How Hackers Move Through Networks (with Ligolo)

Поділитися
Вставка
  • Опубліковано 21 лис 2024

КОМЕНТАРІ • 206

  • @_JohnHammond
    @_JohnHammond  10 місяців тому +33

    Sorry, I just added the Pivoting Lab SnapLabs template link now: jh.live/pivoting
    Thanks for watching and all your support! (and psst, check out Vanta! jh.live/vanta )

    • @flan701
      @flan701 8 місяців тому +1

      Is this template still accessible? I am unable to reach it on SnapLabs. Just gives me "network error" when trying to open it.

    • @goultarde
      @goultarde 5 місяців тому +2

      Hi, i have "Network Error" on my side ;(

    • @Ashiflyy
      @Ashiflyy 6 днів тому +1

      @@goultarde same here. not able to access the template via tha link.

  • @brandhark7935
    @brandhark7935 10 місяців тому +518

    Just did this pivoting and hacked my local police department and they loved it! They even offered me a free room with free toilet and nice orange clothes! Life is good!

  • @F0rc3Tv
    @F0rc3Tv 10 місяців тому +40

    im so glad i learned how to use ligolo before doing the CPTS exam. passed on the exam in august on the first attempt

  • @jayrockjunk
    @jayrockjunk 8 місяців тому +8

    These always start with, "let's assume we already obtained access to this host". That's the hard part. Everything else is easy.

  • @MalwareCube
    @MalwareCube 10 місяців тому +77

    Ligolo is killer for the OSCP Active Directory set. 🎉

    • @Michael_Jackson187
      @Michael_Jackson187 9 місяців тому +6

      They let you use tools on the Oscp?

    • @GodlyTank
      @GodlyTank 9 місяців тому

      @@Michael_Jackson187 Oh yeah, just not any auto exploit tools. So avoid metasploit framework auto-exploits, sqlmap, but you can still use msfvenom (I faded it for a while and have had a few boxes where I couldn't get any of my reverse shells to work without it

    • @eli_the_crypto_guy
      @eli_the_crypto_guy 9 місяців тому

      @@Michael_Jackson187Check rules of engagement, some tools amd techmiques are not allowed, like Metasploit attack modules

    • @DarkDonnieMarco
      @DarkDonnieMarco 8 місяців тому

      @@Michael_Jackson187no you have to do the entire OSCP in assembly.

  • @KevlarSlap
    @KevlarSlap 10 місяців тому +43

    In my experience, servers in a DMZ don't have a second interface on an internal subnet- that defeats the purpose of the DMZ.

    • @flrn84791
      @flrn84791 6 місяців тому +1

      Even then, there's usually a jump box or a way to access them or their network from an internal network

  • @swilson42
    @swilson42 7 місяців тому +7

    Hey look, if someone sets up a server with two interfaces, one with a public IP and one with a private IP on a production internal LAN, AND they kindly let me install my hacking tool (or maybe just happen to have an unpatched vulnerability), AND they don’t use any firewall rules to limit access either on the public or private interfaces, AND they don’t use any endpoint protection tools, AND they don’t use any traffic inspections tools, it’s SO easy to hack them! /s
    Yeah this isn’t remotely how a DMZ is set up. For sure there are sloppy admins who have servers bridging public and private networks like this, but that’s not called a DMZ, that’s called an invitation to the Target and Equifax awards and breaching them would likely be far easier than using a fancy pivot tool like this. They probably have 3389 wide open so you can RDP right onto their server with a guest account like it’s 1999.
    New video title: Compromising networks with no security.

    • @effsixteenblock50
      @effsixteenblock50 5 місяців тому +3

      "I don't often easily pivot to internal networks from the DMZ but when I DO, I *always* fire off nmap scans of the entire /24!"

  • @KenPryor
    @KenPryor 10 місяців тому +60

    This is so cool! It would be very interesting to do a forensic exam on the pivot machine to see what signs are left behind by Ligolo activity. Great video!

    • @deebee201
      @deebee201 8 місяців тому +2

      Please pontificate on this subject with some particulars. I am almost finished with my digital forensics cert, and I want to understand all of the practical scenarios I can. TY

  • @BlizzetaNet
    @BlizzetaNet 10 місяців тому +15

    I love how you've grown into cybersecurity. I'm very rusty and think your videos are helping eliminate that rust.

  • @PrinceJohn84
    @PrinceJohn84 9 місяців тому +27

    Anybody putting servers in a DMZ with interfaces that reside in completely different networks probably needs a recap on exactly what a DMZ is for.

