Mike Grover - How Hacking Tools Are Changing Cyber Warfare | SRS #164

Shawn Ryan Show
02:34:02 Report Issue
Loading transcript... Click for full transcript

Chapters & Sections (222)

0:15 Introduction and Guest Introduction chapter
0:31 Mike Grover's Background and Work chapter 4
0:31 Connecting with Bryce Case Jr.
1:34 OMG Cable and Red Team Operations
2:05 Gift and Patreon Account Discussion
3:40 Simple Trick Hackers Use to Gain Access
4:41 Introduction and Storytelling chapter 1
4:41 Jumping into a Podcast and Hacking Incident
5:13 Security Controls and Detections chapter 2
5:13 Security Risks and Access Control
7:22 Personal Story and Collaboration
8:22 Personal Experience with a Famous Hacker chapter 3
8:22 Initial Disappointment and Lessons Learned
9:23 The Hacker's Infamy and Treatment
10:27 Meeting the Hacker's Wife and Clearing the Air
12:02 Introduction to Red Teaming and Pen Testing chapter 5
12:02 Red Teaming in Corporate Cyber Security
12:33 The Importance of Execution in Red Teaming
13:04 Kill Chain and Vulnerability Exploitation
13:34 Learning from Help Desk Experience in Security
15:12 Transitioning to a Career in Security
15:42 Introduction and Personal Story chapter 1
15:42 Meeting a New Person and DJing
16:13 Business and Partnerships chapter 4
16:13 New Job Opportunity and Red Team
17:21 Promoting Partnerships and Offers
17:48 Hiring and Job Search Made Easier
18:49 Personal Life and Family
19:20 Childhood Experiences with DIY and Electronics chapter 6
19:20 Growing Up in a DIY Environment
19:51 Learning from Parents' DIY Projects
20:23 Influence of Culinary Interests on Family
20:54 Early Interest in Electronics and Gaming
21:25 First Hardware Hack with Atari Joystick
22:28 Transition to Computer Gaming and Learning
23:00 Introduction to Hacking and Early Interest in Electronics chapter 4
23:00 Learning about Hacking and Inflection Point in Interest
23:34 Early Experiences with Atari and Electronics
24:04 Exploring Water Cooling and Overclocking Computers
25:08 Building a Custom Water Cooling System
26:10 Preventing Corrosion in Electronics chapter 4
26:10 Chemistry Behind Corrosion Prevention
26:41 Hacking and Modifying Game Files
27:11 Adding Custom Content to Games
28:14 Exploiting Game Mechanics and Expectations
29:18 Early Online Communities and Hacking chapter 3
29:18 Introduction to Online Communities and Hacking
30:20 Specific Online Communities and Interactions
31:55 Meeting Wife through Online Community
32:26 Meeting Wife and Marriage chapter
32:57 Understanding Complexity and Human Nature chapter 6
32:57 The Importance of Understanding Individuals
33:28 Hacking and Personal Motivations
33:59 Viewing Hacking as Entertainment
34:30 Exploiting Database Access for Fun
35:01 Chasing Down a Hacker and Lighthearted Moments
36:03 Early Interest in Hacking and Magic
36:34 Deception and Human Aspect chapter 2
36:34 Fake Cigarette and Deception
37:05 Hacking People and Manipulation
37:39 Psychological Triggers in Hacking chapter 3
38:08 Psychological Triggers in Hacking
38:39 Generalist Approach to Security
39:11 ExpressVPN and Online Safety
39:44 Data Security and Online Protection chapter 5
39:44 ExpressVPN for Secure Data Transfer
40:14 Promotion and Sponsorship
41:18 Roa Eyewear and Sleep Improvement
41:49 Personal Experience with Roa Glasses
42:50 Hacker Zine 2600 and Security Hobbies
43:21 The Origins of Hacking with Phones chapter 3
43:21 Introduction to Phone Hacking and Joy Bubbles
44:24 Inband Signaling and the 2600 Hertz Tone
44:56 Blue Boxing and its Connection to Apple's Early Days
46:30 The Early Days of Hacking and the Blue Box chapter 1
46:30 The Blue Box and Red Boxes
47:01 Hacker Culture and Experimentation chapter 4
47:01 Old School Hacking and Mischief
47:33 Exploration and Experimentation with Hacking Tools
