer, uh, a couple of minutes + +134 +00:06:49,000 --> 00:06:51,000 +before the exam starts. + +135 +00:06:51,000 --> 00:06:55,000 +They're going to test it, and you just sit and take it at home and you're certified directly from the + +136 +00:06:55,000 --> 00:06:59,000 +comfort of your home, your chair, your computer, and a whole lot less stressful. + +137 +00:06:59,000 --> 00:07:00,000 +All right. + +138 +00:07:00,000 --> 00:07:01,000 +So keep that in mind. + +139 +00:07:01,000 --> 00:07:04,000 +These things I do recommend to take the exam at home. + +140 +00:07:04,000 --> 00:07:05,000 +Remember that. + +141 +00:07:05,000 --> 00:07:08,000 +And then don't forget 90 minutes 90 questions. + +142 +00:07:08,000 --> 00:07:12,000 +And you need 83% to pass to become certified. + diff --git a/01 - Introduction/004 Exam Domains.mp4 b/01 - Introduction/004 Exam Domains.mp4 new file mode 100644 index 0000000000000000000000000000000000000000..b839af8f0d7d91e83f9fe4cd43db7bb0e915aab9 --- /dev/null +++ b/01 - Introduction/004 Exam Domains.mp4 @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:58c158a7a21ad26e9756520ff56a8f0091449cf0d55e1d770930954844448451 +size 144894608 diff --git a/01 - Introduction/004 Exam Domains_en.srt b/01 - Introduction/004 Exam Domains_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..6acb9ff36490914043a7fec02462ed3b11e97162 --- /dev/null +++ b/01 - Introduction/004 Exam Domains_en.srt @@ -0,0 +1,456 @@ +1 +00:00:00,000 --> 00:00:05,000 +Now, before we get into every single one of the topics in the exam objectives, I want to just give + +2 +00:00:05,000 --> 00:00:08,000 +you a brief overview of what exactly is covered on this test. + +3 +00:00:08,000 --> 00:00:12,000 +So here I have this document or I should say this table. + +4 +00:00:12,000 --> 00:00:15,000 +Now I got this out of the exam objectives. + +5 +00:00:15,000 --> 00:00:20,000 +Now you can download the Sy0 701 exam objectives from the CompTIA website. + +6 +00:00:20,000 --> 00:00:26,000 +Or if it's dependent on the platform that this video is hosted on, you could probably probably just + +7 +00:00:26,000 --> 00:00:27,000 +attach it as a PDF. + +8 +00:00:27,000 --> 00:00:29,000 +Again, it depends where this video is hosted on. + +9 +00:00:29,000 --> 00:00:30,000 +I may or may not be able to do that. + +10 +00:00:30,000 --> 00:00:34,000 +If not, you can get the exam objective from Comptia's website. + +11 +00:00:34,000 --> 00:00:36,000 +So let's go over what exactly is this. + +12 +00:00:36,000 --> 00:00:43,000 +And you can see that we got five domains that makes up all of the exam questions. + +13 +00:00:43,000 --> 00:00:44,000 +So let's go over this. + +14 +00:00:44,000 --> 00:00:47,000 +The first thing up I have is that general security concept. + +15 +00:00:47,000 --> 00:00:48,000 +This is 12%. + +16 +00:00:48,000 --> 00:00:52,000 +This is a domain that you're just going to learn basic terms like what is authentication. + +17 +00:00:52,000 --> 00:00:54,000 +What is identification. + +18 +00:00:54,000 --> 00:00:55,000 +What is confidentiality. + +19 +00:00:56,000 --> 00:01:00,000 +Um, it does talk a little bit about physical security and how to classify different kinds of controls + +20 +00:01:00,000 --> 00:01:01,000 +is going to be here. + +21 +00:01:01,000 --> 00:01:06,000 +Now as a security professional, you're going to have to know all the different threats that affect + +22 +00:01:06,000 --> 00:01:12,000 +your network, such as what's the DDoS attack, what's cross-site scripting, what SQL injections, + +23 +00:01:12,000 --> 00:01:18,000 +what are the different threats, what makes your systems vulnerable, such as outdated or unpatched + +24 +00:01:18,000 --> 00:01:21,000 +machines, and what can we do to fix those things? + +25 +00:01:21,000 --> 00:01:21,000 +Right. + +26 +00:01:21,000 --> 00:01:24,000 +What what can we implement to keep our systems more secure? + +27 +00:01:24,000 --> 00:01:28,000 +Such as, hey, maybe you should at least patch your computers or keep them up to date at least. + +28 +00:01:28,000 --> 00:01:32,000 +How do we design secure systems? + +29 +00:01:32,000 --> 00:01:33,000 +Right? + +30 +00:01:33,000 --> 00:01:39,000 +If we go out and we build a network, what should we be doing as we build secure networks? + +31 +00:01:39,000 --> 00:01:40,000 +Is what number three are. + +32 +00:01:40,000 --> 00:01:44,000 +Cover number four is security operations and day to day things that we should be doing. + +33 +00:01:44,000 --> 00:01:48,000 +Like how do you secure and harden a router or switch for example, is going to be covered here. + +34 +00:01:48,000 --> 00:01:52,000 +Notice this is one of the biggest domain with 28%. + +35 +00:01:52,000 --> 00:01:54,000 +So quite a lot is covered in domain four. + +36 +00:01:54,000 --> 00:01:56,000 +Now domain five is pretty simple. + +37 +00:01:56,000 --> 00:02:01,000 +This is more administrative things such as understanding different types of policies and what security + +38 +00:02:01,000 --> 00:02:04,000 +policies are what guidelines are also risk management. + +39 +00:02:05,000 --> 00:02:10,000 +You're going to learn about how do we deal and manage with risk, how do we respond to certain risks, + +40 +00:02:10,000 --> 00:02:13,000 +how do we deal and manage with vendors, for example? + +41 +00:02:13,000 --> 00:02:19,000 +And finally, we'll take a look at user training in this particular section for a total of 100 points. + +42 +00:02:19,000 --> 00:02:22,000 +Now I want you guys to remember that this is the weight of it. + +43 +00:02:22,000 --> 00:02:27,000 +And in theory, in theory you should get questions by the weights. + +44 +00:02:27,000 --> 00:02:33,000 +If CompTIA, for example, said there is up to 90 questions, technically you should get 18 questions + +45 +00:02:33,000 --> 00:02:35,000 +from this domain. + +46 +00:02:35,000 --> 00:02:37,000 +That's 20% of 90. + +47 +00:02:37,000 --> 00:02:38,000 +And so on and so on. + +48 +00:02:39,000 --> 00:02:44,000 +Um, but keep in mind that CompTIA really doesn't publish those numbers, doesn't say what you're going + +49 +00:02:44,000 --> 00:02:49,000 +to get all these questions, uh, on on this particular topic, it's all scattered out all over the + +50 +00:02:49,000 --> 00:02:50,000 +exam. + +51 +00:02:51,000 --> 00:02:51,000 +Okay. + +52 +00:02:51,000 --> 00:02:57,000 +So one of the things that you should you guys should be doing is going through the exam objectives. + +53 +00:02:57,000 --> 00:03:03,000 +Now I have the exam objectives here that you can download from Comptia's website. + +54 +00:03:03,000 --> 00:03:07,000 +And I want to show you guys what that document looks like. + +55 +00:03:08,000 --> 00:03:08,000 +All right. + +56 +00:03:08,000 --> 00:03:09,000 +So I do have it open. + +57 +00:03:09,000 --> 00:03:10,000 +Let's take a look. + +58 +00:03:10,000 --> 00:03:16,000 +So here's the um here's Comptia's exam objectives. + +59 +00:03:17,000 --> 00:03:18,000 +Let me just make this bigger. + +60 +00:03:18,000 --> 00:03:22,000 +And again, this is for the Sci 0701. + +61 +00:03:23,000 --> 00:03:26,000 +Now you can see that this is the table I just showed you. + +62 +00:03:26,000 --> 00:03:28,000 +We just went over this. + +63 +00:03:28,000 --> 00:03:32,000 +Uh, we also went over this, the 1990 questions, 90 minutes and so on. + +64 +00:03:32,000 --> 00:03:41,000 +But if we go down here, you guys see these, uh, all of these topics like general security, number + +65 +00:03:41,000 --> 00:03:46,000 +1.1, it goes through categories of controls, control types. + +66 +00:03:46,000 --> 00:03:50,000 +1.2, you got to know what CIA is, a confidentiality, integrity and availability. + +67 +00:03:50,000 --> 00:03:52,000 +You have to know what zero trust is. + +68 +00:03:52,000 --> 00:03:54,000 +If I go down it goes into more and more. + +69 +00:03:54,000 --> 00:03:58,000 +Now this document is very, very large. + +70 +00:03:58,000 --> 00:04:01,000 +Um, and you can see that it covers quite a lot of topics. + +71 +00:04:01,000 --> 00:04:04,000 +This is why this course is incredibly long. + +72 +00:04:05,000 --> 00:04:08,000 +And you can see it's a lot for me to go over. + +73 +00:04:08,000 --> 00:04:11,000 +Every one of these topics will take a very, very long time. + +74 +00:04:11,000 --> 00:04:15,000 +Now, at the bottom of it, I do want to point out this section. + +75 +00:04:16,000 --> 00:04:19,000 +You see this section here that comes with acronyms. + +76 +00:04:19,000 --> 00:04:22,000 +You guys see that all of these acronyms. + +77 +00:04:23,000 --> 00:04:27,000 +Now throughout the course I will be covering these acronyms. + +78 +00:04:28,000 --> 00:04:30,000 +And you can see it's quite a lot. + +79 +00:04:30,000 --> 00:04:32,000 +And I'm going to give you guys a quick tip here. + +80 +00:04:32,000 --> 00:04:34,000 +So here's a quick tip. + +81 +00:04:34,000 --> 00:04:41,000 +I took this exam and I was stunned to see how many acronyms was on that test. + +82 +00:04:41,000 --> 00:04:45,000 +I'm talking about crazy acronyms and they don't tell you the meaning of them. + +83 +00:04:45,000 --> 00:04:50,000 +So before you take this exam, you want to make sure you review these objectives. + +84 +00:04:50,000 --> 00:04:53,000 +And again you can download this or it might be attached to this video. + +85 +00:04:53,000 --> 00:04:54,000 +Just type. + +86 +00:04:54,000 --> 00:05:00,000 +If you don't know how to use Comptia's website just go to Google Type CompTIA Security+ 701 exam objectives + +87 +00:05:00,000 --> 00:05:01,000 +and you'll get a link to it. + +88 +00:05:01,000 --> 00:05:07,000 +Now these particular acronyms you need to know them before you walk into that exam room. + +89 +00:05:07,000 --> 00:05:09,000 +Make sure you know them. + +90 +00:05:09,000 --> 00:05:15,000 +The other point I want to point out about these exam objectives is that every single thing in the exam + +91 +00:05:15,000 --> 00:05:17,000 +comes from this objective. + +92 +00:05:17,000 --> 00:05:21,000 +Every single question will come from the objectives. + +93 +00:05:21,000 --> 00:05:22,000 +You have to remember that. + +94 +00:05:22,000 --> 00:05:23,000 +All right. + +95 +00:05:23,000 --> 00:05:29,000 +So if you know everything in this exam objectives you will be able not should you will be able to pass + +96 +00:05:29,000 --> 00:05:30,000 +the exam. + +97 +00:05:30,000 --> 00:05:33,000 +But you're saying well how well do I need to know it? + +98 +00:05:33,000 --> 00:05:38,000 +Well, the good thing is in Security+ you don't need to be an expert at the topic. + +99 +00:05:38,000 --> 00:05:40,000 +All I need you to do is be able to explain that. + +100 +00:05:40,000 --> 00:05:42,000 +Be able to tell me what that is. + +101 +00:05:42,000 --> 00:05:44,000 +I don't need you to go configure a firewall. + +102 +00:05:44,000 --> 00:05:46,000 +I just need you to tell me what does a firewall do? + +103 +00:05:46,000 --> 00:05:48,000 +I don't need you to tell me. + +104 +00:05:49,000 --> 00:05:49,000 +I'm sorry. + +105 +00:05:49,000 --> 00:05:54,000 +I don't need you to, uh, set up a different kinds of IDs systems. + +106 +00:05:54,000 --> 00:05:55,000 +I just need you to tell me. + +107 +00:05:55,000 --> 00:05:57,000 +Hey, how does those systems get updated? + +108 +00:05:57,000 --> 00:05:59,000 +What's the point of that? + +109 +00:05:59,000 --> 00:06:00,000 +What's the point of DLP? + +110 +00:06:00,000 --> 00:06:01,000 +Do you know the meaning of that? + +111 +00:06:01,000 --> 00:06:02,000 +Do you even know the purpose it serves? + +112 +00:06:02,000 --> 00:06:06,000 +That's what you need to know for this particular exam. + +113 +00:06:06,000 --> 00:06:10,000 +Now make sure once again, I can't emphasize this enough. + +114 +00:06:10,000 --> 00:06:13,000 +Know your acronyms to pass your exam. + diff --git a/01 - Introduction/005 30-Day-study-Plan.pdf b/01 - Introduction/005 30-Day-study-Plan.pdf new file mode 100644 index 0000000000000000000000000000000000000000..7fcdd748913d37e98a0c934b614d029b3ece483f --- /dev/null +++ b/01 - Introduction/005 30-Day-study-Plan.pdf @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:d66e4361263e47f2f1599f5c079ffe5e794985c72b7ba944856ac205db669b9c +size 201165 diff --git a/01 - Introduction/005 Course Objectives, Notes and Cram Guide Download.html b/01 - Introduction/005 Course Objectives, Notes and Cram Guide Download.html new file mode 100644 index 0000000000000000000000000000000000000000..0bbfae02867059264ce01a3be954ba4285dc03f3 --- /dev/null +++ b/01 - Introduction/005 Course Objectives, Notes and Cram Guide Download.html @@ -0,0 +1,69 @@ + + + + + + Course Objectives, Notes and Cram Guide Download + + + + +
+
+
Course Objectives, Notes and Cram Guide Download
+

Please download all attachment.

Passing your exam requires doing a lot of practice exams. Get my 6 full-length mock exam course here on Udemy to practice your knowledge gain in this class. If you can score a minimum of 80% on all of the mock exams you will ace your exam. Here is the link:

https://www.udemy.com/course/securitypluspracticeexams/


-AR

+
+
+ + diff --git a/01 - Introduction/005 Course-Notes.pdf b/01 - Introduction/005 Course-Notes.pdf new file mode 100644 index 0000000000000000000000000000000000000000..960d508b8ad56be16fe5ffc9a6df00eb01bbb61a --- /dev/null +++ b/01 - Introduction/005 Course-Notes.pdf @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:1d34db2b70c0ea7381dd5d3b094c82efe43f684a395b058e3a442f18ce509f64 +size 14673478 diff --git a/01 - Introduction/005 Security-Last-Minute-Cram-Guide.pdf b/01 - Introduction/005 Security-Last-Minute-Cram-Guide.pdf new file mode 100644 index 0000000000000000000000000000000000000000..6a9e3a64e6f34c230ffb7f185dbe279c62fdee17 --- /dev/null +++ b/01 - Introduction/005 Security-Last-Minute-Cram-Guide.pdf @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:fa966c6b9f54507b6094a771990edabf4c210aad69c3f910b984a9a3e9a12da9 +size 934774 diff --git a/01 - Introduction/005 comptia-security-sy0-701-exam-objectives-5-0.pdf b/01 - Introduction/005 comptia-security-sy0-701-exam-objectives-5-0.pdf new file mode 100644 index 0000000000000000000000000000000000000000..748f9c7e0d81e2492d1ea1cab141ba366841a935 --- /dev/null +++ b/01 - Introduction/005 comptia-security-sy0-701-exam-objectives-5-0.pdf @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:64e5a75df0e6105c724990476b678cf63533d241261538f53d99d2cc73690eba +size 191074 diff --git a/02 - Lesson 1 IT Security Fundamentals/001 Introduction IT Security Fundamentals OB 1.2.mp4 b/02 - Lesson 1 IT Security Fundamentals/001 Introduction IT Security Fundamentals OB 1.2.mp4 new file mode 100644 index 0000000000000000000000000000000000000000..6fc91e299601ffa4ca3354af71ead339d1b462d6 --- /dev/null +++ b/02 - Lesson 1 IT Security Fundamentals/001 Introduction IT Security Fundamentals OB 1.2.mp4 @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:fca859ed882120f6c1ab557a39e5bbe6a288a5e5ac35a4de44eae4728f3e32e4 +size 17971296 diff --git a/02 - Lesson 1 IT Security Fundamentals/001 Introduction IT Security Fundamentals OB 1.2_en.srt b/02 - Lesson 1 IT Security Fundamentals/001 Introduction IT Security Fundamentals OB 1.2_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..4fbccca657be1e758756067392bf7ac31022a8d2 --- /dev/null +++ b/02 - Lesson 1 IT Security Fundamentals/001 Introduction IT Security Fundamentals OB 1.2_en.srt @@ -0,0 +1,44 @@ +1 +00:00:00,000 --> 00:00:04,000 +Welcome to the first section of the course IT Security Fundamentals. + +2 +00:00:04,000 --> 00:00:09,000 +Now I want you guys to pay really careful attention in this particular section. + +3 +00:00:09,000 --> 00:00:15,000 +You see in this section I'm going to be reviewing some concepts such as CIA and triple A that you're + +4 +00:00:15,000 --> 00:00:17,000 +going to need for the entire rest of the course. + +5 +00:00:17,000 --> 00:00:23,000 +Terms such as confidentiality, integrity, availability, authentication, authorizations are terms + +6 +00:00:23,000 --> 00:00:28,000 +that we're going to use throughout the entire class to cover all the other lessons. + +7 +00:00:28,000 --> 00:00:30,000 +This section gives you the foundation. + +8 +00:00:30,000 --> 00:00:33,000 +You're going to need to understand the rest of the course. + +9 +00:00:33,000 --> 00:00:39,000 +So my recommendation is to maybe watch this section maybe two times, or at least understand every part + +10 +00:00:39,000 --> 00:00:41,000 +of it so you can be successful in the rest of the class. + +11 +00:00:41,000 --> 00:00:43,000 +So with that in mind, let's get started. + diff --git a/02 - Lesson 1 IT Security Fundamentals/002 CIA Triad OB 1.2.mp4 b/02 - Lesson 1 IT Security Fundamentals/002 CIA Triad OB 1.2.mp4 new file mode 100644 index 0000000000000000000000000000000000000000..c82eded954037de7ae99d02ed87b090a3b92853a --- /dev/null +++ b/02 - Lesson 1 IT Security Fundamentals/002 CIA Triad OB 1.2.mp4 @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:6172a91d2913d73fec34b2d2bc2e567dc80d574bf722b9a0982f50e3aa4b2bb7 +size 90102008 diff --git a/02 - Lesson 1 IT Security Fundamentals/002 CIA Triad OB 1.2_en.srt b/02 - Lesson 1 IT Security Fundamentals/002 CIA Triad OB 1.2_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..ab73ce241e81cb8d8c72322a7e7b81a06fc49bf6 --- /dev/null +++ b/02 - Lesson 1 IT Security Fundamentals/002 CIA Triad OB 1.2_en.srt @@ -0,0 +1,136 @@ +1 +00:00:00,000 --> 00:00:01,000 +When you think of it. + +2 +00:00:01,000 --> 00:00:03,000 +Security, what comes to mind? + +3 +00:00:03,000 --> 00:00:04,000 +You know what comes to my mind? + +4 +00:00:04,000 --> 00:00:07,000 +Protecting my secret information. + +5 +00:00:07,000 --> 00:00:08,000 +Yeah, I have a lot of secret information. + +6 +00:00:08,000 --> 00:00:09,000 +And so do you. + +7 +00:00:09,000 --> 00:00:16,000 +Credit card information, health care information, passwords to specific website products I buy, and + +8 +00:00:16,000 --> 00:00:17,000 +so on and so on. + +9 +00:00:17,000 --> 00:00:20,000 +All of this private data that I need to keep secret. + +10 +00:00:20,000 --> 00:00:25,000 +You see, protecting your private information from eyes that don't need to see it is a concept we call + +11 +00:00:25,000 --> 00:00:26,000 +confidentiality. + +12 +00:00:26,000 --> 00:00:30,000 +But confidentiality is only one of the three main goals of IT. + +13 +00:00:30,000 --> 00:00:31,000 +Security. + +14 +00:00:31,000 --> 00:00:36,000 +You see it security revolves around three main concepts. + +15 +00:00:36,000 --> 00:00:39,000 +And that concept is right here. + +16 +00:00:39,000 --> 00:00:41,000 +This is called the CIA triad. + +17 +00:00:41,000 --> 00:00:45,000 +The CIA triad tells us that the word CIA is just an acronym. + +18 +00:00:45,000 --> 00:00:50,000 +It's not actually a word that tells us the three main goals of it security. + +19 +00:00:50,000 --> 00:00:52,000 +That's going to be confidentiality. + +20 +00:00:52,000 --> 00:00:54,000 +We just mentioned integrity. + +21 +00:00:54,000 --> 00:00:59,000 +This is ensuring that, hey, unauthorized people don't edit our information or change it. + +22 +00:00:59,000 --> 00:01:01,000 +And then of course we want data to be available. + +23 +00:01:01,000 --> 00:01:02,000 +Availability. + +24 +00:01:02,000 --> 00:01:09,000 +You see all that we're going to be studying throughout this entire course, all your ways to keep your + +25 +00:01:09,000 --> 00:01:16,000 +data secure and to make them available and to keep them from not being altered, such as firewalls and + +26 +00:01:16,000 --> 00:01:22,000 +encryption, intrusion detection system, malware protection, and all the great things that we're going + +27 +00:01:22,000 --> 00:01:28,000 +to be learning to secure our networks, secure our data, secure people is all about revolving against + +28 +00:01:28,000 --> 00:01:30,000 +these three concepts here. + +29 +00:01:30,000 --> 00:01:35,000 +So in the next series of videos, let's get more in depth into these particular three things. + +30 +00:01:35,000 --> 00:01:39,000 +Because on your exam, I want you guys to know this on your exam. + +31 +00:01:39,000 --> 00:01:43,000 +Sometimes they may just say CIA triad, or they might just say CIA. + +32 +00:01:43,000 --> 00:01:47,000 +And you want to make sure, you know, it's not the Central Intelligence Agency, but it's actually + +33 +00:01:47,000 --> 00:01:50,000 +confidentiality, integrity and availability. + +34 +00:01:50,000 --> 00:01:53,000 +So let's keep going to learn more about these particular terms. + diff --git a/02 - Lesson 1 IT Security Fundamentals/003 Confidentiality OB 1.2.mp4 b/02 - Lesson 1 IT Security Fundamentals/003 Confidentiality OB 1.2.mp4 new file mode 100644 index 0000000000000000000000000000000000000000..d421ecf9c47aa07437428ad9a357cecd62494dd4 --- /dev/null +++ b/02 - Lesson 1 IT Security Fundamentals/003 Confidentiality OB 1.2.mp4 @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:562120d0a9cd657c905f68f5b128491e05b8399bbeec87ad67c408d63fcae534 +size 112277736 diff --git a/02 - Lesson 1 IT Security Fundamentals/003 Confidentiality OB 1.2_en.srt b/02 - Lesson 1 IT Security Fundamentals/003 Confidentiality OB 1.2_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..71ad33baec05a0381f0fb37d9b3e5d68ee7a90c0 --- /dev/null +++ b/02 - Lesson 1 IT Security Fundamentals/003 Confidentiality OB 1.2_en.srt @@ -0,0 +1,296 @@ +1 +00:00:00,000 --> 00:00:05,000 +When 99% of people think about it security, they're thinking about confidentiality. + +2 +00:00:05,000 --> 00:00:09,000 +You see, confidentiality is about keeping secret data secret. + +3 +00:00:09,000 --> 00:00:17,000 +It's to ensure that only authorized individuals or systems or entities has access to the right data, + +4 +00:00:17,000 --> 00:00:20,000 +and it keeps away unauthorized folks. + +5 +00:00:20,000 --> 00:00:24,000 +So confidentiality is one of the core tenets of IT security. + +6 +00:00:24,000 --> 00:00:33,000 +In fact, many of the controls, whether it's a firewall, an IDs system, antivirus software, a security + +7 +00:00:33,000 --> 00:00:40,000 +guard badge, access to get into a building, a lot of these controls that we're going to be applying, + +8 +00:00:40,000 --> 00:00:44,000 +we're going to be doing it to keeping our secret data secret. + +9 +00:00:44,000 --> 00:00:48,000 +And only only authorized individuals should have access to it. + +10 +00:00:48,000 --> 00:00:51,000 +Let's take a look here at the definition for confidentiality. + +11 +00:00:51,000 --> 00:00:58,000 +So refers to the refers to the measures taken to ensure that sensitive information is not disclosed + +12 +00:00:58,000 --> 00:01:01,000 +to unauthorized individuals, entities or processes. + +13 +00:01:02,000 --> 00:01:07,000 +It involves preserving, in other words, keeping authorized restrictions. + +14 +00:01:07,000 --> 00:01:11,000 +So we have to place restrictions on our information. + +15 +00:01:11,000 --> 00:01:12,000 +Well, what are those restrictions? + +16 +00:01:12,000 --> 00:01:14,000 +Well, I have some of them listed here. + +17 +00:01:14,000 --> 00:01:15,000 +We'll go through those in a little while. + +18 +00:01:16,000 --> 00:01:20,000 +It involves preserving authorized restrictions on the information. + +19 +00:01:20,000 --> 00:01:27,000 +Access disclosure, and we want to make sure that we keep our personal privacy and proprietary information + +20 +00:01:27,000 --> 00:01:27,000 +secure. + +21 +00:01:27,000 --> 00:01:30,000 +Now, how do we do this in the world of it? + +22 +00:01:30,000 --> 00:01:34,000 +How are we going to keep our secret data secret? + +23 +00:01:34,000 --> 00:01:35,000 +Here are a few ways. + +24 +00:01:35,000 --> 00:01:37,000 +These are not the only ways, but there are a few. + +25 +00:01:37,000 --> 00:01:39,000 +That's pretty pretty popular. + +26 +00:01:39,000 --> 00:01:41,000 +The first thing up we'll talk about is access control. + +27 +00:01:41,000 --> 00:01:43,000 +What exactly is that? + +28 +00:01:43,000 --> 00:01:48,000 +This is a firm you're going to hear about throughout this entire course, or any IT security course. + +29 +00:01:48,000 --> 00:01:49,000 +You're going to take about that. + +30 +00:01:49,000 --> 00:01:50,000 +You're going to be taken. + +31 +00:01:50,000 --> 00:01:54,000 +So in the world of computing, there's two things. + +32 +00:01:54,000 --> 00:01:57,000 +Something called a subject and an object. + +33 +00:01:57,000 --> 00:01:59,000 +Subjects wants to access objects. + +34 +00:01:59,000 --> 00:02:01,000 +Who's a subject. + +35 +00:02:01,000 --> 00:02:06,000 +You're the subject I'm the subject I want to use this computer to make this video. + +36 +00:02:07,000 --> 00:02:08,000 +So there's the subject. + +37 +00:02:08,000 --> 00:02:12,000 +The object is what you want to is is what you want to access. + +38 +00:02:12,000 --> 00:02:16,000 +Maybe a file or a folder, maybe a particular system that you want to access. + +39 +00:02:16,000 --> 00:02:22,000 +How do we control subjects access and objects with access control? + +40 +00:02:22,000 --> 00:02:27,000 +Access controls things such as a password is a type of an access control. + +41 +00:02:27,000 --> 00:02:27,000 +Right. + +42 +00:02:27,000 --> 00:02:31,000 +Because what the password does is that it controls your access to that machine. + +43 +00:02:31,000 --> 00:02:35,000 +If you know the password, you can get into the machine, don't know the password, you can't access + +44 +00:02:35,000 --> 00:02:36,000 +it. + +45 +00:02:36,000 --> 00:02:42,000 +So access control, such as a password or some kind of biometric will stop you from accessing a particular + +46 +00:02:42,000 --> 00:02:43,000 +system. + +47 +00:02:43,000 --> 00:02:47,000 +In other words, if you don't have authorization, you can't see the data on there preserving confidentiality. + +48 +00:02:48,000 --> 00:02:53,000 +Another thing here that we have is going to be that falls in here that you should be familiar with is + +49 +00:02:53,000 --> 00:02:56,000 +something called an ACL, an access control list. + +50 +00:02:56,000 --> 00:03:01,000 +If you work in an organization today and you try to access a file, maybe, or a folder, you double + +51 +00:03:01,000 --> 00:03:04,000 +click on it and it says boom, access denied. + +52 +00:03:04,000 --> 00:03:05,000 +That's an access control list. + +53 +00:03:05,000 --> 00:03:10,000 +Later on in the course, I'm going to show you what access control list looks like on files and folder + +54 +00:03:10,000 --> 00:03:13,000 +here on windows and of course on your different routers and firewalls. + +55 +00:03:14,000 --> 00:03:16,000 +Now encryption. + +56 +00:03:16,000 --> 00:03:20,000 +This is something that plays a huge part of our life. + +57 +00:03:20,000 --> 00:03:25,000 +When you buy on Amazon, you buy the latest gadget, you put your credit card information in, you put + +58 +00:03:25,000 --> 00:03:28,000 +your address, and Amazon ships that product. + +59 +00:03:28,000 --> 00:03:32,000 +Well, when you put your credit card information in, you are sitting at your computer. + +60 +00:03:32,000 --> 00:03:35,000 +So your credit card information went across the internet to Amazon. + +61 +00:03:35,000 --> 00:03:39,000 +Hopefully nobody saw that information from your house to the Amazon web server. + +62 +00:03:39,000 --> 00:03:45,000 +Well, they did see the information, but what they saw was an encrypted session. + +63 +00:03:45,000 --> 00:03:50,000 +And because of encryption, if they when they read it, they're not going to get anything out of it + +64 +00:03:50,000 --> 00:03:52,000 +because the data is fully encrypted. + +65 +00:03:52,000 --> 00:03:59,000 +So encryption is an amazing way to ensure that only authorized party can read the information. + +66 +00:03:59,000 --> 00:04:05,000 +So secure communication combined with encryption, we're going to use protocols or security protocols + +67 +00:04:05,000 --> 00:04:11,000 +such as SSL or TLS, basically the same thing in order to keep our data secure. + +68 +00:04:11,000 --> 00:04:18,000 +So these are some technical ways here that we're going to ensure confidentiality by using things such + +69 +00:04:18,000 --> 00:04:22,000 +as encryption, uh, access control. + +70 +00:04:22,000 --> 00:04:26,000 +And there are a bunch of physical ways to we'll get into those later on okay. + +71 +00:04:26,000 --> 00:04:28,000 +So just remember something about confidentiality. + +72 +00:04:28,000 --> 00:04:34,000 +It's all about keeping secret information secret and how to and how do we do that with a wide variety + +73 +00:04:34,000 --> 00:04:39,000 +of technical things and physical things that we're going to be using, that you're going to be learning + +74 +00:04:39,000 --> 00:04:42,000 +a lot more in the course to keep your secret data secret. + diff --git a/02 - Lesson 1 IT Security Fundamentals/004 Integrity OB 1.2.mp4 b/02 - Lesson 1 IT Security Fundamentals/004 Integrity OB 1.2.mp4 new file mode 100644 index 0000000000000000000000000000000000000000..8ab3e8c2ea280d157ec1996aad8cf5796eeb67fe --- /dev/null +++ b/02 - Lesson 1 IT Security Fundamentals/004 Integrity OB 1.2.mp4 @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:49aeced5d62772206c3adc5c4d98bb3a2d6baa5a1ba8fbafe0fdfb8bb50b9eb4 +size 68409165 diff --git a/02 - Lesson 1 IT Security Fundamentals/004 Integrity OB 1.2_en.srt b/02 - Lesson 1 IT Security Fundamentals/004 Integrity OB 1.2_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..ef5c735d92552bf9c2b33050695cd36e3f471851 --- /dev/null +++ b/02 - Lesson 1 IT Security Fundamentals/004 Integrity OB 1.2_en.srt @@ -0,0 +1,192 @@ +1 +00:00:00,000 --> 00:00:06,000 +One of the most important concepts in IT security is to ensure that there is only authorized changes + +2 +00:00:06,000 --> 00:00:11,000 +to information, basically, accuracy of information you see on systems. + +3 +00:00:11,000 --> 00:00:16,000 +Today, you're going to have tons and tons of data from people, Social Security numbers to secret memos + +4 +00:00:16,000 --> 00:00:18,000 +or business plans on a system. + +5 +00:00:18,000 --> 00:00:23,000 +We want to ensure that only authorized individuals can edit that information. + +6 +00:00:24,000 --> 00:00:29,000 +You see, viewing the information and seeing it, that's confidentiality, but changes and manipulation + +7 +00:00:29,000 --> 00:00:29,000 +of the data. + +8 +00:00:29,000 --> 00:00:32,000 +This is known as integrity. + +9 +00:00:32,000 --> 00:00:37,000 +So integrity is about protecting data from unauthorized changes to ensure it's reliable and correct. + +10 +00:00:37,000 --> 00:00:42,000 +That means that, hey, we want to stop unauthorized people from changing and editing information, + +11 +00:00:42,000 --> 00:00:49,000 +but we also want to make sure that we give authorized people the way or the method to change the data. + +12 +00:00:49,000 --> 00:00:55,000 +Now this really comes back to one core thing in integrity. + +13 +00:00:55,000 --> 00:00:59,000 +When you think integrity for your exam, I want you to think data accuracy. + +14 +00:00:59,000 --> 00:01:04,000 +How do we ensure that the data that you're getting that you're receiving is accurate? + +15 +00:01:04,000 --> 00:01:06,000 +Let me give you an example. + +16 +00:01:06,000 --> 00:01:08,000 +Let's say the CEO writes a memo. + +17 +00:01:08,000 --> 00:01:11,000 +He gives it to the to his assistant. + +18 +00:01:11,000 --> 00:01:13,000 +That memo is then distributed to the company. + +19 +00:01:13,000 --> 00:01:17,000 +But the upcoming goals of the business, let's say it has some secret business plans in there that only + +20 +00:01:17,000 --> 00:01:20,000 +companies I should see when you receive it. + +21 +00:01:20,000 --> 00:01:22,000 +And you're a much lower down the ladder than the CEO here. + +22 +00:01:22,000 --> 00:01:26,000 +So it had to go through many eyes and many hands. + +23 +00:01:26,000 --> 00:01:32,000 +How are you so sure that what's in this memo actually came from the CEO? + +24 +00:01:32,000 --> 00:01:34,000 +How do you ensure that it was never changed or modified? + +25 +00:01:35,000 --> 00:01:36,000 +This is the concept of integrity. + +26 +00:01:36,000 --> 00:01:39,000 +How do you sure that the data that you're receiving is accurate? + +27 +00:01:39,000 --> 00:01:40,000 +Is it consistent. + +28 +00:01:40,000 --> 00:01:45,000 +So consistency with what the CEO wrote and how can you trust it? + +29 +00:01:45,000 --> 00:01:50,000 +Well, one of the ways of doing this in the world of it that we're going to discuss later in this course + +30 +00:01:50,000 --> 00:01:52,000 +is called a digital signature. + +31 +00:01:52,000 --> 00:01:59,000 +If the CEO had used something such as a digital signature, you'll note that the data was never modified + +32 +00:01:59,000 --> 00:02:01,000 +and it actually came from him. + +33 +00:02:01,000 --> 00:02:03,000 +This helps to form integrity. + +34 +00:02:03,000 --> 00:02:09,000 +Another thing that we can use to stop people from changing or manipulating data that they shouldn't + +35 +00:02:09,000 --> 00:02:10,000 +be is access controls. + +36 +00:02:10,000 --> 00:02:16,000 +So access controls is basically controlling the access between subjects and objects. + +37 +00:02:16,000 --> 00:02:21,000 +So I can go in there in my computer and say, Mary, she can write to the data. + +38 +00:02:21,000 --> 00:02:26,000 +She has a, she has the, the, the permission to write to the information. + +39 +00:02:26,000 --> 00:02:30,000 +But Bob, he doesn't have access to write to the data. + +40 +00:02:30,000 --> 00:02:36,000 +He can see it though, so they could both see it, but only one person can write to it this way. + +41 +00:02:36,000 --> 00:02:40,000 +Mary is an authorized, authorized individual for integrity. + +42 +00:02:40,000 --> 00:02:41,000 +Bob is not. + +43 +00:02:41,000 --> 00:02:43,000 +So don't get the concepts confused. + +44 +00:02:43,000 --> 00:02:46,000 +There was two concepts so far confidentiality and integrity. + +45 +00:02:46,000 --> 00:02:49,000 +Confidentiality allows you to view the information. + +46 +00:02:49,000 --> 00:02:53,000 +Integrity allows you to manipulate and change the information. + +47 +00:02:53,000 --> 00:02:54,000 +So keep that in mind. + +48 +00:02:54,000 --> 00:02:57,000 +Confidentiality view it and integrity is about changing it. + diff --git a/02 - Lesson 1 IT Security Fundamentals/005 Availability OB 1.2.mp4 b/02 - Lesson 1 IT Security Fundamentals/005 Availability OB 1.2.mp4 new file mode 100644 index 0000000000000000000000000000000000000000..87ccdacd1b0c385b72dc95045337561f7540f0da --- /dev/null +++ b/02 - Lesson 1 IT Security Fundamentals/005 Availability OB 1.2.mp4 @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:c729741a4cbc53b331814879bd94ceb1083176a0b13ac387a2e05591fe3ba7ca +size 154740853 diff --git a/02 - Lesson 1 IT Security Fundamentals/005 Availability OB 1.2_en.srt b/02 - Lesson 1 IT Security Fundamentals/005 Availability OB 1.2_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..17bd4219283ed83b77e686e5edcef9263a14a59f --- /dev/null +++ b/02 - Lesson 1 IT Security Fundamentals/005 Availability OB 1.2_en.srt @@ -0,0 +1,232 @@ +1 +00:00:00,000 --> 00:00:03,000 +One concept that's missed a lot when talking about it. + +2 +00:00:03,000 --> 00:00:05,000 +Security is availability. + +3 +00:00:05,000 --> 00:00:09,000 +You see, when most people think it security, they're thinking confidentiality. + +4 +00:00:09,000 --> 00:00:11,000 +And some may even think of about about availability. + +5 +00:00:11,000 --> 00:00:15,000 +But it doesn't matter how secure your information is. + +6 +00:00:15,000 --> 00:00:20,000 +For example, you could secure your information by writing it on a piece of paper. + +7 +00:00:20,000 --> 00:00:22,000 +Take it off computer, put in a vault, put it inside the earth. + +8 +00:00:23,000 --> 00:00:27,000 +It's going to be super secure, but then not much people can access it. + +9 +00:00:27,000 --> 00:00:32,000 +It's not very useful if your security is so good that no one can use it when they actually need to use + +10 +00:00:32,000 --> 00:00:35,000 +it to make some money or to grow your organization. + +11 +00:00:35,000 --> 00:00:42,000 +So visibility is really this concept that ensures that data systems and services are accessible to authorized + +12 +00:00:42,000 --> 00:00:44,000 +users when needed. + +13 +00:00:44,000 --> 00:00:51,000 +Now we want to make sure to understand this concept, because there are a lot of attacks against networks + +14 +00:00:51,000 --> 00:00:55,000 +that can bring down an entire system, and then it's not very useful. + +15 +00:00:55,000 --> 00:00:58,000 +For example, what if there is a DDoS attack? + +16 +00:00:58,000 --> 00:01:01,000 +The distributed denial of service that takes out the Amazon website? + +17 +00:01:01,000 --> 00:01:03,000 +If you don't know what this is, don't worry, cover it. + +18 +00:01:04,000 --> 00:01:04,000 +Cover this more later. + +19 +00:01:04,000 --> 00:01:09,000 +Just know it's a type of attack that sends a lot of traffic to a website and takes it offline for malicious + +20 +00:01:09,000 --> 00:01:10,000 +reasons. + +21 +00:01:10,000 --> 00:01:16,000 +Now Amazon can't make money, or maybe your organization can't make money because the website is offline. + +22 +00:01:16,000 --> 00:01:25,000 +We want to protect our systems from unauthorized access, confidentiality, unauthorized changes, integrity, + +23 +00:01:25,000 --> 00:01:29,000 +and we want to make sure that it's available when needed. + +24 +00:01:29,000 --> 00:01:30,000 +How are we going to do that? + +25 +00:01:30,000 --> 00:01:32,000 +Well, here are a couple of ways. + +26 +00:01:32,000 --> 00:01:37,000 +Number one, we could build systems that can take a hit and keep on going. + +27 +00:01:37,000 --> 00:01:37,000 +All right. + +28 +00:01:37,000 --> 00:01:40,000 +They can continuously operate even if something goes wrong. + +29 +00:01:40,000 --> 00:01:44,000 +For example, you may have a server that has a dual power supply. + +30 +00:01:44,000 --> 00:01:47,000 +One of the first things that fails on a computer is the power supply. + +31 +00:01:47,000 --> 00:01:49,000 +So put two power supply. + +32 +00:01:49,000 --> 00:01:51,000 +Another common thing that fails is a hard drive. + +33 +00:01:51,000 --> 00:01:52,000 +Have a Raid system. + +34 +00:01:52,000 --> 00:01:54,000 +If you don't know what those are, talk about those later. + +35 +00:01:55,000 --> 00:01:57,000 +Another thing is you want to make sure you have backup of your information. + +36 +00:01:57,000 --> 00:02:01,000 +So if the system ever dies, you can always restore a backup. + +37 +00:02:02,000 --> 00:02:06,000 +If there's no backup, there's no restoration, and there's no you're going to lose a ton of data. + +38 +00:02:06,000 --> 00:02:08,000 +But if you have a backup, there's going to be no data loss. + +39 +00:02:08,000 --> 00:02:11,000 +So availability is a really important concept. + +40 +00:02:11,000 --> 00:02:15,000 +And there are many things that we're going to talk about later in the course that we're going to be + +41 +00:02:15,000 --> 00:02:18,000 +doing in order to maintain high availability. + +42 +00:02:18,000 --> 00:02:19,000 +All right. + +43 +00:02:19,000 --> 00:02:21,000 +So remember something. + +44 +00:02:21,000 --> 00:02:25,000 +The CIA triad confidentiality keep secret data secret. + +45 +00:02:25,000 --> 00:02:31,000 +Only authorized individuals can access the data, prevents unauthorized access integrity. + +46 +00:02:31,000 --> 00:02:38,000 +Only authorized individuals can edit the information prevents unauthorized changes or manipulation of + +47 +00:02:38,000 --> 00:02:39,000 +data availability. + +48 +00:02:39,000 --> 00:02:46,000 +Keeping systems online ensure there's no unauthorized downtime of information, such as the system failure + +49 +00:02:46,000 --> 00:02:48,000 +or data corruption. + +50 +00:02:48,000 --> 00:02:52,000 +Remember, these are going to be the three main concepts of IT security. + +51 +00:02:52,000 --> 00:02:56,000 +And if you're wondering, well, how is this going to fit in with the rest of the course, are all that + +52 +00:02:56,000 --> 00:02:57,000 +I'm about to learn? + +53 +00:02:58,000 --> 00:03:03,000 +Because believe this or not, every single thing that you're going to be learning. + +54 +00:03:03,000 --> 00:03:06,000 +For the next many, many, many hours. + +55 +00:03:06,000 --> 00:03:09,000 +It's going to be about protecting these three things. + +56 +00:03:09,000 --> 00:03:17,000 +It's going to be about how do we, uh, prevent unauthorized access, manipulation and high uptime on + +57 +00:03:17,000 --> 00:03:18,000 +availability? + +58 +00:03:18,000 --> 00:03:21,000 +This is the core concept of IT security. + diff --git a/02 - Lesson 1 IT Security Fundamentals/006 DAD Triade OB 1.2.mp4 b/02 - Lesson 1 IT Security Fundamentals/006 DAD Triade OB 1.2.mp4 new file mode 100644 index 0000000000000000000000000000000000000000..719bf51c569b15e3d5de38fa3d64ab1387ad1e90 --- /dev/null +++ b/02 - Lesson 1 IT Security Fundamentals/006 DAD Triade OB 1.2.mp4 @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:d4b5553ab5e0906328439265fd51cfeaea5389e19db61b4ca3016e20daf1e4cf +size 48749088 diff --git a/02 - Lesson 1 IT Security Fundamentals/006 DAD Triade OB 1.2_en.srt b/02 - Lesson 1 IT Security Fundamentals/006 DAD Triade OB 1.2_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..c2c3d24e2aa5f731a4bba0db039590319f49a909 --- /dev/null +++ b/02 - Lesson 1 IT Security Fundamentals/006 DAD Triade OB 1.2_en.srt @@ -0,0 +1,136 @@ +1 +00:00:00,000 --> 00:00:02,000 +I generally consider myself a good person. + +2 +00:00:02,000 --> 00:00:08,000 +I generally work with organizations to prevent unauthorized access, confidentiality, unauthorized + +3 +00:00:08,000 --> 00:00:14,000 +changes, integrity, and ensuring uptimes high uptimes under system availability. + +4 +00:00:14,000 --> 00:00:17,000 +But there are those of us or bad people. + +5 +00:00:17,000 --> 00:00:20,000 +Not a lot, but there are some bad people that we work against. + +6 +00:00:20,000 --> 00:00:27,000 +Every single thing in this course that we're going to learn about is to preserve the CIA and to stop + +7 +00:00:27,000 --> 00:00:30,000 +the D&D or the D&D triad. + +8 +00:00:30,000 --> 00:00:32,000 +You see, there is the opposite of the CIA. + +9 +00:00:32,000 --> 00:00:36,000 +So if we're working to preserve CIA, then what are we working against this? + +10 +00:00:36,000 --> 00:00:39,000 +If you are a bad person, this is what you do. + +11 +00:00:39,000 --> 00:00:41,000 +If you're a good person, you do CIA. + +12 +00:00:41,000 --> 00:00:42,000 +So what is this? + +13 +00:00:42,000 --> 00:00:43,000 +Well, this is the opposite. + +14 +00:00:43,000 --> 00:00:47,000 +This tells us so we have confidentiality, integrity and availability. + +15 +00:00:47,000 --> 00:00:51,000 +The opposite of those are going to be disclosure alteration and denial. + +16 +00:00:52,000 --> 00:00:59,000 +For example the opposite of confidentiality which is going to be, uh, preventing unauthorized access + +17 +00:00:59,000 --> 00:01:05,000 +is going to be allowing this unauthorized access or exposure of data, the opposite of integrity, which + +18 +00:01:05,000 --> 00:01:11,000 +is going to be something such as unauthorized, preventing unauthorized manipulation or changes. + +19 +00:01:11,000 --> 00:01:13,000 +This is going to allow authorized changes. + +20 +00:01:13,000 --> 00:01:17,000 +Alteration and availability is ensuring that you always have access. + +21 +00:01:17,000 --> 00:01:21,000 +How about if I deny you access to this actual information. + +22 +00:01:21,000 --> 00:01:26,000 +So this gives you just a quick a quick summary of what I just stated. + +23 +00:01:26,000 --> 00:01:27,000 +So what exactly is it. + +24 +00:01:27,000 --> 00:01:28,000 +Disclosure. + +25 +00:01:28,000 --> 00:01:30,000 +This goes against confidentiality. + +26 +00:01:30,000 --> 00:01:32,000 +This allows unauthorized access alteration. + +27 +00:01:32,000 --> 00:01:38,000 +This is against integrity unauthorized changes and denial is when they take your system offline. + +28 +00:01:38,000 --> 00:01:43,000 +By the way, I want to mention that sometimes depending on the book you read, denial may have they + +29 +00:01:43,000 --> 00:01:47,000 +may replace denial with the word destruction because that will also take data offline. + +30 +00:01:47,000 --> 00:01:53,000 +So sometimes you might see that, okay, just be familiar that there is such a thing as the D&D triad. + +31 +00:01:53,000 --> 00:01:56,000 +You may see it on your exam as just D&D triad. + +32 +00:01:56,000 --> 00:01:58,000 +Just remember that is where the bad guy works. + +33 +00:01:58,000 --> 00:02:02,000 +That's everything that we're going to be doing in this course. + +34 +00:02:02,000 --> 00:02:06,000 +That we're going to be working to stop the D&D triad. + diff --git a/02 - Lesson 1 IT Security Fundamentals/007 Zero Trust OB 1.2.mp4 b/02 - Lesson 1 IT Security Fundamentals/007 Zero Trust OB 1.2.mp4 new file mode 100644 index 0000000000000000000000000000000000000000..e335c04164be938c42c4a3cee38959275426fc8d --- /dev/null +++ b/02 - Lesson 1 IT Security Fundamentals/007 Zero Trust OB 1.2.mp4 @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:1a77d9929feab6395cbd63db5ee5bbca15560ce0d80dad8bdf24343237e7d10e +size 320464412 diff --git a/02 - Lesson 1 IT Security Fundamentals/007 Zero Trust OB 1.2_en.srt b/02 - Lesson 1 IT Security Fundamentals/007 Zero Trust OB 1.2_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..62a8d01d99fbb0f871d26dea07d3f17421b34b71 --- /dev/null +++ b/02 - Lesson 1 IT Security Fundamentals/007 Zero Trust OB 1.2_en.srt @@ -0,0 +1,616 @@ +1 +00:00:00,000 --> 00:00:05,000 +If you make a visit to Tia offices in Midtown Manhattan, and you come to pay us a visit, and you want + +2 +00:00:05,000 --> 00:00:10,000 +to gain access to some of our network resources, such as maybe internet or some files and folders on + +3 +00:00:10,000 --> 00:00:13,000 +our corporate systems or admin network. + +4 +00:00:13,000 --> 00:00:15,000 +You're going to have to go through a device like this. + +5 +00:00:15,000 --> 00:00:21,000 +Now, this is a sonic wall, and this sonic wall basically is a firewall, but it does include a switch, + +6 +00:00:21,000 --> 00:00:22,000 +as you can see at the back. + +7 +00:00:22,000 --> 00:00:24,000 +And it does have an access point. + +8 +00:00:24,000 --> 00:00:27,000 +We're going to talk a lot more about this devices as the course. + +9 +00:00:27,000 --> 00:00:27,000 +Go on. + +10 +00:00:27,000 --> 00:00:31,000 +Let me put this down here for a minute though, because there's something I want to talk to you guys + +11 +00:00:31,000 --> 00:00:33,000 +about, getting access to networks. + +12 +00:00:33,000 --> 00:00:38,000 +You see, in today's world, if you're going to a network and you plug your computer into it, as long + +13 +00:00:38,000 --> 00:00:43,000 +as you're in that particular network, you're probably going to get at least an internet connection. + +14 +00:00:43,000 --> 00:00:48,000 +So you're going to be able to do some kind of work, and you may have access to certain files and folders. + +15 +00:00:48,000 --> 00:00:55,000 +So what what essentially is happening is that you're basically getting access to resources such as the + +16 +00:00:55,000 --> 00:01:00,000 +internet or particular files and folders, without anybody authenticating you or knowing who the hell + +17 +00:01:00,000 --> 00:01:01,000 +you are. + +18 +00:01:01,000 --> 00:01:07,000 +You see, that is the default setup, especially on networks that uses small business devices like this + +19 +00:01:08,000 --> 00:01:10,000 +Sonicwall that I have here. + +20 +00:01:10,000 --> 00:01:12,000 +What we want to do is we want to change that. + +21 +00:01:12,000 --> 00:01:18,000 +What we want to do is have a different mindset, a different method of managing our network. + +22 +00:01:18,000 --> 00:01:22,000 +And that brings me to today's lesson zero trust. + +23 +00:01:22,000 --> 00:01:23,000 +What exactly is this? + +24 +00:01:23,000 --> 00:01:29,000 +Well, it centers on the belief that organizations should not automatically trust anything inside or + +25 +00:01:29,000 --> 00:01:31,000 +outside of their network. + +26 +00:01:31,000 --> 00:01:36,000 +So, for example, if you come into my network and because you're physically standing in it, you plug + +27 +00:01:36,000 --> 00:01:42,000 +your device into it, you're going to gain access to something the internet, internet, certain files + +28 +00:01:42,000 --> 00:01:44,000 +and folders, maybe even access to printers. + +29 +00:01:44,000 --> 00:01:49,000 +But on a zero trust, when you come into my network and you take your computer and you plug it into + +30 +00:01:49,000 --> 00:01:55,000 +the port, or you connect to the access point that that's on this device, you're not going to get anything. + +31 +00:01:55,000 --> 00:02:00,000 +We're going to have to authenticate you, or we're going to have to trust who you are or find out who + +32 +00:02:00,000 --> 00:02:03,000 +are you before this device is going to give you access to the network. + +33 +00:02:03,000 --> 00:02:07,000 +So zero trust is they shouldn't trust anything. + +34 +00:02:07,000 --> 00:02:09,000 +In other words, nothing is trusted. + +35 +00:02:09,000 --> 00:02:11,000 +Let me ask you a question. + +36 +00:02:11,000 --> 00:02:17,000 +As you sit here and you watch this video, if I come to your house and I connect to your network. + +37 +00:02:17,000 --> 00:02:17,000 +All right. + +38 +00:02:17,000 --> 00:02:22,000 +So I take out my laptop and I plug it into the switcher on your network, on your router or your cable + +39 +00:02:22,000 --> 00:02:23,000 +modem or whatever. + +40 +00:02:23,000 --> 00:02:24,000 +Do I get internet access? + +41 +00:02:24,000 --> 00:02:26,000 +Do I get access to things in your house? + +42 +00:02:26,000 --> 00:02:29,000 +If the answer is yes, you don't have zero trust with zero trust. + +43 +00:02:29,000 --> 00:02:31,000 +When people connect, they have nothing. + +44 +00:02:31,000 --> 00:02:35,000 +Not even internet organizations trust no one. + +45 +00:02:35,000 --> 00:02:41,000 +So they instead they verify every anything and everything trying to connect to its system. + +46 +00:02:41,000 --> 00:02:43,000 +Now, how are they going to do that? + +47 +00:02:43,000 --> 00:02:47,000 +Well, they're going to do very strict identity verification. + +48 +00:02:47,000 --> 00:02:51,000 +That's identifying users principles of least privileges. + +49 +00:02:51,000 --> 00:02:55,000 +That way when people connect, they have very little privileges on a network, just what they need to + +50 +00:02:55,000 --> 00:02:58,000 +do, just what they need to do a particular job. + +51 +00:02:58,000 --> 00:03:00,000 +Multi-factor authentication can be used here. + +52 +00:03:00,000 --> 00:03:04,000 +And of course, in Zero Trust, you're going to want to monitor and log all traffic. + +53 +00:03:04,000 --> 00:03:13,000 +Now, to take this a little further, I want to go in to a particular model that was that is given to + +54 +00:03:13,000 --> 00:03:15,000 +us by NIST documentation. + +55 +00:03:15,000 --> 00:03:20,000 +So NIST documentation and particularly NIST SP 800 207. + +56 +00:03:20,000 --> 00:03:21,000 +This is on page nine. + +57 +00:03:21,000 --> 00:03:23,000 +I took this diagram from there. + +58 +00:03:23,000 --> 00:03:30,000 +And this diagram breaks down how we can do a zero trust model using a specific set of components. + +59 +00:03:30,000 --> 00:03:33,000 +Now I'm going to come back to this model here in a minute. + +60 +00:03:33,000 --> 00:03:35,000 +Let me cover some terms first. + +61 +00:03:35,000 --> 00:03:41,000 +So the first thing I want to mention is that you're going to come to understand that you have to break + +62 +00:03:41,000 --> 00:03:48,000 +down your network into two layers, what's called a data layer and a control layer, or what's called + +63 +00:03:48,000 --> 00:03:50,000 +data planes and control planes. + +64 +00:03:50,000 --> 00:03:54,000 +Now I want to go back and I want to look at this particular diagram that we have here. + +65 +00:03:56,000 --> 00:03:58,000 +Let me put on my trusty pen. + +66 +00:03:58,000 --> 00:03:59,000 +Here we go with my trusty pen. + +67 +00:03:59,000 --> 00:04:01,000 +So I want you guys to take a look at this. + +68 +00:04:01,000 --> 00:04:06,000 +So notice you have what's called a data plane and a control plane. + +69 +00:04:06,000 --> 00:04:10,000 +Now as you go through your network and you connect to the network. + +70 +00:04:10,000 --> 00:04:17,000 +So let's say your subjects who are subjects, subjects, um, the subjects comes out of the data plane. + +71 +00:04:17,000 --> 00:04:19,000 +Subjects are entities requesting access. + +72 +00:04:19,000 --> 00:04:23,000 +So this is like you request an access to my particular network. + +73 +00:04:24,000 --> 00:04:26,000 +Now you're going to go on to a system, right? + +74 +00:04:26,000 --> 00:04:29,000 +You're going to be logged in to a laptop. + +75 +00:04:29,000 --> 00:04:32,000 +You're sitting at your laptop, you're sitting at your desktop. + +76 +00:04:32,000 --> 00:04:33,000 +So that's going to be your system. + +77 +00:04:33,000 --> 00:04:36,000 +You're going to be in what's called an untrusted zone. + +78 +00:04:36,000 --> 00:04:41,000 +So you're the subject and the system is untrusted by default on a zero trust. + +79 +00:04:41,000 --> 00:04:45,000 +Remember it's called zero trust, which means you're not trusted to our system. + +80 +00:04:45,000 --> 00:04:49,000 +So you come in and you say, hey, can you give me access to your network? + +81 +00:04:49,000 --> 00:04:57,000 +Well, the request to get access to my network is going to send to send to what we call a policy enforcement + +82 +00:04:57,000 --> 00:04:57,000 +point. + +83 +00:04:57,000 --> 00:04:59,000 +Now, what exactly is a policy enforcement point? + +84 +00:04:59,000 --> 00:05:05,000 +What that is, what's going to be responsible for enabling, monitoring and eventually terminating connections. + +85 +00:05:05,000 --> 00:05:13,000 +So you notice this policy enforcement point sits between you and the resource you want. + +86 +00:05:13,000 --> 00:05:14,000 +Let's say this resource is a printer. + +87 +00:05:16,000 --> 00:05:16,000 +All right. + +88 +00:05:16,000 --> 00:05:18,000 +So you want to access a particular printer. + +89 +00:05:18,000 --> 00:05:23,000 +Well, this policy enforcement point sits between you and accessing that particular resource. + +90 +00:05:23,000 --> 00:05:30,000 +So at the data plane of the network what is there in that data plane is just a subject accessing the + +91 +00:05:30,000 --> 00:05:30,000 +resource. + +92 +00:05:30,000 --> 00:05:34,000 +And there's something in between them that's saying, hey, you know what, you can access this or you + +93 +00:05:34,000 --> 00:05:35,000 +can't. + +94 +00:05:36,000 --> 00:05:40,000 +Now there is something we call an implicit trust. + +95 +00:05:40,000 --> 00:05:48,000 +So an implicit trust is let's say you're already trusted to log into the accounting network, an implicit + +96 +00:05:48,000 --> 00:05:50,000 +trust because you're logged in there. + +97 +00:05:50,000 --> 00:05:55,000 +The company already the company will give you then access to the financial network. + +98 +00:05:55,000 --> 00:05:57,000 +You don't need to re-authenticate it there. + +99 +00:05:57,000 --> 00:06:00,000 +So this has what's called an implicit trust between zones. + +100 +00:06:01,000 --> 00:06:03,000 +Now control plane. + +101 +00:06:03,000 --> 00:06:07,000 +The control plane is where all the magic happens. + +102 +00:06:07,000 --> 00:06:10,000 +You see the control plane has three components. + +103 +00:06:10,000 --> 00:06:12,000 +What's called a policy decision point. + +104 +00:06:12,000 --> 00:06:14,000 +This is what the whole thing is going to be about. + +105 +00:06:14,000 --> 00:06:17,000 +Should we let this guy go or not? + +106 +00:06:17,000 --> 00:06:19,000 +You have a policy engine and a policy administrator. + +107 +00:06:20,000 --> 00:06:25,000 +Now, when you log into a network, there is something we call an adaptive identity. + +108 +00:06:25,000 --> 00:06:27,000 +Adaptive means changing, right. + +109 +00:06:27,000 --> 00:06:31,000 +So we are going to dynamically adjust how we identify you. + +110 +00:06:31,000 --> 00:06:35,000 +Maybe we're going to identify you based on an IP address along with a username. + +111 +00:06:35,000 --> 00:06:39,000 +Maybe we're going to identify you based on where you're located and a particular username. + +112 +00:06:39,000 --> 00:06:44,000 +So I know this username should always log in from the United States or somewhere else. + +113 +00:06:44,000 --> 00:06:50,000 +There are some things this is all going to be done using what's called a policy driven access control. + +114 +00:06:50,000 --> 00:06:54,000 +All the access control that we have that we're going to allow you to access. + +115 +00:06:54,000 --> 00:06:59,000 +This particular printer has to go through a certain policy set up generally by your network administrator. + +116 +00:06:59,000 --> 00:07:03,000 +Now comes the, uh, policy administrator. + +117 +00:07:04,000 --> 00:07:05,000 +Oops. + +118 +00:07:05,000 --> 00:07:07,000 +The policy administrator and the policy engine. + +119 +00:07:07,000 --> 00:07:13,000 +So the policy administrator this is responsible for establishing or shutting down the communication + +120 +00:07:13,000 --> 00:07:16,000 +path between the between you, the subject and the resource. + +121 +00:07:16,000 --> 00:07:22,000 +The printer and the policy engine is responsible for the decision to whether to allow you to grant access + +122 +00:07:22,000 --> 00:07:23,000 +or not. + +123 +00:07:23,000 --> 00:07:25,000 +Now, let me go back to this. + +124 +00:07:25,000 --> 00:07:27,000 +I want to erase. + +125 +00:07:28,000 --> 00:07:29,000 +And I want to put this all together. + +126 +00:07:29,000 --> 00:07:32,000 +I know you're confused right now because this looks complex. + +127 +00:07:32,000 --> 00:07:40,000 +So you log in, you and your system try to gain access to this printer. + +128 +00:07:41,000 --> 00:07:46,000 +So what you do is you send your request to a policy enforcement point. + +129 +00:07:46,000 --> 00:07:49,000 +The policy enforcement point sends it to the administrator. + +130 +00:07:49,000 --> 00:07:56,000 +Now the administrator is responsible for allow for allowing that, uh, communication between you and + +131 +00:07:56,000 --> 00:07:57,000 +the actual printer. + +132 +00:07:57,000 --> 00:08:02,000 +But the policy administrator is not the one making the actual decision. + +133 +00:08:02,000 --> 00:08:04,000 +That's going to be the policy engine. + +134 +00:08:04,000 --> 00:08:10,000 +The policy engine is going to say allow or deny access after verifying the system, knowing who the + +135 +00:08:10,000 --> 00:08:13,000 +system is generally based on some kind of policy. + +136 +00:08:13,000 --> 00:08:17,000 +The policy engine tells the administrator, hey, allow this guy to gain access. + +137 +00:08:17,000 --> 00:08:23,000 +The policy enforcement point says, okay, the policy decision point, the place at the top says, you + +138 +00:08:23,000 --> 00:08:23,000 +know what? + +139 +00:08:23,000 --> 00:08:27,000 +You can gain access and now you gain access to it. + +140 +00:08:27,000 --> 00:08:32,000 +So this is what a zero trust model will look like in full implementation. + +141 +00:08:32,000 --> 00:08:36,000 +Now there is something here we call threat scope reduction. + +142 +00:08:36,000 --> 00:08:38,000 +This is going to be minimizing network attack surfaces. + +143 +00:08:38,000 --> 00:08:41,000 +What you want to do is you know where can you enter a network. + +144 +00:08:41,000 --> 00:08:43,000 +How many entry points do you have in a network. + +145 +00:08:43,000 --> 00:08:45,000 +The less entry points into a network. + +146 +00:08:45,000 --> 00:08:50,000 +For example, if you have no wireless, there's a lot less vulnerabilities or or entry points into a + +147 +00:08:50,000 --> 00:08:51,000 +network. + +148 +00:08:52,000 --> 00:08:52,000 +Okay. + +149 +00:08:53,000 --> 00:08:54,000 +The Zero Trust. + +150 +00:08:54,000 --> 00:08:59,000 +I would suggest for you to review this video one more time to make sure that you understand some of + +151 +00:08:59,000 --> 00:09:02,000 +the terms on it, that some of these terms may or may not appear on your exam. + +152 +00:09:03,000 --> 00:09:10,000 +But what will appear on your exam is probably the concept of zero trust, in which case no one can access + +153 +00:09:10,000 --> 00:09:14,000 +anything on your network without first being authenticated and verified that they should have access + +154 +00:09:14,000 --> 00:09:16,000 +to those particular resources. + diff --git a/02 - Lesson 1 IT Security Fundamentals/008 Non-Repudiation OB 1.2.mp4 b/02 - Lesson 1 IT Security Fundamentals/008 Non-Repudiation OB 1.2.mp4 new file mode 100644 index 0000000000000000000000000000000000000000..5c858dcba25b7b1561ce8b7598bdbf2e8782838c --- /dev/null +++ b/02 - Lesson 1 IT Security Fundamentals/008 Non-Repudiation OB 1.2.mp4 @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:223b6716912eb7ce86f06dc01fc8a700e4ab0c347105d8269c243082c4de95db +size 63283884 diff --git a/02 - Lesson 1 IT Security Fundamentals/008 Non-Repudiation OB 1.2_en.srt b/02 - Lesson 1 IT Security Fundamentals/008 Non-Repudiation OB 1.2_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..58f713facdad5295232149c02d0638492a449efd --- /dev/null +++ b/02 - Lesson 1 IT Security Fundamentals/008 Non-Repudiation OB 1.2_en.srt @@ -0,0 +1,192 @@ +1 +00:00:00,000 --> 00:00:01,000 +In the world of security. + +2 +00:00:01,000 --> 00:00:07,000 +When somebody does something and we tell them, hey, you did something wrong, we want to ensure that + +3 +00:00:07,000 --> 00:00:09,000 +they can't say, it wasn't me. + +4 +00:00:09,000 --> 00:00:14,000 +We want to put so much quote unquote controls, or we want to put so much protection mechanisms. + +5 +00:00:14,000 --> 00:00:18,000 +They don't want to come to you and says, hey, Bob, you stole that pen off the desk. + +6 +00:00:18,000 --> 00:00:20,000 +And Bob is like, was it me? + +7 +00:00:20,000 --> 00:00:21,000 +And I'm like, well, here's the camera footage. + +8 +00:00:21,000 --> 00:00:22,000 +You did it. + +9 +00:00:22,000 --> 00:00:27,000 +I want Bob to not deny that they did something. + +10 +00:00:27,000 --> 00:00:29,000 +You see, there is a terme in it. + +11 +00:00:29,000 --> 00:00:32,000 +Security we call non-repudiation. + +12 +00:00:32,000 --> 00:00:39,000 +Non-repudiation is when an entity cannot deny that an event has taken place. + +13 +00:00:39,000 --> 00:00:41,000 +They can't repudiate that. + +14 +00:00:41,000 --> 00:00:46,000 +So, for example, let's say I like this tablet. + +15 +00:00:46,000 --> 00:00:46,000 +All right. + +16 +00:00:46,000 --> 00:00:47,000 +There's a camera on this wall. + +17 +00:00:47,000 --> 00:00:48,000 +Camera in front of me. + +18 +00:00:48,000 --> 00:00:51,000 +I pick up this tablet, I put it in my bag, and I run out the room. + +19 +00:00:51,000 --> 00:00:56,000 +All right, I steal it, and I run out of the room, and the police comes after me and the police says, + +20 +00:00:56,000 --> 00:00:58,000 +Andrew, you stole that tablet. + +21 +00:00:58,000 --> 00:01:00,000 +And I'm like, no, I didn't, right? + +22 +00:01:00,000 --> 00:01:01,000 +Because I'm a bad person. + +23 +00:01:01,000 --> 00:01:02,000 +I'm a liar, obviously. + +24 +00:01:02,000 --> 00:01:07,000 +And the police says, well, here's the camera footage of you stealing it. + +25 +00:01:08,000 --> 00:01:11,000 +And I'm going to say, oh, you're right, I did steal that. + +26 +00:01:11,000 --> 00:01:15,000 +I guess I forgot, so I can't deny it anymore. + +27 +00:01:15,000 --> 00:01:20,000 +Okay, so in the world of IT security, this is called non-repudiation. + +28 +00:01:20,000 --> 00:01:27,000 +So non-repudiation is that when a party in a communication cannot, cannot deny the authenticity of + +29 +00:01:27,000 --> 00:01:30,000 +their signature on a document or sending of a message that the originator. + +30 +00:01:30,000 --> 00:01:36,000 +So they can't deny that they send something, they can't deny that this didn't come from them. + +31 +00:01:36,000 --> 00:01:43,000 +Now, this is really important because when you receive messages from places like Amazon, right when + +32 +00:01:43,000 --> 00:01:48,000 +you go to a website and you receive a confirmation from Amazon that, hey, your credit card went through + +33 +00:01:48,000 --> 00:01:54,000 +or you go to a website, how are you so sure that's Amazon, how does your computer know that's Amazon? + +34 +00:01:54,000 --> 00:01:59,000 +You see that's going to fall into the world of non-repudiation because those websites have something + +35 +00:01:59,000 --> 00:02:03,000 +we call certificates, which are digitally signed, a digital signature. + +36 +00:02:03,000 --> 00:02:04,000 +We're going to get more into it. + +37 +00:02:04,000 --> 00:02:06,000 +If you want to skip to this, it's going to be in the cryptography section. + +38 +00:02:06,000 --> 00:02:14,000 +But a digital signature is when you attach something to a document, a certificate that when you send + +39 +00:02:14,000 --> 00:02:17,000 +it, people are 100% sure it came from you. + +40 +00:02:17,000 --> 00:02:18,000 +All right. + +41 +00:02:18,000 --> 00:02:20,000 +That way that person can't deny that it came from them. + +42 +00:02:20,000 --> 00:02:22,000 +And you are sure that it came from them. + +43 +00:02:22,000 --> 00:02:26,000 +So that's one way of providing non-repudiation. + +44 +00:02:26,000 --> 00:02:27,000 +So remember what non-repudiation is. + +45 +00:02:27,000 --> 00:02:36,000 +Non-repudiation is going to be a concept that an entity, a subject cannot deny that a particular event + +46 +00:02:36,000 --> 00:02:37,000 +has taken place. + +47 +00:02:37,000 --> 00:02:42,000 +We do this in IT security most of the time by just using a digital signature. + +48 +00:02:42,000 --> 00:02:43,000 +Know that one for your exam. + diff --git a/02 - Lesson 1 IT Security Fundamentals/009 Authentication OB 1.2.mp4 b/02 - Lesson 1 IT Security Fundamentals/009 Authentication OB 1.2.mp4 new file mode 100644 index 0000000000000000000000000000000000000000..99cde2a76f3868d36075b712f53f139a831a284a --- /dev/null +++ b/02 - Lesson 1 IT Security Fundamentals/009 Authentication OB 1.2.mp4 @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:467be145f0cd86815836570a5564fedec1be478b5dbe8248b1294e7b07fa0688 +size 75714389 diff --git a/02 - Lesson 1 IT Security Fundamentals/009 Authentication OB 1.2_en.srt b/02 - Lesson 1 IT Security Fundamentals/009 Authentication OB 1.2_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..52224caf43b3a86161dded6773f828ce33a0f4e3 --- /dev/null +++ b/02 - Lesson 1 IT Security Fundamentals/009 Authentication OB 1.2_en.srt @@ -0,0 +1,164 @@ +1 +00:00:00,000 --> 00:00:06,000 +When working on a system, you're going to want to make sure that three main concepts are applied to + +2 +00:00:06,000 --> 00:00:06,000 +that system. + +3 +00:00:06,000 --> 00:00:11,000 +When a user logs into a computer, you want to make sure that they have the right password. + +4 +00:00:11,000 --> 00:00:16,000 +In other words, they're authenticated, they have access to the correct information authorization, + +5 +00:00:16,000 --> 00:00:18,000 +and you're tracking what they're doing. + +6 +00:00:18,000 --> 00:00:22,000 +You see, these concepts is referred to as triple A. + +7 +00:00:22,000 --> 00:00:26,000 +Triple A talks about authentication authorization and accounting. + +8 +00:00:26,000 --> 00:00:28,000 +Now authentication is a really important terms. + +9 +00:00:28,000 --> 00:00:30,000 +We have a whole dedicated video on it. + +10 +00:00:30,000 --> 00:00:31,000 +Coming up next. + +11 +00:00:31,000 --> 00:00:37,000 +This is the process of verifying the identity of a user, device or other entity to a particular system. + +12 +00:00:38,000 --> 00:00:40,000 +Another concept is authorization. + +13 +00:00:40,000 --> 00:00:46,000 +So authorization is really going to be about ensuring that an authorized individual has access to this + +14 +00:00:46,000 --> 00:00:46,000 +data. + +15 +00:00:46,000 --> 00:00:53,000 +For example, let's say you log in to a computer at your workplace and there's a folder on the desktop, + +16 +00:00:53,000 --> 00:00:54,000 +you double click on it. + +17 +00:00:54,000 --> 00:00:56,000 +Do you have access to that data? + +18 +00:00:56,000 --> 00:01:02,000 +The system has to perform some kind of a check to see, well, this user account, Bob, has access + +19 +00:01:02,000 --> 00:01:03,000 +to this particular folder. + +20 +00:01:03,000 --> 00:01:05,000 +Can you read what's in there? + +21 +00:01:05,000 --> 00:01:08,000 +Can you write to what's in there or can you just read. + +22 +00:01:08,000 --> 00:01:10,000 +This is called authorization. + +23 +00:01:10,000 --> 00:01:11,000 +We got to make sure that you have access to that data. + +24 +00:01:11,000 --> 00:01:15,000 +You try to go to a particular website, open up a particular application. + +25 +00:01:15,000 --> 00:01:19,000 +We have to make sure that only authorized people. + +26 +00:01:19,000 --> 00:01:25,000 +Has or is permitted to access certain types of information. + +27 +00:01:25,000 --> 00:01:29,000 +This is done generally using some kind of thing called we call an access control list. + +28 +00:01:29,000 --> 00:01:32,000 +Another thing we want to do is we want to track what you're doing. + +29 +00:01:32,000 --> 00:01:38,000 +We want to see that when you log in to a particular system, everything you do, we're going to know + +30 +00:01:38,000 --> 00:01:45,000 +as IT security professionals, we need to know that Bob logged in at 8:00 in the morning. + +31 +00:01:45,000 --> 00:01:47,000 +He accessed this file at 802. + +32 +00:01:47,000 --> 00:01:49,000 +He changed this one at 803. + +33 +00:01:49,000 --> 00:01:51,000 +He deleted this at 804, and so on and so on. + +34 +00:01:51,000 --> 00:01:54,000 +We want to keep track of every single thing you're doing. + +35 +00:01:54,000 --> 00:02:00,000 +This is going to help lead to keeping you accountable to what is happening on our systems. + +36 +00:02:00,000 --> 00:02:01,000 +So accountability is a big thing. + +37 +00:02:01,000 --> 00:02:03,000 +We'll talk about that later though in the course. + +38 +00:02:03,000 --> 00:02:03,000 +All right. + +39 +00:02:03,000 --> 00:02:05,000 +So remember what exactly is triple A. + +40 +00:02:06,000 --> 00:02:09,000 +Triple A refers to authentication authorization and accounting. + +41 +00:02:09,000 --> 00:02:15,000 +And every system that we have in our network today should have these particular three things. + diff --git a/02 - Lesson 1 IT Security Fundamentals/010 Authorization OB 1.2.mp4 b/02 - Lesson 1 IT Security Fundamentals/010 Authorization OB 1.2.mp4 new file mode 100644 index 0000000000000000000000000000000000000000..85d1f14d89c82be3a14327bad7d4bf89381bedc0 --- /dev/null +++ b/02 - Lesson 1 IT Security Fundamentals/010 Authorization OB 1.2.mp4 @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:f1c4515ebc370ba6b64ba57e77635683f0d7b33ef92a5bf036841f967890e0f4 +size 137044412 diff --git a/02 - Lesson 1 IT Security Fundamentals/010 Authorization OB 1.2_en.srt b/02 - Lesson 1 IT Security Fundamentals/010 Authorization OB 1.2_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..efc3cd6490a58c00742430f92d2628765f7c522e --- /dev/null +++ b/02 - Lesson 1 IT Security Fundamentals/010 Authorization OB 1.2_en.srt @@ -0,0 +1,268 @@ +1 +00:00:00,000 --> 00:00:04,000 +When a user logs into a system, what can they do? + +2 +00:00:04,000 --> 00:00:05,000 +What can they access? + +3 +00:00:05,000 --> 00:00:07,000 +Can they access a certain application? + +4 +00:00:07,000 --> 00:00:09,000 +Are they denied access to a particular thing? + +5 +00:00:10,000 --> 00:00:12,000 +You see, this is called authorization. + +6 +00:00:12,000 --> 00:00:17,000 +An authorization is all about ensuring that users have access to the right information. + +7 +00:00:17,000 --> 00:00:21,000 +Remember authentication is just about getting them into the system, but what can they access? + +8 +00:00:21,000 --> 00:00:25,000 +I want to show you a quick demonstration of authorization at play. + +9 +00:00:25,000 --> 00:00:27,000 +So here I am at my windows desktop. + +10 +00:00:27,000 --> 00:00:30,000 +I have two folders message and I have homework. + +11 +00:00:30,000 --> 00:00:34,000 +You notice that if I try to double click on messages watch what happens. + +12 +00:00:34,000 --> 00:00:39,000 +It says you don't you you don't currently have permission to access this folder. + +13 +00:00:39,000 --> 00:00:43,000 +That means that the system is denying me access to this particular folder. + +14 +00:00:44,000 --> 00:00:44,000 +All right. + +15 +00:00:44,000 --> 00:00:46,000 +Now you notice homework. + +16 +00:00:46,000 --> 00:00:49,000 +If I double click on this, I have full access to this. + +17 +00:00:49,000 --> 00:00:50,000 +I can access this. + +18 +00:00:50,000 --> 00:00:52,000 +I can go in here. + +19 +00:00:52,000 --> 00:00:54,000 +Maybe I can add a add a text file to this. + +20 +00:00:54,000 --> 00:00:55,000 +Wouldn't the other one. + +21 +00:00:55,000 --> 00:00:56,000 +I couldn't even open it. + +22 +00:00:57,000 --> 00:01:03,000 +The system is doing this by using something files and permissions on a access control list. + +23 +00:01:03,000 --> 00:01:05,000 +I want to show you what that looks like. + +24 +00:01:05,000 --> 00:01:10,000 +You see, if I right click on homework and I go to properties and I go to security. + +25 +00:01:10,000 --> 00:01:15,000 +You'll notice this list here of all the users and what they can do. + +26 +00:01:15,000 --> 00:01:16,000 +You notice I'm listed here. + +27 +00:01:17,000 --> 00:01:20,000 +And it says that I have full control and I can edit this. + +28 +00:01:20,000 --> 00:01:25,000 +Now if you're the administrator of the system like I am, you can actually add and remove permissions + +29 +00:01:25,000 --> 00:01:26,000 +as needed. + +30 +00:01:27,000 --> 00:01:30,000 +If I look at messages though, I right click I go to properties. + +31 +00:01:30,000 --> 00:01:32,000 +You'll notice this one doesn't have anybody. + +32 +00:01:33,000 --> 00:01:33,000 +All right. + +33 +00:01:33,000 --> 00:01:34,000 +Nobody is listed here. + +34 +00:01:34,000 --> 00:01:40,000 +So the administrator of the machine which is me can now go in here and add the permissions or edit permissions + +35 +00:01:40,000 --> 00:01:41,000 +to this. + +36 +00:01:41,000 --> 00:01:47,000 +So to give you a quick demonstration I'm going to show you how we can add a user to a particular system + +37 +00:01:47,000 --> 00:01:49,000 +or add users to a particular folder. + +38 +00:01:49,000 --> 00:01:50,000 +I would just say edit. + +39 +00:01:51,000 --> 00:01:52,000 +Add. + +40 +00:01:53,000 --> 00:01:57,000 +And then I would say advanced because I just want a quick list of users find now. + +41 +00:01:57,000 --> 00:02:01,000 +And you notice all the users in the machine will show up in this list. + +42 +00:02:01,000 --> 00:02:02,000 +I'm looking for myself. + +43 +00:02:02,000 --> 00:02:06,000 +So I'm going to click on me, say okay, okay one more time because it found me. + +44 +00:02:06,000 --> 00:02:12,000 +And then I'm going to give myself full control and say, okay, now when I try to access this, you + +45 +00:02:12,000 --> 00:02:13,000 +notice it opens right up. + +46 +00:02:13,000 --> 00:02:16,000 +And I can now go in there and add another message if I want. + +47 +00:02:16,000 --> 00:02:20,000 +This is the process of what's known as authorization. + +48 +00:02:20,000 --> 00:02:28,000 +So authorization is is going to be that process where we're going to determine what a user is allowed + +49 +00:02:28,000 --> 00:02:30,000 +to do by establishing their rights and privileges. + +50 +00:02:30,000 --> 00:02:31,000 +How are we going to do that? + +51 +00:02:31,000 --> 00:02:34,000 +By using what I just showed you permissions and privileges. + +52 +00:02:34,000 --> 00:02:35,000 +All right. + +53 +00:02:35,000 --> 00:02:41,000 +It involves granting permission to specific folders devices, applications. + +54 +00:02:41,000 --> 00:02:44,000 +And then we can say whether they can read to read to it or write to it. + +55 +00:02:44,000 --> 00:02:49,000 +So you got to remember that now I just showed you a small sample of that. + +56 +00:02:49,000 --> 00:02:54,000 +Rights and permissions are generally going to be done by assigning it to some kind of what's called + +57 +00:02:54,000 --> 00:02:55,000 +an ACL. + +58 +00:02:55,000 --> 00:02:58,000 +Now access control lists are going to be used by firewalls. + +59 +00:02:58,000 --> 00:03:03,000 +It's going to be used by, uh, routers to ensure who can come in and out of your network. + +60 +00:03:04,000 --> 00:03:10,000 +There are something we call an authorized auth authorization model. + +61 +00:03:10,000 --> 00:03:13,000 +And things such as Mac or Dak systems fall into this category. + +62 +00:03:13,000 --> 00:03:19,000 +I'm not going to cover this topic now because I have a whole I have a whole lecture coming up on different + +63 +00:03:19,000 --> 00:03:24,000 +forms of access control models coming up later in the in the course. + +64 +00:03:24,000 --> 00:03:26,000 +So just keep in mind that these do fall in here. + +65 +00:03:26,000 --> 00:03:27,000 +All right. + +66 +00:03:27,000 --> 00:03:33,000 +So remember now for your exam that when it comes to to authorization it's just about ensuring that the + +67 +00:03:33,000 --> 00:03:37,000 +right user has the right access to the correct resources. + diff --git a/02 - Lesson 1 IT Security Fundamentals/011 Accounting OB 1.2.mp4 b/02 - Lesson 1 IT Security Fundamentals/011 Accounting OB 1.2.mp4 new file mode 100644 index 0000000000000000000000000000000000000000..26f27db9dc1ac4d618cb4f0fa0498c2dfaecd1ad --- /dev/null +++ b/02 - Lesson 1 IT Security Fundamentals/011 Accounting OB 1.2.mp4 @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:28a0b1152a42a6f3bcb0b80720711c36fbe806dd2b51f3b19b6e7d013ffadf41 +size 67696549 diff --git a/02 - Lesson 1 IT Security Fundamentals/011 Accounting OB 1.2_en.srt b/02 - Lesson 1 IT Security Fundamentals/011 Accounting OB 1.2_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..7375b40123e7a21012688951047f339342a2d0ed --- /dev/null +++ b/02 - Lesson 1 IT Security Fundamentals/011 Accounting OB 1.2_en.srt @@ -0,0 +1,144 @@ +1 +00:00:00,000 --> 00:00:02,000 +Any time you log into a system. + +2 +00:00:02,000 --> 00:00:05,000 +I'm pretty sure every single thing you do on that system is tracked. + +3 +00:00:05,000 --> 00:00:06,000 +What do I mean by that? + +4 +00:00:06,000 --> 00:00:12,000 +Well, you open a file, you open a folder, you delete a file, you add a file to it. + +5 +00:00:12,000 --> 00:00:17,000 +More than likely, your organization is keeping track of all the activities you're doing in the world + +6 +00:00:17,000 --> 00:00:18,000 +of IT security. + +7 +00:00:18,000 --> 00:00:20,000 +We're going to call this thing accounting. + +8 +00:00:20,000 --> 00:00:27,000 +So accounting refers to tracking of user activity and resources within that system. + +9 +00:00:27,000 --> 00:00:28,000 +How are we tracking it. + +10 +00:00:28,000 --> 00:00:32,000 +Well in things like windows you have these log files and particularly the security log file. + +11 +00:00:32,000 --> 00:00:37,000 +And in that file depending on how your system is set up, I'm going to be able to see that you logged + +12 +00:00:37,000 --> 00:00:38,000 +in at 8:00. + +13 +00:00:38,000 --> 00:00:40,000 +You access this file at 802. + +14 +00:00:40,000 --> 00:00:42,000 +You change this file at 803. + +15 +00:00:42,000 --> 00:00:46,000 +I'm going to see all the actions you did, including all the things you deleted. + +16 +00:00:46,000 --> 00:00:53,000 +So log in is really important in helping keeping you accountable for the actions you took on the system. + +17 +00:00:53,000 --> 00:01:01,000 +So accounting along with authentication, authorization and identification then leads into this concept + +18 +00:01:01,000 --> 00:01:03,000 +of accountability, which we'll cover next. + +19 +00:01:03,000 --> 00:01:08,000 +So just for now, or I should say just in this video, I need you guys to understand that accounting + +20 +00:01:08,000 --> 00:01:11,000 +is about keeping track of everything you do. + +21 +00:01:11,000 --> 00:01:13,000 +It's on servers like windows. + +22 +00:01:13,000 --> 00:01:18,000 +We'll set up user tracking or auditing on them to see in the security log files. + +23 +00:01:18,000 --> 00:01:24,000 +And then of course, you can set up auditing and log in in many other devices such as firewalls, uh, + +24 +00:01:24,000 --> 00:01:27,000 +access points, routers and others. + +25 +00:01:27,000 --> 00:01:28,000 +So how is this done? + +26 +00:01:28,000 --> 00:01:29,000 +Well, user activity tracking. + +27 +00:01:29,000 --> 00:01:30,000 +When did you log in? + +28 +00:01:30,000 --> 00:01:31,000 +When did you log off? + +29 +00:01:31,000 --> 00:01:33,000 +What application you use? + +30 +00:01:33,000 --> 00:01:34,000 +When did you use it? + +31 +00:01:34,000 --> 00:01:36,000 +We're going to store these things in the system log files. + +32 +00:01:36,000 --> 00:01:39,000 +And particularly like in windows in the security log file. + +33 +00:01:39,000 --> 00:01:43,000 +You see users should be aware of this. + +34 +00:01:43,000 --> 00:01:49,000 +All users on a system should be aware that all actions they take is logged by the system log files, + +35 +00:01:49,000 --> 00:01:54,000 +and can be viewed by the authorized professionals, such as the administrators or senior management. + +36 +00:01:54,000 --> 00:01:58,000 +Because it's with accounting, are we going to be able to hold users accountable? + diff --git a/02 - Lesson 1 IT Security Fundamentals/012 Accountability OB 1.2.mp4 b/02 - Lesson 1 IT Security Fundamentals/012 Accountability OB 1.2.mp4 new file mode 100644 index 0000000000000000000000000000000000000000..b2d889c1d7946838c1c073361552da2f717ee1f4 --- /dev/null +++ b/02 - Lesson 1 IT Security Fundamentals/012 Accountability OB 1.2.mp4 @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:22939ae9693ee8d035054da5412de3af3b7cc7d126222a92dea24ac7ee8a8058 +size 72878164 diff --git a/02 - Lesson 1 IT Security Fundamentals/012 Accountability OB 1.2_en.srt b/02 - Lesson 1 IT Security Fundamentals/012 Accountability OB 1.2_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..d6850de9dfa61d802c10ed10d35a0a66fa5e527e --- /dev/null +++ b/02 - Lesson 1 IT Security Fundamentals/012 Accountability OB 1.2_en.srt @@ -0,0 +1,240 @@ +1 +00:00:00,000 --> 00:00:01,000 +When it comes to it security. + +2 +00:00:01,000 --> 00:00:05,000 +One of the things we have to have is going to be accountability. + +3 +00:00:05,000 --> 00:00:08,000 +So what exactly is accountability? + +4 +00:00:08,000 --> 00:00:14,000 +Well, accountability is when we're going to be able to ensure that individuals or entities are held + +5 +00:00:14,000 --> 00:00:16,000 +responsible for their actions. + +6 +00:00:16,000 --> 00:00:21,000 +The thing is, accountability is not something you're going to get by doing nothing, right. + +7 +00:00:21,000 --> 00:00:26,000 +Accountability has a particular set of steps that must be done. + +8 +00:00:26,000 --> 00:00:29,000 +If it's hard to, it's hard to point out where these things are. + +9 +00:00:29,000 --> 00:00:33,000 +Uh, that must be done in order for us to get right here. + +10 +00:00:33,000 --> 00:00:35,000 +So let's let's take a look at this. + +11 +00:00:35,000 --> 00:00:41,000 +So in order to get accountable or in order to hold you accountable for it, the first thing I need to + +12 +00:00:41,000 --> 00:00:43,000 +do is to identify who are you? + +13 +00:00:43,000 --> 00:00:44,000 +What's your name? + +14 +00:00:44,000 --> 00:00:49,000 +Oh, you're Bob, I need to prove to ensure that you prove that you are Bob. + +15 +00:00:49,000 --> 00:00:50,000 +So that's authentication. + +16 +00:00:50,000 --> 00:00:53,000 +This is going to be done maybe with a password or your thumbprint. + +17 +00:00:53,000 --> 00:00:58,000 +And then I want to make sure that I give you the right access to particular things. + +18 +00:00:58,000 --> 00:00:59,000 +Authorization. + +19 +00:00:59,000 --> 00:01:03,000 +And once I know you have access to it I'm going to track that you did it. + +20 +00:01:03,000 --> 00:01:05,000 +That's going to give me accountability. + +21 +00:01:05,000 --> 00:01:10,000 +Now, here's why all of these things are important to get to accountability. + +22 +00:01:10,000 --> 00:01:11,000 +And the reason is this. + +23 +00:01:12,000 --> 00:01:17,000 +If any of these blue boxes are broken, you're not going to get accountability. + +24 +00:01:17,000 --> 00:01:21,000 +For example, let's say everybody was using the same username. + +25 +00:01:21,000 --> 00:01:23,000 +Then there's no real identification. + +26 +00:01:23,000 --> 00:01:26,000 +There's no real way to say that's Bob and that's Mary, right. + +27 +00:01:26,000 --> 00:01:30,000 +Let's say everybody used the same password, but they had different usernames. + +28 +00:01:30,000 --> 00:01:32,000 +Everybody knew each other password. + +29 +00:01:32,000 --> 00:01:34,000 +So when I say, hey Mary, you are still our data. + +30 +00:01:34,000 --> 00:01:36,000 +Mary is going to be like, honestly, your data. + +31 +00:01:36,000 --> 00:01:37,000 +Everybody knows my password. + +32 +00:01:38,000 --> 00:01:39,000 +I can't hold you accountable. + +33 +00:01:39,000 --> 00:01:41,000 +If you never had access to something you're going to. + +34 +00:01:41,000 --> 00:01:44,000 +I'm going to say, hey man, you stole our data, Bob. + +35 +00:01:44,000 --> 00:01:46,000 +And Bob is going to say, I never had access to the data. + +36 +00:01:46,000 --> 00:01:48,000 +That's authorization. + +37 +00:01:48,000 --> 00:01:53,000 +I'm going to say, hey, Bob, you stole the data, and Bob is going to be like, so prove that I actually + +38 +00:01:53,000 --> 00:01:54,000 +stole the data. + +39 +00:01:54,000 --> 00:01:59,000 +That's accounting account is going to track what they did when they did it, how they did it right with + +40 +00:01:59,000 --> 00:02:00,000 +those log files. + +41 +00:02:00,000 --> 00:02:07,000 +So for us to get here to get accountability, we need to have all of these particular things done. + +42 +00:02:07,000 --> 00:02:13,000 +And if any one of those blue boxes are broken, you can best bet that you're not going to get the black + +43 +00:02:13,000 --> 00:02:13,000 +box. + +44 +00:02:13,000 --> 00:02:15,000 +You're not going to get accountability. + +45 +00:02:15,000 --> 00:02:19,000 +So I want to make sure these things here are absolutely correct. + +46 +00:02:19,000 --> 00:02:20,000 +Now you got to remember something. + +47 +00:02:20,000 --> 00:02:23,000 +Accountability is a core concept of security. + +48 +00:02:23,000 --> 00:02:24,000 +Remember this. + +49 +00:02:24,000 --> 00:02:30,000 +If you know you're going to be held accountable for something, you're less likely to commit that crime + +50 +00:02:30,000 --> 00:02:31,000 +driving down the highway. + +51 +00:02:32,000 --> 00:02:36,000 +Imagine every couple of hundred feet on a highway. + +52 +00:02:36,000 --> 00:02:37,000 +There's a cop. + +53 +00:02:37,000 --> 00:02:38,000 +You'd think anybody would speed, right? + +54 +00:02:38,000 --> 00:02:40,000 +You're going up a highway and there's a cop sitting there. + +55 +00:02:41,000 --> 00:02:45,000 +A whole highway slows down or people goes back to the speed limit because they're going to be held accountable. + +56 +00:02:45,000 --> 00:02:47,000 +If you're speeding, you're more likely to get caught. + +57 +00:02:47,000 --> 00:02:54,000 +If somebody knows that every action you take, you're going to be held accountable to those actions. + +58 +00:02:54,000 --> 00:03:00,000 +You're less likely to take bad actions, illegal actions. + +59 +00:03:00,000 --> 00:03:00,000 +Correct. + +60 +00:03:00,000 --> 00:03:04,000 +That's why accountability is really important. + diff --git a/02 - Lesson 1 IT Security Fundamentals/013 Gap analysis OB 1.2.mp4 b/02 - Lesson 1 IT Security Fundamentals/013 Gap analysis OB 1.2.mp4 new file mode 100644 index 0000000000000000000000000000000000000000..d8f61e450466037a754bcb58d45088026eeb3de0 --- /dev/null +++ b/02 - Lesson 1 IT Security Fundamentals/013 Gap analysis OB 1.2.mp4 @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:8634f2ffc03b7f69b11617fc6e8a4d7c22bc2f27b07d09af4c4a72bfbc625b2c +size 54590058 diff --git a/02 - Lesson 1 IT Security Fundamentals/013 Gap analysis OB 1.2_en.srt b/02 - Lesson 1 IT Security Fundamentals/013 Gap analysis OB 1.2_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..1803e66569647122b959ee678e4a692fc637d06f --- /dev/null +++ b/02 - Lesson 1 IT Security Fundamentals/013 Gap analysis OB 1.2_en.srt @@ -0,0 +1,188 @@ +1 +00:00:00,000 --> 00:00:01,000 +In today's organizations. + +2 +00:00:01,000 --> 00:00:08,000 +We all want to go from being good to being great, from making 1 million to 2 million, from being not + +3 +00:00:08,000 --> 00:00:10,000 +so secure to being very secure. + +4 +00:00:10,000 --> 00:00:17,000 +You see, in order to go from here currently to our desired state or where we want to be, we have to + +5 +00:00:17,000 --> 00:00:19,000 +perform what's called a gap analysis. + +6 +00:00:19,000 --> 00:00:20,000 +Easy example. + +7 +00:00:20,000 --> 00:00:24,000 +Well, I'm £210 today and I want to be £180. + +8 +00:00:24,000 --> 00:00:27,000 +Well, we've got a gap of £30. + +9 +00:00:27,000 --> 00:00:30,000 +You see we have to do a gap analysis. + +10 +00:00:30,000 --> 00:00:35,000 +We have to perform an assessment to see where we are right now and how are we going to get there. + +11 +00:00:36,000 --> 00:00:40,000 +So notice terms for your exam a gap analysis. + +12 +00:00:40,000 --> 00:00:44,000 +It's an assessment that organizations use to compare the current state. + +13 +00:00:44,000 --> 00:00:46,000 +That means where they are currently in terms of security. + +14 +00:00:46,000 --> 00:00:53,000 +Remember we are talking security here with a set of standards best practices or regulatory requirements. + +15 +00:00:53,000 --> 00:00:58,000 +So in terms of gap analysis, when it comes to IT security right now there may be a new regulation that + +16 +00:00:58,000 --> 00:01:01,000 +is out there and your organization is here. + +17 +00:01:01,000 --> 00:01:03,000 +So you've got to see what what do we have to do. + +18 +00:01:03,000 --> 00:01:08,000 +What are the controls and mechanisms and things we have to change to meet the new requirements. + +19 +00:01:08,000 --> 00:01:09,000 +So that's going to be the gap. + +20 +00:01:09,000 --> 00:01:14,000 +So in order to do this, one of the first things you have to know is where you are identification of + +21 +00:01:14,000 --> 00:01:15,000 +that current state. + +22 +00:01:16,000 --> 00:01:19,000 +What is your existing security controls and policies? + +23 +00:01:19,000 --> 00:01:21,000 +Then you have to decide, well, where do you want to be? + +24 +00:01:21,000 --> 00:01:22,000 +Right. + +25 +00:01:22,000 --> 00:01:26,000 +So what exactly is going to be that desired state? + +26 +00:01:26,000 --> 00:01:31,000 +Is it a particular policy you're trying to meet a particular standard, a particular um. + +27 +00:01:32,000 --> 00:01:38,000 +Regulation that you want to meet so you can understand what is that like standard. + +28 +00:01:38,000 --> 00:01:38,000 +Right. + +29 +00:01:38,000 --> 00:01:40,000 +What is that target that you want to be. + +30 +00:01:40,000 --> 00:01:42,000 +Then comes the analysis of the gap. + +31 +00:01:42,000 --> 00:01:44,000 +So how do we get there. + +32 +00:01:44,000 --> 00:01:44,000 +Right. + +33 +00:01:44,000 --> 00:01:45,000 +How are we going to go from here. + +34 +00:01:45,000 --> 00:01:47,000 +How am I going to go from 180? + +35 +00:01:47,000 --> 00:01:50,000 +I'm sorry I wish I was 180 from 210 to 180. + +36 +00:01:50,000 --> 00:01:51,000 +Right. + +37 +00:01:51,000 --> 00:01:52,000 +How am I going to do that? + +38 +00:01:52,000 --> 00:01:55,000 +The core of the gap analysis is identifying the difference between the two. + +39 +00:01:55,000 --> 00:01:56,000 +And how are we going to get there? + +40 +00:01:57,000 --> 00:02:03,000 +So keep in mind, guys, what a gap analysis is, is basically knowing your current state to your desired + +41 +00:02:03,000 --> 00:02:07,000 +state and then looking at hey, what is what is the gap? + +42 +00:02:07,000 --> 00:02:08,000 +How far are we off? + +43 +00:02:08,000 --> 00:02:11,000 +I'm £30 off how far his organization will be. + +44 +00:02:11,000 --> 00:02:17,000 +We're off by these many controls and these many policies that has to get implemented to meet the future + +45 +00:02:17,000 --> 00:02:17,000 +state. + +46 +00:02:17,000 --> 00:02:18,000 +And that is what. + +47 +00:02:18,000 --> 00:02:21,000 +And that is what a gap analysis is. + diff --git a/02 - Lesson 1 IT Security Fundamentals/014 Quick Quiz.html b/02 - Lesson 1 IT Security Fundamentals/014 Quick Quiz.html new file mode 100644 index 0000000000000000000000000000000000000000..7b6608a69df804ce6fd56fe279242c333c6a9f4a --- /dev/null +++ b/02 - Lesson 1 IT Security Fundamentals/014 Quick Quiz.html @@ -0,0 +1,479 @@ + + + + + + + Quiz + + + + +
+
+