    • @pimpnosimpg5416
      @pimpnosimpg5416 8 місяців тому

      Can u explain pls?

    • @deebee201
      @deebee201 8 місяців тому

      Right! Thank you! I know he has more experience than me, but I was like no bueno hombre.

    • @forty4seven46
      @forty4seven46 7 місяців тому

      @@pimpnosimpg5416
      Certainly! When setting up a DMZ, the goal is to isolate publicly accessible servers from the internal network to enhance security. Typically, servers in a DMZ have interfaces connected to both the external (untrusted) network and the internal (trusted) network. This setup allows external users to access services like web servers or email servers while keeping them separated from sensitive internal resources.
      However, if servers in a DMZ have interfaces connected to completely different networks, it could indicate a misunderstanding of how to properly configure a DMZ. The purpose of a DMZ is to create a buffer zone between the internet and the internal network, ensuring that any security breaches or attacks targeting public-facing services are contained and don't compromise internal systems. Placing servers with interfaces in different networks within a DMZ could create confusion and potentially undermine the intended security benefits of the DMZ architecture.

    • @flrn84791
      @flrn84791 6 місяців тому

      So how do you access servers in the DMZ from an internal network?

    •  3 місяці тому +1

      ​@flrn84791
      You can't that's the purpose of a DMZ, it should not be accessed from the internal network, unless if you have access to the firewall box that manages the DMZ network.

  • @ScottPlude
    @ScottPlude 10 місяців тому +7

    the RED side of my brain loves ya.
    the BLUE side of my brain has constant headaches!

  • @aleckane99
    @aleckane99 10 місяців тому +9

    Can you make a video on protecting against this or simply show how to setup a detector for it? That would be sick. I had to subscribe after watching this demo, very well done!

    • @AlexandruMocanu
      @AlexandruMocanu 10 місяців тому +3

      A really good starting point is: if a machine is in the DMZ you should not add another Network to it (Hosts network in this case).
      It should not have multiple interfaces attached to other Networks than the DMZ. If the machine has multiple networks attaches no firewall can stop traffic

  • @berthold9582
    @berthold9582 10 місяців тому +11

    I wonder how anyone can provide such exciting content.
    There are no two like you sir

  • @BillHeng
    @BillHeng 7 місяців тому

    I just learnt about this tool a few weeks back for my OSCP prep. looking forward to using it in my exam soon

  • @jonathanj3362
    @jonathanj3362 10 місяців тому +8

    Very cool and thanks for the video!
    Feedback: The multiple camera views of the video I am not the biggest fan of at this time. I feel more connected to the content when its the straight on camera angle where you are engaged with the viewers, when it switches seeing you looking in a different direction makes it feel disconnected from the content. If you plan on keeping the multiple angles personally I would like to see you engage the camera that is active. Appreciate all the new content you are producing! That is my .02.

  • @THOHATRAVELS-o7x
    @THOHATRAVELS-o7x 2 місяці тому

    Please don't listen to the people who are complaining about being your video slow. Don't change it. Most of the creator are really hard to understand

  • @WildDisease72
    @WildDisease72 10 місяців тому +2

    Its easier to social engineer today directly to internal network via employee weakness (especially new people to country)

  • @travis4482
    @travis4482 3 місяці тому

    I'm really glad that you broke down the meaning of cross-platform, I never would have guessed. 😂

  • @chaxiraxi_ytb
    @chaxiraxi_ytb 10 місяців тому +1

    Explaining what Kali is and what is a "cross-platform" software while presenting a network pivoting tool for advanced pentesters is killing me

    • @rob-890
      @rob-890 10 місяців тому

      Gotta fill the time

  • @ulyssesfister3735
    @ulyssesfister3735 10 місяців тому +13

    easy to understand, thanks John. Nifty piece of software

  • @lilp4p1
    @lilp4p1 10 місяців тому +3

    All of that is automated with the havoc-ligolo module as well! Cool video ^^

    • @CyberCelt.
      @CyberCelt. 2 місяці тому

      Thanks, didn't know that was a module

  • @ERICHOEHNINGER
    @ERICHOEHNINGER 10 місяців тому +3

    Is it just me who doesn't like the vision mixer(camera transition) ?😅

  • @CandyGramForMongo_
    @CandyGramForMongo_ 10 місяців тому +3

    Oh, don’t advocate for “real” certs. That’s evidence! Self-signed cert is perfect for this application.

