0:00 Music 0:06 What is modern penetration testing methodologies? 0:12 Basically, penetration testing has been on the market for maybe 40 years. 0:21 And we can say for the last 20 years, it was only growing. 0:26 And for the past three, five years, 0:30 A lot of cybersecurity specialists, they start to work with AI. 0:34 A lot of software start to use AI. 0:38 But penetration testing didn't change that much. 0:45 And it's going to change within like three, five years. 0:48 But methodologies, tools, and real-world approach, it didn't change that much yet. 0:53 So if you will take the book, which is 10 years old, you will read it. 0:58 And if you will buy the new book, which is 2025, 2026, you will see the same pattern on how to do. 1:07 Testing of your mobile applications or how to do testing of your web. 1:13 And the tooling will be almost the same. 1:15 So basically, you can access the website, which is called exploit.company. 1:22 So what is that website? 1:24 That website was converted from the original 20 years old. 1:30 website which is called exploitdb and that website is including a list of vulnerabilities. 1:39 So why it's important? 1:40 Because in exploit.company website you can see ability of you can sort on this website 1:50 different years, different vulnerabilities, and different software. 1:53 For example, if you're running Windows 11, you can just go on Exploit Company, write Exploit 11, and you can see all the vulnerabilities which are there. 2:03 In Secure.Tools, this is also a free website where you can see and download different tools. 2:11 I will open those two websites. 2:13 In here, you can see different tools. 2:15 They are separated by the categories, brute force, OSINT, and much more. 2:21 So on this website, you can see different tools. 2:25 And this website was created by us. 2:28 And we collected different tools. 2:32 Which will help you to do penetration testing of your infrastructure without spending any money. 2:41 So this is an example of how to download and install different tools. 2:48 So you don't need to go and watch continuous YouTube videos. 2:54 You can just go to this website, choose the category which you want, like vulnerability analysis, for example. 3:00 or anything else, and just choose different tools, download them, and you will be able to run them. 3:08 So this is an example of how you're running a tool. 3:10 You're just writing the name of the tool and after your website. 3:14 And it will provide you a big amount of information, which maybe you will not be able to understand right away. 3:20 But with modern AI, it will just convert you to the activities which you really need to do. 3:28 So this is one website, and this is a second website, which I just talked about. 3:34 So this website, both of those websites are done with AI fully. 3:39 So human interaction was in the minimum level. 3:43 So most of the tools, most of the stuff which you see on my screen is done with AI. 3:48 So all this website except design was done with AI. 3:52 So how it was done, basically it... 3:57 The Python script was created, which is going to this website, exploitdb.com, to this website. 4:07 I don't know why it's down. 4:09 ExploitDB. 4:12 Let's see. 4:12 Yeah, it's not down. 4:14 So this is all website. 4:16 And here you don't have enough filters or enough abilities to find what you need. 4:23 And those filters, they look like a little bit outdated. 4:26 Advanced filter is not that good. 4:30 This is what you get, right? 4:31 This is how exploit looks like. 4:34 So hackers are putting... 4:37 Those items in the internet. 4:39 This is exploit 2025 here, right? 4:41 If you will go to our website, you can clearly see the author, the vendor, which is affected, the system, which is affected, description, mitigation, and all that stuff was done by AI. 4:56 So basically, 4:57 We downloaded all 45,000 exploits, spent maybe 7,000 USD 5:06 to convert using API calls, and just created a website for community, for people, so they can just go here and download the exploits and find the 5:18 exploits which they will be using against specific vendors. 5:23 Let me give you an example of what is exploit. 5:26 So, for example, you have some WordPress website, right? 5:31 So you choose WordPress website. 5:33 WordPress is the CMS written on PHP for the content management system to host the websites. 5:43 So this is very popular. 5:46 Content management system along with Drupal and along with like Joomla and Magento and some other content. 6:00 management system. 6:01 In this example, which I'm showing you, we have a specific vulnerability, which is called stored XSS. 6:07 Later, I will tell you what is this exactly. 6:10 So on the WordPress website, there is vulnerability on specific plugin, which is called WordPress file upload plugin. 6:17 So if you have this plugin, 6:19 and this plugin is this specific version or less, you can basically hack this website. 6:25 And this is how you're doing this. 6:27 So this is the answer on what is exploit. 6:31 Inside the WordPress, you have ability to install additional software. 6:37 And that additional software is done by random vendors. 6:41 So different companies or different authors, they can upload the plugins, WordPress plugins to this portal. 6:52 So you can just go here and download different plugins from different people. 6:56 And those plugins are written on PHP. 7:00 And usually they are not analyzed for web vulnerability. 7:07 So if you're running the WordPress website and you are having different type of plugins, there is big possibility that you... 7:15 Can have that type of exploit based on your WordPress version and based on the plugins which you're using. 7:21 So let's go back to our slides because we went too far deep to something that we should not discuss in that 7:30 young stage, early stage. 7:34 So, additionally, you can access the blog. 7:42 In blog, you can read a lot of information about the cybersecurity. 7:46 You can see the stages for AI penetration testing. 7:50 You can see how open AI can be used for SaaS. 7:55 So a lot of stuff which is put in our blog. 8:01 So you can also read it. 8:03 Additionally, there is Wikipedia related to cybersecurity only. 8:12 So if you are interested in specifically, for example, web vulnerabilities, you can just go here and read a couple of... 8:22 Articles and you will get to understand what is going on. 8:27 So I know that it is a little bit hard to understand what I'm saying right now, but when we will keep moving, you will start to get it like better and better.