+

+
+
+
+ Score: 999 of + 999% +
+
Correct: 999
+
Incorrect: 999
+
+ +
+ + + + +
+ + + + diff --git a/03 - Security Controls Categories and Types/001 Control Categories OB 1.1.mp4 b/03 - Security Controls Categories and Types/001 Control Categories OB 1.1.mp4 new file mode 100644 index 0000000000000000000000000000000000000000..6946065833b71ade463a07bc6e31330b26886703 --- /dev/null +++ b/03 - Security Controls Categories and Types/001 Control Categories OB 1.1.mp4 @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:cdf2e7a6c48ee07ed1ff6fc5e4153246b54b1beea7a7bcafdf7816bb41197afa +size 236173595 diff --git a/03 - Security Controls Categories and Types/001 Control Categories OB 1.1_en.srt b/03 - Security Controls Categories and Types/001 Control Categories OB 1.1_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..f521b86c3e29024937f5530809a25edbe48ad810 --- /dev/null +++ b/03 - Security Controls Categories and Types/001 Control Categories OB 1.1_en.srt @@ -0,0 +1,320 @@ +1 +00:00:00,000 --> 00:00:01,000 +Okay. + +2 +00:00:01,000 --> 00:00:07,000 +What does a security policy, a camera and the firewall have in common? + +3 +00:00:07,000 --> 00:00:15,000 +Well, all of these things, such as my paper policy, my user access policy that I have that's not + +4 +00:00:15,000 --> 00:00:15,000 +filled out here. + +5 +00:00:15,000 --> 00:00:17,000 +But just keep in mind this is just a policy. + +6 +00:00:17,000 --> 00:00:20,000 +What does all of these things here have in common. + +7 +00:00:20,000 --> 00:00:24,000 +And that is all about protecting our network. + +8 +00:00:24,000 --> 00:00:32,000 +For example, this firewall will protect our network from having worms, having all kinds of viruses + +9 +00:00:32,000 --> 00:00:34,000 +and hackers from breaking into our network. + +10 +00:00:34,000 --> 00:00:40,000 +This policy will tell you what you should be doing on my computer and what you shouldn't be doing. + +11 +00:00:40,000 --> 00:00:47,000 +And this camera is going to keep an eye on you as you walk around my physical facilities that this GoPro + +12 +00:00:47,000 --> 00:00:51,000 +in particular, but more of a CCTV or more of the cameras you see on the walls. + +13 +00:00:51,000 --> 00:00:53,000 +But let's just say that's one of them. + +14 +00:00:53,000 --> 00:00:58,000 +So in this video I want to talk about different categories of control. + +15 +00:00:58,000 --> 00:01:04,000 +And these are three different categories from a technical category from a technical control and administrative + +16 +00:01:04,000 --> 00:01:07,000 +or managerial control and a physical control. + +17 +00:01:07,000 --> 00:01:08,000 +Let's get into this. + +18 +00:01:09,000 --> 00:01:14,000 +So the first category I want to talk about is going to be technical controls. + +19 +00:01:14,000 --> 00:01:21,000 +As IT professionals we are more interested and we think more of technical controls. + +20 +00:01:21,000 --> 00:01:26,000 +But you've got to keep in mind you can have the best technical controls out there such as firewalls, + +21 +00:01:26,000 --> 00:01:28,000 +IDs, systems, encryption, antivirus. + +22 +00:01:28,000 --> 00:01:30,000 +You can have the best technical controls. + +23 +00:01:30,000 --> 00:01:35,000 +And if somebody can walk into the network and pick up your your data or your server and walk back out, + +24 +00:01:35,000 --> 00:01:36,000 +it's not very good. + +25 +00:01:36,000 --> 00:01:40,000 +So technical controls are basically the also known as logical controls. + +26 +00:01:40,000 --> 00:01:45,000 +And they're mechanisms that we use in hardware, software and firmware to help secure our network. + +27 +00:01:45,000 --> 00:01:50,000 +Now this is going to help us to prevent, detect and respond to security threats. + +28 +00:01:50,000 --> 00:01:51,000 +Here's what I tell my students. + +29 +00:01:51,000 --> 00:01:59,000 +If it's something you configure in a hardware and software like this device, it's considered a technical + +30 +00:01:59,000 --> 00:02:01,000 +control or logical control. + +31 +00:02:01,000 --> 00:02:01,000 +Same thing. + +32 +00:02:02,000 --> 00:02:05,000 +The other one I have is going to fall into this category. + +33 +00:02:05,000 --> 00:02:10,000 +This is going to be a managerial control also known as administrative controls. + +34 +00:02:10,000 --> 00:02:16,000 +So administrative controls are generally I tell my students are basically going to be anything on paper + +35 +00:02:16,000 --> 00:02:23,000 +that's going to be some kind of security policy, risk management processes, recovery plans, um, + +36 +00:02:24,000 --> 00:02:27,000 +incident responses and plans and disaster recovery plans. + +37 +00:02:27,000 --> 00:02:33,000 +Anything that you're going to find on a piece of paper is going to fall into this category of managerial + +38 +00:02:33,000 --> 00:02:36,000 +or also known as administrative control. + +39 +00:02:36,000 --> 00:02:40,000 +Another one we have is going to be operational security controls. + +40 +00:02:40,000 --> 00:02:48,000 +Now, operational controls are basically the things that we do to on a day to day to ensure that we + +41 +00:02:48,000 --> 00:02:51,000 +enforce the organization's policies and procedures. + +42 +00:02:51,000 --> 00:02:53,000 +This is going to be done by people. + +43 +00:02:54,000 --> 00:02:57,000 +So we're going to be doing this to maintain the security. + +44 +00:02:57,000 --> 00:03:01,000 +So what are things that people do within the organization generally? + +45 +00:03:01,000 --> 00:03:03,000 +Security awareness training. + +46 +00:03:03,000 --> 00:03:05,000 +That's something that you should have people be doing. + +47 +00:03:05,000 --> 00:03:10,000 +Training the users how to detect phishing links, training the users not to get scammed or click on + +48 +00:03:10,000 --> 00:03:11,000 +bad things. + +49 +00:03:11,000 --> 00:03:15,000 +Physical media protection such as protecting a USB stick, for example. + +50 +00:03:16,000 --> 00:03:18,000 +And then come the physical control. + +51 +00:03:18,000 --> 00:03:24,000 +Now, while I know security guys are pretty good at technical stuff, I know a lot of use. + +52 +00:03:24,000 --> 00:03:28,000 +Security guys, especially experienced security guys are really good at this one. + +53 +00:03:28,000 --> 00:03:30,000 +This firewall configuration thing. + +54 +00:03:31,000 --> 00:03:35,000 +Uh, most of us would be good at that. + +55 +00:03:35,000 --> 00:03:40,000 +A good set of us, not most of us, though, will also have a lot of respect and implement a lot of + +56 +00:03:40,000 --> 00:03:43,000 +managerial controls or administrative controls, such as policies. + +57 +00:03:44,000 --> 00:03:50,000 +And of course, we're all doing the day to day work, but not many of security people nowadays think + +58 +00:03:50,000 --> 00:03:51,000 +of physical controls. + +59 +00:03:51,000 --> 00:03:55,000 +Physical controls are really important, like I mentioned earlier. + +60 +00:03:55,000 --> 00:04:01,000 +You can have the best encryption on on your servers, but if I can just walk into the organization and + +61 +00:04:01,000 --> 00:04:06,000 +pick up a workstation, pick up the data and just walk back out, you don't really have good controls, + +62 +00:04:06,000 --> 00:04:06,000 +do you? + +63 +00:04:07,000 --> 00:04:13,000 +So physical controls are measures taken to protect the actual hardware and facilities that house the + +64 +00:04:13,000 --> 00:04:14,000 +system. + +65 +00:04:14,000 --> 00:04:17,000 +So these are controls we use to protect the actual physical hardware. + +66 +00:04:17,000 --> 00:04:23,000 +Like somebody just can't walk in and pick up my firewall, really expensive device and walk back out + +67 +00:04:23,000 --> 00:04:24,000 +with it. + +68 +00:04:24,000 --> 00:04:26,000 +So that's going to include things like what. + +69 +00:04:26,000 --> 00:04:31,000 +Well, that's going to include things like cameras, security guards, fences, signs, lighting and + +70 +00:04:31,000 --> 00:04:34,000 +so on that we can use in the physical vicinity. + +71 +00:04:34,000 --> 00:04:38,000 +Now, we do have a whole lesson on physical security coming up later. + +72 +00:04:39,000 --> 00:04:39,000 +Okay. + +73 +00:04:39,000 --> 00:04:43,000 +So keep in mind that we have four categories. + +74 +00:04:43,000 --> 00:04:45,000 +Technical things you can figure. + +75 +00:04:46,000 --> 00:04:48,000 +Are manager or administrative. + +76 +00:04:48,000 --> 00:04:48,000 +Same thing. + +77 +00:04:48,000 --> 00:04:50,000 +Those are going to be things on paper. + +78 +00:04:50,000 --> 00:04:56,000 +Operational things you do on a day to day basis and then come physical things you can touch and feel + +79 +00:04:56,000 --> 00:04:59,000 +to protect physical assets within the environment. + +80 +00:04:59,000 --> 00:05:02,000 +Make sure you know what they are and what they're doing to protect you. + diff --git a/03 - Security Controls Categories and Types/002 Control Types OB 1.1.mp4 b/03 - Security Controls Categories and Types/002 Control Types OB 1.1.mp4 new file mode 100644 index 0000000000000000000000000000000000000000..1ae67fb9a7b65273917edeb3cfbb7748e446ca47 --- /dev/null +++ b/03 - Security Controls Categories and Types/002 Control Types OB 1.1.mp4 @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:cc1f860e5998ef88bd6cfe5ce60130f243d176797aecbc16ec1201221e637d92 +size 230762032 diff --git a/03 - Security Controls Categories and Types/002 Control Types OB 1.1_en.srt b/03 - Security Controls Categories and Types/002 Control Types OB 1.1_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..7ed5550b13083761e3b93fb04636150a7f7ccf0f --- /dev/null +++ b/03 - Security Controls Categories and Types/002 Control Types OB 1.1_en.srt @@ -0,0 +1,400 @@ +1 +00:00:00,000 --> 00:00:05,000 +When protecting your network, you're going to be using a whole lot of controls and a lot of the controls + +2 +00:00:05,000 --> 00:00:08,000 +that we have falls into multiple types. + +3 +00:00:08,000 --> 00:00:10,000 +So let's see what these types are in this video. + +4 +00:00:10,000 --> 00:00:14,000 +So the first thing that we're going to have is we're going to go through one of the most common types + +5 +00:00:14,000 --> 00:00:18,000 +that most people think about is going to be preventative types or preventative controls. + +6 +00:00:18,000 --> 00:00:21,000 +You see preventative controls will stop. + +7 +00:00:21,000 --> 00:00:24,000 +An intrusion will stop a security incident from arising. + +8 +00:00:24,000 --> 00:00:27,000 +So they'll stop all kinds of incidents. + +9 +00:00:27,000 --> 00:00:31,000 +This is going to include things like firewalls, encryption, access control, and even physical things + +10 +00:00:31,000 --> 00:00:33,000 +that could security guard or a fence. + +11 +00:00:33,000 --> 00:00:40,000 +Now, before I get it more into this, I want to I want to keep remind you guys that a single control + +12 +00:00:40,000 --> 00:00:42,000 +falls into multiple types. + +13 +00:00:42,000 --> 00:00:42,000 +All right. + +14 +00:00:42,000 --> 00:00:48,000 +Some controls may only be one type, but generally a lot of the controls that we use falls into multiple + +15 +00:00:48,000 --> 00:00:48,000 +types. + +16 +00:00:48,000 --> 00:00:51,000 +So I want you guys take a look at this firewall that I have here. + +17 +00:00:51,000 --> 00:00:52,000 +So this is a sonicwall. + +18 +00:00:52,000 --> 00:01:00,000 +And this particular firewall will stop all kinds of malicious traffic from entering my network. + +19 +00:01:00,000 --> 00:01:03,000 +So let's say there's a malicious worm spreading around on the internet. + +20 +00:01:03,000 --> 00:01:07,000 +Well this this one here has the internet port here. + +21 +00:01:07,000 --> 00:01:09,000 +And it has a switch port on this end. + +22 +00:01:10,000 --> 00:01:10,000 +All right. + +23 +00:01:10,000 --> 00:01:12,000 +Actually, uh, the switchboard connected here. + +24 +00:01:12,000 --> 00:01:15,000 +So internet comes in here. + +25 +00:01:15,000 --> 00:01:18,000 +The firewall then assesses the traffic and says, hey, you're a worm. + +26 +00:01:18,000 --> 00:01:18,000 +Boom. + +27 +00:01:18,000 --> 00:01:21,000 +You're not coming in here and stops it from going out to Switchport. + +28 +00:01:21,000 --> 00:01:22,000 +So what happens? + +29 +00:01:22,000 --> 00:01:24,000 +This device stopped an intrusion. + +30 +00:01:24,000 --> 00:01:27,000 +So this is a good preventative device. + +31 +00:01:27,000 --> 00:01:31,000 +Another kind of control we're going to have is going to be called a detective control. + +32 +00:01:31,000 --> 00:01:35,000 +Detective controls can detect intrusions as they're happening. + +33 +00:01:35,000 --> 00:01:39,000 +This is going to be something like an intrusion detection system such as snort. + +34 +00:01:39,000 --> 00:01:46,000 +So snort very popular software that you can download right now and try out snort will actually absorb + +35 +00:01:46,000 --> 00:01:51,000 +all your network traffic and then analyze the traffic and says, hey, that computer over there, that + +36 +00:01:51,000 --> 00:01:52,000 +computer has a worm. + +37 +00:01:52,000 --> 00:01:54,000 +That one there is being hacked. + +38 +00:01:54,000 --> 00:01:59,000 +So this is detecting intrusions also that can happen here in the world of physical is going to be things + +39 +00:01:59,000 --> 00:02:05,000 +like a video surveillance camera watching people, security guards watching them can detect them committing + +40 +00:02:05,000 --> 00:02:06,000 +a crime. + +41 +00:02:06,000 --> 00:02:07,000 +Corrective control. + +42 +00:02:07,000 --> 00:02:12,000 +Well, when there is a security incident and something has gone wrong in your network, you have to + +43 +00:02:12,000 --> 00:02:14,000 +remember that we have to go and fix it. + +44 +00:02:14,000 --> 00:02:17,000 +We just after it's done, we got to go fix it. + +45 +00:02:17,000 --> 00:02:19,000 +Let's say a computer got infected with a virus. + +46 +00:02:19,000 --> 00:02:22,000 +The virus deletes the data, corrupts the entire machine. + +47 +00:02:22,000 --> 00:02:25,000 +Well, somebody needs to go in here and do this control. + +48 +00:02:25,000 --> 00:02:31,000 +Somebody needs to restore those backups and reinstall windows on those particular machines. + +49 +00:02:32,000 --> 00:02:35,000 +Another one we have is what's called a deterrent control. + +50 +00:02:35,000 --> 00:02:37,000 +Deterrent control will scare people off. + +51 +00:02:37,000 --> 00:02:40,000 +Deterrent control will discourage a threat. + +52 +00:02:40,000 --> 00:02:47,000 +So, for example, a camera is a kind of a not only is this a detective as this can detect people coming + +53 +00:02:47,000 --> 00:02:49,000 +to crime, but this can also scare people off. + +54 +00:02:49,000 --> 00:02:52,000 +Now I want you to keep in mind the turn versus preventive. + +55 +00:02:52,000 --> 00:02:53,000 +So watch this. + +56 +00:02:53,000 --> 00:02:54,000 +Here's a camera. + +57 +00:02:54,000 --> 00:02:55,000 +It's watching my desk. + +58 +00:02:55,000 --> 00:03:02,000 +So if we position this camera here to watch this desk, and I'm a bad guy and I go to steal my tablet, + +59 +00:03:02,000 --> 00:03:05,000 +let's say I want to steal my tablet and run off. + +60 +00:03:05,000 --> 00:03:07,000 +Well, this camera doesn't do anything. + +61 +00:03:07,000 --> 00:03:08,000 +It just sits here. + +62 +00:03:08,000 --> 00:03:11,000 +Its hands don't come out the camera and stop me. + +63 +00:03:11,000 --> 00:03:18,000 +This is only here to scare me and detect me, discourage me and detect me from stealing a particular + +64 +00:03:18,000 --> 00:03:19,000 +thing or committing a crime. + +65 +00:03:19,000 --> 00:03:23,000 +You see, this is detective. + +66 +00:03:23,000 --> 00:03:25,000 +This is deterrent. + +67 +00:03:25,000 --> 00:03:27,000 +But this is not preventative. + +68 +00:03:27,000 --> 00:03:29,000 +This doesn't prevent a security guard, though. + +69 +00:03:29,000 --> 00:03:32,000 +Can see they have surveillance. + +70 +00:03:32,000 --> 00:03:35,000 +They can deter because they're standing there. + +71 +00:03:35,000 --> 00:03:36,000 +Maybe they have a gun. + +72 +00:03:36,000 --> 00:03:38,000 +And of course there are. + +73 +00:03:38,000 --> 00:03:42,000 +They're going to detect, prevent and deter me. + +74 +00:03:42,000 --> 00:03:42,000 +All right. + +75 +00:03:42,000 --> 00:03:43,000 +So they can do a lot. + +76 +00:03:43,000 --> 00:03:46,000 +Like I said, one control can fall into multiple. + +77 +00:03:46,000 --> 00:03:49,000 +Another one we have is the directive control. + +78 +00:03:49,000 --> 00:03:52,000 +So a directive control is when we're going to. + +79 +00:03:53,000 --> 00:04:01,000 +Have, uh, all kinds of instructions on how to use a system to prevent a response to security incidents, + +80 +00:04:01,000 --> 00:04:07,000 +and particularly having different kind of policies would tell people how to use our systems, compensate + +81 +00:04:07,000 --> 00:04:09,000 +and control compensating controllers. + +82 +00:04:09,000 --> 00:04:14,000 +When you don't have the best control available, you go well with the second best. + +83 +00:04:14,000 --> 00:04:18,000 +You can say, well, he's compensating because he can't do that particular task. + +84 +00:04:18,000 --> 00:04:19,000 +So. + +85 +00:04:19,000 --> 00:04:26,000 +For example, let's say the best control out there is going to be the highest end firewall, next generation + +86 +00:04:26,000 --> 00:04:27,000 +firewall. + +87 +00:04:27,000 --> 00:04:27,000 +You don't have that one. + +88 +00:04:27,000 --> 00:04:31,000 +You don't have the resources or budget for it, so you get the next best one. + +89 +00:04:31,000 --> 00:04:35,000 +Remember, this one is when you don't have the primary control, you go with the second best one. + +90 +00:04:35,000 --> 00:04:38,000 +That's going to be a compensating control. + +91 +00:04:38,000 --> 00:04:38,000 +Okay. + +92 +00:04:38,000 --> 00:04:44,000 +So once again guys, I really want to point out that if you're sitting here saying, well, if you can + +93 +00:04:44,000 --> 00:04:48,000 +think of a particular control that I haven't mentioned and you're saying, well, hey, that sounds + +94 +00:04:48,000 --> 00:04:52,000 +like a complete compensator, that sounds like a detective, that sounds like a preventative. + +95 +00:04:52,000 --> 00:04:53,000 +It probably is. + +96 +00:04:53,000 --> 00:04:58,000 +Now on your exam, they may give you a particular scenario, and you're going to have to say, well, + +97 +00:04:58,000 --> 00:05:01,000 +that's a detective, that's a deterrent. + +98 +00:05:01,000 --> 00:05:02,000 +Or they may even give it to you. + +99 +00:05:02,000 --> 00:05:04,000 +And you may have to say what category it falls in. + +100 +00:05:04,000 --> 00:05:06,000 +Just make sure you know your types and categories for your test. + diff --git a/03 - Security Controls Categories and Types/003 Defense in Depth OB 1.1.mp4 b/03 - Security Controls Categories and Types/003 Defense in Depth OB 1.1.mp4 new file mode 100644 index 0000000000000000000000000000000000000000..0a0c77bed1489f3d04156cb1a3aecb4cee8704c4 --- /dev/null +++ b/03 - Security Controls Categories and Types/003 Defense in Depth OB 1.1.mp4 @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:f07f37584be67761f48e45ff75e8985c7917d39aa5d30329262f0a0ab5fae5d9 +size 159103460 diff --git a/03 - Security Controls Categories and Types/003 Defense in Depth OB 1.1_en.srt b/03 - Security Controls Categories and Types/003 Defense in Depth OB 1.1_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..3e802f8172931b8fe442343671c59f07ce606a1a --- /dev/null +++ b/03 - Security Controls Categories and Types/003 Defense in Depth OB 1.1_en.srt @@ -0,0 +1,236 @@ +1 +00:00:00,000 --> 00:00:06,000 +A good security professional doesn't secure a network with a single control, or a single type or category + +2 +00:00:06,000 --> 00:00:07,000 +of control. + +3 +00:00:07,000 --> 00:00:11,000 +A security professional secures a network using a multi-layered approach. + +4 +00:00:11,000 --> 00:00:14,000 +So that brings me to this section layered security. + +5 +00:00:14,000 --> 00:00:20,000 +One of the more important concepts you'll ever learn in this entire video series is going to be this + +6 +00:00:20,000 --> 00:00:21,000 +concept of defense in depth. + +7 +00:00:21,000 --> 00:00:29,000 +Defense in depth is using multiple or layers of controls in order to secure a network. + +8 +00:00:29,000 --> 00:00:33,000 +It's not just one layer, it's going to be multiple layers. + +9 +00:00:33,000 --> 00:00:37,000 +And for that, I want to draw you guys a particular diagram. + +10 +00:00:37,000 --> 00:00:37,000 +Where is that pen. + +11 +00:00:38,000 --> 00:00:38,000 +Here we go. + +12 +00:00:39,000 --> 00:00:41,000 +So I want to show you guys something. + +13 +00:00:41,000 --> 00:00:43,000 +Let's say you have a network. + +14 +00:00:43,000 --> 00:00:45,000 +And in the network there's data. + +15 +00:00:45,000 --> 00:00:45,000 +All right. + +16 +00:00:45,000 --> 00:00:48,000 +So data is what you're trying to protect. + +17 +00:00:48,000 --> 00:00:51,000 +Well you're going to secure that data with a firewall. + +18 +00:00:51,000 --> 00:00:52,000 +Well that's just one layer. + +19 +00:00:52,000 --> 00:00:58,000 +Then around that you're going to use procedures or policies to tell people, hey, don't share this + +20 +00:00:58,000 --> 00:00:58,000 +data. + +21 +00:00:58,000 --> 00:01:00,000 +Don't give away this data. + +22 +00:01:00,000 --> 00:01:06,000 +And then around this also, you're going to be using physical things like a security guard or a fence. + +23 +00:01:07,000 --> 00:01:09,000 +You can see why I don't write too much. + +24 +00:01:09,000 --> 00:01:10,000 +Not the best handwriting there. + +25 +00:01:10,000 --> 00:01:16,000 +Okay, so you notice that when we're secure in our data, we're not just securing the data with just + +26 +00:01:16,000 --> 00:01:18,000 +one control. + +27 +00:01:18,000 --> 00:01:23,000 +You're using multiple controls across multiple categories. + +28 +00:01:23,000 --> 00:01:28,000 +For example, you're just not going to use a firewall, but you're going to use firewall and encryption. + +29 +00:01:28,000 --> 00:01:31,000 +That's two technical controls. + +30 +00:01:31,000 --> 00:01:36,000 +You're going to use a policy and a procedure to administrative control. + +31 +00:01:36,000 --> 00:01:39,000 +You're going to use physical media protection. + +32 +00:01:39,000 --> 00:01:44,000 +You're going to use a variety, a whole variety and different kinds of physical controls out there. + +33 +00:01:44,000 --> 00:01:49,000 +So when you think of securing a network, you know, I gave this example, I know I'm sound like a broken + +34 +00:01:49,000 --> 00:01:54,000 +record, but if I can walk into the network and pick up your data and walk back out, you really don't + +35 +00:01:54,000 --> 00:01:56,000 +have much security, right? + +36 +00:01:56,000 --> 00:02:01,000 +I don't care what it is because a hacker, bad people, they're just not going to try to break into + +37 +00:02:01,000 --> 00:02:03,000 +your organization one way. + +38 +00:02:03,000 --> 00:02:05,000 +They're going to use multiple ways. + +39 +00:02:05,000 --> 00:02:10,000 +For example, if I can't break through your firewall because this device is updated. + +40 +00:02:12,000 --> 00:02:15,000 +I'll just try to call a user and ask them for the data. + +41 +00:02:15,000 --> 00:02:18,000 +They already have access to the data, they can email it to me. + +42 +00:02:18,000 --> 00:02:23,000 +I defeated all your security users, or people that are known as some of the weakest link in security. + +43 +00:02:23,000 --> 00:02:24,000 +That's what we have to train them. + +44 +00:02:24,000 --> 00:02:30,000 +Well, if that doesn't, if I can't get to a user, uh, nobody's giving me the data. + +45 +00:02:30,000 --> 00:02:32,000 +I can't get through your firewall. + +46 +00:02:33,000 --> 00:02:37,000 +I'll just wait till the night everybody goes home or break into your office and steal all your data. + +47 +00:02:37,000 --> 00:02:41,000 +That way I'll take up the whole server, just walk back out, you see why you need this multi-layered + +48 +00:02:41,000 --> 00:02:42,000 +approach. + +49 +00:02:42,000 --> 00:02:44,000 +So this is known as defense in depth. + +50 +00:02:45,000 --> 00:02:53,000 +And you want to make sure that all entry points is mitigated or assessed, and make sure that you have + +51 +00:02:53,000 --> 00:02:56,000 +the right control to protect your right data. + +52 +00:02:57,000 --> 00:03:01,000 +And I want to mention that when it comes to IT security, don't be single minded. + +53 +00:03:01,000 --> 00:03:05,000 +Don't be narrow focused way too often in IT security. + +54 +00:03:05,000 --> 00:03:10,000 +Are we focused only on one thing which is logical controls, technical controls. + +55 +00:03:10,000 --> 00:03:10,000 +Right. + +56 +00:03:10,000 --> 00:03:11,000 +Configuring this firewall. + +57 +00:03:11,000 --> 00:03:17,000 +Don't forget guys, it's where we don't see that they see in order to steal our information. + +58 +00:03:17,000 --> 00:03:22,000 +That's why in this course we're going to learn a variety of different ways to protect our network and + +59 +00:03:22,000 --> 00:03:23,000 +keep our data secure. + diff --git a/03 - Security Controls Categories and Types/004 Quick Quiz.html b/03 - Security Controls Categories and Types/004 Quick Quiz.html new file mode 100644 index 0000000000000000000000000000000000000000..3afdec3dc2286513dd927deb08f3fbac92f43125 --- /dev/null +++ b/03 - Security Controls Categories and Types/004 Quick Quiz.html @@ -0,0 +1,479 @@ + + + + + + + Quiz + + + + +
+
+