  • @rationalbushcraft
    @rationalbushcraft 10 місяців тому +8

    I would think most DMZs would block unnecessary ports to the inside. Am I missing something here?

    • @Youtupe69
      @Youtupe69 10 місяців тому

      Its actually an outgoing connection from the dmz. It doesnt need an open port from the outside.

    • @rationalbushcraft
      @rationalbushcraft 10 місяців тому

      @@Youtupe69 I get that but doesn’t it need ports between the Private and DMZ? At least whatever port it is using for the proxy connection.

    • @factorialandha5929
      @factorialandha5929 10 місяців тому +6

      ​@@rationalbushcraft if you set up your DMZ properly, you are correct, you would seriously limit and restrict access, most likely using an Internal firewall, so that your DMZ can only access the devices and servers it requires access to internally to function and also restrict any outbound traffic to the outside that isnt required.
      this does not completely remove the risk, it just reduces the scope of the attack and means the attacker may have to "pivot" a few times. Granted they can get the tunnel connected in the first instance.

    • @KevlarSlap
      @KevlarSlap 10 місяців тому

      @@factorialandha5929 I think the issue is that John is selling this as a way to move laterally without explaining further on how DMZs normally work. He says the devices in the DMZ can access the internal network when that's mostly untrue. DMZs are designed to have limited access to the internal network. This might confuse the many newbies watching his channel into thinking that all DMZs have unrestricted internal network access.

    • @peculiarfamiliar
      @peculiarfamiliar 4 місяці тому

      ​@@factorialandha5929how would I be able to regain access to my wifi security and remove multiple administrators off of my laptop? I've been struggling for four years with all of this, alongside of watching multiple videos on what's up with my sh*t(in my limited free time, I have kiddos) & all I've gotten through it all is headaches, very limited help, & laughed at on countless occasions...I have been reaching out everywhere & end up not getting responses or getting responses & then they disappear...it's definitely someone screwing with my network. I see some of the ports or channels are running interface & actually neighboring networks are as well... I tried the app the one popular app... I see multiple devices upon my Bluetooth same name under & identifying as whole other devices under a different color & or icon. I also have multiples of my one device showing in Google home(I've NEVER used Google home, ever) my kids baby monitor is pairing with random objects too. I live alone with my two little girls & am over all of this! I have little $ & what I've saved, I've put out to hire someone other than my service provider... They just mock me & change all of my info... Wifi name, password, & also made me a whole email address that I've never ever used. Sorry so long, but that's some of my sh*t. Any help would be greatly appreciated! Hope you had a beautiful 4th & hope you are well. I read your comment & you seem knowledgeable so I decided to take a shot & throw this out there. Thinking maybe, someone will reach out. You never know, if ya don't try, right?!?!? If I don't answer you, it's because my comments go missing. Alongside of everything tech wise in my life. It's been 4 years & I'd just like a little peace with it all. Ty for listening... 🫀

  • @Jebly_5555
    @Jebly_5555 10 місяців тому +2

    I literally just learned about this program after having trouble with chisel on my OSCP lol. Cannot wait to try it out.

  • @maniakdemi3548
    @maniakdemi3548 10 місяців тому

    Started using this tool yesterday...
    Hopefully, I'll get to understand it here

  • @mr-raa0443
    @mr-raa0443 4 місяці тому

    i dont know why i wasnt subscribed to your channel❤‍🔥

  • @CyberDevilSec
    @CyberDevilSec 10 місяців тому +2

    Jesus John your content has improved soo much!!!
    We love you man :D

    • @nordgaren2358
      @nordgaren2358 10 місяців тому

      Thank you! It's a team effort. :)

  • @0xnightfury
    @0xnightfury 10 місяців тому +1

    John's background looks dope !! wow

  • @stamdar1
    @stamdar1 10 місяців тому +1

    1:38 "links below"
    Never once has anyone on this platform delivered on that promise

  • @Team_VALHALLA69
    @Team_VALHALLA69 10 місяців тому +1

    Hi John sir 👋 love from India 🇮🇳

  • @safelinkit
    @safelinkit 8 місяців тому

    Bye bye Proxychains. Gonna use that fro my PNPT exam in 2 weeks.
    Quick test in my home lab worked flawlessly with your tutorial (well - the agent does get picked up by Defender, but for the purpose of exam-prep I deactivated it in my lab)

  • @Thuja814
    @Thuja814 10 місяців тому

    I’m not a computer expert, Jack Rhysider warped my brain so I listen to videos like this to relax at bedtime

    • @BurtMacklin947
      @BurtMacklin947 10 місяців тому +1

      Lol exactly the same happened to me, now a few years later I'm working as a pentester.
      Thanks Jack 🤣

  • @MrHasooooni
    @MrHasooooni 10 місяців тому

    this tool would make the job a lot easier thank you for the demo man keep up the good work much love from Saudia Arabia

  • @kooroshsanaei
    @kooroshsanaei 9 місяців тому

    Wow -Prefect WHy Don't UA-cam Give you a strike !?

