How to make Millions $$$ hacking zero days?

แชร์
ฝัง
  • เผยแพร่เมื่อ 5 ก.พ. 2025

ความคิดเห็น • 183

  • @_JohnHammond
    @_JohnHammond 2 ปีที่แล้ว +35

    You got STEPHEN SIMS to join the party here!??!? JEALOUS!
    Great stuff as always!!

    • @davidbombal
      @davidbombal  2 ปีที่แล้ว +11

      lol... great to see you here John! We need to talk and get you back on the channel!

  • @macktheripper7454
    @macktheripper7454 2 ปีที่แล้ว +74

    What he says about sacrifice is totally right. I wake up at 5am, workout and then study for at least 2 hours before running my business. I’m tired a lot but I’ve completed 3 courses in a little over a year. Starting an api hacking course in January. 💪 thanks for another great video David

    • @bunchiochi
      @bunchiochi 2 ปีที่แล้ว

      Hey bro! Did you have previous experience with APIs before starting API hacking?

    • @macktheripper7454
      @macktheripper7454 2 ปีที่แล้ว +1

      @@bunchiochi nope, not at all. Websites and network based hacking mainly

    • @corail53
      @corail53 2 ปีที่แล้ว +4

      That sounds more like a luxury than a sacrifice. Waking at 5 am is not a special feat and having 2 hours of spare time to be able to study before work is a luxury most don't have.

    • @bunchiochi
      @bunchiochi 2 ปีที่แล้ว +1

      @@macktheripper7454 I was thinking of starting it but thought I had to have some previous knowledge thanks man. Also I apologize for responding late.

    • @macktheripper7454
      @macktheripper7454 2 ปีที่แล้ว +1

      @corail53 it's not a luxury. I have my own business, I'm just efficient at running it.

  • @iamwithyou1184
    @iamwithyou1184 2 ปีที่แล้ว +12

    My request Stephen to complete playlist on Exploit development from beginners to pro level and thanks to David it's an awesome session

  • @davidbombal
    @davidbombal  2 ปีที่แล้ว +26

    It's possible to earn millions of dollars finding zero days and vulnerabilities in software. But, are you prepared to put in the work?
    Browser Exploitation Introduction: th-cam.com/video/bcnV1dbfKcE/w-d-xo.html
    Introduction to Buffer Overflows: th-cam.com/video/DHCuvMfGLSU/w-d-xo.html
    Modern Windows Kernel Exploitation: th-cam.com/video/nauAlHXrkIk/w-d-xo.html
    Linux Heap Exploitation: th-cam.com/video/dMDoC9DlVzA/w-d-xo.html
    Modern Binary/Patch Diffing: th-cam.com/video/8jVOvPG4TjA/w-d-xo.html
    Crypto and Blockchain Hacks: th-cam.com/video/y5JogTgpp-s/w-d-xo.html
    My apologies for some of the technical issues in this interview. Zoom is a nightmare :(
    // MENU //
    00:00 - Coming up
    00:53 - Stephen Sims introduction & Sans course
    03:28 - Stephen's TH-cam channel // Off By One Security
    07:56 - Growing up with computers
    08:57 - Getting involved with Sans courses // Impressed by instructors
    09:52 - "The Golden Age of Hacking" // Bill Gates changed the game
    15:44 - Making money from Zero-Days // Ethical and Unethical methods, zerodium.com & safety tips
    32:56 - How to get started
    46:53 - Opportunities in Crypto
    50:26 - Windows vs. iOS vs. Linux
    53:47 - Which programming language to start with
    56:22 - Recommended Sans courses
    01:02:04 - Recommended CTF programs & events
    01:04:06 - Recommended books
    01:08:23 - The Vergilius project
    01:10:25 - Connect with Stephen Sims
    01:12:24 - Conclusion
    // Stephen's Social //
    Twitter: twitter.com/Steph3nSims
    TH-cam Live: www.youtube.com/@OffByOneSecurity/streams
    TH-cam videos: www.youtube.com/@OffByOneSecurity/videos
    E-mail: Stephen(at)deadlisting.com
    // Stephen's courses //
    SANS Course sans.org. www.sans.org/cyber-security-courses/
    - Advanced exploit development for penetration testers course
    - Advanced penetration testing, exploit writing, and ethical hacking (GXPN)
    - ARM Exploit Development
    // Books discussed //
    Grey Hat Hacking: amzn.to/3B1FeIK
    Hacking: The art of Exploitation: amzn.to/3Us9Uts
    The Shellcoder’s Handbook: amzn.to/3VqUEhY
    Linkers & Loaders: amzn.to/3itqtbe
    // Websites discussed //
    Zerodium: zerodium.com/
    Corelan Cybersecurity Research: www.corelan.be/
    Shellphish: github.com/suljot/shellphish
    Vergilius Project: www.vergiliusproject.com/
    // David's Social //
    Discord: discord.gg/davidbombal
    Twitter: twitter.com/davidbombal
    Instagram: instagram.com/davidbombal
    LinkedIn: www.linkedin.com/in/davidbombal
    Facebook: facebook.com/davidbombal.co
    TikTok: tiktok.com/@davidbombal
    TH-cam Main Channel: th-cam.com/users/davidbombal
    TH-cam Tech Channel: th-cam.com/channels/ZTIRrENWr_rjVoA7BcUE_A.html
    TH-cam Clips Channel: th-cam.com/channels/bY5wGxQgIiAeMdNkW5wM6Q.html
    TH-cam Shorts Channel: th-cam.com/channels/EyCubIF0e8MYi1jkgVepKg.html
    Apple Podcast: davidbombal.wiki/applepodcast
    Spotify Podcast: open.spotify.com/show/3f6k6gERfuriI96efWWLQQ