+

+
+
+
+ Score: 999 of + 999% +
+
Correct: 999
+
Incorrect: 999
+
+ +
+ + + + +
+ + + + diff --git a/04 - Threats/001 Threats Motivation OB 2.1.mp4 b/04 - Threats/001 Threats Motivation OB 2.1.mp4 new file mode 100644 index 0000000000000000000000000000000000000000..eda1dc8af3e5721b65fec833b38d5606bbf96dd5 --- /dev/null +++ b/04 - Threats/001 Threats Motivation OB 2.1.mp4 @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:9356fb1da896565f0c255d84da13296f4335204cfa11175e0889fcb7f67e1b72 +size 261867505 diff --git a/04 - Threats/001 Threats Motivation OB 2.1_en.srt b/04 - Threats/001 Threats Motivation OB 2.1_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..f8baf28b62726af2bff35bcc3686c54b6a802366 --- /dev/null +++ b/04 - Threats/001 Threats Motivation OB 2.1_en.srt @@ -0,0 +1,384 @@ +1 +00:00:00,000 --> 00:00:04,000 +One of the questions you really have to ask yourself is, why are they coming after me? + +2 +00:00:04,000 --> 00:00:06,000 +Why are they breaking into my network? + +3 +00:00:06,000 --> 00:00:07,000 +My network is small. + +4 +00:00:07,000 --> 00:00:09,000 +Do I have something that they want? + +5 +00:00:09,000 --> 00:00:15,000 +Many organizations, sometimes even nonprofit organizations, are hit with particular attacks. + +6 +00:00:15,000 --> 00:00:17,000 +And they left themselves asking, well, why are they coming after us? + +7 +00:00:17,000 --> 00:00:19,000 +We don't have much data. + +8 +00:00:19,000 --> 00:00:22,000 +We don't have much money, if any money at all. + +9 +00:00:22,000 --> 00:00:23,000 +Why are we being attacked? + +10 +00:00:23,000 --> 00:00:26,000 +Maybe because they're being attacked for a political gain. + +11 +00:00:26,000 --> 00:00:30,000 +Maybe people just don't like what that nonprofit is doing or what they support. + +12 +00:00:31,000 --> 00:00:38,000 +You see, when you most you see when most people think of a motivation for these particular threats, + +13 +00:00:38,000 --> 00:00:40,000 +they're thinking generally of. + +14 +00:00:40,000 --> 00:00:45,000 +The last thing that I have on my list here in this slide is ten of them, basically is just for financial + +15 +00:00:45,000 --> 00:00:46,000 +gains. + +16 +00:00:46,000 --> 00:00:49,000 +But there's a lot more than just financial gains. + +17 +00:00:49,000 --> 00:00:56,000 +So one of the most common things that people do, one of the most common motivations for attacks against + +18 +00:00:56,000 --> 00:01:02,000 +your company, is basically stealing data from the target, taking taking the data right out of the + +19 +00:01:02,000 --> 00:01:07,000 +organization, maybe by using some kind of ransomware or backdoor attacks. + +20 +00:01:07,000 --> 00:01:11,000 +Another one is going to be espionage, just spying on what you're doing. + +21 +00:01:11,000 --> 00:01:13,000 +They're not manipulating or changing the information. + +22 +00:01:13,000 --> 00:01:16,000 +They're just basically spying on your information. + +23 +00:01:16,000 --> 00:01:21,000 +This is famous for when a nation states do this to each other. + +24 +00:01:21,000 --> 00:01:26,000 +So, for example, North Korea may try to break into the United States government to see what kind of + +25 +00:01:26,000 --> 00:01:28,000 +weapons we are developing, and vice versa. + +26 +00:01:28,000 --> 00:01:31,000 +Other governments will do it to other governments also. + +27 +00:01:31,000 --> 00:01:33,000 +You're also going to have service disruptions. + +28 +00:01:33,000 --> 00:01:38,000 +So for example, DDoS distributed denial of service attacks. + +29 +00:01:38,000 --> 00:01:40,000 +These are going to be attacks that you can. + +30 +00:01:41,000 --> 00:01:49,000 +Spin up all kinds of bots on the internet, and then load up these bots on a particular web server. + +31 +00:01:49,000 --> 00:01:54,000 +In other words, generates so much traffic to a particular web server that the web server goes offline. + +32 +00:01:54,000 --> 00:01:59,000 +This disrupts the service of that website to other particular users. + +33 +00:01:59,000 --> 00:02:03,000 +Hacktivists may do this in order to promote a political agenda. + +34 +00:02:03,000 --> 00:02:11,000 +For example, if hacktivists believes that what this organization is doing is injust to their beliefs, + +35 +00:02:11,000 --> 00:02:15,000 +they may just shut that entire website off by sending it a whole bunch of traffic. + +36 +00:02:15,000 --> 00:02:21,000 +Not unheard of as famous hacker group anonymous has done this quite a lot to different government agencies. + +37 +00:02:21,000 --> 00:02:22,000 +Blackmail. + +38 +00:02:23,000 --> 00:02:25,000 +This is common with ransomware. + +39 +00:02:25,000 --> 00:02:29,000 +So what they do here is that they will steal your data. + +40 +00:02:29,000 --> 00:02:32,000 +They're going to hold on to it unless you pay that demand. + +41 +00:02:33,000 --> 00:02:38,000 +200,000 300,000 for small people may be a couple hundred bucks, couple thousand dollars. + +42 +00:02:38,000 --> 00:02:42,000 +Unless you pay that demand, they're going to release your data to the public. + +43 +00:02:42,000 --> 00:02:45,000 +So they're holding you ransom. + +44 +00:02:45,000 --> 00:02:46,000 +They're holding you blackmail. + +45 +00:02:46,000 --> 00:02:48,000 +So this is a form of blackmail. + +46 +00:02:49,000 --> 00:02:50,000 +Okay. + +47 +00:02:50,000 --> 00:02:52,000 +The others I have here is some kind of political belief. + +48 +00:02:54,000 --> 00:02:58,000 +Especially hacktivists, has a political belief, has a political agenda. + +49 +00:02:58,000 --> 00:03:01,000 +They don't support what the government is doing here. + +50 +00:03:01,000 --> 00:03:07,000 +They may shut down a government website, uh, they may deface the website, corrupt a particular website, + +51 +00:03:07,000 --> 00:03:11,000 +all going to be with political beliefs, ethical. + +52 +00:03:11,000 --> 00:03:16,000 +Some people believe that what they're doing is ethically correct. + +53 +00:03:16,000 --> 00:03:20,000 +They consider themselves a whistleblower or white hat hacker. + +54 +00:03:20,000 --> 00:03:24,000 +For example, let's say you work in an organization today. + +55 +00:03:25,000 --> 00:03:26,000 +I cannot see you. + +56 +00:03:26,000 --> 00:03:32,000 +Let's say somebody works in an organization today, and they feel that what this organization is doing + +57 +00:03:32,000 --> 00:03:37,000 +is illegal or bad for the public, even though it might be legal in the country's law. + +58 +00:03:37,000 --> 00:03:44,000 +So what you do argue somebody else, what somebody else does is that then they do bad things. + +59 +00:03:44,000 --> 00:03:45,000 +They corrupt the data. + +60 +00:03:45,000 --> 00:03:48,000 +They release the data, they try to punish the organization. + +61 +00:03:48,000 --> 00:03:53,000 +So what they feel is technically, in their mind, ethical revenge. + +62 +00:03:53,000 --> 00:03:57,000 +Okay, disgruntled employees will do this. + +63 +00:03:57,000 --> 00:03:58,000 +So revenge is this. + +64 +00:03:58,000 --> 00:04:03,000 +Let's say you work for an organization and for some reason they treat you bad. + +65 +00:04:03,000 --> 00:04:05,000 +They didn't send you that last paycheck. + +66 +00:04:05,000 --> 00:04:07,000 +They owe you a bunch of money. + +67 +00:04:07,000 --> 00:04:09,000 +They did bad things to you, don't support. + +68 +00:04:09,000 --> 00:04:15,000 +So what you do is because you probably still had logins, or even if you were fired and your login still + +69 +00:04:15,000 --> 00:04:21,000 +worked, you may go and corrupt their data, expose their information would be revenge, disruption + +70 +00:04:21,000 --> 00:04:22,000 +and chaos. + +71 +00:04:22,000 --> 00:04:25,000 +Some people are just motivated. + +72 +00:04:25,000 --> 00:04:31,000 +They don't have really any agenda other than chaos in a. + +73 +00:04:31,000 --> 00:04:34,000 +I'm not sure if you guys ever saw Batman. + +74 +00:04:34,000 --> 00:04:38,000 +Uh, the one with the Joker, the Dark Knight. + +75 +00:04:38,000 --> 00:04:39,000 +Really good movie. + +76 +00:04:39,000 --> 00:04:40,000 +You should watch that. + +77 +00:04:40,000 --> 00:04:44,000 +So in The Dark Knight, Alfred, uh, acts as bad. + +78 +00:04:44,000 --> 00:04:46,000 +Uh, Batman is asking for. + +79 +00:04:46,000 --> 00:04:47,000 +Why is the Joker doing this? + +80 +00:04:47,000 --> 00:04:50,000 +You know, why is he killing people and creating chaos? + +81 +00:04:50,000 --> 00:04:57,000 +And the gist of it is because there are just some people that prefers to watch the world burn. + +82 +00:04:57,000 --> 00:05:05,000 +There are some people out there that their only motivation is the dissatisfaction and unhappiness of + +83 +00:05:05,000 --> 00:05:06,000 +others. + +84 +00:05:06,000 --> 00:05:07,000 +All right. + +85 +00:05:07,000 --> 00:05:08,000 +This is how we secure against. + +86 +00:05:08,000 --> 00:05:13,000 +And there's quite a lot of people and a lot of attackers that you're going to encounter like this. + +87 +00:05:13,000 --> 00:05:18,000 +In other words, there's no real motive other than destruction in their path. + +88 +00:05:18,000 --> 00:05:20,000 +The next one up I have is war. + +89 +00:05:20,000 --> 00:05:24,000 +Now, this is going to be mostly driven by nation states, okay? + +90 +00:05:24,000 --> 00:05:30,000 +Their motivation is to produce all kinds of warfare between organizations. + +91 +00:05:30,000 --> 00:05:31,000 +Okay. + +92 +00:05:31,000 --> 00:05:32,000 +So here we go guys. + +93 +00:05:32,000 --> 00:05:34,000 +Quite a lot of motivations that are out there. + +94 +00:05:34,000 --> 00:05:42,000 +And as you can see there are many, many motivations that these hackers, these bad people will have + +95 +00:05:42,000 --> 00:05:43,000 +towards your organization. + +96 +00:05:43,000 --> 00:05:47,000 +So just keep these motivations in mind so you can secure against them. + diff --git a/04 - Threats/002 Threats OB 2.1.mp4 b/04 - Threats/002 Threats OB 2.1.mp4 new file mode 100644 index 0000000000000000000000000000000000000000..640e2cf16bb5dbef798821fb87cacdeef6f30b2d --- /dev/null +++ b/04 - Threats/002 Threats OB 2.1.mp4 @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:be8e9e504db5dc386bf6c68bbfb037a2e6b0d1fd08e4110f2eae100ceff30961 +size 85913803 diff --git a/04 - Threats/002 Threats OB 2.1_en.srt b/04 - Threats/002 Threats OB 2.1_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..72d978192380bf4b67e1e93142ce9ac9dfc627e5 --- /dev/null +++ b/04 - Threats/002 Threats OB 2.1_en.srt @@ -0,0 +1,116 @@ +1 +00:00:00,000 --> 00:00:01,000 +When you think of it. + +2 +00:00:01,000 --> 00:00:01,000 +Security. + +3 +00:00:01,000 --> 00:00:08,000 +You have to think of all the different threats that you're protecting your network from, all the safeguards + +4 +00:00:08,000 --> 00:00:15,000 +that we implement from cameras, firewall, security guards, intrusion detection system, anti-malware, + +5 +00:00:15,000 --> 00:00:18,000 +and all the other controls that we're going to apply. + +6 +00:00:18,000 --> 00:00:22,000 +The question is, who are we applying it for? + +7 +00:00:22,000 --> 00:00:24,000 +Who are we securing it against? + +8 +00:00:24,000 --> 00:00:28,000 +Who exactly are these threats that is trying to take us out? + +9 +00:00:28,000 --> 00:00:33,000 +So in this section, we're going to go through a good variety of different threats that we should be + +10 +00:00:33,000 --> 00:00:35,000 +worried about or that we should be protecting against. + +11 +00:00:35,000 --> 00:00:41,000 +Now, I do have in this video, I do have a list of some of the threats here that we're going to be + +12 +00:00:41,000 --> 00:00:48,000 +talking about in this particular section, things such as a nation state, unskilled attacker, hacktivists, + +13 +00:00:48,000 --> 00:00:51,000 +insider threat, organized crime, and shadow it. + +14 +00:00:51,000 --> 00:00:54,000 +Now these are going to be some of the terms you're going to want to know for your exam, as you will + +15 +00:00:54,000 --> 00:00:55,000 +see questions on them. + +16 +00:00:55,000 --> 00:00:57,000 +And I'll get more into them. + +17 +00:00:58,000 --> 00:01:00,000 +But you got to remember something guys. + +18 +00:01:00,000 --> 00:01:08,000 +All of the configuration, all of the policies we write, all of the devices we purchase or the software + +19 +00:01:08,000 --> 00:01:14,000 +we purchase, all of the the times we spend analyzing, analyzing log files and looking for potential + +20 +00:01:14,000 --> 00:01:15,000 +intrusions. + +21 +00:01:15,000 --> 00:01:24,000 +It's from these folks, people, processes and software that we're protecting against. + +22 +00:01:24,000 --> 00:01:27,000 +So in the next comment section, understand their motives. + +23 +00:01:27,000 --> 00:01:29,000 +Why you know, why are they doing this? + +24 +00:01:29,000 --> 00:01:31,000 +What is it that they're going to get out of this? + +25 +00:01:31,000 --> 00:01:33,000 +And not all of them are about money. + +26 +00:01:33,000 --> 00:01:36,000 +In fact, something like an unskilled attacker may not even know they're doing it. + +27 +00:01:37,000 --> 00:01:41,000 +So understand who they are and how we can protect against them. + +28 +00:01:41,000 --> 00:01:46,000 +So let's get into the next set of videos that's going to describe more of their motivations, why they're + +29 +00:01:46,000 --> 00:01:50,000 +doing it, and more in depth on who exactly these folks are. + diff --git a/04 - Threats/003 Attributes of Actors OB 2.1.mp4 b/04 - Threats/003 Attributes of Actors OB 2.1.mp4 new file mode 100644 index 0000000000000000000000000000000000000000..bf16687ac11ec5b3ef7679a0430b340d0e8065d8 --- /dev/null +++ b/04 - Threats/003 Attributes of Actors OB 2.1.mp4 @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:46948d39c39a106ebe46bc8cf873d5c2a89ccd400e35ea34a26fbc157d5c6b38 +size 177327854 diff --git a/04 - Threats/003 Attributes of Actors OB 2.1_en.srt b/04 - Threats/003 Attributes of Actors OB 2.1_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..9daf0e5545096467dabfcbb463a06c7572c3f7b5 --- /dev/null +++ b/04 - Threats/003 Attributes of Actors OB 2.1_en.srt @@ -0,0 +1,272 @@ +1 +00:00:00,000 --> 00:00:05,000 +When it comes to mitigating threats against your network, you have to understand who are you fighting + +2 +00:00:05,000 --> 00:00:07,000 +against and who are you protecting against? + +3 +00:00:07,000 --> 00:00:12,000 +There are a couple of attributes we should know about all particular threats, whether it's a nation + +4 +00:00:12,000 --> 00:00:15,000 +state, unskilled user, or insider threat. + +5 +00:00:15,000 --> 00:00:16,000 +Shadow it. + +6 +00:00:16,000 --> 00:00:21,000 +Whoever it is, know these attributes and understand these attributes about these particular threats. + +7 +00:00:21,000 --> 00:00:23,000 +Let's take a look at what the attributes are. + +8 +00:00:24,000 --> 00:00:29,000 +The first one up I have is are these threats threats internal or external. + +9 +00:00:29,000 --> 00:00:32,000 +The second one would be how much money do they have? + +10 +00:00:32,000 --> 00:00:40,000 +How much resources can they put in to attacking you, stealing your resources or damaging your network? + +11 +00:00:40,000 --> 00:00:43,000 +And then of course, how sophisticated are they? + +12 +00:00:43,000 --> 00:00:45,000 +Are they very sophisticated? + +13 +00:00:45,000 --> 00:00:46,000 +Are they unskilled? + +14 +00:00:46,000 --> 00:00:49,000 +Are they highly skilled and will develop new skills? + +15 +00:00:49,000 --> 00:00:51,000 +So let's get more into this. + +16 +00:00:51,000 --> 00:00:55,000 +The first thing that I'm going to worry about when it comes to threats is going to be, are they in + +17 +00:00:55,000 --> 00:00:56,000 +my network? + +18 +00:00:56,000 --> 00:00:58,000 +Are they outside my network? + +19 +00:00:58,000 --> 00:01:03,000 +For example, Insider Threat and Insider Threat is basically someone working inside of your network + +20 +00:01:03,000 --> 00:01:05,000 +right now that has malicious intent. + +21 +00:01:05,000 --> 00:01:12,000 +This is going to be someone that will probably purposely steal your information, destroy your network. + +22 +00:01:13,000 --> 00:01:19,000 +Easy things like just deleting files, corrupting files, giving away files to competitors, and so + +23 +00:01:19,000 --> 00:01:19,000 +on. + +24 +00:01:19,000 --> 00:01:21,000 +This is a really important one. + +25 +00:01:21,000 --> 00:01:28,000 +It's hard as hell to stop insider threats because they already have access to the resources in your + +26 +00:01:28,000 --> 00:01:28,000 +network. + +27 +00:01:28,000 --> 00:01:33,000 +It's not like they have to break through this all mighty powerful sonicwall. + +28 +00:01:33,000 --> 00:01:35,000 +They're already inside of the Sonicwall. + +29 +00:01:35,000 --> 00:01:40,000 +They're already in the network versus an outsider threat such as a nation state. + +30 +00:01:40,000 --> 00:01:42,000 +Now outsider threats. + +31 +00:01:42,000 --> 00:01:46,000 +They have to get past all your amazing security devices. + +32 +00:01:46,000 --> 00:01:49,000 +So understand, are they internal or are they external? + +33 +00:01:50,000 --> 00:01:54,000 +The next thing you're going to want to worry about is how much funds do they have now? + +34 +00:01:54,000 --> 00:02:02,000 +Something like an unskilled attacker, somebody that is not too skilled, they don't write their own + +35 +00:02:02,000 --> 00:02:03,000 +scripts. + +36 +00:02:03,000 --> 00:02:05,000 +They're not versatile in different codes. + +37 +00:02:05,000 --> 00:02:07,000 +Maybe someone that just doesn't have a lot of money. + +38 +00:02:07,000 --> 00:02:10,000 +So they're going to look for free tools and utilities. + +39 +00:02:10,000 --> 00:02:13,000 +They wouldn't be able to develop their own tools and utility. + +40 +00:02:13,000 --> 00:02:15,000 +So this is going to be how much money they have. + +41 +00:02:15,000 --> 00:02:21,000 +Nation states, states that are, I should say, countries that are against your country. + +42 +00:02:21,000 --> 00:02:23,000 +In the United States, you may worry about North Korea. + +43 +00:02:23,000 --> 00:02:24,000 +They have a ton of resources. + +44 +00:02:24,000 --> 00:02:26,000 +It's an entire government funding it. + +45 +00:02:26,000 --> 00:02:32,000 +And for that reason, they probably have unlimited funds compared to other particular threats that just + +46 +00:02:32,000 --> 00:02:33,000 +doesn't have it. + +47 +00:02:34,000 --> 00:02:39,000 +The other thing is the level of sophistication, their capabilities. + +48 +00:02:40,000 --> 00:02:42,000 +Take, for example, a nation state. + +49 +00:02:42,000 --> 00:02:44,000 +Somebody like a country like North Korea. + +50 +00:02:44,000 --> 00:02:55,000 +They can pour tons of money and train tons of people in order to develop new viruses, malware, uh, + +51 +00:02:55,000 --> 00:02:59,000 +tools that can infiltrate into organizations that hasn't even been detected. + +52 +00:02:59,000 --> 00:03:00,000 +Think about this. + +53 +00:03:00,000 --> 00:03:07,000 +If I write a virus right now that no one knows exists, and I sent it to all of you guys, and because + +54 +00:03:07,000 --> 00:03:12,000 +you know me and you open my email and you're going to get yourself infected, no antivirus is going + +55 +00:03:12,000 --> 00:03:15,000 +to pick it up because they just don't know it exists. + +56 +00:03:15,000 --> 00:03:16,000 +I made it just for you. + +57 +00:03:16,000 --> 00:03:23,000 +That's a high level of sophistication, and places like nation states and organized crimes will have + +58 +00:03:23,000 --> 00:03:25,000 +that versus unskilled attackers. + +59 +00:03:25,000 --> 00:03:27,000 +Probably not. + +60 +00:03:27,000 --> 00:03:30,000 +So I want you guys to keep that in mind. + +61 +00:03:30,000 --> 00:03:34,000 +You really have to understand who are you fighting against, internal and external? + +62 +00:03:34,000 --> 00:03:37,000 +How much money do they have and their level of sophistication? + +63 +00:03:37,000 --> 00:03:42,000 +So keep these things in mind as you look at the different threats that are out there. + +64 +00:03:42,000 --> 00:03:47,000 +Because if they're inside, they have a ton of money and they're well skilled, you're in a lot of trouble + +65 +00:03:47,000 --> 00:03:48,000 +anyway. + +66 +00:03:48,000 --> 00:03:49,000 +Make sure to understand these threats. + +67 +00:03:49,000 --> 00:03:51,000 +Make sure you understand these attributes. + +68 +00:03:51,000 --> 00:03:55,000 +If not, you might get attacked in your network without even knowing it. + diff --git a/04 - Threats/004 Nation-state OB 2.1.mp4 b/04 - Threats/004 Nation-state OB 2.1.mp4 new file mode 100644 index 0000000000000000000000000000000000000000..b74d78cf8dd8f46b0724f463b78e2103cf27b912 --- /dev/null +++ b/04 - Threats/004 Nation-state OB 2.1.mp4 @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:c033dc070aa0561c90846a52fc35d7c6020d595e3a754bf31debbd69090fcc3b +size 221588986 diff --git a/04 - Threats/004 Nation-state OB 2.1_en.srt b/04 - Threats/004 Nation-state OB 2.1_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..399051345e8e0fe7992fbada0d464812c15e9326 --- /dev/null +++ b/04 - Threats/004 Nation-state OB 2.1_en.srt @@ -0,0 +1,260 @@ +1 +00:00:00,000 --> 00:00:06,000 +The threat that keeps me up at night, that makes me the most worried is the one with unlimited money. + +2 +00:00:06,000 --> 00:00:12,000 +Crazy amount of sophistication and a highly driven motivation. + +3 +00:00:12,000 --> 00:00:18,000 +The one that just doesn't care about money, but cares about destruction, that cares about chaos. + +4 +00:00:18,000 --> 00:00:21,000 +That's the one that really worries me. + +5 +00:00:21,000 --> 00:00:26,000 +And that one really falls into the category of a nation state. + +6 +00:00:26,000 --> 00:00:29,000 +So nation state, what exactly is a nation state threat? + +7 +00:00:30,000 --> 00:00:36,000 +Now, a nation state threat is a country's government which can engage in or sponsor cyber activities. + +8 +00:00:36,000 --> 00:00:40,000 +And I'm talking cyber security or cyber warfare activities. + +9 +00:00:40,000 --> 00:00:45,000 +So in particular this is going to be classified as one country. + +10 +00:00:45,000 --> 00:00:47,000 +Don't support or don't like what this country is doing. + +11 +00:00:47,000 --> 00:00:55,000 +So they start to fund and hire and recruit people within their country to learn and develop all kinds + +12 +00:00:55,000 --> 00:01:02,000 +of hacking attempts or bad things, such as sophisticated software and hardware, to get back at the + +13 +00:01:02,000 --> 00:01:06,000 +other country, whether it's stealing that other country's information, manipulating that country's + +14 +00:01:06,000 --> 00:01:12,000 +public, or bringing down the country's critical infrastructure, now it can be all kinds of things, + +15 +00:01:12,000 --> 00:01:16,000 +like I said, from stealing espionage all the way to cyber warfare. + +16 +00:01:16,000 --> 00:01:21,000 +In other words, really battling out on the internet motivations can be things like political gains. + +17 +00:01:21,000 --> 00:01:27,000 +So maybe they support one political party over another, bringing down the country's economy, having + +18 +00:01:27,000 --> 00:01:29,000 +military advantages over others. + +19 +00:01:29,000 --> 00:01:32,000 +Now, one thing about nation states is the funding. + +20 +00:01:32,000 --> 00:01:40,000 +You see, when organizations go up against organizations in the world of competition, there's never, + +21 +00:01:40,000 --> 00:01:43,000 +or I should say, most times unlimited amount of money. + +22 +00:01:43,000 --> 00:01:48,000 +But when it comes to nation states, they pretty much run unlimited bankrolls. + +23 +00:01:48,000 --> 00:01:50,000 +And that's where this gets complicated. + +24 +00:01:50,000 --> 00:01:56,000 +This allows them to have a lot of resources all around the world. + +25 +00:01:56,000 --> 00:02:01,000 +Because you think about it, if North Korea, for example, wants to hire sophisticated programmers, + +26 +00:02:01,000 --> 00:02:06,000 +but the programmers are not in North Korea, North Korea can just set up fake companies and then hire + +27 +00:02:06,000 --> 00:02:07,000 +them in other countries. + +28 +00:02:07,000 --> 00:02:10,000 +Maybe those programmers are located in other countries. + +29 +00:02:10,000 --> 00:02:12,000 +And that's where this gets complex. + +30 +00:02:12,000 --> 00:02:20,000 +One time that I do want you guys to know for your exam is this firm that's called Aipt. + +31 +00:02:20,000 --> 00:02:21,000 +What exactly is that? + +32 +00:02:21,000 --> 00:02:23,000 +It's called an advanced persistent threat. + +33 +00:02:23,000 --> 00:02:32,000 +Somebody like Russia to the United States, uh, North Korea to the United States would be considered + +34 +00:02:32,000 --> 00:02:33,000 +an ATP. + +35 +00:02:33,000 --> 00:02:34,000 +Why? + +36 +00:02:34,000 --> 00:02:35,000 +Because they're advanced. + +37 +00:02:36,000 --> 00:02:38,000 +They're persistent, and they're a threat. + +38 +00:02:38,000 --> 00:02:46,000 +So Apts are these nation states will use ATP to infiltrate into the United States systems and particularly + +39 +00:02:46,000 --> 00:02:53,000 +government systems, and they will go in there and remain undetected within the company, within the, + +40 +00:02:53,000 --> 00:02:59,000 +for example, the Army's infrastructure for long periods of time, gathering all kinds of information + +41 +00:02:59,000 --> 00:03:01,000 +to launch all kinds of attacks. + +42 +00:03:02,000 --> 00:03:10,000 +Now, their operations is going to be highly complex, because remember, it's not just 1 or 2 people. + +43 +00:03:10,000 --> 00:03:13,000 +It's an entire basically government of another country. + +44 +00:03:13,000 --> 00:03:17,000 +So defending them is going to be very, very difficult. + +45 +00:03:17,000 --> 00:03:23,000 +It's going to require massive amounts of resources in all variety and types of control. + +46 +00:03:23,000 --> 00:03:26,000 +Now they're going to target a lot of things from the nation. + +47 +00:03:26,000 --> 00:03:31,000 +States can shut down infrastructures of other countries, such as shutting down power and light and + +48 +00:03:31,000 --> 00:03:34,000 +gas water supply. + +49 +00:03:34,000 --> 00:03:37,000 +They may attack government agencies and corporations within that country. + +50 +00:03:37,000 --> 00:03:43,000 +So you your your organization may not have anything to do generally with the government. + +51 +00:03:43,000 --> 00:03:47,000 +But all of a sudden, because your company is very big in this country, provides a lot of resources + +52 +00:03:47,000 --> 00:03:52,000 +to this country, now all of a sudden you're being attacked because you're part of that particular organization. + +53 +00:03:52,000 --> 00:03:54,000 +I'm sorry, particular country. + +54 +00:03:55,000 --> 00:04:03,000 +Now, it can be, of course, very substantial impact to the country, to the people causing all kinds + +55 +00:04:03,000 --> 00:04:10,000 +of service, uh, disruption, damage to the company's, uh, country's infrastructure and, of course, + +56 +00:04:10,000 --> 00:04:11,000 +release of information. + +57 +00:04:11,000 --> 00:04:14,000 +Nation states are very complex. + +58 +00:04:14,000 --> 00:04:16,000 +They're very hard to defend against. + +59 +00:04:17,000 --> 00:04:23,000 +The only which way you're going to win against a nation state is a massive, layered approach. + +60 +00:04:23,000 --> 00:04:30,000 +You can't have a single layer, whether that's the physical controls, administrative controls. + +61 +00:04:30,000 --> 00:04:33,000 +It's going to be, uh, technical controls. + +62 +00:04:33,000 --> 00:04:38,000 +Because you think about this when a hacker is trying to break, when a company, you know, when a nation + +63 +00:04:38,000 --> 00:04:44,000 +state is trying to break into your organization, your firewall can be amazing, like my firewall is. + +64 +00:04:44,000 --> 00:04:49,000 +But if they can just call users and have them click on a link, it'll bypass every single one of them. + +65 +00:04:49,000 --> 00:04:56,000 +So a massive, robust set of security controls is the only way to protect against nation states. + diff --git a/04 - Threats/005 Unskilled Attacker OB 2.1.mp4 b/04 - Threats/005 Unskilled Attacker OB 2.1.mp4 new file mode 100644 index 0000000000000000000000000000000000000000..bee5278e55e275dd34e12af30a525865754b162c --- /dev/null +++ b/04 - Threats/005 Unskilled Attacker OB 2.1.mp4 @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:1df1dbe162f0131b37efe56ec16875fb74ccc8608a6a0afa341f3e90a36d5f9c +size 81396401 diff --git a/04 - Threats/005 Unskilled Attacker OB 2.1_en.srt b/04 - Threats/005 Unskilled Attacker OB 2.1_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..4dd7a6f3378c1ab0ad652ae72b1b405b7eb4470a --- /dev/null +++ b/04 - Threats/005 Unskilled Attacker OB 2.1_en.srt @@ -0,0 +1,256 @@ +1 +00:00:00,000 --> 00:00:07,000 +There are some threats out there that may seem like they can't cause much problems to an organization, + +2 +00:00:07,000 --> 00:00:08,000 +but they actually could. + +3 +00:00:08,000 --> 00:00:12,000 +And that particular threat is really an unskilled attacker. + +4 +00:00:12,000 --> 00:00:14,000 +Who exactly is an unskilled attacker? + +5 +00:00:14,000 --> 00:00:15,000 +Well, it basically is who it says it is. + +6 +00:00:15,000 --> 00:00:20,000 +It's basically an individual with limited technical expertise in cyber attacks. + +7 +00:00:20,000 --> 00:00:23,000 +So let's say you want to be a hacker, right? + +8 +00:00:23,000 --> 00:00:24,000 +You're a bad person. + +9 +00:00:24,000 --> 00:00:27,000 +You want to be a hacker, but you don't have programming skills. + +10 +00:00:27,000 --> 00:00:34,000 +I've always told my certified ethical hacker students, if you want to be a good, uh, Red hat employees. + +11 +00:00:34,000 --> 00:00:38,000 +In other words, ethical hacker, you should know Bash and Python. + +12 +00:00:38,000 --> 00:00:41,000 +You don't need to know Python in depth Python scripting. + +13 +00:00:41,000 --> 00:00:42,000 +Not really Python programming. + +14 +00:00:43,000 --> 00:00:47,000 +So you can write, you can manipulate your own scripts. + +15 +00:00:47,000 --> 00:00:51,000 +And sometimes you have these kinds of folks that are bad. + +16 +00:00:51,000 --> 00:00:52,000 +They're on the bad side. + +17 +00:00:52,000 --> 00:00:59,000 +And these particular kind of, uh, bad hackers, I should say what they are, they're unskilled. + +18 +00:00:59,000 --> 00:01:01,000 +They don't have the programming skill. + +19 +00:01:01,000 --> 00:01:06,000 +They don't have the knowledge of Python, especially Python and Bash, because a lot of it is done there. + +20 +00:01:06,000 --> 00:01:13,000 +So what they do is they use other people's scripts, other people's tools. + +21 +00:01:13,000 --> 00:01:20,000 +Let's say I write a script to infiltrate a particular system, and you're you're one of these unskilled + +22 +00:01:20,000 --> 00:01:20,000 +attackers. + +23 +00:01:20,000 --> 00:01:22,000 +Well, you don't really know what the script does. + +24 +00:01:22,000 --> 00:01:23,000 +You can't really read it. + +25 +00:01:23,000 --> 00:01:27,000 +You can't really manipulate it, but at least you can run it if this is what you do. + +26 +00:01:27,000 --> 00:01:29,000 +You're known as a script kiddie. + +27 +00:01:29,000 --> 00:01:31,000 +The script script kiddies are just folks. + +28 +00:01:31,000 --> 00:01:38,000 +There's generally a kind of a bad time to, to to, um, Red hat ethical hackers. + +29 +00:01:38,000 --> 00:01:47,000 +But these script kiddies are generally folks that use pre-made tools and scripts made by others to exploit + +30 +00:01:47,000 --> 00:01:49,000 +different vulnerabilities that are out there. + +31 +00:01:49,000 --> 00:01:52,000 +For example, let's say there's a hole in this firewall. + +32 +00:01:52,000 --> 00:01:55,000 +I write a script to exploit it. + +33 +00:01:55,000 --> 00:02:00,000 +You don't know how to write scripts, so you start using my script to exploit particular sonic walls. + +34 +00:02:01,000 --> 00:02:06,000 +They don't have the ability to discover vulnerabilities or create their own tools. + +35 +00:02:06,000 --> 00:02:11,000 +Now you're thinking, all right, these guys, they can't be all that bad, right? + +36 +00:02:11,000 --> 00:02:12,000 +Well, they could. + +37 +00:02:12,000 --> 00:02:19,000 +And the reason is because, oh boy, there is a ton of tools in my course. + +38 +00:02:19,000 --> 00:02:21,000 +I give out a ton of tools. + +39 +00:02:21,000 --> 00:02:23,000 +20 gigs worth of tools. + +40 +00:02:23,000 --> 00:02:25,000 +Doesn't sound 20 gigs, doesn't sound like a lot. + +41 +00:02:25,000 --> 00:02:26,000 +But remember, some of these tools are only a megabyte. + +42 +00:02:27,000 --> 00:02:32,000 +So it's a lot, a lot of tools to exploit all kinds of things. + +43 +00:02:32,000 --> 00:02:34,000 +And these are tools that have been pre-made. + +44 +00:02:34,000 --> 00:02:39,000 +So you don't need to be a super skilled person. + +45 +00:02:39,000 --> 00:02:39,000 +Listen. + +46 +00:02:40,000 --> 00:02:42,000 +As a pen tester. + +47 +00:02:42,000 --> 00:02:46,000 +I have good Python scripting skills. + +48 +00:02:46,000 --> 00:02:48,000 +I have good Basque as my expert added. + +49 +00:02:48,000 --> 00:02:48,000 +No. + +50 +00:02:48,000 --> 00:02:49,000 +Can I write my own? + +51 +00:02:49,000 --> 00:02:50,000 +Yes. + +52 +00:02:50,000 --> 00:02:51,000 +Can I manipulate it? + +53 +00:02:51,000 --> 00:02:52,000 +Yes. + +54 +00:02:52,000 --> 00:02:58,000 +But in the last couple of years I haven't had a need to do any of that because there just so many tools + +55 +00:02:58,000 --> 00:03:03,000 +that are widespread that are out there, and you guys will be surprised to know how many systems are + +56 +00:03:03,000 --> 00:03:07,000 +not patched, they're poorly secured, that are still allow these tools to work. + +57 +00:03:07,000 --> 00:03:14,000 +It is absolutely amazing that these tools even work because there are so many systems that are not secure. + +58 +00:03:14,000 --> 00:03:15,000 +Basically, they're on patch. + +59 +00:03:16,000 --> 00:03:21,000 +Okay, so remember something don't think of on an unskilled attacker or somebody not to worry about. + +60 +00:03:21,000 --> 00:03:27,000 +It's somebody you really need to worry about because they are a variety and a large variety of tools + +61 +00:03:27,000 --> 00:03:28,000 +that are out there. + +62 +00:03:28,000 --> 00:03:33,000 +The moment vulnerabilities come out, somebody's going to make a tool that exploits it, pushes it out + +63 +00:03:33,000 --> 00:03:35,000 +in the internet, and you're going to be in trouble. + +64 +00:03:35,000 --> 00:03:37,000 +That's why you better keep your machines secure. + diff --git a/04 - Threats/006 Hacktivist OB 2.1.mp4 b/04 - Threats/006 Hacktivist OB 2.1.mp4 new file mode 100644 index 0000000000000000000000000000000000000000..e3420e9c95aa4789ea2c0cc3149de83e50152fd4 --- /dev/null +++ b/04 - Threats/006 Hacktivist OB 2.1.mp4 @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:57c61fc236fd3c6063691cf26a1547ee23d7f825433ceabf935e571d53e380ad +size 136335108 diff --git a/04 - Threats/006 Hacktivist OB 2.1_en.srt b/04 - Threats/006 Hacktivist OB 2.1_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..1810f5c1a36d5643bffd895f6c1d6332e27b7582 --- /dev/null +++ b/04 - Threats/006 Hacktivist OB 2.1_en.srt @@ -0,0 +1,196 @@ +1 +00:00:00,000 --> 00:00:06,000 +They are just some folks out there, or some groups and organizations out there that are just not really + +2 +00:00:06,000 --> 00:00:07,000 +motivated by money. + +3 +00:00:07,000 --> 00:00:12,000 +I know a lot of people are motivated by the almighty dollar, but you know what? + +4 +00:00:12,000 --> 00:00:13,000 +There are some people not. + +5 +00:00:13,000 --> 00:00:19,000 +There are some people out there or organizations that are motivated to cause disruptions to bring down + +6 +00:00:19,000 --> 00:00:20,000 +IT systems. + +7 +00:00:21,000 --> 00:00:25,000 +Because of a belief, generally a political belief. + +8 +00:00:25,000 --> 00:00:29,000 +And those folks are going to be known as a hacktivist. + +9 +00:00:29,000 --> 00:00:35,000 +This is someone that uses hacking techniques and digital tools to promote get this a political agenda. + +10 +00:00:35,000 --> 00:00:42,000 +Maybe they want to change a social norm in a particular in a particular country, or some kind of ideological + +11 +00:00:42,000 --> 00:00:43,000 +belief that they have. + +12 +00:00:43,000 --> 00:00:51,000 +Now, these folks are really dangerous because, you see, there's something about financial gains that + +13 +00:00:51,000 --> 00:00:56,000 +at some point the jails jail sentence may not be worth it. + +14 +00:00:56,000 --> 00:01:00,000 +Like you may say, well, I'm going to give you $1 million, but there's a 90% chance you get caught + +15 +00:01:00,000 --> 00:01:01,000 +and go to jail for the rest of your life. + +16 +00:01:01,000 --> 00:01:02,000 +Would you do it? + +17 +00:01:02,000 --> 00:01:05,000 +Probably not, because there's a high chance you go to jail. + +18 +00:01:05,000 --> 00:01:13,000 +But there's some things that people have a strong belief in that they don't mind giving up their lives + +19 +00:01:13,000 --> 00:01:13,000 +for. + +20 +00:01:13,000 --> 00:01:15,000 +They don't care about jail time. + +21 +00:01:15,000 --> 00:01:17,000 +And that's where hacktivism comes in. + +22 +00:01:17,000 --> 00:01:23,000 +You see, their hacktivists comes from the terms an activist, somebody that really believes in this + +23 +00:01:23,000 --> 00:01:28,000 +particular political ideology or some kind of agenda and hacking. + +24 +00:01:28,000 --> 00:01:30,000 +So basically they're using hacking. + +25 +00:01:30,000 --> 00:01:35,000 +They're basically an activist that's using hacking to promote whatever agenda that they have. + +26 +00:01:36,000 --> 00:01:43,000 +Now, I believe that hacktivism is very dangerous for that simple belief, because hacktivists, they + +27 +00:01:43,000 --> 00:01:46,000 +bring down your website without even thinking about the repercussions. + +28 +00:01:46,000 --> 00:01:54,000 +Even if they get caught, they're okay with it versus somebody, you know, a organized crime will try + +29 +00:01:54,000 --> 00:01:59,000 +to try not to get caught because their objective is just to get money out of you. + +30 +00:01:59,000 --> 00:02:01,000 +These folks, they don't care. + +31 +00:02:01,000 --> 00:02:03,000 +They want to bring you down. + +32 +00:02:03,000 --> 00:02:04,000 +They want to change that social norm. + +33 +00:02:04,000 --> 00:02:06,000 +They and they don't care if they go to jail. + +34 +00:02:06,000 --> 00:02:07,000 +They don't care if they die over it. + +35 +00:02:08,000 --> 00:02:11,000 +Hacktivists target websites, servers, other infrastructure. + +36 +00:02:11,000 --> 00:02:13,000 +Sometimes they can bring down an entire infrastructure. + +37 +00:02:14,000 --> 00:02:15,000 +They can. + +38 +00:02:15,000 --> 00:02:16,000 +They have a variety of actions. + +39 +00:02:16,000 --> 00:02:22,000 +They unauthorized access to systems, they may deface a website to deface, and a website is just going + +40 +00:02:22,000 --> 00:02:24,000 +to be going on and changing the website. + +41 +00:02:24,000 --> 00:02:30,000 +So they may put a banner across this web page that says this, this, this organization is bad. + +42 +00:02:30,000 --> 00:02:31,000 +They're not a service. + +43 +00:02:31,000 --> 00:02:33,000 +Releases of confidential information. + +44 +00:02:34,000 --> 00:02:40,000 +Now, the same way you would protect against things like a nation state with a variety of different + +45 +00:02:40,000 --> 00:02:44,000 +security controls, defense in depth, layered approaches is the same way you would protect against + +46 +00:02:44,000 --> 00:02:47,000 +hacktivists you don't know. + +47 +00:02:47,000 --> 00:02:54,000 +You may think that you're okay, but you don't know what people beliefs are about your company. + +48 +00:02:54,000 --> 00:02:58,000 +That's why you want to make sure you really protect all your machines. + +49 +00:02:58,000 --> 00:03:02,000 +Using a robust series of controls to keep your machines secure. + diff --git a/04 - Threats/007 Organized Crime OB 2.1.mp4 b/04 - Threats/007 Organized Crime OB 2.1.mp4 new file mode 100644 index 0000000000000000000000000000000000000000..006e0a836aa98d2f57c089f10443bd6f2bc30202 --- /dev/null +++ b/04 - Threats/007 Organized Crime OB 2.1.mp4 @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:fc74c9ded0655c5f5fcd4181cd8f4b3f56ed854eeca09acab380fc87442b2b14 +size 172047491 diff --git a/04 - Threats/007 Organized Crime OB 2.1_en.srt b/04 - Threats/007 Organized Crime OB 2.1_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..9721f043eb56697bebed10589cc2fe4f58a5431e --- /dev/null +++ b/04 - Threats/007 Organized Crime OB 2.1_en.srt @@ -0,0 +1,256 @@ +1 +00:00:00,000 --> 00:00:04,000 +One of my most favorite movies to watch is a movie called A Bronx Tale. + +2 +00:00:04,000 --> 00:00:07,000 +It's starred by Robert De Niro and Joe Pesci. + +3 +00:00:07,000 --> 00:00:10,000 +If you have never, I'm not going to give you much more than that, but if you've never seen it, you + +4 +00:00:10,000 --> 00:00:11,000 +got to see this film. + +5 +00:00:11,000 --> 00:00:12,000 +It's really good. + +6 +00:00:12,000 --> 00:00:16,000 +But the movie is about organized crime, and in this video I want to talk about organized crime, because + +7 +00:00:16,000 --> 00:00:20,000 +a lot of times when people think of organized crime, they're thinking of a mob. + +8 +00:00:20,000 --> 00:00:21,000 +The mobsters. + +9 +00:00:21,000 --> 00:00:22,000 +Right. + +10 +00:00:22,000 --> 00:00:29,000 +The Italian mobsters that you would see in all the movies from John Gotti, um, Al Capone and so on. + +11 +00:00:29,000 --> 00:00:33,000 +But what if I was to tell you, people think, well, maybe those things really don't exist anymore + +12 +00:00:33,000 --> 00:00:38,000 +because we really don't hear about organized crime anymore, such as the mobsters, but they actually + +13 +00:00:38,000 --> 00:00:41,000 +exist, and they're here today. + +14 +00:00:41,000 --> 00:00:48,000 +But unlike what you saw in the movies where they were doing racketeering, prostitution, selling drugs, + +15 +00:00:48,000 --> 00:00:50,000 +now they're not doing that anymore. + +16 +00:00:50,000 --> 00:00:55,000 +You see, back in the days we think of a mobster as a big guy with a big suit and a big machine gun + +17 +00:00:55,000 --> 00:00:56,000 +right now. + +18 +00:00:56,000 --> 00:00:58,000 +Now he's a geek that looks like me with glasses. + +19 +00:00:58,000 --> 00:01:03,000 +He's a little bit overweight and he wears a button, button up sometimes down shirt. + +20 +00:01:03,000 --> 00:01:07,000 +But he's a programmer and he's making sophisticated tools. + +21 +00:01:07,000 --> 00:01:13,000 +That's working in a hierarchical organization to create tools to infiltrate your data and steal your + +22 +00:01:13,000 --> 00:01:13,000 +money. + +23 +00:01:13,000 --> 00:01:15,000 +You got to remember something. + +24 +00:01:15,000 --> 00:01:16,000 +Where's the money now? + +25 +00:01:16,000 --> 00:01:17,000 +The money is digital. + +26 +00:01:17,000 --> 00:01:19,000 +The money is in your organization. + +27 +00:01:19,000 --> 00:01:24,000 +All those credit card information, bank accounts and data that they can now use steal from you and + +28 +00:01:24,000 --> 00:01:26,000 +then use against you to get money. + +29 +00:01:27,000 --> 00:01:31,000 +This brings us to this particular section, organized crime. + +30 +00:01:31,000 --> 00:01:32,000 +Who exactly is this? + +31 +00:01:32,000 --> 00:01:34,000 +Well, this is a group or operations. + +32 +00:01:34,000 --> 00:01:40,000 +These are going to be run by criminals who engage in illegal activities for profit. + +33 +00:01:40,000 --> 00:01:42,000 +Generally, they do this for profit. + +34 +00:01:42,000 --> 00:01:46,000 +They're not like a nation state where they look to bring down a government. + +35 +00:01:46,000 --> 00:01:49,000 +They're not looking to to push a political belief. + +36 +00:01:49,000 --> 00:01:55,000 +Their objective is just straight up money, uh, often involving sophisticated and coordinated attacks. + +37 +00:01:55,000 --> 00:01:59,000 +Now, one thing that you should understand is that mobsters have a very good hierarchy. + +38 +00:01:59,000 --> 00:02:06,000 +They have good planning, and they're going to use all kinds of technology to do what? + +39 +00:02:06,000 --> 00:02:08,000 +Steal money, financial fraud. + +40 +00:02:08,000 --> 00:02:09,000 +Steal identity. + +41 +00:02:09,000 --> 00:02:10,000 +Do ransomware. + +42 +00:02:10,000 --> 00:02:14,000 +Remember, ransomware is when they come in and they may encrypt your data, and then you have to pay + +43 +00:02:14,000 --> 00:02:15,000 +to get your data back. + +44 +00:02:15,000 --> 00:02:18,000 +They may sell your data in particular. + +45 +00:02:18,000 --> 00:02:22,000 +Now, the thing with organized crime is that they're well funded. + +46 +00:02:22,000 --> 00:02:28,000 +They're not just a guy in a basement, uh, writing tools. + +47 +00:02:28,000 --> 00:02:30,000 +This is going to be a hierarchical organization. + +48 +00:02:30,000 --> 00:02:34,000 +That's their objective is to steal money. + +49 +00:02:34,000 --> 00:02:37,000 +Their objective is to steal data. + +50 +00:02:38,000 --> 00:02:44,000 +They're going to have, uh, access to highly skilled professionals making advanced tools. + +51 +00:02:46,000 --> 00:02:53,000 +And they are going to target more than likely big organizations, financial institutions, retail businesses, + +52 +00:02:53,000 --> 00:02:56,000 +even highly wealthy individuals. + +53 +00:02:56,000 --> 00:03:01,000 +They're not going to come after a small business, not necessarily a small business, because they know + +54 +00:03:01,000 --> 00:03:06,000 +this business just doesn't have the resources to to pay them or things that they can steal. + +55 +00:03:06,000 --> 00:03:12,000 +But big businesses, if you're working things like banking, insurance, medical, government, you + +56 +00:03:12,000 --> 00:03:14,000 +have to be careful with organized crime. + +57 +00:03:15,000 --> 00:03:19,000 +They're going to steal your data, your money, all kinds of assets. + +58 +00:03:19,000 --> 00:03:21,000 +Now, how do you protect against them? + +59 +00:03:21,000 --> 00:03:28,000 +The same way you would protect against all the other threats massive robust controls, firewalls, IDs, + +60 +00:03:28,000 --> 00:03:33,000 +user training policies and procedures, variety of different physical things you're going to need in + +61 +00:03:33,000 --> 00:03:34,000 +order to protect against organized crime. + +62 +00:03:34,000 --> 00:03:38,000 +Because I don't think if they're coming, it's not if they're coming, it's when they're going to come + +63 +00:03:38,000 --> 00:03:39,000 +and get you. + +64 +00:03:39,000 --> 00:03:42,000 +So you better make sure your controls are good to keep your systems secure. + diff --git a/04 - Threats/008 Shadow IT OB 2.1.mp4 b/04 - Threats/008 Shadow IT OB 2.1.mp4 new file mode 100644 index 0000000000000000000000000000000000000000..7029a19b1ba55b1c3b8acd6c22b9b348b8791e7e --- /dev/null +++ b/04 - Threats/008 Shadow IT OB 2.1.mp4 @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:95c916c8160c4569ced9a86efac1a2d9f482862aaad43d2f8d514c3ff8d109c7 +size 167352590 diff --git a/04 - Threats/008 Shadow IT OB 2.1_en.srt b/04 - Threats/008 Shadow IT OB 2.1_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..808c3562cbe56e80023f03e99fb2e43bffe1de7d --- /dev/null +++ b/04 - Threats/008 Shadow IT OB 2.1_en.srt @@ -0,0 +1,316 @@ +1 +00:00:00,000 --> 00:00:08,000 +When working in an organization, a lot of people find that the restrictions on their machines may stop + +2 +00:00:08,000 --> 00:00:12,000 +them from doing tasks that they would like to get done, whether that task is something personal or + +3 +00:00:12,000 --> 00:00:14,000 +something related to the business. + +4 +00:00:14,000 --> 00:00:16,000 +Security is really good at something. + +5 +00:00:16,000 --> 00:00:19,000 +It's good at restricting folks from getting things done. + +6 +00:00:20,000 --> 00:00:27,000 +And because of the restrictions that we place on our systems to protect our systems, people start to + +7 +00:00:27,000 --> 00:00:32,000 +people within the organization starts to want to go around our restrictions. + +8 +00:00:32,000 --> 00:00:36,000 +And this brings me to a topic we're going to call Shadow it. + +9 +00:00:36,000 --> 00:00:44,000 +You see, shadow, it refers to information technology systems and solutions built and use inside the + +10 +00:00:44,000 --> 00:00:45,000 +organization. + +11 +00:00:45,000 --> 00:00:50,000 +Now listen to this without where is that without explicit organization approval. + +12 +00:00:50,000 --> 00:00:56,000 +So this is going to be different kinds of software, different kinds of hardware that's being deployed + +13 +00:00:56,000 --> 00:01:01,000 +and installed within an organization that wasn't done by the IT department. + +14 +00:01:01,000 --> 00:01:04,000 +And this is super dangerous. + +15 +00:01:04,000 --> 00:01:05,000 +Here's why. + +16 +00:01:06,000 --> 00:01:14,000 +Now, let's say, uh, Bob in the accounting department wants to send financial records through the + +17 +00:01:14,000 --> 00:01:19,000 +email, but the company has a policy that says you can't send financial records through emails. + +18 +00:01:19,000 --> 00:01:25,000 +So Bob installed some third party email client because he can't send it through the organization's email + +19 +00:01:25,000 --> 00:01:26,000 +client. + +20 +00:01:26,000 --> 00:01:30,000 +He installed some other third party software and then sends the records. + +21 +00:01:30,000 --> 00:01:36,000 +Here's the problem that email is not encrypted, and because it's not encrypted, the company's financial + +22 +00:01:36,000 --> 00:01:41,000 +secret data is out on the internet in absolute clear text. + +23 +00:01:41,000 --> 00:01:43,000 +This is a massive security breach. + +24 +00:01:43,000 --> 00:01:50,000 +In fact, that may even be against law, against the law in certain certain countries for certain laws, + +25 +00:01:50,000 --> 00:01:55,000 +if it's if it's something like medical information, medical records, and it's sent an unencrypted + +26 +00:01:55,000 --> 00:02:00,000 +format that's against a HIPAA compliance, but the person didn't know that this is where shadow it becomes + +27 +00:02:00,000 --> 00:02:02,000 +super dangerous. + +28 +00:02:02,000 --> 00:02:05,000 +Remember shadow, it includes a lot of things from the hardware, the software, even cloud services + +29 +00:02:05,000 --> 00:02:06,000 +that they're using. + +30 +00:02:06,000 --> 00:02:08,000 +What's the main risk? + +31 +00:02:08,000 --> 00:02:14,000 +Well, the lack of oversight and control, that software, that tool, that system that they put into + +32 +00:02:14,000 --> 00:02:15,000 +the network. + +33 +00:02:15,000 --> 00:02:20,000 +Was that system secure enough to meet the organization, policy and procedure? + +34 +00:02:20,000 --> 00:02:26,000 +Maybe there's a reason why the organization didn't use that, because it just doesn't meet our security + +35 +00:02:26,000 --> 00:02:29,000 +requirements in the organization. + +36 +00:02:29,000 --> 00:02:32,000 +Every user will not understand every law we follow. + +37 +00:02:32,000 --> 00:02:36,000 +They won't understand every regulation we follow, and they may not understand why we have a particular + +38 +00:02:36,000 --> 00:02:37,000 +policy. + +39 +00:02:37,000 --> 00:02:40,000 +So they try to go around it because they're not too sure. + +40 +00:02:40,000 --> 00:02:40,000 +You know why? + +41 +00:02:40,000 --> 00:02:42,000 +A lot of times people say, why is he doing that? + +42 +00:02:42,000 --> 00:02:44,000 +And they're not too sure why. + +43 +00:02:44,000 --> 00:02:47,000 +Maybe this is because the lack of training in the business. + +44 +00:02:47,000 --> 00:02:52,000 +But even if they're not sure why they shouldn't be installing their own things, one of the main things + +45 +00:02:52,000 --> 00:02:57,000 +systems and applications I mentioned is not vetted by them, may not meet organizational standards. + +46 +00:02:57,000 --> 00:03:00,000 +This can, of course, lead to data breaches. + +47 +00:03:00,000 --> 00:03:04,000 +Imagine he sends this email with all this company financial. + +48 +00:03:04,000 --> 00:03:07,000 +It's going to lead to a massive data breach if it's get caught. + +49 +00:03:07,000 --> 00:03:11,000 +Breaking certain compliances, certain regulations and introducing vulnerability. + +50 +00:03:11,000 --> 00:03:14,000 +What if they set up their own wireless and don't secure it? + +51 +00:03:14,000 --> 00:03:15,000 +Maybe they put us. + +52 +00:03:15,000 --> 00:03:17,000 +Maybe the wireless password is password. + +53 +00:03:17,000 --> 00:03:23,000 +Now somebody just put in a wireless access point in your network and the password is literally password. + +54 +00:03:23,000 --> 00:03:25,000 +Now anybody outside can break into your network. + +55 +00:03:25,000 --> 00:03:26,000 +Not good. + +56 +00:03:26,000 --> 00:03:31,000 +Now examples of this is going to be unauthorized, uh, cloud storage. + +57 +00:03:31,000 --> 00:03:34,000 +They may use a Dropbox account that they shouldn't be using. + +58 +00:03:34,000 --> 00:03:39,000 +They may be sharing files or installing systems or even messaging app that we don't support. + +59 +00:03:39,000 --> 00:03:40,000 +Shadow. + +60 +00:03:40,000 --> 00:03:41,000 +It is very real. + +61 +00:03:41,000 --> 00:03:44,000 +Users wants to get their work done. + +62 +00:03:44,000 --> 00:03:47,000 +Departmental heads want to get their work done. + +63 +00:03:47,000 --> 00:03:52,000 +One thing like I mentioned, security restricts the concept of security is restriction. + +64 +00:03:52,000 --> 00:03:55,000 +When I secure something, I'm restricting it from something else. + +65 +00:03:55,000 --> 00:04:00,000 +And because of that, people will try to go around it and that way. + +66 +00:04:00,000 --> 00:04:02,000 +And that's why this exists. + +67 +00:04:02,000 --> 00:04:09,000 +How do we stop this more robust control user awareness training to have people understand why there's + +68 +00:04:09,000 --> 00:04:10,000 +something there? + +69 +00:04:10,000 --> 00:04:12,000 +Why are you being restricted? + +70 +00:04:12,000 --> 00:04:19,000 +Good change management controls people just can't implement and changes consistent monitoring of your + +71 +00:04:19,000 --> 00:04:25,000 +internal systems to see pop ups of unauthorized software that you may not know that exists. + +72 +00:04:25,000 --> 00:04:26,000 +So don't think shadow. + +73 +00:04:26,000 --> 00:04:27,000 +It doesn't exist. + +74 +00:04:27,000 --> 00:04:31,000 +It exists in every single organization in some form or the other. + +75 +00:04:31,000 --> 00:04:35,000 +As you watch this video right now, I want you to keep in mind there's something in that organization, + +76 +00:04:35,000 --> 00:04:40,000 +whether it's a software, it's a hardware, a particular tool, some kind of services being used that + +77 +00:04:40,000 --> 00:04:43,000 +you don't know about that you could be losing data on right now. + +78 +00:04:43,000 --> 00:04:48,000 +So my best suggestion is to go out, monitor your systems right now before you get in a whole lot of + +79 +00:04:48,000 --> 00:04:49,000 +trouble. + diff --git a/04 - Threats/009 Threat Vectors and Attack Surfaces OB 2.2_en.srt b/04 - Threats/009 Threat Vectors and Attack Surfaces OB 2.2_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..3a7dd11bfa095cf997d732b71e114019332cda05 --- /dev/null +++ b/04 - Threats/009 Threat Vectors and Attack Surfaces OB 2.2_en.srt @@ -0,0 +1,560 @@ +1 +00:00:00,000 --> 00:00:07,000 +One of the things that's going to keep you awake every single night is, how are they going to attempt + +2 +00:00:07,000 --> 00:00:07,000 +to attack me? + +3 +00:00:07,000 --> 00:00:13,000 +How are all those threats going to attempt to get to my data, to steal my information, corrupt my + +4 +00:00:13,000 --> 00:00:16,000 +data, bring down my systems? + +5 +00:00:16,000 --> 00:00:18,000 +What surface or vector are they going to use? + +6 +00:00:18,000 --> 00:00:21,000 +So in this video I want to go through a bunch of them. + +7 +00:00:21,000 --> 00:00:26,000 +Now some of these are probably very familiar with as you probably experience a good set of them already. + +8 +00:00:26,000 --> 00:00:27,000 +Let's take a look. + +9 +00:00:27,000 --> 00:00:27,000 +So. + +10 +00:00:28,000 --> 00:00:36,000 +The number one way to get malware in particular, or viruses into an organization is simply to email + +11 +00:00:36,000 --> 00:00:38,000 +it phishing attempts. + +12 +00:00:38,000 --> 00:00:43,000 +So you get an email, it says, hey, uh, you've won a prize for this much money. + +13 +00:00:43,000 --> 00:00:44,000 +Click on this link, click on the link. + +14 +00:00:44,000 --> 00:00:48,000 +You're infected with all kinds of malware, ransomware, and so on. + +15 +00:00:48,000 --> 00:00:54,000 +Another one is going to be instant messaging or instant messaging is very famous. + +16 +00:00:54,000 --> 00:00:57,000 +I'm going to send you a text message with a particular link to malware. + +17 +00:00:57,000 --> 00:01:00,000 +You click on it, boom, you're infected. + +18 +00:01:01,000 --> 00:01:07,000 +Um, whether that is SMS, this is going to be submission, by the way, when I send it to you using, + +19 +00:01:07,000 --> 00:01:13,000 +uh, SMS, if I'm going to send it to you using some kind of instant messaging software like teams, + +20 +00:01:13,000 --> 00:01:17,000 +Microsoft Teams is a good example of that same thing. + +21 +00:01:17,000 --> 00:01:19,000 +I'm just going to send you a link. + +22 +00:01:19,000 --> 00:01:19,000 +You're going to click on it. + +23 +00:01:19,000 --> 00:01:24,000 +Some of these may even allow you to embed, for example, in instant messaging. + +24 +00:01:24,000 --> 00:01:28,000 +They may even allow you to embed software into the instant messenger for you to open up. + +25 +00:01:28,000 --> 00:01:30,000 +Another thing is that image base. + +26 +00:01:30,000 --> 00:01:34,000 +They can embed image codes into images. + +27 +00:01:34,000 --> 00:01:37,000 +They can embed malicious code into images. + +28 +00:01:37,000 --> 00:01:40,000 +You open up the image, boom, your system is infected. + +29 +00:01:40,000 --> 00:01:41,000 +How would you get the image? + +30 +00:01:41,000 --> 00:01:47,000 +You can download the images off of a particular website, or you can email it to you file based well + +31 +00:01:47,000 --> 00:01:52,000 +obviously malicious files because all, all, all malicious codes are going to come in some kind of + +32 +00:01:52,000 --> 00:01:53,000 +a file. + +33 +00:01:53,000 --> 00:01:58,000 +So they may send you like a zip file, in which case it's a type of a compressed file. + +34 +00:01:58,000 --> 00:02:00,000 +You open it, it may have an executable in there. + +35 +00:02:00,000 --> 00:02:01,000 +You click on it. + +36 +00:02:01,000 --> 00:02:03,000 +Your computer is dead. + +37 +00:02:03,000 --> 00:02:05,000 +They have infected your machine. + +38 +00:02:05,000 --> 00:02:08,000 +The other one here you have is going to be phishing attempts. + +39 +00:02:08,000 --> 00:02:13,000 +Phishing attempts is when they call you on the phone with voice calls. + +40 +00:02:13,000 --> 00:02:16,000 +I have we have a section coming up on social engineering. + +41 +00:02:16,000 --> 00:02:17,000 +We'll cover this a little bit later. + +42 +00:02:17,000 --> 00:02:18,000 +But this is the human aspect. + +43 +00:02:18,000 --> 00:02:23,000 +This is me calling you and attempting to get information out of you by just using my voice. + +44 +00:02:24,000 --> 00:02:31,000 +So we'll cover this later on in the course when we go more into social engineering removable devices. + +45 +00:02:31,000 --> 00:02:38,000 +If you ever see a USB stick on the ground somewhere, do not pick it up and plug it in because people + +46 +00:02:38,000 --> 00:02:40,000 +will be tempted to do that. + +47 +00:02:40,000 --> 00:02:47,000 +What they do is they embed malware onto these USB sticks and you just plugging it in, it then installs + +48 +00:02:47,000 --> 00:02:53,000 +a backdoor on your machine, and now they have full control of your entire machine so they can pass + +49 +00:02:53,000 --> 00:02:56,000 +the malware around on a USB stick. + +50 +00:02:56,000 --> 00:02:58,000 +Vulnerable software. + +51 +00:02:59,000 --> 00:03:00,000 +There are two kinds of software that we have. + +52 +00:03:00,000 --> 00:03:03,000 +What's called client and Agentless. + +53 +00:03:03,000 --> 00:03:08,000 +Clients offer software that is installed on your machine, basically some kind of executable that you + +54 +00:03:08,000 --> 00:03:13,000 +have to install an agent less software that you're just like an executable, like the calculator app. + +55 +00:03:13,000 --> 00:03:14,000 +There's nothing to install. + +56 +00:03:14,000 --> 00:03:17,000 +You just, uh, click, it opens up, closes. + +57 +00:03:17,000 --> 00:03:18,000 +Done. + +58 +00:03:18,000 --> 00:03:22,000 +Both of these can have embedded malware in them. + +59 +00:03:22,000 --> 00:03:27,000 +So whether you have to install it or not, you can still put malware in software. + +60 +00:03:28,000 --> 00:03:32,000 +Now unsupported systems and applications. + +61 +00:03:32,000 --> 00:03:36,000 +What happens when a software becomes outdated? + +62 +00:03:36,000 --> 00:03:39,000 +What happens when a software is no longer supported by the manufacturer? + +63 +00:03:39,000 --> 00:03:43,000 +Take, for example, Microsoft Windows 7. + +64 +00:03:43,000 --> 00:03:46,000 +Microsoft Windows 7 is not supported anymore. + +65 +00:03:46,000 --> 00:03:47,000 +No one should be using it. + +66 +00:03:47,000 --> 00:03:50,000 +If the if the operating system has reached its end of life. + +67 +00:03:50,000 --> 00:03:58,000 +Remember that for your exam, end of life or EOL end of life, if an operating system is meet the end + +68 +00:03:58,000 --> 00:04:02,000 +of life, it will not be supported with patches and updates anymore. + +69 +00:04:02,000 --> 00:04:04,000 +Software two Like Microsoft Office. + +70 +00:04:04,000 --> 00:04:08,000 +If somebody writes a vulnerability for that, Microsoft is not going to give you a patch or a fix for + +71 +00:04:08,000 --> 00:04:08,000 +it. + +72 +00:04:09,000 --> 00:04:14,000 +So you're basically using a system that's vulnerable to all kinds of attacks that people have made after + +73 +00:04:14,000 --> 00:04:17,000 +Microsoft has stopped supporting it. + +74 +00:04:17,000 --> 00:04:25,000 +On secure network wireless that is open wireless that has poor passwords, wired network where you have + +75 +00:04:25,000 --> 00:04:31,000 +just a switch on a floor and people can just plug in, plug in to your network without you even knowing. + +76 +00:04:31,000 --> 00:04:36,000 +Bluetooth Bluetooth is one of the most vulnerable things we'll talk about Bluetooth in the wireless + +77 +00:04:36,000 --> 00:04:38,000 +section security part of the course. + +78 +00:04:38,000 --> 00:04:40,000 +But remember something Bluetooth is not very secure. + +79 +00:04:40,000 --> 00:04:43,000 +Many times Bluetooth is not encrypted. + +80 +00:04:43,000 --> 00:04:44,000 +It's one of the biggest flaws. + +81 +00:04:45,000 --> 00:04:49,000 +Um, and people may just have it on their a variety of different Bluetooth attacks. + +82 +00:04:50,000 --> 00:04:51,000 +Open ports. + +83 +00:04:51,000 --> 00:04:52,000 +You do not want to have open ports. + +84 +00:04:52,000 --> 00:04:56,000 +The point of a firewall is to block the ports. + +85 +00:04:56,000 --> 00:05:00,000 +People may have ports 3389, which is a remote desktop port. + +86 +00:05:00,000 --> 00:05:04,000 +Ports such as uh 21 FTP not secure. + +87 +00:05:04,000 --> 00:05:08,000 +You want to make sure you close those open ports if not being used. + +88 +00:05:08,000 --> 00:05:12,000 +And in particularly you have to make sure the ports that are used are things that are secure like don't + +89 +00:05:12,000 --> 00:05:20,000 +use port 80, Http use port 80, port 443, which is SSL default credentials. + +90 +00:05:20,000 --> 00:05:23,000 +Way too often do I try to log into a system. + +91 +00:05:23,000 --> 00:05:27,000 +You know, you go go to somebody's house, you try to log into their router and the password is admin, + +92 +00:05:27,000 --> 00:05:30,000 +the username is admin admin admin or admin password something like that. + +93 +00:05:30,000 --> 00:05:32,000 +Or admin 123456. + +94 +00:05:32,000 --> 00:05:35,000 +Common thing default credentials are left on the device. + +95 +00:05:35,000 --> 00:05:39,000 +Nobody changes them now. + +96 +00:05:39,000 --> 00:05:41,000 +Supply chain. + +97 +00:05:41,000 --> 00:05:42,000 +You're going to deal with vendors. + +98 +00:05:42,000 --> 00:05:47,000 +Everybody in that I know of that manages system purchases things from outside. + +99 +00:05:47,000 --> 00:05:53,000 +We're going to be purchasing hardware and software if those vendors get infected, let's say Sonicwall. + +100 +00:05:53,000 --> 00:05:59,000 +Now Dell owns Sonicwall, let's say Dell was hacked and different kinds of malware was infected when + +101 +00:05:59,000 --> 00:06:00,000 +I buy this device. + +102 +00:06:00,000 --> 00:06:00,000 +Oh. + +103 +00:06:01,000 --> 00:06:02,000 +Great. + +104 +00:06:02,000 --> 00:06:04,000 +I got this great firewall plug into my organization. + +105 +00:06:04,000 --> 00:06:06,000 +Just infected my whole company. + +106 +00:06:06,000 --> 00:06:10,000 +We have to make sure that the supply chain we're using, the vendors that we're using secures their + +107 +00:06:10,000 --> 00:06:11,000 +network also. + +108 +00:06:11,000 --> 00:06:13,000 +So there's a couple of them. + +109 +00:06:13,000 --> 00:06:16,000 +First of all, the MSP a lot of companies uses MSPs. + +110 +00:06:16,000 --> 00:06:21,000 +Managed service providers are third party consultants outside your organization. + +111 +00:06:21,000 --> 00:06:24,000 +That comes into the organization and does work for you. + +112 +00:06:24,000 --> 00:06:27,000 +For example, they may manage your servers, they may manage your desktop. + +113 +00:06:27,000 --> 00:06:29,000 +Take, for example, a small medical office. + +114 +00:06:29,000 --> 00:06:33,000 +They're not going to have IT support staff because there's only 20 people working there, but they're + +115 +00:06:33,000 --> 00:06:39,000 +going to have an MSP if that MSP gets infected, if that MSP has malicious software already on their + +116 +00:06:39,000 --> 00:06:45,000 +network is going to infect that medical office, your vendors, if they get breached, remember the + +117 +00:06:45,000 --> 00:06:48,000 +vendor may be in your company such as Sonicwall. + +118 +00:06:48,000 --> 00:06:50,000 +They're already in my organization. + +119 +00:06:50,000 --> 00:06:54,000 +If this devices gets breached or they send me breach devices. + +120 +00:06:55,000 --> 00:06:56,000 +I'm already hacked, man. + +121 +00:06:56,000 --> 00:06:57,000 +I didn't even do anything. + +122 +00:06:57,000 --> 00:06:57,000 +I just plugged it in. + +123 +00:06:57,000 --> 00:06:58,000 +I'm hacked. + +124 +00:06:58,000 --> 00:06:59,000 +Suppliers. + +125 +00:06:59,000 --> 00:07:02,000 +Suppliers may be building products. + +126 +00:07:02,000 --> 00:07:07,000 +And of course, if the supplier, let's say Dell, is using a particular memory in these devices, the + +127 +00:07:07,000 --> 00:07:08,000 +supplier for Dell gets hacked. + +128 +00:07:08,000 --> 00:07:10,000 +The memory chips comes with the hack. + +129 +00:07:10,000 --> 00:07:12,000 +It infects the sonicwall then infects me. + +130 +00:07:12,000 --> 00:07:14,000 +Ripple effect now. + +131 +00:07:14,000 --> 00:07:18,000 +Okay, so there are many, many, many, many attacks. + +132 +00:07:18,000 --> 00:07:25,000 +Many, I should say different kinds of attacks, many kinds of threats, different threats. + +133 +00:07:25,000 --> 00:07:27,000 +And of course, many, as you saw here. + +134 +00:07:27,000 --> 00:07:32,000 +And these are not just all of them, but there are some of them ways that they're going to attack you. + +135 +00:07:32,000 --> 00:07:33,000 +Once again, how are we going to stop? + +136 +00:07:33,000 --> 00:07:40,000 +These things are robust security design, a robust security infrastructure, layered approach, different + +137 +00:07:40,000 --> 00:07:44,000 +kinds of controls, not just technical controls, but user controls. + +138 +00:07:44,000 --> 00:07:49,000 +For example, technical controls may stop a virus, but it wouldn't stop me from calling in and asking + +139 +00:07:49,000 --> 00:07:51,000 +your users for their passwords and data. + +140 +00:07:51,000 --> 00:07:57,000 +That's why a layered approach is the best way to stop lots of different attacks against your network. + diff --git a/04 - Threats/010 Quick Quiz.html b/04 - Threats/010 Quick Quiz.html new file mode 100644 index 0000000000000000000000000000000000000000..c6bf2ceb35d09a9a7a4657e238ff6ee0e0343b33 --- /dev/null +++ b/04 - Threats/010 Quick Quiz.html @@ -0,0 +1,479 @@ + + + + + + + Quiz + + + + +
+
+