  • @jghuathuat
    @jghuathuat 10 місяців тому +2

    would've like to see a double pivot.

  • @bigdaddy5303
    @bigdaddy5303 10 місяців тому

    Jesus 1 million subs and now we see john for multiple angles in real time

  • @MoveTrueRecords_
    @MoveTrueRecords_ 10 місяців тому +1

    this is super clean content now i love it. Love the examples shown

  • @InsanexBrain
    @InsanexBrain 10 місяців тому

    Where was this program when i took eCPPT? great video!!

  • @quentin7343
    @quentin7343 8 місяців тому

    Brilliant pedagogy

    • @deebee201
      @deebee201 8 місяців тому

      Hey quentin, it has been a while since somebody used verbiage that I had to look up on You Tube. Well said, beautiful nomenclature sir. This will be something I will use. Well spoken, if you don't mind, drop some more knowledge. I am thirsty for smart human interaction.

  • @QuisUtDeus828
    @QuisUtDeus828 7 днів тому

    PIVOT
    - Ross Geller

  • @DholuBholu-q2l
    @DholuBholu-q2l 10 місяців тому +1

    Sir , after completing bca course then what course should we take to fully completed cybersecurity or Ethical hacking

  • @caglayagmurr
    @caglayagmurr 8 місяців тому +1

    i read ligolo as gigolo i need sleep ☠☠☠

  • @zer001
    @zer001 10 місяців тому +1

    Nice Video. But in my opinion it is a little to hectic. The cuts look cool, but they are a bit confusing.

  • @davidbl1981
    @davidbl1981 10 місяців тому +1

    What is the CN of the let’s encrypt certificate? Perhaps you could easily traverse ligolo certificates via the certificate transparency database…

  • @Alwso
    @Alwso 8 місяців тому

    So you should have a machine in DMZ to get it works

  • @steelsteez6118
    @steelsteez6118 9 місяців тому

    00:24 I can see your eyes reading off of a script!! CHEATER!! I thought you were a knowledge BEAST that knew all this from the top of his head when explaining it!!! How dare you prepare such a well prepared video with high production quality!!

  • @brettnieman3453
    @brettnieman3453 10 місяців тому

    Good stuff. Hopefully it doesn't get popped by EDR soon.

  • @CWLabs7209
    @CWLabs7209 4 місяці тому

    Nice tool & nice watch 🥳

  • @ernestoditerribile
    @ernestoditerribile 8 місяців тому

    Aarch64 if you compile all Kali apps directly in MacOS or Fedora Asahi Linux. Off course Kali is easier, because of all the built in tools, but it’s way faster when you compile it natively.

  • @hehefer
    @hehefer 9 місяців тому

    wow john i love u more than i love myself

  • @hamidb75
    @hamidb75 9 місяців тому

    Great stuff, looking forward to test it out. Thanks

  • @s.hariharan6958
    @s.hariharan6958 10 місяців тому

    Thank you John! 🙂

  • @l2xsniper1
    @l2xsniper1 10 місяців тому

    Wow awesome tool. Could you maybe do a follow up of some more complex scenario's?

  • @JackOfAllThreatsMasterOfNone
    @JackOfAllThreatsMasterOfNone 10 місяців тому

    Thanks for making this tutorial

  • @jarrettgoh8920
    @jarrettgoh8920 7 місяців тому

    This concept can be achieved with dynamic port forwarding with SSH too right? But just that it’s slower when running nmap scans?

  • @garycacoon
    @garycacoon 7 місяців тому

    What about docker, sysdig and Falco??

  • @0oNoiseo0
    @0oNoiseo0 10 місяців тому

    Thank you John!

  • @evodefense
    @evodefense 10 місяців тому

    Great video and tools thanks!