    • @Blackibangalore
      @Blackibangalore 2 ปีที่แล้ว

      Please share where we can find free classes and books to study sir@ @davidbombal

    • @PortSwigger-ho3ye
      @PortSwigger-ho3ye 2 ปีที่แล้ว

      thanks for posting such a precious content

    • @decoder6878
      @decoder6878 2 ปีที่แล้ว

      Thanks a lot David and Stephen for this wonderful discussion.
      I'm very interested in binary exploration and was looking forward more details on related platforms. This was very helpful.

  • @jamesrobertson2712
    @jamesrobertson2712 2 ปีที่แล้ว +8

    Absolutely fantastic video. I have calculated it will probably take me about 750 years to get anywhere near the level of knowledge displayed here. Either way, I have started writing that Windows driver, using Kernel-Mode Driver Framework (KMDF)...which I had to google.

  • @robd.2466
    @robd.2466 2 ปีที่แล้ว +13

    Tremendous interview, David. Thank you for these. Incredibly interesting and informative.

  • @graham-moss
    @graham-moss 2 ปีที่แล้ว +19

    Love hearing about the more advanced stuff. Having a roadmap is very helpful even if you end up taking a different path. Just knowing how to get started is a huge help.

  • @ANTGPRO
    @ANTGPRO 2 ปีที่แล้ว +10

    Great topic, David. Thanks!

    • @davidbombal
      @davidbombal  2 ปีที่แล้ว +2

      You're welcome! Glad you enjoyed the video :)

  • @ashwanthbalajir5153
    @ashwanthbalajir5153 2 ปีที่แล้ว +12

    This is what I am waiting for. Thanks David

    • @davidbombal
      @davidbombal  2 ปีที่แล้ว +4

      Very happy to hear that!

    • @sudhanshusingh-yo6nc
      @sudhanshusingh-yo6nc 2 ปีที่แล้ว

      @@davidbombal i want learn exploit development in free can you give me roadmap and platform

  • @Naath000
    @Naath000 2 ปีที่แล้ว +4

    thank you david sir for taking stephen sir interview that interview helped me to clearify most of the things for better future

    • @davidbombal
      @davidbombal  2 ปีที่แล้ว +2

      You're welcome! And I'm very happy to that that!

  • @cybercashz
    @cybercashz 2 ปีที่แล้ว +1

    I don't know how you do it , I just searched for exploit development thought would be good for my skill set and you just released this video.
    I love your content helped me alot in my work I really wish you grow more and keep bringing this amazing content. Bless you!!!

  • @kevinnevs2666
    @kevinnevs2666 2 ปีที่แล้ว +9

    Loved this video. Very inspirational & informative. Thank you David.

