0:00 Music 0:07 Basically, you should understand that penetration tester is not the guy who is just sitting behind the computer and running some crazy scripts. 0:18 A real penetration tester is the guy who knows how to hack basically psychology. 0:27 Of human and he is doing different activities which 0:35 force him to use social engineering because without social engineering he cannot exploit most of vulnerabilities which are on the internet now so for example if we talk about 0:50 exercise vulnerability, which I showed you before. 0:53 You need to ask guy to go to that website, for example, or if you are trying to deliver malware, or if you're trying to deliver the phishing email, right? 1:05 You need to pursue the guy to open email. 1:09 You need to pursue the guy to open SMS. 1:12 You need this guy to, you know, to follow your link, to install your software. 1:19 So... 1:21 It's not only about, you know, the designing of the email. 1:26 It's not that content of that email. 1:30 all together. 1:31 If you will fail on some point, the guy will not buy it. 1:38 If your domain name doesn't make sense, he will not buy it. 1:42 If you don't have HTTPS certificate, guy will not buy it. 1:46 If your stuff is blocked by Google, 1:51 not going to go there. 1:52 If it's blocked by the antivirus, again failed. 1:56 So he needs to understand all the steps of protection, which you have on your computer, and he needs to simulate them. 2:04 He needs to have the same Windows, with the same update, with the same Windows Defender, with the same browser, and he can know which browser you're using by the previous recon, which he did. 2:17 And having all that information, he can attack you. 2:22 Because it doesn't make sense to attack you with the Windows malware if you're using MacOS. 2:27 So just imagine that, you know, some guys are trying to hack you and they're getting paid to hack you and they prepared all the stuff. 2:37 And they try to attack you, but you are using macros. 2:40 This is like dumb, right? 2:42 It means they didn't do their homework. 2:44 They just attacked you, but they didn't basically prepare. 2:49 So the main stage for social engineering is collection of information. 2:55 You go to LinkedIn. 2:57 You find all the employees of that company. 3:00 And you check their stack. 3:03 For example, developers, what they're developing, what are their skills, which operating system they're using. 3:12 After you go to jobs, what guys they're looking. 3:17 Maybe they're looking for Windows developer or Linux developer. 3:22 Maybe they talk about PHP. 3:24 So you can just go on the job posting website and collect all the information from there. 3:31 After, you can just go to Google and check all their websites and understand which technology they're using, which email provider they're using. 3:41 And during the discussion in LinkedIn, 3:46 That guy, he will be communicating with a very nice lady. 3:52 And that lady is trying to provide him a very cool job. 3:58 And that job is all what he needs to do just to check that website of the job, you know. 4:05 So he will just go to that website. 4:08 Nobody will need to collect his password. 4:11 Nobody will need to collect anything. 4:13 All what that lady, which is not lady, will want to collect is his IP, his operating system, and his browser. 4:25 So next time that lady, which is not lady, will know. 4:30 not send him the link with malware for Windows, he or she will create the malware for Linux because he is using Linux. 4:41 And she understood this because on the user agent, it was written it is Linux. 4:51 See my user agent. 4:54 So let me show you that stuff. 4:57 Google has just blocked me. 4:59 After this training, I'm done. 5:03 So what is my user agent? 5:05 This is basically my browser is saying to the server information about me. 5:17 So basically, 5:21 It is saying that I'm using Windows 64 desktop. 5:28 And it is Windows 11. 5:32 And what else? 5:36 browser, it is showing my screen size. 5:39 So now this server knows about me a lot of information. 5:47 So I will show you 5:51 Something interesting. 5:58 So what is SNFAC? 6:01 Call like this. 6:03 So what is SNFAC? 6:05 SNFAC is specially created for such operations to collect the information about the guy. 6:18 This one, I created this during my work in cyber police to create fake links. 6:29 Which are showing images, but when you watch this image, in the background, it is collecting that information. 6:38 Why do we need this information? 6:40 Because it's information directly links you to the guy. 6:46 If you see his IP address, right? 