48:36 Software Trojans and Pranks
49:08 Using Hacking for Fun and Games
50:08 Personal Anecdotes and Illegal Activities chapter 1
50:08 Spamming and Illegal Activities as a Teenager
50:40 Computer Fraud and Abuse Act (CFAA) and Statute of Limitations chapter 4
50:40 Common Misconceptions about Statute of Limitations
51:10 CFAA and Illegal Access to Electronic Interfaces
51:44 Security Mentorship and First Job Experience
52:47 Physical Security and Social Engineering Examples
53:49 Password Cracking and Management chapter 2
53:49 Introduction to Password Cracking Techniques
54:19 Password Manager Recommendations and Best Practices
56:22 Engineering a Clock for 10,000 Years chapter 1
56:22 Long-term Thinking and the 10,000 Year Clock
57:24 The Origins and Consequences of the Y2K Bug chapter
1:00:01 The Game Industry and Divergent Thinking chapter
1:01:05 Hands-On Hardware Hacking and Hobbyist Projects chapter 2
1:01:05 Introduction to Maker Space and Hobbyist Hacking
1:01:37 Bean Bot Design Philosophy and Aesthetics
1:02:38 Minimalism and Creativity chapter 1
1:02:38 Logic Gates and Binary Math in Bean Bot
1:06:50 Frustration with Mainstream Media and News Sources chapter
1:07:51 Defense Distributed and 3D Printing chapter
1:09:27 The Power of Creation and Artistic Approach chapter 7
1:09:27 The Artistic Process and Politics of Firearms
1:10:00 Bitcoin as an Example of Unstoppable Existence
1:10:31 Helping with Security and Computer Stuff
1:11:34 Motivations for Creating the OMG Cable
1:11:34 Security and Network Help for a Company
1:12:36 Experimenting with Artistic Mediums
1:12:36 Kickstarting Inspiration from the Forefront of 3D Printing
1:13:06 NSA Leaks and Surveillance Technology chapter 2
1:13:06 Snowden and NSA Leaks
1:14:10 Cotton Mouth Cables and Surveillance Capabilities
1:17:18 Discussion of Surveillance Technology chapter 5
1:17:18 Snowden and Spy Gear
1:17:50 Hardware Implants for Surveillance
1:18:53 Customizable Hardware Implants
1:19:24 Long-term Access and Covert Exfiltration
1:20:27 Targeted Surveillance and Gray Area
1:20:57 Privacy Concerns and Government Surveillance chapter 5
1:20:57 Government Surveillance and Internet Providers
1:21:30 Hardware Implants and Targeted Surveillance
1:22:03 Widespread Surveillance and Privacy Invasion
1:22:35 China's Role in Electronics and Surveillance
1:23:05 Software Backdoors and Encryption
1:24:40 Government Surveillance and Secure Communication chapter 3
1:24:40 Government Access to Private Communication
1:25:42 Vulnerabilities in Modern Society and Technology
1:26:14 The Importance of Secure Communication Tools
1:28:22 Contextual Psychology and Surveillance chapter 5
1:28:22 Surveillance and Behavior Modification
1:28:52 Audio and Cellular Surveillance Tools
1:29:22 Tiny Implant Technology and Signal Bouncing
1:30:24 Discussion on Spy Balloon and Surveillance Technology
1:31:27 Unmanned Aerial Vehicles (UAVs) and Surveillance
1:32:00 Exploding Hard Drive and USB Rubber Ducky chapter 5
1:32:00 Inspiration and USB Rubber Ducky Concept
1:33:01 Shrinking the Rubber Ducky and Adding Explosive Payload
1:33:32 Rigging the USB Drive and Creating a Malicious Payload
1:34:35 Liability Concerns and Potential Negative Use Cases
1:35:08 Finding Space for the Malicious Payload in USB Cable Repair Ends and Boots
1:35:38 Designing a Tool for Red Teaming chapter 5
1:35:38 Combining Red Teaming and Prank Concepts
1:36:08 Designing a Tool for Deploying Payloads
1:36:39 Prototyping and Open Sourcing the Tool
1:37:11 Creating a Custom PCB for the Tool
1:38:13 Evolving the Design to Include Complex PCBs
1:39:14 Introduction to OMG Cable and USB Rubber Ducky chapter 3
1:39:14 Explaining the OMG Cable and USB Rubber Ducky Concepts
1:39:45 Early Prototype Tests and Bad USB Research
1:40:48 Scaling Up OMG Cable Production and Manufacturing Challenges