  • @ragnarok55
    @ragnarok55 2 ปีที่แล้ว +2

    20 years experience guy said you can't be a expert in every subject 👍 but my TH-cam feed destructed myself to learn everything 😂

  • @CyberDevilSec
    @CyberDevilSec 2 ปีที่แล้ว +6

    Awesome stuff David as always 🔥

    • @davidbombal
      @davidbombal  2 ปีที่แล้ว +3

      Thank you! You're welcome :)

    • @CyberDevilSec
      @CyberDevilSec 2 ปีที่แล้ว

      @@davidbombal I do my best 😃

  • @nathanchan1900
    @nathanchan1900 2 ปีที่แล้ว

    Thanks for initiating the talk with Steven. Now, to find some good zero-days for ZDI.

  • @vardhangoud8851
    @vardhangoud8851 2 ปีที่แล้ว +18

    Here is the Game changer content🔥

    • @davidbombal
      @davidbombal  2 ปีที่แล้ว +5

      Hope you enjoy the video Vardhan! Also check out the amazing training that Stephen has on his TH-cam channel.

    • @vardhangoud8851
      @vardhangoud8851 2 ปีที่แล้ว +2

      @@davidbombal In previous video in my comment, one fraud replayed me with ur name like you won something prize Dm in telegram. I just ignored the message

    • @ayushmishra5410
      @ayushmishra5410 2 ปีที่แล้ว

      (@@davidbombal) my chipset supports monitor mode but airodump-ng doesn't show any targets , Anyone knows how to fix ?

  • @ali_linux5097
    @ali_linux5097 2 ปีที่แล้ว +4

    The Best Videos on youtube Thx David for Your Time Giving to us 💖💖💖

  • @itzdm0r3
    @itzdm0r3 ปีที่แล้ว

    Stephen's SANS class sound pretty cool, also good talk!

  •  2 ปีที่แล้ว

    When I hear these topics if feel there's an entire universe to discover in a digital realm.
    One can only learn and specialize a certain direction and still be memorized of the vastness of knowledge, tools, techniques available.

  • @mukbangheat3080
    @mukbangheat3080 2 ปีที่แล้ว +5

    awesome content as always, keep what you're doing. thanks David

  • @rhinofart89
    @rhinofart89 2 ปีที่แล้ว +4

    SANS is the country club in the world of cybersecurity. I’d literally have to pay 1/3 of my yearly salary to take a 6 day course.
    SANS in essence is saying you must already be successful to be successful in cybersecurity.

    • @rhinofart89
      @rhinofart89 2 ปีที่แล้ว +2

      Will definitely be subscribing to his TH-cam channel though.

  • @gilbertohernandez9223
    @gilbertohernandez9223 2 ปีที่แล้ว +1

    We need this guy back asap

  • @CyberDevilSec
    @CyberDevilSec 2 ปีที่แล้ว +1

    I feel like he's my lost brother We have a lot in common.
    I look almost identical to him. Green gray blue eyes stretch etc.
    Secondly i relate to him because I was basically born with a computer and always had a curiosity.
    And I also have the exact same black guitar 😁🎸
    Rock on brother 🤘🤘I hope I can speak with you

  • @emmetgwilliam6527
    @emmetgwilliam6527 2 ปีที่แล้ว +2

    Thanks for the good video on exploits and vulnerability’s I’ve tested a few vulnerabilities before

    • @davidbombal
      @davidbombal  2 ปีที่แล้ว +3

      You're welcome! Stephen has amazing content on his TH-cam channel.

  • @PeterAdiSaputro
    @PeterAdiSaputro ปีที่แล้ว

    Advanced knowledges beyond what I've learned and knew so far. Need to learn a lot more.

  • @davidroach112
    @davidroach112 2 ปีที่แล้ว +1

    Took a Sans class taught by Mr. Simms. The guy is legit.

  • @ThatNiceDutchGuy
    @ThatNiceDutchGuy ปีที่แล้ว +1

    Setting a reasonable goal and path towards it, execute and stick to it. It does sound rather easy, however it is not. Great podcast, as always! Thank you for sharing.

  • @user-uk5qk1zo4k
    @user-uk5qk1zo4k 2 ปีที่แล้ว +1

    Thanks for this one, was looking for ages how to start with a clear roadmap, would be nice to have him back to discuss malwares like Shikitega or eternal blue etc

  • @AMCSec
    @AMCSec 2 ปีที่แล้ว

    My mind in frazzled 😵‍💫 great video!

