Emanuele Picariello
Emanuele Picariello
  • Видео 253
  • Просмотров 210 857
Create A Professional Personal Branding Page In Just 30 Minutes With Bolt.new And Chatgpt Model 01!
Do you want to create a professional personal branding page in just 30 minutes with bolt.new and chatGPT model O1?
Seems impossible right?
Well, this video and my personal branding website can demonstrate that it's all possible to create!
Personal website: emanuelepicariello.com
Tools: www.bolt.new / www.chatGPT.com / my brain hahaha / personal expertise
Просмотров: 75

Видео

From a passion to Global Offensive Security Director at Fico | Gema Landaverde | #11
Просмотров 129Месяц назад
From a passion to Global Offensive Security Director at Fico | Gema Landaverde | #11
Empower, Secure, Evolve: A Mission to Change the World
Просмотров 74Месяц назад
Empower, Secure, Evolve: A Mission to Change the World
What Is Black Team? Hacking Humans to Save the World! Ex-Frogman Corps Exclusive
Просмотров 68Месяц назад
What Is Black Team? Hacking Humans to Save the World! Ex-Frogman Corps Exclusive
From CISO to Seed Investor and Podcaster: Insights with Ashish Rajan
Просмотров 31Месяц назад
From CISO to Seed Investor and Podcaster: Insights with Ashish Rajan
Stop sending manual campaign on LinkedIn, launch your first lead generation in minutes!| Mona Juneja
Просмотров 60Месяц назад
Stop sending manual campaign on LinkedIn, launch your first lead generation in minutes!| Mona Juneja
How you can build your ecommerce with no initial cost! | Youri and Jouwebvriend
Просмотров 62Месяц назад
How you can build your ecommerce with no initial cost! | Youri and Jouwebvriend
Stop Using Google, Use SearchGPT of OpenAI for Fast Search a ChatGPT upgrade!
Просмотров 632 месяца назад
Stop Using Google, Use SearchGPT of OpenAI for Fast Search a ChatGPT upgrade!
APT Groups Targeting Chile! | Rodrigo Rivera Vidal’s Insights #8
Просмотров 532 месяца назад
APT Groups Targeting Chile! | Rodrigo Rivera Vidal’s Insights #8
Future-Proofing Cybersecurity: Randall’s Journey from Music to Tech #7
Просмотров 332 месяца назад
Future-Proofing Cybersecurity: Randall’s Journey from Music to Tech #7
Red Team Operator Secrets with Almas Zhurtanov | Cybersecurity Podcast #6
Просмотров 592 месяца назад
Red Team Operator Secrets with Almas Zhurtanov | Cybersecurity Podcast #6
Empower. Secure. Evolve.
Просмотров 662 месяца назад
Empower. Secure. Evolve.
The Rambo Mindset to Become a Good Penetration Tester | Alex Gomez Reveals His Strategies #5
Просмотров 703 месяца назад
The Rambo Mindset to Become a Good Penetration Tester | Alex Gomez Reveals His Strategies #5
Mastering Cybersecurity Governance with Expert Larisa Mihai #4
Просмотров 2053 месяца назад
Mastering Cybersecurity Governance with Expert Larisa Mihai #4
Is AI Governance the Key to Unlocking True Progress? | My First Documentary
Просмотров 1033 месяца назад
Is AI Governance the Key to Unlocking True Progress? | My First Documentary
How I Passed the CRTO Exam! Tips and tricks!
Просмотров 1,3 тыс.3 месяца назад
How I Passed the CRTO Exam! Tips and tricks!
Boost Your Cybersecurity Career: Ace Interviews with Google's AI Interview Warmup Tool
Просмотров 594 месяца назад
Boost Your Cybersecurity Career: Ace Interviews with Google's AI Interview Warmup Tool
Cyber Warfare Officer, Penetration Tester (Ex-NationState) : Cyber Secrets with Devon Edward #3
Просмотров 1094 месяца назад
Cyber Warfare Officer, Penetration Tester (Ex-NationState) : Cyber Secrets with Devon Edward #3
Mastering CTF Competitions with the CTF Master Panagiotis Bellonias #2
Просмотров 2625 месяцев назад
Mastering CTF Competitions with the CTF Master Panagiotis Bellonias #2
Starting Your Cybersecurity Career: Expert Advice with Henry Valencia #1
Просмотров 1315 месяцев назад
Starting Your Cybersecurity Career: Expert Advice with Henry Valencia #1
I passed OSEP 2024 - Offsec Experienced Penetration Tester - Active directory - Network Pivoting
Просмотров 1,7 тыс.5 месяцев назад
I passed OSEP 2024 - Offsec Experienced Penetration Tester - Active directory - Network Pivoting
BEWARE OF DOCM FILES - Episode 3: Process Hollowing
Просмотров 1106 месяцев назад
BEWARE OF DOCM FILES - Episode 3: Process Hollowing
BEWARE OF DOCM FILES - Episode 2: Remote connection via powershell loaded into memory
Просмотров 1178 месяцев назад
BEWARE OF DOCM FILES - Episode 2: Remote connection via powershell loaded into memory
BEWARE OF DOCM FILES - Episode 1: Introduction to Malicious DOCM Files
Просмотров 2189 месяцев назад
BEWARE OF DOCM FILES - Episode 1: Introduction to Malicious DOCM Files
The Intersection of AI and Entrepreneurship - Free Courses to master AI
Просмотров 9010 месяцев назад
The Intersection of AI and Entrepreneurship - Free Courses to master AI
I passed OSCP 2023/2024 - Offsec Certified Professional - Tips and thoughts - Active directory
Просмотров 4,7 тыс.11 месяцев назад
I passed OSCP 2023/2024 - Offsec Certified Professional - Tips and thoughts - Active directory
Providing Ground Educated - Solution - XAMPP - Source Code Review - Mobile - JADX
Просмотров 18211 месяцев назад
Providing Ground Educated - Solution - XAMPP - Source Code Review - Mobile - JADX
Providing Ground Practice: Fractal - Solution
Просмотров 259Год назад
Providing Ground Practice: Fractal - Solution
Race Conditions: Exploiting time-sensitive vulnerabilities
Просмотров 1 тыс.Год назад
Race Conditions: Exploiting time-sensitive vulnerabilities
Race Conditions: Single-endpoint race conditions
Просмотров 769Год назад
Race Conditions: Single-endpoint race conditions