  • @KanjiasDev
    @KanjiasDev 9 місяців тому

    I guess you could also use that as a quick and dirty solution to create bridges to fix problems with NATed networks, right? 😅

  • @pmcforever9686
    @pmcforever9686 10 місяців тому +34

    i prefer the slightly fast paced videos this was a bit too slow for my liking but this is great for people that are just getting into this

    • @ZeroAlpha1173
      @ZeroAlpha1173 10 місяців тому +2

      I am just getting to cyber security. After being in the desktop / server support area for a while I recently found my passion for cyber security. I have signed up for some certification exams and found this channel. :)

    • @ahr0cdovlzk3my1lahqtbmftdw7
      @ahr0cdovlzk3my1lahqtbmftdw7 10 місяців тому +5

      TikTok User

    • @yodaiam5235
      @yodaiam5235 10 місяців тому +7

      Dude can't even hack the playback speed 😂

    • @ronin0x_
      @ronin0x_ 10 місяців тому

      Shut up man

    • @dolbearrr
      @dolbearrr 10 місяців тому

      Loll - i love the playback speed comments

  • @architvats2633
    @architvats2633 8 місяців тому

    You're simply the best

  • @criteriumprovidus4360
    @criteriumprovidus4360 9 місяців тому

    Yeay! Great Ligolo !!! oh wait most computers in a network don't have two NICs unless is a server and servers don't get malware from users clicking an email. So this means that Ligolo CAN"T move laterally. Damn too bad. Too much fanfare for things that almost never happen. Please tell me that I'm wrong!

  • @compote-s1r
    @compote-s1r 10 місяців тому

    Thanks for all the content, again very nice video !

  • @ryanstricklin198
    @ryanstricklin198 10 місяців тому

    You should really look into investing into a teleprompter so that you don't have to keep looking off the camera, in order to keep the audience engaged. Good work!

  • @augustinemunene3469
    @augustinemunene3469 10 місяців тому

    does this mean you will be able to access the subnet of the companies assuming they are using active directory

  • @danieltran7637
    @danieltran7637 10 місяців тому

    Thank you so much John for sharing, all that super useful knowledge with us. I realy enjoying watching your videos. 👍

  • @andreighita8762
    @andreighita8762 9 місяців тому

    What keyboard are you using?

  • @darkdagger032
    @darkdagger032 10 місяців тому

    Great video, John!

  • @mmgm
    @mmgm 10 місяців тому

    Isn’t the certificate generated on the proxy side ie your kali box that does have internet? And then the TLS certificate can be verified offline by the agent

  • @clementanguandia104
    @clementanguandia104 10 місяців тому +1

    Windows will flag ligolo as malicious soon ;p

  • @erglaligzda2265
    @erglaligzda2265 10 місяців тому

    Is there a way to find out if agent has been installed on machine, for example ligolo agent? In case, AV cannot find anything...

  • @relevant3329
    @relevant3329 10 місяців тому

    I like this new version videos

  • @codingpandas
    @codingpandas 10 місяців тому

    Hey john, you are one of the best and i have been learning from you from the last three years.. but hey did anyone tell you you look alot like that footballer Kevin De Bruyne

  • @havoc_64
    @havoc_64 10 місяців тому

    Great Video!! Thanks for sharing this

  • @janekmachnicki2593
    @janekmachnicki2593 10 місяців тому

    Awesome mate Thanks

  • @AGASTRONICS
    @AGASTRONICS 10 місяців тому +1

    Cool Video 📼
    How I wish these tools were not honeypots developed by Blue Team or the Government 😅 😡🙂😄
    Just stick with the tradition 🤗 you what I mean.
    Cool video Thanks 🎉

  • @Jebly_5555
    @Jebly_5555 10 місяців тому

    I tried using the autocert but it seems to have an issue. "yamux: Failed to write header: acme/autocert: missing server name
    ERRO[0151] could not register agent, error: session shutdown". For the purposes of taking exams and stuff though, this is super awesome, don't need real certs.

  • @salemmusbah3676
    @salemmusbah3676 10 місяців тому

    Thanks
    John Hammond more Tut like this plz

  • @georgehammond867
    @georgehammond867 9 місяців тому

    this thing is very dangerous program!

  • @Toxicbananaz007
    @Toxicbananaz007 10 місяців тому

    Could we get a link to the template of the cloud lab? I may just be blind but i couldnt find it

  • @chathurangaonnet
    @chathurangaonnet 10 місяців тому

    Can we still use this in network client isolation network ? I mean if the access restricted network withing the same vlan clients ?

