0:00 Music 0:07 This is an example of port scan. 0:10 So you can choose which ports you want to scan. 0:16 Or you can try to scan all popular services. 0:23 Or you can try to scan all possible ports like this. 0:35 So like this, you can scan all ports, TCP and UDP. 0:41 For example, we want to scan 1000 ports. 0:47 Yeah, so the only one which is open is 80 here. 0:52 If we will scan some other website, maybe example.com. 0:59 It is also having only 80 for 4.3. 1:03 Cloudflare. 1:05 It's just a banner. 1:08 So I'm just showing you example because last time we discussed port scan. 1:14 So I wanted to show you what is the port scan itself. 1:18 So this solution is very similar to Nmap or to some other solutions. 1:25 So this is a solution which we created. 1:28 And this is an example of the port scan. 1:33 So you can just try to run your own test, for example, scanning 10,000 ports. 1:42 And this is the list of ports which are open. 1:45 And as I know, all those ports 1:48 This is Cloudflare ports. 1:50 So they just reserved. 1:52 They are not used. 1:54 This is the only one port which is used because here you grab the banner. 1:59 All other ones, you don't see anything. 2:04 So let's maybe scan Google.com. 2:11 Just using the top words. 2:17 And it will give us port 80, port 443. 2:23 So in port 80, Google is saying, look, I don't really like that you scan my port 80 or you access through the browser. 2:32 So you should go and follow this redirection. 2:38 So Google is sending us redirection. 2:43 From port 80 to google.com location. 2:49 So what this means that if, let's see, right? 2:53 If we will access this website, this stuff, what will happen? 3:01 You see? 3:03 This is the port. 3:05 We go. 3:05 It redirects. 3:07 Again, this is port. 3:08 This is IP. 3:11 Let's try to understand again what is going on. 3:20 So now you understand a little bit more about that stuff. 3:28 Let's analyze. 3:33 So, Paul, again. 3:38 This is TCP and UDP. 3:41 We don't need TCP. 3:42 We just need TCP only. 3:44 Yes. 3:45 Those ones. 3:46 Okay. 3:49 So yeah, this is how we scan the Google. 3:52 And this clearly we understand what it is doing. 3:56 What else? 3:58 What else can we do? 4:02 Let me show you some AI tricks. 4:07 Right. 4:08 I'm sure you want to see some AI stuff. 4:14 Look. 4:17 So I'm calling the agent. 4:23 So now I'm sitting inside the agent, which has full access to insomnia. 4:32 And I will say, man, I would like to scan test PHP, test PHP. 4:45 Dot world web dot com and my local host for top 4:54 ports and please be sure to focus on XSS and please 5:04 Don't miss. 5:06 Let me close this. 5:08 Don't miss. 5:11 Don't miss subdomains. 5:15 And also make it fast, like five minutes. 5:21 And do not overload my server and make me HTML report in the end. 5:34 And also, let's focus on critical findings as well. 5:44 And please validate findings for me. 5:50 crazy stuff. 5:51 Now, what will happen? 5:54 It will analyze that stuff and it will just answer me with one answer. 5:58 It will say, listen, we will be doing the insomnia against those two targets. 6:06 We will be using model which is called XSS. 6:10 We will do the port scan for top 100 ports, as you asked. 6:14 We will do enumeration of subdomains. 6:17 We will scan those subdomains. 6:19 We will do the max time five. 6:22 We will do it fast. 6:24 And we will rate limit to 10. 6:26 And we will validate the findings using AI. 6:29 And we will filter the false positives. 6:31 And the report will be HTML. 6:33 And threads will be only five. 6:36 So did you get what is going on? 6:39 So AI is using the software. 6:44 To create the flag. 6:51 So this one you will never see. 6:55 I mean, currently in the internet, this is like what we did. 7:00 And this is one stuff. 7:03 So now what it is doing, it is scanning the stuff. 7:10 And basically... 7:13 What you can see. 7:15 He did the pulse scan, right? 7:19 And it generated the reports, which you can read. 7:27 All two hosts are live. 7:31 Nothing is down. 7:34 So yeah, and you can go and check the reports which it produced. 7:41 This is the report for open ports. 7:44 And it also provided the summary in JSON. 7:50 And you can like ask for 7:54 detailed summary or generate like remediation plan. 8:02 So this is the report. 8:07 Which it produced. 8:18 So, as an example, you can see like the port scan. 8:25 So this is the pulse scan, which was done previously. 8:31 And let's check by the notification date. 8:37 This is example of report, how it's scanned the local host. 8:46 This is remediation, which it is writing. 8:51 And this is example of open ports and example of vulnerable ports. 8:56 So for example, here we can see that this port is 3306. 9:03 It is MySQL database. 9:05 MySQL database, no authentication required. 9:09 This is vulnerability. 9:11 It means that during the scan, scanner was able to anonymously log into MySQL server. 9:20 And basically, database access without credentials. 9:26 So this is example of vulnerability. 