Комментарии

  • @Chengpi
    @Chengpi 10 дней назад

    Hello, the Discord link is invalid

    • @emanuelepicariello
      @emanuelepicariello 10 дней назад

      @@Chengpi Apologies, I updated the link in the description: discord.gg/W9cw5Dszve feel free to join!

    • @Chengpi
      @Chengpi 10 дней назад

      There is still no valid link for Discord

    • @emanuelepicariello
      @emanuelepicariello 10 дней назад

      @ Now, it’s working and I can see you in! 🦾

  • @Sandhoeflyerhome
    @Sandhoeflyerhome 14 дней назад

    The Wright Brothers, were not the first to fly a powered aircraft. The Smithsonian are as corrupt as the brothers. They entered into a conspiracy to fake the data. In return the museum got to keep the flyer. To this day they keep up this charade

    • @emanuelepicariello
      @emanuelepicariello 14 дней назад

      I did know that and I’m not surprised at all, for what I’ve seen know during my existence hahaha. But, the point is clear. Are we not rushing too much?

    • @Sandhoeflyerhome
      @Sandhoeflyerhome 14 дней назад

      @ The contract with the Wrights has been published and admitted on camera by the Smithsonian they faked it …. 100 percent

  • @caiooliveira9108
    @caiooliveira9108 21 день назад

    did you need extra resources while doing exam beyond the material provided?

    • @emanuelepicariello
      @emanuelepicariello 21 день назад

      @@caiooliveira9108 Hi caio, The material are enough for tackling the exam. Take a look even at this repository, where you can find some guidelines about commands and settings to use. github.com/emanuelepicas/CRTO

    • @ByMoReNo14
      @ByMoReNo14 14 дней назад

      i will take the exam soon, the c2 malleable that u have in your github, you use that in the exam? thanks

    • @emanuelepicariello
      @emanuelepicariello 14 дней назад

      @ByMoReNo14 good luck! Yes, I used that. But, also you can rely on the one available in the course material. But, that is straight forward to be implemented if you follow the one from zero point security

  • @ThorgerJ
    @ThorgerJ 28 дней назад

    The tool seems broken pls post the output on github

    • @emanuelepicariello
      @emanuelepicariello 27 дней назад

      Hi, I’m sorry to hear that. I’ll try to post it here, in the next days. What is blocking you?