+

+
+
+
+ Score: 999 of + 999% +
+
Correct: 999
+
Incorrect: 999
+
+ +
+ + + + +
+ + + + diff --git a/05 - Vulnerabilities/001 Vulnerabilities OB 2.3_en.srt b/05 - Vulnerabilities/001 Vulnerabilities OB 2.3_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..571331ae5bc867fcbb46ca246e16d8a1922ed004 --- /dev/null +++ b/05 - Vulnerabilities/001 Vulnerabilities OB 2.3_en.srt @@ -0,0 +1,144 @@ +1 +00:00:00,000 --> 00:00:02,000 +When it comes to it security. + +2 +00:00:02,000 --> 00:00:06,000 +The thing that keeps me up the most at night are vulnerabilities. + +3 +00:00:06,000 --> 00:00:12,000 +You see, vulnerabilities refer to a weakness in a system that can be exploited by a threat actor, + +4 +00:00:12,000 --> 00:00:17,000 +such as a hacker, to gain unauthorized access or perform really bad things to our systems. + +5 +00:00:17,000 --> 00:00:20,000 +You see, a vulnerability is basically a weakness in our system. + +6 +00:00:20,000 --> 00:00:25,000 +It's basically a hole in our system that the hacker comes through. + +7 +00:00:25,000 --> 00:00:31,000 +If you have vulnerabilities right now in your network, you could be getting hacked as we speak. + +8 +00:00:31,000 --> 00:00:35,000 +Maybe somebody is stealing your data as we're speaking right now. + +9 +00:00:36,000 --> 00:00:38,000 +Take for example, here's my firewall. + +10 +00:00:38,000 --> 00:00:42,000 +This firewall protects this entire network here at the school. + +11 +00:00:42,000 --> 00:00:49,000 +But if this firewall is misconfigured, for example, let's say whoever configured it left the password + +12 +00:00:49,000 --> 00:00:50,000 +is password. + +13 +00:00:50,000 --> 00:00:53,000 +Well, people can easily break in. + +14 +00:00:53,000 --> 00:00:58,000 +In fact, hackers can easily just guess the password as password, which is a pretty common default + +15 +00:00:58,000 --> 00:00:58,000 +password. + +16 +00:00:59,000 --> 00:01:03,000 +And take complete control of this device and be in my network. + +17 +00:01:03,000 --> 00:01:09,000 +If whoever configured the firewall had left things such as open ports that allow cleartext traffic, + +18 +00:01:09,000 --> 00:01:16,000 +such as just plain old port 80 or port 21, FTP and Http to come directly to the firewall. + +19 +00:01:16,000 --> 00:01:18,000 +Well then you know what happens now. + +20 +00:01:18,000 --> 00:01:19,000 +Data can be going around the internet. + +21 +00:01:19,000 --> 00:01:24,000 +Confidential data companies data can be going around the internet in clear text. + +22 +00:01:24,000 --> 00:01:26,000 +In other words, anybody can see it. + +23 +00:01:27,000 --> 00:01:30,000 +What happens if this device was never updated? + +24 +00:01:30,000 --> 00:01:31,000 +This device was never patched. + +25 +00:01:31,000 --> 00:01:36,000 +Then there could be a ton of vulnerabilities or holes in this particular device that could be exploited + +26 +00:01:36,000 --> 00:01:40,000 +for them to take complete control and be in my network remotely. + +27 +00:01:40,000 --> 00:01:41,000 +You see vulnerabilities. + +28 +00:01:41,000 --> 00:01:44,000 +Is that weakness in your network? + +29 +00:01:45,000 --> 00:01:51,000 +It's the thing I said that keeps me up at night, because there are weaknesses in our network that I + +30 +00:01:51,000 --> 00:01:53,000 +may not know about, I may not be aware of. + +31 +00:01:54,000 --> 00:01:58,000 +They may have something called a zero day vulnerability, but look at later. + +32 +00:01:58,000 --> 00:02:00,000 +They may have new kinds of attacks that are coming out right now. + +33 +00:02:01,000 --> 00:02:03,000 +That there is no fix for that. + +34 +00:02:03,000 --> 00:02:04,000 +I don't even know that exists. + +35 +00:02:04,000 --> 00:02:09,000 +So in this section, let's go through some different kind of vulnerabilities that can affect our network + +36 +00:02:09,000 --> 00:02:12,000 +and that you should be familiar with to protect your systems. + diff --git a/05 - Vulnerabilities/002 Memory injection and buffer overflows OB 2.3_en.srt b/05 - Vulnerabilities/002 Memory injection and buffer overflows OB 2.3_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..58549b807005ecc5d51fd965efa7406f82f5ac3a --- /dev/null +++ b/05 - Vulnerabilities/002 Memory injection and buffer overflows OB 2.3_en.srt @@ -0,0 +1,500 @@ +1 +00:00:00,000 --> 00:00:06,000 +Using any kind of a computer requires interacting with some kind of software, whether that's the operating + +2 +00:00:06,000 --> 00:00:12,000 +system itself, such as Windows or Mac OS, to some kind of application like Microsoft Word. + +3 +00:00:12,000 --> 00:00:15,000 +Uh, Chrome browser, a video game that you're playing. + +4 +00:00:15,000 --> 00:00:16,000 +It doesn't matter. + +5 +00:00:16,000 --> 00:00:21,000 +They're all applications and it doesn't matter the systems, whether it's my phone, it's a laptop, + +6 +00:00:21,000 --> 00:00:22,000 +it's a desktop. + +7 +00:00:22,000 --> 00:00:23,000 +It doesn't matter what it is. + +8 +00:00:23,000 --> 00:00:26,000 +They're all going to be using some kind of software. + +9 +00:00:26,000 --> 00:00:30,000 +Now software you got to remember something about software. + +10 +00:00:30,000 --> 00:00:34,000 +Software is executed in the CPU of the computer. + +11 +00:00:34,000 --> 00:00:39,000 +But there's a very, really important component of a computer where we store data. + +12 +00:00:39,000 --> 00:00:41,000 +And that's going to be a Ram, your memory. + +13 +00:00:41,000 --> 00:00:45,000 +So in this video I want to take a look at what's called memory injection. + +14 +00:00:45,000 --> 00:00:49,000 +Memory injection involves basically what it says it is. + +15 +00:00:49,000 --> 00:00:55,000 +It's about injecting malicious codes into the ram, into the memory of the actual machine. + +16 +00:00:55,000 --> 00:00:59,000 +And I want to take a look at one of the examples of this called buffer overflow. + +17 +00:00:59,000 --> 00:01:02,000 +And I'll show you an actual example of it in this video. + +18 +00:01:02,000 --> 00:01:03,000 +So let's get started. + +19 +00:01:04,000 --> 00:01:08,000 +So memory injection, what exactly is this kind of a vulnerability? + +20 +00:01:08,000 --> 00:01:08,000 +What? + +21 +00:01:08,000 --> 00:01:13,000 +A memory injection vulnerability is about inserting malicious codes into a program's memory. + +22 +00:01:13,000 --> 00:01:19,000 +The attacker leverages this vulnerability to allow them to execute all kinds of malicious codes against + +23 +00:01:19,000 --> 00:01:19,000 +your system. + +24 +00:01:19,000 --> 00:01:23,000 +When I show you the buffer overflow, and that's going to be one of the examples here, I'll show you + +25 +00:01:23,000 --> 00:01:24,000 +what I mean. + +26 +00:01:24,000 --> 00:01:30,000 +Common techniques included using shell scripts, a shell codes and different kinds of scripts and so + +27 +00:01:30,000 --> 00:01:30,000 +on. + +28 +00:01:30,000 --> 00:01:34,000 +Now the example here we're going to be taking a look at is a buffer overflow. + +29 +00:01:34,000 --> 00:01:37,000 +But before I get into this, let me explain a little bit more about this. + +30 +00:01:37,000 --> 00:01:44,000 +You see, any time an application opens up, the application will then take a part of Ram. + +31 +00:01:44,000 --> 00:01:49,000 +In other words, the programmers of the application is going to allocate a certain amount of memory + +32 +00:01:49,000 --> 00:01:51,000 +that the application needs. + +33 +00:01:51,000 --> 00:01:53,000 +So let's say you're writing an application ABC. + +34 +00:01:53,000 --> 00:02:00,000 +When application ABC executes it's going to tell the computer, hey, I need this much memory to function. + +35 +00:02:00,000 --> 00:02:03,000 +The computer checks and says, well, okay, you have that much. + +36 +00:02:03,000 --> 00:02:04,000 +We have this much memory. + +37 +00:02:04,000 --> 00:02:07,000 +I'm going to now allocate this memory for this application. + +38 +00:02:07,000 --> 00:02:08,000 +Remember this. + +39 +00:02:09,000 --> 00:02:14,000 +So the application is allocated a section of the Ram on the actual computer. + +40 +00:02:14,000 --> 00:02:17,000 +Now there is an attack here that I want to show you. + +41 +00:02:17,000 --> 00:02:20,000 +And that's going to be called a buffer overflow. + +42 +00:02:20,000 --> 00:02:21,000 +There is this mouse. + +43 +00:02:21,000 --> 00:02:21,000 +Here we go. + +44 +00:02:22,000 --> 00:02:27,000 +So a buffer overflow occurs when data that is meant to be stored in a buffer, which is a contiguous + +45 +00:02:27,000 --> 00:02:31,000 +block of computer memory, exceeds the buffer storage capacity. + +46 +00:02:31,000 --> 00:02:35,000 +This results in the adjacent memory allocations being overwritten. + +47 +00:02:35,000 --> 00:02:40,000 +I know that sounds like a lot of really important words that you can't understand yet, but it's really + +48 +00:02:40,000 --> 00:02:41,000 +simple here. + +49 +00:02:41,000 --> 00:02:46,000 +There I have it fully explained here, but it's best showing you okay. + +50 +00:02:46,000 --> 00:02:49,000 +It's best showing you with a link that I have here. + +51 +00:02:49,000 --> 00:02:54,000 +So if you guys type in this URL, you'll find the website that I'm about to show you because it's this + +52 +00:02:54,000 --> 00:02:56,000 +is complex all to understand. + +53 +00:02:56,000 --> 00:02:57,000 +It's it's complex. + +54 +00:02:57,000 --> 00:03:01,000 +It's easier for me just to show it to you with a nice diagram. + +55 +00:03:01,000 --> 00:03:06,000 +So let me exit out of this and we're going to go to this website. + +56 +00:03:06,000 --> 00:03:11,000 +So if you type in the URL that you see on the screen there, remember you have all the data. + +57 +00:03:11,000 --> 00:03:13,000 +Um, it should bring you to this website. + +58 +00:03:13,000 --> 00:03:15,000 +Now I want to show you guys something. + +59 +00:03:16,000 --> 00:03:19,000 +So this is an example of a buffer overflow attack. + +60 +00:03:19,000 --> 00:03:22,000 +And you'll get really to understand what it is. + +61 +00:03:22,000 --> 00:03:28,000 +So in this particular example imagine that you have a prom right. + +62 +00:03:28,000 --> 00:03:31,000 +It's a username and a password prompt. + +63 +00:03:31,000 --> 00:03:36,000 +So in the in the scenario that they're giving you the password prompt at the bottom, you know when + +64 +00:03:36,000 --> 00:03:39,000 +you type in your password you put a username, it's going to be another box for you to type in a password. + +65 +00:03:39,000 --> 00:03:44,000 +In that box the programmer has to allocate a certain amount of memory. + +66 +00:03:44,000 --> 00:03:46,000 +So let's see what happens here. + +67 +00:03:46,000 --> 00:03:52,000 +So for example a buffer for a login credential may be designed to expect a username and a password inputs + +68 +00:03:52,000 --> 00:03:53,000 +of eight bytes. + +69 +00:03:53,000 --> 00:03:59,000 +So what happens here is the application is expecting the password to be just a. + +70 +00:03:59,000 --> 00:04:00,000 +Now it's 0 to 7 which is eight. + +71 +00:04:00,000 --> 00:04:02,000 +They always start at zero. + +72 +00:04:02,000 --> 00:04:05,000 +So you notice the word password full eight bytes. + +73 +00:04:06,000 --> 00:04:13,000 +So in other words, the application is expecting eight bytes of data into this particular field. + +74 +00:04:13,000 --> 00:04:17,000 +But what happens if you type in ten bytes of data? + +75 +00:04:17,000 --> 00:04:18,000 +What happens? + +76 +00:04:18,000 --> 00:04:21,000 +So what happens when you do ten bytes of data? + +77 +00:04:21,000 --> 00:04:27,000 +What happens is the program may write the excessive data past the memory buffer boundary. + +78 +00:04:27,000 --> 00:04:29,000 +So what does that mean? + +79 +00:04:29,000 --> 00:04:32,000 +Well let's say the buffer memory was eight bytes. + +80 +00:04:32,000 --> 00:04:34,000 +So you put in ten things. + +81 +00:04:34,000 --> 00:04:35,000 +So what happened to this extra two. + +82 +00:04:35,000 --> 00:04:38,000 +What is extra two overflows the buffer. + +83 +00:04:38,000 --> 00:04:40,000 +In other words the buffer was eight. + +84 +00:04:40,000 --> 00:04:41,000 +But now you're outside of the buffer. + +85 +00:04:41,000 --> 00:04:46,000 +Now you're executing code that shouldn't have been executed. + +86 +00:04:46,000 --> 00:04:47,000 +Now what does this mean. + +87 +00:04:48,000 --> 00:04:58,000 +Well, all this means is that it's going to now allow all kinds of malicious execution against your + +88 +00:04:58,000 --> 00:04:59,000 +software. + +89 +00:04:59,000 --> 00:05:08,000 +You see, buffer overflows or buffer overflows is going to allow you to execute codes against different + +90 +00:05:08,000 --> 00:05:15,000 +forms of software you have installed on your phone, your operating system, your Microsoft Word application, + +91 +00:05:15,000 --> 00:05:16,000 +your video game that you're playing. + +92 +00:05:16,000 --> 00:05:21,000 +It doesn't matter what the software is, if it's software that is going to use a CPU and Ram, which + +93 +00:05:21,000 --> 00:05:27,000 +is all of them are subject to buffer overflows because it's with a buffer overflow that you can basically + +94 +00:05:27,000 --> 00:05:30,000 +execute malicious codes against software. + +95 +00:05:30,000 --> 00:05:31,000 +Well, what can you do? + +96 +00:05:31,000 --> 00:05:34,000 +Well, you might you might be able to steal data. + +97 +00:05:34,000 --> 00:05:37,000 +You might be able to manipulate data. + +98 +00:05:37,000 --> 00:05:41,000 +You might be able to cause a denial of service by bringing down the application. + +99 +00:05:41,000 --> 00:05:44,000 +So there's a lot of things you can do that are really bad. + +100 +00:05:44,000 --> 00:05:47,000 +If you're asking yourself, well, Andrew, how do I fix this? + +101 +00:05:47,000 --> 00:05:49,000 +How do I stop a buffer overflow from happening? + +102 +00:05:49,000 --> 00:05:52,000 +Because we don't want that when it comes to IT. + +103 +00:05:52,000 --> 00:05:54,000 +Security guys, it's probably not a realm. + +104 +00:05:55,000 --> 00:06:01,000 +Although we do detect these kinds of vulnerabilities generally by doing a vulnerability scan. + +105 +00:06:01,000 --> 00:06:02,000 +We'll talk more about that later. + +106 +00:06:02,000 --> 00:06:04,000 +What about a vulnerability scan. + +107 +00:06:04,000 --> 00:06:06,000 +So we're able to detect it. + +108 +00:06:06,000 --> 00:06:10,000 +But unless you're some kind of a programmer or a coder, you're not going to be able to fix it because + +109 +00:06:10,000 --> 00:06:13,000 +you have to go in there and fix how the buffer allocations are done. + +110 +00:06:13,000 --> 00:06:19,000 +So this is generally fixed by following good, good coding practices, checking and of course checking + +111 +00:06:19,000 --> 00:06:22,000 +the length of the data that's being written into the buffers. + +112 +00:06:24,000 --> 00:06:24,000 +For your exam. + +113 +00:06:24,000 --> 00:06:28,000 +You want to understand what is a buffer overflow and memory injection. + +114 +00:06:28,000 --> 00:06:30,000 +Notice memory injection is a worm that it's a broad worm. + +115 +00:06:30,000 --> 00:06:37,000 +It basically means injecting data into memory, generally malicious data into memory. + +116 +00:06:37,000 --> 00:06:39,000 +And a buffer overflow is just one of the examples of them. + +117 +00:06:39,000 --> 00:06:42,000 +There are a few others like DLL injections and so on. + +118 +00:06:42,000 --> 00:06:44,000 +Don't don't worry too much about that. + +119 +00:06:44,000 --> 00:06:47,000 +Just understand what exactly is a buffer overflow or memory injection. + +120 +00:06:47,000 --> 00:06:53,000 +Remember, it's just really getting malicious codes into a software through the Ram and that causes + +121 +00:06:53,000 --> 00:06:54,000 +bad things. + +122 +00:06:54,000 --> 00:06:55,000 +How do we fix it? + +123 +00:06:55,000 --> 00:07:00,000 +Following good secure code and practices using vulnerability scanners to find them. + +124 +00:07:00,000 --> 00:07:05,000 +And let me tell you guys something, this may be a scary thing, but if you work hard and you find them + +125 +00:07:05,000 --> 00:07:07,000 +and you fix them, they're not that bad. + diff --git a/05 - Vulnerabilities/003 Race Conditions OB 2.3_en.srt b/05 - Vulnerabilities/003 Race Conditions OB 2.3_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..19bc92899a4bc3597822eca38c914b2b157941cc --- /dev/null +++ b/05 - Vulnerabilities/003 Race Conditions OB 2.3_en.srt @@ -0,0 +1,388 @@ +1 +00:00:00,000 --> 00:00:04,000 +When you're writing applications as a programmer, you have to be concerned with something we call a + +2 +00:00:04,000 --> 00:00:06,000 +race condition. + +3 +00:00:06,000 --> 00:00:13,000 +You see, what happens is when a program executes into memory, generally there is a time between one + +4 +00:00:13,000 --> 00:00:15,000 +thing happening and another thing happening. + +5 +00:00:15,000 --> 00:00:17,000 +It's generally like a sequence of events. + +6 +00:00:17,000 --> 00:00:18,000 +This happens, then this happens. + +7 +00:00:18,000 --> 00:00:27,000 +Now in this, this happening and then this happening forms an opportunity for a hacker to insert malicious + +8 +00:00:27,000 --> 00:00:27,000 +code here. + +9 +00:00:28,000 --> 00:00:30,000 +You see this is called a top two error. + +10 +00:00:30,000 --> 00:00:34,000 +And it's called a time of check to time of use error, also known as a race condition. + +11 +00:00:34,000 --> 00:00:35,000 +Let's get more into this. + +12 +00:00:35,000 --> 00:00:39,000 +So this is something that's going to happen in the world of programming. + +13 +00:00:39,000 --> 00:00:44,000 +And in the next in the next display here, I'm going to show you guys an actual example of the coding + +14 +00:00:44,000 --> 00:00:45,000 +that goes behind it. + +15 +00:00:45,000 --> 00:00:50,000 +Don't worry, you don't need to be super smart to understand the Unix code, but let's get into it. + +16 +00:00:50,000 --> 00:00:55,000 +So this is a vulnerability that occurs when the timing of an action of a system affects a state and + +17 +00:00:55,000 --> 00:00:56,000 +a particular outcome. + +18 +00:00:57,000 --> 00:01:03,000 +The danger arises when the success of a security operation depends on the timing of a certain event. + +19 +00:01:03,000 --> 00:01:03,000 +All right. + +20 +00:01:03,000 --> 00:01:12,000 +So before going into all of these things here, I actually want to show you a famous old it's not going + +21 +00:01:12,000 --> 00:01:12,000 +to happen anymore. + +22 +00:01:12,000 --> 00:01:15,000 +But this was a famous old Unix talk to. + +23 +00:01:15,000 --> 00:01:21,000 +So Toc2 stands for it's talk to time of check to time of use. + +24 +00:01:21,000 --> 00:01:22,000 +That's what that means. + +25 +00:01:22,000 --> 00:01:26,000 +So I want to show it to you and it'll be easier to explain it that way. + +26 +00:01:26,000 --> 00:01:27,000 +Don't get scared. + +27 +00:01:27,000 --> 00:01:28,000 +Don't don't stop the video. + +28 +00:01:28,000 --> 00:01:29,000 +It's not that bad. + +29 +00:01:29,000 --> 00:01:31,000 +It's really easy to understand. + +30 +00:01:32,000 --> 00:01:33,000 +So. + +31 +00:01:34,000 --> 00:01:37,000 +When you want to open a file in Unix. + +32 +00:01:37,000 --> 00:01:37,000 +All right. + +33 +00:01:38,000 --> 00:01:45,000 +Basically when you let's say you have a Unix system, let's say it has a GUI on it just to make it easy. + +34 +00:01:45,000 --> 00:01:46,000 +And you double click on the file. + +35 +00:01:46,000 --> 00:01:47,000 +But what happens? + +36 +00:01:47,000 --> 00:01:48,000 +Well it runs this code. + +37 +00:01:48,000 --> 00:01:50,000 +It basically it's saying look at the code. + +38 +00:01:50,000 --> 00:01:57,000 +It says if you access the file and you have met the permission then okay, right. + +39 +00:01:57,000 --> 00:02:03,000 +Check, check the file if the permissions are good, if the access is good, if it's good, then this + +40 +00:02:03,000 --> 00:02:06,000 +line here says open the file. + +41 +00:02:06,000 --> 00:02:06,000 +All right. + +42 +00:02:06,000 --> 00:02:08,000 +That's all it means when you access the file. + +43 +00:02:08,000 --> 00:02:10,000 +If your permissions are good, open the file. + +44 +00:02:10,000 --> 00:02:11,000 +Easy enough. + +45 +00:02:11,000 --> 00:02:11,000 +Right. + +46 +00:02:11,000 --> 00:02:13,000 +So that's all you got to really know there. + +47 +00:02:14,000 --> 00:02:17,000 +But you notice it's two commands. + +48 +00:02:17,000 --> 00:02:20,000 +There's one access and there's one open. + +49 +00:02:20,000 --> 00:02:22,000 +So notice the if statement that's here. + +50 +00:02:22,000 --> 00:02:25,000 +So if it's if this person tries to open this file they need the permission. + +51 +00:02:25,000 --> 00:02:26,000 +Let them in. + +52 +00:02:26,000 --> 00:02:27,000 +If not don't let them in. + +53 +00:02:28,000 --> 00:02:29,000 +Easy enough. + +54 +00:02:30,000 --> 00:02:32,000 +But what an attacker is going to do. + +55 +00:02:32,000 --> 00:02:34,000 +And here's where the race condition exists. + +56 +00:02:34,000 --> 00:02:40,000 +You see, in between this if statement and this open here, between this access and between this open, + +57 +00:02:40,000 --> 00:02:43,000 +there is a race condition that can happen. + +58 +00:02:43,000 --> 00:02:44,000 +So look at the attack. + +59 +00:02:44,000 --> 00:02:46,000 +Now look at the talk two attack. + +60 +00:02:46,000 --> 00:02:47,000 +So it's the same thing. + +61 +00:02:48,000 --> 00:02:50,000 +But now look what happens. + +62 +00:02:50,000 --> 00:02:56,000 +The attacker, the moment the access attributes, it starts to run and it says, okay, you have permission + +63 +00:02:56,000 --> 00:02:57,000 +to open the file. + +64 +00:02:57,000 --> 00:03:00,000 +The attacker inserts a line of code. + +65 +00:03:00,000 --> 00:03:05,000 +This line of code basically says to replace the password file in the in the operating system. + +66 +00:03:05,000 --> 00:03:06,000 +That's what that means. + +67 +00:03:06,000 --> 00:03:11,000 +So the attacker can make up a set of passwords, put it into a file and then run this command. + +68 +00:03:11,000 --> 00:03:17,000 +And basically you're going to replace the password file in the operating system with this malicious + +69 +00:03:17,000 --> 00:03:18,000 +file that he has. + +70 +00:03:19,000 --> 00:03:21,000 +So what happens now? + +71 +00:03:21,000 --> 00:03:24,000 +Well, it's executing this file with this permission. + +72 +00:03:24,000 --> 00:03:24,000 +That's here. + +73 +00:03:24,000 --> 00:03:25,000 +That's what that's doing. + +74 +00:03:25,000 --> 00:03:30,000 +So it's executing your password file with this particular command. + +75 +00:03:30,000 --> 00:03:34,000 +Even though you can't run this command by itself, it wouldn't do anything because you don't have permission + +76 +00:03:34,000 --> 00:03:34,000 +to it. + +77 +00:03:34,000 --> 00:03:37,000 +But when you open this file, a ticket opens up the administration. + +78 +00:03:37,000 --> 00:03:41,000 +It opens up the access on the machine, allowing this command to execute. + +79 +00:03:41,000 --> 00:03:45,000 +And he replaces the password file, basically giving them full access. + +80 +00:03:45,000 --> 00:03:49,000 +This is an example of a race condition. + +81 +00:03:50,000 --> 00:03:53,000 +Notice between the access and the open. + +82 +00:03:53,000 --> 00:03:57,000 +There is a time difference from when it says okay, I'm going to give you access and then it opens the + +83 +00:03:57,000 --> 00:04:00,000 +file this time difference between them. + +84 +00:04:00,000 --> 00:04:02,000 +That's the race condition. + +85 +00:04:02,000 --> 00:04:05,000 +So this is a complicated thing. + +86 +00:04:06,000 --> 00:04:10,000 +So what I just explained there to you guys is basically what you have here. + +87 +00:04:10,000 --> 00:04:10,000 +Now, I'm gonna let you guys read this. + +88 +00:04:10,000 --> 00:04:15,000 +I'm not going to read this word for word here, but it's basically what I just showed you. + +89 +00:04:15,000 --> 00:04:18,000 +Now, if you're wondering, well, how do we stop this race condition? + +90 +00:04:18,000 --> 00:04:22,000 +What can we do to stop a race condition from happening? + +91 +00:04:22,000 --> 00:04:27,000 +Well, to fix the top two error, the easiest way to do that would be to code your applications correctly + +92 +00:04:27,000 --> 00:04:29,000 +and not allowing that. + +93 +00:04:29,000 --> 00:04:34,000 +So once again, the best way to fix these kinds of application coding problems or coding errors is to + +94 +00:04:34,000 --> 00:04:36,000 +follow good secure programming practices. + +95 +00:04:36,000 --> 00:04:40,000 +That's going to include not ensuring that these things don't happen. + +96 +00:04:40,000 --> 00:04:41,000 +Systems are checked. + +97 +00:04:41,000 --> 00:04:46,000 +Input validations are done in order to stop these kinds of attacks. + diff --git a/05 - Vulnerabilities/004 Malicious Updates OB 2.3_en.srt b/05 - Vulnerabilities/004 Malicious Updates OB 2.3_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..e613c3d150b0dfe8ec4e028f566d16d837cbf4e2 --- /dev/null +++ b/05 - Vulnerabilities/004 Malicious Updates OB 2.3_en.srt @@ -0,0 +1,164 @@ +1 +00:00:00,000 --> 00:00:05,000 +When it comes to security 101, one of the most important things you can do is keeping your machines + +2 +00:00:05,000 --> 00:00:12,000 +updated, such as keeping your windows box updated, keeping your phones updated, keeping your Mac + +3 +00:00:12,000 --> 00:00:13,000 +laptop updated. + +4 +00:00:13,000 --> 00:00:18,000 +Whatever you're doing, keep your operating system updated, keeping your application updated. + +5 +00:00:18,000 --> 00:00:24,000 +But there are times when these updates could be malicious. + +6 +00:00:24,000 --> 00:00:31,000 +You see, malicious update happens when an attacker is able to install a fake update to an operating + +7 +00:00:31,000 --> 00:00:34,000 +system that actually weakens the security of that operating system. + +8 +00:00:34,000 --> 00:00:37,000 +Now, I want to point out that it just doesn't only apply to operating system. + +9 +00:00:37,000 --> 00:00:41,000 +Malicious update can also apply to applications. + +10 +00:00:41,000 --> 00:00:46,000 +It can also apply to firmware, malicious uh, or fake firmware updates. + +11 +00:00:46,000 --> 00:00:53,000 +Now, this of course is really bad because what happens here is now an attacker is able to install a + +12 +00:00:53,000 --> 00:00:59,000 +seriously malicious software onto your operating system, onto your application, onto your device, + +13 +00:00:59,000 --> 00:01:04,000 +causing either the operating system to get corrupted and shut down for data to be stolen. + +14 +00:01:04,000 --> 00:01:09,000 +For them to maybe have a type of a ransomware that will hold your data hostage and make you pay to get + +15 +00:01:09,000 --> 00:01:10,000 +your data back. + +16 +00:01:10,000 --> 00:01:16,000 +So be careful with actually putting in updates where you get your update matters. + +17 +00:01:16,000 --> 00:01:22,000 +You should never download updates from anywhere but the manufacturer's website. + +18 +00:01:22,000 --> 00:01:27,000 +So, for example, Windows Update should only ever come from windows. + +19 +00:01:27,000 --> 00:01:32,000 +If I'm going to go and I'm going to get a firmware, I'm going to get an update to to the Sonicwall + +20 +00:01:32,000 --> 00:01:38,000 +device, and I get an email to my inbox that says, hey, we are from Sonicwall and we have a brand + +21 +00:01:38,000 --> 00:01:41,000 +new update that gives you a bunch of features to your Sonicwall device. + +22 +00:01:42,000 --> 00:01:46,000 +Click this link to download it and install it. + +23 +00:01:46,000 --> 00:01:48,000 +Well, it's probably not a good idea, right? + +24 +00:01:48,000 --> 00:01:52,000 +Because that update that they're sending me is probably not coming from Sonicwall. + +25 +00:01:52,000 --> 00:01:56,000 +You know, it could be coming from a bad person, bad hackers. + +26 +00:01:56,000 --> 00:01:59,000 +So what are we going to do? + +27 +00:01:59,000 --> 00:02:04,000 +Well, if I want the update to Sonicwall, I should go to the Sonicwall website, the official manufacturer's + +28 +00:02:04,000 --> 00:02:10,000 +website, and download it from their website, not from some unknown person. + +29 +00:02:10,000 --> 00:02:18,000 +Now, one thing that manufacturers could do is call code sign and they digitally sign the update. + +30 +00:02:18,000 --> 00:02:23,000 +Now, I haven't covered digital signature yet in this course, but you'll learn that in a cryptography + +31 +00:02:23,000 --> 00:02:23,000 +section. + +32 +00:02:23,000 --> 00:02:28,000 +But just remember, digital signature is when are they signed the code? + +33 +00:02:28,000 --> 00:02:33,000 +The code sign code signing is when the manufacturer digitally signed the updates or digitally signed + +34 +00:02:33,000 --> 00:02:34,000 +the codes. + +35 +00:02:34,000 --> 00:02:41,000 +So your operating system, your application, your device is 100% sure that that update is coming from + +36 +00:02:41,000 --> 00:02:44,000 +a particular manufacturer and no one else. + +37 +00:02:45,000 --> 00:02:46,000 +Okay. + +38 +00:02:46,000 --> 00:02:49,000 +Update is security 101. + +39 +00:02:49,000 --> 00:02:54,000 +We have to make sure that we keep all devices, all software and all application updated. + +40 +00:02:54,000 --> 00:03:00,000 +Just ensure that where you're getting those updates from our trusted and once again, you should really + +41 +00:03:00,000 --> 00:03:02,000 +get them from the manufacturers only. + diff --git a/05 - Vulnerabilities/005 OS-Based Vulnerabilities OB 2.3_en.srt b/05 - Vulnerabilities/005 OS-Based Vulnerabilities OB 2.3_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..c0739fbc432de9bafa2ae9f47abc001607d43dfb --- /dev/null +++ b/05 - Vulnerabilities/005 OS-Based Vulnerabilities OB 2.3_en.srt @@ -0,0 +1,320 @@ +1 +00:00:00,000 --> 00:00:06,000 +Every single device that is out there, whether it's the TV on your wall, your phone, your firewall, + +2 +00:00:06,000 --> 00:00:09,000 +your desktop, your laptop, it doesn't matter. + +3 +00:00:09,000 --> 00:00:14,000 +They all have some kind of an operating system, whether it's running on windows operating system, + +4 +00:00:14,000 --> 00:00:17,000 +Linux, Unix, Mac OS, it doesn't matter. + +5 +00:00:18,000 --> 00:00:21,000 +All of them are subject to all kinds of vulnerabilities. + +6 +00:00:21,000 --> 00:00:24,000 +And this is vulnerabilities related to the operating system. + +7 +00:00:24,000 --> 00:00:29,000 +So in this video I want to talk about some of the weaknesses that can arise in terms of the operating + +8 +00:00:29,000 --> 00:00:30,000 +system. + +9 +00:00:30,000 --> 00:00:35,000 +You see the operating system is going to be one of the most complex software on your device. + +10 +00:00:35,000 --> 00:00:39,000 +In fact, the operating system of windows is a very complex piece of software. + +11 +00:00:39,000 --> 00:00:45,000 +The Microsoft has basically been built in for a long, long time since the creation of Microsoft, basically. + +12 +00:00:46,000 --> 00:00:53,000 +So the weaknesses in the OS can be exploited to gain unauthorized access to your device, gaining pushing + +13 +00:00:53,000 --> 00:00:54,000 +up privileges. + +14 +00:00:54,000 --> 00:00:57,000 +This, of course, can and is a long list here, right? + +15 +00:00:57,000 --> 00:00:58,000 +You think about this. + +16 +00:00:58,000 --> 00:01:02,000 +If somebody is able to exploit the operating system or gain control of the operating system, every + +17 +00:01:02,000 --> 00:01:08,000 +and anything is possible from installing malicious applications, stealing your data, manipulating + +18 +00:01:08,000 --> 00:01:12,000 +your data, tracking your use, tracking your movements on your computer, seeing everything that you're + +19 +00:01:12,000 --> 00:01:13,000 +doing. + +20 +00:01:14,000 --> 00:01:15,000 +You name it. + +21 +00:01:15,000 --> 00:01:17,000 +That's bad in the world of computers. + +22 +00:01:17,000 --> 00:01:21,000 +If they take control of your operating system, they have everything on you. + +23 +00:01:22,000 --> 00:01:24,000 +So how do we prevent this? + +24 +00:01:24,000 --> 00:01:28,000 +Well, generally you're going to stop this by updating the operating system. + +25 +00:01:28,000 --> 00:01:29,000 +You're going to. + +26 +00:01:29,000 --> 00:01:36,000 +Most most operating system are going to get frequent updates Microsoft releases updates. + +27 +00:01:36,000 --> 00:01:42,000 +Generally on Tuesdays you should be updating your operating system or set your operating system to be + +28 +00:01:42,000 --> 00:01:45,000 +updated automatically whenever the updates are available. + +29 +00:01:45,000 --> 00:01:50,000 +If you're using the Mac OS, if you're using any type of Linux, you should be checking or just set + +30 +00:01:50,000 --> 00:01:52,000 +the machine to get updates automatically. + +31 +00:01:53,000 --> 00:01:58,000 +Now, the problem arises when you work in certain organizations. + +32 +00:01:58,000 --> 00:02:01,000 +In certain organizations, they don't want updates automatically. + +33 +00:02:01,000 --> 00:02:06,000 +The reason for that is because updates sometimes breaks the machines themselves. + +34 +00:02:06,000 --> 00:02:07,000 +I've seen this. + +35 +00:02:07,000 --> 00:02:12,000 +I've seen updates automatically installed and kill a video card. + +36 +00:02:12,000 --> 00:02:18,000 +I was working in a school and we used it a very specialized video card for them to teach graphics design + +37 +00:02:18,000 --> 00:02:19,000 +program. + +38 +00:02:19,000 --> 00:02:21,000 +One day we comes in, we come in. + +39 +00:02:21,000 --> 00:02:23,000 +None of the machines video cards are working. + +40 +00:02:23,000 --> 00:02:25,000 +It's like the driver got misplaced. + +41 +00:02:25,000 --> 00:02:25,000 +Why? + +42 +00:02:25,000 --> 00:02:28,000 +Because the update came in, overwrote the driver that was there. + +43 +00:02:28,000 --> 00:02:30,000 +We had to roll it back for it to work. + +44 +00:02:30,000 --> 00:02:32,000 +So sometimes updates causes problems. + +45 +00:02:32,000 --> 00:02:36,000 +This causes organizations to not roll out updates automatically. + +46 +00:02:36,000 --> 00:02:39,000 +That leaves the machines vulnerable for a period of time. + +47 +00:02:39,000 --> 00:02:45,000 +Another thing that we have to keep in mind is end of life OS's. + +48 +00:02:45,000 --> 00:02:49,000 +What this means is that OS's that are not supported anymore. + +49 +00:02:49,000 --> 00:02:51,000 +This may sound hard to believe. + +50 +00:02:52,000 --> 00:02:54,000 +Especially if you're like a home user. + +51 +00:02:54,000 --> 00:03:01,000 +But there are many, many organizations in corporate America today that still uses end of life. + +52 +00:03:01,000 --> 00:03:07,000 +Remember that terms for your exam, end of life operating system or EOL, end of life operating system, + +53 +00:03:07,000 --> 00:03:10,000 +operating system not being supported anymore. + +54 +00:03:10,000 --> 00:03:15,000 +If you are a hacker and you write a malicious code. + +55 +00:03:16,000 --> 00:03:22,000 +For Windows 7, one of the most popular versions of Windows in Windows XP. + +56 +00:03:22,000 --> 00:03:24,000 +Older, but still very popular. + +57 +00:03:25,000 --> 00:03:27,000 +I can guarantee you that you're going to infect. + +58 +00:03:27,000 --> 00:03:33,000 +Thousands and thousands, maybe even millions of computers and nothing will stop you. + +59 +00:03:33,000 --> 00:03:34,000 +Why? + +60 +00:03:34,000 --> 00:03:40,000 +Because Microsoft doesn't make updates and patches for those operating systems anymore. + +61 +00:03:40,000 --> 00:03:46,000 +So that is bad if you're using and there are many organizations that are utilizing end of life. + +62 +00:03:46,000 --> 00:03:54,000 +Operating systems that are that are utilizing these operating system in different type of kiosk machines. + +63 +00:03:54,000 --> 00:03:59,000 +For example, it's very famous to know that a lot of ATM machines ran on a versions of Windows Embedded + +64 +00:03:59,000 --> 00:04:00,000 +systems. + +65 +00:04:01,000 --> 00:04:01,000 +All right. + +66 +00:04:01,000 --> 00:04:08,000 +And if you have an old ATM machine that runs on that, that machine is vulnerable and people can manipulate + +67 +00:04:08,000 --> 00:04:09,000 +it and steal money from it. + +68 +00:04:10,000 --> 00:04:15,000 +So even though this sounds like something very elementary, like, okay, Andrew, I know, I know, + +69 +00:04:15,000 --> 00:04:16,000 +keep keep the machine updated. + +70 +00:04:16,000 --> 00:04:22,000 +It's it's more complex in corporate America, in the home world we probably change your machines quick, + +71 +00:04:22,000 --> 00:04:23,000 +or at least I do. + +72 +00:04:23,000 --> 00:04:25,000 +So I was generally keep the latest and greatest. + +73 +00:04:25,000 --> 00:04:31,000 +But in corporate America, especially in government agencies especially, you may have really legacy + +74 +00:04:31,000 --> 00:04:32,000 +systems. + +75 +00:04:33,000 --> 00:04:37,000 +I'm old enough to know what windows 3.1 was, as I've used it as a young child. + +76 +00:04:38,000 --> 00:04:43,000 +And I'm pretty sure there are machines out there running today in military systems. + +77 +00:04:43,000 --> 00:04:49,000 +Still, windows 3.1, which is a very old operating system, came out in late 80s or early 90s, I remember. + +78 +00:04:50,000 --> 00:04:52,000 +Anyway, the point is, keep your machine updated. + +79 +00:04:52,000 --> 00:04:57,000 +Don't use end of life systems, because if you do, that's introducing a whole lot of vulnerabilities + +80 +00:04:57,000 --> 00:04:59,000 +in your environment. + diff --git a/05 - Vulnerabilities/006 SQL Injections OB 2.3_en.srt b/05 - Vulnerabilities/006 SQL Injections OB 2.3_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..855cc7354776b08f0d3b13ffd3412e89894b81e5 --- /dev/null +++ b/05 - Vulnerabilities/006 SQL Injections OB 2.3_en.srt @@ -0,0 +1,720 @@ +1 +00:00:00,000 --> 00:00:05,000 +All applications that are out there today is pretty much powered by some kind of a database. + +2 +00:00:05,000 --> 00:00:09,000 +You see, a database is something that holds data. + +3 +00:00:09,000 --> 00:00:10,000 +It's basically like it says it is. + +4 +00:00:10,000 --> 00:00:11,000 +It's a base of data. + +5 +00:00:11,000 --> 00:00:17,000 +Famous databases include things like Microsoft Excel that I use a lot because it's pretty simple. + +6 +00:00:17,000 --> 00:00:24,000 +Then you have Microsoft SQL, Oracle's SQL, NoSQL and many others. + +7 +00:00:24,000 --> 00:00:30,000 +So in this video, I want to explain to you an attack that you should be familiar with for your exam. + +8 +00:00:30,000 --> 00:00:33,000 +This can get very complex and very long, but I want to keep it very simple. + +9 +00:00:33,000 --> 00:00:38,000 +And I want to give you a quick demonstration just so you understand exactly what it is. + +10 +00:00:38,000 --> 00:00:43,000 +And that's going to be called a SQL injection or SQL injection structured Query language. + +11 +00:00:43,000 --> 00:00:47,000 +So the Structured Query Language is what we're going to use to talk to the database. + +12 +00:00:47,000 --> 00:00:48,000 +Let's take a look at this. + +13 +00:00:49,000 --> 00:00:58,000 +So an SQL injection allows attackers to insert malicious SQL code into input fields to run unauthorized + +14 +00:00:58,000 --> 00:00:59,000 +SQL queries. + +15 +00:00:59,000 --> 00:01:04,000 +Now I want to draw you guys a quick diagram so you better understand what I am talking about. + +16 +00:01:05,000 --> 00:01:06,000 +So. + +17 +00:01:06,000 --> 00:01:13,000 +I'm going to give you a really easy to understand format of this in all applications today. + +18 +00:01:13,000 --> 00:01:15,000 +There's something we call a front end. + +19 +00:01:16,000 --> 00:01:19,000 +And then in all applications we have something called the back end. + +20 +00:01:20,000 --> 00:01:22,000 +The front end connects to the back end. + +21 +00:01:22,000 --> 00:01:27,000 +The front end is generally the user interface that you see, such as that web page that you see when + +22 +00:01:27,000 --> 00:01:29,000 +you go to Amazon.com. + +23 +00:01:29,000 --> 00:01:35,000 +But behind Amazon.com is a back end, and that back end is going to be a SQL database or basically a + +24 +00:01:35,000 --> 00:01:38,000 +database that holds all of the information. + +25 +00:01:38,000 --> 00:01:46,000 +So as you come and you search for stuff, you may search for sneakers, you type sneakers and you press + +26 +00:01:46,000 --> 00:01:47,000 +enter. + +27 +00:01:47,000 --> 00:01:52,000 +What happens is that it queries query is a word that basically means ask questions. + +28 +00:01:52,000 --> 00:01:54,000 +Hey, can I query you? + +29 +00:01:54,000 --> 00:01:55,000 +That means can I ask you a question? + +30 +00:01:56,000 --> 00:02:01,000 +The front end is going to send the back end a query that says, send me all the records you have for + +31 +00:02:01,000 --> 00:02:02,000 +sneakers. + +32 +00:02:02,000 --> 00:02:07,000 +The database and response here is all the sneakers I got and then it's displayed on your screen. + +33 +00:02:07,000 --> 00:02:10,000 +Now this is a really simplified version of what I'm trying to tell you here. + +34 +00:02:10,000 --> 00:02:15,000 +So what I'm trying to mention here basically is all these applications have a database that goes behind + +35 +00:02:15,000 --> 00:02:16,000 +them. + +36 +00:02:16,000 --> 00:02:17,000 +This database stores a lot of things. + +37 +00:02:17,000 --> 00:02:19,000 +It's everything about the application. + +38 +00:02:19,000 --> 00:02:25,000 +If you think of Amazon, the back end of Amazon is going to store things like your username and passwords, + +39 +00:02:25,000 --> 00:02:30,000 +your credit card, your address, all the products that it sells, how much is there. + +40 +00:02:30,000 --> 00:02:34,000 +All of that is stored in the Amazon's database now. + +41 +00:02:35,000 --> 00:02:37,000 +What if you're a bad person? + +42 +00:02:37,000 --> 00:02:38,000 +Well, then, if you get. + +43 +00:02:40,000 --> 00:02:49,000 +If you get access to the front end, you can then try to insert malicious codes from the front end to + +44 +00:02:49,000 --> 00:02:51,000 +manipulate data in the back end. + +45 +00:02:52,000 --> 00:02:53,000 +And this part here I want to show you. + +46 +00:02:53,000 --> 00:02:54,000 +So I have a link. + +47 +00:02:54,000 --> 00:03:01,000 +And you guys can type this link in uh into your browser and it should pull up a website. + +48 +00:03:02,000 --> 00:03:03,000 +Let me get it. + +49 +00:03:04,000 --> 00:03:06,000 +It should pull up this website. + +50 +00:03:06,000 --> 00:03:07,000 +Oops. + +51 +00:03:07,000 --> 00:03:09,000 +It should pull up this website right here. + +52 +00:03:10,000 --> 00:03:11,000 +So here's a website. + +53 +00:03:11,000 --> 00:03:16,000 +This is going to give us an easy to understand SQL uh injection. + +54 +00:03:17,000 --> 00:03:20,000 +So now you can read the example on it. + +55 +00:03:20,000 --> 00:03:21,000 +I'm just going to give you the gist of it. + +56 +00:03:21,000 --> 00:03:23,000 +So they have an application. + +57 +00:03:24,000 --> 00:03:26,000 +And I'll explain to you exactly what it's doing. + +58 +00:03:26,000 --> 00:03:28,000 +So they have an application. + +59 +00:03:28,000 --> 00:03:30,000 +I'm going to run this application. + +60 +00:03:30,000 --> 00:03:35,000 +So they basically have an application that is asking for a username and a password. + +61 +00:03:35,000 --> 00:03:39,000 +Now if you go in it tells you the username is admin. + +62 +00:03:41,000 --> 00:03:46,000 +And it tells you the password is admin 123 okay. + +63 +00:03:46,000 --> 00:03:49,000 +So if you try to log in you would just put admin 123. + +64 +00:03:50,000 --> 00:03:54,000 +And it's telling me, hey you need to change your password and Google doesn't like it, but you notice + +65 +00:03:54,000 --> 00:03:58,000 +that log you basically in to the actual application itself. + +66 +00:03:58,000 --> 00:03:59,000 +All right easy enough. + +67 +00:04:00,000 --> 00:04:01,000 +Let's reload this. + +68 +00:04:02,000 --> 00:04:05,000 +So that would be in a normal world. + +69 +00:04:05,000 --> 00:04:12,000 +So what a SQL injection does is they're now going to insert a SQL command into the password field to + +70 +00:04:12,000 --> 00:04:14,000 +accomplish the same task without knowing the password. + +71 +00:04:14,000 --> 00:04:16,000 +So watch this. + +72 +00:04:16,000 --> 00:04:17,000 +Let's run the application. + +73 +00:04:18,000 --> 00:04:21,000 +And I am going to copy the username. + +74 +00:04:23,000 --> 00:04:25,000 +And I'm going to highlight this. + +75 +00:04:29,000 --> 00:04:32,000 +And I'm just going to paste all of that in there and watch what happens now. + +76 +00:04:32,000 --> 00:04:34,000 +So remember I didn't put the password. + +77 +00:04:34,000 --> 00:04:36,000 +All I put was this particular thing. + +78 +00:04:36,000 --> 00:04:37,000 +And I'll explain what this is in a minute. + +79 +00:04:37,000 --> 00:04:40,000 +But you notice when I log in notice it logs. + +80 +00:04:40,000 --> 00:04:41,000 +Hello administrator. + +81 +00:04:41,000 --> 00:04:44,000 +It logs me in it without even knowing the password. + +82 +00:04:44,000 --> 00:04:45,000 +It logged me in. + +83 +00:04:46,000 --> 00:04:48,000 +How the hell is that possible? + +84 +00:04:49,000 --> 00:04:52,000 +Well, this is the SQL command, you see. + +85 +00:04:54,000 --> 00:04:58,000 +When you go to a prompt and you put a password in. + +86 +00:04:59,000 --> 00:05:03,000 +You put your username, you put your password, you press enter. + +87 +00:05:03,000 --> 00:05:05,000 +It sends that to the SQL database. + +88 +00:05:05,000 --> 00:05:09,000 +The SQL database then compares what you typed in to what it has. + +89 +00:05:09,000 --> 00:05:13,000 +So if you typed in the username as admin it says okay, we got admin and then you typed in your password + +90 +00:05:13,000 --> 00:05:15,000 +was admin 123. + +91 +00:05:15,000 --> 00:05:16,000 +Then it checks okay. + +92 +00:05:16,000 --> 00:05:16,000 +Is this admin. + +93 +00:05:16,000 --> 00:05:17,000 +Yeah it is okay. + +94 +00:05:17,000 --> 00:05:18,000 +It lines it up. + +95 +00:05:18,000 --> 00:05:21,000 +But look at the command that we have here. + +96 +00:05:21,000 --> 00:05:23,000 +You notice this command is the really part. + +97 +00:05:23,000 --> 00:05:24,000 +Here is this part. + +98 +00:05:24,000 --> 00:05:26,000 +It's one is equal to one. + +99 +00:05:26,000 --> 00:05:32,000 +Basically all this means it's it's unknown means we don't know our it's one equal to one. + +100 +00:05:32,000 --> 00:05:34,000 +But let me ask a question. + +101 +00:05:34,000 --> 00:05:36,000 +Does one actually equal to one. + +102 +00:05:37,000 --> 00:05:38,000 +Yes. + +103 +00:05:38,000 --> 00:05:42,000 +We're basically telling the database that it's true. + +104 +00:05:42,000 --> 00:05:47,000 +So when we're saying one equal to one, we're basically telling the database that, you know what? + +105 +00:05:48,000 --> 00:05:50,000 +It's already true that we already matched the password. + +106 +00:05:50,000 --> 00:05:54,000 +Because remember in the old one it matched it admin 1 to 3 to 1 to 3. + +107 +00:05:54,000 --> 00:05:55,000 +Now we're saying, hey, you know what? + +108 +00:05:55,000 --> 00:05:56,000 +We already matched it for you. + +109 +00:05:56,000 --> 00:05:59,000 +We already saying, hey, this is equal to this. + +110 +00:05:59,000 --> 00:06:02,000 +And the database is not smart enough to say, well, yeah, you know, I didn't do it. + +111 +00:06:02,000 --> 00:06:05,000 +You you're you should be doing that or should I be doing it? + +112 +00:06:05,000 --> 00:06:06,000 +Database doesn't know this. + +113 +00:06:06,000 --> 00:06:07,000 +So what's happening. + +114 +00:06:07,000 --> 00:06:08,000 +We're doing it for the database. + +115 +00:06:08,000 --> 00:06:09,000 +And the database is like oh okay. + +116 +00:06:09,000 --> 00:06:10,000 +You you know what? + +117 +00:06:10,000 --> 00:06:15,000 +I'm just going to let you in because it seems like, uh, you did match up to what I had. + +118 +00:06:15,000 --> 00:06:17,000 +This is a SQL injection. + +119 +00:06:17,000 --> 00:06:21,000 +A SQL injection can get very, very complex and they can do bad things. + +120 +00:06:21,000 --> 00:06:24,000 +I'm going to show you an example of what you can do on Amazon. + +121 +00:06:24,000 --> 00:06:25,000 +It's not going to work. + +122 +00:06:26,000 --> 00:06:31,000 +It's not going to work, but it'll show you the power of what it can do, because I'm pretty sure. + +123 +00:06:31,000 --> 00:06:35,000 +And if this works in Amazon on this video, uh, we got a serious problem. + +124 +00:06:35,000 --> 00:06:37,000 +So I want to show you guys something. + +125 +00:06:37,000 --> 00:06:39,000 +So I'm going to use, uh SQL. + +126 +00:06:41,000 --> 00:06:44,000 +SQL select statement. + +127 +00:06:44,000 --> 00:06:46,000 +So SQL select. + +128 +00:06:46,000 --> 00:06:49,000 +So I'm going to use the W3 schools and I am going to. + +129 +00:06:52,000 --> 00:06:57,000 +So when you have a this is a table in a database, this is what a table looks like in a database. + +130 +00:06:57,000 --> 00:07:02,000 +And you'll notice that it has a customer ID, has the customer name address and so on. + +131 +00:07:02,000 --> 00:07:06,000 +So when somebody runs a command such as. + +132 +00:07:07,000 --> 00:07:10,000 +Select from customers. + +133 +00:07:10,000 --> 00:07:13,000 +It should return basically the table. + +134 +00:07:13,000 --> 00:07:14,000 +All right. + +135 +00:07:14,000 --> 00:07:19,000 +Now so you can use select statements. + +136 +00:07:19,000 --> 00:07:22,000 +So you can go in and say where's the code. + +137 +00:07:22,000 --> 00:07:24,000 +Let me copy this so you can say. + +138 +00:07:25,000 --> 00:07:29,000 +Take a SQL command, you would go to Amazon.com. + +139 +00:07:29,000 --> 00:07:34,000 +You would then type in the SQL command into an input field. + +140 +00:07:34,000 --> 00:07:39,000 +And I'm not going to get complex here, but you can say something like select from customers and then + +141 +00:07:39,000 --> 00:07:45,000 +you can even be more specific, their user, their first name, last name, address and credit card + +142 +00:07:45,000 --> 00:07:46,000 +number. + +143 +00:07:46,000 --> 00:07:51,000 +And in theory, when you basically run it, you're basically going to get a list of all the customers + +144 +00:07:51,000 --> 00:07:52,000 +that Amazon has. + +145 +00:07:53,000 --> 00:07:54,000 +Sounds crazy now. + +146 +00:07:54,000 --> 00:07:59,000 +Right now, all the customers and all the credit card information will be displayed here. + +147 +00:07:59,000 --> 00:08:03,000 +That is the gist of a basically a SQL injection. + +148 +00:08:05,000 --> 00:08:09,000 +So if you're wondering, was that supposed to work? + +149 +00:08:09,000 --> 00:08:11,000 +Well, it wasn't supposed to work on Amazon. + +150 +00:08:12,000 --> 00:08:15,000 +Amazon is too smart for that because you see, SQL commands are known. + +151 +00:08:16,000 --> 00:08:18,000 +A SQL injection, I should say SQL injections are known. + +152 +00:08:18,000 --> 00:08:21,000 +The question is how do we stop something like this? + +153 +00:08:21,000 --> 00:08:29,000 +SQL injections are generally stopped by fixing and using secure code and practice fixing your code, + +154 +00:08:29,000 --> 00:08:33,000 +limiting what can be inputted into a field. + +155 +00:08:33,000 --> 00:08:37,000 +This time you should be familiar with input validation. + +156 +00:08:37,000 --> 00:08:38,000 +What exactly is it? + +157 +00:08:38,000 --> 00:08:42,000 +Input validation is when you validate all the inputs. + +158 +00:08:42,000 --> 00:08:42,000 +Now. + +159 +00:08:43,000 --> 00:08:47,000 +For a SQL injection to work, you probably have to type in a pretty long SQL command. + +160 +00:08:47,000 --> 00:08:50,000 +What if you limit the field to just ten characters? + +161 +00:08:50,000 --> 00:08:53,000 +That will kill many of the SQL injections. + +162 +00:08:53,000 --> 00:09:00,000 +What if you limit a search field in particularly on a web application, for example, to just 20 characters + +163 +00:09:00,000 --> 00:09:03,000 +and it can't have commas or colons or semicolons? + +164 +00:09:03,000 --> 00:09:08,000 +It'll basically kill every single SQL in SQL command that is out there. + +165 +00:09:08,000 --> 00:09:16,000 +So by doing input validation and input validation means you're just validating your testing out what + +166 +00:09:16,000 --> 00:09:17,000 +people type into the field. + +167 +00:09:17,000 --> 00:09:22,000 +So if you go and you type in particular commands and it has a colon, it has numbers, you can say, + +168 +00:09:22,000 --> 00:09:24,000 +I don't want that in this particular field. + +169 +00:09:24,000 --> 00:09:29,000 +And it wouldn't even run the command basically securing your application. + +170 +00:09:29,000 --> 00:09:32,000 +So remember input validation is really important because it's something that we're going to use not + +171 +00:09:32,000 --> 00:09:35,000 +just to secure against SQL injection but many other attacks. + +172 +00:09:35,000 --> 00:09:36,000 +So keep that in mind. + +173 +00:09:37,000 --> 00:09:40,000 +Okay I didn't want to get too complex on this. + +174 +00:09:40,000 --> 00:09:42,000 +They are the demonstration videos. + +175 +00:09:42,000 --> 00:09:46,000 +I do, uh, when I really hack a database. + +176 +00:09:46,000 --> 00:09:49,000 +But for your exam, this is all you need to know. + +177 +00:09:49,000 --> 00:09:50,000 +I gave you a good example. + +178 +00:09:50,000 --> 00:09:54,000 +You can try that website link that I gave you on the slide there. + +179 +00:09:54,000 --> 00:09:56,000 +You can check it out, play around with it. + +180 +00:09:56,000 --> 00:10:00,000 +You don't need to for your exam, but at least understand what it is and how to stop it. + diff --git a/05 - Vulnerabilities/007 XSS OB 2.3_en.srt b/05 - Vulnerabilities/007 XSS OB 2.3_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..ab6e5edaabaa611b41ce67fbe9e816bfe683b9fb --- /dev/null +++ b/05 - Vulnerabilities/007 XSS OB 2.3_en.srt @@ -0,0 +1,408 @@ +1 +00:00:00,000 --> 00:00:03,000 +I think most of us spend way too much time on the internet. + +2 +00:00:03,000 --> 00:00:07,000 +We interact with so many different web pages, we gain so much information from it. + +3 +00:00:07,000 --> 00:00:13,000 +But there's one attack that you should be familiar with for your exam, and that is cross site scripting. + +4 +00:00:13,000 --> 00:00:19,000 +And cross site scripting is basically a security vulnerability found in web applications. + +5 +00:00:19,000 --> 00:00:25,000 +This enables attackers to basically inject client side scripts onto pages that you're currently viewing. + +6 +00:00:25,000 --> 00:00:31,000 +So all almost all web applications have some kind of box that you can type into. + +7 +00:00:31,000 --> 00:00:37,000 +Search for something, putting a username and a password or something like that in those boxes they + +8 +00:00:37,000 --> 00:00:38,000 +can type scripts in. + +9 +00:00:38,000 --> 00:00:40,000 +This is different than a SQL injection. + +10 +00:00:40,000 --> 00:00:45,000 +A SQL injection is typing in a SQL command to interact with the SQL database in the back end. + +11 +00:00:45,000 --> 00:00:51,000 +In this one, you're typing in a scripting language such as such as the Java script, in order to make + +12 +00:00:51,000 --> 00:00:56,000 +the website do all kinds of things, whether it's manipulating data, exposing the website, or even + +13 +00:00:56,000 --> 00:00:58,000 +bringing the website down. + +14 +00:00:58,000 --> 00:01:02,000 +Now this is best shown with an example that I have here. + +15 +00:01:02,000 --> 00:01:09,000 +So Google set up a website that you can actually practice your cross site scripting skills. + +16 +00:01:09,000 --> 00:01:15,000 +So we're going to do a level one cross site scripting attack against a website that Google has set up. + +17 +00:01:15,000 --> 00:01:22,000 +Now the link is there and you guys can type it into your URLs and give it a shot if you're interested + +18 +00:01:22,000 --> 00:01:23,000 +in these things. + +19 +00:01:23,000 --> 00:01:26,000 +Anyhow, uh, so where am I? + +20 +00:01:26,000 --> 00:01:31,000 +Okay, so here is the website that I'm at and uh, I'm going to try it again. + +21 +00:01:31,000 --> 00:01:32,000 +This is a free website. + +22 +00:01:32,000 --> 00:01:33,000 +Anyone can try it. + +23 +00:01:33,000 --> 00:01:39,000 +I'm going to do the there's basically, uh, there's going to be two games on here to test your cross-site + +24 +00:01:39,000 --> 00:01:41,000 +scripting attack, and this is going to be the first one. + +25 +00:01:42,000 --> 00:01:44,000 +So they have a website here. + +26 +00:01:44,000 --> 00:01:50,000 +And if you you would basically type in just like you would have Google and you would type in what you're + +27 +00:01:50,000 --> 00:01:53,000 +searching for and you would click search just like a normal search engine. + +28 +00:01:53,000 --> 00:01:57,000 +But I'm going to do something different, I'm going to make it and it's going to take what's called + +29 +00:01:57,000 --> 00:01:58,000 +an alert box. + +30 +00:01:58,000 --> 00:02:05,000 +So the alert box, when I execute the script, if I type it right, when I execute the script, what's + +31 +00:02:05,000 --> 00:02:09,000 +going to happen is that it's going to generate an alert box and pop up on my screen. + +32 +00:02:09,000 --> 00:02:15,000 +Basically, I'm going to run a script my own JavaScript on Dear Web Application. + +33 +00:02:15,000 --> 00:02:16,000 +So let's go in here. + +34 +00:02:16,000 --> 00:02:19,000 +Now, this is not a coding class, guys. + +35 +00:02:19,000 --> 00:02:22,000 +Uh, you notice it starts out with a script. + +36 +00:02:22,000 --> 00:02:27,000 +So I'm going to open the script and I'm going to say let me use the alert box alert. + +37 +00:02:27,000 --> 00:02:35,000 +We'll do an open and we'll say, uh, and since that's me and you could put whatever you want in this + +38 +00:02:35,000 --> 00:02:42,000 +colon here, uh, in between the quotations, close this up. + +39 +00:02:42,000 --> 00:02:44,000 +Um, put a semicolon. + +40 +00:02:44,000 --> 00:02:47,000 +Can't remember my script in here, and I got to close up the script now. + +41 +00:02:49,000 --> 00:02:49,000 +Oops. + +42 +00:02:52,000 --> 00:02:53,000 +Close up the script. + +43 +00:02:53,000 --> 00:02:54,000 +Let's see if I execute this right now. + +44 +00:02:54,000 --> 00:02:55,000 +If I type this in. + +45 +00:02:55,000 --> 00:02:57,000 +Right, I just want to show you what I'm doing here. + +46 +00:02:57,000 --> 00:02:57,000 +So. + +47 +00:02:59,000 --> 00:03:02,000 +Basically what I'm doing is I'm telling it that I want to run a script. + +48 +00:03:02,000 --> 00:03:06,000 +You notice start script and end script. + +49 +00:03:06,000 --> 00:03:07,000 +That's what these are saying. + +50 +00:03:07,000 --> 00:03:12,000 +And the script that I'm going to be using now, it does want me to use an alert box. + +51 +00:03:12,000 --> 00:03:14,000 +So it says alert box. + +52 +00:03:14,000 --> 00:03:15,000 +Oops. + +53 +00:03:15,000 --> 00:03:18,000 +Oh man, I forgot to do it and it deleted it. + +54 +00:03:18,000 --> 00:03:19,000 +So let's start. + +55 +00:03:19,000 --> 00:03:20,000 +Let's try that again. + +56 +00:03:20,000 --> 00:03:24,000 +So script I'm just going to execute it this time though. + +57 +00:03:25,000 --> 00:03:29,000 +You see this is why we don't do code in uh in these video based classes. + +58 +00:03:29,000 --> 00:03:36,000 +But I want to get this over with and put my semicolon close up my script. + +59 +00:03:37,000 --> 00:03:38,000 +Let's see here. + +60 +00:03:39,000 --> 00:03:45,000 +I put close this up and now let's see what happens when I execute it. + +61 +00:03:45,000 --> 00:03:48,000 +And you notice that an alert box just popped up. + +62 +00:03:48,000 --> 00:03:49,000 +See that? + +63 +00:03:50,000 --> 00:03:52,000 +You've executed an alert. + +64 +00:03:52,000 --> 00:03:53,000 +And my alert was me just saying. + +65 +00:03:53,000 --> 00:03:56,000 +And then I could have put anything into to that particular box. + +66 +00:03:56,000 --> 00:03:57,000 +And that's what this do. + +67 +00:03:57,000 --> 00:04:05,000 +But what this is showing you is that in between the the script open and closed script, JavaScript basically + +68 +00:04:05,000 --> 00:04:10,000 +language that I was using in between that I could have put anything in there. + +69 +00:04:10,000 --> 00:04:16,000 +Now this particular website is coded for this, and you just don't go about executing cross-site scripting + +70 +00:04:16,000 --> 00:04:17,000 +against anybody's website. + +71 +00:04:17,000 --> 00:04:18,000 +You don't do that. + +72 +00:04:18,000 --> 00:04:19,000 +That's against the law, actually. + +73 +00:04:20,000 --> 00:04:20,000 +Okay. + +74 +00:04:21,000 --> 00:04:24,000 +This is a website made for it, and it's only going to accept that. + +75 +00:04:24,000 --> 00:04:26,000 +That's why I showed you this particular one. + +76 +00:04:26,000 --> 00:04:30,000 +If you're interested in learning more about how to do these things, I would highly suggest you take + +77 +00:04:30,000 --> 00:04:35,000 +my Certified Ethical Hacking course, where I will give you a whole lot more examples and a whole lot + +78 +00:04:35,000 --> 00:04:39,000 +more other websites that some of them I even built in order to show you how to do this better. + +79 +00:04:39,000 --> 00:04:40,000 +All right. + +80 +00:04:40,000 --> 00:04:40,000 +Let's go back here. + +81 +00:04:40,000 --> 00:04:42,000 +So I'm just going to say okay. + +82 +00:04:42,000 --> 00:04:43,000 +And um. + +83 +00:04:44,000 --> 00:04:44,000 +That's it. + +84 +00:04:44,000 --> 00:04:47,000 +I've executed it and we are good. + +85 +00:04:47,000 --> 00:04:49,000 +Now let's go back here. + +86 +00:04:49,000 --> 00:04:49,000 +So. + +87 +00:04:52,000 --> 00:04:53,000 +Cross site scripting. + +88 +00:04:53,000 --> 00:04:54,000 +You saw what it is. + +89 +00:04:54,000 --> 00:04:55,000 +All right. + +90 +00:04:55,000 --> 00:05:02,000 +These are going to be vulnerabilities because the input that's being typed in there is on uh, on validated. + +91 +00:05:02,000 --> 00:05:05,000 +What that means is that in order to fix this, you're going to have to do input validation. + +92 +00:05:05,000 --> 00:05:07,000 +So what is input validation. + +93 +00:05:08,000 --> 00:05:16,000 +Well, in that box that I just typed into, they should have uh, they should have validated what I + +94 +00:05:16,000 --> 00:05:19,000 +was typing in on a good website. + +95 +00:05:19,000 --> 00:05:23,000 +You're not going to allow people to put open tag, close tag, semicolons. + +96 +00:05:23,000 --> 00:05:27,000 +There's no need for that, especially in a search box that they should be searching for text anyhow. + +97 +00:05:27,000 --> 00:05:29,000 +So you can eliminate you can say, don't put that in. + +98 +00:05:29,000 --> 00:05:32,000 +Maybe you don't want numbers in there or something like that. + +99 +00:05:32,000 --> 00:05:36,000 +And this is going to stop a lot of these kinds of cross site scripting from occurring. + +100 +00:05:36,000 --> 00:05:39,000 +So if you have a web application that is out there. + +101 +00:05:40,000 --> 00:05:45,000 +Keep in mind that all web applications are subject to cross-site scripting attacks. + +102 +00:05:45,000 --> 00:05:48,000 +The best way to stop them is input validation. + diff --git a/05 - Vulnerabilities/008 Hardware Vulnerabilities OB 2.3_en.srt b/05 - Vulnerabilities/008 Hardware Vulnerabilities OB 2.3_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..87ba71a650e5c46a4785f53fe05cddb07a064c55 --- /dev/null +++ b/05 - Vulnerabilities/008 Hardware Vulnerabilities OB 2.3_en.srt @@ -0,0 +1,268 @@ +1 +00:00:00,000 --> 00:00:05,000 +A lot of times when thinking about vulnerabilities, a lot of people just automatically think of software + +2 +00:00:05,000 --> 00:00:08,000 +vulnerabilities like some of the ones I've shown you earlier. + +3 +00:00:08,000 --> 00:00:11,000 +But there are also hardware vulnerabilities. + +4 +00:00:11,000 --> 00:00:14,000 +Hard hardware is what that software is going to run on. + +5 +00:00:14,000 --> 00:00:16,000 +Let's take a look at three of them in particular. + +6 +00:00:16,000 --> 00:00:19,000 +One of them is firmware vulnerabilities. + +7 +00:00:19,000 --> 00:00:22,000 +This is weaknesses in the low level software that runs on a hardware. + +8 +00:00:22,000 --> 00:00:25,000 +All devices have a firmware. + +9 +00:00:25,000 --> 00:00:28,000 +So like on windows we have our Bios, right. + +10 +00:00:28,000 --> 00:00:34,000 +And in there that's going to tell basically the operating system how to interact with the actual hardware + +11 +00:00:34,000 --> 00:00:35,000 +itself. + +12 +00:00:35,000 --> 00:00:42,000 +Now, one of the worst things that can happen is when you download firmware from manufacturers that + +13 +00:00:42,000 --> 00:00:43,000 +you don't know. + +14 +00:00:44,000 --> 00:00:49,000 +This firmware, let's say right now on this computer is a custom built machine we use to make these + +15 +00:00:49,000 --> 00:00:50,000 +videos. + +16 +00:00:50,000 --> 00:00:53,000 +And this machine runs on an Asus motherboard. + +17 +00:00:53,000 --> 00:00:57,000 +On there is a firmware from Asus, the makers of the motherboard. + +18 +00:00:57,000 --> 00:01:02,000 +Now, if I want to update the particular firmware on this particular motherboard, I should be going + +19 +00:01:02,000 --> 00:01:05,000 +to Asus and taking the firmware from them. + +20 +00:01:06,000 --> 00:01:08,000 +And then I can update the motherboard. + +21 +00:01:08,000 --> 00:01:13,000 +But what if you get an email from that looks like Asus and says, hey man, we just released this new + +22 +00:01:13,000 --> 00:01:18,000 +great firmware that's going to allow you to put better processors and memory into this machine, install + +23 +00:01:18,000 --> 00:01:20,000 +this, you install it before you know it. + +24 +00:01:20,000 --> 00:01:24,000 +The firmware itself is a is a virus infects and breaks the machine. + +25 +00:01:25,000 --> 00:01:30,000 +Also, there are times when firmware have or has been hacked. + +26 +00:01:30,000 --> 00:01:35,000 +This firmware has been sitting in this machine now for about six months. + +27 +00:01:35,000 --> 00:01:37,000 +In other words, we haven't updated it in six months. + +28 +00:01:38,000 --> 00:01:42,000 +This is a problem because what if Asus has. + +29 +00:01:42,000 --> 00:01:47,000 +What if there was some kind of vulnerability found in the firmware on this particular motherboard? + +30 +00:01:47,000 --> 00:01:52,000 +In that situation, this machine is vulnerable to whatever that hack is. + +31 +00:01:52,000 --> 00:01:57,000 +I would need to go and get that particular newest firmware that Asus has released to install it. + +32 +00:01:57,000 --> 00:01:59,000 +So keep that in mind. + +33 +00:01:59,000 --> 00:02:04,000 +Be careful where you get the firmware from, and ensure that you always have the latest firmware running + +34 +00:02:04,000 --> 00:02:08,000 +on your devices, especially in high secure network environments. + +35 +00:02:08,000 --> 00:02:10,000 +The other one is going to be end of life hardware. + +36 +00:02:11,000 --> 00:02:13,000 +So let's say this firewall. + +37 +00:02:13,000 --> 00:02:18,000 +Now, we had an older sonicwall device that we had to replace. + +38 +00:02:18,000 --> 00:02:22,000 +I love Sonicwall, it's one of my favorite small business firewall. + +39 +00:02:22,000 --> 00:02:24,000 +They're really easy to use and configure. + +40 +00:02:24,000 --> 00:02:27,000 +And because of that and they're cheap too. + +41 +00:02:27,000 --> 00:02:28,000 +Relatively cheap. + +42 +00:02:28,000 --> 00:02:30,000 +I mean, this one is about six, 700 bucks. + +43 +00:02:30,000 --> 00:02:32,000 +I think this one was um. + +44 +00:02:33,000 --> 00:02:34,000 +We have to stop using it. + +45 +00:02:34,000 --> 00:02:35,000 +Why? + +46 +00:02:35,000 --> 00:02:37,000 +Because it basically reached its end of life. + +47 +00:02:37,000 --> 00:02:43,000 +And that means that what happens is sonicwall stop pushing out updates to the device. + +48 +00:02:43,000 --> 00:02:44,000 +Sonicwall. + +49 +00:02:44,000 --> 00:02:49,000 +Just like in windows, when windows reaches its end of life, they say, you can't use this anymore. + +50 +00:02:49,000 --> 00:02:50,000 +We're not going to be pushing out updates. + +51 +00:02:50,000 --> 00:02:52,000 +It's the same concept here. + +52 +00:02:53,000 --> 00:02:58,000 +Eventually, this device will reach its end of life and Sonicwall will not be pushing out