The Cyber Mentor
The Cyber Mentor
  • 460
  • 27 431 495
How to Prepare for The Practical Web Penetration Tester Exam
Sponsor a Video: www.tcm.rocks/Sponsors
Pentests & Security Consulting: tcm-sec.com
Get Trained: academy.tcm-sec.com
Get Certified: certifications.tcm-sec.com
Merch: merch.tcm-sec.com
📱Social Media📱
___________________________________________
Twitter: thecybermentor
Twitch: www.twitch.tv/thecybermentor
Instagram: thecybermentor
LinkedIn: www.linkedin.com/in/heathadams
TikTok: tiktok.com/@thecybermentor
Discord: discord.gg/tcm
💸Donate💸
___________________________________________
Like the channel? Please consider supporting me on Patreon:
www.patreon.com/thecybermentor
Support the stream (one-time): streamlabs.com/thecybermentor
Hacker Books:
Penetration Testing: A Hands-On Introduction to Hacking: amzn.to/31GN7iX
The Hacker Playbook 3: amzn.to/34XkIY2
Hacking: The Art of Exploitation: amzn.to/2VchDyL
The Web Application Hacker's Handbook: amzn.to/30Fj21S
Real-World Bug Hunting: A Field Guide to Web Hacking: amzn.to/2V9srOe
Social Engineering: The Science of Human Hacking: amzn.to/31HAmVx
Linux Basics for Hackers: amzn.to/34WvcXP
Python Crash Course, 2nd Edition: amzn.to/30gINu0
Violent Python: amzn.to/2QoGoJn
Black Hat Python: amzn.to/2V9GpQk
My Build:
lg 32gk850g-b 32" Gaming Monitor:amzn.to/30C0qzV
darkFlash Phantom Black ATX Mid-Tower Case: amzn.to/30d1UW1
EVGA 2080TI: amzn.to/30d2lj7
MSI Z390 MotherBoard: amzn.to/30eu5TL
Intel 9700K: amzn.to/2M7hM2p
G.SKILL 32GB DDR4 RAM: amzn.to/2M638Zb
Razer Nommo Chroma Speakers: amzn.to/30bWjiK
Razer BlackWidow Chroma Keyboard: amzn.to/2V7A0or
CORSAIR Pro RBG Gaming Mouse: amzn.to/30hvg4P
Sennheiser RS 175 RF Wireless Headphones: amzn.to/31MOgpu
My Recording Equipment:
Panasonic G85 4K Camera: amzn.to/2Mk9vsf
Logitech C922x Pro Webcam: amzn.to/2LIRxAp
Aston Origin Microphone: amzn.to/2LFtNNE
Rode VideoMicro: amzn.to/309yLKH
Mackie PROFX8V2 Mixer: amzn.to/31HKOMB
Elgato Cam Link 4K: amzn.to/2QlicYx
Elgate Stream Deck: amzn.to/2OlchA5
*We are a participant in the Amazon Services LLC Associates Program, an affiliate advertising program designed to provide a means for us to earn fees by linking to Amazon.com and affiliated sites.
Переглядів: 4 024