9:30 So don't think that vulnerability is something that is very hard to understand. 9:37 Vulnerability can be very easy. 9:38 For example, open database. 9:40 So each developer knows that if they deploy database, if the database does not have credentials and it is exposed to the internet, you know, it can be hacked. 9:51 So yeah, and a lot of stuff like this, for example, malbot openclo exposed scanner. 9:59 So this is example of how the scanner is trying to find that this is 10:12 All bought. 10:14 So it accessed this endpoint and it sent a specific 10:21 pattern, it sends specific request to it, and it expected that it will say it's malbot. 10:28 The issue here is that this is new vulnerability with open flow. 10:36 So this is false positive. 10:38 Why? 10:39 Because scanner itself is expecting, for example, that when it goes to specific endpoint and it asks for specific 10:52 page, that page will give him 200 and, for example, it will say OK. 10:59 Now think about this. 11:01 If it will go to specific endpoint and that endpoint will say you OG and it will be 200, it means it's vulnerable. 11:10 This is what the scanner thinks as well. 11:13 But let's imagine that there is firewall which is... 11:18 Blocking all of your requests and it is replying 200 and for some reason on the page it's written okay or whatever so it is clear example of false positive where scanner 11:32 is having the detectors and those detectors are matching the page 11:37 So in reality, it is error. 11:41 But what we can see in some cases, this is 11:50 Because the templates themselves are not that much strict. 11:57 So I will show you what I mean by templates. 12:01 So there are templates. 12:04 Like this. 12:09 For example, 2026. 12:14 Let's see. 12:16 So this is template for vulnerability detection. 12:20 This is vulnerable page. 12:26 Right? 12:26 So this is what we are sending to this page. 12:31 We are sending this content, an example, an example, and it will try to check success through. 12:42 So let's imagine that. 12:47 Our web page has the firewall, which is sending the guy from this page to the firewall page, and it is saying success true or debug info. 13:02 In this case, scanner will think 13:06 that it is vulnerable because it doesn't have anything else. 13:09 It is saying, is it 200 status? 13:13 Yes. 13:15 Is it success true? 13:17 Yes. 13:17 It's enough for me to be sure that this is vulnerability. 13:21 So I am showing you an example of how scanner can accidentally catch the false positive.
0:00 Music 0:07 This is an example of port scan. 0:10 So you can choose which ports you want to scan. 0:16 Or you can try to scan all popular services. 0:23 Or you can try to scan all possible ports like this. 0:35 So like this, you can scan all ports, TCP and UDP. 0:41 For example, we want to scan 1000 ports. 0:47 Yeah, so the only one which is open is 80 here. 0:52 If we will scan some other website, maybe example.com. 0:59 It is also having only 80 for 4.3. 1:03 Cloudflare. 1:05 It's just a banner. 1:08 So I'm just showing you example because last time we discussed port scan. 1:14 So I wanted to show you what is the port scan itself. 1:18 So this solution is very similar to Nmap or to some other solutions. 1:25 So this is a solution which we created. 1:28 And this is an example of the port scan. 1:33 So you can just try to run your own test, for example, scanning 10,000 ports. 1:42 And this is the list of ports which are open. 1:45 And as I know, all those ports 1:48 This is Cloudflare ports. 1:50 So they just reserved. 1:52 They are not used. 1:54 This is the only one port which is used because here you grab the banner. 1:59 All other ones, you don't see anything. 2:04 So let's maybe scan Google.com. 2:11 Just using the top words. 2:17 And it will give us port 80, port 443. 2:23 So in port 80, Google is saying, look, I don't really like that you scan my port 80 or you access through the browser. 2:32 So you should go and follow this redirection. 2:38 So Google is sending us redirection. 2:43 From port 80 to google.com location. 2:49 So what this means that if, let's see, right? 2:53 If we will access this website, this stuff, what will happen? 3:01 You see? 3:03 This is the port. 3:05 We go. 3:05 It redirects. 3:07 Again, this is port. 3:08 This is IP. 3:11 Let's try to understand again what is going on. 3:20 So now you understand a little bit more about that stuff. 3:28 Let's analyze. 3:33 So, Paul, again. 3:38 This is TCP and UDP. 3:41 We don't need TCP. 3:42 We just need TCP only. 3:44 Yes. 3:45 Those ones. 3:46 Okay. 3:49 So yeah, this is how we scan the Google. 3:52 And this clearly we understand what it is doing. 3:56 What else? 3:58 What else can we do? 4:02 Let me show you some AI tricks. 4:07 Right. 4:08 I'm sure you want to see some AI stuff. 4:14 Look. 4:17 So I'm calling the agent. 4:23 So now I'm sitting inside the agent, which has full access to insomnia. 