updates to + +53 +00:02:58,000 --> 00:02:59,000 +it anymore. + +54 +00:02:59,000 --> 00:03:03,000 +Now, generally this in software, it takes a long time and so does hardware. + +55 +00:03:03,000 --> 00:03:08,000 +Sometimes it'll take ten years after the hardware comes out for it to reach an end of life. + +56 +00:03:08,000 --> 00:03:11,000 +And what that means is that it's no longer supported. + +57 +00:03:11,000 --> 00:03:16,000 +So if there's a vulnerability against it, there's no patches for it, and you will remain vulnerable + +58 +00:03:16,000 --> 00:03:18,000 +to those to those threats. + +59 +00:03:19,000 --> 00:03:20,000 +Legacy hardware. + +60 +00:03:20,000 --> 00:03:25,000 +This is going to go with the end of life older hardware that may not be compatible. + +61 +00:03:25,000 --> 00:03:29,000 +There's a lot of old hardware that people may be using that just doesn't support the level of encryption + +62 +00:03:29,000 --> 00:03:31,000 +that you may want. + +63 +00:03:31,000 --> 00:03:37,000 +For example, you may have a really old, old wireless router that doesn't support Wpa2 or three. + +64 +00:03:37,000 --> 00:03:40,000 +It only supports WEP, which is easily cracked. + +65 +00:03:40,000 --> 00:03:43,000 +So you want to make sure that you always stay updated. + +66 +00:03:43,000 --> 00:03:48,000 +You don't want to use legacy hardware or end of life hardware, and always make sure your firmware are + +67 +00:03:48,000 --> 00:03:52,000 +always updated to mitigate any kind of hardware threats. + diff --git a/05 - Vulnerabilities/009 VM Vulnerabilities OB 2.3_en.srt b/05 - Vulnerabilities/009 VM Vulnerabilities OB 2.3_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..47f5bd1bb6f286e42c33c92c89af2d11344fc734 --- /dev/null +++ b/05 - Vulnerabilities/009 VM Vulnerabilities OB 2.3_en.srt @@ -0,0 +1,244 @@ +1 +00:00:00,000 --> 00:00:07,000 +One of the most common things we're going to be doing in it today is virtualizing lots and lots of servers, + +2 +00:00:07,000 --> 00:00:11,000 +different kinds of workstations to run different kinds of applications. + +3 +00:00:11,000 --> 00:00:16,000 +Now virtualization is massive, and if you haven't played with it, I don't know what you're doing. + +4 +00:00:17,000 --> 00:00:18,000 +Virtualization. + +5 +00:00:18,000 --> 00:00:24,000 +You guys should have all downloaded things like VirtualBox and install different operating system from + +6 +00:00:24,000 --> 00:00:26,000 +Windows 10, Windows 11. + +7 +00:00:26,000 --> 00:00:28,000 +You guys should have installed different versions of Linux. + +8 +00:00:28,000 --> 00:00:31,000 +Kali Linux my favorite one. + +9 +00:00:31,000 --> 00:00:35,000 +Uh, Red Hat Linux, whatever you want on ubuntu and whatever. + +10 +00:00:35,000 --> 00:00:37,000 +Hopefully you guys did your A+. + +11 +00:00:37,000 --> 00:00:41,000 +If you did your A+ with me, you saw I use a lot of virtualization. + +12 +00:00:41,000 --> 00:00:44,000 +Now in this course I'm not going to get into how to install virtualization. + +13 +00:00:44,000 --> 00:00:49,000 +Hopefully you did your A+ and if you did it with me, I did a lot of hands on in that course with that. + +14 +00:00:49,000 --> 00:00:52,000 +But today I want to show you guys something interesting. + +15 +00:00:52,000 --> 00:00:56,000 +And that's going to be virtualization vulnerabilities. + +16 +00:00:56,000 --> 00:01:00,000 +And there's two kinds of vulnerabilities that we want to talk about. + +17 +00:01:00,000 --> 00:01:02,000 +And I'll show you somewhat of an example of what I'm talking about. + +18 +00:01:02,000 --> 00:01:07,000 +And the first one that you should be familiar with is something we call VM escape. + +19 +00:01:07,000 --> 00:01:13,000 +This is when an attacker runs code on a VM, which allows them to break out and interact with the whole + +20 +00:01:13,000 --> 00:01:14,000 +system. + +21 +00:01:14,000 --> 00:01:21,000 +So basically they're in the VM, but the code that they're running allows them to get out of that VM + +22 +00:01:21,000 --> 00:01:26,000 +because the VM maybe doesn't have access or shouldn't have access to the actual physical box that it's + +23 +00:01:26,000 --> 00:01:27,000 +sitting on. + +24 +00:01:27,000 --> 00:01:30,000 +It gets out and it's then executed on the host machine. + +25 +00:01:30,000 --> 00:01:33,000 +And another one is going to be resource reuse, which is sensitive. + +26 +00:01:33,000 --> 00:01:38,000 +Data can remain in the system's resources and accessed by other processes. + +27 +00:01:38,000 --> 00:01:43,000 +So for example, things that are stored in memory that the VM can then access. + +28 +00:01:43,000 --> 00:01:48,000 +Now I want to show you guys in particularly the famous one is called a VM escape. + +29 +00:01:49,000 --> 00:01:50,000 +So VM escape. + +30 +00:01:51,000 --> 00:01:53,000 +I want to show you this. + +31 +00:01:53,000 --> 00:01:57,000 +So here I have a Windows 10 virtual machine. + +32 +00:01:58,000 --> 00:01:58,000 +All right. + +33 +00:01:58,000 --> 00:02:00,000 +This is a Windows 10 virtual machine. + +34 +00:02:00,000 --> 00:02:04,000 +And the big obviously the big blue thing behind it is the host that it's sitting on, not the Windows + +35 +00:02:04,000 --> 00:02:05,000 +10 box. + +36 +00:02:05,000 --> 00:02:08,000 +Andrew does not like Windows 11. + +37 +00:02:08,000 --> 00:02:09,000 +I hate it with a passion. + +38 +00:02:09,000 --> 00:02:11,000 +I really hate that operating system. + +39 +00:02:11,000 --> 00:02:16,000 +So in none of my videos will you ever see me use Windows 11 until Microsoft forces it on me. + +40 +00:02:16,000 --> 00:02:18,000 +Now I want to show you guys this. + +41 +00:02:18,000 --> 00:02:19,000 +Check this out. + +42 +00:02:20,000 --> 00:02:31,000 +So VM escape would be, let's say, on this virtual machine that you guys see here, somebody executes + +43 +00:02:31,000 --> 00:02:35,000 +a code like an application on this machine. + +44 +00:02:35,000 --> 00:02:38,000 +Let's say this putty putty is a SSH thing. + +45 +00:02:38,000 --> 00:02:43,000 +But just let's say somebody opens this, this is some kind of a malicious application. + +46 +00:02:43,000 --> 00:02:44,000 +They open it. + +47 +00:02:44,000 --> 00:02:49,000 +And when they run this particular application, this application is infected with malware. + +48 +00:02:49,000 --> 00:02:56,000 +VM escape is generally going to occur when this malicious application that we run executes within the + +49 +00:02:56,000 --> 00:03:03,000 +VM, but then infects the host, the machine behind it with malicious software. + +50 +00:03:03,000 --> 00:03:05,000 +So that's considered a VM escape. + +51 +00:03:05,000 --> 00:03:10,000 +In other words, the malicious code is escaping the virtual machine and infecting the host. + +52 +00:03:10,000 --> 00:03:14,000 +Now, what can we do to stop this? + +53 +00:03:14,000 --> 00:03:14,000 +Right? + +54 +00:03:15,000 --> 00:03:17,000 +The way to stop this is updates most. + +55 +00:03:17,000 --> 00:03:20,000 +Most of the time this updates most of the time. + +56 +00:03:20,000 --> 00:03:29,000 +This occurs when the VM software is outdated and the malicious code is taking advantage of that outdated + +57 +00:03:29,000 --> 00:03:32,000 +unpatched virtual virtualization software. + +58 +00:03:32,000 --> 00:03:36,000 +Maybe you're using a really old version of VirtualBox, maybe using a really old version of VMware, + +59 +00:03:36,000 --> 00:03:42,000 +for example, that allows these codes to be executed and escape the VM. + +60 +00:03:42,000 --> 00:03:47,000 +So keep in mind, guys, not because you're using a VM doesn't mean you're 100% secure, because VM + +61 +00:03:47,000 --> 00:03:51,000 +escape is a real thing and occurs quite often in corporate environments. + diff --git a/05 - Vulnerabilities/010 Cloud-specific Vulnerabilities OB 2.3_en.srt b/05 - Vulnerabilities/010 Cloud-specific Vulnerabilities OB 2.3_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..858ae5c7bbc9c11305afd57830234698a745b06e --- /dev/null +++ b/05 - Vulnerabilities/010 Cloud-specific Vulnerabilities OB 2.3_en.srt @@ -0,0 +1,484 @@ +1 +00:00:00,000 --> 00:00:07,000 +Did you know that right now, as you're sitting watching me, your private data is stored in multiple + +2 +00:00:07,000 --> 00:00:09,000 +instances in the cloud. + +3 +00:00:09,000 --> 00:00:10,000 +The. + +4 +00:00:10,000 --> 00:00:11,000 +Let me ask you guys a question. + +5 +00:00:11,000 --> 00:00:18,000 +Do you store your, uh, Social Security number or credit card information addresses in the cloud? + +6 +00:00:18,000 --> 00:00:21,000 +Do you do that if you're probably saying, nah, I don't use the cloud, I don't store any of that. + +7 +00:00:21,000 --> 00:00:27,000 +Well, you whether you know it or not, your data is in multiple instances in the cloud. + +8 +00:00:27,000 --> 00:00:33,000 +For example, if you shop on Amazon, where do you think Amazon stores your data in the Amazon Web Services + +9 +00:00:33,000 --> 00:00:35,000 +or the Amazon cloud? + +10 +00:00:35,000 --> 00:00:40,000 +That alone, a lot of doctor's offices and medical offices that uses web application. + +11 +00:00:40,000 --> 00:00:45,000 +All your medical information is in some instance in the Amazon cloud. + +12 +00:00:46,000 --> 00:00:52,000 +Use Dropbox, put your private pictures, put some important documents in your Dropbox or your Google + +13 +00:00:52,000 --> 00:00:53,000 +Drive. + +14 +00:00:53,000 --> 00:00:55,000 +That's all in Google's cloud or AWS. + +15 +00:00:55,000 --> 00:00:57,000 +And this doesn't stop. + +16 +00:00:57,000 --> 00:01:04,000 +Cloud is here to stay, and it's what all organizations I'm I can't think of a single organization unless + +17 +00:01:04,000 --> 00:01:06,000 +they're just using paper that just doesn't use a cloud. + +18 +00:01:06,000 --> 00:01:08,000 +You use a device today, use a phone. + +19 +00:01:08,000 --> 00:01:09,000 +You're using a cloud. + +20 +00:01:11,000 --> 00:01:14,000 +If you have a Dropbox account that's in AWS, that means your credit card number is there too. + +21 +00:01:14,000 --> 00:01:21,000 +Anyhow, the point of this video is to talk about these cloud vulnerabilities because don't think that + +22 +00:01:21,000 --> 00:01:23,000 +the cloud doesn't have vulnerabilities. + +23 +00:01:23,000 --> 00:01:25,000 +It has quite a few vulnerabilities. + +24 +00:01:25,000 --> 00:01:31,000 +You see, there's what's called on prem and off prem on premises, off premises. + +25 +00:01:31,000 --> 00:01:39,000 +This machine that I have on this desk, this machine has a hard drive that's storing data for the organization + +26 +00:01:39,000 --> 00:01:39,000 +on it. + +27 +00:01:39,000 --> 00:01:47,000 +This machine is considered on prem, but off prem is we use AWS to have storage there. + +28 +00:01:47,000 --> 00:01:49,000 +We do store data in AWS. + +29 +00:01:49,000 --> 00:01:52,000 +That means that we have on prem and off prem now. + +30 +00:01:53,000 --> 00:01:55,000 +This is really like a hybrid environment. + +31 +00:01:55,000 --> 00:01:56,000 +Some of the data is here. + +32 +00:01:56,000 --> 00:02:00,000 +Some of the data is on this desktop here and some of it is in the cloud. + +33 +00:02:00,000 --> 00:02:04,000 +But because data is in the cloud, it brings a ton of vulnerability. + +34 +00:02:04,000 --> 00:02:11,000 +You see, when data is on prem like I have with this computer right here, when data is on prem, I + +35 +00:02:11,000 --> 00:02:13,000 +control all access to the information. + +36 +00:02:13,000 --> 00:02:19,000 +For you to steal this data, you have to be in this network or you actually have to break it, break + +37 +00:02:19,000 --> 00:02:21,000 +through the firewall to get to it. + +38 +00:02:21,000 --> 00:02:25,000 +And of course you have to get there or you can get to the physical box. + +39 +00:02:25,000 --> 00:02:29,000 +When data is in the cloud, basically you can access the data anywhere in the world. + +40 +00:02:29,000 --> 00:02:32,000 +But that opens a whole new can of worms, doesn't it? + +41 +00:02:32,000 --> 00:02:39,000 +Because if I can access my data anywhere in the world, technically that means you could too. + +42 +00:02:40,000 --> 00:02:41,000 +What's stopping you, though? + +43 +00:02:42,000 --> 00:02:45,000 +Well, different kinds of authentication. + +44 +00:02:45,000 --> 00:02:46,000 +Do you know my username? + +45 +00:02:46,000 --> 00:02:47,000 +Do you know my password? + +46 +00:02:47,000 --> 00:02:49,000 +Is it a multi-factor authentication? + +47 +00:02:49,000 --> 00:02:50,000 +Let's take a look at this list here. + +48 +00:02:50,000 --> 00:02:56,000 +So I have a list of cloud specific vulnerabilities on the cloud. + +49 +00:02:57,000 --> 00:02:59,000 +First thing up is data breaches. + +50 +00:02:59,000 --> 00:03:01,000 +This is a very common thing. + +51 +00:03:01,000 --> 00:03:06,000 +Way too often does hackers get into cloud systems. + +52 +00:03:06,000 --> 00:03:08,000 +And what are they going to do? + +53 +00:03:08,000 --> 00:03:13,000 +They're going to breach weak credentials, weak authentication, inadequate credential management, + +54 +00:03:13,000 --> 00:03:19,000 +people using weak passwords, people being phished or socially engineered to give up passwords. + +55 +00:03:19,000 --> 00:03:22,000 +They're going to go into the cloud and steal the data. + +56 +00:03:22,000 --> 00:03:29,000 +So exposing sensitive data right out of the cloud, sometimes it's insecure interfaces and APIs. + +57 +00:03:29,000 --> 00:03:30,000 +Let me stop right there. + +58 +00:03:30,000 --> 00:03:31,000 +What is an API? + +59 +00:03:31,000 --> 00:03:33,000 +The cloud is well known for APIs. + +60 +00:03:34,000 --> 00:03:37,000 +I want to show you guys before we move on, let me cover what APIs are. + +61 +00:03:38,000 --> 00:03:43,000 +So an API stands for Application Programming Interface for example. + +62 +00:03:43,000 --> 00:03:44,000 +You know what let me check the weather. + +63 +00:03:44,000 --> 00:03:46,000 +Do I have my phone on me? + +64 +00:03:46,000 --> 00:03:47,000 +Let me check the weather. + +65 +00:03:47,000 --> 00:03:48,000 +Hold on a second. + +66 +00:03:48,000 --> 00:03:48,000 +Hold on. + +67 +00:03:48,000 --> 00:03:49,000 +I need to check. + +68 +00:03:49,000 --> 00:03:50,000 +It's really important. + +69 +00:03:50,000 --> 00:03:51,000 +Don't stop the video, I need to. + +70 +00:03:52,000 --> 00:03:53,000 +I want to show you the weather too. + +71 +00:03:53,000 --> 00:03:55,000 +So I'm looking at the weather. + +72 +00:03:55,000 --> 00:04:00,000 +And I live in Long Island, New York, and it's telling me I don't want to show you where I am. + +73 +00:04:00,000 --> 00:04:04,000 +It's telling me it's 59, 58 degrees. + +74 +00:04:05,000 --> 00:04:06,000 +Did you get the weather? + +75 +00:04:07,000 --> 00:04:10,000 +You say, Andrew, why do we need to know the weather well? + +76 +00:04:11,000 --> 00:04:19,000 +This weather is not coming from this phone, this weather, if you notice it. + +77 +00:04:19,000 --> 00:04:22,000 +I know you guys can't see that, but it says the Weather Channel on the bottom. + +78 +00:04:22,000 --> 00:04:24,000 +I don't know if this is going to show it on the screen. + +79 +00:04:24,000 --> 00:04:25,000 +Maybe you zoom in on it. + +80 +00:04:25,000 --> 00:04:26,000 +It says Weather Channel. + +81 +00:04:27,000 --> 00:04:31,000 +This is important not because actually of the weather but because of this watch. + +82 +00:04:31,000 --> 00:04:36,000 +So you have an application, the app on the phone, the weather app. + +83 +00:04:36,000 --> 00:04:39,000 +Right, the weather app on your phone. + +84 +00:04:40,000 --> 00:04:45,000 +And then there is the Weather Channel, the actual host of the information. + +85 +00:04:45,000 --> 00:04:50,000 +So the Weather Channel keeps all the weather for all people all around us. + +86 +00:04:50,000 --> 00:04:56,000 +How does this application gain access to the Weather Channel's database? + +87 +00:04:57,000 --> 00:04:58,000 +Did you say API? + +88 +00:04:58,000 --> 00:04:59,000 +Did you say that? + +89 +00:04:59,000 --> 00:04:59,000 +Then? + +90 +00:04:59,000 --> 00:05:00,000 +You're absolutely correct. + +91 +00:05:00,000 --> 00:05:01,000 +API. + +92 +00:05:01,000 --> 00:05:05,000 +API is what connects an application program, interface and API. + +93 +00:05:06,000 --> 00:05:11,000 +The best example that I've ever heard of an API is in a restaurant is the server. + +94 +00:05:11,000 --> 00:05:15,000 +So when you go into a restaurant, there's you that wants the food and there is the cook that makes + +95 +00:05:15,000 --> 00:05:16,000 +the food. + +96 +00:05:16,000 --> 00:05:22,000 +The server is the person that takes the order, takes it to the chef and brings the food back. + +97 +00:05:22,000 --> 00:05:23,000 +Basically an API. + +98 +00:05:23,000 --> 00:05:29,000 +I can get into the specifics of APIs in this particular lessons, but the cloud is basically full of + +99 +00:05:29,000 --> 00:05:30,000 +APIs. + +100 +00:05:31,000 --> 00:05:36,000 +Sometimes these APIs are not coded right there in secure coded. + +101 +00:05:37,000 --> 00:05:42,000 +That could be exploited for people to inject data or steal information. + +102 +00:05:42,000 --> 00:05:43,000 +System vulnerabilities. + +103 +00:05:43,000 --> 00:05:46,000 +The infrastructure itself can be exploited. + +104 +00:05:46,000 --> 00:05:47,000 +Sometimes. + +105 +00:05:47,000 --> 00:05:53,000 +Cloud providers may not be updating their systems using legacy systems that causes it to be exploited. + +106 +00:05:53,000 --> 00:05:54,000 +Account hijacking. + +107 +00:05:54,000 --> 00:06:00,000 +This is used in a variety of different ways and methods to take control of your user account. + +108 +00:06:00,000 --> 00:06:08,000 +So let's say I use Google Cloud, G drive or Google Drive, whatever you want to call it, and you gain + +109 +00:06:08,000 --> 00:06:13,000 +access to my to my Google account using a variety of different ways, whether it's sniffing my data, + +110 +00:06:13,000 --> 00:06:18,000 +such as ears dropping on transactions or whatever is that I'm doing, you gain access to that, then + +111 +00:06:18,000 --> 00:06:19,000 +you can see all my data. + +112 +00:06:21,000 --> 00:06:27,000 +Yes, the cloud is here to stay and the cloud is only getting bigger as I make this video. + +113 +00:06:27,000 --> 00:06:34,000 +But over time, I should say, and over time, the attacks will get more sophisticated and complex. + +114 +00:06:34,000 --> 00:06:40,000 +Never have the sense, the false belief that because my data is in the cloud, it is secure. + +115 +00:06:41,000 --> 00:06:43,000 +Your data in the cloud is not secure. + +116 +00:06:43,000 --> 00:06:45,000 +You have to take good security measurement measures. + +117 +00:06:45,000 --> 00:06:48,000 +You can't have weak passwords. + +118 +00:06:48,000 --> 00:06:50,000 +You have to use good application programming interface. + +119 +00:06:50,000 --> 00:06:52,000 +You have to train your users on it. + +120 +00:06:52,000 --> 00:06:54,000 +The cloud is not all mighty secure. + +121 +00:06:55,000 --> 00:07:01,000 +Vulnerabilities can exist within AWS themselves, so keep this in mind as we use cloud computing. + diff --git a/05 - Vulnerabilities/011 Supply Chain Vulnerabilities OB 2.3_en.srt b/05 - Vulnerabilities/011 Supply Chain Vulnerabilities OB 2.3_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..67b049cd960cdc99317b281940d0ce5c628f8904 --- /dev/null +++ b/05 - Vulnerabilities/011 Supply Chain Vulnerabilities OB 2.3_en.srt @@ -0,0 +1,384 @@ +1 +00:00:00,000 --> 00:00:00,000 +Okay. + +2 +00:00:00,000 --> 00:00:05,000 +When you're thinking of about vulnerabilities, one type of vulnerabilities that a lot of people don't + +3 +00:00:05,000 --> 00:00:08,000 +think about is the supply chain vulnerability. + +4 +00:00:08,000 --> 00:00:10,000 +But what exactly is a supply chain? + +5 +00:00:10,000 --> 00:00:11,000 +Well, take a look at this. + +6 +00:00:11,000 --> 00:00:17,000 +Well, you see, in order to create this particular device that I have in my hands, it takes quite + +7 +00:00:17,000 --> 00:00:18,000 +a lot of supplies. + +8 +00:00:18,000 --> 00:00:21,000 +First of all, it's metal. + +9 +00:00:21,000 --> 00:00:23,000 +You also have plastic within it. + +10 +00:00:23,000 --> 00:00:26,000 +You have silicone because there's a chip inside of it. + +11 +00:00:26,000 --> 00:00:32,000 +There is all kinds of different metals, not just steel, but they may be aluminum for the pins inside + +12 +00:00:32,000 --> 00:00:34,000 +of the ports here there's also plastic. + +13 +00:00:34,000 --> 00:00:37,000 +So a supply chain is basically this. + +14 +00:00:37,000 --> 00:00:46,000 +How do you take raw materials, raw iron ore coming out of the earth and manufacturing it, refining + +15 +00:00:46,000 --> 00:00:53,000 +it, giving it over to people like Sonicwall or Dell for them to then use it, mold it, created, program + +16 +00:00:53,000 --> 00:00:58,000 +it basically from the raw materials to the finished product. + +17 +00:00:58,000 --> 00:00:59,000 +Think about that for a second. + +18 +00:00:59,000 --> 00:01:04,000 +The raw materials to the finished product from the stuff coming out of the earth to what I'm holding + +19 +00:01:04,000 --> 00:01:05,000 +in my hands. + +20 +00:01:06,000 --> 00:01:07,000 +This is a supply chain. + +21 +00:01:07,000 --> 00:01:14,000 +It's a chain of different things so that raw materials will be taken out of the earth and mined into + +22 +00:01:14,000 --> 00:01:17,000 +different kinds of metals, such as steel or aluminum. + +23 +00:01:17,000 --> 00:01:23,000 +And then that is then produced, given over to somebody else, that somebody else will then take it, + +24 +00:01:23,000 --> 00:01:27,000 +mold it, maybe put it into specific, uh, panels, send it to Dell. + +25 +00:01:27,000 --> 00:01:30,000 +Dell cuts it to produce the box. + +26 +00:01:30,000 --> 00:01:35,000 +Then of course, the plastic, the silicone, all the things that it needs to produce this particular + +27 +00:01:35,000 --> 00:01:36,000 +device. + +28 +00:01:37,000 --> 00:01:41,000 +Now, when it comes to vulnerabilities in this particular supply chain, there are things here that + +29 +00:01:41,000 --> 00:01:43,000 +we should be familiar with. + +30 +00:01:44,000 --> 00:01:45,000 +The first thing up. + +31 +00:01:45,000 --> 00:01:45,000 +Oops. + +32 +00:01:45,000 --> 00:01:52,000 +The first thing up that we that we want to know is that a supply chain is really a complex network of + +33 +00:01:52,000 --> 00:01:58,000 +suppliers that will be producing and distribution of IT products and services. + +34 +00:01:58,000 --> 00:02:03,000 +And there's basically three we're going to talk about the service provider, hardware providers and + +35 +00:02:03,000 --> 00:02:08,000 +service providers, hardware providers and software providers, because those are going to be the three + +36 +00:02:08,000 --> 00:02:10,000 +main suppliers that we deal with. + +37 +00:02:10,000 --> 00:02:16,000 +We have service providers that basically deliver IT services, such as cloud computing like AWS. + +38 +00:02:16,000 --> 00:02:21,000 +You have hardware providers that you're going to use to purchase hardware, like I did from Dell with + +39 +00:02:21,000 --> 00:02:22,000 +the Sonicwall. + +40 +00:02:22,000 --> 00:02:26,000 +And then you have software providers that I did for purchasing Microsoft Windows. + +41 +00:02:26,000 --> 00:02:32,000 +So those are going to be the three suppliers that we as IT professionals will deal with. + +42 +00:02:32,000 --> 00:02:35,000 +So let's get let's see some of the uh, vulnerabilities. + +43 +00:02:35,000 --> 00:02:37,000 +So first of all is your service provider. + +44 +00:02:37,000 --> 00:02:42,000 +So service providers are going to be folks that deliver quote unquote services like cloud computing, + +45 +00:02:42,000 --> 00:02:45,000 +data storages, even networking services. + +46 +00:02:45,000 --> 00:02:47,000 +For example, Verizon gives us internet. + +47 +00:02:48,000 --> 00:02:55,000 +This is a main security concern is that when it comes to service providers, is that they themselves + +48 +00:02:55,000 --> 00:02:56,000 +could be breached. + +49 +00:02:56,000 --> 00:02:57,000 +Think about this. + +50 +00:02:58,000 --> 00:03:00,000 +AWS seems secure. + +51 +00:03:00,000 --> 00:03:01,000 +Right. + +52 +00:03:01,000 --> 00:03:05,000 +Amazon has great security, but Amazon themselves could be breached. + +53 +00:03:05,000 --> 00:03:10,000 +Amazon can have, um, vulnerabilities within their cloud based systems. + +54 +00:03:10,000 --> 00:03:12,000 +You have your data in Amazon. + +55 +00:03:13,000 --> 00:03:16,000 +If Amazon gets a breach today, your data might be stolen. + +56 +00:03:16,000 --> 00:03:18,000 +That's a big vulnerability. + +57 +00:03:18,000 --> 00:03:21,000 +Unfortunately, there's not a lot we can do with these. + +58 +00:03:21,000 --> 00:03:23,000 +We can't go and configure AWS. + +59 +00:03:24,000 --> 00:03:26,000 +I mean configure their actual internal systems. + +60 +00:03:26,000 --> 00:03:28,000 +We can configure our portions of it. + +61 +00:03:28,000 --> 00:03:33,000 +But the infrastructure that runs AWS might be more out of our hands. + +62 +00:03:33,000 --> 00:03:36,000 +So you're saying so Andrew, how do we you know, how are we going to deal with that. + +63 +00:03:36,000 --> 00:03:45,000 +Well AWS has certifications and they have audits that they have to get through in order to be AWS. + +64 +00:03:45,000 --> 00:03:48,000 +We'll talk more about that in the management section of the course. + +65 +00:03:48,000 --> 00:03:54,000 +When we look at different ISO certifications and laws that they have to follow, such as SoC audits. + +66 +00:03:54,000 --> 00:03:57,000 +The other one here that we want to be familiar with is hardware providers. + +67 +00:03:57,000 --> 00:04:03,000 +So hardware providers are people that produce physical devices like servers, routers and chips. + +68 +00:04:03,000 --> 00:04:06,000 +These hardware providers could have an issue. + +69 +00:04:06,000 --> 00:04:08,000 +For example, the hardware could be tampered with. + +70 +00:04:08,000 --> 00:04:15,000 +For example, sometimes the hardware may have embedded malware into the physical hardware. + +71 +00:04:15,000 --> 00:04:24,000 +This may sound odd, but there was an incident where server boards I think was super micro boards coming + +72 +00:04:24,000 --> 00:04:30,000 +out of China had embedded malware to monitor systems. + +73 +00:04:30,000 --> 00:04:31,000 +This was a known thing. + +74 +00:04:31,000 --> 00:04:33,000 +So that has happened before. + +75 +00:04:33,000 --> 00:04:36,000 +So don't think because it's a piece of hardware it can't have. + +76 +00:04:36,000 --> 00:04:39,000 +Remember, every piece of computer hardware has a firmware in it. + +77 +00:04:39,000 --> 00:04:44,000 +And because there's that hardware firmware, there is a probability of malware being in that firmware + +78 +00:04:44,000 --> 00:04:46,000 +coming from the manufacturer. + +79 +00:04:46,000 --> 00:04:50,000 +Sometimes the manufacturer may not even know that their systems are being infected. + +80 +00:04:50,000 --> 00:04:53,000 +Then comes software providers think Microsoft, right? + +81 +00:04:53,000 --> 00:04:58,000 +They produce operating systems, they produce the Microsoft Office applications, and even the firmware + +82 +00:04:58,000 --> 00:05:04,000 +that comes onto your hardware security vulnerabilities is that these things could be exploited. + +83 +00:05:04,000 --> 00:05:05,000 +An operating system. + +84 +00:05:05,000 --> 00:05:09,000 +I'll tell you guys right now, the operating if you go and you purchase windows in a store. + +85 +00:05:10,000 --> 00:05:15,000 +Let's say you get a USB stick or DVD or whatever and you install it. + +86 +00:05:15,000 --> 00:05:19,000 +That operating system is vulnerable because it's not fully updated. + +87 +00:05:19,000 --> 00:05:23,000 +Microsoft release updates basically on a weekly basis for their products. + +88 +00:05:23,000 --> 00:05:26,000 +So that is already full of vulnerabilities. + +89 +00:05:27,000 --> 00:05:27,000 +Okay. + +90 +00:05:27,000 --> 00:05:29,000 +So don't think that because. + +91 +00:05:30,000 --> 00:05:33,000 +You purchase something off the shelf, it's it's going to be secure. + +92 +00:05:33,000 --> 00:05:34,000 +It's not. + +93 +00:05:34,000 --> 00:05:39,000 +You have to know that there are vulnerabilities throughout the entire supply chain. + +94 +00:05:39,000 --> 00:05:42,000 +These vulnerabilities can bring down an entire supply chain. + +95 +00:05:42,000 --> 00:05:48,000 +So keep that in mind when you're looking at all the different products and services we use to maintain + +96 +00:05:48,000 --> 00:05:49,000 +IT services. + diff --git a/05 - Vulnerabilities/012 Cryptographic Vulnerabilities OB 2.3_en.srt b/05 - Vulnerabilities/012 Cryptographic Vulnerabilities OB 2.3_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..5ccb7af9f6c9b15e62a4e4e2809bac48a0ba05c7 --- /dev/null +++ b/05 - Vulnerabilities/012 Cryptographic Vulnerabilities OB 2.3_en.srt @@ -0,0 +1,284 @@ +1 +00:00:00,000 --> 00:00:06,000 +One of the most common security control that we apply to keep our data secure is encryption. + +2 +00:00:06,000 --> 00:00:09,000 +We use encryption all the time. + +3 +00:00:09,000 --> 00:00:14,000 +You go to any website basically on today's internet, and you purchase something. + +4 +00:00:14,000 --> 00:00:16,000 +It's fully encrypted with TLS. + +5 +00:00:17,000 --> 00:00:22,000 +Now, they are vulnerabilities in these forms of encryption, and we should be familiar with it, not + +6 +00:00:22,000 --> 00:00:28,000 +because somebody says, well, it's encrypted means that there's no vulnerability, and there's no way + +7 +00:00:28,000 --> 00:00:33,000 +people stealing this information because they are vulnerabilities against encryption. + +8 +00:00:33,000 --> 00:00:35,000 +And there's more than what you can think. + +9 +00:00:35,000 --> 00:00:40,000 +So this is generally going to be referred to the weaknesses within the cryptographic algorithms or their + +10 +00:00:40,000 --> 00:00:42,000 +implementation is really what's going to happen. + +11 +00:00:42,000 --> 00:00:50,000 +One of the most easiest one to understand is when providers uses weak algorithms. + +12 +00:00:50,000 --> 00:00:56,000 +So in the cryptographic section you're going to learn of an algorithm called Des, the Data Encryption + +13 +00:00:56,000 --> 00:00:56,000 +Standard. + +14 +00:00:56,000 --> 00:01:04,000 +So Des is a very old algorithm that the United States government pretty much made a standard 1970s or + +15 +00:01:04,000 --> 00:01:12,000 +80s, and it was used up until about around 1998 99, when Des was officially cracked. + +16 +00:01:12,000 --> 00:01:15,000 +In other words, they were able to guess pretty much the keys. + +17 +00:01:15,000 --> 00:01:20,000 +Now, there are systems out there that can still use Des. + +18 +00:01:20,000 --> 00:01:23,000 +They are software that can still use Des. + +19 +00:01:23,000 --> 00:01:31,000 +So for example, if somebody encrypts your data across the internet using Des, they can say, hey, + +20 +00:01:31,000 --> 00:01:34,000 +your data is encrypted and you're like, oh, great. + +21 +00:01:34,000 --> 00:01:36,000 +So I'm not don't worry about it, right? + +22 +00:01:36,000 --> 00:01:37,000 +Not really. + +23 +00:01:37,000 --> 00:01:42,000 +Because if that encrypted using Des, it is 100% crackable. + +24 +00:01:42,000 --> 00:01:44,000 +So it's not very secure now is it? + +25 +00:01:44,000 --> 00:01:48,000 +As a security professional, you're just not going to. + +26 +00:01:49,000 --> 00:01:51,000 +Say, oh, it's encrypted and you're done. + +27 +00:01:51,000 --> 00:01:54,000 +A good security professional to say it's encrypted. + +28 +00:01:54,000 --> 00:01:56,000 +What algorithm are you using? + +29 +00:01:56,000 --> 00:01:59,000 +You know, what security protocol are you using? + +30 +00:01:59,000 --> 00:02:01,000 +That's what you should be asking. + +31 +00:02:01,000 --> 00:02:04,000 +So we know that there's weaknesses within the Des algorithm. + +32 +00:02:04,000 --> 00:02:06,000 +In other words, using ReLU. + +33 +00:02:06,000 --> 00:02:07,000 +And it's not just Des. + +34 +00:02:07,000 --> 00:02:11,000 +There are other, uh, cryptographic algorithms that are crackable. + +35 +00:02:11,000 --> 00:02:14,000 +We'll talk more about that though when we get to the cryptographic section. + +36 +00:02:14,000 --> 00:02:15,000 +Another thing here is key management. + +37 +00:02:15,000 --> 00:02:19,000 +One of the main things with cryptography is the keys. + +38 +00:02:19,000 --> 00:02:20,000 +The key is the secret. + +39 +00:02:20,000 --> 00:02:24,000 +Remember in cryptography the algorithm is public. + +40 +00:02:24,000 --> 00:02:28,000 +We all know we're using a yes to secure our information. + +41 +00:02:28,000 --> 00:02:33,000 +What we don't know is the key that's used to encrypt that particular session. + +42 +00:02:33,000 --> 00:02:35,000 +That's the main secret. + +43 +00:02:35,000 --> 00:02:41,000 +The key is the secret mismanagement of these keys, for example, the key not being generated randomly. + +44 +00:02:41,000 --> 00:02:49,000 +The key is being stored in securely, or the key is being passed in securely can lead to it being compromised. + +45 +00:02:49,000 --> 00:02:50,000 +Remember something? + +46 +00:02:50,000 --> 00:02:51,000 +They guess the key. + +47 +00:02:51,000 --> 00:02:52,000 +They know the key. + +48 +00:02:52,000 --> 00:02:54,000 +They can decrypt all of your information. + +49 +00:02:54,000 --> 00:02:56,000 +Another thing is just poor implementation. + +50 +00:02:56,000 --> 00:03:03,000 +Maybe the guy that's implementing the system misconfigured the system didn't set up the system correctly. + +51 +00:03:03,000 --> 00:03:09,000 +All types of programming errors, maybe even buffer overflows that can exploit and gain information + +52 +00:03:09,000 --> 00:03:10,000 +to the actual machine. + +53 +00:03:12,000 --> 00:03:15,000 +The point of this is that I want you guys to remember something. + +54 +00:03:15,000 --> 00:03:20,000 +Not because somebody says that it's encrypted means that it's secure. + +55 +00:03:20,000 --> 00:03:21,000 +It could be fully encrypted. + +56 +00:03:21,000 --> 00:03:24,000 +Doesn't mean it's secure, right? + +57 +00:03:24,000 --> 00:03:29,000 +You have to question and understand the type of cryptography that's being used. + +58 +00:03:29,000 --> 00:03:31,000 +That's why we have a whole cryptography section. + +59 +00:03:31,000 --> 00:03:40,000 +Because, you see, if your exam didn't want you to know cryptography, then you would never know that + +60 +00:03:40,000 --> 00:03:42,000 +Des is a algorithm that could be cracked. + +61 +00:03:42,000 --> 00:03:43,000 +Now would you? + +62 +00:03:44,000 --> 00:03:50,000 +You see, as security professionals, we don't need and we are not mathematicians to create cryptographic + +63 +00:03:50,000 --> 00:03:50,000 +algorithms. + +64 +00:03:50,000 --> 00:03:57,000 +We are generally not high end programmers to create security and cryptographic protocols such as TLS. + +65 +00:03:57,000 --> 00:04:05,000 +But as security professionals, we do need to understand, hey, AAS is a standard 128 is pretty secure, + +66 +00:04:05,000 --> 00:04:06,000 +but not really. + +67 +00:04:06,000 --> 00:04:06,000 +Not anymore. + +68 +00:04:06,000 --> 00:04:10,000 +We should be using AES 256 as that is secure. + +69 +00:04:10,000 --> 00:04:13,000 +More secure against time than AES 128. + +70 +00:04:13,000 --> 00:04:17,000 +These are things that you should know, and we're going to talk more about that when we get to the crypto, + +71 +00:04:17,000 --> 00:04:20,000 +when we get to the cryptography section. + diff --git a/05 - Vulnerabilities/013 Misconfiguration OB 2.3_en.srt b/05 - Vulnerabilities/013 Misconfiguration OB 2.3_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..4536c796e4e348792e929b478ca4f6ca9931d32a --- /dev/null +++ b/05 - Vulnerabilities/013 Misconfiguration OB 2.3_en.srt @@ -0,0 +1,348 @@ +1 +00:00:00,000 --> 00:00:06,000 +The most important requirement when it comes to working as a technical professional is having good technical + +2 +00:00:06,000 --> 00:00:07,000 +knowledge. + +3 +00:00:07,000 --> 00:00:09,000 +It's knowing what you're doing. + +4 +00:00:09,000 --> 00:00:12,000 +It's being confident that what you're doing is correct. + +5 +00:00:12,000 --> 00:00:17,000 +You see, way too often our systems misconfigured. + +6 +00:00:17,000 --> 00:00:19,000 +That leads to vulnerability. + +7 +00:00:19,000 --> 00:00:28,000 +Way too often our IT professionals configuring firewalls, configuring anti-malware software, configuring + +8 +00:00:28,000 --> 00:00:36,000 +intrusion detection systems, configuring cryptographic uh cryptographic solutions, not knowing exactly + +9 +00:00:36,000 --> 00:00:37,000 +what they're doing. + +10 +00:00:37,000 --> 00:00:39,000 +In fact, they're not too sure of what they're doing. + +11 +00:00:39,000 --> 00:00:45,000 +And what this does is this leads to something we call misconfiguration vulnerabilities. + +12 +00:00:46,000 --> 00:00:49,000 +First of all, this is a very common thing. + +13 +00:00:49,000 --> 00:00:51,000 +Don't think that this doesn't happen a lot. + +14 +00:00:51,000 --> 00:00:54,000 +Technology is not easy to learn. + +15 +00:00:54,000 --> 00:00:59,000 +I have 66 certifications and I could tell you guys I don't know at all. + +16 +00:00:59,000 --> 00:01:04,000 +In fact, I don't think I even know 20% of this industry when it comes to configuration. + +17 +00:01:04,000 --> 00:01:08,000 +Every single time I go to configure something, I have to learn the whole -- thing again. + +18 +00:01:08,000 --> 00:01:11,000 +Technology always changes over time. + +19 +00:01:11,000 --> 00:01:12,000 +So what? + +20 +00:01:12,000 --> 00:01:16,000 +I know within two years it's completely obsolete and I have to learn it again. + +21 +00:01:16,000 --> 00:01:23,000 +And this leads to basically misconfiguration, because if you know how to set up a system one way, + +22 +00:01:23,000 --> 00:01:25,000 +that new system may require a whole different way. + +23 +00:01:25,000 --> 00:01:28,000 +And when I set it up, my old way leads to vulnerabilities. + +24 +00:01:28,000 --> 00:01:33,000 +What are some improper configuration of hardware and software? + +25 +00:01:33,000 --> 00:01:37,000 +Well, one of the one of the worst things we can ever do is default settings. + +26 +00:01:37,000 --> 00:01:40,000 +So default settings is let's say this thing comes right out of the box. + +27 +00:01:40,000 --> 00:01:41,000 +I plug it in. + +28 +00:01:43,000 --> 00:01:49,000 +I connect a, I connect the lan, the the Wang port to the to the router. + +29 +00:01:49,000 --> 00:01:55,000 +I connect a computer, I, I connect a switch to the LAN port, I plug in a few machines and boom, + +30 +00:01:55,000 --> 00:01:56,000 +I start working. + +31 +00:01:56,000 --> 00:01:57,000 +Right. + +32 +00:01:57,000 --> 00:01:57,000 +It starts. + +33 +00:01:57,000 --> 00:01:59,000 +It works right out the box. + +34 +00:02:00,000 --> 00:02:05,000 +And let's say now this one actually doesn't a lot of default settings. + +35 +00:02:05,000 --> 00:02:07,000 +Uh, that stopped a long time ago. + +36 +00:02:07,000 --> 00:02:16,000 +But a lot of times in the early 2000, mid 2000, you could have bought a router, a Linksys, a D-Link. + +37 +00:02:16,000 --> 00:02:17,000 +You plugged it in, boom. + +38 +00:02:17,000 --> 00:02:18,000 +It worked. + +39 +00:02:18,000 --> 00:02:19,000 +Even the wireless worked. + +40 +00:02:19,000 --> 00:02:22,000 +The username was, uh, the wireless was called Linksys. + +41 +00:02:22,000 --> 00:02:24,000 +The username is admin password admin. + +42 +00:02:25,000 --> 00:02:29,000 +Default setting, insecure, no real configuration for it. + +43 +00:02:29,000 --> 00:02:31,000 +And what did security professionals do? + +44 +00:02:31,000 --> 00:02:34,000 +They weren't sure how to configure it, so they left it. + +45 +00:02:34,000 --> 00:02:37,000 +And of course this led to a massive security vulnerability. + +46 +00:02:37,000 --> 00:02:39,000 +So never leave default settings. + +47 +00:02:40,000 --> 00:02:45,000 +Nowadays we're getting good at this because nowadays when you purchase a device and you plug it in, + +48 +00:02:45,000 --> 00:02:46,000 +it doesn't work. + +49 +00:02:46,000 --> 00:02:51,000 +You you're forced to go in and configure it and give it good security settings. + +50 +00:02:51,000 --> 00:02:57,000 +Another thing that's that's left on machines, and I see this way too often is unnecessary services. + +51 +00:02:57,000 --> 00:03:06,000 +A lot of times when you install a lot of these cots, cots notice terme cots commercial off the shelf. + +52 +00:03:06,000 --> 00:03:08,000 +Remember that commercial off the shelf products? + +53 +00:03:08,000 --> 00:03:13,000 +A lot of times you install cots, cots, products you basically buy on a shelf. + +54 +00:03:13,000 --> 00:03:19,000 +It's basically not a custom built product, not a not a product that your company designed and built, + +55 +00:03:19,000 --> 00:03:23,000 +but it's basically a product that you purchase from Dell, HP. + +56 +00:03:23,000 --> 00:03:25,000 +You got it at Staples or Best Buy or whatever. + +57 +00:03:26,000 --> 00:03:31,000 +A lot of times you buy these Cots product, they come with many services enabled. + +58 +00:03:31,000 --> 00:03:36,000 +In fact, when you install windows, just this Windows 10 box, there's a ton of services that I'm not + +59 +00:03:36,000 --> 00:03:37,000 +using. + +60 +00:03:37,000 --> 00:03:41,000 +You see, when you have many services, it increases the attack surface. + +61 +00:03:41,000 --> 00:03:42,000 +Think about this. + +62 +00:03:42,000 --> 00:03:49,000 +If this machine is running 1010 different services to keep windows bare, minimum to keep windows running, + +63 +00:03:49,000 --> 00:03:52,000 +then just those ten services are hacked. + +64 +00:03:52,000 --> 00:03:53,000 +Could be hacked. + +65 +00:03:53,000 --> 00:03:54,000 +But if. + +66 +00:03:55,000 --> 00:03:58,000 +Let's say the machine comes with 200 service services that are running. + +67 +00:03:58,000 --> 00:03:59,000 +A lot of them are not using. + +68 +00:03:59,000 --> 00:04:04,000 +Maybe it has an FTP service running, maybe it has a print spooler running or there's no printer connected + +69 +00:04:04,000 --> 00:04:04,000 +to it. + +70 +00:04:04,000 --> 00:04:05,000 +Then what happens? + +71 +00:04:06,000 --> 00:04:09,000 +Well, now you can hack that the print spooler was hack is hackable. + +72 +00:04:09,000 --> 00:04:14,000 +There's a big hack on that print nightmare windows print nightmare, if you know what that is. + +73 +00:04:14,000 --> 00:04:17,000 +Don't you don't need to know history lesson for this course though. + +74 +00:04:17,000 --> 00:04:24,000 +But for example, if you're not using the printer on a machine like there's no physical printer connected + +75 +00:04:24,000 --> 00:04:26,000 +to your machine, turn that service off. + +76 +00:04:26,000 --> 00:04:30,000 +Disable that particular service so you don't have it. + +77 +00:04:30,000 --> 00:04:32,000 +Inadequate security controls is a common thing. + +78 +00:04:32,000 --> 00:04:36,000 +People just not applying the right firewalls anti-malware to their devices. + +79 +00:04:37,000 --> 00:04:39,000 +Don't think misconfiguration is something that doesn't happen. + +80 +00:04:39,000 --> 00:04:42,000 +It happens more often than you know. + +81 +00:04:42,000 --> 00:04:47,000 +In fact, it's probably happening right now in your organization and you're not even you don't even + +82 +00:04:47,000 --> 00:04:48,000 +know about it. + +83 +00:04:48,000 --> 00:04:49,000 +You're not aware of it. + +84 +00:04:49,000 --> 00:04:52,000 +So a couple of quick tips on this. + +85 +00:04:52,000 --> 00:04:55,000 +I want you guys to make sure to change all default configurations. + +86 +00:04:55,000 --> 00:05:01,000 +And I want you guys to make sure you disable all unneeded services that are out there in order to keep + +87 +00:05:01,000 --> 00:05:04,000 +our devices and our network secure. + diff --git a/05 - Vulnerabilities/014 Mobile Device Vulnerabilities OB 2.3_en.srt b/05 - Vulnerabilities/014 Mobile Device Vulnerabilities OB 2.3_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..d39257137e2d0bc9c869bba62b92551f6238ea77 --- /dev/null +++ b/05 - Vulnerabilities/014 Mobile Device Vulnerabilities OB 2.3_en.srt @@ -0,0 +1,668 @@ +1 +00:00:00,000 --> 00:00:08,000 +One device that has taken over our lives, especially my children's lives, is right here. + +2 +00:00:08,000 --> 00:00:09,000 +Mobile devices. + +3 +00:00:09,000 --> 00:00:15,000 +This is one of the worst things that has ever been made, in my opinion, but it is also one of the + +4 +00:00:15,000 --> 00:00:18,000 +most useful things that has ever been made. + +5 +00:00:18,000 --> 00:00:21,000 +The ability to walk around with a full blown computer. + +6 +00:00:21,000 --> 00:00:26,000 +Now I want before I get into this video, I really want you guys to really analyze what what is on here, + +7 +00:00:26,000 --> 00:00:26,000 +right? + +8 +00:00:26,000 --> 00:00:27,000 +Let's talk about this for a second. + +9 +00:00:27,000 --> 00:00:29,000 +What is on this device? + +10 +00:00:29,000 --> 00:00:31,000 +Well, I'm going to tell you what's on mine. + +11 +00:00:31,000 --> 00:00:32,000 +Maybe you're the same. + +12 +00:00:32,000 --> 00:00:35,000 +My emails my corporate emails all the time. + +13 +00:00:36,000 --> 00:00:36,000 +Emails are here. + +14 +00:00:36,000 --> 00:00:40,000 +So all the companies secret data is on here. + +15 +00:00:40,000 --> 00:00:42,000 +My credit card information is here. + +16 +00:00:42,000 --> 00:00:43,000 +How do I know? + +17 +00:00:43,000 --> 00:00:46,000 +Because I buy stuff from using my phone quite often. + +18 +00:00:46,000 --> 00:00:51,000 +So a lot of my credit card, a lot of the login information to all the different websites that I that + +19 +00:00:51,000 --> 00:00:59,000 +I use, private messages between me and colleagues, me and me and my wife and my children. + +20 +00:00:59,000 --> 00:01:06,000 +Coworker and whatever, uh, pictures, private pictures, family pictures are all here, you know, + +21 +00:01:06,000 --> 00:01:08,000 +now I'm thinking about it. + +22 +00:01:08,000 --> 00:01:15,000 +This device has more confidential information than my desktop. + +23 +00:01:15,000 --> 00:01:16,000 +All right, there's more. + +24 +00:01:16,000 --> 00:01:17,000 +And are you the same? + +25 +00:01:17,000 --> 00:01:20,000 +Would you say you fall into my category? + +26 +00:01:20,000 --> 00:01:25,000 +So this brings me to this video on mobile device vulnerabilities. + +27 +00:01:25,000 --> 00:01:33,000 +Now, we know that the mobile device has a ton of useful information, a ton of secure information that + +28 +00:01:33,000 --> 00:01:35,000 +needs to be secure. + +29 +00:01:35,000 --> 00:01:37,000 +Now the question is, what are some of the vulnerabilities? + +30 +00:01:37,000 --> 00:01:38,000 +And there's quite a lot. + +31 +00:01:40,000 --> 00:01:43,000 +So a couple of mobile device vulnerabilities that we should talk about. + +32 +00:01:43,000 --> 00:01:48,000 +Now remember what this vulnerability is like a weakness on this device that attackers can attack or + +33 +00:01:48,000 --> 00:01:54,000 +take advantage of in order to steal everything on the actual device. + +34 +00:01:54,000 --> 00:01:56,000 +Now, this is going to be let's go down this list here that I have. + +35 +00:01:56,000 --> 00:02:02,000 +Number one, first thing up I think about is not having updates. + +36 +00:02:02,000 --> 00:02:08,000 +If this device is not patched and it's not updated every time, whether you use an Android, you're + +37 +00:02:08,000 --> 00:02:09,000 +using the iOS. + +38 +00:02:09,000 --> 00:02:14,000 +Apple pushes out an update, Android pushes out an update, or I have a Samsung. + +39 +00:02:15,000 --> 00:02:16,000 +Samsung pushes out an update. + +40 +00:02:16,000 --> 00:02:22,000 +You have to make sure that you get that update installed, because that's going to plug up lots of security + +41 +00:02:22,000 --> 00:02:25,000 +holes using unencrypted network. + +42 +00:02:25,000 --> 00:02:29,000 +All right, unencrypted Wi-Fi never connect to open Wi-Fi. + +43 +00:02:29,000 --> 00:02:33,000 +I always tell people that I don't use public Wi-Fi for a reason. + +44 +00:02:33,000 --> 00:02:38,000 +When you go into a public Wi-Fi, everybody is on it, and you're in somebody else's network, and people + +45 +00:02:38,000 --> 00:02:44,000 +around you can even scan your devices, and Bluetooth can expose data, physical access. + +46 +00:02:44,000 --> 00:02:47,000 +Well, do you guys have I have a thumbprint installed? + +47 +00:02:47,000 --> 00:02:49,000 +Um, your Pin. + +48 +00:02:49,000 --> 00:02:54,000 +You know, one of the things I tell people with pins, how many digits is your Pin? + +49 +00:02:54,000 --> 00:02:55,000 +Is it four digits? + +50 +00:02:55,000 --> 00:02:58,000 +Four digits is 10,000 combinations. + +51 +00:02:58,000 --> 00:03:00,000 +If I ever steal your phone. + +52 +00:03:00,000 --> 00:03:02,000 +And I really want your data. + +53 +00:03:02,000 --> 00:03:04,000 +I could put 10,000 combinations in. + +54 +00:03:04,000 --> 00:03:07,000 +You should make it eight digits like I do. + +55 +00:03:07,000 --> 00:03:10,000 +It's a lot of combinations, almost uncrackable for a user to sit there. + +56 +00:03:10,000 --> 00:03:16,000 +It'll take too long because every time you put in a couple it, it's going to disable the phone for + +57 +00:03:16,000 --> 00:03:16,000 +a little while. + +58 +00:03:16,000 --> 00:03:21,000 +And I have my phone set that if you put in too many combinations, it wipes the phone out. + +59 +00:03:21,000 --> 00:03:25,000 +So don't think that because you have a Pin, you're secure. + +60 +00:03:25,000 --> 00:03:28,000 +If it's a four digit Pin, it's not very strong. + +61 +00:03:28,000 --> 00:03:33,000 +Somebody can sit there and over time, maybe a month or two, depending on how valuable your data is, + +62 +00:03:34,000 --> 00:03:35,000 +they'll put in there. + +63 +00:03:35,000 --> 00:03:40,000 +They'll put it in a couple every day and they'll eventually crack your stuff. + +64 +00:03:40,000 --> 00:03:47,000 +Now physical, physical access of course, your phone being unlocked, unsecure, easily tampered with + +65 +00:03:47,000 --> 00:03:48,000 +now system flaws. + +66 +00:03:48,000 --> 00:03:52,000 +These are going to be inherited weakness in the operating system or in the hardware. + +67 +00:03:52,000 --> 00:03:58,000 +Maybe there is an a flaw on the Android OS that could be exploited. + +68 +00:03:58,000 --> 00:03:59,000 +User behavior. + +69 +00:04:00,000 --> 00:04:01,000 +You're not sharing your password. + +70 +00:04:01,000 --> 00:04:04,000 +You're not giving away your password to your phone, are you? + +71 +00:04:04,000 --> 00:04:08,000 +In fact, the only person that really knows the password to my phone is my wife and nobody else. + +72 +00:04:08,000 --> 00:04:08,000 +Children? + +73 +00:04:08,000 --> 00:04:09,000 +Nobody else. + +74 +00:04:09,000 --> 00:04:10,000 +Why? + +75 +00:04:10,000 --> 00:04:13,000 +Well, because, she says if I don't give it to her, I'm not going to have a bed to sleep on. + +76 +00:04:13,000 --> 00:04:14,000 +So I had to. + +77 +00:04:14,000 --> 00:04:15,000 +I was kind of forced to. + +78 +00:04:15,000 --> 00:04:20,000 +Now phishing links, way too often do I get text messages submission. + +79 +00:04:20,000 --> 00:04:24,000 +We talked about this and we're going to talk about this in, uh, social engineering. + +80 +00:04:24,000 --> 00:04:29,000 +But people sending you links to your phone and you're clicking on them and getting exploited. + +81 +00:04:29,000 --> 00:04:34,000 +Now there's two security hacks that we do want to mention that you should be familiar with. + +82 +00:04:34,000 --> 00:04:37,000 +It's something called jailbreaking and sideloading. + +83 +00:04:37,000 --> 00:04:40,000 +Let's start with jailbreaking because I have done this. + +84 +00:04:40,000 --> 00:04:43,000 +Don't ask why I did it for an experiment at one point. + +85 +00:04:43,000 --> 00:04:47,000 +So jailbreaking generally refers to iOS devices. + +86 +00:04:47,000 --> 00:04:48,000 +Now I go between iPhones. + +87 +00:04:48,000 --> 00:04:53,000 +I'll have an iPhone for about a year or two, then I'll have an Android phone for a year. + +88 +00:04:53,000 --> 00:04:54,000 +I always switch them up. + +89 +00:04:55,000 --> 00:04:56,000 +I don't use much apps. + +90 +00:04:56,000 --> 00:04:58,000 +I'm not into anybody's ecosystem. + +91 +00:04:58,000 --> 00:05:04,000 +Whichever one has a better camera and a better screen, I just go with whatever that one is and one + +92 +00:05:04,000 --> 00:05:11,000 +of the things that drives me crazy with the iOS or with Apple based devices is they restrict the hell + +93 +00:05:11,000 --> 00:05:12,000 +out of you. + +94 +00:05:12,000 --> 00:05:14,000 +You are not an admin on that phone. + +95 +00:05:14,000 --> 00:05:18,000 +So what people do is they jailbreak the phone. + +96 +00:05:18,000 --> 00:05:23,000 +When you jailbreak a phone, basically what you're going to be done is you're going to replace the operating + +97 +00:05:23,000 --> 00:05:28,000 +system on it with another operating system that's going to give you root access to the phone. + +98 +00:05:28,000 --> 00:05:29,000 +Now, what is root access? + +99 +00:05:29,000 --> 00:05:36,000 +So all your iOS and your Android is based on Unix based operating systems. + +100 +00:05:36,000 --> 00:05:40,000 +And in windows we have admin or administrator. + +101 +00:05:40,000 --> 00:05:42,000 +In Linux we have root. + +102 +00:05:42,000 --> 00:05:43,000 +So it's the same account. + +103 +00:05:43,000 --> 00:05:45,000 +One is called root, one is called admin. + +104 +00:05:45,000 --> 00:05:50,000 +So when we say jailbreak and basically what you're doing is you're gaining you're giving yourself admin + +105 +00:05:50,000 --> 00:05:52,000 +on the actual device. + +106 +00:05:52,000 --> 00:05:54,000 +Now Apple don't want you to do that. + +107 +00:05:54,000 --> 00:05:59,000 +Apple don't want you to be an admin on the device because it's technically it's their device, even + +108 +00:05:59,000 --> 00:06:01,000 +though you paid for it. + +109 +00:06:02,000 --> 00:06:07,000 +Um, let me not get into the Apple, you know, Android discussion here, but. + +110 +00:06:08,000 --> 00:06:11,000 +Uh, even though you paid for the device, you're not an admin on that device. + +111 +00:06:11,000 --> 00:06:13,000 +You may own that device. + +112 +00:06:13,000 --> 00:06:17,000 +You may own that software, but they control it so people jailbreak it. + +113 +00:06:17,000 --> 00:06:23,000 +So jailbreaking does is basically you write over their OS with an OS that gives you full access to the + +114 +00:06:23,000 --> 00:06:24,000 +entire operating system. + +115 +00:06:24,000 --> 00:06:25,000 +Now, why would you want to do this? + +116 +00:06:25,000 --> 00:06:31,000 +Because now you can install all kinds and any kind of application that you want. + +117 +00:06:31,000 --> 00:06:34,000 +You can manipulate any part of that operating system that you want. + +118 +00:06:34,000 --> 00:06:39,000 +Now jailbreak can generally will result in the device being off of warranty. + +119 +00:06:39,000 --> 00:06:42,000 +So if Apple finds out, they'll probably kick you off and you can't get a warrant. + +120 +00:06:42,000 --> 00:06:45,000 +The warranty will not be good on the phone anymore. + +121 +00:06:45,000 --> 00:06:50,000 +If you are going to jailbreak, maybe it's best to jailbreak all the phones that you can't send back + +122 +00:06:50,000 --> 00:06:51,000 +to Apple at at any point. + +123 +00:06:51,000 --> 00:06:53,000 +For Android, we do the same thing. + +124 +00:06:53,000 --> 00:06:55,000 +It's called rooting, although not necessarily. + +125 +00:06:55,000 --> 00:07:00,000 +You don't really need to root Android phones anymore because Android just basically will say, hey, + +126 +00:07:00,000 --> 00:07:01,000 +are you sure you want to do this? + +127 +00:07:01,000 --> 00:07:02,000 +And they'll let you install it? + +128 +00:07:03,000 --> 00:07:05,000 +Another thing now is side loader. + +129 +00:07:05,000 --> 00:07:13,000 +So side loading is when you install applications that is outside of the Google Play Store or the App + +130 +00:07:13,000 --> 00:07:14,000 +Store. + +131 +00:07:14,000 --> 00:07:14,000 +All right. + +132 +00:07:14,000 --> 00:07:21,000 +So for example, let's say there is a corporate application that you want to install on your device. + +133 +00:07:21,000 --> 00:07:25,000 +This corporate application was not published in Google or Apple Store. + +134 +00:07:25,000 --> 00:07:28,000 +And you want to install it on your device for your organization. + +135 +00:07:28,000 --> 00:07:32,000 +Now the bad thing is that Apple generally will not allow this. + +136 +00:07:32,000 --> 00:07:35,000 +Right side loading is something that's forbidden. + +137 +00:07:35,000 --> 00:07:35,000 +Why? + +138 +00:07:35,000 --> 00:07:41,000 +Because if they allow you to sideload applications in other words, install applications that doesn't + +139 +00:07:41,000 --> 00:07:46,000 +come from the store if they allow this, those applications haven't been vetted. + +140 +00:07:46,000 --> 00:07:52,000 +Generally, Google and iOS will vet the application to make sure it's not malware. + +141 +00:07:53,000 --> 00:07:59,000 +I don't recommend side loading, never side load if you always get the application from a good known + +142 +00:07:59,000 --> 00:08:00,000 +source. + +143 +00:08:00,000 --> 00:08:03,000 +For example, get it from a play store your organization. + +144 +00:08:03,000 --> 00:08:09,000 +If it wants to push out an app, maybe you should just push it to Apple and have them push the application + +145 +00:08:09,000 --> 00:08:10,000 +to the phone so it could be checked. + +146 +00:08:11,000 --> 00:08:11,000 +Okay. + +147 +00:08:11,000 --> 00:08:12,000 +Make sure you know these two terms. + +148 +00:08:12,000 --> 00:08:16,000 +So jailbreaking is when you regenerate, replace the operating system to give you root access to give + +149 +00:08:16,000 --> 00:08:17,000 +you admin privileges. + +150 +00:08:17,000 --> 00:08:23,000 +And side is generally install an application to your device, generally not from some kind of official + +151 +00:08:23,000 --> 00:08:24,000 +store. + +152 +00:08:25,000 --> 00:08:27,000 +As time is progressing. + +153 +00:08:27,000 --> 00:08:30,000 +I've always told my security students this. + +154 +00:08:30,000 --> 00:08:36,000 +The great hacks that are going to be coming over the next few years is not going to be to windows. + +155 +00:08:36,000 --> 00:08:40,000 +It's not going to be to the to OS ten or the Mac OS. + +156 +00:08:40,000 --> 00:08:48,000 +It's going to be right here because this has more confidential, and we use this more than we use our + +157 +00:08:48,000 --> 00:08:50,000 +desktops, our laptops. + +158 +00:08:51,000 --> 00:08:57,000 +I want you guys ask yourself, how many hours do I spend here versus how many hours I spent on a desktop. + +159 +00:08:57,000 --> 00:09:00,000 +And you're probably you spend more hours here. + +160 +00:09:00,000 --> 00:09:02,000 +If you're spending more time here, it means you're doing more things here. + +161 +00:09:02,000 --> 00:09:04,000 +So the greatest hacks will come from here. + +162 +00:09:04,000 --> 00:09:07,000 +So be aware of these vulnerabilities. + +163 +00:09:07,000 --> 00:09:09,000 +Make sure to keep your phones. + +164 +00:09:09,000 --> 00:09:10,000 +How do you stop them. + +165 +00:09:10,000 --> 00:09:12,000 +Well obviously don't jailbreak your phone. + +166 +00:09:12,000 --> 00:09:18,000 +Don't sideload applications, keep your device updated, and make sure that you always use very complex + +167 +00:09:18,000 --> 00:09:22,000 +pins or passwords on your device to keep them secure. + diff --git a/05 - Vulnerabilities/015 Zero-day Vulnerabilities OB 2.3_en.srt b/05 - Vulnerabilities/015 Zero-day Vulnerabilities OB 2.3_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..23834b74fb11cfc4c272141caa0251ab06c43aba --- /dev/null +++ b/05 - Vulnerabilities/015 Zero-day Vulnerabilities OB 2.3_en.srt @@ -0,0 +1,364 @@ +1 +00:00:00,000 --> 00:00:07,000 +Now, I know that I told you guys that quite a lot of vulnerabilities keeps me up at night, but all + +2 +00:00:07,000 --> 00:00:12,000 +those vulnerabilities that I spoke about that keeps me up at night, there are things that I can do + +3 +00:00:12,000 --> 00:00:13,000 +to stop them. + +4 +00:00:13,000 --> 00:00:19,000 +Firewalls, windows updates, anti-malware software, good user training, and so on. + +5 +00:00:20,000 --> 00:00:22,000 +And now there's quite a lot of controls. + +6 +00:00:23,000 --> 00:00:31,000 +But the real vulnerability that should keep you up at night is the one that you don't know is coming, + +7 +00:00:31,000 --> 00:00:33,000 +and the one that you don't even know about. + +8 +00:00:33,000 --> 00:00:35,000 +That's the one that should scare you. + +9 +00:00:36,000 --> 00:00:44,000 +Imagine a biological virus coming into the wild and starts to infect and kill a few people. + +10 +00:00:45,000 --> 00:00:50,000 +Imagine this scenario like in a movie, it's, you know, if you ever watch these movies where the the + +11 +00:00:50,000 --> 00:00:55,000 +viruses comes and it starts to kill, but people don't know it, they don't know this is a new virus + +12 +00:00:55,000 --> 00:00:56,000 +and people just start dropping dead. + +13 +00:00:56,000 --> 00:01:02,000 +It'll take them a few weeks or a few months to realize, Holy crap, that's a that's a new virus. + +14 +00:01:02,000 --> 00:01:04,000 +People are dying from this thing. + +15 +00:01:05,000 --> 00:01:07,000 +Well, it's the same thing that can happen in computers. + +16 +00:01:07,000 --> 00:01:15,000 +You see, in the world of computers, generally, when a new virus, a new vulnerability, uh, a new + +17 +00:01:15,000 --> 00:01:19,000 +hole is discovered in a system, right? + +18 +00:01:19,000 --> 00:01:20,000 +What starts to happen? + +19 +00:01:20,000 --> 00:01:23,000 +They're going to be a few people that gets infected. + +20 +00:01:23,000 --> 00:01:29,000 +There's going to be a few people that get basically killed without any, without any fixes. + +21 +00:01:29,000 --> 00:01:32,000 +This is called a zero day vulnerability. + +22 +00:01:32,000 --> 00:01:39,000 +It's basically a security flaw that is discovered by attackers before the vendor of the software is + +23 +00:01:39,000 --> 00:01:42,000 +aware of it, or before they have released a patch to fix it. + +24 +00:01:43,000 --> 00:01:43,000 +All right. + +25 +00:01:43,000 --> 00:01:45,000 +So that's what this is. + +26 +00:01:45,000 --> 00:01:52,000 +People find holes in the operating system and they're able to exploit that hole. + +27 +00:01:52,000 --> 00:01:57,000 +But Microsoft doesn't know it's a hole yet Microsoft haven't they basically found a backdoor in. + +28 +00:01:58,000 --> 00:02:01,000 +And they start infecting it. + +29 +00:02:01,000 --> 00:02:01,000 +Think about this. + +30 +00:02:01,000 --> 00:02:02,000 +If you own a house. + +31 +00:02:03,000 --> 00:02:03,000 +Right. + +32 +00:02:03,000 --> 00:02:07,000 +And all of a sudden you start seeing mouses running around in your house. + +33 +00:02:08,000 --> 00:02:10,000 +You're like, Holy crap, there's a hole in my house. + +34 +00:02:10,000 --> 00:02:14,000 +Okay, now you got to go find the mouse hole where they're coming from. + +35 +00:02:15,000 --> 00:02:20,000 +Now you find the hole, you start searching, you find the hole and you patch it up. + +36 +00:02:20,000 --> 00:02:22,000 +But remember something. + +37 +00:02:22,000 --> 00:02:22,000 +There's. + +38 +00:02:22,000 --> 00:02:24,000 +There is mouse in your house. + +39 +00:02:24,000 --> 00:02:26,000 +The mouse came through the hole already. + +40 +00:02:26,000 --> 00:02:28,000 +That means some people got through. + +41 +00:02:28,000 --> 00:02:30,000 +And that's the concept of zero day exploit. + +42 +00:02:31,000 --> 00:02:33,000 +In other words, the mouse found a hole. + +43 +00:02:34,000 --> 00:02:35,000 +The hacker found a hole. + +44 +00:02:35,000 --> 00:02:40,000 +They got into your network, they stole some things, probably got back out. + +45 +00:02:40,000 --> 00:02:44,000 +And then later on, you come to find out zero day exploits. + +46 +00:02:44,000 --> 00:02:48,000 +You see, this is one of the worst things that can ever happen in it. + +47 +00:02:48,000 --> 00:02:51,000 +Because and it's this is the pattern. + +48 +00:02:51,000 --> 00:02:53,000 +This is how it works. + +49 +00:02:53,000 --> 00:02:55,000 +Vulnerability comes out. + +50 +00:02:55,000 --> 00:02:57,000 +A few people get killed, a few people get hacked. + +51 +00:02:57,000 --> 00:03:02,000 +Well, uh, manufacturer finds the vulnerability or is alerted to it. + +52 +00:03:02,000 --> 00:03:04,000 +They patch it or they create a patch for it. + +53 +00:03:04,000 --> 00:03:07,000 +We install the patch, the vulnerability goes away. + +54 +00:03:07,000 --> 00:03:08,000 +That's the general pattern. + +55 +00:03:08,000 --> 00:03:09,000 +Then it starts again. + +56 +00:03:09,000 --> 00:03:11,000 +Then the attacker finds a new vulnerability. + +57 +00:03:12,000 --> 00:03:13,000 +Manufacturer finds out. + +58 +00:03:13,000 --> 00:03:14,000 +Patch it. + +59 +00:03:14,000 --> 00:03:16,000 +We install the patch starts again. + +60 +00:03:16,000 --> 00:03:18,000 +This is the cycle of it. + +61 +00:03:19,000 --> 00:03:23,000 +So don't think that you can ever you work an IT security. + +62 +00:03:23,000 --> 00:03:25,000 +You're never going to sleep good again because. + +63 +00:03:26,000 --> 00:03:32,000 +Doesn't matter what you do, it doesn't matter how well we secure our systems. + +64 +00:03:32,000 --> 00:03:35,000 +You cannot stop a zero day exploit. + +65 +00:03:35,000 --> 00:03:37,000 +You can't stop what you don't know. + +66 +00:03:37,000 --> 00:03:41,000 +You can't secure what you don't understand and what you don't know that's coming after you. + +67 +00:03:41,000 --> 00:03:50,000 +The best thing that we can do to stop Zero Day is basically to just have a layered security approach. + +68 +00:03:50,000 --> 00:03:50,000 +Right? + +69 +00:03:50,000 --> 00:03:53,000 +Have a good layer because if there's a vulnerability in windows. + +70 +00:03:53,000 --> 00:03:56,000 +But in order to get into the network, you have to pass my sonicwall. + +71 +00:03:56,000 --> 00:04:01,000 +Well, they're not really going to be able to get in my network if they can't get through my sonicwall + +72 +00:04:02,000 --> 00:04:03,000 +if they. + +73 +00:04:03,000 --> 00:04:07,000 +This is a zero day exploit on the on the Sonicwall. + +74 +00:04:07,000 --> 00:04:12,000 +Well, they could get into the network, but they can't get into the data because there's no vulnerability + +75 +00:04:12,000 --> 00:04:12,000 +on windows. + +76 +00:04:12,000 --> 00:04:16,000 +So you want a good layer approach to stopping these things. + +77 +00:04:17,000 --> 00:04:19,000 +So remember what a zero day exploit is. + +78 +00:04:19,000 --> 00:04:25,000 +It's nothing more than a vulnerability that has come out or is being exploited, and there's really + +79 +00:04:25,000 --> 00:04:26,000 +no fixed yet for it. + +80 +00:04:27,000 --> 00:04:34,000 +It can also apply to new viruses that has come out in the wild, and there is no fix or patches for + +81 +00:04:34,000 --> 00:04:35,000 +it yet. + +82 +00:04:35,000 --> 00:04:37,000 +This is a common thing also. + +83 +00:04:39,000 --> 00:04:43,000 +Like I mentioned, working in IT security ensures no sleep. + +84 +00:04:43,000 --> 00:04:48,000 +You're always worried about that next vulnerability, but the best thing we can do to calm our worries + +85 +00:04:48,000 --> 00:04:51,000 +and maybe get a good night's sleep is that layered approach. + +86 +00:04:51,000 --> 00:04:53,000 +That's why that layered approach is so important. + +87 +00:04:53,000 --> 00:04:55,000 +A layered approach means that you know what? + +88 +00:04:55,000 --> 00:05:01,000 +Even if they broke one section in order to get to the center of the data center with the data, they + +89 +00:05:01,000 --> 00:05:07,000 +have to go through multiple layers, and it's very unlikely for them to be zero day exploit across so + +90 +00:05:07,000 --> 00:05:08,000 +many layers. + +91 +00:05:08,000 --> 00:05:11,000 +That's why it's so important to have that particular approach. + diff --git a/05 - Vulnerabilities/016 Quick Quiz.html b/05 - Vulnerabilities/016 Quick Quiz.html new file mode 100644 index 0000000000000000000000000000000000000000..4481b0cfc3b9e588e0ca958f4f3b8868e3d719c5 --- /dev/null +++ b/05 - Vulnerabilities/016 Quick Quiz.html @@ -0,0 +1,479 @@ + + + + + + + Quiz + + + + +
+
+