Відео

Your Voter Records Reveal A LOT of Info
Переглядів 3 тис.День тому
A huge thank you to DeleteMe for sponsoring today's video! Get 20% off DeleteMe US consumer plans when you go to joindeleteme.com/tcm and use coupon code TCM at checkout! For international users, go to international.joindeleteme.com/tcm and use coupon code TCM for 20% off. Sponsor a Video: www.tcm.rocks/Sponsors Pentests & Security Consulting: tcm-sec.com Get Trained: academy.tcm-sec.com Get Ce...
Fuzz Faster with Turbo Intruder
Переглядів 3,4 тис.День тому
00:00 Introduction to Turbo Intruder 00:35 TCM Security Academy 01:02 Setting up the lab 01:22 Lab Walkthrough 03:08 Account bruteforcing 07:26 Defeating a 60second MFA timer 15:10 Outro Lab: github.com/AppSecExplained/turbo-intruder-lab/tree/main Script: gist.github.com/AppSecExplained/d0af69d525c776267703fa5f9508776a Sponsor a Video: www.tcm.rocks/Sponsors Pentests & Security Consulting: tcm-...
Are IT Certifications Necessary?
Переглядів 7 тис.14 днів тому
Thank you so much to Snyk for sponsoring this video. Sign up for Snyk for free to secure your products from the start: snyk.co/thecybermentor A video on how to network in IT/Cyber: ua-cam.com/video/pJimy574Sh8/v-deo.html A guide with community resources: tcm-sec.com/so-you-want-to-be-a-hacker-2023-edition/ Sponsor a Video: www.tcm.rocks/Sponsors Pentests & Security Consulting: tcm-sec.com Get T...
Three Mental Models for Cybersecurity
Переглядів 5 тис.14 днів тому
Sponsor a Video: www.tcm.rocks/Sponsors Pentests & Security Consulting: tcm-sec.com Get Trained: academy.tcm-sec.com Get Certified: certifications.tcm-sec.com Merch: merch.tcm-sec.com 📱Social Media📱 Twitter: thecybermentor Twitch: www.twitch.tv/thecybermentor Instagram: thecybermentor LinkedIn: www.linkedin.com/in/heathadams TikTok: tiktok.com/@thecybermentor Discord: ...
Designing A Web Application for PWPT
Переглядів 5 тис.21 день тому
00:00 Introduction to designing CTFs 01:35 Overview of building a CTF 04:47 Creating requirements 07:00 Idea and theme creation 08:30 Creating wireframes 09:30 System design and architecture 17:00 Creating design documentation and deciding on the tech stack 23:21 Project management and Kanban 24:57 Outro Sponsor a Video: www.tcm.rocks/Sponsors Pentests & Security Consulting: tcm-sec.com Get Tra...
Exploiting the Front-End: Challenge Walkthrough
Переглядів 3,5 тис.21 день тому
To learn why over 6,000 companies partner with Vanta to automate compliance, strengthen security posture, streamline security reviews, and reduce third-party risk, go to vanta.com/mentor to watch their 3 minute demo video! Resources: Front End Weather App Challenge: github.com/AppSecExplained/frontend-chall-weather-app Sponsor a Video: www.tcm.rocks/Sponsors Pentests & Security Consulting: tcm-...
How to Prevent, Detect, and Respond to Attacks with this Free Tool?
Переглядів 8 тис.Місяць тому
How to Prevent, Detect, and Respond to Attacks with this Free Tool?
Learn Any Programming Language (from scratch)
Переглядів 6 тис.Місяць тому
Learn Any Programming Language (from scratch)
How to Secure Your Email (DMARC, DKIM, SPF Tutorial)
Переглядів 8 тис.Місяць тому
How to Secure Your Email (DMARC, DKIM, SPF Tutorial)
Learn Rust Programming in 2 Hours
Переглядів 7 тис.Місяць тому
Learn Rust Programming in 2 Hours
Do You Need to Know Programming to Be A Hacker?
Переглядів 7 тис.Місяць тому
Do You Need to Know Programming to Be A Hacker?
6 Tips to Stay Motivated
Переглядів 7 тис.Місяць тому
6 Tips to Stay Motivated
Hack Active Directory with LLMNR
Переглядів 7 тис.2 місяці тому
Hack Active Directory with LLMNR
Start Hacking for FREE
Переглядів 27 тис.2 місяці тому
Start Hacking for FREE
Start Your Cybersecurity Career with TryHackMe
Переглядів 14 тис.2 місяці тому
Start Your Cybersecurity Career with TryHackMe
How to Keep Up with Cybersecurity News
Переглядів 10 тис.2 місяці тому
How to Keep Up with Cybersecurity News
Can AI Solve CAPTCHAs?
Переглядів 4,7 тис.2 місяці тому
Can AI Solve CAPTCHAs?
5 Ways To Be More Productive
Переглядів 8 тис.3 місяці тому
5 Ways To Be More Productive
How to Exploit File Disclosure
Переглядів 3,7 тис.3 місяці тому
How to Exploit File Disclosure
Remediate XXE (XML External Entity Injection)
Переглядів 4 тис.3 місяці тому
Remediate XXE (XML External Entity Injection)
3 Ways to Level Up Your Hacking
Переглядів 8 тис.3 місяці тому
3 Ways to Level Up Your Hacking
Build Your Own TryHackMe CTF (from start to finish)
Переглядів 9 тис.3 місяці тому
Build Your Own TryHackMe CTF (from start to finish)
Can AI Fix Vulnerable Code?
Переглядів 3,5 тис.3 місяці тому
Can AI Fix Vulnerable Code?
Getting Started with Hack The Box
Переглядів 23 тис.3 місяці тому
Getting Started with Hack The Box
A Beginners Guide to Code Review
Переглядів 6 тис.3 місяці тому
A Beginners Guide to Code Review
What is a Race Condition? (and how to exploit it)
Переглядів 4,6 тис.3 місяці тому
What is a Race Condition? (and how to exploit it)
Practical Bug Bounty
Переглядів 65 тис.4 місяці тому
Practical Bug Bounty
Turbocharging Your Recon Using ChatGPT
Переглядів 4 тис.4 місяці тому
Turbocharging Your Recon Using ChatGPT
Start Your Cybersecurity Career in 2024
Переглядів 13 тис.4 місяці тому
Start Your Cybersecurity Career in 2024