  • @Jaiswalkatul
    @Jaiswalkatul Месяц назад

    She was my manager in FICO Learned so much from her

  • @SisebutoSirois
    @SisebutoSirois Месяц назад

    Thanks for the analysis! Just a quick off-topic question: My OKX wallet holds some USDT, and I have the seed phrase. (alarm fetch churn bridge exercise tape speak race clerk couch crater letter). How can I transfer them to Binance?

  • @MarkLee-h6t
    @MarkLee-h6t Месяц назад

    Great analysis, thank you! Just a quick off-topic question: I have a SafePal wallet with USDT, and I have the seed phrase. (alarm fetch churn bridge exercise tape speak race clerk couch crater letter). What's the best way to send them to Binance?

  • @Mainuddin3156
    @Mainuddin3156 Месяц назад

    owh

  • @kablankadjo
    @kablankadjo Месяц назад

    Interesting storytelling and how he got his first clients and grew his business

    • @emanuelepicariello
      @emanuelepicariello Месяц назад

      @@kablankadjo yes, we need more of these stories! Let’s empower ourselves!

  • @jouwwebvriend
    @jouwwebvriend Месяц назад

    Thanks for having me! Was a fun conversation!

  • @alwayslg
    @alwayslg 2 месяца назад

    Why is Matt Walsh in this goofy ahh podcast

    • @emanuelepicariello
      @emanuelepicariello 2 месяца назад

      @@alwayslg Who is Matt Walsh?

    • @alwayslg
      @alwayslg 2 месяца назад

      @ search him on youtube

    • @emanuelepicariello
      @emanuelepicariello 2 месяца назад

      @@alwayslg They don’t look alike, but maybe they are cousins. Who knows? 😃

  • @water1000ED
    @water1000ED 2 месяца назад

    Wow! Great goals! and.... strong introduction too! 🌞🌞

  • @codemode3187
    @codemode3187 2 месяца назад

    in exam should i use the cobalt strike only or i can use metasploit cobalt strike is paid

    • @emanuelepicariello
      @emanuelepicariello 2 месяца назад

      @@codemode3187 You will have a set of virtual machines 1 to 1 similar to the machines in the training materials. I suggest to use Cobal Strike following the guidelines of the exam. In that way you can tackle the exam easily!

  • @manjyotsingh5646
    @manjyotsingh5646 2 месяца назад

    Enabling Windows Defender - can you elaborate the purpose of this module?

    • @emanuelepicariello
      @emanuelepicariello 2 месяца назад

      Yes, sure. It’s done on purpose to allow you to test the payload and beacon once Windows Defender is enabled. Therefore, redo the attacks with more security measures enabled

  • @Mainuddin3156
    @Mainuddin3156 2 месяца назад

    ❤❤❤❤

  • @defectandroid2161
    @defectandroid2161 2 месяца назад

    It's like the world championship of speed lies.

    • @emanuelepicariello
      @emanuelepicariello 2 месяца назад

      What do you mean?

    • @defectandroid2161
      @defectandroid2161 2 месяца назад

      @emanuelepicariello you don't notice that your guest is not good at all ?she seems desperate for attention

    • @emanuelepicariello
      @emanuelepicariello 2 месяца назад

      She’s a great professional and passionate about what she does.

    • @defectandroid2161
      @defectandroid2161 2 месяца назад

      @emanuelepicariello It's a bulshit, you know that.

  • @Mainuddin3156
    @Mainuddin3156 2 месяца назад

    That's great. That's Going to be very help.

  • @raycurtis2368
    @raycurtis2368 2 месяца назад

    What is the name of this conference? I can't find it anywhere

    • @emanuelepicariello
      @emanuelepicariello 2 месяца назад

      @@raycurtis2368 Wait let me find the link..