+

+
+
+
+ Score: 999 of + 999% +
+
Correct: 999
+
Incorrect: 999
+
+ +
+ + + + +
+ + + + diff --git a/06 - Signs of Attacks/001 Malware OB 2.4_en.srt b/06 - Signs of Attacks/001 Malware OB 2.4_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..e173add70f78d7100bca6499b386d3886f030877 --- /dev/null +++ b/06 - Signs of Attacks/001 Malware OB 2.4_en.srt @@ -0,0 +1,92 @@ +1 +00:00:00,000 --> 00:00:06,000 +99% of the time when people think of information security and things that can cause us problems and + +2 +00:00:06,000 --> 00:00:12,000 +kill our machines and steal our data, they're mostly thinking about malware. + +3 +00:00:12,000 --> 00:00:21,000 +So malware, which is sort which is short for malicious software, is basically software that's intentionally + +4 +00:00:21,000 --> 00:00:23,000 +designed to beat up your machine. + +5 +00:00:23,000 --> 00:00:26,000 +Intentionally designed to break your computer. + +6 +00:00:26,000 --> 00:00:34,000 +So in this series of videos that is coming up, I want to discuss all the different malware threats + +7 +00:00:34,000 --> 00:00:36,000 +and the difference between them. + +8 +00:00:36,000 --> 00:00:36,000 +All right. + +9 +00:00:36,000 --> 00:00:42,000 +Here I have a whole bunch of them, like many people, consider worms and viruses to be the same thing. + +10 +00:00:42,000 --> 00:00:45,000 +But worm has a very unique characteristic. + +11 +00:00:45,000 --> 00:00:47,000 +So does Trojan horses. + +12 +00:00:47,000 --> 00:00:49,000 +So does logic bombs or rootkits. + +13 +00:00:49,000 --> 00:00:55,000 +Now, for your exam, you're going to want to make sure that you know the difference between these things. + +14 +00:00:55,000 --> 00:01:01,000 +It's not uncommon to get a question on your exam when they describe a particular characteristics or + +15 +00:01:01,000 --> 00:01:06,000 +some kind of an attack, and it's going to be your job to differentiate. + +16 +00:01:06,000 --> 00:01:07,000 +Is that a worm? + +17 +00:01:07,000 --> 00:01:09,000 +Is that a ransomware? + +18 +00:01:09,000 --> 00:01:11,000 +Is that a rootkit of some kind? + +19 +00:01:11,000 --> 00:01:12,000 +So you're going to have to make sure you know the difference. + +20 +00:01:12,000 --> 00:01:18,000 +So as we get into the sections I want you guys just don't understand that, hey, this thing is going + +21 +00:01:18,000 --> 00:01:24,000 +to do bad things to my computer, but also understand its characteristics and draw some of the videos. + +22 +00:01:24,000 --> 00:01:27,000 +I'm also going to give you ways to stop some of these particular things. + +23 +00:01:27,000 --> 00:01:30,000 +So let's get right into it and have some fun with malware. + diff --git a/06 - Signs of Attacks/002 Viruses OB 2.4_en.srt b/06 - Signs of Attacks/002 Viruses OB 2.4_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..66ff81f072bfba6034368efadae1e2d4ac2abc48 --- /dev/null +++ b/06 - Signs of Attacks/002 Viruses OB 2.4_en.srt @@ -0,0 +1,468 @@ +1 +00:00:00,000 --> 00:00:04,000 +When most of us think of malware, the first thing that comes to our mind is a virus. + +2 +00:00:04,000 --> 00:00:10,000 +So in this video, I want to talk more in depth about what exactly are computer based viruses. + +3 +00:00:10,000 --> 00:00:11,000 +We're not talking about the flu here, guys. + +4 +00:00:11,000 --> 00:00:13,000 +We're talking about computer viruses. + +5 +00:00:13,000 --> 00:00:15,000 +So what exactly is it? + +6 +00:00:15,000 --> 00:00:22,000 +Well, basically a virus is a type of type of malicious software or basically malware that is really + +7 +00:00:22,000 --> 00:00:23,000 +designed to spread. + +8 +00:00:23,000 --> 00:00:25,000 +You see, a lot of people get this wrong. + +9 +00:00:25,000 --> 00:00:33,000 +A lot of people have this belief that viruses are designed to steal data or corrupt data, but in actuality, + +10 +00:00:33,000 --> 00:00:39,000 +all viruses have one unique characteristics, which is basically to spread. + +11 +00:00:39,000 --> 00:00:43,000 +All viruses wants to be able to spread from machine to machine. + +12 +00:00:43,000 --> 00:00:50,000 +Now, other than that, characteristics of spreading viruses, some of them are dependent on what they + +13 +00:00:50,000 --> 00:00:57,000 +are, may steal data, while others may corrupt data, while others may just mass mail itself and just + +14 +00:00:57,000 --> 00:00:59,000 +cause a lot of disruption. + +15 +00:00:59,000 --> 00:01:00,000 +They don't really do anything. + +16 +00:01:00,000 --> 00:01:03,000 +So I want you guys to remember this part for your exam. + +17 +00:01:03,000 --> 00:01:07,000 +A virus has one main objective to spread. + +18 +00:01:07,000 --> 00:01:09,000 +Then comes its other objective, right? + +19 +00:01:09,000 --> 00:01:12,000 +The other objective may be to steal data, corrupt data or something like that. + +20 +00:01:12,000 --> 00:01:13,000 +How does it do it? + +21 +00:01:13,000 --> 00:01:18,000 +Well, it's going to typically attach itself to some kind of software, and it has to be executed on + +22 +00:01:18,000 --> 00:01:20,000 +the person's machine. + +23 +00:01:20,000 --> 00:01:24,000 +Now viruses are different than what's called a worm. + +24 +00:01:24,000 --> 00:01:26,000 +Now in the next video, I'll cover worms. + +25 +00:01:26,000 --> 00:01:31,000 +But for now, just remember, unlike a worm, which can spread across a network on its own, viruses + +26 +00:01:31,000 --> 00:01:35,000 +require some form of user action to replicate. + +27 +00:01:35,000 --> 00:01:36,000 +Now what does that mean? + +28 +00:01:36,000 --> 00:01:43,000 +Well, you see, when when I send you, let's say I'm a bad person and I send you an email and it has + +29 +00:01:43,000 --> 00:01:47,000 +an attachment, it has a bad payload, a virus in particular. + +30 +00:01:47,000 --> 00:01:51,000 +You're going to have to open that email and execute it yourself. + +31 +00:01:51,000 --> 00:01:56,000 +I'm going to have to type something in there that says, hey, you just want a new jackpot and open + +32 +00:01:56,000 --> 00:01:57,000 +this to see your price. + +33 +00:01:57,000 --> 00:02:02,000 +I'm going to have to write something in there, try to get you to open or execute the virus. + +34 +00:02:02,000 --> 00:02:05,000 +This is vastly different than what's called worms. + +35 +00:02:05,000 --> 00:02:10,000 +Worms are basically malware that it'll infect this machine, and then it'll scan all the machines in + +36 +00:02:10,000 --> 00:02:13,000 +this network and start infecting the machines by itself. + +37 +00:02:13,000 --> 00:02:14,000 +A virus can't do that. + +38 +00:02:14,000 --> 00:02:21,000 +A virus needs the host, needs the user to do some kind of action in order to get infected with the + +39 +00:02:21,000 --> 00:02:22,000 +particular virus. + +40 +00:02:23,000 --> 00:02:23,000 +Now. + +41 +00:02:24,000 --> 00:02:28,000 +There are a couple of different kinds of viruses that I just want to mention, and I have them all right + +42 +00:02:28,000 --> 00:02:29,000 +here. + +43 +00:02:29,000 --> 00:02:33,000 +So the first thing up we have is what's called a file infected viruses. + +44 +00:02:33,000 --> 00:02:38,000 +These are viruses that attach themselves to the executables of files. + +45 +00:02:38,000 --> 00:02:42,000 +That way when you run an executable it runs the virus also. + +46 +00:02:42,000 --> 00:02:45,000 +And then they spread to other executables on on the actual computer. + +47 +00:02:45,000 --> 00:02:47,000 +So why they call it file infector. + +48 +00:02:47,000 --> 00:02:52,000 +Well, as you can imagine it infects the executables on the machine, a macro virus. + +49 +00:02:52,000 --> 00:02:59,000 +Now, if you've ever used it and you're a power user of Microsoft Office, Microsoft Office uses a very + +50 +00:02:59,000 --> 00:03:04,000 +particular scripting language called VBA or Visual Basic scripting. + +51 +00:03:04,000 --> 00:03:07,000 +And this is basically a scripting language that you can write codes in. + +52 +00:03:07,000 --> 00:03:14,000 +Now, if you are a bad person, you can use this script in order to write malicious codes. + +53 +00:03:14,000 --> 00:03:20,000 +For an example of this would be like if I send you an Excel file that has a macro in it, and because + +54 +00:03:20,000 --> 00:03:25,000 +I don't like you, when you double click my Excel file, it executes the scripting in Excel or the macro + +55 +00:03:25,000 --> 00:03:31,000 +in Excel, and then it can erase all your Excel files or cause corruption to your other Excel files. + +56 +00:03:31,000 --> 00:03:34,000 +Very malicious boot sector virus. + +57 +00:03:34,000 --> 00:03:34,000 +Oh man. + +58 +00:03:34,000 --> 00:03:37,000 +I got a lot of stories about these types of things. + +59 +00:03:37,000 --> 00:03:42,000 +These are viruses that when they infect your machine, they prevent the machines from booting up. + +60 +00:03:42,000 --> 00:03:43,000 +Well, what does that mean? + +61 +00:03:43,000 --> 00:03:44,000 +Well, I'll give you an example. + +62 +00:03:45,000 --> 00:03:50,000 +One time I was working at a law firm while I was a consultant, going into a law firm to help their + +63 +00:03:50,000 --> 00:03:55,000 +machine, and when I got to the law firm to help them, they got a bop, a pop up message that says + +64 +00:03:55,000 --> 00:03:59,000 +your copy of windows was illegal and Microsoft is going to lock all you up. + +65 +00:03:59,000 --> 00:04:01,000 +The machine wouldn't boot. + +66 +00:04:01,000 --> 00:04:03,000 +This was a boot virus. + +67 +00:04:03,000 --> 00:04:05,000 +It wasn't asking for ransom. + +68 +00:04:05,000 --> 00:04:06,000 +It's not a ransomware. + +69 +00:04:06,000 --> 00:04:08,000 +It was just saying the computer was in boot. + +70 +00:04:08,000 --> 00:04:11,000 +So it infects the boot sector and stops the machine from booting. + +71 +00:04:12,000 --> 00:04:13,000 +Okay. + +72 +00:04:13,000 --> 00:04:17,000 +These are some of the kinds of viruses that you're going to want to probably be familiar with for your + +73 +00:04:17,000 --> 00:04:22,000 +exam, although I don't think they're going to go depth in depth into these kinds of viruses. + +74 +00:04:22,000 --> 00:04:25,000 +But you should know different kinds of viruses exist. + +75 +00:04:25,000 --> 00:04:28,000 +Now, how do we prevent viruses? + +76 +00:04:28,000 --> 00:04:33,000 +Well, one of the most common way that most of you should know already, I mean, you shouldn't be watching + +77 +00:04:33,000 --> 00:04:38,000 +this video if you don't know that you need antivirus software on your computer. + +78 +00:04:38,000 --> 00:04:43,000 +In fact, if you're using a windows box, Windows Defender comes built on the machine for free. + +79 +00:04:43,000 --> 00:04:47,000 +There are tons of free antivirus software like Avast is pretty good. + +80 +00:04:47,000 --> 00:04:50,000 +Also, most people know anti-malware software such as. + +81 +00:04:51,000 --> 00:04:56,000 +Norton or Symantec's McAfee are popular brands. + +82 +00:04:56,000 --> 00:04:58,000 +Now I want to go through some things here. + +83 +00:04:58,000 --> 00:05:02,000 +You notice it says use a signature to detect known viruses and heuristic. + +84 +00:05:02,000 --> 00:05:06,000 +Can't pronounce that word too well to detect new and unknown viruses. + +85 +00:05:06,000 --> 00:05:07,000 +So here's how it works. + +86 +00:05:07,000 --> 00:05:10,000 +Antivirus works basically using two methods. + +87 +00:05:10,000 --> 00:05:13,000 +It uses what's called a knowledge based method. + +88 +00:05:13,000 --> 00:05:14,000 +This is the signature. + +89 +00:05:14,000 --> 00:05:20,000 +It basically knows how a particular virus will operate and what type of files are going to use. + +90 +00:05:20,000 --> 00:05:27,000 +If it detects that those kinds of files or activities on your machine, it goes in and it deletes it. + +91 +00:05:27,000 --> 00:05:29,000 +It knows that's that virus. + +92 +00:05:30,000 --> 00:05:33,000 +The other way does is that it's called a learning method. + +93 +00:05:33,000 --> 00:05:35,000 +Anomaly based detection. + +94 +00:05:35,000 --> 00:05:39,000 +What this does is that it looks for unusual activities on the machine. + +95 +00:05:39,000 --> 00:05:45,000 +It knows the normal function of your computer, and if it finds that it has some kind of variance off, + +96 +00:05:45,000 --> 00:05:48,000 +it may say it's a potential virus over here. + +97 +00:05:48,000 --> 00:05:50,000 +So that's the two ways this is going to work. + +98 +00:05:50,000 --> 00:05:54,000 +Another thing you guys should be doing I'm going to jump down here is system scan regular scanning for + +99 +00:05:54,000 --> 00:05:56,000 +viruses to detect and remove. + +100 +00:05:56,000 --> 00:06:01,000 +You should have your computer being scanned almost on a weekly basis. + +101 +00:06:01,000 --> 00:06:04,000 +And you can set this in your antivirus software. + +102 +00:06:04,000 --> 00:06:09,000 +Now the other thing here is going to be keeping the antivirus software updated. + +103 +00:06:09,000 --> 00:06:14,000 +It's going to be important because it doesn't make sense for you to have great antivirus software, + +104 +00:06:14,000 --> 00:06:17,000 +but then you don't update it with the latest quote unquote definition. + +105 +00:06:17,000 --> 00:06:25,000 +Definitions are going to be all the all the files or all the characteristics of new viruses that are + +106 +00:06:25,000 --> 00:06:25,000 +coming out. + +107 +00:06:25,000 --> 00:06:29,000 +So your virus protection could keep you protected from the newest virus. + +108 +00:06:30,000 --> 00:06:35,000 +Now, the other thing here that I should have added would have been to Windows Update. + +109 +00:06:35,000 --> 00:06:37,000 +Always keep your machine updated. + +110 +00:06:37,000 --> 00:06:38,000 +Remember something? + +111 +00:06:38,000 --> 00:06:44,000 +A lot of these viruses that are out there is going to infect your computer based on, generally speaking, + +112 +00:06:44,000 --> 00:06:46,000 +some kind of vulnerability on windows. + +113 +00:06:46,000 --> 00:06:49,000 +In other words, there's some kind of hole in windows. + +114 +00:06:49,000 --> 00:06:52,000 +The best thing you can do is patch those holes by getting Windows Update. + +115 +00:06:52,000 --> 00:06:54,000 +Always keep your machine as updated as possible. + +116 +00:06:54,000 --> 00:06:56,000 +If you're using a mac, no problem. + +117 +00:06:56,000 --> 00:07:01,000 +Just make sure your machine stays updated to protect you from viruses. + diff --git a/06 - Signs of Attacks/003 Worms OB 2.4_en.srt b/06 - Signs of Attacks/003 Worms OB 2.4_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..e46cad1447efa66fab6f7a95a79e1cec235c9c7a --- /dev/null +++ b/06 - Signs of Attacks/003 Worms OB 2.4_en.srt @@ -0,0 +1,404 @@ +1 +00:00:00,000 --> 00:00:06,000 +While a virus may seem pretty scary to get because it could destroy your machine, it could steal your + +2 +00:00:06,000 --> 00:00:06,000 +data. + +3 +00:00:06,000 --> 00:00:11,000 +One of the worst things that can happen in a network or managing a network, is a network administrator + +4 +00:00:11,000 --> 00:00:14,000 +that you might have to deal with our worms. + +5 +00:00:14,000 --> 00:00:16,000 +Well, what exactly are worms? + +6 +00:00:16,000 --> 00:00:19,000 +A worm is a type of malware that replicates itself. + +7 +00:00:19,000 --> 00:00:25,000 +Keyword for your exam replicates itself in order to spread to other computers. + +8 +00:00:25,000 --> 00:00:31,000 +Unlike a virus, it doesn't need to attach itself to a particular program or require any user intervention. + +9 +00:00:31,000 --> 00:00:33,000 +That's the main difference here. + +10 +00:00:33,000 --> 00:00:35,000 +You see worms. + +11 +00:00:35,000 --> 00:00:36,000 +And I'm not really talking about these worms. + +12 +00:00:36,000 --> 00:00:38,000 +I'm talking about computer virus worms. + +13 +00:00:38,000 --> 00:00:49,000 +Worms in particular is basically an application that itself executes onto the host, infects the host, + +14 +00:00:49,000 --> 00:00:53,000 +then looks for other hosts on the network and then infects those hosts. + +15 +00:00:53,000 --> 00:00:55,000 +This is why this is dangerous. + +16 +00:00:55,000 --> 00:01:01,000 +You get a worm in your network and before you know it, it starts to spread to every single machine + +17 +00:01:01,000 --> 00:01:03,000 +and you're in a whole lot of trouble. + +18 +00:01:03,000 --> 00:01:08,000 +Worms typically exploit vulnerabilities in networking, in network services to protagonist. + +19 +00:01:08,000 --> 00:01:13,000 +Now this is going to be a key word, because one of the things worms do in order for them to function, + +20 +00:01:13,000 --> 00:01:15,000 +they are going to exploit. + +21 +00:01:15,000 --> 00:01:21,000 +They're going to take advantage of generally things wrong with your operating system and the network + +22 +00:01:21,000 --> 00:01:26,000 +and services that your operating system is running, like here I have windows, so obviously one of + +23 +00:01:26,000 --> 00:01:29,000 +the things to do to protect yourself from worms is going to be Windows Update. + +24 +00:01:29,000 --> 00:01:31,000 +So let's take a look at some things here. + +25 +00:01:32,000 --> 00:01:37,000 +That we should be doing in order to protect ourselves from worms. + +26 +00:01:37,000 --> 00:01:40,000 +Well, I just mentioned Windows Update keeping your machine updated. + +27 +00:01:40,000 --> 00:01:44,000 +Now, I know I talk a lot about windows because that's what I'm using. + +28 +00:01:44,000 --> 00:01:45,000 +If you're using a mac, no problem. + +29 +00:01:45,000 --> 00:01:47,000 +Macs are great machines. + +30 +00:01:47,000 --> 00:01:49,000 +If then once again, they're just like windows. + +31 +00:01:49,000 --> 00:01:51,000 +They have to be updated. + +32 +00:01:51,000 --> 00:01:58,000 +If you have a virus that takes advantage of the TCP IP stack, particularly on on Unix boxes, it could + +33 +00:01:58,000 --> 00:02:01,000 +probably take advantage of a mac also because it runs on a Unix system. + +34 +00:02:01,000 --> 00:02:05,000 +If it takes advantage of a certain version of windows, it may take advantage of multiple versions of + +35 +00:02:05,000 --> 00:02:06,000 +windows. + +36 +00:02:06,000 --> 00:02:08,000 +So once again, always keep your machine updated. + +37 +00:02:08,000 --> 00:02:14,000 +Next thing you're going to do is, of course, have antivirus anti-malware software on your computer + +38 +00:02:14,000 --> 00:02:17,000 +that can detect the latest kinds of worms that are out there. + +39 +00:02:17,000 --> 00:02:21,000 +Now, I want to bring in some really good things here. + +40 +00:02:21,000 --> 00:02:25,000 +This is going to be called network segmentation. + +41 +00:02:25,000 --> 00:02:27,000 +What exactly is network segmentation? + +42 +00:02:27,000 --> 00:02:31,000 +Network segmentation is when you break your network apart. + +43 +00:02:31,000 --> 00:02:34,000 +Now I want to just draw you guys a quick diagram on this. + +44 +00:02:34,000 --> 00:02:37,000 +So let's talk network segmentation. + +45 +00:02:37,000 --> 00:02:41,000 +So let's say you have a switch right. + +46 +00:02:41,000 --> 00:02:42,000 +You have a switch. + +47 +00:02:42,000 --> 00:02:45,000 +And the switch on it has three ports. + +48 +00:02:45,000 --> 00:02:49,000 +Now we're going to talk about network segmentation more in depth. + +49 +00:02:49,000 --> 00:02:54,000 +When we get to the part of the course that talks about network segmentation basically protect how to + +50 +00:02:54,000 --> 00:02:55,000 +protect the network. + +51 +00:02:55,000 --> 00:02:56,000 +One of the ways is to segment. + +52 +00:02:56,000 --> 00:02:58,000 +But let me give you a quick heads up. + +53 +00:02:58,000 --> 00:03:01,000 +VLANs is one of the ways to do it. + +54 +00:03:01,000 --> 00:03:03,000 +So you can have Vlan that says air. + +55 +00:03:03,000 --> 00:03:06,000 +You can have a Vlan that says management. + +56 +00:03:06,000 --> 00:03:08,000 +One that says accounting. + +57 +00:03:09,000 --> 00:03:13,000 +So these are going to be your different VLANs and your different segments of your network in every segment. + +58 +00:03:13,000 --> 00:03:16,000 +You may have computers right. + +59 +00:03:16,000 --> 00:03:18,000 +You can have a ton of computers and every one of them. + +60 +00:03:18,000 --> 00:03:24,000 +The great thing why you want to segment a network is because let's say somebody gets a worm here. + +61 +00:03:25,000 --> 00:03:26,000 +What's going to happen now? + +62 +00:03:26,000 --> 00:03:31,000 +This worm is going to start to spread to this HR machine and then to this HR machine. + +63 +00:03:31,000 --> 00:03:37,000 +But because of your segmentation, using your virtual Lans, data from HR can't reach management and + +64 +00:03:37,000 --> 00:03:39,000 +management can't reach accountant. + +65 +00:03:39,000 --> 00:03:43,000 +That means that the worm is stuck in this segment of your network. + +66 +00:03:43,000 --> 00:03:48,000 +So network segmentation is super important, especially on large networks. + +67 +00:03:48,000 --> 00:03:52,000 +If you have hundreds of computers, consider segmenting them. + +68 +00:03:52,000 --> 00:03:57,000 +So if one of them does get infected or a problem, it doesn't start to replicate to all the machines. + +69 +00:03:57,000 --> 00:03:59,000 +Another thing is going to be access control. + +70 +00:03:59,000 --> 00:04:04,000 +This is giving people permissions on machines that they don't need. + +71 +00:04:04,000 --> 00:04:08,000 +For example, somebody with administrator permission could cause a lot of damage. + +72 +00:04:08,000 --> 00:04:10,000 +Firewalls. + +73 +00:04:10,000 --> 00:04:14,000 +So remember something worms go from machine to machine. + +74 +00:04:14,000 --> 00:04:15,000 +They may exploit this service. + +75 +00:04:15,000 --> 00:04:17,000 +They come through ports on a machine. + +76 +00:04:17,000 --> 00:04:23,000 +A firewall will be able to stop or block the ports that the worm can get through, preventing the worm + +77 +00:04:23,000 --> 00:04:24,000 +from being executed. + +78 +00:04:24,000 --> 00:04:31,000 +Traffic filtering can stop certain traffic, especially if that traffic has a worm coming into it. + +79 +00:04:31,000 --> 00:04:40,000 +Disable unnecessary services A lot of times, worms and different forms of malware may exploit a particular + +80 +00:04:40,000 --> 00:04:41,000 +service on a computer. + +81 +00:04:41,000 --> 00:04:46,000 +For example, one service that was exploited very recently is the print spooler on windows. + +82 +00:04:46,000 --> 00:04:48,000 +This caused a massive problem. + +83 +00:04:48,000 --> 00:04:49,000 +It allowed remote execution. + +84 +00:04:50,000 --> 00:04:55,000 +So if you don't, if you're not using a particular service, especially on a server or particular workstations, + +85 +00:04:55,000 --> 00:04:56,000 +disable it. + +86 +00:04:57,000 --> 00:04:58,000 +Just go in there and turn it off. + +87 +00:04:58,000 --> 00:05:00,000 +That way no one can. + +88 +00:05:00,000 --> 00:05:04,000 +Even if the service is exploitable, it wouldn't harm you because you're not running it. + +89 +00:05:04,000 --> 00:05:05,000 +And then of course, user training. + +90 +00:05:05,000 --> 00:05:10,000 +Nothing is able to beat malware like a user training. + +91 +00:05:10,000 --> 00:05:18,000 +User training is super important because it will tell people how to detect malicious emails. + +92 +00:05:18,000 --> 00:05:24,000 +Most malware comes into an organization through emails to some kind of phishing attempt, where they + +93 +00:05:24,000 --> 00:05:28,000 +come in and you double click on something and you open something. + +94 +00:05:28,000 --> 00:05:34,000 +So user training can teach people, hey, don't get don't click on this to get the machine infected. + +95 +00:05:34,000 --> 00:05:40,000 +Also, user training can teach users how to detect if the machine is going weird. + +96 +00:05:40,000 --> 00:05:47,000 +For example, malicious pop ups programs closing on their own, programs being corrupted consistently. + +97 +00:05:47,000 --> 00:05:50,000 +These are signs of malicious activity on a machine. + +98 +00:05:50,000 --> 00:05:56,000 +User training can teach users that, and then those users can then report it to it to check the machine. + +99 +00:05:57,000 --> 00:06:01,000 +Once again, worms are incredibly dangerous to your network. + +100 +00:06:01,000 --> 00:06:06,000 +Worms can cause a lot of chaos, so make sure you implement some of the things we looked at to stop + +101 +00:06:06,000 --> 00:06:10,000 +worms from spreading uncontrollably in your network. + diff --git a/06 - Signs of Attacks/004 Trojans OB 2.4_en.srt b/06 - Signs of Attacks/004 Trojans OB 2.4_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..b540f540bbe331da0aa5a10fd14959edbfb981ec --- /dev/null +++ b/06 - Signs of Attacks/004 Trojans OB 2.4_en.srt @@ -0,0 +1,212 @@ +1 +00:00:00,000 --> 00:00:05,000 +Sometimes you may go to a website, and you may get a pop up on the website that says they want you + +2 +00:00:05,000 --> 00:00:09,000 +to download this software to give you some kind of functionality. + +3 +00:00:09,000 --> 00:00:15,000 +Like maybe it's it's a great antivirus, a great video editing utility or something, and you're like, + +4 +00:00:15,000 --> 00:00:16,000 +oh, that's great. + +5 +00:00:16,000 --> 00:00:21,000 +So you go and you download this video editing utility, you install it, and all of a sudden your machine + +6 +00:00:21,000 --> 00:00:22,000 +cranks out. + +7 +00:00:22,000 --> 00:00:27,000 +Your machine starts to delete all the files, it reboots, and then it's dead. + +8 +00:00:27,000 --> 00:00:31,000 +What just happened here was that kind of a malware we call a Trojan. + +9 +00:00:31,000 --> 00:00:38,000 +You see, Trojans, or short for Trojan horses, is a type of malware that disguises itself as legitimate + +10 +00:00:38,000 --> 00:00:38,000 +software. + +11 +00:00:39,000 --> 00:00:42,000 +Or sometimes it's even hidden in legitimate software. + +12 +00:00:42,000 --> 00:00:49,000 +Now, this kind of determine itself comes from the Greek story of the Trojan horse that I have here. + +13 +00:00:49,000 --> 00:00:52,000 +I'm not going to go through the Greek story in the fall of the city of Troy. + +14 +00:00:52,000 --> 00:00:55,000 +You can read that on Wikipedia or watch a YouTube video on it. + +15 +00:00:55,000 --> 00:01:00,000 +Just know that basically one army wanted to take out another in order to get into a city. + +16 +00:01:00,000 --> 00:01:05,000 +They made this horse, and they put a lot of, uh, all their soldiers in the horse and beat it into + +17 +00:01:05,000 --> 00:01:06,000 +the city. + +18 +00:01:06,000 --> 00:01:12,000 +Now, that is the same effect of the word trojan in computer viruses or computer malware, because, + +19 +00:01:13,000 --> 00:01:19,000 +you see, we think we're getting this particular beautiful ornament or this particular horse. + +20 +00:01:19,000 --> 00:01:23,000 +But in particularly what we're getting is a bunch of bad actors coming into our machine. + +21 +00:01:23,000 --> 00:01:28,000 +So Trojans tricks people into downloading and executing it because they think they're getting some great + +22 +00:01:28,000 --> 00:01:29,000 +software. + +23 +00:01:29,000 --> 00:01:31,000 +In actuality, they're just getting the virus. + +24 +00:01:32,000 --> 00:01:35,000 +So make sure you understand that that's really what a Trojan is. + +25 +00:01:35,000 --> 00:01:38,000 +It's nothing more than a software disguised as another software. + +26 +00:01:38,000 --> 00:01:41,000 +Sometimes it's even embedded into good software. + +27 +00:01:41,000 --> 00:01:43,000 +For example, I may send you a calculator software. + +28 +00:01:43,000 --> 00:01:47,000 +When you double click on it, you'll get a calculator, but then I'll install a malicious payload on + +29 +00:01:47,000 --> 00:01:48,000 +the back end also. + +30 +00:01:48,000 --> 00:01:52,000 +Now how do we stop a Trojan? + +31 +00:01:52,000 --> 00:01:56,000 +Well, it's going to be the same solution we use for things like worms. + +32 +00:01:56,000 --> 00:02:03,000 +Number one patch management A windows has all kinds of holes that is discovered all the time. + +33 +00:02:03,000 --> 00:02:07,000 +If you don't patch those holes, no matter how much antivirus you get, you're going to keep getting + +34 +00:02:07,000 --> 00:02:08,000 +infected. + +35 +00:02:08,000 --> 00:02:10,000 +Of course, if you're infected, you need something to clean it with. + +36 +00:02:10,000 --> 00:02:14,000 +Antivirus network segmentation is when you break your network apart. + +37 +00:02:14,000 --> 00:02:22,000 +That way, if one segment of the network gets infected, it's very unlikely for it to spread to another + +38 +00:02:22,000 --> 00:02:23,000 +segment. + +39 +00:02:23,000 --> 00:02:26,000 +Access control is limited in what people can have access to. + +40 +00:02:26,000 --> 00:02:30,000 +This can limit the attack surface or where it can go firewalls. + +41 +00:02:30,000 --> 00:02:36,000 +Now, if the Trojan itself operates on certain kinds of ports or allowing certain kind of malicious + +42 +00:02:36,000 --> 00:02:38,000 +software, a firewall can stop that traffic. + +43 +00:02:38,000 --> 00:02:41,000 +Filtering will block unnecessary traffic to a machine. + +44 +00:02:41,000 --> 00:02:46,000 +And then, of course, the best thing I think we can always do when it comes to managing malware is + +45 +00:02:46,000 --> 00:02:47,000 +user training. + +46 +00:02:47,000 --> 00:02:53,000 +User training is going to be one of the most important thing is this can allow users to detect, you + +47 +00:02:53,000 --> 00:02:59,000 +know, maybe I shouldn't click on that link, or it can allow users to detect malicious behavior, actions, + +48 +00:02:59,000 --> 00:03:01,000 +weird things happening on their machine. + +49 +00:03:01,000 --> 00:03:06,000 +For your exam, make sure that you understand that a Trojan is generally a software disguised as another + +50 +00:03:06,000 --> 00:03:11,000 +software, or it's malicious software disguised as legitimate software. + +51 +00:03:11,000 --> 00:03:13,000 +And anytime you're surfing the internet. + +52 +00:03:14,000 --> 00:03:18,000 +And they're giving you something for free or you got to download some software. + +53 +00:03:18,000 --> 00:03:22,000 +I recommend not to do that because more than likely it's a Trojan. + diff --git a/06 - Signs of Attacks/005 Ransomware OB 2.4_en.srt b/06 - Signs of Attacks/005 Ransomware OB 2.4_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..435606ee69cdad1b8a9d3d9799714a565b7a8f24 --- /dev/null +++ b/06 - Signs of Attacks/005 Ransomware OB 2.4_en.srt @@ -0,0 +1,360 @@ +1 +00:00:00,000 --> 00:00:02,000 +Almost on a daily basis. + +2 +00:00:02,000 --> 00:00:10,000 +I hear of organizations being held ransom by bad actors for money, and the way they're doing that is + +3 +00:00:10,000 --> 00:00:15,000 +they're going into the organizations releasing some kind of a malware in the organization. + +4 +00:00:16,000 --> 00:00:22,000 +Called ransomware that then encrypts the organization data or steals it and then tells them, you know + +5 +00:00:22,000 --> 00:00:23,000 +what? + +6 +00:00:23,000 --> 00:00:26,000 +If you want your data back, or for me not to release it. + +7 +00:00:27,000 --> 00:00:28,000 +You need to pay us. + +8 +00:00:28,000 --> 00:00:31,000 +Now this brings us to the topic of ransomware. + +9 +00:00:31,000 --> 00:00:37,000 +It's a type of malicious software designed to block access to a computer system or encrypt files until + +10 +00:00:37,000 --> 00:00:38,000 +a sum of money is paid. + +11 +00:00:38,000 --> 00:00:45,000 +Now, this is the general definition of ransomware, but nowadays, what the other thing they're doing + +12 +00:00:45,000 --> 00:00:52,000 +in addition to this definition is they're also stealing the data or taking the data out the organizations + +13 +00:00:52,000 --> 00:00:57,000 +without their approval and then holding it ransom and say, well, if you don't give us a couple of + +14 +00:00:57,000 --> 00:01:00,000 +million dollars or a couple of hundred thousand dollars, we're going to release this to the public. + +15 +00:01:00,000 --> 00:01:09,000 +So at the end of the day, the word ransomware is all about extracting somehow money from the person + +16 +00:01:09,000 --> 00:01:11,000 +holding something hostage. + +17 +00:01:11,000 --> 00:01:17,000 +And it's particularly data from the organization or from the person to get money out of you. + +18 +00:01:17,000 --> 00:01:23,000 +Now it's a direct threat to the availability of data and the normal operations, because one of the + +19 +00:01:23,000 --> 00:01:27,000 +one of the most popular ways they do it is by encrypting. + +20 +00:01:27,000 --> 00:01:28,000 +Then here's what they do. + +21 +00:01:29,000 --> 00:01:35,000 +Let's say you get an email, and in the email, one of the popular ones was a Fedex email. + +22 +00:01:35,000 --> 00:01:37,000 +Now Fedex is a shipping company here in the United States. + +23 +00:01:37,000 --> 00:01:42,000 +So you get this email that says Fedex has a package for you and for you to receive it. + +24 +00:01:42,000 --> 00:01:44,000 +It's been delayed or something. + +25 +00:01:44,000 --> 00:01:46,000 +Check this link or check this attachment. + +26 +00:01:47,000 --> 00:01:52,000 +You double click the attachment and boom, it starts encrypting your files. + +27 +00:01:52,000 --> 00:01:56,000 +Now your files are encrypted, which means you can't get them back because here's what they do. + +28 +00:01:56,000 --> 00:01:58,000 +Encryption is done with a key. + +29 +00:01:58,000 --> 00:02:02,000 +They hold the key on a central server, and they use that key to encrypt your data. + +30 +00:02:02,000 --> 00:02:07,000 +You can't you can't decrypt your data without that particular key. + +31 +00:02:07,000 --> 00:02:11,000 +Then they tell you, well, if you want your data back, you have to pay up. + +32 +00:02:11,000 --> 00:02:13,000 +I have a picture of this here. + +33 +00:02:13,000 --> 00:02:13,000 +Let's take a look. + +34 +00:02:13,000 --> 00:02:17,000 +So here is a screenshot of a particular ransomware. + +35 +00:02:18,000 --> 00:02:22,000 +Uh, and in it they're telling you if you read this top part here that says, uh, what's happening + +36 +00:02:22,000 --> 00:02:24,000 +to my computer? + +37 +00:02:24,000 --> 00:02:25,000 +Can you recover your file? + +38 +00:02:25,000 --> 00:02:28,000 +And they give you a time frame, in which case, if you make a payment. + +39 +00:02:28,000 --> 00:02:35,000 +And in this particular case, they wanted $300 in Bitcoin, if you paid them their $300 in Bitcoin. + +40 +00:02:35,000 --> 00:02:38,000 +And within this doable time you can get your data back. + +41 +00:02:38,000 --> 00:02:42,000 +If not, they delete the key and your data is lost forever. + +42 +00:02:42,000 --> 00:02:45,000 +This is one of the reasons why you should always have a data backup and. + +43 +00:02:46,000 --> 00:02:51,000 +You know, there was a lot of different and very popular ransomware, like a very popular one was called + +44 +00:02:51,000 --> 00:02:52,000 +Cryptolocker. + +45 +00:02:52,000 --> 00:02:55,000 +That one was incredibly popular when it came out. + +46 +00:02:55,000 --> 00:02:57,000 +In fact, our organization got hit with it. + +47 +00:02:57,000 --> 00:03:00,000 +But we have data backups, so it didn't really bother us. + +48 +00:03:01,000 --> 00:03:03,000 +But we did have to do more user training. + +49 +00:03:03,000 --> 00:03:04,000 +How is it distributed? + +50 +00:03:04,000 --> 00:03:10,000 +A lot of times you get a ransomware, you're going to get a ransomware from emails. + +51 +00:03:10,000 --> 00:03:18,000 +A lot of times, different kinds of phishing emails, people receiving emails that they think is good. + +52 +00:03:18,000 --> 00:03:21,000 +This is poor user training and they click on it. + +53 +00:03:21,000 --> 00:03:26,000 +You can also be on a certain website, see malicious advertising or even vulnerabilities in certain + +54 +00:03:26,000 --> 00:03:27,000 +software. + +55 +00:03:29,000 --> 00:03:29,000 +All right. + +56 +00:03:29,000 --> 00:03:30,000 +How do we stop it? + +57 +00:03:30,000 --> 00:03:30,000 +Now? + +58 +00:03:30,000 --> 00:03:36,000 +You notice if you watch some of the previous videos, uh, it's going to be the same thing. + +59 +00:03:36,000 --> 00:03:41,000 +Whether we are having patch management update our machine antivirus software. + +60 +00:03:41,000 --> 00:03:46,000 +This way, if it is a particular malware and the antivirus knows it might be able to get it before it + +61 +00:03:46,000 --> 00:03:49,000 +starts to break your system, segment your network. + +62 +00:03:49,000 --> 00:03:54,000 +That way, if one particular segment gets it and it starts to spread, no big deal, it's not going + +63 +00:03:54,000 --> 00:03:55,000 +to get every machine. + +64 +00:03:55,000 --> 00:03:58,000 +Firewalls can stop it from entering your machine. + +65 +00:03:58,000 --> 00:04:03,000 +Traffic filtering can stop you from downloading or going to bad traffic. + +66 +00:04:03,000 --> 00:04:07,000 +User training is probably the best thing here for when it comes to ransomware. + +67 +00:04:07,000 --> 00:04:12,000 +And the reason is because a lot of time, ransomware is some kind of phishing email. + +68 +00:04:12,000 --> 00:04:15,000 +A lot of times people go to battle websites and get it. + +69 +00:04:15,000 --> 00:04:17,000 +That's why I think user training is the best thing here. + +70 +00:04:17,000 --> 00:04:22,000 +We have to teach the users how to detect phishing emails that this is a phishing email. + +71 +00:04:22,000 --> 00:04:23,000 +Don't click on this. + +72 +00:04:23,000 --> 00:04:27,000 +How do we know that this is a legitimate or illegitimate email? + +73 +00:04:27,000 --> 00:04:34,000 +And when it comes to ransomware, data backups is important because a lot of times if you get hit with + +74 +00:04:34,000 --> 00:04:36,000 +a ransomware, it may encrypt the data. + +75 +00:04:36,000 --> 00:04:43,000 +But if you have backup your data or you have backups of the data, you don't have to worry about ransomware + +76 +00:04:43,000 --> 00:04:44,000 +too much. + +77 +00:04:44,000 --> 00:04:48,000 +Because if it does encrypt your data, at least you have a copy of it. + +78 +00:04:48,000 --> 00:04:52,000 +Now, a lot of organizations don't have backups every minute. + +79 +00:04:52,000 --> 00:04:58,000 +So let's say you have you backed up your data last night, and it's now 4:00 in the afternoon and everybody's + +80 +00:04:58,000 --> 00:05:00,000 +been working all day. + +81 +00:05:00,000 --> 00:05:02,000 +Ransomware comes in and booms encrypts your data. + +82 +00:05:02,000 --> 00:05:06,000 +This is not good news because you basically lost an entire day's worth of work. + +83 +00:05:06,000 --> 00:05:13,000 +If it was 200 people worth of work, that's 200 people of pay loss for that day that you lost. + +84 +00:05:13,000 --> 00:05:15,000 +So don't think, well, I have a data backup. + +85 +00:05:15,000 --> 00:05:16,000 +It's the means, the ends. + +86 +00:05:16,000 --> 00:05:16,000 +No. + +87 +00:05:17,000 --> 00:05:19,000 +You got to make sure you do everything here. + +88 +00:05:19,000 --> 00:05:24,000 +Not just that, but make sure you have a data backup, because I know some people personally that got + +89 +00:05:24,000 --> 00:05:29,000 +hit with ransomware and paid the fee to get their data back because they did not have a backup. + +90 +00:05:29,000 --> 00:05:36,000 +So you personally have made sure to have backups just in case you get hit with this terrible thing. + diff --git a/06 - Signs of Attacks/006 Spyware OB 2.4_en.srt b/06 - Signs of Attacks/006 Spyware OB 2.4_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..bd3344f6c79bf79617d139b8c4e6d47d5cbd7f76 --- /dev/null +++ b/06 - Signs of Attacks/006 Spyware OB 2.4_en.srt @@ -0,0 +1,292 @@ +1 +00:00:00,000 --> 00:00:06,000 +Sitting in a room using a computer gives you a false sense of privacy. + +2 +00:00:06,000 --> 00:00:15,000 +So if I'm sitting in my office and I'm just surfing the internet, I am alone by myself in my room. + +3 +00:00:15,000 --> 00:00:21,000 +You know, I'm looking at I'm reading some news, I'm downloading some software, whatever you may think + +4 +00:00:21,000 --> 00:00:27,000 +that no one is watching, but in actuality, there are malware that can keep an eye on you. + +5 +00:00:27,000 --> 00:00:28,000 +Track what you're doing. + +6 +00:00:28,000 --> 00:00:31,000 +You see, this particular kind of malware is called spyware. + +7 +00:00:32,000 --> 00:00:37,000 +This is designed to gather data from users organizations without their knowledge. + +8 +00:00:37,000 --> 00:00:38,000 +And this is really bad. + +9 +00:00:38,000 --> 00:00:39,000 +Here's why. + +10 +00:00:39,000 --> 00:00:43,000 +You see in the previous malware that I spoke about. + +11 +00:00:44,000 --> 00:00:47,000 +Generally something would go wrong with the machine. + +12 +00:00:47,000 --> 00:00:49,000 +The machine wouldn't boot like a boot sector virus. + +13 +00:00:50,000 --> 00:00:55,000 +Your data would be encrypted, similar like with ransomware. + +14 +00:00:55,000 --> 00:00:59,000 +A worm will generally cause some kind of data corruption on your machine. + +15 +00:00:59,000 --> 00:01:04,000 +Generally, you can tell that you know my machine is acting pretty funny. + +16 +00:01:04,000 --> 00:01:05,000 +It's been really slow. + +17 +00:01:05,000 --> 00:01:08,000 +I couldn't open those files or something like that. + +18 +00:01:08,000 --> 00:01:12,000 +But when it comes to spyware, spyware is a different thing. + +19 +00:01:12,000 --> 00:01:14,000 +Spyware is basically a virus. + +20 +00:01:14,000 --> 00:01:20,000 +It's malicious software that is generally designed to collect your data. + +21 +00:01:20,000 --> 00:01:25,000 +It logs your keystrokes, capture images on your screen, record your browsing history, and even access + +22 +00:01:25,000 --> 00:01:26,000 +files. + +23 +00:01:26,000 --> 00:01:30,000 +So if I install a spyware on your computer, I'll know where you went. + +24 +00:01:30,000 --> 00:01:32,000 +I'll even know what you typed. + +25 +00:01:32,000 --> 00:01:34,000 +So all your passwords I will capture. + +26 +00:01:34,000 --> 00:01:37,000 +I will see what you are looking at because I'm on my. + +27 +00:01:37,000 --> 00:01:40,000 +Take a screenshot of your machine as time goes on. + +28 +00:01:42,000 --> 00:01:47,000 +Some of them can even activate physical cameras and a physical environment to see what you're physically + +29 +00:01:47,000 --> 00:01:48,000 +doing. + +30 +00:01:49,000 --> 00:01:50,000 +They're generally stealth. + +31 +00:01:50,000 --> 00:01:53,000 +They run in the background and they don't want to be detected. + +32 +00:01:53,000 --> 00:01:57,000 +And they're generally going to upload this data to a third party. + +33 +00:01:57,000 --> 00:02:04,000 +In other words, whoever installed this has a reason and they're trying to watch you for whatever reason. + +34 +00:02:04,000 --> 00:02:09,000 +Maybe your high level executive and you have access to some of the organization's biggest bank accounts, + +35 +00:02:09,000 --> 00:02:15,000 +maybe your high level executive, and you have access to some of the organization's most secret projects + +36 +00:02:15,000 --> 00:02:18,000 +coming out, and you're trying to steal it for your for your for a competitor. + +37 +00:02:19,000 --> 00:02:19,000 +Now. + +38 +00:02:20,000 --> 00:02:21,000 +The. + +39 +00:02:21,000 --> 00:02:28,000 +The bad thing that scares me a lot with spyware is that spyware doesn't make your machine act any different. + +40 +00:02:28,000 --> 00:02:31,000 +Your machine is as normal as you know it. + +41 +00:02:31,000 --> 00:02:35,000 +Your machine does not get slow. + +42 +00:02:35,000 --> 00:02:37,000 +Files don't get corrupted. + +43 +00:02:37,000 --> 00:02:39,000 +It's as if nothing is happening. + +44 +00:02:39,000 --> 00:02:42,000 +You could be infected with spyware right now and not even know it. + +45 +00:02:43,000 --> 00:02:48,000 +Now you've got to keep in mind that spyware is a malware. + +46 +00:02:48,000 --> 00:02:52,000 +So the steps we use to stop malware is the same steps. + +47 +00:02:52,000 --> 00:02:53,000 +Obviously. + +48 +00:02:53,000 --> 00:02:54,000 +Let's patch our machines. + +49 +00:02:54,000 --> 00:02:56,000 +Keep your machine updated. + +50 +00:02:56,000 --> 00:03:05,000 +We must all have some form of anti-malware software, some kind of antivirus like McAfee, uh, Norton + +51 +00:03:05,000 --> 00:03:06,000 +or good software. + +52 +00:03:07,000 --> 00:03:08,000 +Now, secure browsing habit. + +53 +00:03:08,000 --> 00:03:10,000 +I can't emphasize that one enough. + +54 +00:03:10,000 --> 00:03:12,000 +Secure browsing habit. + +55 +00:03:12,000 --> 00:03:13,000 +We need to do user training. + +56 +00:03:13,000 --> 00:03:17,000 +The last one there, I should say this one right here. + +57 +00:03:17,000 --> 00:03:24,000 +User training to teach our users where to go, where not to go. + +58 +00:03:24,000 --> 00:03:27,000 +Don't open this email, don't get hacked with this. + +59 +00:03:27,000 --> 00:03:29,000 +Firewalls is another thing. + +60 +00:03:29,000 --> 00:03:34,000 +That way, if the spyware can come through open ports, the firewalls can stop that. + +61 +00:03:34,000 --> 00:03:39,000 +And of course traffic filtering, you can run traffic filtering limits what type of traffic can come + +62 +00:03:39,000 --> 00:03:39,000 +into the machine. + +63 +00:03:39,000 --> 00:03:42,000 +So if it's malicious traffic that does contain spyware, it'll stop you. + +64 +00:03:43,000 --> 00:03:45,000 +Now I've always said this about spyware. + +65 +00:03:45,000 --> 00:03:45,000 +All right. + +66 +00:03:45,000 --> 00:03:50,000 +These all all these malware that we're looking at is of course, dangerous. + +67 +00:03:50,000 --> 00:03:53,000 +But a lot of them you can know. + +68 +00:03:53,000 --> 00:03:54,000 +You'll know your machine is off. + +69 +00:03:54,000 --> 00:03:56,000 +You'll know that something is wrong. + +70 +00:03:56,000 --> 00:03:59,000 +The problem with spyware is you don't know. + +71 +00:03:59,000 --> 00:04:04,000 +That's why it's important to have all of the preventative steps in place. + +72 +00:04:04,000 --> 00:04:04,000 +So you're down. + +73 +00:04:04,000 --> 00:04:07,000 +You don't become infected with spyware. + diff --git a/06 - Signs of Attacks/007 Rootkit OB 2.4_en.srt b/06 - Signs of Attacks/007 Rootkit OB 2.4_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..bbf5453c6993a1dbecff52178ee51bce8cb358ff --- /dev/null +++ b/06 - Signs of Attacks/007 Rootkit OB 2.4_en.srt @@ -0,0 +1,276 @@ +1 +00:00:00,000 --> 00:00:08,000 +I remember working for organizations and as a normal user, and I wanted to get admin privileges. + +2 +00:00:08,000 --> 00:00:13,000 +Maybe I wanted to install a particular software on the machine to give me something to do. + +3 +00:00:13,000 --> 00:00:17,000 +At launch, I used to love I was a big PC gamer. + +4 +00:00:17,000 --> 00:00:22,000 +Sometimes I just want to install a little game to play while I'm on lunch, but the administrator blocks + +5 +00:00:22,000 --> 00:00:23,000 +it now. + +6 +00:00:24,000 --> 00:00:27,000 +A lot of times organizations will. + +7 +00:00:27,000 --> 00:00:31,000 +I should say most of the times organizations will limit people from the admin account. + +8 +00:00:31,000 --> 00:00:35,000 +In other words, you don't have access to do what you want on the machine because first of all, it's + +9 +00:00:35,000 --> 00:00:37,000 +not your machine like I want it. + +10 +00:00:37,000 --> 00:00:40,000 +But there is a way to get around this. + +11 +00:00:40,000 --> 00:00:45,000 +A particular kind of malware we call a rootkit. + +12 +00:00:45,000 --> 00:00:47,000 +What is a rootkit? + +13 +00:00:47,000 --> 00:00:48,000 +Well, let's see what this is. + +14 +00:00:50,000 --> 00:00:58,000 +What a rootkit does is that it basically is a is a kind of a computer program that's designed to provide + +15 +00:00:58,000 --> 00:01:04,000 +continued privilege access to a computer while actively hiding its presence from administrators. + +16 +00:01:04,000 --> 00:01:06,000 +Now, let's break this down. + +17 +00:01:06,000 --> 00:01:14,000 +Continued privileged access the most privileged access privilege access is the admin permission is the + +18 +00:01:14,000 --> 00:01:15,000 +admins privilege. + +19 +00:01:15,000 --> 00:01:22,000 +When you install a rootkit on a computer, you basically boost your privilege from a standard user account + +20 +00:01:22,000 --> 00:01:24,000 +to an administrator account. + +21 +00:01:24,000 --> 00:01:26,000 +Now the question is why would people do this? + +22 +00:01:26,000 --> 00:01:29,000 +So you basically can install anything you want. + +23 +00:01:29,000 --> 00:01:32,000 +You basically can take control of the machine. + +24 +00:01:33,000 --> 00:01:41,000 +Famous rootkits that are done today is if you guys have ever jailbroken an iPhone, for example. + +25 +00:01:42,000 --> 00:01:42,000 +Uh. + +26 +00:01:42,000 --> 00:01:44,000 +Our route. + +27 +00:01:44,000 --> 00:01:45,000 +You ever heard this thing? + +28 +00:01:45,000 --> 00:01:47,000 +A route, an Android device. + +29 +00:01:47,000 --> 00:01:53,000 +So basically, you don't have admin privileges to the operating system on your phone, so you're rooted, + +30 +00:01:53,000 --> 00:01:58,000 +or you install a root kit, and that gives you full administrator access, and you can install any program + +31 +00:01:58,000 --> 00:02:00,000 +from anywhere on the world. + +32 +00:02:00,000 --> 00:02:02,000 +And you're not limited by what the device restrictions are. + +33 +00:02:02,000 --> 00:02:06,000 +Basically removes all restrictions from the device or from your operating system. + +34 +00:02:07,000 --> 00:02:13,000 +But of course, this is not what you should be doing because the administrator set permissions for a + +35 +00:02:13,000 --> 00:02:16,000 +purpose and you doing that is of course a problem. + +36 +00:02:16,000 --> 00:02:22,000 +Now, rootkits can be installed by malicious intrusions on systems to gain access. + +37 +00:02:22,000 --> 00:02:29,000 +A lot of times what hackers will do is they'll gain use or they'll gain access to a user machine as + +38 +00:02:29,000 --> 00:02:35,000 +a user, then install a rootkit and upped their permission to an administrator to steal data off the + +39 +00:02:35,000 --> 00:02:37,000 +company's network or corrupt data. + +40 +00:02:38,000 --> 00:02:42,000 +Now, this is a type of a malware. + +41 +00:02:42,000 --> 00:02:47,000 +In the same way, we're going to stop things like viruses and and worms and so on. + +42 +00:02:47,000 --> 00:02:48,000 +And Trojans is the same way. + +43 +00:02:48,000 --> 00:02:51,000 +We're going to do these things here now. + +44 +00:02:51,000 --> 00:02:52,000 +Secure system access. + +45 +00:02:52,000 --> 00:02:54,000 +One of the steps here. + +46 +00:02:54,000 --> 00:02:57,000 +No one should have unsecure access to a machine. + +47 +00:02:57,000 --> 00:02:59,000 +No one should be an administrator, for example. + +48 +00:03:00,000 --> 00:03:05,000 +Uh, antivirus, obviously, but there is things anti-rootkit tools. + +49 +00:03:05,000 --> 00:03:12,000 +There are some manufacturers that makes tools that are capable of detecting certain kinds of rootkits, + +50 +00:03:12,000 --> 00:03:17,000 +and that you can use to remove them, hardening your system, such as removing unnecessary services, + +51 +00:03:17,000 --> 00:03:18,000 +of course. + +52 +00:03:18,000 --> 00:03:19,000 +Patch management. + +53 +00:03:19,000 --> 00:03:22,000 +Now I want to talk about this one called Secure Boot. + +54 +00:03:22,000 --> 00:03:28,000 +A lot of times rootkits are installed on on a system generally right as the machine is booting up. + +55 +00:03:28,000 --> 00:03:33,000 +So they may put like a USB stick in there and then boot it through this USB stick. + +56 +00:03:33,000 --> 00:03:37,000 +Or they may install a kind of a software on the device. + +57 +00:03:37,000 --> 00:03:41,000 +And when the device reboots, it then of course boots up that malicious software. + +58 +00:03:42,000 --> 00:03:46,000 +So a secure boot is when they're going to use hardware and software to secure the boot process. + +59 +00:03:46,000 --> 00:03:52,000 +That way, no unauthorized code can run and corrupt windows before windows or the Android operating + +60 +00:03:52,000 --> 00:03:53,000 +system even start. + +61 +00:03:54,000 --> 00:03:58,000 +Now I want to I want to point out that the word rootkit, why is it called a rootkit? + +62 +00:03:58,000 --> 00:04:01,000 +Well, the word root is the administrator. + +63 +00:04:01,000 --> 00:04:05,000 +The word root is basically administrator account on Linux box. + +64 +00:04:05,000 --> 00:04:09,000 +And basically a lot of rootkits come from Linux and Unix based systems. + +65 +00:04:09,000 --> 00:04:12,000 +There's not many root kits that will work on windows. + +66 +00:04:13,000 --> 00:04:19,000 +So rootkits are more than likely going to be installed on some kind of Linux and Unix Unix system to + +67 +00:04:19,000 --> 00:04:22,000 +take a normal user and make them an admin. + +68 +00:04:22,000 --> 00:04:25,000 +This is, of course not good because you're bypassing permissions and privileges. + +69 +00:04:25,000 --> 00:04:29,000 +So keep that in mind of what a rootkit is for your exam. + diff --git a/06 - Signs of Attacks/008 Logic Bomb OB 2.4_en.srt b/06 - Signs of Attacks/008 Logic Bomb OB 2.4_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..ce7d4bb3c5cf225afa5c148bd425dce27446a12c --- /dev/null +++ b/06 - Signs of Attacks/008 Logic Bomb OB 2.4_en.srt @@ -0,0 +1,304 @@ +1 +00:00:00,000 --> 00:00:06,000 +I once worked in an organization that had a disgruntled programmer. + +2 +00:00:06,000 --> 00:00:11,000 +To make a long story short, there was a programmer in this organization that didn't like the company. + +3 +00:00:11,000 --> 00:00:17,000 +When the programmer left about six months, exactly six months after he left. + +4 +00:00:17,000 --> 00:00:21,000 +The entire HR database started self deleting itself. + +5 +00:00:21,000 --> 00:00:26,000 +This is a true story, but they had a backup of it and they were able to detect it and fix it before + +6 +00:00:26,000 --> 00:00:28,000 +it caused too much chaos. + +7 +00:00:29,000 --> 00:00:35,000 +Now this particular kind of software, this particular kind of attack that was done, is known as a + +8 +00:00:35,000 --> 00:00:36,000 +logic bomb. + +9 +00:00:36,000 --> 00:00:43,000 +A logic bomb is basically a piece of code intentionally inserted into a software that will set off a + +10 +00:00:43,000 --> 00:00:46,000 +malicious function with a certain condition. + +11 +00:00:47,000 --> 00:00:49,000 +Now, unlike a virus, they don't replicate. + +12 +00:00:50,000 --> 00:00:50,000 +All right. + +13 +00:00:50,000 --> 00:00:57,000 +A logic bomb is generally some code that is inserted or installed or built into a system, generally + +14 +00:00:57,000 --> 00:00:58,000 +for malicious reasons. + +15 +00:00:58,000 --> 00:00:58,000 +But it does. + +16 +00:00:58,000 --> 00:01:02,000 +One of the things that makes it unique is that it stays dormant. + +17 +00:01:02,000 --> 00:01:08,000 +In other words, I can install a logic bomb on your computer and. + +18 +00:01:08,000 --> 00:01:13,000 +It'll do nothing for weeks, months, maybe even years. + +19 +00:01:13,000 --> 00:01:13,000 +It'll do nothing. + +20 +00:01:13,000 --> 00:01:16,000 +But it has a certain trigger point. + +21 +00:01:16,000 --> 00:01:19,000 +It could be that trigger point could be a time or a particular action. + +22 +00:01:19,000 --> 00:01:20,000 +Let me give you a couple of examples. + +23 +00:01:20,000 --> 00:01:25,000 +Let's say I don't like you and I send you an email with an attachment. + +24 +00:01:25,000 --> 00:01:29,000 +You open up the attachment and you double click on it. + +25 +00:01:29,000 --> 00:01:30,000 +Nothing happens. + +26 +00:01:30,000 --> 00:01:31,000 +All right. + +27 +00:01:31,000 --> 00:01:31,000 +Nothing happens. + +28 +00:01:31,000 --> 00:01:34,000 +Maybe I send you a word document and it has a little payload on it. + +29 +00:01:34,000 --> 00:01:35,000 +The word documents. + +30 +00:01:35,000 --> 00:01:36,000 +But nothing happens right away. + +31 +00:01:36,000 --> 00:01:42,000 +Nothing happens exactly two months later when you open it, that you turn your machine on and boom, + +32 +00:01:42,000 --> 00:01:43,000 +everything is wiped out. + +33 +00:01:43,000 --> 00:01:44,000 +That's a logic bomb. + +34 +00:01:44,000 --> 00:01:47,000 +The condition here was time. + +35 +00:01:48,000 --> 00:01:54,000 +So the condition is that as soon as this two month has been met, it erases all the logic bombs. + +36 +00:01:54,000 --> 00:01:55,000 +Watch your machine. + +37 +00:01:55,000 --> 00:01:57,000 +They don't do anything. + +38 +00:01:57,000 --> 00:02:01,000 +But you go visit a particular website or you take a particular action on your machine. + +39 +00:02:01,000 --> 00:02:03,000 +It then activates and record everything you're doing. + +40 +00:02:04,000 --> 00:02:08,000 +Another type of logic bomb now logic bombs the malicious intent. + +41 +00:02:08,000 --> 00:02:10,000 +They're generally going to be destructive in nature. + +42 +00:02:10,000 --> 00:02:16,000 +Some of them, though, can spy also, but generally they're going to do things like delete files or + +43 +00:02:16,000 --> 00:02:17,000 +corrupt data. + +44 +00:02:17,000 --> 00:02:19,000 +They do stay dormant. + +45 +00:02:19,000 --> 00:02:20,000 +That's the thing with them. + +46 +00:02:20,000 --> 00:02:23,000 +You don't know you have it until that condition is met. + +47 +00:02:24,000 --> 00:02:31,000 +Now, a lot of times they're going to be like I mentioned earlier, they're going to be insider threats. + +48 +00:02:31,000 --> 00:02:33,000 +So what exactly is an insider threat? + +49 +00:02:33,000 --> 00:02:41,000 +An insider threat is somebody inside the organization that is malicious, somebody that has an issue + +50 +00:02:41,000 --> 00:02:43,000 +with the organization, somebody that doesn't like what they did. + +51 +00:02:43,000 --> 00:02:48,000 +Maybe they are fired because, uh, for reasons they don't agree with. + +52 +00:02:49,000 --> 00:02:54,000 +So they write these malicious codes and after they're gone, after a certain while the code executes + +53 +00:02:54,000 --> 00:02:59,000 +and the organization gets severely disabled, how do we stop logic bombs? + +54 +00:02:59,000 --> 00:03:03,000 +Remember, a logic bomb is basically a lot of times going to be a form of a malware. + +55 +00:03:03,000 --> 00:03:08,000 +So anti-malware antivirus is what you should have. + +56 +00:03:08,000 --> 00:03:12,000 +Make sure you have and train your users to detect any kind of malicious activity. + +57 +00:03:12,000 --> 00:03:13,000 +Security awareness training. + +58 +00:03:13,000 --> 00:03:18,000 +You also want to make sure you have backups because in the story I told you, it didn't affect them + +59 +00:03:18,000 --> 00:03:21,000 +too much because they had backups of certain systems and data. + +60 +00:03:22,000 --> 00:03:24,000 +Uh, that didn't affect them too much. + +61 +00:03:24,000 --> 00:03:26,000 +If they didn't have the backups, that would have been a problem. + +62 +00:03:26,000 --> 00:03:31,000 +Another thing here we want is code reviews and auditing, especially people that writes codes. + +63 +00:03:31,000 --> 00:03:38,000 +A lot of times these logic bombs are inserted into the application code by, like I mentioned earlier, + +64 +00:03:38,000 --> 00:03:39,000 +malicious programmers. + +65 +00:03:39,000 --> 00:03:45,000 +And you should know and audit the codes to check for malicious codes in your personal organization. + +66 +00:03:45,000 --> 00:03:52,000 +Software access control by limiting what access people have so they don't have an administrator permission + +67 +00:03:52,000 --> 00:03:57,000 +to even get that logic bomb in their change management is important. + +68 +00:03:57,000 --> 00:04:02,000 +Change management is if anybody wants to change source codes, add features, remove features from certain + +69 +00:04:02,000 --> 00:04:07,000 +applications or systems, we'll be able to deny it or approve it. + +70 +00:04:07,000 --> 00:04:08,000 +Depending on what that change is. + +71 +00:04:08,000 --> 00:04:11,000 +It's going to prevent malicious software from from getting in there. + +72 +00:04:12,000 --> 00:04:17,000 +Logic bombs is a common thing in giant enterprises, especially enterprises that has a lot of programmers + +73 +00:04:17,000 --> 00:04:18,000 +coming in and out. + +74 +00:04:18,000 --> 00:04:23,000 +But it can also be a malicious software that's inserted into your organization through some kind of + +75 +00:04:23,000 --> 00:04:24,000 +an email. + +76 +00:04:24,000 --> 00:04:28,000 +So keep an eye out for it because it could be very destructive. + diff --git a/06 - Signs of Attacks/009 Keyloggers OB 2.4_en.srt b/06 - Signs of Attacks/009 Keyloggers OB 2.4_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..4b9760539383733384ffd1aa3d6d8e0a88b0b6b9 --- /dev/null +++ b/06 - Signs of Attacks/009 Keyloggers OB 2.4_en.srt @@ -0,0 +1,520 @@ +1 +00:00:00,000 --> 00:00:02,000 +Okay, imagine this scenario. + +2 +00:00:02,000 --> 00:00:05,000 +You're working in an organization and you're a bad person. + +3 +00:00:05,000 --> 00:00:06,000 +All right? + +4 +00:00:06,000 --> 00:00:09,000 +You're you want to steal the organization's data. + +5 +00:00:09,000 --> 00:00:11,000 +You want to get the administrator password. + +6 +00:00:11,000 --> 00:00:16,000 +You want to, uh, steal the data and take it to a competitor because that's where you're from. + +7 +00:00:16,000 --> 00:00:20,000 +One of the best ways to do that is with this. + +8 +00:00:21,000 --> 00:00:27,000 +This, uh, my fellow security professionals, is what's called a hardware keylogger. + +9 +00:00:27,000 --> 00:00:31,000 +Now, don't ask me why I have this thing, but this is a hardware keylogger. + +10 +00:00:31,000 --> 00:00:33,000 +Now, I know this thing is difficult to see. + +11 +00:00:33,000 --> 00:00:37,000 +I know this video is never going to give it justice here, but this is what it looks like. + +12 +00:00:37,000 --> 00:00:39,000 +It's a tiny little device. + +13 +00:00:39,000 --> 00:00:42,000 +It has a USB port on the back and a USB port in the front. + +14 +00:00:42,000 --> 00:00:43,000 +Now, what exactly is this? + +15 +00:00:43,000 --> 00:00:46,000 +This is a hardware keylogger, and the way this thing works is I have a keyboard. + +16 +00:00:48,000 --> 00:00:52,000 +Normal keyboard and the way a hardware keylogger works is like this. + +17 +00:00:52,000 --> 00:00:56,000 +Basically, you go to somebody's machine. + +18 +00:00:56,000 --> 00:00:59,000 +Obviously you don't do this, you know, off hours or on hours. + +19 +00:00:59,000 --> 00:01:01,000 +Do this off hours when nobody's looking. + +20 +00:01:01,000 --> 00:01:01,000 +Okay. + +21 +00:01:01,000 --> 00:01:08,000 +You go to somebody's machine, you unplug their keyboard, see the number, keyboard, USB wire from + +22 +00:01:08,000 --> 00:01:09,000 +the keyboard. + +23 +00:01:09,000 --> 00:01:12,000 +You take the hardware keylogger, okay? + +24 +00:01:12,000 --> 00:01:14,000 +And you're just going to plug it in. + +25 +00:01:15,000 --> 00:01:18,000 +You're going to plug in the hardware keylogger just like that. + +26 +00:01:18,000 --> 00:01:21,000 +And you notice it doesn't look odd. + +27 +00:01:21,000 --> 00:01:22,000 +It doesn't look off. + +28 +00:01:22,000 --> 00:01:23,000 +All right. + +29 +00:01:23,000 --> 00:01:24,000 +And you plug it into the back of the machine. + +30 +00:01:24,000 --> 00:01:29,000 +Now you're going to remember when you look at it from the back of the machine, it kind of looks like + +31 +00:01:29,000 --> 00:01:29,000 +this. + +32 +00:01:30,000 --> 00:01:31,000 +So you really can't tell? + +33 +00:01:31,000 --> 00:01:33,000 +I mean, like from that angle, right? + +34 +00:01:33,000 --> 00:01:37,000 +From the camera angle, you really can't tell what exactly it's seeing there. + +35 +00:01:37,000 --> 00:01:37,000 +Yeah. + +36 +00:01:38,000 --> 00:01:39,000 +A little bit off. + +37 +00:01:39,000 --> 00:01:41,000 +You really still can't tell. + +38 +00:01:41,000 --> 00:01:42,000 +So you really can't tell. + +39 +00:01:42,000 --> 00:01:42,000 +This is on. + +40 +00:01:42,000 --> 00:01:44,000 +Now here's what this little device does. + +41 +00:01:44,000 --> 00:01:49,000 +This little device captures every single keystroke. + +42 +00:01:49,000 --> 00:01:51,000 +Every single keystroke. + +43 +00:01:51,000 --> 00:01:53,000 +Username. + +44 +00:01:53,000 --> 00:01:54,000 +Passwords. + +45 +00:01:54,000 --> 00:01:55,000 +Memos. + +46 +00:01:55,000 --> 00:01:55,000 +Email. + +47 +00:01:55,000 --> 00:01:58,000 +If they typed it, it's on this device. + +48 +00:01:58,000 --> 00:02:01,000 +Now, this one in particular I have here is a pretty advanced one. + +49 +00:02:01,000 --> 00:02:09,000 +This thing has a built in wireless access point that I can access the text file with all the keystrokes + +50 +00:02:10,000 --> 00:02:13,000 +on my phone, and I could monitor what you're typing in real time. + +51 +00:02:14,000 --> 00:02:17,000 +Now, you could buy this, and I'm not going to tell you where, because that's not what this class + +52 +00:02:17,000 --> 00:02:18,000 +is about. + +53 +00:02:18,000 --> 00:02:23,000 +If you're interested in learning more about these kinds of things and how to use them, take my course, + +54 +00:02:23,000 --> 00:02:29,000 +my Certified Ethical Hacking course, where I actually show you how to use this, and I will show you + +55 +00:02:29,000 --> 00:02:32,000 +how to use the software keyloggers also. + +56 +00:02:32,000 --> 00:02:37,000 +But anyways, this one allows me to connect my phone to it and steal the data right off of it, or take + +57 +00:02:37,000 --> 00:02:40,000 +the data right off of it in real time as you're typing. + +58 +00:02:40,000 --> 00:02:43,000 +Now this, of course, is a keylogger. + +59 +00:02:43,000 --> 00:02:44,000 +So what exactly is it? + +60 +00:02:44,000 --> 00:02:44,000 +What? + +61 +00:02:44,000 --> 00:02:45,000 +I just told you what it is. + +62 +00:02:45,000 --> 00:02:47,000 +It's basically surveillance. + +63 +00:02:47,000 --> 00:02:48,000 +They come in two types. + +64 +00:02:48,000 --> 00:02:52,000 +What I showed you is a hardware keylogger. + +65 +00:02:52,000 --> 00:02:54,000 +There is another one called a software keylogger. + +66 +00:02:54,000 --> 00:02:58,000 +And this is just an application that's installed on your machine. + +67 +00:02:58,000 --> 00:03:05,000 +And then that application basically will that application will then. + +68 +00:03:06,000 --> 00:03:11,000 +Capture all your keystrokes, and a lot of them do screenshots and so on their legal versions of this. + +69 +00:03:11,000 --> 00:03:18,000 +In fact, organizations have legal software that they use to capture your keystrokes. + +70 +00:03:18,000 --> 00:03:24,000 +Many organizations install keyloggers not for malicious intent, but for surveillance and monitoring + +71 +00:03:24,000 --> 00:03:27,000 +because they're machines and they can do whatever they want with it. + +72 +00:03:27,000 --> 00:03:30,000 +Uh, but you just have to be notified that it's there. + +73 +00:03:30,000 --> 00:03:30,000 +All right. + +74 +00:03:30,000 --> 00:03:34,000 +By law, I think they have to notify you, especially that employee handbook that we don't read, that + +75 +00:03:34,000 --> 00:03:34,000 +we all sign to. + +76 +00:03:34,000 --> 00:03:35,000 +It's probably listed there. + +77 +00:03:35,000 --> 00:03:42,000 +Now, what's the primary purpose is generally to monitor logs, all the key presses made by the user, + +78 +00:03:42,000 --> 00:03:44,000 +any kind of sensitive data. + +79 +00:03:44,000 --> 00:03:49,000 +Now I'm talking about when I say key logger from the context of discourse, we're talking about it being + +80 +00:03:49,000 --> 00:03:50,000 +malicious. + +81 +00:03:50,000 --> 00:03:55,000 +In other words, stealing your passwords, stealing the data, the text that you're typing. + +82 +00:03:55,000 --> 00:03:55,000 +Now. + +83 +00:03:57,000 --> 00:04:01,000 +Keyloggers, the couple of different ways to stop them. + +84 +00:04:01,000 --> 00:04:01,000 +All right. + +85 +00:04:01,000 --> 00:04:04,000 +Of course, if it's a piece of software you need anti. + +86 +00:04:04,000 --> 00:04:10,000 +Software give you less access to you can't install them make them make your user account access control. + +87 +00:04:10,000 --> 00:04:11,000 +No changes to a system. + +88 +00:04:11,000 --> 00:04:16,000 +No one should be able to change a system without approval of installing software or hardware. + +89 +00:04:16,000 --> 00:04:20,000 +Always have a backup because the keyloggers can cause corruption. + +90 +00:04:20,000 --> 00:04:22,000 +Train your users to detect. + +91 +00:04:22,000 --> 00:04:24,000 +For example, you can train users to. + +92 +00:04:24,000 --> 00:04:25,000 +Every once in a while. + +93 +00:04:25,000 --> 00:04:32,000 +Watch the back of the machine for the look for something as covert as this, um, update the operating + +94 +00:04:32,000 --> 00:04:37,000 +system as much as possible, especially applications two now I want to come down here. + +95 +00:04:38,000 --> 00:04:41,000 +I added some really specific things for key loggers. + +96 +00:04:41,000 --> 00:04:48,000 +One of the best things we can do for a key logger is by enabling two for or two factor authentication. + +97 +00:04:48,000 --> 00:04:51,000 +If you remember, there are multiple ways to authenticate something. + +98 +00:04:51,000 --> 00:04:54,000 +You know something you have, something you are, somewhere you are, and so on. + +99 +00:04:55,000 --> 00:05:01,000 +So instead of having just the password, maybe they have to do a password and a biometric. + +100 +00:05:01,000 --> 00:05:06,000 +And that's important because if that's how you login in right now, you do a password and a thumbprint. + +101 +00:05:06,000 --> 00:05:09,000 +Even if I steal your password with this. + +102 +00:05:10,000 --> 00:05:12,000 +It's not going to help me because I don't have your thumbprint. + +103 +00:05:13,000 --> 00:05:16,000 +So that would be very useful, right? + +104 +00:05:16,000 --> 00:05:19,000 +It's not just or maybe you use a smart card and a password. + +105 +00:05:19,000 --> 00:05:25,000 +If I have the, uh, password, I'm not going to be able to do anything else because I still need the + +106 +00:05:25,000 --> 00:05:31,000 +smart card monitor for hardware key loggers once in a while, as admins, especially on the machine + +107 +00:05:31,000 --> 00:05:35,000 +of the CEO, people with access to really sensitive data, maybe you just want to pop in the back. + +108 +00:05:35,000 --> 00:05:41,000 +I showed you this and I show people this because most security administrator has never, ever seen one. + +109 +00:05:41,000 --> 00:05:42,000 +Now you do. + +110 +00:05:42,000 --> 00:05:46,000 +You can go online, just Google hardware key loggers for purchase. + +111 +00:05:46,000 --> 00:05:48,000 +See all the websites. + +112 +00:05:48,000 --> 00:05:52,000 +This is not a course on telling you how to buy hacking software and tools, but see what they look like. + +113 +00:05:52,000 --> 00:05:55,000 +Be familiar with their design. + +114 +00:05:55,000 --> 00:05:57,000 +So when you see one, you'll be like, ah, that's a hardware key logger. + +115 +00:05:57,000 --> 00:05:59,000 +They come a lot bigger. + +116 +00:05:59,000 --> 00:06:00,000 +This is a really covert one. + +117 +00:06:00,000 --> 00:06:01,000 +I really like this one. + +118 +00:06:01,000 --> 00:06:07,000 +Now the other thing you could do is you can prevent people, you tell people use the on screen keyboard. + +119 +00:06:07,000 --> 00:06:10,000 +So in windows there's always a little keyboard icon. + +120 +00:06:10,000 --> 00:06:15,000 +When you go to log in, tell them to use that particular don't use the physical keyboard, use that + +121 +00:06:15,000 --> 00:06:16,000 +software keyboard. + +122 +00:06:16,000 --> 00:06:21,000 +And if they're using a software keyboard, they're not going to be able to capture the keystrokes. + +123 +00:06:21,000 --> 00:06:23,000 +This never went through the physical keyboard. + +124 +00:06:23,000 --> 00:06:28,000 +Now, key loggers are some of the best ways to steal information. + +125 +00:06:28,000 --> 00:06:29,000 +Guys, I'm telling you, especially hardware. + +126 +00:06:29,000 --> 00:06:32,000 +But this one here, you really have to be on the inside to make this work. + +127 +00:06:32,000 --> 00:06:34,000 +Software keyloggers. + +128 +00:06:34,000 --> 00:06:37,000 +You'll be able to send people okay. + +129 +00:06:37,000 --> 00:06:41,000 +Make sure to know the ways because on your exam you may see a question like how do you stop this? + +130 +00:06:41,000 --> 00:06:47,000 +One of the best ways is do a factor authentication or on screen keyboard to stop one of these devices. + diff --git a/06 - Signs of Attacks/010 Bloatware OB 2.4_en.srt b/06 - Signs of Attacks/010 Bloatware OB 2.4_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..a5ca3ccb64f921dcfcda3d58d4dbe7f3d3a56a2b --- /dev/null +++ b/06 - Signs of Attacks/010 Bloatware OB 2.4_en.srt @@ -0,0 +1,216 @@ +1 +00:00:00,000 --> 00:00:08,000 +So one of the things that drives me crazy is when you purchase a computer from a store or of a device + +2 +00:00:08,000 --> 00:00:11,000 +like this Samsung, it comes with a lot of junk. + +3 +00:00:11,000 --> 00:00:17,000 +Like, I really hate the quote unquote bloatware that it comes with. + +4 +00:00:18,000 --> 00:00:24,000 +Now, bloatware, by definition, is unwanted software that comes pre-installed on a device. + +5 +00:00:24,000 --> 00:00:29,000 +For example, Samsung installs a whole bunch of junk. + +6 +00:00:29,000 --> 00:00:31,000 +That I don't want. + +7 +00:00:31,000 --> 00:00:34,000 +I'm never going to use their stuff. + +8 +00:00:34,000 --> 00:00:36,000 +I wish I could just on some of them. + +9 +00:00:36,000 --> 00:00:38,000 +You can't really even uninstall. + +10 +00:00:38,000 --> 00:00:41,000 +This particular thing is called bloatware. + +11 +00:00:42,000 --> 00:00:48,000 +Now a lot of times in windows, especially when you purchase a laptop or you purchase a desktop from + +12 +00:00:48,000 --> 00:00:52,000 +particular manufacturers like Dell or Lenovo. + +13 +00:00:52,000 --> 00:00:58,000 +I noticed my Lenovo laptop had a ton of software installed that I had to just go and on install. + +14 +00:00:58,000 --> 00:01:00,000 +Now, it's not really malicious. + +15 +00:01:00,000 --> 00:01:01,000 +That's the thing. + +16 +00:01:01,000 --> 00:01:06,000 +They're not inherently malicious, like malware, like bloatware is not there to steal your data corrupt, + +17 +00:01:06,000 --> 00:01:08,000 +but it does slow down the system. + +18 +00:01:08,000 --> 00:01:13,000 +It does take up unnecessary memory, because when the machines start to bloatware, the maybe they have + +19 +00:01:13,000 --> 00:01:19,000 +a specific pen software, maybe they have a particular type in software, maybe they have a particular + +20 +00:01:19,000 --> 00:01:24,000 +chat software that they're always installing takes up system resources, disk space and times. + +21 +00:01:25,000 --> 00:01:28,000 +Some of them may not even be updated and may even cause a vulnerability. + +22 +00:01:28,000 --> 00:01:30,000 +So what is the characteristics? + +23 +00:01:30,000 --> 00:01:31,000 +Well, they're pre-installed. + +24 +00:01:31,000 --> 00:01:33,000 +They consume a lot of resources. + +25 +00:01:33,000 --> 00:01:36,000 +Sometimes they're difficult or sometimes you can't even remove them. + +26 +00:01:36,000 --> 00:01:41,000 +And sometimes these applications may cause other security risks. + +27 +00:01:41,000 --> 00:01:41,000 +Why? + +28 +00:01:41,000 --> 00:01:46,000 +Because you see those applications may not be updatable. + +29 +00:01:46,000 --> 00:01:47,000 +What can you do about this? + +30 +00:01:47,000 --> 00:01:50,000 +Well careful selection of devices now. + +31 +00:01:52,000 --> 00:01:58,000 +My colleague here at TIAA told me that he hates Samsung because of all the bloatware, and he buys the + +32 +00:01:58,000 --> 00:02:00,000 +pixel Google Pixel devices. + +33 +00:02:00,000 --> 00:02:02,000 +This is a Galaxy phone. + +34 +00:02:02,000 --> 00:02:06,000 +He has a pixel phone, and he says the pixel comes with no bloatware. + +35 +00:02:06,000 --> 00:02:09,000 +In other words, just pure, plain Android. + +36 +00:02:10,000 --> 00:02:10,000 +Great. + +37 +00:02:10,000 --> 00:02:12,000 +So careful selection. + +38 +00:02:12,000 --> 00:02:15,000 +Maybe next time I'll get a pixel to get rid of the Samsung bloatware. + +39 +00:02:16,000 --> 00:02:18,000 +Uh, bloatware removal tools. + +40 +00:02:18,000 --> 00:02:20,000 +Sometimes they have specific tools for that. + +41 +00:02:20,000 --> 00:02:25,000 +If you could install your own operating system, you may not be able to do that with a with a phone, + +42 +00:02:25,000 --> 00:02:26,000 +but certain things. + +43 +00:02:26,000 --> 00:02:33,000 +So a lot of times when I purchase a pre-made machine, like I got a Dell laptop, uh, that I've been + +44 +00:02:33,000 --> 00:02:37,000 +using and that particular one I just want to use at work. + +45 +00:02:37,000 --> 00:02:37,000 +At home. + +46 +00:02:37,000 --> 00:02:42,000 +I have my Lenovo at work the moment we got it, we just uninstalled, put in our own operating system. + +47 +00:02:42,000 --> 00:02:45,000 +It wiped everything out because we can't deal with the bloatware. + +48 +00:02:45,000 --> 00:02:50,000 +Of course, you could disable any unnecessary applications that may be needed. + +49 +00:02:50,000 --> 00:02:52,000 +All right, keep in mind something with bloatware. + +50 +00:02:52,000 --> 00:02:54,000 +Bloatware is not necessarily bad. + +51 +00:02:54,000 --> 00:02:56,000 +It's not done with a malicious intent. + +52 +00:02:56,000 --> 00:03:01,000 +It's just the the makers of the device giving you things they feel that you might use. + +53 +00:03:01,000 --> 00:03:06,000 +And sometimes they're just things that you don't want it just bloating up your device for no reason. + +54 +00:03:06,000 --> 00:03:11,000 +The best thing to do is see if you can remove them so you can speed up your device and get rid of bloatware. + diff --git a/06 - Signs of Attacks/011 DDOS OB 2.4_en.srt b/06 - Signs of Attacks/011 DDOS OB 2.4_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..9be2f65098bd27031a0a2b79b082edb53af8a588 --- /dev/null +++ b/06 - Signs of Attacks/011 DDOS OB 2.4_en.srt @@ -0,0 +1,916 @@ +1 +00:00:00,000 --> 00:00:05,000 +So far, I've covered quite a few different attacks that can take out a network. + +2 +00:00:05,000 --> 00:00:12,000 +Disabled systems corrupt data, but one of the most prominent attacks that still affects systems until + +3 +00:00:12,000 --> 00:00:17,000 +today, and it's something that all network administrators have to be worried about, is called a DDoS + +4 +00:00:17,000 --> 00:00:20,000 +or distributed denial of service. + +5 +00:00:20,000 --> 00:00:22,000 +What exactly is this kind of attack? + +6 +00:00:22,000 --> 00:00:27,000 +Well, in this video, in this video, I want to go through in depth what exactly is it and how are + +7 +00:00:27,000 --> 00:00:29,000 +we going to prevent it in different types of it. + +8 +00:00:29,000 --> 00:00:31,000 +So let's see exactly what it is. + +9 +00:00:31,000 --> 00:00:39,000 +Well, a DDoS is basically malicious generally always is malicious to disrupt the normal traffic of + +10 +00:00:39,000 --> 00:00:42,000 +a targeted server service or network. + +11 +00:00:42,000 --> 00:00:48,000 +And the key thing is going to be by overwhelming the target and target or its surrounding infrastructure + +12 +00:00:48,000 --> 00:00:50,000 +with a flood of traffic, basically. + +13 +00:00:51,000 --> 00:00:52,000 +Let's say you have a network right now. + +14 +00:00:52,000 --> 00:00:55,000 +I'm going to send you so much traffic. + +15 +00:00:55,000 --> 00:01:00,000 +I'm going to let's say your infrastructure can hold 1000 requests at any given point, but I'm going + +16 +00:01:00,000 --> 00:01:02,000 +to send you 20,000. + +17 +00:01:02,000 --> 00:01:06,000 +My objective is to bring your system to a crawl and halt and shut it down. + +18 +00:01:06,000 --> 00:01:10,000 +That way, when people try to come to your website or you try to use your network, it's not going to + +19 +00:01:10,000 --> 00:01:14,000 +work because I've overwhelmed the system with a ton of traffic. + +20 +00:01:14,000 --> 00:01:16,000 +And that's the whole idea behind this. + +21 +00:01:16,000 --> 00:01:22,000 +Now, what it is is that they're going to utilize multiple compromised computer systems. + +22 +00:01:22,000 --> 00:01:25,000 +These are known as bots as a source of an attack traffic. + +23 +00:01:25,000 --> 00:01:29,000 +Now what what these bots are made up of. + +24 +00:01:29,000 --> 00:01:31,000 +So first of all, let's define the word bot. + +25 +00:01:31,000 --> 00:01:36,000 +A bot is generally some kind of infected system. + +26 +00:01:36,000 --> 00:01:40,000 +A bot can be a desktop like my windows box here. + +27 +00:01:40,000 --> 00:01:43,000 +It could be even an IoT device or internet of things. + +28 +00:01:43,000 --> 00:01:50,000 +Now, IoT devices are basically anything that connects to the internet, from your phone to the camera + +29 +00:01:50,000 --> 00:01:54,000 +in your ceiling, to your cable box, to your TV, to your printer. + +30 +00:01:54,000 --> 00:01:58,000 +If something has an IP address, technically it could be turned into a bot. + +31 +00:01:58,000 --> 00:02:01,000 +All they need to do is compromise that machine. + +32 +00:02:01,000 --> 00:02:03,000 +They install malicious software. + +33 +00:02:03,000 --> 00:02:04,000 +I'm talking Debian hacker. + +34 +00:02:04,000 --> 00:02:09,000 +They install malicious software, they take control of it, and now they have thousands of machines + +35 +00:02:09,000 --> 00:02:10,000 +around the world. + +36 +00:02:10,000 --> 00:02:13,000 +Take for example, let me give you guys a quick example. + +37 +00:02:13,000 --> 00:02:19,000 +Let's say uh, there is a vulnerability on Linksys routers or D-Link. + +38 +00:02:19,000 --> 00:02:20,000 +All right. + +39 +00:02:20,000 --> 00:02:21,000 +One of one of those brands. + +40 +00:02:21,000 --> 00:02:27,000 +And I'm able to exploit that vulnerability and take control of everybody's Linksys or D-Link router + +41 +00:02:27,000 --> 00:02:28,000 +in the world. + +42 +00:02:28,000 --> 00:02:35,000 +That gives me millions of bots, that gives me millions of computers, technically full computers that + +43 +00:02:35,000 --> 00:02:40,000 +I can use to generate traffic to send to your website and take you offline. + +44 +00:02:40,000 --> 00:02:42,000 +That's the idea behind a botnet. + +45 +00:02:42,000 --> 00:02:49,000 +Now I want to show you guys a website, this particular one here, you guys can put this link in and + +46 +00:02:49,000 --> 00:02:52,000 +this is going to show you a live DDoS attack. + +47 +00:02:52,000 --> 00:02:55,000 +Now as I'm recording this. + +48 +00:02:55,000 --> 00:02:55,000 +All right. + +49 +00:02:55,000 --> 00:03:03,000 +As I am recording this right here today, it's December 1st, it's 3:00 in the afternoon. + +50 +00:03:03,000 --> 00:03:08,000 +And I want to show you guys, um, here is a live DDoS map. + +51 +00:03:08,000 --> 00:03:10,000 +So this is the website that I just gave you. + +52 +00:03:10,000 --> 00:03:12,000 +Here's a live website of what it looks like. + +53 +00:03:12,000 --> 00:03:15,000 +So