0:00 Music 0:06 What is modern penetration testing methodologies? 0:12 Basically, penetration testing has been on the market for maybe 40 years. 0:21 And we can say for the last 20 years, it was only growing. 0:26 And for the past three, five years, 0:30 A lot of cybersecurity specialists, they start to work with AI. 0:34 A lot of software start to use AI. 0:38 But penetration testing didn't change that much. 0:45 And it's going to change within like three, five years. 0:48 But methodologies, tools, and real-world approach, it didn't change that much yet. 0:53 So if you will take the book, which is 10 years old, you will read it. 0:58 And if you will buy the new book, which is 2025, 2026, you will see the same pattern on how to do. 1:07 Testing of your mobile applications or how to do testing of your web. 1:13 And the tooling will be almost the same. 1:15 So basically, you can access the website, which is called exploit.company. 1:22 So what is that website? 1:24 That website was converted from the original 20 years old. 1:30 website which is called exploitdb and that website is including a list of vulnerabilities. 1:39 So why it's important? 1:40 Because in exploit.company website you can see ability of you can sort on this website 1:50 different years, different vulnerabilities, and different software. 1:53 For example, if you're running Windows 11, you can just go on Exploit Company, write Exploit 11, and you can see all the vulnerabilities which are there. 2:03 In Secure.Tools, this is also a free website where you can see and download different tools. 2:11 I will open those two websites. 2:13 In here, you can see different tools. 2:15 They are separated by the categories, brute force, OSINT, and much more. 2:21 So on this website, you can see different tools. 2:25 And this website was created by us. 2:28 And we collected different tools. 2:32 Which will help you to do penetration testing of your infrastructure without spending any money. 2:41 So this is an example of how to download and install different tools. 2:48 So you don't need to go and watch continuous YouTube videos. 2:54 You can just go to this website, choose the category which you want, like vulnerability analysis, for example. 3:00 or anything else, and just choose different tools, download them, and you will be able to run them. 3:08 So this is an example of how you're running a tool. 3:10 You're just writing the name of the tool and after your website. 3:14 And it will provide you a big amount of information, which maybe you will not be able to understand right away. 3:20 But with modern AI, it will just convert you to the activities which you really need to do. 3:28 So this is one website, and this is a second website, which I just talked about. 3:34 So this website, both of those websites are done with AI fully. 3:39 So human interaction was in the minimum level. 3:43 So most of the tools, most of the stuff which you see on my screen is done with AI. 3:48 So all this website except design was done with AI. 3:52 So how it was done, basically it... 3:57 The Python script was created, which is going to this website, exploitdb.com, to this website. 4:07 I don't know why it's down. 4:09 ExploitDB. 4:12 Let's see. 4:12 Yeah, it's not down. 4:14 So this is all website. 4:16 And here you don't have enough filters or enough abilities to find what you need. 4:23 And those filters, they look like a little bit outdated. 4:26 Advanced filter is not that good. 4:30 This is what you get, right? 4:31 This is how exploit looks like. 4:34 So hackers are putting... 4:37 Those items in the internet. 4:39 This is exploit 2025 here, right? 4:41 If you will go to our website, you can clearly see the author, the vendor, which is affected, the system, which is affected, description, mitigation, and all that stuff was done by AI. 4:56 So basically, 4:57 We downloaded all 45,000 exploits, spent maybe 7,000 USD 5:06 to convert using API calls, and just created a website for community, for people, so they can just go here and download the exploits and find the 5:18 exploits which they will be using against specific vendors. 5:23 Let me give you an example of what is exploit. 5:26 So, for example, you have some WordPress website, right? 5:31 So you choose WordPress website. 5:33 WordPress is the CMS written on PHP for the content management system to host the websites. 5:43 So this is very popular. 5:46 Content management system along with Drupal and along with like Joomla and Magento and some other content. 6:00 management system. 6:01 In this example, which I'm showing you, we have a specific vulnerability, which is called stored XSS. 6:07 Later, I will tell you what is this exactly. 6:10 So on the WordPress website, there is vulnerability on specific plugin, which is called WordPress file upload plugin. 6:17 So if you have this plugin, 6:19 and this plugin is this specific version or less, you can basically hack this website. 6:25 And this is how you're doing this. 6:27 So this is the answer on what is exploit. 6:31 Inside the WordPress, you have ability to install additional software. 6:37 And that additional software is done by random vendors. 6:41 So different companies or different authors, they can upload the plugins, WordPress plugins to this portal. 6:52 So you can just go here and download different plugins from different people. 6:56 And those plugins are written on PHP. 7:00 And usually they are not analyzed for web vulnerability. 7:07 So if you're running the WordPress website and you are having different type of plugins, there is big possibility that you... 7:15 Can have that type of exploit based on your WordPress version and based on the plugins which you're using. 7:21 So let's go back to our slides because we went too far deep to something that we should not discuss in that 7:30 young stage, early stage. 7:34 So, additionally, you can access the blog. 7:42 In blog, you can read a lot of information about the cybersecurity. 7:46 You can see the stages for AI penetration testing. 7:50 You can see how open AI can be used for SaaS. 7:55 So a lot of stuff which is put in our blog. 8:01 So you can also read it. 8:03 Additionally, there is Wikipedia related to cybersecurity only. 8:12 So if you are interested in specifically, for example, web vulnerabilities, you can just go here and read a couple of... 8:22 Articles and you will get to understand what is going on. 8:27 So I know that it is a little bit hard to understand what I'm saying right now, but when we will keep moving, you will start to get it like better and better.