  • @TonyAsh-rp6fp
    @TonyAsh-rp6fp 10 місяців тому

    Thanks john, I have downloaded adn installed it but you are realy fast explaining. Dont get all how to do properly. May be this video is for intro but if you have time please show us the complete tutorial like attacker machine ---> compromised machine --> then from pivoting how to do just for beginners. I am newbie. Many thanks in advance. Love your previous contents.

  • @nathanielsmith2918
    @nathanielsmith2918 10 місяців тому

    Anytime you open up a web page on my screen it got all garbage and pixelated like. But no the sponsors Segway worked fine...

  • @LionBrine
    @LionBrine 10 місяців тому

    Ligolo mentioned RAHHHHH

  • @aadishm4793
    @aadishm4793 10 місяців тому

    Great video,
    Keep it up 💪🎉🎉

  • @dm3035
    @dm3035 10 місяців тому

    💥EXCELLENT VIDEO - GREAT SKILLS SHARING - MUST WATCH - THANK YOU 💥

  • @haroldvelasquez9631
    @haroldvelasquez9631 10 місяців тому

    Wow this is awesome!! I will try to make it work on the pivoting labs of HTB. Hope this makes it easier. A video like this pivoting and double pivoting on windows environments will be really cool

  • @itsksujan
    @itsksujan 10 місяців тому

    where is the link to the cloud lab ?

  • @vnit4security
    @vnit4security 7 місяців тому

    Very nice

  • @The_Pariah
    @The_Pariah 8 місяців тому

    As some constructive criticism for making your videos better, you should consider moving the monitor you're reading from closer to your camera. Probably underneath or above it.
    As it is now, your eyes are continually darting from the webcam to the screen. You're going back and forth and you lose that seemless effect of talking to the viewer while you're reading.
    Instead, it looks more like you're distracted and you keep looking at something "over there" while trying to address your viewers.

  • @robyee3325
    @robyee3325 10 місяців тому

    So how do you protect against this attack?

    • @berndeckenfels
      @berndeckenfels 10 місяців тому +1

      You can watch for untrusted binaries, filter egress ports and of course don’t give attackers shell on your hosts.

    • @robyee3325
      @robyee3325 10 місяців тому

      @@berndeckenfels Thank you for not trolling!

  • @RyLeedepressed
    @RyLeedepressed 9 місяців тому +1

    That was an illegal advertisement, buddy you have to disclose that it’s an advertisement you can’t say that it’s just a cool company

  • @kooolafrid
    @kooolafrid 5 місяців тому

    Make a video about jwt encrypted token as well

  • @ak0904
    @ak0904 10 місяців тому +2

    I like this but the name ligolo is kinda weird 💀... ngl

  • @vpswede98
    @vpswede98 10 місяців тому

    9:00 John, what did you mean that selfsigned certificates are vulnerable for man in the middle attacks?
    I ofcourse might be wrong, but the encryption doesn't change (aslong as you do it correctly) only that there is no CA. And pretty much only case where this would be an issue would be in a externally communicating website, but for internal traffic, i dont see the issue with running selfsigned?

    • @nekkrokvlt
      @nekkrokvlt 10 місяців тому

      Because MiTM uses self signed cert as well, so if you tell ligolo to accept self-signed cert, there's no way to know if it is the self signed from from the ligolo device, or someone doing MiTM.

    • @vpswede98
      @vpswede98 10 місяців тому

      @@nekkrokvlt ahh so it’s not a diss on self signed certs in general but only in the way that ligolo gets a hold of its cert. Thanks for the response

    • @berndeckenfels
      @berndeckenfels 10 місяців тому +1

      If you use a self signed cert AND verify its fingerprint, it’s actually safer than trusting a thirdparty. It’s just less convenient (ligolo could make it more convenient by pasting the fingerprint to accept) so this step is often skipped. However, do you fear you get hacked as a hacker? ,)

  • @aunghtoomyat9481
    @aunghtoomyat9481 10 місяців тому

    Yo I cannot seem to find the premade template.

  • @bunnyslayer14
    @bunnyslayer14 8 місяців тому

    Thank you, great study material for the comptia sec+ test that I'm studying for

  • @saucegotti8538
    @saucegotti8538 10 місяців тому

    “you wanna be in the streets” 🤨🤨

  • @SecretProfitsClub
    @SecretProfitsClub 6 місяців тому

    I need to chat with you. I am in a position I am not sure what to do with. Its all new world to me, but I ended up at the end of it with a mountain of intel and I think I can connect quite a few dots