  • @ranjanadissanayaka5390
    @ranjanadissanayaka5390 2 ปีที่แล้ว +3

    Amazing video... Thanks for both of you.

  • @davidrobertson1980
    @davidrobertson1980 2 ปีที่แล้ว

    Good Onya David, you're a ledge ;) and many thanks to Stephen

  • @lunhamegenogueira1969
    @lunhamegenogueira1969 2 ปีที่แล้ว

    This was a great talk! Thanks for bringing another guru to light lol! Much appreciated!

  • @Chrisnakano
    @Chrisnakano 2 ปีที่แล้ว +5

    Most people are taught that "you only need a good job to become rich". These billionaires are operating on a whole other playbook that many don't even know exists.

  • @PortSwigger-ho3ye
    @PortSwigger-ho3ye 2 ปีที่แล้ว +1

    your content is always FIRE Sir!

  • @cipi5
    @cipi5 2 ปีที่แล้ว

    oh snaps! i love exploit dev training! thanks david!

  • @Z0nd4
    @Z0nd4 2 ปีที่แล้ว

    Amazing, OMG. Awesome content David, thank you very much! I have met these spectacular professionals thanks to your channel

  • @Kodlak15
    @Kodlak15 2 ปีที่แล้ว

    I find this stuff fascinating. Thank you for the talk, appreciate you and your content!

  • @fernandopierola
    @fernandopierola 2 ปีที่แล้ว

    Amazing Video David and Stephens!!! Thanks so so much

  • @notorioussil7646
    @notorioussil7646 2 ปีที่แล้ว

    very very good and interesting interview. Top notch stuff!!

  • @ojochegbe_
    @ojochegbe_ 2 ปีที่แล้ว +2

    Thanks David 🖤❤️

  • @rickrick444x
    @rickrick444x 2 ปีที่แล้ว

    I like your friend skill that behind the curtain and love your videos also 😍😍😍 I m a c.s.e student really want to learn how to work on language but never understand R.I.P mostly one flaw is Indian teachers 😔 they are followed books not any practicals but now a days study is different I m fast a learner in computing and electronics but when I studied my time is bad I have no teacher like today 😔.

  • @prodigyprogrammer3187
    @prodigyprogrammer3187 2 ปีที่แล้ว +2

    Exactly what i wanted

    • @davidbombal
      @davidbombal  2 ปีที่แล้ว +1

      Very happy to hear that!

  • @skytechbits
    @skytechbits 2 ปีที่แล้ว

    I know what the benefit to a company like Verisign would have by buying those exploits that way. They sell SSL certificates which effects every website everywhere. It is a benefit for them to accept top bug bounty finds than to pay employees to look around for such problems that need fixed. Then directly talking to their clients and the corporations who advocates SSL certificates which are becoming a standard. They can go out of business if their SSL become useless. MS now controls hardware with TPM which is their security key.

  • @izzy9ish
    @izzy9ish 2 ปีที่แล้ว +3

    🔥🔥🔥🔥 Content keep them videos coming 🎥

    • @davidbombal
      @davidbombal  2 ปีที่แล้ว +2

      Thank you! Lots of great content coming soon :)

  • @BlacEyedPriest765
    @BlacEyedPriest765 2 ปีที่แล้ว +3

    Thanks David 😊

  • @fsydlx4546
    @fsydlx4546 2 ปีที่แล้ว +2

    Thank You David!

  • @timcyb
    @timcyb 2 ปีที่แล้ว +5

    Thanks for the amazing contents

  • @alisenjary
    @alisenjary 2 ปีที่แล้ว +4

    Thank you 🌹

    • @davidbombal
      @davidbombal  2 ปีที่แล้ว +1

      You’re welcome 😊

  • @ArSiddharth
    @ArSiddharth 2 ปีที่แล้ว +2

    will someone help me,
    my college website is using old version of php (php5)
    So what should I do, See also Exploits of the Exploits Database but they are many,
    There are many vulnerabilities from PHP 5 to the latest version

  • @PhilosophyEpochs
    @PhilosophyEpochs 2 ปีที่แล้ว +3

    love your content sir

  • @jaiminpatel2784
    @jaiminpatel2784 2 ปีที่แล้ว +5

    Thank you sir!