6:49 You can basically go to internet provider and say, this guy yesterday killed that man. 6:56 This is his AP. 6:58 Who is this person? 6:59 And they're saying, this is the guy. 7:01 He paid like for internet yesterday. 7:04 So this is how the things are working. 7:08 But... 7:10 Let's think from the other side. 7:11 Criminals can also send you this link. 7:14 They can also collect your information and they will know your location, your breaking 7:19 system and all this stuff. 7:21 Now, you got the point. 7:23 When somebody is starting social engineering activity against you, they will collect information about you if they are smart. 7:31 If they are not, they will just send you some random malware and it will never work. 7:39 So there is like spear attack, like targeted attack. 7:44 And there are wide attacks, like widespread. 7:47 Widespread attacks are not meant to, you know, are not meant to be converted on like something like blackmail. 7:59 It is meant to be converted on ransomware. 8:01 It is meant to be converted on mass data stealage. 8:06 It is meant to be converted on the botnet creation. 8:09 So you will be infected, but nobody will be interested, especially like in specific person. 8:15 But if somebody is trying to hack Tesla, for example, 8:20 They will be profiling all the guys who work there. 8:24 They will be profiling their IPs, their operating system, and they will know that, okay, 90% of employees are using Windows, 20% are using Mac. 8:36 So we need to understand that it is better. 8:39 You know, maybe to create Windows malware for those users. 8:46 And I think it makes also sense to create 8:49 the Mac malware. 8:51 So 20% of users who will be using Mac should be redirected to the page with the Mac malware. 8:58 So if you remember, I was showing you VPN update, right? 9:01 That VPN update was for Windows. 9:04 But now let's imagine that we know that by user agent, he's using Mac. 9:09 We will push him Mac. 9:12 So in our server, we'll understand that this guy is accessing from Mac hosts. 9:17 We will show him Mac malware. 9:20 So I'm just giving you some examples that guys who are doing the malware, they know all that stuff. 9:27 And they are, you know, targeting guys badly.
0:00 Music 0:07 Basically, you should understand that penetration tester is not the guy who is just sitting behind the computer and running some crazy scripts. 0:18 A real penetration tester is the guy who knows how to hack basically psychology. 0:27 Of human and he is doing different activities which 0:35 force him to use social engineering because without social engineering he cannot exploit most of vulnerabilities which are on the internet now so for example if we talk about 0:50 exercise vulnerability, which I showed you before. 0:53 You need to ask guy to go to that website, for example, or if you are trying to deliver malware, or if you're trying to deliver the phishing email, right? 1:05 You need to pursue the guy to open email. 1:09 You need to pursue the guy to open SMS. 1:12 You need this guy to, you know, to follow your link, to install your software. 1:19 So... 1:21 It's not only about, you know, the designing of the email. 1:26 It's not that content of that email. 1:30 all together. 1:31 If you will fail on some point, the guy will not buy it. 1:38 If your domain name doesn't make sense, he will not buy it. 1:42 If you don't have HTTPS certificate, guy will not buy it. 1:46 If your stuff is blocked by Google, 1:51 not going to go there. 1:52 If it's blocked by the antivirus, again failed. 1:56 So he needs to understand all the steps of protection, which you have on your computer, and he needs to simulate them. 2:04 He needs to have the same Windows, with the same update, with the same Windows Defender, with the same browser, and he can know which browser you're using by the previous recon, which he did. 2:17 And having all that information, he can attack you. 2:22 Because it doesn't make sense to attack you with the Windows malware if you're using MacOS. 2:27 So just imagine that, you know, some guys are trying to hack you and they're getting paid to hack you and they prepared all the stuff. 2:37 And they try to attack you, but you are using macros. 2:40 This is like dumb, right? 2:42 It means they didn't do their homework. 2:44 They just attacked you, but they didn't basically prepare. 2:49 So the main stage for social engineering is collection of information. 2:55 You go to LinkedIn. 2:57 You find all the employees of that company. 