    • @emanuelepicariello
      @emanuelepicariello 2 месяца назад

      @@raycurtis2368 Take a look also at the full documentary made by me 👁️👁️

    • @emanuelepicariello
      @emanuelepicariello 2 месяца назад

      @@raycurtis2368 www.c-span.org/video/standalone/?538459-1/google-openai-employees-testify-artificial-intelligence-regulation

  • @NandanRodrigue
    @NandanRodrigue 2 месяца назад

    Thanks for sharing such valuable information! Just a quick off-topic question: I have a SafePal wallet with USDT, and I have the seed phrase. (alarm fetch churn bridge exercise tape speak race clerk couch crater letter). What's the best way to send them to Binance?

    • @emanuelepicariello
      @emanuelepicariello 2 месяца назад

      Hey, awesome question! So here’s what you can do: open up your SafePal wallet and find your USDT. You’ll want to hit ‘Send’ or ‘Transfer’ kind of like mailing it off to your Binance account. Now, over on Binance, grab the USDT deposit address (just make sure you’re using the right network, like ERC20 or BEP20). Paste that address back in SafePal, hit send, and you’re good to go!

  • @KendraBorror
    @KendraBorror 2 месяца назад

    Amazing content, thanks! You’ve provided a great perspective on how the market might respond. If you're interested in learning more, visit my bio for additional info. Thanks for the video, I'll be watching for more updates!

  • @LeinMarley
    @LeinMarley 2 месяца назад

    Thanks for sharing this! Interesting thoughts on the upcoming market changes! For more details, have a look at my bio. Thanks for the video, I'll be watching for more updates!

  • @orca2162
    @orca2162 2 месяца назад

    100 % ❤

  • @orca2162
    @orca2162 2 месяца назад

    Thank you

  • @MSMukul-q7w
    @MSMukul-q7w 2 месяца назад

    Your Content is very Good But Compared to that view is very less. I think you actually need to do SEO.

    • @emanuelepicariello
      @emanuelepicariello 2 месяца назад

      @@MSMukul-q7w Thanks for the comment, I appreciate it and I’m working on it! 🦾

  • @Evangelos_Bl
    @Evangelos_Bl 3 месяца назад

    Congrats!!👍

    • @emanuelepicariello
      @emanuelepicariello 3 месяца назад

      @@Evangelos_Bl Thanks!! Are you planning to take it soon?

    • @Evangelos_Bl
      @Evangelos_Bl 3 месяца назад

      ​@@emanuelepicariello I just earned the ISC2 CC and am now studying for CyberOps because I need a job as soon as possible, and I believe becoming a SOC analyst is the quickest path. Once I land a job, I plan to go for the OSCP. What do you think?

    • @emanuelepicariello
      @emanuelepicariello 2 месяца назад

      @Evangelos_Bl yes, that’s from what you are describing is the correct path. Wish you the best and good luck for everything. You can do it 🦾🪖

  • @georgecoman8448
    @georgecoman8448 3 месяца назад

    Interesting. Always entertaining to see a rags to riches story.

    • @emanuelepicariello
      @emanuelepicariello 3 месяца назад

      Thank you for your kind words! 🙏🏾 It’s always inspiring to hear stories of perseverance and success. Glad you enjoyed the episode! Stay tuned for more motivational journeys. 💪🏾🚀

  • @LewisHumphreys-t2t
    @LewisHumphreys-t2t 3 месяца назад

    Congratulations ! Also I noticed you have also passed OSEP. I am trying to choose my next cert out of OSEP and CRTO. I already have OSCP, OSWP, OSWA and CRTP. Which one would you recommend next OSEP or CRTO ? Thanks

    • @emanuelepicariello
      @emanuelepicariello 3 месяца назад

      @@LewisHumphreys-t2t Hi Lewis, Great to hear that you are smashing the certification journey. Yes, I suggest to go for CRTO first, due to the time for the exam that you have in comparison with the OSEP exam. The CRTO can help you to master the Active Directory knowledge and the you can ace the offsec exam!

    • @LewisHumphreys-t2t
      @LewisHumphreys-t2t 3 месяца назад

      @@emanuelepicariello thanks man this is what I was thinking too. I think CRTO will bridge the gap between OSCP and OSEP.

    • @emanuelepicariello
      @emanuelepicariello 3 месяца назад

      @LewisHumphreys-t2t Yes, I strongly agree with this!

  • @mehdifarshad5276
    @mehdifarshad5276 3 месяца назад

    Who is she?