4:32 And I will say, man, I would like to scan test PHP, test PHP. 4:45 Dot world web dot com and my local host for top 4:54 ports and please be sure to focus on XSS and please 5:04 Don't miss. 5:06 Let me close this. 5:08 Don't miss. 5:11 Don't miss subdomains. 5:15 And also make it fast, like five minutes. 5:21 And do not overload my server and make me HTML report in the end. 5:34 And also, let's focus on critical findings as well. 5:44 And please validate findings for me. 5:50 crazy stuff. 5:51 Now, what will happen? 5:54 It will analyze that stuff and it will just answer me with one answer. 5:58 It will say, listen, we will be doing the insomnia against those two targets. 6:06 We will be using model which is called XSS. 6:10 We will do the port scan for top 100 ports, as you asked. 6:14 We will do enumeration of subdomains. 6:17 We will scan those subdomains. 6:19 We will do the max time five. 6:22 We will do it fast. 6:24 And we will rate limit to 10. 6:26 And we will validate the findings using AI. 6:29 And we will filter the false positives. 6:31 And the report will be HTML. 6:33 And threads will be only five. 6:36 So did you get what is going on? 6:39 So AI is using the software. 6:44 To create the flag. 6:51 So this one you will never see. 6:55 I mean, currently in the internet, this is like what we did. 7:00 And this is one stuff. 7:03 So now what it is doing, it is scanning the stuff. 7:10 And basically... 7:13 What you can see. 7:15 He did the pulse scan, right? 7:19 And it generated the reports, which you can read. 7:27 All two hosts are live. 7:31 Nothing is down. 7:34 So yeah, and you can go and check the reports which it produced. 7:41 This is the report for open ports. 7:44 And it also provided the summary in JSON. 7:50 And you can like ask for 7:54 detailed summary or generate like remediation plan. 8:02 So this is the report. 8:07 Which it produced. 8:18 So, as an example, you can see like the port scan. 8:25 So this is the pulse scan, which was done previously. 8:31 And let's check by the notification date. 8:37 This is example of report, how it's scanned the local host. 8:46 This is remediation, which it is writing. 8:51 And this is example of open ports and example of vulnerable ports. 8:56 So for example, here we can see that this port is 3306. 9:03 It is MySQL database. 9:05 MySQL database, no authentication required. 9:09 This is vulnerability. 9:11 It means that during the scan, scanner was able to anonymously log into MySQL server. 9:20 And basically, database access without credentials. 9:26 So this is example of vulnerability. 9:30 So don't think that vulnerability is something that is very hard to understand. 9:37 Vulnerability can be very easy. 9:38 For example, open database. 9:40 So each developer knows that if they deploy database, if the database does not have credentials and it is exposed to the internet, you know, it can be hacked. 9:51 So yeah, and a lot of stuff like this, for example, malbot openclo exposed scanner. 9:59 So this is example of how the scanner is trying to find that this is 10:12 All bought. 10:14 So it accessed this endpoint and it sent a specific 10:21 pattern, it sends specific request to it, and it expected that it will say it's malbot. 10:28 The issue here is that this is new vulnerability with open flow. 10:36 So this is false positive. 10:38 Why? 10:39 Because scanner itself is expecting, for example, that when it goes to specific endpoint and it asks for specific 10:52 page, that page will give him 200 and, for example, it will say OK. 10:59 Now think about this. 11:01 If it will go to specific endpoint and that endpoint will say you OG and it will be 200, it means it's vulnerable. 11:10 This is what the scanner thinks as well. 11:13 But let's imagine that there is firewall which is... 11:18 Blocking all of your requests and it is replying 200 and for some reason on the page it's written okay or whatever so it is clear example of false positive where scanner 11:32 is having the detectors and those detectors are matching the page 11:37 So in reality, it is error. 11:41 But what we can see in some cases, this is 11:50 Because the templates themselves are not that much strict. 11:57 So I will show you what I mean by templates. 12:01 So there are templates. 12:04 Like this. 12:09 For example, 2026. 12:14 Let's see. 12:16 So this is template for vulnerability detection. 12:20 This is vulnerable page. 12:26 Right? 12:26 So this is what we are sending to this page. 12:31 We are sending this content, an example, an example, and it will try to check success through. 12:42 So let's imagine that. 12:47 Our web page has the firewall, which is sending the guy from this page to the firewall page, and it is saying success true or debug info. 13:02 In this case, scanner will think 13:06 that it is vulnerable because it doesn't have anything else. 13:09 It is saying, is it 200 status? 13:13 Yes. 13:15 Is it success true? 13:17 Yes. 13:17 It's enough for me to be sure that this is vulnerability. 13:21 So I am showing you an example of how scanner can accidentally catch the false positive.