  • @AliRagabali
    @AliRagabali ปีที่แล้ว

    Best video ever on the channel, thank you so much

  • @hakem739
    @hakem739 2 ปีที่แล้ว +1

    Thank you. I love your channel

  • @willredmambo3777
    @willredmambo3777 2 ปีที่แล้ว +2

    Awesome stuff

  • @jarsal_firahel
    @jarsal_firahel 2 ปีที่แล้ว

    Hey David, would you do a video on browser fingerprinting ?

  • @stephenrankin3941
    @stephenrankin3941 2 ปีที่แล้ว

    hey David,
    how would you rate hack the box academy? I've been considering going for their bug bounty hunter course, I'm just wo dering if my time would be better spent somewhere else.

  • @RoyalNatangwe
    @RoyalNatangwe 2 ปีที่แล้ว

    just started my journey in C and Assembly but though this is good information🔥🔥🔥 it is a bit more oriented for intermediate users. wish he recommended books for complete beginners as the way he emphasised on starting with building blocks, books like Hacking the Art of Exploitation when I first bought it, I initially thought it's a complete book but it just made me realise how much I don't know, that I needed to search up more before I understood a certain complex topic.....but ey its life of refusing to be a script kiddie😂😂😂

    • @don156
      @don156 2 ปีที่แล้ว

      If you're just starting in C I think "C Programming Absolute Beginner's Guide" is a great place to start

  • @red-zi7fg
    @red-zi7fg 2 ปีที่แล้ว +1

    David interviewing Matchbox 20 :)

  • @AliYar-Khan
    @AliYar-Khan 2 ปีที่แล้ว

    David you are love man ❤️😇

  • @hendahmed2408
    @hendahmed2408 2 ปีที่แล้ว +1

    is it still not working😢?
    iam starting my pentesting course,
    i have mac m1pro
    so u think i should seal it and buy windows?beacuse as you say some tools doesnt work?

  • @johnhyhintchmn3674
    @johnhyhintchmn3674 2 ปีที่แล้ว

    Cant wait

  • @ghninoumehdi9516
    @ghninoumehdi9516 2 ปีที่แล้ว

    Thank you so much! This is very instructive

  • @nitinjangra653
    @nitinjangra653 2 ปีที่แล้ว +5

    Thanku sir

  • @patrickparson9628
    @patrickparson9628 2 ปีที่แล้ว

    Great work. Beautiful.

  • @NoName-ey9hy
    @NoName-ey9hy 2 ปีที่แล้ว +1

    No fluff❤❤❤

    • @davidbombal
      @davidbombal  2 ปีที่แล้ว +1

      Stephen has amazing content on his TH-cam channel. Please go and subscribe :)

  • @privilegedesign8745
    @privilegedesign8745 2 ปีที่แล้ว

    I have it this PDF book but is really hard go with it when you have some knowledge I stopped for later I need more knowledge

  • @rev.kenshostad2888
    @rev.kenshostad2888 ปีที่แล้ว

    @41:00 Practice makes perfect... PERIOD... Time is the only REAL commodity we have, all have to start somewhere and once known practice practice practice...

  • @brycegalbraith6375
    @brycegalbraith6375 ปีที่แล้ว

    Outstanding.

  • @malua7021
    @malua7021 2 ปีที่แล้ว +1

    Nice David..

  • @ashace6092
    @ashace6092 2 ปีที่แล้ว +1

    Thank you

    • @davidbombal
      @davidbombal  2 ปีที่แล้ว +1

      You're welcome! I hope the video helps you!

  • @MegaFeedee
    @MegaFeedee 2 ปีที่แล้ว +1

    Thank you VERY much for this awesome content, David!
    .
    .
    .
    .
    .
    Corgee hacks you 2 please...

  • @C1t1z3n1
    @C1t1z3n1 2 ปีที่แล้ว

    Have him show us how to do a buffer overflow.

  • @supriyoguha5421
    @supriyoguha5421 2 ปีที่แล้ว

    Amazing Content @David.....

  • @incognitohacks4850
    @incognitohacks4850 2 ปีที่แล้ว

    Would you recommend using a vm or an old laptop you found lying around for practice?