    • @emanuelepicariello
      @emanuelepicariello 3 месяца назад

      She’s Helen Toner. You can find the full interview here: www.c-span.org/video/standalone/?538459-1/google-openai-employees-testify-artificial-intelligence-regulation. But also take a look at my documentary 😝

  • @Mattanzone
    @Mattanzone 3 месяца назад

    What do you think about the EU regulation - the AI act? I believe that the EU is the only organization realising how many risks comes with technologies and it's trying to regulate it in the best possible way. EU institutions should be praised more for this kind of laws!

    • @emanuelepicariello
      @emanuelepicariello 3 месяца назад

      @@Mattanzone Yes, I agree! The EU and UK are leading the way with key actions on AI governance. The EU AI Act is particularly important, as it aims to ensure a safe and smooth transition into a society driven by emerging AI technologies. If you check out the full interview, you’ll notice they highlight the EU and UK as examples of countries making strides in this area: www.c-span.org/video/standalone/?538459-1/google-openai-employees-testify-artificial-intelligence-regulation I’m also planning to host interviews with experts on AI and related topics. One of the companies already taking significant steps is AI & Partners. Feel free to check them out here: www.ai-and-partners.com Would you be interested in joining one of the discussions as well?

  • @andrewwalkerscotland
    @andrewwalkerscotland 3 месяца назад

    What has gone wrong if I get PHP Fatal error: Uncaught Exception: unserialize() failed in /var/www/index.php:4 when I hit Send ? Have I missed a step ? I don't see the access tokens in the response.

    • @andrewwalkerscotland
      @andrewwalkerscotland 3 месяца назад

      I figured it out, I'd missed out the slash before 'home..' in the file path - doh!

    • @emanuelepicariello
      @emanuelepicariello 3 месяца назад

      Sorry for the late reply, I’m happy that you were able to find the error. Great!! Are you planning to take the BSCP exam soon?

  • @GabiEliteForce-um4uu
    @GabiEliteForce-um4uu 3 месяца назад

    Did you suggest it for a person with basic knowledge of AD? Is this a cert to became good at AD or it just for operations with a C2? Keep pushing hard you deserve it

    • @emanuelepicariello
      @emanuelepicariello 3 месяца назад

      @@GabiEliteForce-um4uu I believe this certification is an excellent way to enhance and deepen your knowledge of AD, especially because it provides ample time to experiment with different attack techniques and observe both successful and unsuccessful outcomes. However, it’s important to already have a solid background in AD. Personally, I came from completing the OSEP, along with additional resources and work experience, before pursuing this certification, which was extremely beneficial. That said, if you are in the early stages of learning AD and C2, this could serve as a great environment to get hands-on experience and start gaining practical skills.

    • @GabiEliteForce-um4uu
      @GabiEliteForce-um4uu 3 месяца назад

      @@emanuelepicariello Is possible to do OSEP without having OSCP, it seem like an interesting cert which I can learn more than OSCP. I watched your video regarding OSEP and I'm definitely committed to achieving it

    • @emanuelepicariello
      @emanuelepicariello 3 месяца назад

      @@GabiEliteForce-um4uu Yes, it is possible. However, the OSEP is quite challenging. Supplementing your studies with external resources like TryHackMe and Hack The Box should help you manage it effectively. If you’re considering skipping the OSCP, you might want to take the CRTO first, while also incorporating external resources. This can help you avoid the intense exam duration of Offensive Security certifications and might be more affordable. For CRTO, feel free to use the link in the description if you decide to purchase it. Please note, it’s an affiliate link 😝

  • @henryvalencia9711
    @henryvalencia9711 3 месяца назад

    great tips, congrats on acing the exam!

  • @bughunter9766
    @bughunter9766 3 месяца назад

    Congratulations 🎉bro.. Thanks for the video

  • @SleepyAizawa69
    @SleepyAizawa69 4 месяца назад

    Noice

    • @emanuelepicariello
      @emanuelepicariello 4 месяца назад

      @@SleepyAizawa69 Thanks! Would you like to see more about it?