I'm just going to go to full interactive map when you go to there. + +54 +00:03:15,000 --> 00:03:22,000 +And then it brings you this and it starts to show all the DDoS events that's being recorded as I'm talking + +55 +00:03:22,000 --> 00:03:22,000 +to you. + +56 +00:03:22,000 --> 00:03:26,000 +So DDoS events right now are showing 23 DDoS events. + +57 +00:03:26,000 --> 00:03:32,000 +33 and you're going to see this number go up as the map stays on longer, it's going to start to look + +58 +00:03:32,000 --> 00:03:34,000 +like this world war going on. + +59 +00:03:34,000 --> 00:03:39,000 +Now, I'm not going to get into the specifics of this, but if you leave it on for quite a long time, + +60 +00:03:39,000 --> 00:03:42,000 +it gets insane as it detects more events. + +61 +00:03:42,000 --> 00:03:51,000 +So these these particular DDoS event is actually being reported to this company by firewall vendors + +62 +00:03:51,000 --> 00:03:56,000 +such as, uh, sonicwall, like I have on my desk here, or a checkpoint or something like that. + +63 +00:03:56,000 --> 00:04:01,000 +So if you think that DDoS events are not happening, oh, they're happening. + +64 +00:04:01,000 --> 00:04:03,000 +And here's a live map that shows you that. + +65 +00:04:04,000 --> 00:04:09,000 +Okay, uh, I don't want to spend a lot of time on that because it is not going to be really covered + +66 +00:04:09,000 --> 00:04:11,000 +on your exam, like how many DDoS you have in a day. + +67 +00:04:11,000 --> 00:04:14,000 +But I just want to prove to you guys that, you know what? + +68 +00:04:14,000 --> 00:04:20,000 +There is a lot of DDoS attack happens every single minute of the world right now. + +69 +00:04:20,000 --> 00:04:25,000 +There's a bunch of companies getting hit right now with a DDoS and they're being taken out. + +70 +00:04:26,000 --> 00:04:27,000 +The websites are not functional. + +71 +00:04:28,000 --> 00:04:30,000 +Their network services are not functioning. + +72 +00:04:30,000 --> 00:04:32,000 +Those companies can't collect payments and so on. + +73 +00:04:32,000 --> 00:04:33,000 +All right. + +74 +00:04:33,000 --> 00:04:37,000 +There are some things here we want to get into with this, as there are a variety of different DDoS + +75 +00:04:37,000 --> 00:04:39,000 +that I want to talk about with you guys. + +76 +00:04:39,000 --> 00:04:43,000 +So the first one up I want to mention is going to be a network based DDoS attack. + +77 +00:04:43,000 --> 00:04:46,000 +Now, the one that I explained to you is basically that. + +78 +00:04:47,000 --> 00:04:52,000 +This is when they use multiple compromise computers and do so. + +79 +00:04:52,000 --> 00:04:54,000 +The compromise computers are going to be the bots. + +80 +00:04:54,000 --> 00:04:55,000 +All right. + +81 +00:04:55,000 --> 00:04:56,000 +So this is going to be all the bots. + +82 +00:04:56,000 --> 00:04:59,000 +And you notice how the bots is taking out the target here. + +83 +00:04:59,000 --> 00:05:00,000 +As you guys can see. + +84 +00:05:01,000 --> 00:05:02,000 +Um how do they do it. + +85 +00:05:02,000 --> 00:05:08,000 +Well how does the bad guys get, you know, how do they get the bots? + +86 +00:05:08,000 --> 00:05:15,000 +Well, what they do is they infect normal computers or IoT devices with some kind of malicious software. + +87 +00:05:15,000 --> 00:05:19,000 +Generally, it's going to be a Trojan that they're probably going to install on a machine. + +88 +00:05:19,000 --> 00:05:25,000 +And once they get control of this, then they're going to launch a massive attack against it. + +89 +00:05:25,000 --> 00:05:29,000 +Now, it could be as something these bots can be something as simple as just going to a website and + +90 +00:05:29,000 --> 00:05:35,000 +keep refreshing the website over and over, and that's really one of the easiest way to do it. + +91 +00:05:35,000 --> 00:05:40,000 +And basically anybody that tries to go to that target is not going to be able to get there. + +92 +00:05:41,000 --> 00:05:44,000 +Now another one is called a UDP flood. + +93 +00:05:44,000 --> 00:05:48,000 +Now this is not a networking course. + +94 +00:05:48,000 --> 00:05:54,000 +Uh, and if you are studying networking, all right, uh, if you are in Network Plus or you are in + +95 +00:05:54,000 --> 00:05:59,000 +Network Plus right now and you're watching this video, remember something there's TCP and there's UDP. + +96 +00:05:59,000 --> 00:06:04,000 +Remember TCP has a handshake but UDP doesn't. + +97 +00:06:04,000 --> 00:06:11,000 +So what I could do is I could send you a bunch of illegitimate UDP traffic. + +98 +00:06:11,000 --> 00:06:14,000 +So look at this right now you have an attacker. + +99 +00:06:14,000 --> 00:06:17,000 +And there are certain protocols that runs on UDP. + +100 +00:06:17,000 --> 00:06:21,000 +For example, uh, NTP or Network Time Protocol. + +101 +00:06:21,000 --> 00:06:25,000 +For example, you can see Ssdp also and even UDP fragmented packets. + +102 +00:06:25,000 --> 00:06:30,000 +And basically what I'm doing is I'm just sending sending tons and tons of UDP packets to you. + +103 +00:06:30,000 --> 00:06:35,000 +Now UDP doesn't have the three way handshake like TCP does. + +104 +00:06:35,000 --> 00:06:37,000 +We'll look at that there in a minute. + +105 +00:06:37,000 --> 00:06:45,000 +But UDP, they can still send a lot of traffic to you to overwhelm that particular router. + +106 +00:06:45,000 --> 00:06:50,000 +Uh, and take it out so you can see like this client is sending the legitimate traffic and the attacker + +107 +00:06:50,000 --> 00:06:52,000 +is sending really bad traffic. + +108 +00:06:52,000 --> 00:06:58,000 +Once again, the objective here is to overwhelm that router, bring that router particularly down. + +109 +00:06:58,000 --> 00:07:06,000 +Now I want to talk a little bit about the TCP handshake, because one of the most famous DDoS attacks + +110 +00:07:06,000 --> 00:07:14,000 +that you see on multiple exams that they talk about Security+, CISSP and so on, are call Syn floods. + +111 +00:07:14,000 --> 00:07:15,000 +And here's what these are. + +112 +00:07:16,000 --> 00:07:23,000 +If you remember how the TCP how the TCP handshake works, it's sin sin act and act. + +113 +00:07:23,000 --> 00:07:24,000 +All right. + +114 +00:07:24,000 --> 00:07:26,000 +So I'm going to send you something. + +115 +00:07:26,000 --> 00:07:27,000 +Synchronization. + +116 +00:07:27,000 --> 00:07:28,000 +You send me back a syn ack. + +117 +00:07:28,000 --> 00:07:30,000 +And I respond back with an acknowledgment. + +118 +00:07:30,000 --> 00:07:34,000 +Once again review your networking section to learn more about this. + +119 +00:07:34,000 --> 00:07:35,000 +But that's what it is. + +120 +00:07:35,000 --> 00:07:37,000 +So if I if you're the receiver right, I want to talk to you. + +121 +00:07:37,000 --> 00:07:39,000 +I'm going to send you a synchronization. + +122 +00:07:39,000 --> 00:07:43,000 +You send me back a synchronization acknowledgment and I send you back an acknowledgment. + +123 +00:07:43,000 --> 00:07:47,000 +Now Syn floods is going to play off of that. + +124 +00:07:47,000 --> 00:07:50,000 +Syn floods is going to work like this. + +125 +00:07:51,000 --> 00:07:53,000 +So take a look at the attacker here. + +126 +00:07:53,000 --> 00:07:54,000 +The attacker host. + +127 +00:07:54,000 --> 00:07:55,000 +This is the victim machine. + +128 +00:07:55,000 --> 00:08:03,000 +What the attacker does is the attacker sends thousands, hundreds and thousands of Syn packets with + +129 +00:08:03,000 --> 00:08:09,000 +a spoofed source IP, not the source IP of the attacker sends it to the victim. + +130 +00:08:09,000 --> 00:08:13,000 +Now, when you receive a synchronization packet, what do you do? + +131 +00:08:13,000 --> 00:08:18,000 +You send back whoever sent that to you as Syn act, right? + +132 +00:08:18,000 --> 00:08:19,000 +So you send it back. + +133 +00:08:19,000 --> 00:08:23,000 +But remember you're sending it to an IP address that doesn't exist because the attacker spoofed it. + +134 +00:08:23,000 --> 00:08:25,000 +So you send back. + +135 +00:08:25,000 --> 00:08:26,000 +Now what do you do? + +136 +00:08:27,000 --> 00:08:30,000 +Remember the handshake sin sin act and act. + +137 +00:08:30,000 --> 00:08:32,000 +So what do you do now is you wait. + +138 +00:08:32,000 --> 00:08:39,000 +The victim waits for the actual computers to respond with an acknowledgment, but he never gets it. + +139 +00:08:39,000 --> 00:08:40,000 +So it works like this. + +140 +00:08:40,000 --> 00:08:45,000 +Let's say me and you in a conversation and I send you synchronization and you say synchronization, + +141 +00:08:45,000 --> 00:08:46,000 +acknowledgement. + +142 +00:08:46,000 --> 00:08:47,000 +And then I never respond. + +143 +00:08:47,000 --> 00:08:49,000 +I'm just going to say, so let's try it. + +144 +00:08:49,000 --> 00:08:52,000 +Synchronization you respond synchronization acknowledgment. + +145 +00:08:52,000 --> 00:08:53,000 +And I'm just looking at you. + +146 +00:08:54,000 --> 00:08:55,000 +See you're waiting, right? + +147 +00:08:55,000 --> 00:08:56,000 +You're waiting for me to say acknowledgement. + +148 +00:08:56,000 --> 00:08:58,000 +I never say it, though. + +149 +00:08:58,000 --> 00:09:01,000 +The idea is I'm going to keep doing this over and over. + +150 +00:09:01,000 --> 00:09:03,000 +I'm going to send you thousands and thousands of these things. + +151 +00:09:03,000 --> 00:09:05,000 +And what it does is that it starts to open up a wait state. + +152 +00:09:05,000 --> 00:09:11,000 +So the memory in the victim's machine, whether it's a router or it's a server farm or something, what + +153 +00:09:11,000 --> 00:09:16,000 +happens is the memory and the machine starts to get overwhelmed with these wait states. + +154 +00:09:16,000 --> 00:09:17,000 +Wait wait wait wait wait wait wait. + +155 +00:09:18,000 --> 00:09:21,000 +This of course brings the ram down and disables the machine. + +156 +00:09:22,000 --> 00:09:23,000 +The machine can't function with no more Ram. + +157 +00:09:23,000 --> 00:09:26,000 +That's the idea between this now. + +158 +00:09:27,000 --> 00:09:28,000 +The are some ways that you can stop this. + +159 +00:09:28,000 --> 00:09:30,000 +And one of the easiest ways you can stop this. + +160 +00:09:30,000 --> 00:09:37,000 +And a lot of firewalls, including this firewall, can even detect things like Syn floods and stop them, + +161 +00:09:37,000 --> 00:09:42,000 +because if they have a lot of, uh, wait states open up, they start to shut them down without actually + +162 +00:09:42,000 --> 00:09:43,000 +getting back the acknowledgement. + +163 +00:09:43,000 --> 00:09:48,000 +So there are syn flood detections and preventions on devices nowadays. + +164 +00:09:50,000 --> 00:09:55,000 +Two terms that you may want to know for your exam is something we call amplification and reflection. + +165 +00:09:56,000 --> 00:10:00,000 +Some some protocols allows you to amplify attacks. + +166 +00:10:00,000 --> 00:10:07,000 +So an amplified attack is like you send one request, but then that request amplifies into three requests. + +167 +00:10:07,000 --> 00:10:08,000 +So let's say there's a phone here. + +168 +00:10:08,000 --> 00:10:12,000 +Let's say this is a DNS server and there's a victim here. + +169 +00:10:12,000 --> 00:10:12,000 +And then there's me. + +170 +00:10:12,000 --> 00:10:13,000 +So I'm the attacker. + +171 +00:10:13,000 --> 00:10:15,000 +I sent a request to DNS server. + +172 +00:10:15,000 --> 00:10:18,000 +The DNS server then sends out three requests to the victim. + +173 +00:10:18,000 --> 00:10:22,000 +So this is this is a this is a way of me amplifying the amount of traffic. + +174 +00:10:23,000 --> 00:10:25,000 +I can send you. + +175 +00:10:25,000 --> 00:10:27,000 +Another one is called a reflective dos. + +176 +00:10:27,000 --> 00:10:30,000 +So a reflective dos is this. + +177 +00:10:30,000 --> 00:10:36,000 +Basically, I'm going to reflect traffic off of machines to come to you. + +178 +00:10:36,000 --> 00:10:39,000 +And you can also use the DNS server to do this. + +179 +00:10:39,000 --> 00:10:45,000 +So basically meaning the attacker used a third party servers to direct traffic to the victim. + +180 +00:10:45,000 --> 00:10:51,000 +So basically instead of me sending you a whole bunch of DDoS attacks directly from me, basically I'm + +181 +00:10:51,000 --> 00:10:54,000 +going to put a server in between and then have that server go come after you. + +182 +00:10:54,000 --> 00:10:55,000 +That's the idea. + +183 +00:10:55,000 --> 00:10:57,000 +Some reflecting traffic over the other. + +184 +00:10:57,000 --> 00:11:02,000 +Now, when you combine things like amplification and reflection, they're generally going to be combined + +185 +00:11:02,000 --> 00:11:09,000 +to do things like in a network flooding to make it even more prominent, to really bring you down. + +186 +00:11:09,000 --> 00:11:13,000 +Now, if you're wondering, --, Andrew, that's pretty bad. + +187 +00:11:14,000 --> 00:11:16,000 +Um, you know, what can we do? + +188 +00:11:16,000 --> 00:11:21,000 +The first thing I want to mention is that DDoS attacks generally does not result. + +189 +00:11:21,000 --> 00:11:28,000 +And I'm saying generally because it's 90% of the time, it wouldn't result in data being stolen. + +190 +00:11:28,000 --> 00:11:35,000 +The objective of a DDoS denial of service is generally to shut the server or service down, so it wouldn't + +191 +00:11:35,000 --> 00:11:43,000 +result generally in data being stolen, but it would also almost always result in data being unavailable. + +192 +00:11:43,000 --> 00:11:44,000 +So it hits availability. + +193 +00:11:44,000 --> 00:11:47,000 +But it can also cause data corruption. + +194 +00:11:47,000 --> 00:11:49,000 +Integrity of the information. + +195 +00:11:49,000 --> 00:11:53,000 +If you remember CIA confidential integrity and availability, it generally is not going to affect that, + +196 +00:11:53,000 --> 00:11:54,000 +see. + +197 +00:11:54,000 --> 00:11:57,000 +But it's generally going to affect the Indah, which is just as bad. + +198 +00:11:58,000 --> 00:11:59,000 +Now. + +199 +00:11:59,000 --> 00:12:00,000 +How can you do it? + +200 +00:12:00,000 --> 00:12:04,000 +Well, let's say you're building a network and you're like, Andrew, I don't want no DDoS to bring + +201 +00:12:04,000 --> 00:12:04,000 +me down. + +202 +00:12:04,000 --> 00:12:05,000 +Then. + +203 +00:12:05,000 --> 00:12:07,000 +Have massive bandwidth. + +204 +00:12:07,000 --> 00:12:12,000 +Instead of building your network with a one gigabit line, use a ten gigabit line. + +205 +00:12:12,000 --> 00:12:15,000 +It would take a massive amount of traffic to bring you down. + +206 +00:12:15,000 --> 00:12:20,000 +Another thing you can do on what most company does is the two bottom here. + +207 +00:12:20,000 --> 00:12:23,000 +Most company uses companies like Cloudflare. + +208 +00:12:23,000 --> 00:12:23,000 +I'm not going to. + +209 +00:12:23,000 --> 00:12:26,000 +Now I put the link here if you want to check it out. + +210 +00:12:26,000 --> 00:12:28,000 +But this course is not going to sell Cloudflare to you. + +211 +00:12:28,000 --> 00:12:34,000 +But there are companies that is able to protect you from DDoS. + +212 +00:12:34,000 --> 00:12:35,000 +How do they do it? + +213 +00:12:35,000 --> 00:12:39,000 +Generally, they have massive systems that can absorb the DDoS attack from you. + +214 +00:12:39,000 --> 00:12:41,000 +So let's say you're running a website right now. + +215 +00:12:42,000 --> 00:12:46,000 +Basically, I could uh, I'm going to try to DDoS you and if you're using Cloudflare, they would just + +216 +00:12:46,000 --> 00:12:50,000 +get they would take the traffic away from you and put it into their systems. + +217 +00:12:51,000 --> 00:12:56,000 +Another thing is that there are routers and firewalls and things like that that come built in with DDoS + +218 +00:12:56,000 --> 00:12:57,000 +detection. + +219 +00:12:57,000 --> 00:13:03,000 +Even this small device has the ability to detect certain kinds of DDoS and disable them. + +220 +00:13:03,000 --> 00:13:06,000 +So you do have those options when it comes to fixing these things. + +221 +00:13:08,000 --> 00:13:09,000 +Okay. + +222 +00:13:09,000 --> 00:13:10,000 +I want you guys make sure you know does well. + +223 +00:13:11,000 --> 00:13:15,000 +Because as your security career starts to go up, I may be already in security already? + +224 +00:13:16,000 --> 00:13:19,000 +Uh, you will be hit if you work. + +225 +00:13:19,000 --> 00:13:20,000 +Especially in large organizations. + +226 +00:13:20,000 --> 00:13:21,000 +Government agency. + +227 +00:13:21,000 --> 00:13:21,000 +It's not. + +228 +00:13:22,000 --> 00:13:27,000 +You know, it's not unusual to get hit with DDoS attack because there's something that's pretty common. + +229 +00:13:27,000 --> 00:13:30,000 +So make sure you know what they are and how to stop them. + diff --git a/06 - Signs of Attacks/012 DNS OB 2.4_en.srt b/06 - Signs of Attacks/012 DNS OB 2.4_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..cc448e880e523a13fe585e2bc875eaa4ef40500d --- /dev/null +++ b/06 - Signs of Attacks/012 DNS OB 2.4_en.srt @@ -0,0 +1,936 @@ +1 +00:00:00,000 --> 00:00:06,000 +In this video, I want to show you guys how I'm going to be purchasing a brand new laptop from Bestbuy.com, + +2 +00:00:06,000 --> 00:00:09,000 +because I absolutely need a laptop. + +3 +00:00:09,000 --> 00:00:11,000 +Uh, and in this video, I want to show you that. + +4 +00:00:11,000 --> 00:00:15,000 +And then I want to explain a really important concept to you with DNS. + +5 +00:00:15,000 --> 00:00:17,000 +But let's go and get this laptop here quickly. + +6 +00:00:17,000 --> 00:00:19,000 +So I'm going to go here. + +7 +00:00:19,000 --> 00:00:23,000 +Here I am at my browser, I'm going to type a bestbuy.com. + +8 +00:00:23,000 --> 00:00:25,000 +And I want to show you guys my laptop. + +9 +00:00:27,000 --> 00:00:31,000 +Laptop hmm'hmm Bestbuy.com huh? + +10 +00:00:31,000 --> 00:00:32,000 +Returned Google. + +11 +00:00:34,000 --> 00:00:36,000 +It's an error and it says Google on it. + +12 +00:00:36,000 --> 00:00:40,000 +Maybe we'll just we'll just look for Best Buy and I'll just. + +13 +00:00:40,000 --> 00:00:41,000 +Here it is. + +14 +00:00:41,000 --> 00:00:42,000 +Click on this Best Buy. + +15 +00:00:42,000 --> 00:00:43,000 +All right. + +16 +00:00:45,000 --> 00:00:45,000 +Hmm'hmm. + +17 +00:00:46,000 --> 00:00:47,000 +It's not good. + +18 +00:00:49,000 --> 00:00:52,000 +So Best buy.com is being resolved to Google. + +19 +00:00:53,000 --> 00:00:55,000 +Did Google buy Best buy.com? + +20 +00:00:56,000 --> 00:01:01,000 +Guys, my machine has been hacked and somebody have hacked my DNS. + +21 +00:01:01,000 --> 00:01:05,000 +And that brings me to this video lesson which is DNS attacks. + +22 +00:01:05,000 --> 00:01:08,000 +So this is AI. + +23 +00:01:08,000 --> 00:01:10,000 +There's no hack on my machine because I did that. + +24 +00:01:10,000 --> 00:01:12,000 +I'm going to show you how I did it in a few minutes. + +25 +00:01:12,000 --> 00:01:14,000 +But before I get to that, I want to talk about DNS. + +26 +00:01:14,000 --> 00:01:17,000 +What exactly is DNS? + +27 +00:01:17,000 --> 00:01:24,000 +DNS stands for Domain Name Server or Service, depending on whatever documentation you're reading, + +28 +00:01:24,000 --> 00:01:31,000 +and it's one of the most important service on the entire internet because without it, you can't do + +29 +00:01:31,000 --> 00:01:31,000 +anything. + +30 +00:01:31,000 --> 00:01:33,000 +Without it, you can't go to no websites. + +31 +00:01:33,000 --> 00:01:40,000 +DNS, if you remember from your networking, resolves domain names like bestbuy.com to a particular + +32 +00:01:40,000 --> 00:01:41,000 +IP address. + +33 +00:01:41,000 --> 00:01:44,000 +So basically resolves domain names to IP address. + +34 +00:01:44,000 --> 00:01:50,000 +Now in this particular one there there are lots of attacks against DNS. + +35 +00:01:50,000 --> 00:01:52,000 +And way too many to count. + +36 +00:01:52,000 --> 00:01:55,000 +This video, I want to go through some of those attacks and one of the attacks. + +37 +00:01:55,000 --> 00:01:59,000 +I'm going to explain the attack that you guys are seeing here. + +38 +00:01:59,000 --> 00:02:08,000 +So the attack you guys are seeing here is an attack where they have redirected on this computer bestbuy.com + +39 +00:02:08,000 --> 00:02:11,000 +to actual google.com. + +40 +00:02:11,000 --> 00:02:12,000 +That's really what's happening here. + +41 +00:02:12,000 --> 00:02:15,000 +And I'm going to show you guys the steps on how to do that. + +42 +00:02:15,000 --> 00:02:20,000 +But before we do that, let's get into some text about this particular attack that I need you guys to + +43 +00:02:20,000 --> 00:02:23,000 +be familiar with for your exam. + +44 +00:02:23,000 --> 00:02:24,000 +So where are we? + +45 +00:02:24,000 --> 00:02:25,000 +Here we go. + +46 +00:02:26,000 --> 00:02:26,000 +Okay. + +47 +00:02:26,000 --> 00:02:28,000 +So way off here. + +48 +00:02:28,000 --> 00:02:29,000 +Here we go. + +49 +00:02:29,000 --> 00:02:30,000 +Where is DNS? + +50 +00:02:30,000 --> 00:02:31,000 +DNS here we go. + +51 +00:02:31,000 --> 00:02:33,000 +So DNS we know what it is. + +52 +00:02:33,000 --> 00:02:40,000 +Is the internet's phone book translates domain names like bestbuy.com into your IP address that we should + +53 +00:02:40,000 --> 00:02:40,000 +all know. + +54 +00:02:40,000 --> 00:02:44,000 +Now I want to talk about some attacks against it. + +55 +00:02:44,000 --> 00:02:47,000 +So DNS is generally a service. + +56 +00:02:47,000 --> 00:02:58,000 +And the way DNS works is that when your machine actually wants to grab an IP address of a particular + +57 +00:02:58,000 --> 00:03:05,000 +domain, it checks your DNS server that whatever DNS server your machine is assigned to, we all have + +58 +00:03:05,000 --> 00:03:11,000 +a DNS server configured on the machine, but we also have a host file on the machine that the computer + +59 +00:03:11,000 --> 00:03:13,000 +checks before checking the server. + +60 +00:03:13,000 --> 00:03:15,000 +And I'm going to show you guys that host file in a minute. + +61 +00:03:16,000 --> 00:03:20,000 +So the first attack I want to mention is one that's called DNS spoofing or cache poisoning. + +62 +00:03:21,000 --> 00:03:25,000 +This attack involves corrupting the DNS cache with false information. + +63 +00:03:25,000 --> 00:03:31,000 +An attacker can redirect traffic from a legitimate website to a fraudulent one without the user knowing. + +64 +00:03:31,000 --> 00:03:35,000 +So in this one, they're spoofing DNS entries by doing a cache poisoning. + +65 +00:03:35,000 --> 00:03:37,000 +Now I want to show you guys something. + +66 +00:03:38,000 --> 00:03:39,000 +Let's take a look. + +67 +00:03:39,000 --> 00:03:40,000 +Um. + +68 +00:03:42,000 --> 00:03:43,000 +Oops. + +69 +00:03:43,000 --> 00:03:43,000 +All right. + +70 +00:03:43,000 --> 00:03:48,000 +CMD, I want to show you guys IP config slash. + +71 +00:03:51,000 --> 00:03:54,000 +Slash display DNS. + +72 +00:03:55,000 --> 00:03:57,000 +This is called your DNS cache. + +73 +00:03:59,000 --> 00:04:06,000 +And this DNS cache shows me all the domains that I've been to and like I've been to Bestbuy.com and + +74 +00:04:06,000 --> 00:04:07,000 +the corresponding IP address. + +75 +00:04:07,000 --> 00:04:14,000 +So what they do, and this is done with malware is they're going to make this bigger. + +76 +00:04:15,000 --> 00:04:19,000 +What they're going to do is malware is going to come in here and infect this cache. + +77 +00:04:19,000 --> 00:04:25,000 +So if they can come into this cache and say something like google.com goes to this malicious IP address, + +78 +00:04:25,000 --> 00:04:28,000 +every time you type google.com, you're going to go there. + +79 +00:04:28,000 --> 00:04:31,000 +Now this is generally going to be done once again with malware. + +80 +00:04:31,000 --> 00:04:31,000 +All right. + +81 +00:04:32,000 --> 00:04:36,000 +Now another thing that they could be doing is an amplification attack. + +82 +00:04:36,000 --> 00:04:40,000 +Now amplification attack is something that I've mentioned before. + +83 +00:04:40,000 --> 00:04:40,000 +All right. + +84 +00:04:40,000 --> 00:04:47,000 +So amplification attack we talked about in DDoS attacks what an amplification attack is that they're + +85 +00:04:47,000 --> 00:04:49,000 +going to use publicly accessible DNS servers. + +86 +00:04:49,000 --> 00:04:52,000 +It's going to be like the ones that your ISP has. + +87 +00:04:52,000 --> 00:04:57,000 +They're going to be using those publicly accessible to flood targets with DNS responses. + +88 +00:04:57,000 --> 00:05:00,000 +So basically let's say your ISP is Verizon files. + +89 +00:05:01,000 --> 00:05:04,000 +And they have a DNS server. + +90 +00:05:04,000 --> 00:05:11,000 +Attackers can now use that server to send traffic to it, and that server will now amplify the traffic. + +91 +00:05:11,000 --> 00:05:16,000 +So if they send one request, that server may send out ten requests from that one request to you, sending + +92 +00:05:16,000 --> 00:05:18,000 +you massive amounts of traffic. + +93 +00:05:18,000 --> 00:05:21,000 +Another attack here is going to be DNS tunneling. + +94 +00:05:21,000 --> 00:05:26,000 +This one is not the most popular thing, but it does occur. + +95 +00:05:26,000 --> 00:05:27,000 +Here's what DNS tunneling is. + +96 +00:05:28,000 --> 00:05:34,000 +This involves encoding data or other programs into DNS queries and responses. + +97 +00:05:34,000 --> 00:05:39,000 +It could be used for legitimate purposes, like bypassing certain security controls, but it's more + +98 +00:05:39,000 --> 00:05:43,000 +than likely going to be used to get malicious data out of the network. + +99 +00:05:43,000 --> 00:05:45,000 +So here's what it is. + +100 +00:05:45,000 --> 00:05:52,000 +Basically, it encodes legitimate private data into DNS requests and sends it out to company. + +101 +00:05:52,000 --> 00:06:00,000 +So let's say right now your computer, your desktop, your laptop is configured with an IP address of + +102 +00:06:00,000 --> 00:06:02,000 +a DNS server outside your organization. + +103 +00:06:02,000 --> 00:06:10,000 +When you send a request to that DNS server to resolve google.com, what happens is that that leaves + +104 +00:06:10,000 --> 00:06:11,000 +the organization. + +105 +00:06:11,000 --> 00:06:18,000 +But if you can embed private data that the organization don't want you to steal into those DNS requests + +106 +00:06:18,000 --> 00:06:23,000 +or telnet into those requests, it allows you to send it directly out the business. + +107 +00:06:23,000 --> 00:06:27,000 +And this, of course, means that they're basically stealing your information. + +108 +00:06:28,000 --> 00:06:30,000 +Another one is DNS hijacking. + +109 +00:06:30,000 --> 00:06:31,000 +And this one here. + +110 +00:06:31,000 --> 00:06:33,000 +Pretty simple things. + +111 +00:06:33,000 --> 00:06:34,000 +What they're going to do. + +112 +00:06:34,000 --> 00:06:42,000 +The attacker basically moves diverts queries to malicious DNS servers leading to a fraudulent website. + +113 +00:06:42,000 --> 00:06:50,000 +This is done by compromising the DNS server or by the DNS settings on the computer. + +114 +00:06:50,000 --> 00:06:54,000 +So right now your machine has a setting. + +115 +00:06:54,000 --> 00:06:57,000 +The DNS server on your computer is set to this. + +116 +00:06:57,000 --> 00:07:01,000 +So if I go in let's go back to the desktop. + +117 +00:07:02,000 --> 00:07:03,000 +If I go in. + +118 +00:07:04,000 --> 00:07:07,000 +I'm just going to open up my network. + +119 +00:07:07,000 --> 00:07:09,000 +Uh, my network information. + +120 +00:07:09,000 --> 00:07:12,000 +I want to show you guys what DNS server am I set to. + +121 +00:07:12,000 --> 00:07:14,000 +So if I do ipconfig. + +122 +00:07:15,000 --> 00:07:16,000 +Now this is not a networking class. + +123 +00:07:16,000 --> 00:07:18,000 +I'm going to show you guys how to change an IP address. + +124 +00:07:18,000 --> 00:07:23,000 +But, uh, you know, make sure you guys should know how to do that. + +125 +00:07:23,000 --> 00:07:24,000 +So here we go. + +126 +00:07:24,000 --> 00:07:30,000 +Uh ipconfig we got my internal IP address is going to be 1.80. + +127 +00:07:31,000 --> 00:07:35,000 +And you notice my uh gateway which is just a router. + +128 +00:07:35,000 --> 00:07:39,000 +But I want to show you guys my DNS servers 1.1.1. + +129 +00:07:39,000 --> 00:07:42,000 +Now this is I'm not going to go into whose DNS services. + +130 +00:07:42,000 --> 00:07:43,000 +You guys can Google that. + +131 +00:07:43,000 --> 00:07:46,000 +But you should be using 1.1.1 DNS server. + +132 +00:07:46,000 --> 00:07:46,000 +Google. + +133 +00:07:46,000 --> 00:07:48,000 +That is a little surprise for you. + +134 +00:07:48,000 --> 00:07:49,000 +Uh, but this is my DNS server. + +135 +00:07:49,000 --> 00:07:54,000 +So what would happen is they would install malware on my computer and they would change my DNS server + +136 +00:07:54,000 --> 00:07:58,000 +from 1.1.1.1 to something malicious. + +137 +00:07:58,000 --> 00:08:07,000 +And then every time I query, every time I look for some other website, maybe I want to go to yahoo.com. + +138 +00:08:07,000 --> 00:08:08,000 +What are they going to do? + +139 +00:08:08,000 --> 00:08:09,000 +Well, it's going to redirect me. + +140 +00:08:09,000 --> 00:08:11,000 +It's going to give me a bad website. + +141 +00:08:11,000 --> 00:08:13,000 +So they could do that. + +142 +00:08:13,000 --> 00:08:16,000 +And this is called DNS hijacking. + +143 +00:08:16,000 --> 00:08:22,000 +Now, before I get into how to stop this, one of the questions that people ask me is, Andrew, how + +144 +00:08:22,000 --> 00:08:22,000 +did you do that? + +145 +00:08:22,000 --> 00:08:24,000 +How do how did you hack your own machine? + +146 +00:08:24,000 --> 00:08:31,000 +Well, the way this is done is that your computer has you have to understand how it works. + +147 +00:08:31,000 --> 00:08:32,000 +Your computer has what's called a host file. + +148 +00:08:33,000 --> 00:08:37,000 +So before your computer. + +149 +00:08:38,000 --> 00:08:41,000 +Sends out a request to a DNS server. + +150 +00:08:41,000 --> 00:08:48,000 +It checks the local cache and the host file on your computer, so that way it doesn't have to keep asking + +151 +00:08:48,000 --> 00:08:49,000 +the DNS server for something. + +152 +00:08:50,000 --> 00:09:02,000 +So to edit that host file, you would go to uh, this, you would do C windows system32 drivers, etc. + +153 +00:09:03,000 --> 00:09:05,000 +and you would edit this file called hosts. + +154 +00:09:06,000 --> 00:09:08,000 +So I'm just going to open this in. + +155 +00:09:08,000 --> 00:09:09,000 +Notepad. + +156 +00:09:11,000 --> 00:09:17,000 +And you notice I add an entry for Bestbuy.com and best Bestbuy.com. + +157 +00:09:17,000 --> 00:09:20,000 +So notice this IP address. + +158 +00:09:20,000 --> 00:09:25,000 +If I actually take this and I put it into the actually put it here you'll see it's Google see it's Google. + +159 +00:09:25,000 --> 00:09:29,000 +So basically I'm telling the computer that this points to Google. + +160 +00:09:29,000 --> 00:09:31,000 +And if I delete this. + +161 +00:09:33,000 --> 00:09:36,000 +Because I don't want that in my DNS cache. + +162 +00:09:36,000 --> 00:09:36,000 +It's going to save that. + +163 +00:09:36,000 --> 00:09:38,000 +I'll just open it really quickly. + +164 +00:09:38,000 --> 00:09:41,000 +I always like to reopen it just to make sure it's gone. + +165 +00:09:41,000 --> 00:09:45,000 +It's all clear and I won't have to clear the DNS cache. + +166 +00:09:45,000 --> 00:09:46,000 +I'm going to open up ipconfig. + +167 +00:09:46,000 --> 00:09:50,000 +I'll do IP, actually open my command prompt and I'll do flush. + +168 +00:09:51,000 --> 00:09:53,000 +How many of you guys took net. + +169 +00:09:53,000 --> 00:09:57,000 +Plus how many of you guys remember this flush DNS flush the cache. + +170 +00:09:57,000 --> 00:09:59,000 +That way it clears all the DNS cache. + +171 +00:09:59,000 --> 00:10:09,000 +So if you do ipconfig slash display DNS you'll notice there's nothing there right. + +172 +00:10:09,000 --> 00:10:11,000 +Because we just flushed it. + +173 +00:10:11,000 --> 00:10:14,000 +So now if I go back and I say Best Buy. + +174 +00:10:16,000 --> 00:10:19,000 +And let's see if it opens up Bestbuy.com. + +175 +00:10:19,000 --> 00:10:20,000 +So that's how that was done. + +176 +00:10:20,000 --> 00:10:24,000 +So this was a type of a poison that they did. + +177 +00:10:24,000 --> 00:10:31,000 +So what happens here is that they would actually do they would install malware on my computer to edit + +178 +00:10:31,000 --> 00:10:32,000 +that host file. + +179 +00:10:32,000 --> 00:10:34,000 +And that's a really common thing. + +180 +00:10:34,000 --> 00:10:39,000 +A lot of times if you clean up malware from a machine and you're still getting the resolutions are being + +181 +00:10:39,000 --> 00:10:41,000 +bad, check the host file. + +182 +00:10:41,000 --> 00:10:44,000 +That's a good way of stopping that now. + +183 +00:10:44,000 --> 00:10:48,000 +There are some other things here that we that I want to mention to you guys. + +184 +00:10:48,000 --> 00:10:54,000 +Uh, in particular is going to be ways to stop these attacks. + +185 +00:10:54,000 --> 00:10:58,000 +How are we going to go about stopping and killing these attacks against our systems? + +186 +00:10:58,000 --> 00:11:00,000 +Let's see how to do that. + +187 +00:11:04,000 --> 00:11:04,000 +Where is our. + +188 +00:11:04,000 --> 00:11:05,000 +Here we go. + +189 +00:11:05,000 --> 00:11:06,000 +Let's take a look at some attacks. + +190 +00:11:06,000 --> 00:11:10,000 +I'm going to show you guys on a windows server how that's done. + +191 +00:11:10,000 --> 00:11:18,000 +So the first thing up is that what's called DNSSec or security extension, what DNSSec does is that + +192 +00:11:18,000 --> 00:11:20,000 +it digitally signs the zone files. + +193 +00:11:20,000 --> 00:11:23,000 +So in DNS there's this thing called a zone file. + +194 +00:11:24,000 --> 00:11:31,000 +The zone file has the translation of all the domains to the IP address. + +195 +00:11:31,000 --> 00:11:32,000 +Now here's the thing. + +196 +00:11:33,000 --> 00:11:38,000 +When you say hey DNS server what's the IP to Best Buy. + +197 +00:11:39,000 --> 00:11:46,000 +How do you know that that request you're getting from that server actually came from that server. + +198 +00:11:46,000 --> 00:11:55,000 +And it is that server you really have no way of telling when a zone file is signed or DNSSec is is enabled + +199 +00:11:55,000 --> 00:11:56,000 +on it. + +200 +00:11:56,000 --> 00:12:01,000 +When it signs the zone file, it's basically going to guarantee you using digital signatures and so + +201 +00:12:01,000 --> 00:12:05,000 +on that that request actually came from that server. + +202 +00:12:06,000 --> 00:12:07,000 +How do you enable it? + +203 +00:12:08,000 --> 00:12:11,000 +Well, I'm going to show you guys that right now. + +204 +00:12:12,000 --> 00:12:13,000 +So I have a virtual machine. + +205 +00:12:13,000 --> 00:12:19,000 +This is going to be our Windows Server 2019 machine that I have set up to, uh, run in this course. + +206 +00:12:19,000 --> 00:12:26,000 +And I'm going to show you guys if you have a DNS server, um, here's a windows server, if you have + +207 +00:12:26,000 --> 00:12:30,000 +a Windows server and you're setting this up on a windows server, you would just open up the Windows + +208 +00:12:30,000 --> 00:12:35,000 +Server server, uh, server manager I'm going to go to my DNS tools. + +209 +00:12:35,000 --> 00:12:36,000 +So here we go. + +210 +00:12:36,000 --> 00:12:37,000 +Tools DNS. + +211 +00:12:37,000 --> 00:12:40,000 +And here are those zone files that I mentioned. + +212 +00:12:40,000 --> 00:12:43,000 +So this is my domain R dot local. + +213 +00:12:43,000 --> 00:12:46,000 +And in here I have a computer. + +214 +00:12:46,000 --> 00:12:47,000 +That's this machine. + +215 +00:12:48,000 --> 00:12:51,000 +But you'll notice that if I right click here. + +216 +00:12:51,000 --> 00:12:56,000 +I can go to DNSSec and I can say sign the zone file. + +217 +00:12:56,000 --> 00:12:59,000 +And it's as simple as just going through a wizard and say sign. + +218 +00:12:59,000 --> 00:13:02,000 +I'm just going to use default settings and that's it. + +219 +00:13:02,000 --> 00:13:03,000 +Now it's signed. + +220 +00:13:03,000 --> 00:13:05,000 +Now anybody that requests. + +221 +00:13:06,000 --> 00:13:08,000 +A DNS resolution from this server. + +222 +00:13:08,000 --> 00:13:14,000 +In my corporate network, they will be 100% sure it came from them and it was never spoofed. + +223 +00:13:14,000 --> 00:13:17,000 +So that's the idea with DNS seek. + +224 +00:13:17,000 --> 00:13:21,000 +Now other things here we can do secure the DNS server. + +225 +00:13:21,000 --> 00:13:26,000 +This is going to be regularly updating it and patching it that way the server itself can't get hacked. + +226 +00:13:26,000 --> 00:13:30,000 +Uh monitoring keeping an eye on DNS traffic is of course going to be important. + +227 +00:13:30,000 --> 00:13:34,000 +But other things here that I didn't list that you should already know are going to be things like because + +228 +00:13:34,000 --> 00:13:39,000 +I mentioned earlier, a lot of times the DNS attacks are basically malware on your computer. + +229 +00:13:39,000 --> 00:13:46,000 +So obviously anti-malware user training don't get, you know, uh, hooked with a Trojan or don't get, + +230 +00:13:46,000 --> 00:13:50,000 +you know, don't get Trojans installed on your machine by clicking on wrong emails. + +231 +00:13:50,000 --> 00:13:51,000 +All right. + +232 +00:13:51,000 --> 00:13:54,000 +That's going to be our discussion on DNS attacks that are out there. + +233 +00:13:54,000 --> 00:13:56,000 +Make sure you understand them for your exam. + +234 +00:13:56,000 --> 00:14:02,000 +And remember DNS attacks are super dangerous because DNS is something we use all the time. + diff --git a/06 - Signs of Attacks/013 Onpath Attack OB 2.4_en.srt b/06 - Signs of Attacks/013 Onpath Attack OB 2.4_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..4a6be80d215b0be67a4d5d44cfc5e7f5d410bd15 --- /dev/null +++ b/06 - Signs of Attacks/013 Onpath Attack OB 2.4_en.srt @@ -0,0 +1,420 @@ +1 +00:00:00,000 --> 00:00:00,000 +Okay. + +2 +00:00:00,000 --> 00:00:02,000 +You're sitting at your desk. + +3 +00:00:02,000 --> 00:00:05,000 +You're going to be downloading a file from a server. + +4 +00:00:05,000 --> 00:00:07,000 +Imagine this. + +5 +00:00:07,000 --> 00:00:09,000 +Now here's your computer. + +6 +00:00:09,000 --> 00:00:10,000 +Here's your server. + +7 +00:00:10,000 --> 00:00:17,000 +That file is going to leave that server and come directly across the network to your machine. + +8 +00:00:17,000 --> 00:00:24,000 +But what if I told you that between your computer and the server was an attacker? + +9 +00:00:25,000 --> 00:00:34,000 +And what that attacker is doing is that attacker is sniffing all of the information between you and + +10 +00:00:34,000 --> 00:00:35,000 +that particular server. + +11 +00:00:35,000 --> 00:00:38,000 +So what you believe is the right connection. + +12 +00:00:38,000 --> 00:00:39,000 +This is you. + +13 +00:00:39,000 --> 00:00:40,000 +This is the server. + +14 +00:00:40,000 --> 00:00:44,000 +What you believe is that you're transferring data to that server. + +15 +00:00:44,000 --> 00:00:51,000 +But in actuality, all the data is being transferred between you and the server through an intermediate + +16 +00:00:51,000 --> 00:00:54,000 +person attacker of some kind. + +17 +00:00:54,000 --> 00:00:57,000 +You see, this is called an on path attack. + +18 +00:00:58,000 --> 00:01:05,000 +Now on path attack, just for your information, uh, is an attack that used to be called man in the + +19 +00:01:05,000 --> 00:01:06,000 +middle attack. + +20 +00:01:06,000 --> 00:01:13,000 +But for word and purposes, it's better to call it on path, because this is an attack where somebody + +21 +00:01:13,000 --> 00:01:20,000 +sits, an attacker sits in between the path between you and the communication between whoever you're + +22 +00:01:20,000 --> 00:01:24,000 +communicating to you on another host, you want a particular server of some kind. + +23 +00:01:25,000 --> 00:01:27,000 +So they basically they position themselves. + +24 +00:01:27,000 --> 00:01:32,000 +Now you may you may be asking yourself, well, if they do that, what are they going to get out of + +25 +00:01:32,000 --> 00:01:33,000 +this. + +26 +00:01:33,000 --> 00:01:33,000 +Right. + +27 +00:01:33,000 --> 00:01:34,000 +Like why would they do this? + +28 +00:01:34,000 --> 00:01:41,000 +Well, basically a lot of the times it's really to intercept the communication by them doing this between + +29 +00:01:41,000 --> 00:01:45,000 +two parties, they're basically ears dropping on your information. + +30 +00:01:45,000 --> 00:01:47,000 +They're basically listening to whatever you're doing. + +31 +00:01:48,000 --> 00:01:53,000 +And if you're using things that are not encrypted, for example, you're transferring data using FTP, + +32 +00:01:53,000 --> 00:01:59,000 +they'll be able to see all of the information that you're transferring between you and that particular + +33 +00:01:59,000 --> 00:02:00,000 +server. + +34 +00:02:00,000 --> 00:02:05,000 +If you're using a particular web page, for example, it's not Https, it's unencrypted. + +35 +00:02:05,000 --> 00:02:09,000 +Without SSL, they'll be able to see everything you're seeing on that page. + +36 +00:02:09,000 --> 00:02:11,000 +So they're intercepting the communication. + +37 +00:02:11,000 --> 00:02:15,000 +And this can be done, uh, over Wi-Fi networks, plug in networks. + +38 +00:02:16,000 --> 00:02:19,000 +And a lot of times they do it using ARP spoofing. + +39 +00:02:19,000 --> 00:02:22,000 +Now, this class, I'm not going to get into exactly how it's done. + +40 +00:02:22,000 --> 00:02:23,000 +If you want to know how it's done. + +41 +00:02:23,000 --> 00:02:28,000 +And for me to actually show you how to do it, that's in the course Certified Ethical Hacking Course. + +42 +00:02:28,000 --> 00:02:33,000 +But for these kinds of courses now, you don't need you don't need to know the specifics, how it's + +43 +00:02:33,000 --> 00:02:35,000 +done, but you need to understand what it is. + +44 +00:02:35,000 --> 00:02:41,000 +So they're basically sitting in between the the communication between you and this particular server + +45 +00:02:41,000 --> 00:02:43,000 +or entity that you're communicating with. + +46 +00:02:43,000 --> 00:02:48,000 +The ears drop and they're seeing all of the information from login to personal information, corporate + +47 +00:02:48,000 --> 00:02:49,000 +corporate data. + +48 +00:02:51,000 --> 00:02:54,000 +Now, what they could do is they could session hijacking. + +49 +00:02:55,000 --> 00:02:57,000 +Another thing that they can do is they can hijack it. + +50 +00:02:57,000 --> 00:02:58,000 +They're just not watching it. + +51 +00:02:58,000 --> 00:03:03,000 +They're just not stealing the information, but they start to impersonate you and start to go into systems + +52 +00:03:03,000 --> 00:03:04,000 +as you. + +53 +00:03:04,000 --> 00:03:09,000 +They can also manipulate the data because they're, they, they're the person in the middle between + +54 +00:03:09,000 --> 00:03:10,000 +you and the server. + +55 +00:03:10,000 --> 00:03:16,000 +They can now manipulate the data that the server is sending you, let's say a particular memo, and + +56 +00:03:16,000 --> 00:03:18,000 +they're manipulating that and then sending it to you. + +57 +00:03:18,000 --> 00:03:21,000 +And you think that comes from the server, but it doesn't. + +58 +00:03:21,000 --> 00:03:24,000 +So they could do data manipulation. + +59 +00:03:24,000 --> 00:03:30,000 +Now another famous one that worked with a man in the middle was a famous attack a long time ago. + +60 +00:03:30,000 --> 00:03:32,000 +We had called this one SSL stripping. + +61 +00:03:33,000 --> 00:03:43,000 +And this was a type of a of a man on path attack that basically turned Https insecure and Https with + +62 +00:03:43,000 --> 00:03:45,000 +SSL was generally considered very secure. + +63 +00:03:45,000 --> 00:03:49,000 +It basically downgrades an SSL connection to an unencrypted connection. + +64 +00:03:50,000 --> 00:03:56,000 +Now, this here has been pretty obsolete for a long time, but in case you ever see it anywhere, you + +65 +00:03:56,000 --> 00:03:57,000 +just remember it's pretty. + +66 +00:03:57,000 --> 00:03:59,000 +It's pretty obsolete at this point. + +67 +00:04:00,000 --> 00:04:01,000 +And if you're wondering, okay, Andrew, what can we do? + +68 +00:04:01,000 --> 00:04:05,000 +Like how can we stop, man, uh, on path attacks? + +69 +00:04:05,000 --> 00:04:10,000 +What can we do to ensure that this doesn't happen or we don't get our data stolen? + +70 +00:04:10,000 --> 00:04:17,000 +Well, first of all, every connection that you use in today's world should be encrypted. + +71 +00:04:17,000 --> 00:04:18,000 +Okay? + +72 +00:04:18,000 --> 00:04:18,000 +Period. + +73 +00:04:18,000 --> 00:04:24,000 +Every encryption that you use in your corporate network, in, in a in a Starbucks Wi-Fi, some kind + +74 +00:04:24,000 --> 00:04:28,000 +of cafe has to be encrypted. + +75 +00:04:28,000 --> 00:04:31,000 +Now, the question on that is going to be okay, Andrew. + +76 +00:04:31,000 --> 00:04:33,000 +Well, what are some encryption protocols? + +77 +00:04:33,000 --> 00:04:35,000 +Well, the first one up that comes to my mind is SSL. + +78 +00:04:36,000 --> 00:04:36,000 +All right. + +79 +00:04:36,000 --> 00:04:37,000 +Don't use Http. + +80 +00:04:37,000 --> 00:04:40,000 +Use what you see here, use https. + +81 +00:04:40,000 --> 00:04:45,000 +The reason is because even if the connection is intercepted and they sniff it, they wouldn't be able + +82 +00:04:45,000 --> 00:04:46,000 +to see anything. + +83 +00:04:46,000 --> 00:04:55,000 +They wouldn't be able to see any of the actual, uh, any of the actual data, passwords, memos, whatever + +84 +00:04:55,000 --> 00:04:57,000 +is that you have in text files or anything like that. + +85 +00:04:58,000 --> 00:05:03,000 +Another thing is that if you are accessing your company's information from a remote site. + +86 +00:05:03,000 --> 00:05:06,000 +Maybe you're in a Starbucks Wi-Fi. + +87 +00:05:07,000 --> 00:05:07,000 +All right. + +88 +00:05:07,000 --> 00:05:08,000 +You're working remotely. + +89 +00:05:08,000 --> 00:05:12,000 +You should always be using a VPN of some kind. + +90 +00:05:12,000 --> 00:05:14,000 +Always have that VPN on. + +91 +00:05:14,000 --> 00:05:19,000 +The VPN is going to utilize things like IPsec to ensure that the connection is encrypted. + +92 +00:05:19,000 --> 00:05:25,000 +And of course, just having good education, being aware that never use unencrypted communications, + +93 +00:05:26,000 --> 00:05:31,000 +um, make sure that the networks are connected to a secure for example, don't connect to public Wi-Fi. + +94 +00:05:31,000 --> 00:05:32,000 +It's never good. + +95 +00:05:32,000 --> 00:05:40,000 +I always tell people public Wi-Fi should never be used, but you should be doing is you should be using. + +96 +00:05:40,000 --> 00:05:45,000 +Keep this in mind, uh, your own private connection like you can. + +97 +00:05:45,000 --> 00:05:51,000 +What I like to do is I'm not going to use Starbucks Wi-Fi, but I'll open up a internet connection sharing + +98 +00:05:51,000 --> 00:05:53,000 +on my phone and just use something like that, like a hotspot. + +99 +00:05:53,000 --> 00:05:54,000 +Okay. + +100 +00:05:55,000 --> 00:05:57,000 +Understand that what these on path attacks are. + +101 +00:05:58,000 --> 00:06:04,000 +It's an attacker that intercepts the communication between you and a particular device or server or + +102 +00:06:04,000 --> 00:06:06,000 +service that you're getting in there. + +103 +00:06:06,000 --> 00:06:09,000 +They can sniff the data, manipulate the data, of course, view the data by sniffing it. + +104 +00:06:10,000 --> 00:06:11,000 +Now, how do you stop it? + +105 +00:06:11,000 --> 00:06:18,000 +Make sure that when you use any kind of connection, that connection is secure and encrypted. + diff --git a/06 - Signs of Attacks/014 Credential Replay OB 2.4_en.srt b/06 - Signs of Attacks/014 Credential Replay OB 2.4_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..3ce9ec7cc157e4cebd4aacf84656cdeae48bd784 --- /dev/null +++ b/06 - Signs of Attacks/014 Credential Replay OB 2.4_en.srt @@ -0,0 +1,292 @@ +1 +00:00:00,000 --> 00:00:07,000 +One of the most important things that you have to secure is your login, your login information, your + +2 +00:00:07,000 --> 00:00:09,000 +particularly your username and password. + +3 +00:00:09,000 --> 00:00:15,000 +Anybody that captures your username and password or has access to it basically becomes you on a network. + +4 +00:00:15,000 --> 00:00:21,000 +So in this particular attack, which is called credential replay, it's where the attacker basically + +5 +00:00:21,000 --> 00:00:25,000 +captures your username and password, generally username and password. + +6 +00:00:25,000 --> 00:00:28,000 +And they gain unauthorized access to a system. + +7 +00:00:29,000 --> 00:00:32,000 +So if I am able to capture your credential. + +8 +00:00:33,000 --> 00:00:35,000 +Whether a socially engineered for me I called you and actually. + +9 +00:00:35,000 --> 00:00:36,000 +What's your password? + +10 +00:00:36,000 --> 00:00:39,000 +I email it to you. + +11 +00:00:39,000 --> 00:00:45,000 +I do an on path attack and take it from the communication on the network, whatever it is. + +12 +00:00:45,000 --> 00:00:50,000 +Once I get that, I can then become you and have access to all this information. + +13 +00:00:50,000 --> 00:00:54,000 +So it's really authentication credentials are transmitted over the network. + +14 +00:00:54,000 --> 00:00:55,000 +Now. + +15 +00:00:55,000 --> 00:01:00,000 +That's why you want to make sure that you encrypt your credential information. + +16 +00:01:00,000 --> 00:01:01,000 +You secure it. + +17 +00:01:01,000 --> 00:01:03,000 +And I'm going to show you guys some ways of how to stop this. + +18 +00:01:03,000 --> 00:01:04,000 +But here's really how it works. + +19 +00:01:04,000 --> 00:01:09,000 +For credential replay to work, the first thing the attacker needs to do is to capture the credential. + +20 +00:01:09,000 --> 00:01:11,000 +It's going to be done using a variety of ways. + +21 +00:01:11,000 --> 00:01:15,000 +Some of the ways are like phishing attacks I mentioned, which is going to be sending you some kind + +22 +00:01:15,000 --> 00:01:22,000 +of email network sniffers, if you're using unsecure protocols, like if you're using FTP instead of + +23 +00:01:22,000 --> 00:01:27,000 +SftP or Ftps, they'll be able to capture your FTP credentials. + +24 +00:01:27,000 --> 00:01:30,000 +Um, the other thing is that they can use keyloggers. + +25 +00:01:30,000 --> 00:01:34,000 +If you remember from the keylogger video, I showed you this little device that captures credentials. + +26 +00:01:34,000 --> 00:01:37,000 +The first thing the attacker needs to do is to capture that credential. + +27 +00:01:37,000 --> 00:01:40,000 +The next thing the attacker is going to do is then replay this. + +28 +00:01:40,000 --> 00:01:44,000 +They're just going to go against the system and put the username and password that they capture. + +29 +00:01:44,000 --> 00:01:49,000 +This, of course, gives them widespread access to everything that you have access to. + +30 +00:01:49,000 --> 00:01:56,000 +Um, if you use that same username and password or your username and password gives them access to many + +31 +00:01:56,000 --> 00:01:56,000 +servers. + +32 +00:01:56,000 --> 00:01:58,000 +Well, like I said, they just become you. + +33 +00:01:59,000 --> 00:02:03,000 +Now the question is, well, how do you stop this? + +34 +00:02:03,000 --> 00:02:05,000 +Like, what are some ways of stopping this? + +35 +00:02:05,000 --> 00:02:13,000 +Well, there's no reason why in today's world 2023, whatever you're using to transmit credentials is + +36 +00:02:13,000 --> 00:02:14,000 +not encrypted. + +37 +00:02:15,000 --> 00:02:16,000 +IPsec. + +38 +00:02:16,000 --> 00:02:18,000 +Of course, SSL or TLS. + +39 +00:02:18,000 --> 00:02:25,000 +Those types of things should be used all the time to ensure that there is no at no point, no network + +40 +00:02:25,000 --> 00:02:27,000 +traffic should ever be in clear text. + +41 +00:02:27,000 --> 00:02:34,000 +Another thing is that when it comes to secure systems, I love dual factor authentication like two factor + +42 +00:02:34,000 --> 00:02:37,000 +authentication, multi factor authentication. + +43 +00:02:37,000 --> 00:02:43,000 +So that way even if I capture a password or a social engineered a password, maybe because I called + +44 +00:02:43,000 --> 00:02:49,000 +you and says, hey, you know, I'm Bob from the help desk, I would like to, uh, fix your systems. + +45 +00:02:49,000 --> 00:02:51,000 +Let me have your password, and then you just give it to me. + +46 +00:02:51,000 --> 00:02:56,000 +Well, even if somebody knows one factor, something, you know, like your password, they'll probably + +47 +00:02:56,000 --> 00:03:00,000 +still have to have a biometric thumbprint or maybe some kind of smartcard. + +48 +00:03:01,000 --> 00:03:05,000 +Another thing here we could be doing is regular password changes and strong passwords. + +49 +00:03:05,000 --> 00:03:08,000 +You should be changing your password every 60 to 90 days. + +50 +00:03:08,000 --> 00:03:11,000 +You don't want to keep the same password over and over. + +51 +00:03:11,000 --> 00:03:18,000 +You want to make sure that the passwords you're using are not like 2 or 3 years old. + +52 +00:03:18,000 --> 00:03:22,000 +Because if those passwords ever gets compromised, they're just going to keep replaying it, just going + +53 +00:03:22,000 --> 00:03:22,000 +to keep hacking you. + +54 +00:03:23,000 --> 00:03:24,000 +Monitoring detection. + +55 +00:03:24,000 --> 00:03:26,000 +Make sure your systems is always being monitored. + +56 +00:03:26,000 --> 00:03:27,000 +Only kind of unusual attempts. + +57 +00:03:27,000 --> 00:03:35,000 +For example, we have particular monitoring systems that can look at log files and detect malicious + +58 +00:03:35,000 --> 00:03:39,000 +activity or unusual login attempts from certain locations, for example. + +59 +00:03:40,000 --> 00:03:44,000 +When was the last you try to log into your Gmail from a different device? + +60 +00:03:44,000 --> 00:03:47,000 +Google will send you an email and says, hey man, there was an email. + +61 +00:03:48,000 --> 00:03:50,000 +Somebody logged in with this username and password from that device. + +62 +00:03:50,000 --> 00:03:51,000 +Did you do that? + +63 +00:03:51,000 --> 00:03:52,000 +That's a good way. + +64 +00:03:52,000 --> 00:03:57,000 +Another thing here that we could do is you can prevent those credentials from being logged in from different + +65 +00:03:57,000 --> 00:03:58,000 +locations. + +66 +00:03:58,000 --> 00:03:59,000 +That is geo fenced. + +67 +00:03:59,000 --> 00:04:04,000 +We call this the geo fence means you're locking those credentials to that location only. + +68 +00:04:04,000 --> 00:04:08,000 +So there's a lot of ways we can lock lock up our credentials. + +69 +00:04:09,000 --> 00:04:10,000 +Credential replays, of course. + +70 +00:04:10,000 --> 00:04:11,000 +Dangerous. + +71 +00:04:12,000 --> 00:04:14,000 +If they grabbed your username and password, you better. + +72 +00:04:14,000 --> 00:04:16,000 +Best bet they have access to everything you have. + +73 +00:04:16,000 --> 00:04:20,000 +So make sure to secure your credentials. + diff --git a/06 - Signs of Attacks/015 Privilege Escalation OB 2.4_en.srt b/06 - Signs of Attacks/015 Privilege Escalation OB 2.4_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..0072c493c44d371b08310dac7ac11c1042b92e6c --- /dev/null +++ b/06 - Signs of Attacks/015 Privilege Escalation OB 2.4_en.srt @@ -0,0 +1,268 @@ +1 +00:00:00,000 --> 00:00:07,000 +When it comes to hacking an organization, it's easier to hack a normal, everyday user than someone + +2 +00:00:07,000 --> 00:00:12,000 +like myself, a security administrator, or a high end administrator in the business. + +3 +00:00:12,000 --> 00:00:12,000 +Now. + +4 +00:00:12,000 --> 00:00:13,000 +Here's the thing. + +5 +00:00:13,000 --> 00:00:20,000 +When a hacker hacks a user, okay, there's a problem because that user only has access to very specific + +6 +00:00:20,000 --> 00:00:21,000 +information. + +7 +00:00:21,000 --> 00:00:24,000 +That user is not an administrator on a machine. + +8 +00:00:24,000 --> 00:00:27,000 +That user may not have access to real sensitive data. + +9 +00:00:27,000 --> 00:00:30,000 +For example, let's say the hacker sales person. + +10 +00:00:30,000 --> 00:00:35,000 +Well, that sales person may only have access to sales information, maybe prospective clients that + +11 +00:00:35,000 --> 00:00:36,000 +the company wants to do business with. + +12 +00:00:36,000 --> 00:00:42,000 +But it's not going to that sales person is not going to have access to things like financial data or + +13 +00:00:42,000 --> 00:00:43,000 +company secrets. + +14 +00:00:43,000 --> 00:00:47,000 +For that, they're going to have to move their privilege up. + +15 +00:00:47,000 --> 00:00:49,000 +And that brings me to this particular attack. + +16 +00:00:49,000 --> 00:00:52,000 +This is called privilege escalation. + +17 +00:00:53,000 --> 00:01:00,000 +This is an attack where the attacker gains elevated access to resources that are normally protected + +18 +00:01:00,000 --> 00:01:01,000 +from an application or user. + +19 +00:01:02,000 --> 00:01:09,000 +So in this one, what the attacker does is they start at a lower permission level and escalate their + +20 +00:01:09,000 --> 00:01:10,000 +privileges up. + +21 +00:01:10,000 --> 00:01:15,000 +So for example, let's say you have a normal user account on a computer. + +22 +00:01:15,000 --> 00:01:18,000 +You don't have the administrator passwords or access. + +23 +00:01:18,000 --> 00:01:20,000 +And you're like, well, I want to install something. + +24 +00:01:20,000 --> 00:01:25,000 +I want to go to this server, I want to add this or remove this, but you can't unless you use this + +25 +00:01:25,000 --> 00:01:25,000 +attack. + +26 +00:01:25,000 --> 00:01:30,000 +Now if you depending on how it's done, it basically takes a normal user accounts and turns it into + +27 +00:01:30,000 --> 00:01:31,000 +administrators. + +28 +00:01:31,000 --> 00:01:36,000 +Really all it does now, this is not something that's uncommon. + +29 +00:01:36,000 --> 00:01:43,000 +In fact, if you guys have ever done things like maybe route your your Android or jailbreak your iPhone, + +30 +00:01:43,000 --> 00:01:45,000 +it's a type of a privilege escalation. + +31 +00:01:45,000 --> 00:01:49,000 +Because on these devices, especially on an iPhone, you don't have administrator privileges. + +32 +00:01:49,000 --> 00:01:54,000 +So you're basically using a privilege escalation to give yourself admin privileges so you can install + +33 +00:01:54,000 --> 00:01:57,000 +whatever app and do whatever you want to your phone. + +34 +00:01:57,000 --> 00:02:01,000 +Now, when it comes to the escalation, there's two kinds of escalation. + +35 +00:02:01,000 --> 00:02:03,000 +What's called a vertical and horizontal. + +36 +00:02:03,000 --> 00:02:10,000 +So in a vertical this occurs when the attacker tries to gain a higher level of privilege than they're + +37 +00:02:10,000 --> 00:02:16,000 +supposed to have, for example, going from a regular user to administrator privileges. + +38 +00:02:16,000 --> 00:02:18,000 +Horizontal. + +39 +00:02:18,000 --> 00:02:22,000 +This is when they move across the network at the same level. + +40 +00:02:22,000 --> 00:02:27,000 +So for example, they start with a restricted user account, but using that same restricted user account + +41 +00:02:27,000 --> 00:02:31,000 +to start accessing other data in the network that that account has access to. + +42 +00:02:31,000 --> 00:02:35,000 +So basically they're moving across the network in terms of permission to not move it up. + +43 +00:02:35,000 --> 00:02:36,000 +The permission. + +44 +00:02:37,000 --> 00:02:39,000 +Now, if you're asking yourself, well, Andrew, how do they do this? + +45 +00:02:39,000 --> 00:02:47,000 +99% of the time it's done by exploiting some kind of vulnerability, some kind of software bug or design + +46 +00:02:47,000 --> 00:02:51,000 +flaw in the operating system or in the application. + +47 +00:02:51,000 --> 00:02:54,000 +So this how do you fix this? + +48 +00:02:54,000 --> 00:02:56,000 +Update the application and don't get malware. + +49 +00:02:56,000 --> 00:03:01,000 +More than likely they're going to be installing like a rootkit, for example, onto the machine to give + +50 +00:03:01,000 --> 00:03:03,000 +them root access to the machine. + +51 +00:03:03,000 --> 00:03:05,000 +That's a type of a privilege escalation. + +52 +00:03:05,000 --> 00:03:10,000 +This thing here allows them to bypass all types of security mechanisms and controls. + +53 +00:03:11,000 --> 00:03:15,000 +Uh, another thing they can do here, they can socially engineer it. + +54 +00:03:15,000 --> 00:03:15,000 +All right. + +55 +00:03:15,000 --> 00:03:17,000 +This is believe it or not, that's one way of doing it. + +56 +00:03:17,000 --> 00:03:23,000 +They could manipulate administrators into giving out passwords, or they even use existing credentials, + +57 +00:03:23,000 --> 00:03:25,000 +higher level credentials on the network. + +58 +00:03:25,000 --> 00:03:29,000 +Now, privilege escalation is not something that you're going to ignore. + +59 +00:03:29,000 --> 00:03:30,000 +That doesn't happen a lot. + +60 +00:03:30,000 --> 00:03:32,000 +In fact, it happens way too much. + +61 +00:03:32,000 --> 00:03:37,000 +Like I mentioned, there are more bad people. + +62 +00:03:37,000 --> 00:03:45,000 +A hacker attacker is more than likely to compromise a user than they are to compromise an administrator + +63 +00:03:45,000 --> 00:03:47,000 +or a security person. + +64 +00:03:47,000 --> 00:03:49,000 +So what are they going to do? + +65 +00:03:49,000 --> 00:03:53,000 +They're going to do privilege escalation because they're going to take that normal user account and + +66 +00:03:53,000 --> 00:03:55,000 +they're going to turn it into an administrator. + +67 +00:03:55,000 --> 00:03:58,000 +So make sure you protect against privilege escalation. + diff --git a/06 - Signs of Attacks/016 Request Forgery OB 2.4_en.srt b/06 - Signs of Attacks/016 Request Forgery OB 2.4_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..623924997d846f1aed4ea0cc5017c447c227e207 --- /dev/null +++ b/06 - Signs of Attacks/016 Request Forgery OB 2.4_en.srt @@ -0,0 +1,380 @@ +1 +00:00:00,000 --> 00:00:05,000 +One of the most dangerous things you can ever do when you surf the internet is to leave your credentials + +2 +00:00:05,000 --> 00:00:07,000 +logged in on websites. + +3 +00:00:08,000 --> 00:00:09,000 +I'm going to give you a scenario. + +4 +00:00:09,000 --> 00:00:13,000 +Basically, I'm going to describe an attack for you and you're going to see what I mean. + +5 +00:00:13,000 --> 00:00:15,000 +Let's say right now you went to Amazon. + +6 +00:00:15,000 --> 00:00:19,000 +You bought yourself a brand new gaming desktop. + +7 +00:00:19,000 --> 00:00:20,000 +Congratulations. + +8 +00:00:20,000 --> 00:00:23,000 +You checked out and you left it logged in. + +9 +00:00:23,000 --> 00:00:25,000 +Two minutes later, I send you an email. + +10 +00:00:25,000 --> 00:00:28,000 +In that email has a link. + +11 +00:00:28,000 --> 00:00:31,000 +Now, you you trust me because I'm the world's best teacher, remember? + +12 +00:00:32,000 --> 00:00:35,000 +Andrew, send you a link to how to get your certification. + +13 +00:00:35,000 --> 00:00:37,000 +So you click on it. + +14 +00:00:37,000 --> 00:00:38,000 +Now here's what it does. + +15 +00:00:38,000 --> 00:00:44,000 +That link sends a message to Amazon telling it to ship me the same computer you bought. + +16 +00:00:45,000 --> 00:00:48,000 +Or tells me to buy anything on Amazon and ship it to me. + +17 +00:00:49,000 --> 00:00:51,000 +Before, you don't even know what's happening. + +18 +00:00:51,000 --> 00:00:52,000 +You just click the link. + +19 +00:00:52,000 --> 00:00:54,000 +You don't even know what happened and boom, it happened. + +20 +00:00:55,000 --> 00:00:58,000 +They basically bought something and sent it to me. + +21 +00:00:58,000 --> 00:00:59,000 +It all happens in the background. + +22 +00:01:00,000 --> 00:01:01,000 +You don't even know what happened. + +23 +00:01:01,000 --> 00:01:04,000 +The question is, how the hell did that happen? + +24 +00:01:04,000 --> 00:01:10,000 +Well, it happened because you left your Amazon username and password logged in to Amazon. + +25 +00:01:10,000 --> 00:01:17,000 +So what's happening in the background is I'm using your credentials to prompt purchasing on your account + +26 +00:01:17,000 --> 00:01:18,000 +and send it to me. + +27 +00:01:18,000 --> 00:01:22,000 +This kind of an attack is called a request forgery attack. + +28 +00:01:23,000 --> 00:01:24,000 +All right. + +29 +00:01:25,000 --> 00:01:31,000 +A request forgery attack is the attacker tricks a user, browser or application to perform an unwanted + +30 +00:01:31,000 --> 00:01:34,000 +action on a trusted site. + +31 +00:01:34,000 --> 00:01:35,000 +Now it comes in two forms. + +32 +00:01:35,000 --> 00:01:38,000 +The one I described to you is called a cross-site request forgery. + +33 +00:01:38,000 --> 00:01:42,000 +The other one is called a server side request forgery. + +34 +00:01:42,000 --> 00:01:47,000 +Now I want to show you guys the diagram that I have here from this great website. + +35 +00:01:47,000 --> 00:01:48,000 +Uh, right there. + +36 +00:01:48,000 --> 00:01:50,000 +Now I want to show you guys this. + +37 +00:01:50,000 --> 00:01:52,000 +So imagine the scenario goes like this. + +38 +00:01:52,000 --> 00:01:55,000 +Imagine you're logged in to a banking website. + +39 +00:01:56,000 --> 00:02:01,000 +You're logged into a Chase bank Chase.com you log in, you're checking your balance. + +40 +00:02:01,000 --> 00:02:03,000 +Well, I'm a bad guy. + +41 +00:02:03,000 --> 00:02:08,000 +I, uh, make up some kind of, uh, email, and I send it to you. + +42 +00:02:08,000 --> 00:02:10,000 +I says, hey, this is Chase Bank. + +43 +00:02:10,000 --> 00:02:11,000 +Com. + +44 +00:02:11,000 --> 00:02:18,000 +Make sure to use this to to transfer data or to see the next policy attacker forges a request to for + +45 +00:02:18,000 --> 00:02:19,000 +a funds transfer. + +46 +00:02:19,000 --> 00:02:23,000 +So what I'm going to do is I'm going to make I'm the attacker. + +47 +00:02:23,000 --> 00:02:30,000 +I'm going to make a type of a JavaScript that basically transfer funds from your bank account to mines. + +48 +00:02:31,000 --> 00:02:35,000 +I'm going to embed this hyperlink and then I'm going to send it to you. + +49 +00:02:35,000 --> 00:02:36,000 +All right. + +50 +00:02:36,000 --> 00:02:39,000 +You click on this hyperlink. + +51 +00:02:40,000 --> 00:02:47,000 +Now what happens is the hyperlink goes directly to Chase.com to transfer money to me out of your account. + +52 +00:02:47,000 --> 00:02:48,000 +It's the same thing I told you with the Amazon. + +53 +00:02:48,000 --> 00:02:49,000 +Except this is. + +54 +00:02:49,000 --> 00:02:51,000 +This diagram here was done with banking. + +55 +00:02:53,000 --> 00:02:58,000 +Now, when it comes to request forgery, everything I just went through here, guys, is right here. + +56 +00:02:59,000 --> 00:03:04,000 +Uh, basically everything I just went through is right here, and the diagram is on the next one. + +57 +00:03:04,000 --> 00:03:06,000 +So this is very dangerous. + +58 +00:03:06,000 --> 00:03:13,000 +And this is one of the reasons why you should never have your account logged in at all times, especially + +59 +00:03:13,000 --> 00:03:16,000 +important things such as Amazon. + +60 +00:03:16,000 --> 00:03:21,000 +Anything that has to deal with what I consider financial and health information, hospital information, + +61 +00:03:22,000 --> 00:03:25,000 +uh, especially financial things like your credit card. + +62 +00:03:25,000 --> 00:03:26,000 +Be careful with that. + +63 +00:03:26,000 --> 00:03:31,000 +Now the other one here that's mentioned is called server side request forgery. + +64 +00:03:31,000 --> 00:03:37,000 +In this one, the attacker manipulates a server to make a request to an internal service within the + +65 +00:03:37,000 --> 00:03:38,000 +organization. + +66 +00:03:39,000 --> 00:03:43,000 +So imagine an attacker is outside. + +67 +00:03:43,000 --> 00:03:47,000 +They can't get in to make requests because they don't have access in. + +68 +00:03:47,000 --> 00:03:52,000 +But if they can get an internal server to make a request on their behalf. + +69 +00:03:53,000 --> 00:03:57,000 +They are basically golden, because now that internal server can get all kinds of data and send it to + +70 +00:03:57,000 --> 00:03:58,000 +them. + +71 +00:03:58,000 --> 00:04:02,000 +Remember, we generally don't stop things going out a lot most of the time. + +72 +00:04:03,000 --> 00:04:07,000 +Uh, but when you think malicious traffic trying to come in, you always stop. + +73 +00:04:08,000 --> 00:04:09,000 +Now. + +74 +00:04:09,000 --> 00:04:09,000 +How? + +75 +00:04:09,000 --> 00:04:10,000 +How are they going to do this? + +76 +00:04:10,000 --> 00:04:16,000 +Well, that's going to be exploited in some kind of application on that server to send this bad request. + +77 +00:04:17,000 --> 00:04:23,000 +This allows them to bypass all your firewalls and all of your good security devices. + +78 +00:04:23,000 --> 00:04:26,000 +Now, these forgery requests is, of course, very bad. + +79 +00:04:26,000 --> 00:04:30,000 +One of the first things we can do is I mentioned already, is to make sure you secure your username + +80 +00:04:30,000 --> 00:04:31,000 +and password and always log out of it. + +81 +00:04:32,000 --> 00:04:40,000 +There are some things we can implement called anti cross-site request forgery tokens in certain applications. + +82 +00:04:40,000 --> 00:04:44,000 +These token is shorter requests are generated by the actual user, not a third party. + +83 +00:04:44,000 --> 00:04:48,000 +So that way they are internal tokens that they can use. + +84 +00:04:48,000 --> 00:04:53,000 +That way when you go to a particular website, it knows the token was generated by you and not somebody + +85 +00:04:53,000 --> 00:04:54,000 +else far away. + +86 +00:04:55,000 --> 00:05:01,000 +There's also different things you can do in custom headers and check in what's called a refer header. + +87 +00:05:01,000 --> 00:05:05,000 +When it comes to server side scripting, input validation is going to be important. + +88 +00:05:05,000 --> 00:05:08,000 +Validating particular user inputs, especially on web server. + +89 +00:05:08,000 --> 00:05:10,000 +Least principles. + +90 +00:05:10,000 --> 00:05:11,000 +Principles of least privileges. + +91 +00:05:11,000 --> 00:05:15,000 +Make sure that server doesn't have access to multiple data or confidential data. + +92 +00:05:15,000 --> 00:05:18,000 +And of course, segmenting your network is going to work. + +93 +00:05:19,000 --> 00:05:22,000 +Cross-site request forgery is something that was popular a long time ago. + +94 +00:05:22,000 --> 00:05:29,000 +Although it's not very popular today, it can still happen, so make sure you take good care when surfing + +95 +00:05:29,000 --> 00:05:31,000 +the internet so this doesn't happen to you. + diff --git a/06 - Signs of Attacks/017 Directory Traversal OB 2.4_en.srt b/06 - Signs of Attacks/017 Directory Traversal OB 2.4_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..f13c463dff17b1f72a65a71e5828046197db1ac9 --- /dev/null +++ b/06 - Signs of Attacks/017 Directory Traversal OB 2.4_en.srt @@ -0,0 +1,216 @@ +1 +00:00:00,000 --> 00:00:07,000 +Okay, I just finished setting up a website on Windows Web Server known as IIs or Internet Information + +2 +00:00:07,000 --> 00:00:08,000 +Services. + +3 +00:00:08,000 --> 00:00:13,000 +Now, it's not the most popular web server out there, but if you're running specific applications that + +4 +00:00:13,000 --> 00:00:17,000 +needs to utilize certain Microsoft services, it's probably your only option. + +5 +00:00:17,000 --> 00:00:22,000 +A lot of websites such as Microsoft.com runs on IIs. + +6 +00:00:22,000 --> 00:00:27,000 +Now, I made a website and it has a vulnerability and I want to show you this particular vulnerability. + +7 +00:00:27,000 --> 00:00:28,000 +Let's take a look at what I did. + +8 +00:00:28,000 --> 00:00:30,000 +So this is the virtual machine. + +9 +00:00:30,000 --> 00:00:30,000 +All right. + +10 +00:00:30,000 --> 00:00:32,000 +This is our Windows Virtual machine. + +11 +00:00:32,000 --> 00:00:36,000 +All right a windows 2019 server 2019 virtual machine. + +12 +00:00:37,000 --> 00:00:41,000 +And uh, I want to show you the website that I made. + +13 +00:00:41,000 --> 00:00:45,000 +So it's called R host dot local. + +14 +00:00:45,000 --> 00:00:47,000 +So r host dot local, as you can see. + +15 +00:00:48,000 --> 00:00:51,000 +Now what happens if I just go there and I say images. + +16 +00:00:52,000 --> 00:00:55,000 +Um I'm able to browse this directory. + +17 +00:00:55,000 --> 00:00:56,000 +That's not right. + +18 +00:00:57,000 --> 00:01:02,000 +So you notice it has in this directory is a pic a picture okay. + +19 +00:01:02,000 --> 00:01:04,000 +All right I was able to see that picture. + +20 +00:01:04,000 --> 00:01:07,000 +And I'm able to see the secret dot txt text. + +21 +00:01:07,000 --> 00:01:08,000 +And this is a file I just added in there. + +22 +00:01:10,000 --> 00:01:14,000 +So what is happening is I'm able to browse the directory on here. + +23 +00:01:14,000 --> 00:01:20,000 +Now this is because I misconfigured a web server and I'm allowing this. + +24 +00:01:20,000 --> 00:01:21,000 +You see here is the web server. + +25 +00:01:21,000 --> 00:01:28,000 +Here's the IaaS manager that you would open from your server console or your dashboard tools IIs. + +26 +00:01:28,000 --> 00:01:31,000 +And you notice in here there is something we call directory browser. + +27 +00:01:31,000 --> 00:01:35,000 +So when I go here right now it's enabled I'm going to disable it. + +28 +00:01:35,000 --> 00:01:37,000 +That's what it should be. + +29 +00:01:37,000 --> 00:01:38,000 +So what happened? + +30 +00:01:38,000 --> 00:01:39,000 +That was a vulnerability. + +31 +00:01:39,000 --> 00:01:47,000 +You see, by having directory browser enabled, people can then come and see all the different files + +32 +00:01:47,000 --> 00:01:50,000 +and folders on your particular machine. + +33 +00:01:50,000 --> 00:01:54,000 +That's not good because a lot of websites has. + +34 +00:01:54,000 --> 00:01:55,000 +Good. + +35 +00:01:55,000 --> 00:01:56,000 +Yeah. + +36 +00:01:56,000 --> 00:02:02,000 +Listen carefully a lot of websites has all kinds of files, different kinds of script, file images + +37 +00:02:02,000 --> 00:02:05,000 +and password files that are listed there. + +38 +00:02:05,000 --> 00:02:10,000 +So you don't want directory traversal enabled on the machine. + +39 +00:02:10,000 --> 00:02:12,000 +You want this to be something that's disabled. + +40 +00:02:12,000 --> 00:02:19,000 +A lot of times directory traversal is more than likely some kind of misconfiguration on the web server. + +41 +00:02:20,000 --> 00:02:21,000 +And these different ways of doing this. + +42 +00:02:21,000 --> 00:02:23,000 +You can manipulate the variables. + +43 +00:02:23,000 --> 00:02:28,000 +It's generally done through the URL, and sometimes you can look for PDF like you can go, uh Andrew + +44 +00:02:28,000 --> 00:02:36,000 +host.com/uh security plus PDF, CISSP, PDF, CompTIA PDF, whatever. + +45 +00:02:36,000 --> 00:02:38,000 +And you can look for files like that. + +46 +00:02:38,000 --> 00:02:41,000 +But if directory traversal is not enabled you can't do that. + +47 +00:02:41,000 --> 00:02:42,000 +Now. + +48 +00:02:43,000 --> 00:02:48,000 +They can use all kinds of sequence and variants and some of them that can even find password files. + +49 +00:02:48,000 --> 00:02:50,000 +So you want to make sure that this thing is disabled. + +50 +00:02:50,000 --> 00:02:56,000 +More than likely directory traversal is something that happens because the web server is misconfigured. + +51 +00:02:56,000 --> 00:02:57,000 +So keep that in mind. + +52 +00:02:57,000 --> 00:02:58,000 +All right. + +53 +00:02:58,000 --> 00:03:03,000 +So keep in mind directory traversal just allows you to browse all the files on that particular web server. + +54 +00:03:03,000 --> 00:03:06,000 +And of course this can expose sensitive data. + diff --git a/06 - Signs of Attacks/018 Indicators of Malicious Activity OB 2.4_en.srt b/06 - Signs of Attacks/018 Indicators of Malicious Activity OB 2.4_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..d97d3be0b3d43bcc0d578ad53c8d751628b6cc98 --- /dev/null +++ b/06 - Signs of Attacks/018 Indicators of Malicious Activity OB 2.4_en.srt @@ -0,0 +1,256 @@ +1 +00:00:00,000 --> 00:00:07,000 +When it comes to detecting attacks, it's super important to know what are indicators of an attack. + +2 +00:00:07,000 --> 00:00:08,000 +Like what? + +3 +00:00:08,000 --> 00:00:09,000 +Like let's say you're using a machine. + +4 +00:00:09,000 --> 00:00:11,000 +How do you know that your machine is under attack? + +5 +00:00:11,000 --> 00:00:14,000 +How do you know that somebody's stealing your data? + +6 +00:00:14,000 --> 00:00:21,000 +How can we teach our users the different symptoms that could occur when their machines is being attacked? + +7 +00:00:21,000 --> 00:00:28,000 +So I have here a list of things that we should know that can occur during an attack. + +8 +00:00:28,000 --> 00:00:31,000 +The first thing up is that I see pretty common. + +9 +00:00:31,000 --> 00:00:32,000 +It's something we call account lockout. + +10 +00:00:32,000 --> 00:00:33,000 +Now what is that? + +11 +00:00:33,000 --> 00:00:33,000 +Well. + +12 +00:00:34,000 --> 00:00:40,000 +When they're trying to break into your account, they're going to try multiple passwords and a lot of + +13 +00:00:40,000 --> 00:00:41,000 +websites and computers. + +14 +00:00:41,000 --> 00:00:45,000 +If you put the passwords too many times, it kind of locks out the account. + +15 +00:00:45,000 --> 00:00:49,000 +For example, if you take my phone and you put my password in a whole bunch of times wrong, it basically + +16 +00:00:49,000 --> 00:00:52,000 +locks out the the phone and you can't log in. + +17 +00:00:52,000 --> 00:00:56,000 +So that's one indicator that you know what your system is under attack. + +18 +00:00:56,000 --> 00:00:58,000 +Concurrent session usage. + +19 +00:00:58,000 --> 00:01:04,000 +For example, if you notice that your session is logged into multiple computers and an administrator + +20 +00:01:04,000 --> 00:01:10,000 +can notice depending on what type of information systems they're managing, what's called Siem systems, + +21 +00:01:10,000 --> 00:01:15,000 +security information, event management systems, they can see all kinds of logins happening all over. + +22 +00:01:15,000 --> 00:01:20,000 +So if they see, for example, one user account is logged into four different systems, that's a good + +23 +00:01:20,000 --> 00:01:25,000 +indicator that the guy's hacked because technically can be used in four machines at the exact same time. + +24 +00:01:27,000 --> 00:01:29,000 +Block content or firewall filters. + +25 +00:01:29,000 --> 00:01:35,000 +So for example, if a firewall sends out an alert that this guy is downloading this bad file, that + +26 +00:01:35,000 --> 00:01:41,000 +right there tells you, hey, the system is being attacked, or this person is attempting to get bad + +27 +00:01:41,000 --> 00:01:45,000 +data in impossible travel logins from geographically distant locations. + +28 +00:01:45,000 --> 00:01:51,000 +So let's say you're walking around one day, you check your email and you say, my Gmail is trying to + +29 +00:01:51,000 --> 00:01:55,000 +log in from Europe and you're in the United States, or vice versa, or something like, oh my God, + +30 +00:01:55,000 --> 00:01:56,000 +what the hell is this? + +31 +00:01:56,000 --> 00:01:56,000 +I don't live in Europe. + +32 +00:01:56,000 --> 00:01:58,000 +I didn't try that again. + +33 +00:01:58,000 --> 00:02:02,000 +Impossible travel could be somebody hacking your account. + +34 +00:02:02,000 --> 00:02:05,000 +Resource consumption the telltale sign of known. + +35 +00:02:05,000 --> 00:02:10,000 +If you're having a virus, your machine slows down to a crawling halt. + +36 +00:02:10,000 --> 00:02:11,000 +No one could. + +37 +00:02:11,000 --> 00:02:12,000 +Nothing could move. + +38 +00:02:12,000 --> 00:02:15,000 +No application is opening resource consumption. + +39 +00:02:15,000 --> 00:02:21,000 +If you notice your hard drive is really slow, or your CPU open up your task manager. + +40 +00:02:21,000 --> 00:02:25,000 +And if you realize your CPU is always at the top and you're not doing anything, probably attacked or + +41 +00:02:25,000 --> 00:02:28,000 +some virus is stealing something resource. + +42 +00:02:29,000 --> 00:02:34,000 +If you can't get to certain resources or services like certain websites, it's probably under an attack + +43 +00:02:34,000 --> 00:02:39,000 +out of cycle logins logs generated outside of expected time frames. + +44 +00:02:40,000 --> 00:02:43,000 +So we know that between 9 and 5:00 everybody's in the office. + +45 +00:02:43,000 --> 00:02:48,000 +You got a lot of log files, but then all of a sudden you start getting log files at 9 p.m. to 12. + +46 +00:02:48,000 --> 00:02:49,000 +It's kind of odd. + +47 +00:02:49,000 --> 00:02:50,000 +Nobody's there. + +48 +00:02:50,000 --> 00:02:53,000 +Why is there, why is there traffic? + +49 +00:02:54,000 --> 00:02:55,000 +Published document. + +50 +00:02:55,000 --> 00:02:56,000 +Known vulnerabilities. + +51 +00:02:56,000 --> 00:02:58,000 +This is going to be something that's common. + +52 +00:02:58,000 --> 00:03:05,000 +Microsoft for example, Sonicwall all big vendors publishes known vulnerabilities against their systems. + +53 +00:03:05,000 --> 00:03:07,000 +Keep an eye on them. + +54 +00:03:07,000 --> 00:03:10,000 +Always be subscribed to security news, for example. + +55 +00:03:10,000 --> 00:03:12,000 +And of course missing log files. + +56 +00:03:12,000 --> 00:03:17,000 +One of the number one thing hackers are going to do when they try to hack you is delete the log files. + +57 +00:03:17,000 --> 00:03:22,000 +Because when I teach ethical hacking, I say clean up or clear your tracks. + +58 +00:03:22,000 --> 00:03:23,000 +I mean, that's what this is. + +59 +00:03:23,000 --> 00:03:25,000 +You're basically going to go. + +60 +00:03:25,000 --> 00:03:29,000 +And so if you have a missing log files or gaps in it, you're probably been hacked. + +61 +00:03:29,000 --> 00:03:30,000 +All right. + +62 +00:03:30,000 --> 00:03:36,000 +These are some things that more than likely you want to tell your users good user training should really + +63 +00:03:36,000 --> 00:03:42,000 +go in there and tell them, hey, these are things that if you notice, let the it know because those + +64 +00:03:42,000 --> 00:03:44,000 +people could be under attack. + diff --git a/06 - Signs of Attacks/019 Quick Quiz.html b/06 - Signs of Attacks/019 Quick Quiz.html new file mode 100644 index 0000000000000000000000000000000000000000..edf45875deeb90e38c8cfc7678d22e059af653a9 --- /dev/null +++ b/06 - Signs of Attacks/019 Quick Quiz.html @@ -0,0 +1,479 @@ + + + + + + + Quiz + + + + +
+
+