1:42:49 Wi-Fi Pineapple and Network Attacks chapter 2
1:42:49 Wi-Fi Pineapple and Man-in-the-Middle Attacks
1:43:20 Wi-Fi Pineapple and Interception Techniques
1:44:21 Unrelated Topic - Finance chapter 1
1:44:21 Nearfield Communication and Security
1:46:23 Introduction to Rocket Money chapter 1
1:46:23 Rocket Money Features and Benefits
1:47:57 Discussion of OMG Cable chapter 2
1:48:58 OMG Cable Physical Aspect
1:49:29 PCB Design and Integration
1:50:01 Introduction to Wireless Keyboard Emulator chapter 4
1:50:01 Wireless Connection and Remote Access
1:50:31 Internet Connectivity and Password Bypass
1:51:01 Keyboard Emulation Functionality
1:51:34 Intercepting Keystrokes and Unlocking Machines
1:53:07 Introduction to Keystroke Logging chapter 3
1:53:07 Basic Functionality of Keystroke Logging
1:54:07 Keylogging and Trojan Horses
1:54:39 Payloads and Automatic Execution
1:56:12 USB Rubber Ducky and Malware chapter 3
1:56:12 Using USB Rubber Ducky for Malware Deployment
1:57:15 Keylogging and Mouse Injection
1:57:46 Geofencing and Self-Destruct Functionality
1:59:53 Luma Field's Machines and Technology chapter 4
1:59:53 Luma Field's Machines and Applications
2:00:24 CT Scanning Technology and Democratization
2:00:55 Luma Field's Business Model and Partnerships
2:01:59 Hack Five and Red Team Research
2:03:30 Discussion on Red Teaming and Cable Usage chapter
2:03:30 Critical Infrastructure Security and Hid X Stealth Link chapter 2
2:03:30 Red Teaming and Cable Usage Examples
2:06:06 Team Background and Firmware Development
2:07:07 Introduction and Explanation of Key Logger chapter 2
2:07:07 Visual Interface and Controls
2:07:38 Key Logger's Functionality and Automation
2:08:09 Key Logger's Popularity and Marketing chapter 2
2:08:39 Marketing and Traction of Key Logger
2:09:44 Future Plans and Concerns about Abuse
2:10:47 Discussion on Red Team Operations and Security chapter 5
2:10:47 Red Team Professionalism and Corporate Infrastructure
2:12:21 Detectable Defense Faults and Red Cell Operations
2:12:54 Results of Red Team Operations and Intent
2:13:26 Firmware Tool and Self-Destruct Capability
2:13:58 Raising the Bar for Security and Forensic Capabilities
2:14:28 Discussion on Targeted Attacks and Malware chapter 4
2:14:28 Avoiding Counterfeit Products and Targeted Attacks
2:15:00 Comparing Pickpocketing and Sophisticated Attacks
2:15:33 The Bloomberg Grain of Rice Story and Hardware Implants
2:16:05 Controlling Hardware Implants and the Israeli Pager Story
2:18:10 Discussion on Encryption and Surveillance chapter 3
2:18:10 Encryption Methods and Surveillance Avoidance
2:19:47 Risks of Discovery and Stuck Nets Example
2:20:18 Worms, Vulnerabilities, and Discovery Events
2:21:24 Personal Reflections and Business Discussion chapter 5
2:21:24 Counting Patri Situations and Personal Priorities
2:21:54 Business Ideas and Passion for Work
2:22:58 USB Adapters, Keychains, and Data Blockers
2:23:29 Airport Charging Security Concerns and FBI Advisories
2:23:59 Data Blockers, Safe Charging, and Inventions
2:25:02 Discussion on Automation and Manufacturing chapter 4
2:25:02 Desire to Automate Envelope Labeling and Inspiration from Cliff Sto
2:25:32 Exploration of Klein Bottles and Robotic Warehouse System
2:26:04 Discussion on Redesigning and Optimizing Manufacturing Processes
2:27:07 Overview of PCB Assembly Process and Implant Design
2:28:09 Challenges in Running a Hardware Business chapter 1
2:28:09 Compromises in Engineering for Size Constraints and Future Plans
2:29:12 Manufacturing and Quality Control Process chapter
2:29:43 Business Partnerships and Product Availability chapter
2:33:19 Closing Remarks and Call to Action chapter 2
2:33:19 Wishing the Best and Appreciation
2:33:50 Sharing and Reviewing the Show

Transcript

Loading transcript...