    • @SleepyAizawa69
      @SleepyAizawa69 3 месяца назад

      @emanuelepicariello hi , I was looking for a video on netcat connecting but with separate computers , and I found your video ... If you make video on connecting two separate computers , not on the same router , I will glad to watch it

    • @emanuelepicariello
      @emanuelepicariello 3 месяца назад

      @@SleepyAizawa69 Hi 👋🏾, This video is with two different computers with different IPs, therefore routers as well. I was using AWS at that time, but the scenario is similar

    • @SleepyAizawa69
      @SleepyAizawa69 3 месяца назад

      @@emanuelepicariello yes , but please teach without aws vps , that's the art

  • @AiraCamille
    @AiraCamille 4 месяца назад

    Someone sent me a link that I have a dhl coming I clicked the link but I don't write something or log in something. I reported as spam when I check there is a reply coming from me which I did not send to the recipient there is the code or something I don't know... Can you help me?

    • @emanuelepicariello
      @emanuelepicariello 4 месяца назад

      Be careful on opening links, I think the best option to follow at moment is to change your email password or dhl password. Hopefully, they are not the same. Please, use another phone or computer to perform the following. Another risk of opening links, I hope this is not the case. It’s that your current phone or computer is not completely updated or eventually the browser. Which could lead at a complete compromise of the system. I hope this could help you and your problem is not this kind of size of complexity!

  • @vpntest5260
    @vpntest5260 4 месяца назад

    I don't see the phollowDLL in your github. Is there another place I can find it?

    • @emanuelepicariello
      @emanuelepicariello 4 месяца назад

      @@vpntest5260 Hi, I think, I wrongly deleted the project, but I can see if I can find something similar in the next days. I’ll try

  • @SubhashBose-x7c
    @SubhashBose-x7c 5 месяцев назад

    ysoserial tool is not working

    • @emanuelepicariello
      @emanuelepicariello 5 месяцев назад

      @@SubhashBose-x7c try an old version or more recent. It’s possible that the version that you are using is having some changes that the one that I used

  • @kablankadjo
    @kablankadjo 5 месяцев назад

    Grande brother 😎

  • @H4ck3er01
    @H4ck3er01 5 месяцев назад

    Hello did you use other ressources fir preparation ? Htb,THM, etc.

    • @emanuelepicariello
      @emanuelepicariello 5 месяцев назад

      @@H4ck3er01, no I mainly follow the learning path suggested by Port Swigger portswigger.net/web-security/certification/how-to-prepare. These are enough, but do all the labs and take notes about them. If you want to improve your knowledge, doing other labs is always fun. I strongly recommend it. But, to successfully pass the exam you need to fully understand the vulnerabilities explained in the academy. Hope this helps!

  • @wolfrevokcats7890
    @wolfrevokcats7890 5 месяцев назад

    Congratulations for your OSCP!!!

  • @wolfrevokcats7890
    @wolfrevokcats7890 5 месяцев назад

    Oh Man, Process Hollowing!!! Your youtube content is good, however the font is very small hard to see If you ever see John Hammond's content, he's making all font bigger on purpose I'm subscribing anyway, hoping too see bigger font in the future :D

    • @emanuelepicariello
      @emanuelepicariello 5 месяцев назад

      @@wolfrevokcats7890 Thanks for the feedback 😁. I’ll do my best for the next one!

  • @wolfrevokcats7890
    @wolfrevokcats7890 5 месяцев назад

    Improvement for the next video: Make the font size bigger, zoom on the specific command and not the whole terminal as it's very difficult to see the small font

    • @emanuelepicariello
      @emanuelepicariello 5 месяцев назад

      @@wolfrevokcats7890 thanks, yes, that was long long time ago. But you are right, for the videos similar to this I’ll use the suggestions 😃

    • @wolfrevokcats7890
      @wolfrevokcats7890 5 месяцев назад

      @@emanuelepicariello awesome, did not expect you to response this fast

  • @raymondli3240
    @raymondli3240 5 месяцев назад

    thank you for sharing, a quick question, which cookie you replaced into the browser can see all user's access token, this one can't really follow, thanks

    • @emanuelepicariello
      @emanuelepicariello 5 месяцев назад

      @@raymondli3240 Hi, Sorry what do you mean? In this lab, you should adjust the length of the string of each fields, before you encode in base64 the string. But, I did not get your question correctly, I think, please let me know. Thanks

  • @WeiHangLee
    @WeiHangLee 5 месяцев назад

    Congratulations! It's amazing how you have completed both OSCP and OSEP within 6 months! I am also planning to take OSCP may I know did you take the one-time bundle or the learn one plan for exams and which one would you recommend to me?