3:00 And you check their stack. 3:03 For example, developers, what they're developing, what are their skills, which operating system they're using. 3:12 After you go to jobs, what guys they're looking. 3:17 Maybe they're looking for Windows developer or Linux developer. 3:22 Maybe they talk about PHP. 3:24 So you can just go on the job posting website and collect all the information from there. 3:31 After, you can just go to Google and check all their websites and understand which technology they're using, which email provider they're using. 3:41 And during the discussion in LinkedIn, 3:46 That guy, he will be communicating with a very nice lady. 3:52 And that lady is trying to provide him a very cool job. 3:58 And that job is all what he needs to do just to check that website of the job, you know. 4:05 So he will just go to that website. 4:08 Nobody will need to collect his password. 4:11 Nobody will need to collect anything. 4:13 All what that lady, which is not lady, will want to collect is his IP, his operating system, and his browser. 4:25 So next time that lady, which is not lady, will know. 4:30 not send him the link with malware for Windows, he or she will create the malware for Linux because he is using Linux. 4:41 And she understood this because on the user agent, it was written it is Linux. 4:51 See my user agent. 4:54 So let me show you that stuff. 4:57 Google has just blocked me. 4:59 After this training, I'm done. 5:03 So what is my user agent? 5:05 This is basically my browser is saying to the server information about me. 5:17 So basically, 5:21 It is saying that I'm using Windows 64 desktop. 5:28 And it is Windows 11. 5:32 And what else? 5:36 browser, it is showing my screen size. 5:39 So now this server knows about me a lot of information. 5:47 So I will show you 5:51 Something interesting. 5:58 So what is SNFAC? 6:01 Call like this. 6:03 So what is SNFAC? 6:05 SNFAC is specially created for such operations to collect the information about the guy. 6:18 This one, I created this during my work in cyber police to create fake links. 6:29 Which are showing images, but when you watch this image, in the background, it is collecting that information. 6:38 Why do we need this information? 6:40 Because it's information directly links you to the guy. 6:46 If you see his IP address, right? 6:49 You can basically go to internet provider and say, this guy yesterday killed that man. 6:56 This is his AP. 6:58 Who is this person? 6:59 And they're saying, this is the guy. 7:01 He paid like for internet yesterday. 7:04 So this is how the things are working. 7:08 But... 7:10 Let's think from the other side. 7:11 Criminals can also send you this link. 7:14 They can also collect your information and they will know your location, your breaking 7:19 system and all this stuff. 7:21 Now, you got the point. 7:23 When somebody is starting social engineering activity against you, they will collect information about you if they are smart. 7:31 If they are not, they will just send you some random malware and it will never work. 7:39 So there is like spear attack, like targeted attack. 7:44 And there are wide attacks, like widespread. 7:47 Widespread attacks are not meant to, you know, are not meant to be converted on like something like blackmail. 7:59 It is meant to be converted on ransomware. 8:01 It is meant to be converted on mass data stealage. 8:06 It is meant to be converted on the botnet creation. 8:09 So you will be infected, but nobody will be interested, especially like in specific person. 8:15 But if somebody is trying to hack Tesla, for example, 8:20 They will be profiling all the guys who work there. 8:24 They will be profiling their IPs, their operating system, and they will know that, okay, 90% of employees are using Windows, 20% are using Mac. 8:36 So we need to understand that it is better. 8:39 You know, maybe to create Windows malware for those users. 8:46 And I think it makes also sense to create 8:49 the Mac malware. 8:51 So 20% of users who will be using Mac should be redirected to the page with the Mac malware. 8:58 So if you remember, I was showing you VPN update, right? 9:01 That VPN update was for Windows. 9:04 But now let's imagine that we know that by user agent, he's using Mac. 9:09 We will push him Mac. 9:12 So in our server, we'll understand that this guy is accessing from Mac hosts. 9:17 We will show him Mac malware. 9:20 So I'm just giving you some examples that guys who are doing the malware, they know all that stuff. 9:27 And they are, you know, targeting guys badly.