+

+
+
+
+ Score: 999 of + 999% +
+
Correct: 999
+
Incorrect: 999
+
+ +
+ + + + +
+ + + + diff --git a/07 - Cryptography/001 Intro to cryptography OB 1.4_en.srt b/07 - Cryptography/001 Intro to cryptography OB 1.4_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..7c940f67ae55b00b5dbcfc1bb53a77a2e8f3550a --- /dev/null +++ b/07 - Cryptography/001 Intro to cryptography OB 1.4_en.srt @@ -0,0 +1,248 @@ +1 +00:00:00,000 --> 00:00:03,000 +Welcome to the world of cryptography. + +2 +00:00:03,000 --> 00:00:10,000 +And in this section, I'm going to be going through all the cryptographic terms, algorithms, processes + +3 +00:00:10,000 --> 00:00:13,000 +that you're going to need to know to pass your exam. + +4 +00:00:13,000 --> 00:00:19,000 +Now this section is quite large and it's considered quite complex, as cryptography is known to be one + +5 +00:00:19,000 --> 00:00:21,000 +of the hardest topics to study for. + +6 +00:00:21,000 --> 00:00:26,000 +Now, the good news is that for your exam, you don't need to know math. + +7 +00:00:26,000 --> 00:00:31,000 +If you're starting out this section and you're scared to death because I'm going to put a bunch of math + +8 +00:00:31,000 --> 00:00:33,000 +in front of you, you don't need to know any of that. + +9 +00:00:33,000 --> 00:00:35,000 +In fact, there's not even a ton of memorization. + +10 +00:00:35,000 --> 00:00:40,000 +But you do need to understand some core concepts for your actual exam. + +11 +00:00:40,000 --> 00:00:42,000 +And with that in mind, let's get started. + +12 +00:00:42,000 --> 00:00:49,000 +So first of all, when people talk about it, security, when people come out and say, well, I want + +13 +00:00:49,000 --> 00:00:55,000 +to keep my secret data secret, what exactly is keeping the data secret? + +14 +00:00:55,000 --> 00:00:57,000 +Well, that's cryptography. + +15 +00:00:57,000 --> 00:01:00,000 +Almost every single thing we do. + +16 +00:01:00,000 --> 00:01:06,000 +In the world of security especially, it revolves around cryptography. + +17 +00:01:06,000 --> 00:01:13,000 +So whether you're a newbie or a noob in the world of security, or you're a seasoned IT security professional + +18 +00:01:13,000 --> 00:01:20,000 +with tons of experience, you should have basic understanding of cryptography from logging in to this + +19 +00:01:20,000 --> 00:01:22,000 +sonicwall, which we'll do in the course, right? + +20 +00:01:22,000 --> 00:01:26,000 +If you haven't watched that section yet, we log in from configuring this device. + +21 +00:01:26,000 --> 00:01:28,000 +Because why passwords are hashed. + +22 +00:01:28,000 --> 00:01:32,000 +And that's falls into the realm of cryptography to transferring data from Amazon. + +23 +00:01:32,000 --> 00:01:37,000 +When I when I bought the purchase for this device, that's all SSL. + +24 +00:01:37,000 --> 00:01:41,000 +We're going to learn the process of the SSL handshake in this section. + +25 +00:01:41,000 --> 00:01:46,000 +So there is a lot to learn in cryptography. + +26 +00:01:46,000 --> 00:01:53,000 +But remember there is many, many, many applications of it throughout IT security. + +27 +00:01:53,000 --> 00:02:00,000 +Once again, from logging in with a password that's a hash to all communications across all networks, + +28 +00:02:00,000 --> 00:02:03,000 +which is of course encrypted or should be encrypted. + +29 +00:02:03,000 --> 00:02:05,000 +Cryptography affects all of that. + +30 +00:02:06,000 --> 00:02:09,000 +Now, when we talk about cryptography, what exactly is it? + +31 +00:02:09,000 --> 00:02:17,000 +Well, crypto cryptography itself is the practice and study of techniques for securing communications + +32 +00:02:17,000 --> 00:02:20,000 +and data in the perseverance of adversaries. + +33 +00:02:20,000 --> 00:02:21,000 +And what does that mean? + +34 +00:02:21,000 --> 00:02:29,000 +Well, basically cryptography is how we're going to keep our data secure when there's adversaries who + +35 +00:02:29,000 --> 00:02:29,000 +are adversaries. + +36 +00:02:29,000 --> 00:02:36,000 +Well, adversaries are that hacker that wants to steal your data, that organized crime that's looking + +37 +00:02:36,000 --> 00:02:37,000 +to steal your credit card. + +38 +00:02:37,000 --> 00:02:41,000 +So cryptography is going to be there to secure against them. + +39 +00:02:41,000 --> 00:02:46,000 +It involves creating written or generated codes that allows information to keep secret. + +40 +00:02:46,000 --> 00:02:48,000 +And I'm going to show you guys some of those codes coming up. + +41 +00:02:48,000 --> 00:02:55,000 +So cryptography both protects information from theft or alteration and can be used and can also be used + +42 +00:02:55,000 --> 00:02:57,000 +for user authentication. + +43 +00:02:57,000 --> 00:03:02,000 +So we're going to protect information as it traverses the network securely. + +44 +00:03:02,000 --> 00:03:03,000 +So anybody that looks at it can't read it. + +45 +00:03:03,000 --> 00:03:07,000 +We're also going to be able to detect if the data was modified. + +46 +00:03:07,000 --> 00:03:13,000 +So if I send you information across a large network such as the internet, we're going to be able to + +47 +00:03:13,000 --> 00:03:15,000 +detect if that data was modified. + +48 +00:03:15,000 --> 00:03:20,000 +And finally, I already mentioned that we use cryptography in the world of hashing. + +49 +00:03:20,000 --> 00:03:20,000 +Right. + +50 +00:03:20,000 --> 00:03:21,000 +Cryptographic hashes. + +51 +00:03:21,000 --> 00:03:25,000 +We do use it there, uh, to authenticate and log people in. + +52 +00:03:25,000 --> 00:03:29,000 +So we'll come on to all of this coming up in this section. + +53 +00:03:29,000 --> 00:03:29,000 +All right. + +54 +00:03:29,000 --> 00:03:35,000 +So let's get started with the all the terminologies, all the processes that you're going to have. + +55 +00:03:35,000 --> 00:03:41,000 +Now the way I'm going to teach this is that I'm going to start out by giving you some basic cryptography + +56 +00:03:41,000 --> 00:03:42,000 +concepts. + +57 +00:03:42,000 --> 00:03:44,000 +That's not going to be covered on your exam. + +58 +00:03:44,000 --> 00:03:49,000 +But that forms the basis of understanding everything that is covered on your exam. + +59 +00:03:49,000 --> 00:03:56,000 +So while it seems like I'm covering some basic elementary things, I want you to keep in mind that without + +60 +00:03:56,000 --> 00:04:01,000 +those basic elementary things, you're not going to understand the things you do need to know for your + +61 +00:04:01,000 --> 00:04:01,000 +tests. + +62 +00:04:01,000 --> 00:04:05,000 +So let's get started and have some fun in the world of cryptography. + diff --git a/07 - Cryptography/002 Crypto Terms OB 1.4_en.srt b/07 - Cryptography/002 Crypto Terms OB 1.4_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..23835f34b06559e56787fdc2059d0f9c486e2875 --- /dev/null +++ b/07 - Cryptography/002 Crypto Terms OB 1.4_en.srt @@ -0,0 +1,160 @@ +1 +00:00:00,000 --> 00:00:05,000 +Let's take a look at some basic cryptography terms that you're going to probably see throughout your + +2 +00:00:05,000 --> 00:00:07,000 +readings and throughout your studying. + +3 +00:00:07,000 --> 00:00:10,000 +The first one up is the actual terms itself cryptography. + +4 +00:00:10,000 --> 00:00:17,000 +So cryptography, the Tum itself means the art and science of hiding the meaning of communications from + +5 +00:00:17,000 --> 00:00:18,000 +unintended recipient. + +6 +00:00:18,000 --> 00:00:23,000 +So when we say we are doing cryptography, what is what exactly are we doing? + +7 +00:00:23,000 --> 00:00:29,000 +We're basically taking information and we're going to be traversing we're going to be sending this information. + +8 +00:00:29,000 --> 00:00:36,000 +But the whole point of it is to hide the meaning of that communication from people that just doesn't + +9 +00:00:36,000 --> 00:00:36,000 +need it. + +10 +00:00:36,000 --> 00:00:40,000 +So, for example, let's say I go on Amazon and I buy something. + +11 +00:00:40,000 --> 00:00:47,000 +Well, the only people that should ever know what I purchase, what my credit card number is, what + +12 +00:00:47,000 --> 00:00:49,000 +my login is, was me and Amazon. + +13 +00:00:49,000 --> 00:00:54,000 +Any other unintended recipient like a hacker or some kind shouldn't get that. + +14 +00:00:54,000 --> 00:01:00,000 +So when we encrypt it, the only people that should know the data is the sender and the receiver. + +15 +00:01:00,000 --> 00:01:06,000 +Okay, the other terms here is and I hope you guys don't do this is crypto analysis. + +16 +00:01:06,000 --> 00:01:11,000 +Crypto analysis is a study of methods to defeat codes and ciphers. + +17 +00:01:11,000 --> 00:01:18,000 +So although this is what hackers do, they find ways or they try to find ways to defeat certain cryptographic + +18 +00:01:18,000 --> 00:01:18,000 +algorithms. + +19 +00:01:18,000 --> 00:01:22,000 +I want you guys to understand something about cryptanalysis. + +20 +00:01:22,000 --> 00:01:27,000 +Crypto analysis, although it sounds negative, can also be used in positive lights. + +21 +00:01:27,000 --> 00:01:34,000 +For example, in World War Two, British cryptographers and American cryptographers came together to + +22 +00:01:34,000 --> 00:01:36,000 +defeat the German Enigma machine. + +23 +00:01:36,000 --> 00:01:39,000 +That was a machine that the Germans were using. + +24 +00:01:39,000 --> 00:01:45,000 +Nazis in particular, were using to encrypt their data so they could do crypto analysis and break that + +25 +00:01:45,000 --> 00:01:47,000 +machine or break the codes. + +26 +00:01:47,000 --> 00:01:49,000 +It would give them a heads up and know exactly what's going on. + +27 +00:01:50,000 --> 00:01:55,000 +But in today's world, remember something cryptoanalysis is basically how do we defeat ciphers? + +28 +00:01:55,000 --> 00:01:59,000 +One of the most famous ciphers we use today is AES encryption. + +29 +00:01:59,000 --> 00:01:59,000 +Can we? + +30 +00:01:59,000 --> 00:02:05,000 +This probably hackers or bad guys today looking for ways to break that particular algorithm? + +31 +00:02:05,000 --> 00:02:08,000 +The word cryptology though is a different thing. + +32 +00:02:08,000 --> 00:02:09,000 +That's the study of both. + +33 +00:02:09,000 --> 00:02:13,000 +Cryptology is cryptography, which is going to be secure in the data. + +34 +00:02:13,000 --> 00:02:18,000 +And of course, breaking the cipher another time is going to be crypto variable. + +35 +00:02:18,000 --> 00:02:21,000 +Now you hear sometimes we refer to this as cryptographic keys. + +36 +00:02:21,000 --> 00:02:25,000 +Crypto variable is what's changing in the cryptographic systems all the time. + +37 +00:02:25,000 --> 00:02:28,000 +In fact, every single time you encrypt data you generally use a new key. + +38 +00:02:29,000 --> 00:02:34,000 +So these are some interesting terms here that you want to be familiar with for your exam. + +39 +00:02:34,000 --> 00:02:38,000 +And of course as we go through this section, because sometimes I'm going to be referring to them and + +40 +00:02:38,000 --> 00:02:40,000 +you make sure you know the meaning of them. + diff --git a/07 - Cryptography/003 Goals Cryptography OB 1.4_en.srt b/07 - Cryptography/003 Goals Cryptography OB 1.4_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..c1f02b0441d16298486bc7de83d3e91c2f33cdce --- /dev/null +++ b/07 - Cryptography/003 Goals Cryptography OB 1.4_en.srt @@ -0,0 +1,420 @@ +1 +00:00:00,000 --> 00:00:06,000 +Before we implement all of the different algorithms and keys and cryptosystems that are out there in + +2 +00:00:06,000 --> 00:00:10,000 +order to secure information, the key point is what's the main goal? + +3 +00:00:10,000 --> 00:00:15,000 +By encrypting your data using something such as SSL? + +4 +00:00:15,000 --> 00:00:17,000 +What exactly is the main goal? + +5 +00:00:17,000 --> 00:00:21,000 +So in this video I want to look at four main goals of cryptography. + +6 +00:00:21,000 --> 00:00:23,000 +Now you already know the first one. + +7 +00:00:23,000 --> 00:00:25,000 +You already talked about this and that's confidentiality. + +8 +00:00:25,000 --> 00:00:27,000 +It's keeping secret data secret. + +9 +00:00:27,000 --> 00:00:31,000 +But there are three others that we want to get in depth also. + +10 +00:00:31,000 --> 00:00:34,000 +So the first thing up is of course confidentiality. + +11 +00:00:34,000 --> 00:00:35,000 +One of the main goals. + +12 +00:00:35,000 --> 00:00:40,000 +You know, when people think of encrypted information, they're thinking about ensuring that the information + +13 +00:00:40,000 --> 00:00:44,000 +is only accessible to those who have authorized access to it. + +14 +00:00:44,000 --> 00:00:50,000 +So when I encrypt data, only the person that's supposed to be receiving it and seeing it should have + +15 +00:00:50,000 --> 00:00:51,000 +access to it. + +16 +00:00:52,000 --> 00:00:58,000 +Now, of course, encryption is one of the main ways of providing confidentiality. + +17 +00:00:58,000 --> 00:01:00,000 +Now, there's two terms here that we want to talk about. + +18 +00:01:00,000 --> 00:01:04,000 +That's called plaintext and ciphertext. + +19 +00:01:04,000 --> 00:01:09,000 +When data lies in a state that anyone can read it, that's called plaintext. + +20 +00:01:09,000 --> 00:01:13,000 +So right now this text on this slide here is plain text. + +21 +00:01:13,000 --> 00:01:18,000 +When the data becomes encrypted it turns into ciphertext or scrambled. + +22 +00:01:18,000 --> 00:01:19,000 +It's unreadable. + +23 +00:01:19,000 --> 00:01:26,000 +Now in the process of encryption you're basically going to be listen carefully taking this plaintext + +24 +00:01:26,000 --> 00:01:29,000 +encrypting it to form ciphertext. + +25 +00:01:29,000 --> 00:01:32,000 +The process of decryption is when you take. + +26 +00:01:33,000 --> 00:01:37,000 +Ciphertext and then decrypt it to form plaintext. + +27 +00:01:37,000 --> 00:01:37,000 +So keep that in mind. + +28 +00:01:37,000 --> 00:01:44,000 +So when we think of encryption most of us are thinking about confidentiality right. + +29 +00:01:44,000 --> 00:01:45,000 +Hey I'm going to be encrypting this data. + +30 +00:01:45,000 --> 00:01:50,000 +You're thinking okay then no one should have access to the information, but the senders and receivers + +31 +00:01:50,000 --> 00:01:53,000 +of the data or the intended recipients of the data. + +32 +00:01:53,000 --> 00:01:58,000 +Now, the other goal of cryptography is going to be integrity. + +33 +00:01:59,000 --> 00:02:07,000 +If you remember, when we covered the basic concepts of security, we talked about integrity being about + +34 +00:02:07,000 --> 00:02:11,000 +detecting or preventing alteration of information. + +35 +00:02:11,000 --> 00:02:17,000 +Well, one of the main goals of cryptography is, is going to be protecting data from unauthorized or + +36 +00:02:17,000 --> 00:02:19,000 +accidental changes. + +37 +00:02:19,000 --> 00:02:23,000 +We do this using cryptographic hash functions. + +38 +00:02:23,000 --> 00:02:24,000 +So here's what this is. + +39 +00:02:25,000 --> 00:02:30,000 +We have data and we will be able to hash the data. + +40 +00:02:30,000 --> 00:02:36,000 +And what a cryptographic hash does is that it's going to be able to detect if the data has been modified. + +41 +00:02:36,000 --> 00:02:42,000 +For example, let's say I'm sitting at my desk here and you're sitting at your desk across the room. + +42 +00:02:42,000 --> 00:02:49,000 +I'm going to send data from my computer to yours as the data traverses the entire corporate network. + +43 +00:02:49,000 --> 00:02:53,000 +Did anybody intercept the data and manipulate or change the data? + +44 +00:02:53,000 --> 00:02:56,000 +Well, a cryptographic hash will be able to detect that. + +45 +00:02:56,000 --> 00:03:01,000 +It'll be able to detect that the data was changed or it was not changed. + +46 +00:03:02,000 --> 00:03:10,000 +Even more prominent is, for example, let's say I go to Amazon, I buy something and the credit card + +47 +00:03:10,000 --> 00:03:12,000 +information that I type on my computer and send to Amazon. + +48 +00:03:12,000 --> 00:03:18,000 +Hopefully nobody intercepted that and manipulated it or the data that Amazon is sending me back my order + +49 +00:03:18,000 --> 00:03:19,000 +confirmation. + +50 +00:03:19,000 --> 00:03:22,000 +Nobody has intercepted that and manipulated. + +51 +00:03:22,000 --> 00:03:25,000 +So integrity is a big part of cryptography. + +52 +00:03:25,000 --> 00:03:27,000 +And this is generally done using cryptographic hash. + +53 +00:03:27,000 --> 00:03:30,000 +And once again it's to verify the data has not been altered. + +54 +00:03:32,000 --> 00:03:36,000 +Two other things here is going to be authentication and non-repudiation. + +55 +00:03:36,000 --> 00:03:42,000 +So authentication is verifying the identity of a user device or entity in a communication process. + +56 +00:03:42,000 --> 00:03:49,000 +Now when you go to a computer how do you verify your identity to that machine. + +57 +00:03:49,000 --> 00:03:51,000 +How does that desktop like this one right on my desk. + +58 +00:03:51,000 --> 00:04:00,000 +How does that desktop, that laptop, that firewall, that router, how does that how does those devices + +59 +00:04:00,000 --> 00:04:06,000 +verify you are who you say you are generally with a password. + +60 +00:04:07,000 --> 00:04:10,000 +Passwords generally are cryptographic hashes. + +61 +00:04:10,000 --> 00:04:13,000 +So once again we're using a hash to verify data. + +62 +00:04:13,000 --> 00:04:17,000 +But we also encrypt those passwords a quote unquote hash those passwords. + +63 +00:04:17,000 --> 00:04:21,000 +Another thing we use in cryptography is digital certificates. + +64 +00:04:21,000 --> 00:04:27,000 +For example, when you go to Amazon and you type Amazon.com, how does your machine. + +65 +00:04:27,000 --> 00:04:35,000 +And you in particular know that that's actually Amazon and not some fake website pretending to be Amazon. + +66 +00:04:35,000 --> 00:04:40,000 +Keep that in mind, because when we get to the whole section of public key infrastructure digital certificates, + +67 +00:04:40,000 --> 00:04:46,000 +one of the main jobs of digital certificate is to authenticate that site against your machine. + +68 +00:04:46,000 --> 00:04:49,000 +So digital certificates, cryptographic hashes is going to help me here. + +69 +00:04:50,000 --> 00:04:54,000 +And last goal here I want to talk about is non-repudiation. + +70 +00:04:55,000 --> 00:04:59,000 +So one of the things we have is something called a digital signature. + +71 +00:04:59,000 --> 00:05:04,000 +And what a digital signature does is that if I sign something and I send it to you, you're going to + +72 +00:05:04,000 --> 00:05:06,000 +be 100% sure it came from me. + +73 +00:05:06,000 --> 00:05:12,000 +And I cannot deny that I didn't send it because only I can create that signature. + +74 +00:05:12,000 --> 00:05:18,000 +So non-repudiation prevents an entity from denying their involvement in a transaction or activity. + +75 +00:05:18,000 --> 00:05:19,000 +So what does that mean? + +76 +00:05:20,000 --> 00:05:25,000 +Well, if I digitally sign something and I sent it to you, I can't deny it wasn't me. + +77 +00:05:25,000 --> 00:05:27,000 +I can't say, well, I didn't make that document. + +78 +00:05:27,000 --> 00:05:30,000 +Well, you're the only one that could have digitally signed it. + +79 +00:05:30,000 --> 00:05:32,000 +So we'll come to digital signature later. + +80 +00:05:32,000 --> 00:05:37,000 +But remember, digital signatures helps with non-repudiation, digital certificates, and cryptographic + +81 +00:05:38,000 --> 00:05:40,000 +helps with authentication. + +82 +00:05:40,000 --> 00:05:46,000 +Uh, the general cryptographic symmetric encryption is going to help with confidentiality and cryptographic + +83 +00:05:46,000 --> 00:05:48,000 +hashes helps with integrity. + +84 +00:05:48,000 --> 00:05:56,000 +Keep these in mind that when you're thinking of cryptography it does what confidentiality it does integrity. + +85 +00:05:56,000 --> 00:05:58,000 +It does authentication. + +86 +00:05:58,000 --> 00:06:00,000 +It does non-repudiation. + +87 +00:06:00,000 --> 00:06:06,000 +There is a very important security concept that cryptography doesn't do. + +88 +00:06:07,000 --> 00:06:08,000 +Do you guys remember what that is? + +89 +00:06:08,000 --> 00:06:13,000 +If you remember the CIA triad that A was an authentication that A was availability. + +90 +00:06:13,000 --> 00:06:16,000 +Cryptography has nothing to do with availability. + +91 +00:06:16,000 --> 00:06:17,000 +But people think of availability. + +92 +00:06:18,000 --> 00:06:20,000 +You're thinking high up times on systems. + +93 +00:06:20,000 --> 00:06:26,000 +You're thinking Raid systems to keep like redundant hard drives, redundant power supply, redundant + +94 +00:06:26,000 --> 00:06:28,000 +sites, uh, clustering. + +95 +00:06:28,000 --> 00:06:31,000 +Those are going to be things that keeps high availability. + +96 +00:06:31,000 --> 00:06:37,000 +So remember for your exam cryptography one of the goals of cryptography is not availability. + +97 +00:06:37,000 --> 00:06:38,000 +All right. + +98 +00:06:38,000 --> 00:06:41,000 +There's nothing in the world of cryptography that deals with availability. + +99 +00:06:41,000 --> 00:06:45,000 +So remember that time for your exam because sometimes they like asking that. + +100 +00:06:45,000 --> 00:06:48,000 +And it's all if you're looking at a question that talks about. + +101 +00:06:49,000 --> 00:06:50,000 +Oh, what is this? + +102 +00:06:50,000 --> 00:06:51,000 +You know, what is the goal of cryptography here? + +103 +00:06:51,000 --> 00:06:52,000 +And you see availability. + +104 +00:06:52,000 --> 00:06:56,000 +Just take that choice out because that's never never going to be the answer. + +105 +00:06:56,000 --> 00:06:59,000 +So remember these goals for cryptography for your tests. + diff --git a/07 - Cryptography/004 Algorithm vs Keys OB 1.4_en.srt b/07 - Cryptography/004 Algorithm vs Keys OB 1.4_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..3bbc03c292a683720f3120d015b32d5f6011451c --- /dev/null +++ b/07 - Cryptography/004 Algorithm vs Keys OB 1.4_en.srt @@ -0,0 +1,1764 @@ +1 +00:00:00,000 --> 00:00:01,000 +In the world of cryptography. + +2 +00:00:01,000 --> 00:00:06,000 +Two terms that you're going to hear a lot of is what we call algorithm and keys. + +3 +00:00:06,000 --> 00:00:12,000 +And in this video, I want to make sense of that to you because they're not the same thing, okay? + +4 +00:00:12,000 --> 00:00:16,000 +In fact, one is completely public and one is should be completely secret. + +5 +00:00:16,000 --> 00:00:20,000 +So in this video, let's get down to the difference between algorithm and keys. + +6 +00:00:20,000 --> 00:00:29,000 +But before I do that, I want to go through a quick encryption, really simple encryption process for + +7 +00:00:29,000 --> 00:00:30,000 +you to understand. + +8 +00:00:30,000 --> 00:00:33,000 +I want, I want, I'm going to actually encrypt data with an algorithm and a key. + +9 +00:00:33,000 --> 00:00:36,000 +And you're going to see that it's going to make explaining everything a lot easier. + +10 +00:00:36,000 --> 00:00:41,000 +Now I do want to mention that the links I'm going to use is going to be provided in a slide at the end + +11 +00:00:41,000 --> 00:00:42,000 +of this video. + +12 +00:00:42,000 --> 00:00:45,000 +So no worries with that and I'll show you where I got them from. + +13 +00:00:45,000 --> 00:00:45,000 +Okay. + +14 +00:00:45,000 --> 00:00:47,000 +So I want you guys to take a look at this. + +15 +00:00:47,000 --> 00:00:48,000 +Let's go here. + +16 +00:00:48,000 --> 00:00:51,000 +So I have the Caesar cipher decryption tool. + +17 +00:00:51,000 --> 00:00:52,000 +Now don't worry about Caesar cipher. + +18 +00:00:52,000 --> 00:00:55,000 +I just want you to see how this thing works. + +19 +00:00:55,000 --> 00:00:56,000 +It's pretty easy. + +20 +00:00:56,000 --> 00:00:57,000 +And just see. + +21 +00:00:57,000 --> 00:00:59,000 +And this is going to make my life a lot easier. + +22 +00:00:59,000 --> 00:01:00,000 +And your life a lot easier to understand. + +23 +00:01:02,000 --> 00:01:04,000 +Okay, so I want you guys to take a look at a Caesar. + +24 +00:01:04,000 --> 00:01:09,000 +Cipher was an old cipher that was used to encrypt data back in the days of Julius Caesar. + +25 +00:01:09,000 --> 00:01:11,000 +Hence the name Caesar cipher. + +26 +00:01:11,000 --> 00:01:13,000 +And it's a really easy cipher to understand. + +27 +00:01:13,000 --> 00:01:14,000 +Let me show you how it works. + +28 +00:01:14,000 --> 00:01:15,000 +It basically is a rotational cipher. + +29 +00:01:15,000 --> 00:01:16,000 +It rotates alphabets. + +30 +00:01:16,000 --> 00:01:17,000 +Watch this. + +31 +00:01:17,000 --> 00:01:21,000 +If I have the plaintext a, b, c. + +32 +00:01:22,000 --> 00:01:28,000 +What this does is that it rotates the alphabet by a certain number of places, for example. + +33 +00:01:29,000 --> 00:01:34,000 +If now I want you guys to watch the outside rim okay. + +34 +00:01:34,000 --> 00:01:36,000 +The outside rim is going to be your plain text. + +35 +00:01:36,000 --> 00:01:39,000 +The inside rim here is going to be your cipher text. + +36 +00:01:39,000 --> 00:01:42,000 +So you notice a is the plain text. + +37 +00:01:42,000 --> 00:01:44,000 +Then it would become be in a cipher text. + +38 +00:01:44,000 --> 00:01:44,000 +Watch this. + +39 +00:01:44,000 --> 00:01:47,000 +If I say ABC and I say encrypt. + +40 +00:01:48,000 --> 00:01:51,000 +You'll notice ABC becomes BCD. + +41 +00:01:51,000 --> 00:01:58,000 +Everything shifts over one place, so A becomes B, B becomes C, and you can see that here A becomes + +42 +00:01:58,000 --> 00:02:00,000 +b, b becomes c, c becomes d. + +43 +00:02:00,000 --> 00:02:04,000 +If I say let's rotate this by two places. + +44 +00:02:04,000 --> 00:02:05,000 +Now look a is C. + +45 +00:02:05,000 --> 00:02:07,000 +Let's encrypt that. + +46 +00:02:07,000 --> 00:02:08,000 +And you notice A is C. + +47 +00:02:09,000 --> 00:02:13,000 +If I say rotate this by three places a becomes what. + +48 +00:02:13,000 --> 00:02:14,000 +D. + +49 +00:02:14,000 --> 00:02:15,000 +If you said D correct. + +50 +00:02:15,000 --> 00:02:17,000 +So this is the plaintext. + +51 +00:02:17,000 --> 00:02:18,000 +This is the cipher text. + +52 +00:02:19,000 --> 00:02:24,000 +This is the key and the algorithm is to rotate the alphabet. + +53 +00:02:24,000 --> 00:02:33,000 +So Caesar's cipher okay in its in its encryption is known as a rot13 or Rot three depending like right + +54 +00:02:33,000 --> 00:02:35,000 +now I have it as three. + +55 +00:02:35,000 --> 00:02:36,000 +This would be a Rot three encryption. + +56 +00:02:36,000 --> 00:02:36,000 +Why? + +57 +00:02:36,000 --> 00:02:38,000 +Because it's rot means rotation. + +58 +00:02:38,000 --> 00:02:44,000 +It's literally rotating the alphabet three places as the way I have it here now, right now it looks + +59 +00:02:44,000 --> 00:02:44,000 +easy. + +60 +00:02:44,000 --> 00:02:50,000 +But if I take a whole sentence like you see here, put this in here, copy paste that and I change this + +61 +00:02:50,000 --> 00:02:52,000 +to let's say eight and I say encrypt. + +62 +00:02:52,000 --> 00:02:55,000 +You'll notice that now it looks kind of weird right? + +63 +00:02:55,000 --> 00:02:59,000 +If I send you this in an email, you would know what the hell this means. + +64 +00:02:59,000 --> 00:03:02,000 +You would need to know he's using Caesar cipher. + +65 +00:03:02,000 --> 00:03:07,000 +And to decrypt this you probably need to know the key, which is eight. + +66 +00:03:07,000 --> 00:03:09,000 +So if you know the key, you'll be able to encrypt it. + +67 +00:03:09,000 --> 00:03:14,000 +Notice this key encrypts it, and this key is also can be used to decrypt it. + +68 +00:03:15,000 --> 00:03:18,000 +Now Caesar cipher is a really old cipher. + +69 +00:03:18,000 --> 00:03:21,000 +Again it came in the days of Julius Caesar 7 billion years ago. + +70 +00:03:21,000 --> 00:03:27,000 +Now, in this lesson, we're not going to talk so much about Caesar cipher, but Caesar cipher taught + +71 +00:03:27,000 --> 00:03:28,000 +us important concepts. + +72 +00:03:28,000 --> 00:03:32,000 +It taught us the difference between algorithm and keys. + +73 +00:03:32,000 --> 00:03:34,000 +And that's what we want to discuss in this video. + +74 +00:03:36,000 --> 00:03:37,000 +So let's get into it. + +75 +00:03:38,000 --> 00:03:40,000 +So a cryptographic algorithm. + +76 +00:03:40,000 --> 00:03:41,000 +Let's talk about this. + +77 +00:03:41,000 --> 00:03:42,000 +And I'm going to give you guys more examples of it. + +78 +00:03:42,000 --> 00:03:44,000 +There's going to be a long video. + +79 +00:03:44,000 --> 00:03:46,000 +So the first thing up cryptographic algorithms. + +80 +00:03:46,000 --> 00:03:48,000 +What are what exactly is an algorithm. + +81 +00:03:48,000 --> 00:03:54,000 +Well the algorithms are methods or procedures that are used to encrypt and decrypt the data. + +82 +00:03:55,000 --> 00:03:55,000 +All right. + +83 +00:03:55,000 --> 00:04:01,000 +Remember that algorithms defines how the encryption and decryption process are going to work in today's + +84 +00:04:01,000 --> 00:04:01,000 +world. + +85 +00:04:01,000 --> 00:04:04,000 +We're not going to use Caesar cipher. + +86 +00:04:04,000 --> 00:04:11,000 +In today's world, we're going to use things like AES, RSA, Sha 256, 384, shot two, shot three. + +87 +00:04:11,000 --> 00:04:14,000 +These are going to be algorithms that we use in today's world. + +88 +00:04:14,000 --> 00:04:15,000 +We're not going to use Caesar cipher. + +89 +00:04:15,000 --> 00:04:22,000 +Once again, the strength and security of an algorithms are determined by its ability to withstand cryptanalysis + +90 +00:04:22,000 --> 00:04:23,000 +attacks. + +91 +00:04:23,000 --> 00:04:30,000 +Now if you remember, cryptanalysis are basically, uh, the ability to study to defeat ciphers. + +92 +00:04:30,000 --> 00:04:38,000 +So remember, for now, the algorithm is the procedure used to encrypt and decrypt data. + +93 +00:04:38,000 --> 00:04:40,000 +Then what's the key? + +94 +00:04:40,000 --> 00:04:45,000 +Well, the cryptographic key are strings of bits used by the cryptographic algorithm. + +95 +00:04:45,000 --> 00:04:50,000 +So keep in mind they're used by the cryptographic algorithm to transform the data. + +96 +00:04:50,000 --> 00:04:54,000 +The key is what makes your encrypted data unique. + +97 +00:04:55,000 --> 00:04:58,000 +Now the key itself is basically a string. + +98 +00:04:58,000 --> 00:05:00,000 +In today's world, it's a string of data. + +99 +00:05:00,000 --> 00:05:02,000 +And I'm going to show you those keys coming up later. + +100 +00:05:02,000 --> 00:05:07,000 +The security of the encrypted data is directly tied to the length and randomness of the key. + +101 +00:05:07,000 --> 00:05:08,000 +You have to remember this. + +102 +00:05:08,000 --> 00:05:16,000 +The bigger the key and the more random the key is, the more secure your data is, the longer and more + +103 +00:05:16,000 --> 00:05:20,000 +random the key, the more combinations the potential attacker has to try. + +104 +00:05:20,000 --> 00:05:23,000 +Now I want to really break this down to you. + +105 +00:05:23,000 --> 00:05:23,000 +All right? + +106 +00:05:23,000 --> 00:05:27,000 +Because I'm going to give you the most amazing introduction you've ever had to cryptography. + +107 +00:05:28,000 --> 00:05:31,000 +Uh, so Caesar cipher, let's talk about this. + +108 +00:05:31,000 --> 00:05:33,000 +So Caesar cipher. + +109 +00:05:34,000 --> 00:05:38,000 +The rotation of the alphabet is the algorithm. + +110 +00:05:38,000 --> 00:05:41,000 +The key is the number of rotation. + +111 +00:05:42,000 --> 00:05:43,000 +Remember that. + +112 +00:05:44,000 --> 00:05:44,000 +Okay. + +113 +00:05:44,000 --> 00:05:52,000 +The actual procedure to encrypt the data and decrypt the data is to rotate the alphabet forward, to + +114 +00:05:52,000 --> 00:05:55,000 +encrypt and then to decrypt it is to rotate it backwards. + +115 +00:05:55,000 --> 00:05:57,000 +So that is the algorithm. + +116 +00:05:58,000 --> 00:06:02,000 +The secret was the actual key itself. + +117 +00:06:02,000 --> 00:06:08,000 +The key rotated by three places we had, or 12 or 13, or how many ever places you want. + +118 +00:06:09,000 --> 00:06:10,000 +That's the secret. + +119 +00:06:10,000 --> 00:06:15,000 +You see, in the world of cryptography, there is a principle that we follow. + +120 +00:06:16,000 --> 00:06:22,000 +That principle is going to be known as Kerckhoffs principle. + +121 +00:06:22,000 --> 00:06:26,000 +I'm not going to go into who this guy is, name right there and all that stuff. + +122 +00:06:26,000 --> 00:06:30,000 +But this is a principle that all cryptographic system follows. + +123 +00:06:30,000 --> 00:06:36,000 +And that principle states that a cryptographic system should be secure, even if everything about the + +124 +00:06:36,000 --> 00:06:37,000 +system. + +125 +00:06:38,000 --> 00:06:39,000 +Is public knowledge. + +126 +00:06:39,000 --> 00:06:40,000 +Except the key. + +127 +00:06:41,000 --> 00:06:41,000 +All right. + +128 +00:06:41,000 --> 00:06:49,000 +So even if everything about the system except the key is public knowledge, in today's world, we know + +129 +00:06:49,000 --> 00:06:56,000 +that all data, pretty much all data on this planet that's flying around the internet and our networks + +130 +00:06:56,000 --> 00:06:59,000 +is basically encrypted with the algorithm of AIS. + +131 +00:07:00,000 --> 00:07:06,000 +We know that if you're using SSA, if you're watching me using a TLS connection right now, maybe across + +132 +00:07:06,000 --> 00:07:12,000 +the internet on some web based platform or something, this data that's leaving that server to come + +133 +00:07:12,000 --> 00:07:15,000 +to your phone or your laptop, wherever you're watching me is encrypted. + +134 +00:07:15,000 --> 00:07:18,000 +I'm almost 100% sure by AIS. + +135 +00:07:18,000 --> 00:07:22,000 +I know the algorithm that's encrypting the data. + +136 +00:07:22,000 --> 00:07:24,000 +What's the secret is the key. + +137 +00:07:24,000 --> 00:07:28,000 +The key is the secret to the encryption process. + +138 +00:07:28,000 --> 00:07:31,000 +The key is what needs to be secret, and it has to be random. + +139 +00:07:31,000 --> 00:07:32,000 +And I'll explain more of that. + +140 +00:07:32,000 --> 00:07:34,000 +So if I go back. + +141 +00:07:35,000 --> 00:07:41,000 +Okay if I go back to Caesar cipher. + +142 +00:07:41,000 --> 00:07:44,000 +If you remember what Caesar cipher looked like, you know what it says. + +143 +00:07:44,000 --> 00:07:46,000 +Notice it says use key. + +144 +00:07:46,000 --> 00:07:53,000 +So in C's in the world of Caesar cipher, the strength of the Caesar cipher wasn't that it was rotating + +145 +00:07:53,000 --> 00:07:54,000 +the alphabet. + +146 +00:07:54,000 --> 00:07:55,000 +That's the algorithm. + +147 +00:07:55,000 --> 00:07:57,000 +The strength lied in the key. + +148 +00:07:57,000 --> 00:08:02,000 +Now, the problem with something like Caesar cipher is it's just not a lot of keys, man. + +149 +00:08:02,000 --> 00:08:04,000 +Let me show you guys what I mean. + +150 +00:08:05,000 --> 00:08:06,000 +You see right here. + +151 +00:08:06,000 --> 00:08:12,000 +We got not a lot of keys, because you can only rotate the alphabet by a certain number of places. + +152 +00:08:12,000 --> 00:08:16,000 +There are 25 usable keys in Caesar cipher. + +153 +00:08:16,000 --> 00:08:16,000 +Watch. + +154 +00:08:16,000 --> 00:08:20,000 +When you rotate it by one, this text becomes. + +155 +00:08:20,000 --> 00:08:22,000 +Looks like cipher text. + +156 +00:08:22,000 --> 00:08:27,000 +If I rotate it by 22 again, it still looks like cipher text. + +157 +00:08:27,000 --> 00:08:29,000 +Some people say, well, 26 rotations. + +158 +00:08:29,000 --> 00:08:30,000 +Not really. + +159 +00:08:30,000 --> 00:08:34,000 +You see, on rotation 26 A goes back to A. + +160 +00:08:34,000 --> 00:08:35,000 +So. + +161 +00:08:36,000 --> 00:08:43,000 +Notice the cipher text in the plain text is the same key 27 if there was a 27, we'll go back to one. + +162 +00:08:43,000 --> 00:08:44,000 +They'll just go right back there. + +163 +00:08:44,000 --> 00:08:50,000 +So technically speaking, there's only 25 combinations of possible keys. + +164 +00:08:51,000 --> 00:08:52,000 +Well, what does that mean? + +165 +00:08:52,000 --> 00:08:54,000 +So here's what that means. + +166 +00:08:54,000 --> 00:08:59,000 +That means that you don't have a lot of keys in order to encrypt your data. + +167 +00:08:59,000 --> 00:09:00,000 +Remember what I mentioned earlier? + +168 +00:09:00,000 --> 00:09:02,000 +The algorithm is always public knowledge. + +169 +00:09:02,000 --> 00:09:03,000 +It's the key. + +170 +00:09:03,000 --> 00:09:04,000 +That's the secret. + +171 +00:09:04,000 --> 00:09:06,000 +So let's say I give you a scenario. + +172 +00:09:06,000 --> 00:09:12,000 +Let's say you are communicating a secret message to your friend Bob in the same network. + +173 +00:09:12,000 --> 00:09:14,000 +I am going to know I'm a hacker. + +174 +00:09:14,000 --> 00:09:17,000 +I know that you guys are using Caesar cipher. + +175 +00:09:17,000 --> 00:09:21,000 +So you send the secret message to your friend Bob. + +176 +00:09:21,000 --> 00:09:22,000 +Encrypt it. + +177 +00:09:22,000 --> 00:09:24,000 +I was sniffing the network. + +178 +00:09:24,000 --> 00:09:27,000 +I sniffed the data, and I got your ciphertext. + +179 +00:09:27,000 --> 00:09:29,000 +Now, remember, ciphertext is all over the internet. + +180 +00:09:29,000 --> 00:09:34,000 +Anybody sniffing internet traffic or network traffic will be able to detect ciphertext. + +181 +00:09:34,000 --> 00:09:41,000 +So I grabbed the ciphertext and I look at it and I know, okay, you and Bob encrypted it with Caesar + +182 +00:09:41,000 --> 00:09:41,000 +cipher. + +183 +00:09:41,000 --> 00:09:46,000 +Well, there's only 25 really usable keys in Caesar cipher. + +184 +00:09:46,000 --> 00:09:48,000 +That means all I got to do is sit there and try it. + +185 +00:09:48,000 --> 00:09:50,000 +Okay, maybe he rotated it by one. + +186 +00:09:50,000 --> 00:09:54,000 +Maybe he rotated it by two, by three, by four by five. + +187 +00:09:54,000 --> 00:09:55,000 +Just like that. + +188 +00:09:55,000 --> 00:09:59,000 +I'll be able to detect it because 25 keys is not a lot to try. + +189 +00:10:00,000 --> 00:10:03,000 +That brings me to another point in the world of cryptography. + +190 +00:10:03,000 --> 00:10:09,000 +If your algorithm doesn't support a ton of keys and attackers can just sit there and try all the possible + +191 +00:10:09,000 --> 00:10:12,000 +combination of keys and decrypt your data, you're in big trouble. + +192 +00:10:12,000 --> 00:10:18,000 +In fact, the attacker trying all possible combinations in order to break the encryption or to decrypt + +193 +00:10:18,000 --> 00:10:21,000 +the data is an attack that's famously known as. + +194 +00:10:22,000 --> 00:10:22,000 +Did you see it? + +195 +00:10:22,000 --> 00:10:27,000 +Brute force attack so they can brute force attack you and try every combination out there. + +196 +00:10:27,000 --> 00:10:28,000 +Because there's just not many. + +197 +00:10:29,000 --> 00:10:35,000 +Now, before I move on, I want to just talk a little bit more about Caesar cipher. + +198 +00:10:35,000 --> 00:10:38,000 +Caesar cipher has a lot of terms that I'm going to be using later. + +199 +00:10:38,000 --> 00:10:42,000 +And why do I talk about Caesar cipher in my cryptography section, even though it's a billion years + +200 +00:10:42,000 --> 00:10:45,000 +old, is because it's easy to understand. + +201 +00:10:45,000 --> 00:10:51,000 +And the principles that it teaches us still applies to cryptographic algorithms of today. + +202 +00:10:51,000 --> 00:10:56,000 +Cryptographic algorithms today are really complex to understand way beyond the scope of this class. + +203 +00:10:56,000 --> 00:10:58,000 +So let's stick with this. + +204 +00:10:58,000 --> 00:11:00,000 +And I want to just go over some terms here with you. + +205 +00:11:00,000 --> 00:11:02,000 +So let's go back to Caesar cipher. + +206 +00:11:02,000 --> 00:11:04,000 +So Caesar cipher once again. + +207 +00:11:05,000 --> 00:11:07,000 +I want you guys just a couple of quick points. + +208 +00:11:07,000 --> 00:11:09,000 +Remember, if you know this key. + +209 +00:11:10,000 --> 00:11:14,000 +You can encrypt the data, but if you notice, you can also decrypt the data. + +210 +00:11:14,000 --> 00:11:16,000 +This is called symmetric encryption. + +211 +00:11:16,000 --> 00:11:17,000 +So this is symmetric cipher. + +212 +00:11:18,000 --> 00:11:20,000 +Caesar cipher is known as a rotational cipher. + +213 +00:11:20,000 --> 00:11:20,000 +Why? + +214 +00:11:20,000 --> 00:11:22,000 +Because it rotates the alphabet. + +215 +00:11:22,000 --> 00:11:26,000 +Caesar cipher is known as a substitution cipher. + +216 +00:11:26,000 --> 00:11:28,000 +Substitution is important. + +217 +00:11:28,000 --> 00:11:29,000 +Substitution means that it's. + +218 +00:11:29,000 --> 00:11:32,000 +It's substituting one character for another. + +219 +00:11:32,000 --> 00:11:32,000 +Look at this. + +220 +00:11:32,000 --> 00:11:33,000 +You see this? + +221 +00:11:33,000 --> 00:11:35,000 +I was substituted for h. + +222 +00:11:35,000 --> 00:11:37,000 +This f was substituted for e. + +223 +00:11:37,000 --> 00:11:41,000 +You see, if I rotate this by, let's say three places, I encrypt it. + +224 +00:11:42,000 --> 00:11:45,000 +Now this ai is substituted for l. + +225 +00:11:45,000 --> 00:11:47,000 +This a this. + +226 +00:11:47,000 --> 00:11:49,000 +This word here is substituted for d. + +227 +00:11:49,000 --> 00:11:51,000 +So what a what? + +228 +00:11:51,000 --> 00:11:54,000 +This is telling me that this is a type of a substitution cipher. + +229 +00:11:54,000 --> 00:11:59,000 +The other types of cipher that exist is called a transposition cipher. + +230 +00:11:59,000 --> 00:12:06,000 +Substitution cipher substitutes one character for the other versus transposition jumbles data up all + +231 +00:12:06,000 --> 00:12:07,000 +over the place. + +232 +00:12:07,000 --> 00:12:16,000 +For example, the word war w a r in transposition may become r a w or a w r, so transposition moves + +233 +00:12:16,000 --> 00:12:18,000 +data around substitution. + +234 +00:12:18,000 --> 00:12:21,000 +Fully substitute those characters for other characters. + +235 +00:12:21,000 --> 00:12:30,000 +In today's world, complex algorithms like AES, um, RSA, all these kinds of echos, Des, and whichever + +236 +00:12:30,000 --> 00:12:38,000 +more algorithms that exist and there is a lot they use multiple rounds of substitution and transposition. + +237 +00:12:38,000 --> 00:12:39,000 +So keep that in mind. + +238 +00:12:39,000 --> 00:12:41,000 +So what exactly would Caesar cipher. + +239 +00:12:41,000 --> 00:12:42,000 +Lots of terms. + +240 +00:12:42,000 --> 00:12:44,000 +Caesar cipher was a symmetric algorithm. + +241 +00:12:44,000 --> 00:12:44,000 +Why? + +242 +00:12:44,000 --> 00:12:49,000 +Because if you know the key, you can encrypt the data and you can decrypt the data. + +243 +00:12:49,000 --> 00:12:49,000 +So keep that in mind. + +244 +00:12:49,000 --> 00:12:50,000 +Symmetric encryption. + +245 +00:12:50,000 --> 00:12:53,000 +The same key uses to encrypt and decrypt the data. + +246 +00:12:53,000 --> 00:12:55,000 +It is a substitution cipher. + +247 +00:12:56,000 --> 00:12:59,000 +It's a rotational cipher because it rotates the alphabet. + +248 +00:13:00,000 --> 00:13:04,000 +Now Caesar cipher is not secure right. + +249 +00:13:04,000 --> 00:13:07,000 +Caesar cipher is definitely not a secure cipher. + +250 +00:13:07,000 --> 00:13:07,000 +Why? + +251 +00:13:07,000 --> 00:13:08,000 +Because it's easily cracked. + +252 +00:13:08,000 --> 00:13:12,000 +Now, I want to bring this discussion into today's world. + +253 +00:13:12,000 --> 00:13:16,000 +And that's going to be the world of modern day algorithms. + +254 +00:13:16,000 --> 00:13:20,000 +Now, Caesar cipher is also an alphabetical cipher. + +255 +00:13:20,000 --> 00:13:26,000 +Alphabetical ciphers are ciphers that utilizes the English alphabet like Caesar cipher using A, B, + +256 +00:13:26,000 --> 00:13:27,000 +C, D, E, F, g. + +257 +00:13:27,000 --> 00:13:34,000 +But keep in mind that in today's world, computers don't read alphabets. + +258 +00:13:34,000 --> 00:13:34,000 +They read. + +259 +00:13:34,000 --> 00:13:36,000 +What did you say? + +260 +00:13:36,000 --> 00:13:37,000 +Binary correct. + +261 +00:13:37,000 --> 00:13:39,000 +Computer reads ones and zeros. + +262 +00:13:39,000 --> 00:13:40,000 +They don't read ABC computers. + +263 +00:13:40,000 --> 00:13:41,000 +Doesn't even know what the hell is ABC? + +264 +00:13:41,000 --> 00:13:43,000 +We do not them. + +265 +00:13:43,000 --> 00:13:49,000 +So what that means is this okay, is that in today's world, everything's is ones and zeros. + +266 +00:13:49,000 --> 00:13:51,000 +Everything is ones and zeros. + +267 +00:13:51,000 --> 00:13:59,000 +So I want to really show you how today's world work in terms of crypto cryptography, keys and algorithms. + +268 +00:14:00,000 --> 00:14:01,000 +Let's go back here to my desktop. + +269 +00:14:01,000 --> 00:14:02,000 +And I'm going to use one note. + +270 +00:14:02,000 --> 00:14:08,000 +Now I want to show you guys some interesting concepts in my one note thing okay. + +271 +00:14:10,000 --> 00:14:12,000 +Watch carefully. + +272 +00:14:12,000 --> 00:14:17,000 +In today's world, we don't have Caesar cipher. + +273 +00:14:17,000 --> 00:14:19,000 +We have something like EOS. + +274 +00:14:21,000 --> 00:14:23,000 +128 bit. + +275 +00:14:24,000 --> 00:14:26,000 +Okay, so what exactly does that mean? + +276 +00:14:26,000 --> 00:14:28,000 +So if you ever see this, what does that mean? + +277 +00:14:28,000 --> 00:14:30,000 +Well this is the algorithm. + +278 +00:14:31,000 --> 00:14:34,000 +This is the key size. + +279 +00:14:35,000 --> 00:14:42,000 +The key size tells me the number of keys that is possible if I utilize 128 bit. + +280 +00:14:42,000 --> 00:14:44,000 +Now that number is way too big to understand. + +281 +00:14:44,000 --> 00:14:45,000 +I'll come back. + +282 +00:14:45,000 --> 00:14:47,000 +I'm going to come back to this in a minute. + +283 +00:14:47,000 --> 00:14:52,000 +For now, to make this more understandable, I'm going to create a fake algorithm. + +284 +00:14:52,000 --> 00:14:53,000 +Just to show. + +285 +00:14:53,000 --> 00:14:57,000 +Just to give you an illustration, let's say Andrew is very smart. + +286 +00:14:57,000 --> 00:15:02,000 +So I make my own algorithm, I'm going to call it the R algorithm doesn't actually exist. + +287 +00:15:02,000 --> 00:15:03,000 +That's two bits in size. + +288 +00:15:04,000 --> 00:15:08,000 +It's not 128 bits like S is. + +289 +00:15:08,000 --> 00:15:09,000 +It's two bits. + +290 +00:15:09,000 --> 00:15:09,000 +Okay. + +291 +00:15:09,000 --> 00:15:11,000 +Well what does that mean? + +292 +00:15:11,000 --> 00:15:13,000 +Well, once again this is my algorithm. + +293 +00:15:13,000 --> 00:15:16,000 +This is the procedure that's used to encrypt and decrypt the data. + +294 +00:15:16,000 --> 00:15:20,000 +But what it's actually what that procedure is using is a key. + +295 +00:15:21,000 --> 00:15:25,000 +This two bit is telling me the number of those keys that exist. + +296 +00:15:25,000 --> 00:15:26,000 +And what are those keys? + +297 +00:15:26,000 --> 00:15:29,000 +You see two bits gives me four keys. + +298 +00:15:29,000 --> 00:15:30,000 +How is that? + +299 +00:15:31,000 --> 00:15:35,000 +Well, you remember a bit is a binary. + +300 +00:15:35,000 --> 00:15:38,000 +Remember every time we say bit a bit is either a one or a zero. + +301 +00:15:39,000 --> 00:15:42,000 +If you have two bits, that means two digits. + +302 +00:15:43,000 --> 00:15:43,000 +Okay. + +303 +00:15:43,000 --> 00:15:44,000 +Two digits. + +304 +00:15:44,000 --> 00:15:46,000 +And they could be either 1 or 0 each of them. + +305 +00:15:46,000 --> 00:15:47,000 +Let me show you guys what I mean. + +306 +00:15:47,000 --> 00:15:50,000 +I'm literally if you use two bits I'm going to show you your four keys. + +307 +00:15:50,000 --> 00:15:52,000 +Two bits is zero zero. + +308 +00:15:53,000 --> 00:15:54,000 +Either it could be zero zero. + +309 +00:15:55,000 --> 00:15:58,000 +1101A10. + +310 +00:15:58,000 --> 00:16:01,000 +Those are all the combination of keys. + +311 +00:16:01,000 --> 00:16:08,000 +So if I'm using this algorithm of two bits you're going to say, hey Andrew you're crazy man. + +312 +00:16:08,000 --> 00:16:09,000 +Why would you use that? + +313 +00:16:09,000 --> 00:16:11,000 +That anybody can hack that. + +314 +00:16:11,000 --> 00:16:16,000 +Because if you're using if you're using that algorithm with two bits, the hackers just got to guess + +315 +00:16:16,000 --> 00:16:16,000 +four keys. + +316 +00:16:16,000 --> 00:16:18,000 +You're best off with Caesar cipher. + +317 +00:16:18,000 --> 00:16:20,000 +Caesar cipher had 25 keys. + +318 +00:16:20,000 --> 00:16:22,000 +This only has four. + +319 +00:16:22,000 --> 00:16:22,000 +Okay. + +320 +00:16:22,000 --> 00:16:24,000 +I'm going to increase it to three. + +321 +00:16:24,000 --> 00:16:27,000 +So let's see what happens when I put it up by three bits here. + +322 +00:16:27,000 --> 00:16:29,000 +So let me just erase this I'll say three bits. + +323 +00:16:29,000 --> 00:16:32,000 +So instead of it being two bits it'll be three bits. + +324 +00:16:32,000 --> 00:16:37,000 +Well with three bits do you have a lot more keys. + +325 +00:16:37,000 --> 00:16:39,000 +Well not really. + +326 +00:16:39,000 --> 00:16:40,000 +Let me show you guys something. + +327 +00:16:40,000 --> 00:16:45,000 +Three bits would be the keys would be zero zero, 0111. + +328 +00:16:45,000 --> 00:16:53,000 +And everything in between that such as 001011, um, 101 and so on and so on. + +329 +00:16:53,000 --> 00:16:57,000 +Any which way the we're not spending too long in this video, because I know this video is quite long + +330 +00:16:57,000 --> 00:16:57,000 +already. + +331 +00:16:57,000 --> 00:17:01,000 +You know what, three bits would give me eight combinations of keys. + +332 +00:17:01,000 --> 00:17:06,000 +If you just do the math here and you keep going down all of it, you'll get eight different keys. + +333 +00:17:06,000 --> 00:17:07,000 +How did I get eight? + +334 +00:17:07,000 --> 00:17:09,000 +Well, you do a simple math. + +335 +00:17:09,000 --> 00:17:16,000 +You do the two to the number of bits you have 2 to 3, two to the 3 or 2 to third power is eight. + +336 +00:17:16,000 --> 00:17:18,000 +So it's two times two times two. + +337 +00:17:18,000 --> 00:17:20,000 +Two times two is four times two is eight. + +338 +00:17:20,000 --> 00:17:22,000 +The question is why am I using a base two? + +339 +00:17:22,000 --> 00:17:25,000 +Because this is a bit and it's a binary. + +340 +00:17:25,000 --> 00:17:27,000 +So in binary the base is two. + +341 +00:17:27,000 --> 00:17:28,000 +It's either 1 or 0. + +342 +00:17:28,000 --> 00:17:32,000 +For example in decimal it's a base of ten right 0 to 9. + +343 +00:17:32,000 --> 00:17:34,000 +But in binary it's a base of two. + +344 +00:17:34,000 --> 00:17:37,000 +And you would put the number of bits you have. + +345 +00:17:37,000 --> 00:17:39,000 +So two to the three is eight. + +346 +00:17:39,000 --> 00:17:40,000 +So. + +347 +00:17:40,000 --> 00:17:42,000 +Eight keys. + +348 +00:17:42,000 --> 00:17:43,000 +Is that a lot? + +349 +00:17:43,000 --> 00:17:45,000 +No, not really. + +350 +00:17:45,000 --> 00:17:48,000 +But what if I said let's use four bits? + +351 +00:17:48,000 --> 00:17:51,000 +Well, if I do four bits, it'll be two to the four. + +352 +00:17:51,000 --> 00:17:52,000 +Be 16 keys. + +353 +00:17:52,000 --> 00:17:54,000 +Caesar cipher is still stronger. + +354 +00:17:55,000 --> 00:17:59,000 +But what if I say let's do five keys? + +355 +00:17:59,000 --> 00:18:01,000 +So if I do five bits, I'm not five keys. + +356 +00:18:01,000 --> 00:18:02,000 +I'm sorry. + +357 +00:18:02,000 --> 00:18:03,000 +Five bits. + +358 +00:18:03,000 --> 00:18:05,000 +Then two to the five would become what? + +359 +00:18:07,000 --> 00:18:10,000 +Two to the five would become 32. + +360 +00:18:11,000 --> 00:18:14,000 +Two to 5 to 32 is a big, big number. + +361 +00:18:14,000 --> 00:18:14,000 +All right. + +362 +00:18:15,000 --> 00:18:16,000 +To humans 32. + +363 +00:18:16,000 --> 00:18:17,000 +Big number right there. + +364 +00:18:17,000 --> 00:18:22,000 +I have to guess, but if you're using a computer to crack this, you can guess 32 keys in milliseconds. + +365 +00:18:23,000 --> 00:18:25,000 +Now this keeps on going. + +366 +00:18:25,000 --> 00:18:27,000 +This is stronger than a Caesar cipher. + +367 +00:18:27,000 --> 00:18:29,000 +But is it really strong for a computer? + +368 +00:18:29,000 --> 00:18:30,000 +No. + +369 +00:18:31,000 --> 00:18:35,000 +In today's world, we use two to the 128 or 2 to 156. + +370 +00:18:35,000 --> 00:18:36,000 +This isn't a math class. + +371 +00:18:36,000 --> 00:18:38,000 +And I told you I want to keep the math minimum. + +372 +00:18:39,000 --> 00:18:42,000 +But let me, you know, give you guys some numbers. + +373 +00:18:42,000 --> 00:18:45,000 +Uh, two to the 32 is 4 billion keys. + +374 +00:18:45,000 --> 00:18:51,000 +So if you were using a 32, you see, every time you go up by one exponent, the number of keys double. + +375 +00:18:51,000 --> 00:18:57,000 +For example, if there was two bits for keys, three bits, eight keys, that was the point of that. + +376 +00:18:58,000 --> 00:19:04,000 +Two to the four was 16, two to the five was 32, two to the six is 64. + +377 +00:19:04,000 --> 00:19:05,000 +You understand this. + +378 +00:19:05,000 --> 00:19:10,000 +Every time we add one bit the number of possible keys double. + +379 +00:19:11,000 --> 00:19:18,000 +Now, by the time you get to two to the 32, it's four point something billion, which is a lot. + +380 +00:19:18,000 --> 00:19:21,000 +But is it really a lot for a computer? + +381 +00:19:21,000 --> 00:19:27,000 +Computers have the ability normal desktop like minds have the ability to guess millions of keys per + +382 +00:19:27,000 --> 00:19:31,000 +second, so they would crack that in no time. + +383 +00:19:31,000 --> 00:19:38,000 +By the time you get to 128, it is not feasible for any computer on this planet, single machine, to + +384 +00:19:38,000 --> 00:19:41,000 +basically crack that the number is too big. + +385 +00:19:42,000 --> 00:19:43,000 +I forgot the number. + +386 +00:19:43,000 --> 00:19:46,000 +It's like it's a number with like 36 zeros. + +387 +00:19:46,000 --> 00:19:51,000 +It's the number is how many possible combination of keys. + +388 +00:19:51,000 --> 00:19:52,000 +Now remember. + +389 +00:19:53,000 --> 00:19:59,000 +The 128 bit doesn't is not the is not the total number of keys. + +390 +00:19:59,000 --> 00:20:00,000 +It's just the size of the key. + +391 +00:20:00,000 --> 00:20:04,000 +So when somebody says they're using a key that's 128 bit. + +392 +00:20:04,000 --> 00:20:07,000 +So when you take 128 bit AES key. + +393 +00:20:08,000 --> 00:20:11,000 +In the computer sees it as this. + +394 +00:20:11,000 --> 00:20:12,000 +The computer sees it as this. + +395 +00:20:14,000 --> 00:20:16,000 +128 ones. + +396 +00:20:16,000 --> 00:20:16,000 +Ones and zeros. + +397 +00:20:16,000 --> 00:20:18,000 +That's what the computer is seeing. + +398 +00:20:19,000 --> 00:20:24,000 +Now, in the world of cryptography, the key size matters, right? + +399 +00:20:24,000 --> 00:20:30,000 +Because if the key is very small, the key size is very small. + +400 +00:20:30,000 --> 00:20:34,000 +Hackers can guess every combination of key and they'll decrypt your data just like that. + +401 +00:20:34,000 --> 00:20:37,000 +Because remember the algorithm utilizes the key to encrypt the data. + +402 +00:20:37,000 --> 00:20:41,000 +Now the other concept to understand is randomness. + +403 +00:20:41,000 --> 00:20:46,000 +You see, randomness is really important in the world of cryptography. + +404 +00:20:46,000 --> 00:20:47,000 +Why? + +405 +00:20:48,000 --> 00:20:53,000 +Well, listen, man, I don't care how big your key is. + +406 +00:20:54,000 --> 00:20:55,000 +I don't care how big. + +407 +00:20:55,000 --> 00:20:55,000 +I don't care. + +408 +00:20:55,000 --> 00:20:58,000 +Your key could be a billion bits for all I care. + +409 +00:20:58,000 --> 00:21:06,000 +But if I can guess the key that you use, or I find a way to determine the key you use, I could just + +410 +00:21:06,000 --> 00:21:07,000 +decrypt your data. + +411 +00:21:07,000 --> 00:21:07,000 +Just like that. + +412 +00:21:08,000 --> 00:21:09,000 +Remember something? + +413 +00:21:09,000 --> 00:21:12,000 +The pool of keys lies in the total size of the key. + +414 +00:21:12,000 --> 00:21:15,000 +So if you're you were using two to the five, you're using five bits. + +415 +00:21:15,000 --> 00:21:18,000 +For example, there was a pool of 32 keys. + +416 +00:21:18,000 --> 00:21:23,000 +When you encrypted the data, you choose one of those 32 keys to encrypt your data with. + +417 +00:21:24,000 --> 00:21:30,000 +If you're using two to the 128 bit, there is two to the 128 number of keys out there. + +418 +00:21:30,000 --> 00:21:34,000 +You choose one of those keys to encrypt your data. + +419 +00:21:35,000 --> 00:21:37,000 +I now have to guess the key that you choose. + +420 +00:21:37,000 --> 00:21:43,000 +But what if I'm psychic and I'm able to read your mind and then determine how you got the key? + +421 +00:21:43,000 --> 00:21:45,000 +The key that you choose? + +422 +00:21:45,000 --> 00:21:46,000 +Well, that breaks the whole system. + +423 +00:21:46,000 --> 00:21:50,000 +So in order for the system to be secure, three things must be true. + +424 +00:21:50,000 --> 00:21:52,000 +Remember this for your exam. + +425 +00:21:52,000 --> 00:21:54,000 +Three things must be true. + +426 +00:21:54,000 --> 00:21:59,000 +Number one, the algorithm has to be able to withstand any kind of cryptoanalysis attack. + +427 +00:21:59,000 --> 00:22:02,000 +The procedure it's using to encrypt and decrypt the data. + +428 +00:22:03,000 --> 00:22:08,000 +Number two is that the key has to be moderately large. + +429 +00:22:08,000 --> 00:22:09,000 +The key has to be big. + +430 +00:22:09,000 --> 00:22:11,000 +You can't use a five bit key. + +431 +00:22:11,000 --> 00:22:15,000 +In fact, even 128 bit keys technically are not that secure. + +432 +00:22:16,000 --> 00:22:17,000 +And number three. + +433 +00:22:17,000 --> 00:22:23,000 +The key has to be random, because if the key that you're choosing to encrypt your data is not fully + +434 +00:22:23,000 --> 00:22:30,000 +random, and the attacker can guess the key, or have a method or a procedure to determine the key, + +435 +00:22:30,000 --> 00:22:31,000 +you're out of luck. + +436 +00:22:31,000 --> 00:22:36,000 +So remember these three things when you're selecting an algorithm or when you're designing algorithms. + +437 +00:22:36,000 --> 00:22:39,000 +Now in this course we're not designing algorithms. + +438 +00:22:39,000 --> 00:22:44,000 +And as 99% of IT security professionals will never do that, we'll just use AES or whichever is the + +439 +00:22:44,000 --> 00:22:45,000 +industry standard. + +440 +00:22:45,000 --> 00:22:47,000 +But these are important terms to understand. + +441 +00:22:48,000 --> 00:22:51,000 +When it comes to the world of cryptography. + diff --git a/07 - Cryptography/005 Ciphers OB 1.4_en.srt b/07 - Cryptography/005 Ciphers OB 1.4_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..f79df5e8655f14bdcd295583c03b2ea463741348 --- /dev/null +++ b/07 - Cryptography/005 Ciphers OB 1.4_en.srt @@ -0,0 +1,208 @@ +1 +00:00:00,000 --> 00:00:07,000 +Let's take a look at a few techniques that different ciphers can use to make themselves secure or process + +2 +00:00:07,000 --> 00:00:07,000 +data. + +3 +00:00:08,000 --> 00:00:15,000 +Now getting into this, ciphers are either going to be what's called a block cipher or a stream cipher. + +4 +00:00:15,000 --> 00:00:18,000 +And then they're either going to be doing transposition, substitution or both. + +5 +00:00:18,000 --> 00:00:19,000 +So let's take a look. + +6 +00:00:19,000 --> 00:00:24,000 +The first thing I want to mention is something called a block cipher like AES, which is a block cipher. + +7 +00:00:24,000 --> 00:00:29,000 +Now as we'll talk more about later, the Advanced Encryption Standard, we'll talk about this later. + +8 +00:00:29,000 --> 00:00:31,000 +But just remember it is a block cipher. + +9 +00:00:31,000 --> 00:00:36,000 +Block ciphers encrypts data block by block by block versus stream cipher. + +10 +00:00:36,000 --> 00:00:39,000 +They encrypt data one bit or byte at a time. + +11 +00:00:39,000 --> 00:00:41,000 +Now what is the difference? + +12 +00:00:41,000 --> 00:00:48,000 +Well, let's say you have data that's 1500 bits. + +13 +00:00:48,000 --> 00:00:50,000 +And that's the size of the data that you want to encrypt. + +14 +00:00:50,000 --> 00:01:00,000 +Well, a block cipher may break your 1500 bits into blocks of like 64 bit, 128 bit, uh, over and + +15 +00:01:00,000 --> 00:01:03,000 +over and then encrypt each block individually. + +16 +00:01:03,000 --> 00:01:08,000 +So it'll encrypt 64 bit, then it'll move to the next 64 bit, then move to the next 64 bit and so on + +17 +00:01:08,000 --> 00:01:08,000 +and so on. + +18 +00:01:08,000 --> 00:01:11,000 +So it's block by block by block encryption. + +19 +00:01:11,000 --> 00:01:15,000 +If it's a stream cipher, it's going to encrypt one bit at a time. + +20 +00:01:15,000 --> 00:01:21,000 +So if there's 1500 bits it's going to do this bit then that bit, then that bit is going to be like + +21 +00:01:21,000 --> 00:01:23,000 +1500 times. + +22 +00:01:23,000 --> 00:01:26,000 +It has to do this versus a stream a block cipher. + +23 +00:01:27,000 --> 00:01:30,000 +How many encryption process does it have to do? + +24 +00:01:30,000 --> 00:01:32,000 +Well, 1500 divided by 64. + +25 +00:01:32,000 --> 00:01:34,000 +If the blocks were 64 bit. + +26 +00:01:35,000 --> 00:01:37,000 +When would you want to use one over the other? + +27 +00:01:37,000 --> 00:01:41,000 +So block ciphers are suitable for processing large amounts of data. + +28 +00:01:41,000 --> 00:01:46,000 +Because remember, stream cipher is not good for large data because it has to do the process over and + +29 +00:01:46,000 --> 00:01:47,000 +over and over. + +30 +00:01:47,000 --> 00:01:52,000 +And in order to do a block cipher, the machine has to have adequate memory or resources. + +31 +00:01:52,000 --> 00:01:56,000 +Because remember it has to take the block of plaintext. + +32 +00:01:56,000 --> 00:01:57,000 +It then has to get the key. + +33 +00:01:57,000 --> 00:02:00,000 +It then has to get the block of ciphertext out. + +34 +00:02:00,000 --> 00:02:03,000 +All of that is stored in the Ram versus on a stream cipher. + +35 +00:02:03,000 --> 00:02:05,000 +It's just one bit at a time. + +36 +00:02:05,000 --> 00:02:08,000 +So it doesn't need a lot of resources to get this done. + +37 +00:02:08,000 --> 00:02:09,000 +I'm talking memory and CPU. + +38 +00:02:11,000 --> 00:02:16,000 +Another two terms here we want to be familiar with is going to be the concept of substitution and transposition. + +39 +00:02:16,000 --> 00:02:20,000 +Now, I did mention this when I talked about algorithm and keys. + +40 +00:02:20,000 --> 00:02:23,000 +So substitution cipher each letter is replaced by another letter. + +41 +00:02:23,000 --> 00:02:28,000 +Like Caesar cipher was a famous substitution cipher. + +42 +00:02:28,000 --> 00:02:30,000 +Another one is a transposition. + +43 +00:02:30,000 --> 00:02:33,000 +This is when letter are rearranged. + +44 +00:02:33,000 --> 00:02:36,000 +They're not changed, but they're just rearranged or altered. + +45 +00:02:37,000 --> 00:02:41,000 +In today's world, we're not going to use just substitution or transposition. + +46 +00:02:41,000 --> 00:02:47,000 +In fact, we're going to use multiple rounds of substitution and transposition in order to get our data + +47 +00:02:47,000 --> 00:02:48,000 +highly secure. + +48 +00:02:48,000 --> 00:02:55,000 +Now make sure you understand these particular terms here because as I get into algorithms like symmetric + +49 +00:02:55,000 --> 00:02:57,000 +asymmetric, you hear me say, oh, this is a transposition. + +50 +00:02:57,000 --> 00:02:59,000 +They're using multiple rounds of this. + +51 +00:02:59,000 --> 00:03:00,000 +It'll make more sense then. + +52 +00:03:00,000 --> 00:03:05,000 +But for now just make sure that you understand these terms and how these ciphers work. + diff --git a/07 - Cryptography/006 Symmetric Encryption OB 1.4_en.srt b/07 - Cryptography/006 Symmetric Encryption OB 1.4_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..e905db64f40c7f8b3f2fd7dbf198b2c3dbb4732a --- /dev/null +++ b/07 - Cryptography/006 Symmetric Encryption OB 1.4_en.srt @@ -0,0 +1,896 @@ +1 +00:00:00,000 --> 00:00:06,000 +The type of encryption that we use to encrypt most data with on the entire planet, and secures all + +2 +00:00:06,000 --> 00:00:11,000 +your data for everything that you've ever purchased on the internet, is symmetric algorithms or symmetric + +3 +00:00:11,000 --> 00:00:12,000 +encryption. + +4 +00:00:12,000 --> 00:00:17,000 +So in this video, let's take an in-depth dive into what exactly is symmetric encryption its pros and + +5 +00:00:17,000 --> 00:00:18,000 +its cons. + +6 +00:00:18,000 --> 00:00:19,000 +Let's get started. + +7 +00:00:20,000 --> 00:00:28,000 +But before I get into all of this text here on symmetric encryption, just think of the word symmetric. + +8 +00:00:28,000 --> 00:00:31,000 +What exactly is symmetric? + +9 +00:00:31,000 --> 00:00:33,000 +The word symmetric means same. + +10 +00:00:34,000 --> 00:00:38,000 +In other words, if something is taught to be symmetric, it's the same as something else. + +11 +00:00:38,000 --> 00:00:40,000 +Are my hands symmetric? + +12 +00:00:40,000 --> 00:00:43,000 +Yeah, they're basically symmetric in terms of length. + +13 +00:00:43,000 --> 00:00:44,000 +Are they symmetric in size? + +14 +00:00:44,000 --> 00:00:44,000 +No. + +15 +00:00:44,000 --> 00:00:48,000 +Actually I think the right arm is a little bit bigger than the left arm in terms of bicep size. + +16 +00:00:48,000 --> 00:00:50,000 +So that's not symmetric. + +17 +00:00:50,000 --> 00:00:52,000 +That's considered asymmetric. + +18 +00:00:52,000 --> 00:00:54,000 +So the word symmetric means the same. + +19 +00:00:54,000 --> 00:01:00,000 +Now when we come to cryptography the word symmetric basically means that we're going to be using the + +20 +00:01:00,000 --> 00:01:05,000 +same key that's used for encryption is the same key that's used for decryption. + +21 +00:01:05,000 --> 00:01:11,000 +Remember that the key to choosing to encrypt the data is the same key that we're going to use to decrypt + +22 +00:01:11,000 --> 00:01:12,000 +the data. + +23 +00:01:12,000 --> 00:01:15,000 +So that's the world of symmetric encryption. + +24 +00:01:15,000 --> 00:01:17,000 +One key used to encrypt and decrypt. + +25 +00:01:17,000 --> 00:01:21,000 +If you remember from an earlier video we looked at Caesar cipher. + +26 +00:01:21,000 --> 00:01:28,000 +And in Caesar cipher, that particular that particular cipher, the key rotating the alphabet by five, + +27 +00:01:28,000 --> 00:01:30,000 +six, seven places, whatever it was, that key can encrypt. + +28 +00:01:30,000 --> 00:01:35,000 +If, you know, the key was, let's say five, you know, to encrypt it, rotate it by five. + +29 +00:01:35,000 --> 00:01:38,000 +But if you knew that key, you can also decrypt it. + +30 +00:01:38,000 --> 00:01:39,000 +Just rotate it back by five. + +31 +00:01:40,000 --> 00:01:42,000 +So that is a symmetric cipher. + +32 +00:01:43,000 --> 00:01:47,000 +Now this thing has a variety of names. + +33 +00:01:47,000 --> 00:01:48,000 +And I'm going to give you the names. + +34 +00:01:48,000 --> 00:01:49,000 +But for now remember this. + +35 +00:01:49,000 --> 00:01:55,000 +This shared key is used to convert plaintext into cipher text and vice versa. + +36 +00:01:55,000 --> 00:01:58,000 +Now this thing comes in a variety of names. + +37 +00:01:58,000 --> 00:02:02,000 +If you ever taken an exam questions, or you're reading a book and you hear something called secret + +38 +00:02:02,000 --> 00:02:09,000 +key cryptography or private key cryptography, that's symmetric encryption. + +39 +00:02:09,000 --> 00:02:16,000 +So symmetric key cryptography, private key cryptography, secret key cryptography, they're all the + +40 +00:02:16,000 --> 00:02:17,000 +same thing. + +41 +00:02:18,000 --> 00:02:22,000 +Now there are some characteristics and pros and cons of using it. + +42 +00:02:23,000 --> 00:02:28,000 +One of its main characteristics is this concept of the key sharing. + +43 +00:02:28,000 --> 00:02:34,000 +Since it's the same key using in both encrypting and decrypting, you have to share the key. + +44 +00:02:34,000 --> 00:02:35,000 +This is where the problem comes, you see. + +45 +00:02:35,000 --> 00:02:36,000 +Think about it this way. + +46 +00:02:37,000 --> 00:02:43,000 +If I encrypt data right, let's say I got data in front of me and I encrypt it with a key. + +47 +00:02:43,000 --> 00:02:46,000 +And then I give you the ciphertext. + +48 +00:02:46,000 --> 00:02:50,000 +You cannot decrypt that ciphertext without the key. + +49 +00:02:50,000 --> 00:02:52,000 +The question is how do I get you that key? + +50 +00:02:52,000 --> 00:02:59,000 +That's the problem with symmetric encryption is transferring that key because it is a shared key. + +51 +00:02:59,000 --> 00:03:02,000 +The same key used to encrypt is the same key used to decrypt. + +52 +00:03:02,000 --> 00:03:05,000 +The key has to be shared between all parties. + +53 +00:03:05,000 --> 00:03:12,000 +There has to be a way to securely distribute that key in the medium that you're using to transport your + +54 +00:03:12,000 --> 00:03:13,000 +data. + +55 +00:03:14,000 --> 00:03:19,000 +So it has to be somewhere securely distributed in the key, which is something I will cover later on + +56 +00:03:19,000 --> 00:03:20,000 +in this course. + +57 +00:03:21,000 --> 00:03:22,000 +Now the great thing. + +58 +00:03:22,000 --> 00:03:26,000 +So one of its key characteristics here is that it's you have to share the key. + +59 +00:03:26,000 --> 00:03:33,000 +Another good characteristics of this is that it is incredibly fast and efficient. + +60 +00:03:33,000 --> 00:03:39,000 +So its speed and efficiency symmetric key algorithms are generally faster and more efficient than asymmetric, + +61 +00:03:40,000 --> 00:03:43,000 +making them suitable for encrypting large bulks of data. + +62 +00:03:44,000 --> 00:03:48,000 +They have a simpler mathematical operation, and actually the keys are generally smaller. + +63 +00:03:48,000 --> 00:03:51,000 +So remember this a couple of things. + +64 +00:03:51,000 --> 00:03:52,000 +Two, two things we got here. + +65 +00:03:52,000 --> 00:03:55,000 +Number one is that you have to be able to share that key. + +66 +00:03:55,000 --> 00:03:58,000 +It's a shared key type of cryptography. + +67 +00:03:58,000 --> 00:04:02,000 +And one of its greatest things is its speed and efficiency. + +68 +00:04:02,000 --> 00:04:04,000 +It's very very quick. + +69 +00:04:04,000 --> 00:04:05,000 +Now. + +70 +00:04:06,000 --> 00:04:07,000 +Where do we use it? + +71 +00:04:07,000 --> 00:04:14,000 +Well, symmetric key is used in many, many, many, many applications that we use. + +72 +00:04:14,000 --> 00:04:22,000 +In fact all data that's being encrypted today I'm talking private data utilizes symmetric keys such + +73 +00:04:22,000 --> 00:04:23,000 +as AES encryption. + +74 +00:04:23,000 --> 00:04:26,000 +We'll do another video where I'll go over the different kinds of symmetric algorithms. + +75 +00:04:26,000 --> 00:04:28,000 +But a yes is the most famous one. + +76 +00:04:28,000 --> 00:04:33,000 +Whether you're doing things such as a VPN, wireless networking. + +77 +00:04:35,000 --> 00:04:40,000 +SSL transfer data, Https and all the whole realm of, you know, let me stop right? + +78 +00:04:40,000 --> 00:04:44,000 +Every time I say SSL TLS for your exam, it's basically the same thing, right? + +79 +00:04:44,000 --> 00:04:45,000 +TLS is the upgrade to SSL. + +80 +00:04:45,000 --> 00:04:47,000 +SSL technically doesn't exist. + +81 +00:04:47,000 --> 00:04:52,000 +So whether you're doing things like Https or doing some kind of VPN, you're on some kind of wireless + +82 +00:04:52,000 --> 00:04:52,000 +network. + +83 +00:04:52,000 --> 00:04:55,000 +It's all encrypted using symmetric algorithms. + +84 +00:04:56,000 --> 00:05:00,000 +But remember something I told you guys that. + +85 +00:05:01,000 --> 00:05:03,000 +This concept of sharing the key. + +86 +00:05:03,000 --> 00:05:07,000 +Sharing the key is the biggest problem with symmetric encryption. + +87 +00:05:08,000 --> 00:05:10,000 +The key, the biggest challenge here. + +88 +00:05:10,000 --> 00:05:12,000 +And it's a major challenge. + +89 +00:05:12,000 --> 00:05:14,000 +Is key management. + +90 +00:05:14,000 --> 00:05:19,000 +Since the same key is used for encryption and decryption, it must be shared securely. + +91 +00:05:19,000 --> 00:05:21,000 +Now I'm going to give you guys a scenario. + +92 +00:05:22,000 --> 00:05:28,000 +Let's say I'm standing here and to the back of the room where the camera guy is actually watching me. + +93 +00:05:29,000 --> 00:05:37,000 +Me and the camera guy, Rick, let's say, or Bob standing there, let's say I have to get him data. + +94 +00:05:37,000 --> 00:05:38,000 +Okay. + +95 +00:05:38,000 --> 00:05:42,000 +I'm going I'm going to encrypt my data, and I'm going to give him the cipher text. + +96 +00:05:42,000 --> 00:05:44,000 +But how do I get him the key? + +97 +00:05:44,000 --> 00:05:46,000 +That's its biggest problem. + +98 +00:05:46,000 --> 00:05:50,000 +Technically speaking, there's no real way of doing this. + +99 +00:05:50,000 --> 00:05:51,000 +I know it sounds crazy. + +100 +00:05:51,000 --> 00:05:57,000 +There is a there is a way of doing it in the world of cryptography, but it's not with symmetric. + +101 +00:05:57,000 --> 00:06:02,000 +In fact, it uses asymmetric to pass symmetric keys called hybrid cryptography cover that later. + +102 +00:06:02,000 --> 00:06:08,000 +But in the world of pure asymmetric encryption, there is no way of doing this. + +103 +00:06:08,000 --> 00:06:13,000 +You can think of all the different ways and you're going to come up with, okay, if I'm using pure + +104 +00:06:13,000 --> 00:06:15,000 +symmetric, how do I get this person? + +105 +00:06:15,000 --> 00:06:16,000 +There really is no way. + +106 +00:06:17,000 --> 00:06:22,000 +Back in the days, we could have used something called an out of band method. + +107 +00:06:22,000 --> 00:06:27,000 +Out of band methods is you send the data one way and you send the key another way. + +108 +00:06:28,000 --> 00:06:35,000 +So you would send the key using this path, and then you would send the data using another path. + +109 +00:06:35,000 --> 00:06:39,000 +So that way it would take two interceptions to get the key in the data. + +110 +00:06:40,000 --> 00:06:47,000 +For example, if I'm I'm going to encrypt data using Caesar cipher like you saw, and I'm going to email + +111 +00:06:47,000 --> 00:06:52,000 +you the cipher text, and then I'm going to call you on the phone and tell you the key. + +112 +00:06:52,000 --> 00:06:53,000 +You get the point. + +113 +00:06:53,000 --> 00:07:00,000 +So in other words, one band was email, the other band the out of band was the was the phone call. + +114 +00:07:00,000 --> 00:07:01,000 +So that's one way of doing it. + +115 +00:07:01,000 --> 00:07:07,000 +But in the world of pure cryptography, for example, when you go to Amazon and you buy something, + +116 +00:07:07,000 --> 00:07:10,000 +they don't call you and give you a key or have some kind of pre-made setup. + +117 +00:07:10,000 --> 00:07:12,000 +So there is a way of doing this. + +118 +00:07:12,000 --> 00:07:14,000 +It's just not done with symmetric. + +119 +00:07:15,000 --> 00:07:18,000 +Another thing is the strength of the symmetric key typically depends on the key. + +120 +00:07:18,000 --> 00:07:20,000 +And this is something we talked about earlier. + +121 +00:07:20,000 --> 00:07:24,000 +The longer the keys the harder they are to crack due to the bigger combinations. + +122 +00:07:24,000 --> 00:07:30,000 +So remember I told you guys 128 is generally considered secure in today's world, although we should + +123 +00:07:30,000 --> 00:07:34,000 +be using 256 bit encryption now. + +124 +00:07:35,000 --> 00:07:40,000 +Symmetric key is not just a problem of the key distribution. + +125 +00:07:40,000 --> 00:07:40,000 +Okay. + +126 +00:07:40,000 --> 00:07:42,000 +That's what we're talking about here. + +127 +00:07:42,000 --> 00:07:44,000 +Distributing the key is the main problem. + +128 +00:07:44,000 --> 00:07:47,000 +The other problem it has is scalability. + +129 +00:07:47,000 --> 00:07:51,000 +In a large network the number of required keys can grow. + +130 +00:07:51,000 --> 00:07:56,000 +There's a formula I need you to know for your exam n times n minus one divided by two. + +131 +00:07:56,000 --> 00:07:59,000 +Let me give you guys some examples here. + +132 +00:07:59,000 --> 00:08:04,000 +So what happens if I have a network that has a few users. + +133 +00:08:04,000 --> 00:08:08,000 +Let's say we have Bob, Mary and Peter. + +134 +00:08:08,000 --> 00:08:11,000 +These are three users on my network. + +135 +00:08:11,000 --> 00:08:15,000 +Now they want to communicate with each other securely. + +136 +00:08:15,000 --> 00:08:19,000 +So let's say you have a symmetric key between Bob and Mary. + +137 +00:08:19,000 --> 00:08:23,000 +This is one key that Bob can communicate with Mary securely. + +138 +00:08:23,000 --> 00:08:26,000 +That way Peter can't read it because he doesn't have that key. + +139 +00:08:26,000 --> 00:08:27,000 +So this is one key. + +140 +00:08:27,000 --> 00:08:29,000 +Then Bob needs one with Peter. + +141 +00:08:29,000 --> 00:08:30,000 +That's two. + +142 +00:08:30,000 --> 00:08:33,000 +Then Peter needs a key with Mary, that's three. + +143 +00:08:33,000 --> 00:08:41,000 +So for these three people to communicate securely you need to have three keys. + +144 +00:08:41,000 --> 00:08:42,000 +Easy enough right. + +145 +00:08:43,000 --> 00:08:50,000 +But what happens when Christine comes along and she wants to communicate with everybody securely? + +146 +00:08:50,000 --> 00:08:52,000 +Well, now Christine needs a key with Mary. + +147 +00:08:52,000 --> 00:08:55,000 +That's key, for she needs a key with Peter. + +148 +00:08:55,000 --> 00:08:56,000 +Key five. + +149 +00:08:56,000 --> 00:09:00,000 +And she needs a key to with that one does not look like a nice line. + +150 +00:09:00,000 --> 00:09:02,000 +She needs a key with Bob. + +151 +00:09:02,000 --> 00:09:03,000 +That's six keys. + +152 +00:09:04,000 --> 00:09:06,000 +So there's a formula. + +153 +00:09:06,000 --> 00:09:11,000 +So if you ever have to do this, you may get a question on your exam that actually calculate this number. + +154 +00:09:12,000 --> 00:09:15,000 +It's n times n minus one. + +155 +00:09:16,000 --> 00:09:17,000 +Divide by two. + +156 +00:09:17,000 --> 00:09:19,000 +So n would be the number of users. + +157 +00:09:19,000 --> 00:09:25,000 +So you got four users four minus one is three, three times four is 12 divided by two is six. + +158 +00:09:25,000 --> 00:09:29,000 +If there was three users there would be uh three keys. + +159 +00:09:29,000 --> 00:09:29,000 +It would be three. + +160 +00:09:29,000 --> 00:09:32,000 +Minus one is two, two times three six divided by two is three. + +161 +00:09:32,000 --> 00:09:38,000 +So if we increase and this is the problem with symmetric encryption one of its problem if you add the + +162 +00:09:38,000 --> 00:09:41,000 +more users you add you got to keep adding keys. + +163 +00:09:41,000 --> 00:09:47,000 +For example, what if Mary's friend Jacqueline comes along. + +164 +00:09:47,000 --> 00:09:54,000 +So now Jacqueline, she got to get a key with Bob, with Mary, with Peter and with Christine. + +165 +00:09:55,000 --> 00:09:56,000 +You guys get the point. + +166 +00:09:56,000 --> 00:10:00,000 +This is going to get real complex really, really fast. + +167 +00:10:01,000 --> 00:10:10,000 +So this is one of its major problems is that its enlarged networks, this thing becomes very, very + +168 +00:10:10,000 --> 00:10:12,000 +difficult to manage the number of keys. + +169 +00:10:12,000 --> 00:10:15,000 +And don't forget the formula for your exam. + +170 +00:10:15,000 --> 00:10:20,000 +Now this grows and it could be starting to grow exponentially in large networks. + +171 +00:10:20,000 --> 00:10:22,000 +It becomes basically unmanageable. + +172 +00:10:23,000 --> 00:10:29,000 +So now keep in mind that two major problems already. + +173 +00:10:29,000 --> 00:10:34,000 +Number one is that it's you have to the key distribution, find a way to share the key. + +174 +00:10:34,000 --> 00:10:37,000 +And then of course the managing the number of keys. + +175 +00:10:37,000 --> 00:10:38,000 +So the number of keys grows really big. + +176 +00:10:39,000 --> 00:10:41,000 +It does have a couple more problems. + +177 +00:10:41,000 --> 00:10:45,000 +Key storage and protection keys must be stored securely. + +178 +00:10:45,000 --> 00:10:48,000 +Remember the key is used to encrypt and decrypt the data. + +179 +00:10:48,000 --> 00:10:53,000 +So we have to find a way to ensure that the D is not the key, is never stolen or exposed to any kind + +180 +00:10:53,000 --> 00:10:54,000 +of attacker. + +181 +00:10:55,000 --> 00:10:59,000 +And the final problem I want to mention is that it lacks non-repudiation. + +182 +00:11:00,000 --> 00:11:04,000 +You see, because the key is shared with everyone. + +183 +00:11:04,000 --> 00:11:08,000 +Uh, you know, everyone that I want to communicate with has to know that key. + +184 +00:11:08,000 --> 00:11:09,000 +So if I encrypt data. + +185 +00:11:10,000 --> 00:11:14,000 +For me to give it to you to decrypt, I also have to give you the key. + +186 +00:11:14,000 --> 00:11:18,000 +That means that there's nothing specific to me. + +187 +00:11:18,000 --> 00:11:20,000 +There's nothing secret to me. + +188 +00:11:20,000 --> 00:11:23,000 +Like, for example, what's the password to my phone? + +189 +00:11:23,000 --> 00:11:25,000 +Well, the only person that knows that is me. + +190 +00:11:25,000 --> 00:11:29,000 +So that's a way to authenticate me to the system, right? + +191 +00:11:30,000 --> 00:11:31,000 +Non-repudiation. + +192 +00:11:32,000 --> 00:11:36,000 +It doesn't provide that, since it's the same key that can be used in all parties. + +193 +00:11:36,000 --> 00:11:39,000 +For example, what if I need to share this? + +194 +00:11:39,000 --> 00:11:41,000 +Secured this data with ten users? + +195 +00:11:41,000 --> 00:11:41,000 +I'm going to encrypt it. + +196 +00:11:41,000 --> 00:11:44,000 +Then all ten of us, ten of them have to have the key. + +197 +00:11:45,000 --> 00:11:47,000 +So the key is not specific to a user. + +198 +00:11:47,000 --> 00:11:51,000 +This is solved in the world of asymmetric where there is something called a private key. + +199 +00:11:51,000 --> 00:11:52,000 +This doesn't have that. + +200 +00:11:52,000 --> 00:11:54,000 +This key is a shared key. + +201 +00:11:54,000 --> 00:11:56,000 +So there's nothing of non-repudiation. + +202 +00:11:57,000 --> 00:12:00,000 +Now we're going to come to this in a minute. + +203 +00:12:00,000 --> 00:12:02,000 +That's going to be all the different algorithms. + +204 +00:12:02,000 --> 00:12:08,000 +But for now, let's do a quick summary of what we have learned so far in the world of symmetric encryption. + +205 +00:12:08,000 --> 00:12:11,000 +The key to choosing to encrypt is the same key used to decrypt. + +206 +00:12:12,000 --> 00:12:14,000 +That's what makes it symmetric. + +207 +00:12:14,000 --> 00:12:19,000 +Another thing to remember about this the good thing number one it's really fast. + +208 +00:12:19,000 --> 00:12:22,000 +It's really fast and it's really efficient. + +209 +00:12:23,000 --> 00:12:25,000 +The other thing is that it's relatively secure. + +210 +00:12:25,000 --> 00:12:26,000 +All right. + +211 +00:12:26,000 --> 00:12:32,000 +So even though the key sizes have to be big, it's still considered fast and secure. + +212 +00:12:32,000 --> 00:12:35,000 +So it's fast and it's -- secure now. + +213 +00:12:36,000 --> 00:12:37,000 +What's bad about it? + +214 +00:12:37,000 --> 00:12:40,000 +Well, how do you distribute the key? + +215 +00:12:40,000 --> 00:12:45,000 +Remember I said there really isn't a way by itself, managing the keys become a problem. + +216 +00:12:45,000 --> 00:12:49,000 +The more users, the exponentially you're going to be getting more keys to manage. + +217 +00:12:50,000 --> 00:12:55,000 +And of course, there's no non-repudiation, there's nothing specific to users. + +218 +00:12:56,000 --> 00:12:59,000 +So your problem is saying itself, well, why do we still use it if it has so many problems? + +219 +00:12:59,000 --> 00:13:01,000 +Because it's secure and it's fast. + +220 +00:13:01,000 --> 00:13:03,000 +That's why we use it. + +221 +00:13:03,000 --> 00:13:08,000 +And we have developed other ways to counteract its problem. + +222 +00:13:08,000 --> 00:13:10,000 +We'll talk about that on hybrid cryptography. + +223 +00:13:10,000 --> 00:13:15,000 +But before we get into that, there are a variety of different algorithms you want to know in the next + +224 +00:13:15,000 --> 00:13:15,000 +video. + diff --git a/07 - Cryptography/007 Symmetric Algorithms OB 1.4_en.srt b/07 - Cryptography/007 Symmetric Algorithms OB 1.4_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..1f1810ab73a4c49de03b8c2544c467434f50d4e4 --- /dev/null +++ b/07 - Cryptography/007 Symmetric Algorithms OB 1.4_en.srt @@ -0,0 +1,648 @@ +1 +00:00:00,000 --> 00:00:00,000 +Okay. + +2 +00:00:00,000 --> 00:00:06,000 +Now that we understand the specifics of symmetric encryption, let's take a look at some pretty famous + +3 +00:00:06,000 --> 00:00:08,000 +algorithms that exist for it. + +4 +00:00:08,000 --> 00:00:11,000 +Now, I don't want you guys to take a bunch of notes as I go through this. + +5 +00:00:11,000 --> 00:00:16,000 +I have a table at the end that summarizes all of it for us, so let's knock it out. + +6 +00:00:17,000 --> 00:00:17,000 +All right. + +7 +00:00:17,000 --> 00:00:26,000 +So one of the very first symmetric algorithm that was utilized to encrypt data basically across the + +8 +00:00:26,000 --> 00:00:28,000 +world was this one. + +9 +00:00:28,000 --> 00:00:32,000 +This one here is the Data Encryption standard. + +10 +00:00:32,000 --> 00:00:34,000 +It was based on an algorithm called the Lucifer algorithm. + +11 +00:00:34,000 --> 00:00:38,000 +And it came out in the late 1970s. + +12 +00:00:38,000 --> 00:00:44,000 +Now the data Encryption standard, let me just say right off the bat, has been cracked and should never + +13 +00:00:44,000 --> 00:00:49,000 +be used, although some legacy systems may still use Des. + +14 +00:00:49,000 --> 00:00:57,000 +Now, the reason why Des is considered not secure is because it has a very small key size relative to + +15 +00:00:57,000 --> 00:00:58,000 +today's computing. + +16 +00:00:58,000 --> 00:01:03,000 +You see, when this algorithm came out in the late 1970s. + +17 +00:01:03,000 --> 00:01:06,000 +Its key size of 56 bits. + +18 +00:01:06,000 --> 00:01:12,000 +Now its known to be a 64 bit algorithm, but eight of those bits were used for parity. + +19 +00:01:12,000 --> 00:01:15,000 +In other words, they weren't really used as part of the encryption. + +20 +00:01:15,000 --> 00:01:18,000 +So it's effectively a 56 bit algorithm. + +21 +00:01:18,000 --> 00:01:26,000 +Now here's the thing with that, because it was effectively 56 bit, uh, in length back in the 1970s + +22 +00:01:26,000 --> 00:01:30,000 +when computers were really, really slow compared to today. + +23 +00:01:30,000 --> 00:01:32,000 +No one could have cracked this. + +24 +00:01:32,000 --> 00:01:35,000 +No modern machine at that time was able to crack this. + +25 +00:01:35,000 --> 00:01:38,000 +So it was considered uncrackable for its time. + +26 +00:01:38,000 --> 00:01:43,000 +But by the late 1990s, it was cracked with a machine that was called the des cracker. + +27 +00:01:43,000 --> 00:01:48,000 +This machine would crack des, I think, at like 56 or 48 hours, something like that. + +28 +00:01:48,000 --> 00:01:53,000 +You can actually go to Google and type des cracking des or des cracker. + +29 +00:01:53,000 --> 00:01:54,000 +There's a whole history on it. + +30 +00:01:54,000 --> 00:02:00,000 +So when that happened, the United States government says, oh no, we have a problem. + +31 +00:02:00,000 --> 00:02:03,000 +And they would hold a competition to replace. + +32 +00:02:04,000 --> 00:02:08,000 +Des with a new one, which would eventually become a yes. + +33 +00:02:08,000 --> 00:02:12,000 +So des was replaced with basically a yes for all data encryption. + +34 +00:02:12,000 --> 00:02:18,000 +There was a competition held, and multiple algorithms would be, uh, selected as finalists, and eventually + +35 +00:02:18,000 --> 00:02:22,000 +one of them would win the competition to become a yes. + +36 +00:02:22,000 --> 00:02:29,000 +Now, a couple of things is that Des uses long series of exclusive XOR operations to generate ciphertext, + +37 +00:02:29,000 --> 00:02:32,000 +and that just makes it as complex as possible. + +38 +00:02:32,000 --> 00:02:34,000 +It has 16. + +39 +00:02:34,000 --> 00:02:37,000 +It does the 16 times 16 operations. + +40 +00:02:37,000 --> 00:02:42,000 +Now, when Des was cracked, the United States government was like, oh boy, we got we got a big problem. + +41 +00:02:42,000 --> 00:02:46,000 +What can we do to extend the life of this? + +42 +00:02:46,000 --> 00:02:50,000 +So the government came up with this thing that's called triple des. + +43 +00:02:50,000 --> 00:02:55,000 +So it's basically des that they ran three times. + +44 +00:02:55,000 --> 00:02:56,000 +So let me show you something. + +45 +00:02:56,000 --> 00:02:56,000 +What. + +46 +00:02:56,000 --> 00:02:57,000 +Look at this. + +47 +00:02:57,000 --> 00:02:58,000 +Look at this part here. + +48 +00:02:58,000 --> 00:02:59,000 +They would take plain text. + +49 +00:03:00,000 --> 00:03:06,000 +They were encrypted with a Des key, generate another Des key, encrypt it again, then generate another + +50 +00:03:06,000 --> 00:03:09,000 +Des key, encrypt it again, and then you would get the ciphertext. + +51 +00:03:09,000 --> 00:03:12,000 +So it would be encrypt encrypt encrypt with three different keys. + +52 +00:03:12,000 --> 00:03:14,000 +Now there's four different ways this thing can work. + +53 +00:03:14,000 --> 00:03:15,000 +I'm not going to go into all of them. + +54 +00:03:15,000 --> 00:03:18,000 +You don't need to know it for your exam. + +55 +00:03:18,000 --> 00:03:21,000 +But some of them would be encrypt, decrypt, encrypt and so on. + +56 +00:03:21,000 --> 00:03:24,000 +But just keep in mind that it worked in a variety of different ways. + +57 +00:03:24,000 --> 00:03:27,000 +And what this did was this extended it. + +58 +00:03:27,000 --> 00:03:32,000 +Now it's known to be 168 bits, but. + +59 +00:03:32,000 --> 00:03:36,000 +Technically it's not really 168 bit. + +60 +00:03:36,000 --> 00:03:37,000 +It's not a full 168 bit key. + +61 +00:03:38,000 --> 00:03:40,000 +It's not a 168 ones and zeros. + +62 +00:03:40,000 --> 00:03:43,000 +It was actually three different 56 bit keys doing it. + +63 +00:03:43,000 --> 00:03:48,000 +So technically it wasn't effectively strengthened as 168 bit. + +64 +00:03:48,000 --> 00:03:51,000 +Its effective strength was 111 bit. + +65 +00:03:51,000 --> 00:03:54,000 +This thing is not very secure anymore. + +66 +00:03:54,000 --> 00:03:57,000 +It's approaching the end of life and you shouldn't really be using this. + +67 +00:03:57,000 --> 00:04:03,000 +Although I've seen this use in certain kinds of VPN softwares and options and certain IPsec implementations. + +68 +00:04:03,000 --> 00:04:07,000 +For example, I've seen this, but you shouldn't be using it, all right? + +69 +00:04:07,000 --> 00:04:10,000 +Because you should be using AES in today's world. + +70 +00:04:12,000 --> 00:04:22,000 +Now there was a competition that was held, uh, to replace des, and that competition brought a variety + +71 +00:04:22,000 --> 00:04:23,000 +of different algorithms. + +72 +00:04:23,000 --> 00:04:23,000 +All right. + +73 +00:04:23,000 --> 00:04:28,000 +Let me go through a variety of different symmetric algorithms that are not very famous, although one + +74 +00:04:28,000 --> 00:04:32,000 +of them is pretty famous, uh, until EAS would come up. + +75 +00:04:32,000 --> 00:04:34,000 +But there's lots of different algorithms out there now. + +76 +00:04:34,000 --> 00:04:36,000 +You don't need to be specific on them. + +77 +00:04:36,000 --> 00:04:43,000 +I know I give a lot of data on them, but just know for your exam that these are symmetric algorithms. + +78 +00:04:43,000 --> 00:04:47,000 +Your exam is really not going to say, is this 128 or how many rounds of encryption, although I put + +79 +00:04:47,000 --> 00:04:47,000 +it there. + +80 +00:04:48,000 --> 00:04:50,000 +So another one was called idea. + +81 +00:04:50,000 --> 00:04:53,000 +This one was developed to replace deaths. + +82 +00:04:53,000 --> 00:04:54,000 +But remember this wasn't the winner. + +83 +00:04:54,000 --> 00:05:00,000 +The winner of the competition would be called the Rijndael algorithm that would replace Des to become + +84 +00:05:00,000 --> 00:05:00,000 +a. + +85 +00:05:00,000 --> 00:05:00,000 +Yes. + +86 +00:05:00,000 --> 00:05:02,000 +This was one of them. + +87 +00:05:02,000 --> 00:05:04,000 +There was another one called Blowfish. + +88 +00:05:04,000 --> 00:05:04,000 +All right. + +89 +00:05:04,000 --> 00:05:07,000 +This one produced a large key sizes much bigger. + +90 +00:05:07,000 --> 00:05:12,000 +This one went up to 448 bit skipjack was a unique thing. + +91 +00:05:12,000 --> 00:05:18,000 +Skipjack used it a concept of key escrow, which we'll cover in another video now. + +92 +00:05:18,000 --> 00:05:21,000 +There are some arcs that are out there. + +93 +00:05:21,000 --> 00:05:23,000 +So arc four, five and six. + +94 +00:05:23,000 --> 00:05:27,000 +These algorithms here are pretty unique and you should understand them. + +95 +00:05:27,000 --> 00:05:28,000 +Why? + +96 +00:05:28,000 --> 00:05:31,000 +Because RC four was a very famous algorithm. + +97 +00:05:31,000 --> 00:05:32,000 +It was basically a stream. + +98 +00:05:32,000 --> 00:05:33,000 +It wasn't a block. + +99 +00:05:33,000 --> 00:05:35,000 +It was a very, very pretty much a stream cipher. + +100 +00:05:35,000 --> 00:05:39,000 +And it was used in very famous WEP. + +101 +00:05:39,000 --> 00:05:49,000 +If you guys remember WEP, the wired equivalency, uh, privacy, I think that was I forgot I covered + +102 +00:05:49,000 --> 00:05:50,000 +this in a web, by the way. + +103 +00:05:50,000 --> 00:05:56,000 +Yes, guys, Andrew cannot remember every single acronym I have 60, 66. + +104 +00:05:56,000 --> 00:05:58,000 +I can't remember every acronym. + +105 +00:05:58,000 --> 00:06:05,000 +Um, anyhow, so WEP was a algorithm was a wireless encryption that we first used in the early 2000 + +106 +00:06:05,000 --> 00:06:09,000 +used by RC, RC four, and it was cracked. + +107 +00:06:09,000 --> 00:06:16,000 +It did have older implementations of SSL and TLS did use it also, but this thing had a giant variations + +108 +00:06:16,000 --> 00:06:19,000 +in key size from 40 bits to 2048 bits. + +109 +00:06:19,000 --> 00:06:26,000 +Then there were other things like RC five, um, RC six these here are some of these would become widely + +110 +00:06:26,000 --> 00:06:28,000 +adopted now. + +111 +00:06:29,000 --> 00:06:31,000 +Another tool. + +112 +00:06:31,000 --> 00:06:32,000 +Not super famous. + +113 +00:06:32,000 --> 00:06:33,000 +Cass. + +114 +00:06:34,000 --> 00:06:35,000 +This one here. + +115 +00:06:35,000 --> 00:06:36,000 +128 bit. + +116 +00:06:36,000 --> 00:06:37,000 +256 bit. + +117 +00:06:37,000 --> 00:06:38,000 +You can go to. + +118 +00:06:38,000 --> 00:06:39,000 +There's two fish. + +119 +00:06:39,000 --> 00:06:42,000 +Another one to this one is made to replace the Blowfish algorithm. + +120 +00:06:42,000 --> 00:06:48,000 +Now, the other one here that I want to talk about because I know there was a lot of algorithms there. + +121 +00:06:49,000 --> 00:06:50,000 +Quite a lot. + +122 +00:06:50,000 --> 00:06:58,000 +But the algorithm that we're going to use today, 99% of communications that are done on the internet, + +123 +00:06:58,000 --> 00:07:02,000 +which utilizes things like SSL, TLS is echoes, encryption. + +124 +00:07:02,000 --> 00:07:03,000 +Now echoes. + +125 +00:07:03,000 --> 00:07:08,000 +Remember I told you, des, in the late 1990s, Des was cracked. + +126 +00:07:08,000 --> 00:07:10,000 +The government would hold a competition. + +127 +00:07:11,000 --> 00:07:13,000 +To replace this. + +128 +00:07:13,000 --> 00:07:17,000 +The winner, the algorithm that would win it would be the algorithm that won. + +129 +00:07:17,000 --> 00:07:19,000 +It has this name, the Rijndael algorithm. + +130 +00:07:19,000 --> 00:07:22,000 +This would this is the algorithm that would win the competition. + +131 +00:07:23,000 --> 00:07:25,000 +This would now be rebranded now. + +132 +00:07:25,000 --> 00:07:25,000 +That's right. + +133 +00:07:25,000 --> 00:07:32,000 +But as the echoes or the Advanced Encryption Standard since 2001, this has been the standards of encryption + +134 +00:07:32,000 --> 00:07:33,000 +that we use today. + +135 +00:07:33,000 --> 00:07:39,000 +It supports a variety of key sizes 128, 192 and 256. + +136 +00:07:39,000 --> 00:07:41,000 +It does have a variety of different rounds of encryption. + +137 +00:07:41,000 --> 00:07:45,000 +This is how many times it's going to run through the encryption process. + +138 +00:07:45,000 --> 00:07:46,000 +At 128. + +139 +00:07:46,000 --> 00:07:47,000 +It can do this ten times. + +140 +00:07:48,000 --> 00:07:52,000 +I'm not going to get into the specifics on the math about rounds of encryption is you don't really need + +141 +00:07:52,000 --> 00:07:57,000 +to know that or it's beyond the scope of this class, but just know this thing is very secure. + +142 +00:07:58,000 --> 00:08:03,000 +128 bit in today's world is considered incredibly secure. + +143 +00:08:03,000 --> 00:08:07,000 +But as but as as we sit on the horizons of quantum computing. + +144 +00:08:07,000 --> 00:08:15,000 +Technically, quantum computing may be able to crack this, but 256 bit is technically unbreakable by + +145 +00:08:15,000 --> 00:08:18,000 +any quantum computer, or it's considered quantum computer and resistant. + +146 +00:08:18,000 --> 00:08:24,000 +We'll do another video on quantum computing and why 256 is important coming up later. + +147 +00:08:24,000 --> 00:08:27,000 +Okay, lots of different algorithms. + +148 +00:08:27,000 --> 00:08:29,000 +If you're saying, Andrew, that was a lot. + +149 +00:08:29,000 --> 00:08:32,000 +Well, everything I just spoke about is here. + +150 +00:08:32,000 --> 00:08:33,000 +This is all of it. + +151 +00:08:33,000 --> 00:08:35,000 +Now you're taking your exam. + +152 +00:08:35,000 --> 00:08:37,000 +Here's what you should know. + +153 +00:08:37,000 --> 00:08:43,000 +I'm going to tell you guys, I don't think your exam is going to cover block size and key size and rounds, + +154 +00:08:43,000 --> 00:08:44,000 +although I put it in there. + +155 +00:08:44,000 --> 00:08:48,000 +But what I want you guys to know is understand that these here. + +156 +00:08:49,000 --> 00:08:51,000 +Are symmetric algorithms. + +157 +00:08:51,000 --> 00:08:56,000 +I want you guys to also understand that Des shouldn't be used or triple Des. + +158 +00:08:56,000 --> 00:08:57,000 +Don't use these. + +159 +00:08:57,000 --> 00:08:58,000 +All right. + +160 +00:08:58,000 --> 00:09:03,000 +The one you should be using is a yes no dot like those terms you should know for your exam. + +161 +00:09:03,000 --> 00:09:11,000 +Your exam is probably not going to say hey notice key size or notice block size or notice round. + +162 +00:09:11,000 --> 00:09:17,000 +I don't think so, but make sure you know what algorithm is considered symmetric. +