КОМЕНТАРІ

  • @gurmukhshahani2044
    @gurmukhshahani2044 10 годин тому

    I'm using Macbook air M2 chipset

  • @MehdiGuizani
    @MehdiGuizani 10 годин тому

    Why not use rainbow tables to crack the hasjiesj?😂🌈

  • @gho5tspartan26yt
    @gho5tspartan26yt 15 годин тому

    I started this traveling security job over 2 weeks ago and somehow they hacked my Facebook and bypassed my 2fa phone code and email code. Facebook says that’s my device isn’t recognized on BOTH phones even though I used them for years… please help if you can.

  • @ovisual2161
    @ovisual2161 16 годин тому

    great course, thanks so much

  • @goodgirl9484
    @goodgirl9484 17 годин тому

    is this course for beginners?

  • @dimaryk11
    @dimaryk11 18 годин тому

    If it's a rom how can you write to it

  • @silverruv6220
    @silverruv6220 20 годин тому

    When report writing slide come I was like uh hell no 😂

  • @Andrey_Smirnov
    @Andrey_Smirnov 23 години тому

    how about a9 ip camera?

  • @dimasprajoko
    @dimasprajoko День тому

    Nothing is safe, nothing is unhackable

  • @RejoiceA.
    @RejoiceA. День тому

    hackerone975 thanks for all you do

  • @Naeidea
    @Naeidea День тому

    If he can it so too can the Chinese factory that made it in the country of China that is using every means to undermine the power of the Western countries they ship billions of devices to each year.

  • @jeffking9705
    @jeffking9705 День тому

    4:29:20 was too good lol

  • @jorgegranada4964
    @jorgegranada4964 День тому

    you forgot to mention as a reason for doing this " because its my frogging camera and i enjoy playing with it"

  • @HotNoob
    @HotNoob День тому

    this is how i hack bios passwords for bios that uses eeproms.

  • @RahofAboRefaat-mr2mu
    @RahofAboRefaat-mr2mu День тому

    You have such extensive knowledge and experience in web penetration testing! 🌟 I'm really looking forward to trying out your exam preparation tips. Could you share a specific strategy you find most effective for tackling practical scenarios in the exam? I'd love to hear your insights!

  • @davidhenderson3400
    @davidhenderson3400 День тому

    And just what is on that camera that requires so much protection what did that see

  • @dimasprajoko
    @dimasprajoko День тому

    True act of hacking

  • @aSpyIntheHaus
    @aSpyIntheHaus День тому

    Good stuff mate

  • @Prateek_d_y
    @Prateek_d_y День тому

    i have gone through a lot of setting check but still my browser says "proxy server refusing connections"...