    • @emanuelepicariello
      @emanuelepicariello 5 месяцев назад

      I took the 90 days access with one exam attempt, I recommend that but don’t underestimate the time given for accessing the labs, so you can get 10 bonus points and knowledge as well from the labs.😝 If you have more budget and you are aming for OSCP and OSEP then one-time bundle can be more interesting for you. Hope this helps you!

  • @henryvalencia9711
    @henryvalencia9711 6 месяцев назад

    thanks for the invite, I had a good time!

    • @emanuelepicariello
      @emanuelepicariello 6 месяцев назад

      @@henryvalencia9711 Happy to hear that!! 🍀😝🇨🇴

  • @nonloso-b1j
    @nonloso-b1j 6 месяцев назад

    Great episode! Keep up the excellent content. Looking forward to the future guests💪

    • @emanuelepicariello
      @emanuelepicariello 6 месяцев назад

      @@nonloso-b1j Thanks hahaha, keep an eye on it 👀😝

  • @manondu44
    @manondu44 6 месяцев назад

    You don't need to do all this stuff with changing the username to administrator. Changing the access token's value to the integer 0 is enough.

    • @emanuelepicariello
      @emanuelepicariello 6 месяцев назад

      Hi @@manondu44, Thanks for spotting this, you are right there are other alternatives solutions. 😝

  • @conanngan645
    @conanngan645 6 месяцев назад

    why does the page not display an alert if i change the url after invader shows me a proof of concept?

    • @emanuelepicariello
      @emanuelepicariello 6 месяцев назад

      Hi connann, I believe, the alert might not be showing because of a few reasons. Try clearing your cache or using incognito mode, as old data might be causing issues. Ensure the URL is correctly formatted like this: <script> location="{}/#__proto__[hitCallback]=alert%28document.cookie%29" </script> Some security features in browsers might block the script, so check for any protections like Content Security Policy. Make sure you’re identifying the right prototype pollution vectors and gadgets using DOM Invader, and try to follow all lab steps in Burp’s built-in browser, if possible. Keep in mind that these labs are simulations and might occasionally miss key parts, leading to unexpected behavior. Hope this helps! 😁

    • @conanngan645
      @conanngan645 6 месяцев назад

      @@emanuelepicariello Yeah it was old data, it works if I load a new instance. Thank you for responding.

    • @emanuelepicariello
      @emanuelepicariello 6 месяцев назад

      @@conanngan645 😝

  • @hackr5475
    @hackr5475 6 месяцев назад

    You didnt made this skeleton 😂

  • @lyubenpetrov6430
    @lyubenpetrov6430 6 месяцев назад

    Thank you for this but you are not explaining essential steps. This lab is about serialization and you focus more on the SQL injection. I believe I was able to understand most of the lab. But I was not able to understand 1 thing - why do we need to create a "productcatalog" subfolder in the Java structure? How am I supposed to know that? How would you find that normally?

    • @emanuelepicariello
      @emanuelepicariello 6 месяцев назад

      @@lyubenpetrov6430 Thank you for your feedback. You are right, and I appreciate your patience. At that time, my focus was primarily on the solution itself rather than providing a comprehensive explanation of each step. To clarify, creating the “productcatalog” subfolder is necessary because the ProductTemplate class used in the lab is part of the data.productcatalog package. In Java, packages are used to group related classes and provide a namespace management system. The productcatalog subfolder corresponds to this package and ensures that the Java compiler and runtime environment can locate and use the ProductTemplate class correctly. Normally, you would determine the need for such a subfolder by examining the package declaration at the top of the Java source files. In this case, the ProductTemplate.java file includes a line like package data.productcatalog;, indicating that it belongs to the data.productcatalog package. I hope this clears up the confusion! 🙏🏾

    • @lyubenpetrov6430
      @lyubenpetrov6430 6 месяцев назад

      @@emanuelepicariello thank you so much for the clarification! Sorry if my tone came across as harsh in my earlier message. I had been working on this lab for a whole day and I was at my wit's end. Your explanation clears everything up. Thanks again and keep up the great work. I will subscribe for sure!

    • @emanuelepicariello
      @emanuelepicariello 6 месяцев назад

      @@lyubenpetrov6430 Thanks for the support and no worries at all. Feel free to ask always!