  • @Ghislo
    @Ghislo 2 ปีที่แล้ว

    super inspiring omg thanks for this

  • @pradyumgupta9711
    @pradyumgupta9711 ปีที่แล้ว

    "litigation" is a word used a lot in this video, just wondering what that is exactly with respect to security.
    New in the industry.

  • @marios4275
    @marios4275 หลายเดือนก่อน

    Σας χαιρετω ολους. Δεν κτραταω κακια σε κανενα.

  • @mohammadamiry7385
    @mohammadamiry7385 2 ปีที่แล้ว

    please make of iot full Introduction and about attacking and hacking it I need it for my monograph please

  • @wingwing2683
    @wingwing2683 10 หลายเดือนก่อน

    Thank you very much!

  • @anishgoud651
    @anishgoud651 2 ปีที่แล้ว

    There is any certification for automotive cybersecurity ??

  • @zemourizemouri2406
    @zemourizemouri2406 2 ปีที่แล้ว

    Amazing video!!!

  • @catoshyare969
    @catoshyare969 2 ปีที่แล้ว

    David we want you to make some videos of basics of Linux. help

  • @Nigashm
    @Nigashm 2 ปีที่แล้ว +1

    Thank you sir

  • @WarrenKirkpatrick
    @WarrenKirkpatrick 2 ปีที่แล้ว +1

    Went to check the website out and the beginner course, the fundamentals, was like $7k… I mean wow..

  • @rhinofart89
    @rhinofart89 2 ปีที่แล้ว

    Can he come back and talk about hooking system calls

  • @mujahidAli-eg8qh
    @mujahidAli-eg8qh 2 ปีที่แล้ว +1

    That's Crazy bro

    • @davidbombal
      @davidbombal  2 ปีที่แล้ว +1

      Hope you enjoy the video and learn a lot Mujahid! Also check out the amazing training that Stephen has on his TH-cam channel.

  • @elywacime5411
    @elywacime5411 2 ปีที่แล้ว +1

    Is that a Gibson in the background

  • @420yttsantsujzttad
    @420yttsantsujzttad 2 ปีที่แล้ว +2

    Gud video 👍

  • @Sevo.yt.....
    @Sevo.yt..... 2 ปีที่แล้ว

    My files are encrypted with ransomware can u help to decrypt them

  • @hustle717
    @hustle717 2 ปีที่แล้ว

    TH-camr Jay Williams "Lets live life" recently had his page hacked, any tips on getting it back?

  • @hackmedia7755
    @hackmedia7755 ปีที่แล้ว

    common lisp has a lot of advanced features and doesn't have many security vulnerabilities like many other languages.

  • @michaelnieves8087
    @michaelnieves8087 ปีที่แล้ว

    I can't find that book he mentioned "Journey Into Ring 0"

  • @Oswee
    @Oswee 2 ปีที่แล้ว

    Don't worry. We have a ChatGPT now. You better pick carpentry. :D

  • @yungdnny
    @yungdnny ปีที่แล้ว

    Are you really a hacker if your webcam isn't half frozen? (i'm just teasing bc linux seems to struggle with screen tearing so much and i thought it was my pc)

  • @SiamYaya-s4h
    @SiamYaya-s4h ปีที่แล้ว

    انا ارغب فى هذه البرمجة ولكن لا عرف عنها شي اني صفر هل ممكن ان اتبدي وكم مدة سياخذني

  • @guilherme5094
    @guilherme5094 2 ปีที่แล้ว

    👍👍!

  • @cdcrjp2nft867
    @cdcrjp2nft867 2 ปีที่แล้ว

    I been validating exploits on multiple platforms still no deal

  • @MAGICIANHACKERS
    @MAGICIANHACKERS 2 ปีที่แล้ว

    Hello, is there a virus for all platforms?

  • @MutinyInteractive
    @MutinyInteractive 2 ปีที่แล้ว +1

    This is why coding instructor are NEVER GOOD, at 35:15…. A good teacher can recognize a student savant who learns backwards. Those are usually the most talented and naturally inclined individuals on the planet per their respective interests
    Dave Chappelle, he writes his jokes backwards…. Same way I do, he doesn’t seem like someone who can recognize the ability to reverse engineer and have that actually be the better teaching instrument than not, he doesn’t have that radar

  • @PUIT1280
    @PUIT1280 2 ปีที่แล้ว +1

    ❤😊