  • @braaap322
    @braaap322 День тому

    Is there any advantage of using a VM over a live USB? I've used VM in the past but after finding live usb I've only. Been using that and it seems a lot more portable and doesn't take up space on my PC .

  • @AngelMaldonado2
    @AngelMaldonado2 2 дні тому

    Is it possible when... 8hs job, sometimes 11hs+ mm maybe 6hs sleep(? I'm scared

  • @stealthyarcher1382
    @stealthyarcher1382 2 дні тому

    Dude thanks. But I wasn’t able to join the domain at this 40:52 point. I’ll figure it out eventually.

  • @jitendravishwakarma9256
    @jitendravishwakarma9256 2 дні тому

    I got a question Is it possible to hire a hacker to delete insta message of someone's elese I actually deleted whole chat at once unfortunately but the messages are still vibile to that person , he has info about me which he might use to blackmail me I need help....:,

  • @lewisfaraitimba4338
    @lewisfaraitimba4338 2 дні тому

    i got it Cert, thank u TCM i got a good job offer this 2024

  • @paddymcgrath605
    @paddymcgrath605 2 дні тому

    As it stands most likely you will get an error 522 from VM workstation player. It's been going on for months since Broadcom took over.

  • @rashidmohamed2626
    @rashidmohamed2626 2 дні тому

    After creating the lab, what is the next program

  • @Devilexon
    @Devilexon 2 дні тому

    Love your vids man i am a 15 year old boy who is really into computers and i really understood the subnetting part and the rest . Keep it up!. This course is amazing. The way you explain is simply great.

  • @rw2783
    @rw2783 2 дні тому

    I have just come across your site today. Thank you for the advice! I really like the look of the TCM courses.

  • @isusmater-qj2rq
    @isusmater-qj2rq 2 дні тому

    REMEMBER GUYS, ALWAYS ASK PERMISSION!!😅

  • @TheQuark6789
    @TheQuark6789 2 дні тому

    Beyond searching for vulnerabilities, this seems useful for confirming there are no backdoors or modifying it to work with the rest of your stuff (since cheap IoT usually comes with garbage apps to control it).

  • @betatester03
    @betatester03 2 дні тому

    Tried to use the coupon code "TCM" at checkout, but it said it was invalid.

  • @thomas_xsg
    @thomas_xsg 3 дні тому

    Wouldn’t the password be hashed? Meaning even if you know where it is, it doesn’t help you?

  • @shawnio
    @shawnio 3 дні тому

    end of the video "I take pictures"

  • @user-wh5mr4tr8u
    @user-wh5mr4tr8u 3 дні тому

    Or goverment uses you to hack muslims😂ethical hacking in my ass

  • @paddymcgrath605
    @paddymcgrath605 3 дні тому

    Just finishing subnet pt1 and found your method so easy, for context about 7yrs ago I did an Open University course on CISCO networking and could not get my head around subnetting, I struggled for weeks with it.. your explanation and cheat sheet had me solving it in minutes.. I am truly stunned.. I'm now so excited for the rest of your course. Thank you.

  • @toby-we3zj
    @toby-we3zj 3 дні тому

    33:21

  • @lexjansenio2933
    @lexjansenio2933 3 дні тому

    This is the stuff I want to see on my feed! I need to do this with my Roku cameras so I can create an NVR to store on my raspberry pi NAS. I have found my people

  • @pavankishore.n2938
    @pavankishore.n2938 3 дні тому

    mnemonic for OSI Models "PLEASE DO NOT TOUCH STEVE PET ALLIGATOR".

  • @silverruv6220
    @silverruv6220 3 дні тому

    Brother I want to hack my coaching system to get my crush no. I don't even know her name only face is this right platform for this?😂

  • @rewolff2
    @rewolff2 3 дні тому

    About 34 years ago I used to do this. But I'd just patch the passwd file to have a hash of a password that I knew. (There was a (common!) configuration error that would allow anyone on the internet to patch /etc/passwd without requiring credentials).

  • @XdekHckr
    @XdekHckr 4 дні тому

    ok but what's the usecase?

  • @Scruff444
    @Scruff444 4 дні тому

    After running the script I am receiving a blank screen in the immunity debugger. Is this the software crashing?

  • @adrianaycock
    @adrianaycock 4 дні тому

    $30 per Month for DK pics is crazy! 🤪

  • @grabasandwich
    @grabasandwich 4 дні тому

    I've been using computers since the early 90s, yet I never tried to learn this kind of stuff. I'd always get easily overwhelmed and give up. But now after 18 years of being a cable guy, I want to do something different. I might not have the means to jump into this, but I gotta start somewhere. I don't know where I'm going with my comment 😑

    • @TCMSecurityAcademy
      @TCMSecurityAcademy 4 дні тому

      If you're interested, we offer a course on hardware hacking led by Andrew in our Academy. And if you join the Academy, Andrew is doing a live workshop just for members on June 27th and July 11th where you'll learn how to hack like he does here. This might be helpful for you if it's something you want to learn! www.tcm.rocks/hh-y

  • @MiDo-by8ib
    @MiDo-by8ib 4 дні тому

    Could someone explain where the number in in the dd command: seek=1048576 comes from? How do you know where the rootfs belongs?

  • @meh.7539
    @meh.7539 4 дні тому

    Check lists for: technologies, vulnerabilities. Schedule regular breaks. Make notes of tests and edge cases to test along the way. My biggest problem is the 'slow down' part. I need to work on being more methodical.

    • @TCMSecurityAcademy
      @TCMSecurityAcademy 4 дні тому

      That's an ongoing thing sometimes. It doesn't come natural to some of us. But trying to slow down and be more mindful can help a lot.

    • @kevinlaurent577
      @kevinlaurent577 2 дні тому

      @@TCMSecurityAcademy Hello, I asked a question also

  • @mamoonbhatti3873
    @mamoonbhatti3873 4 дні тому

    Hello! Can you teach java programming for beginners? Because you teach well than others if you start teaching java programming plz tell me soon as possible it's important for me and if you not so recommend some other channel . Thanks

    • @TCMSecurityAcademy
      @TCMSecurityAcademy 4 дні тому

      ua-cam.com/video/RRubcjpTkks/v-deo.html - Try this for now! And maybe in the future we'll do some Java stuff.

    • @mamoonbhatti3873
      @mamoonbhatti3873 4 дні тому

      Thank you 👍😊

  • @Johan-rm6ec
    @Johan-rm6ec 4 дні тому

    This would be cool in a movie.

  • @kevinlaurent577
    @kevinlaurent577 4 дні тому

    Hello, If you have both certifications are you ready to ewpt? What will be your level with both ?

  • @Denvercoder
    @Denvercoder 4 дні тому

    I'm enrolled in the "Practical Ethical Hacking - The Complete Course" right now and I've been a software developer for 10+ years. Will I be ready for this do you think? Trying to decide between this one and the PNPT.

    • @isaiahkaiver1917
      @isaiahkaiver1917 4 дні тому

      Depends on what you are looking for. If you want to do more Active Directory and internal pentesting then PNPT will be the best route. PWPT looks to be more towards web apps and APIs. Two very different types of tests but similar mindset. If you are already enrolled in PEH I'd recommend doing PNPT then moving over to the PWPT material but it's really up to what interests you more

    • @Denvercoder
      @Denvercoder 4 дні тому

      @@isaiahkaiver1917 I'm probably going to keep my job as a software developer. I mainly want to learn how to attack our own applications.

    • @TCMSecurityAcademy
      @TCMSecurityAcademy 4 дні тому

      The Practical API Hacking and Practical Web Hacking courses would be your best bets to take before the PWPT. But the comment about the PNPT is very valid - you're on the right track for that cert, and you could always try the PWPT in the future.

    • @Denvercoder
      @Denvercoder 4 дні тому

      @@TCMSecurityAcademy If you take the exam and fail and then fail the retake do you have to pay for the whole thing again or can you just pay like a $99 retest fee?

    • @TCMSecurityAcademy
      @TCMSecurityAcademy 4 дні тому

      @@Denvercoder You can retake an exam again if you fail the included retake for $100.