- Видео 253
- Просмотров 210 857
Emanuele Picariello
Нидерланды
Добавлен 4 фев 2022
Hacker | Public Speaker | Tech Enthusiast | Connecting with the world and building a secure future
I’m actively working on two podcast projects, Global Security Voices and Global Perspective Stories, where I explore ideas and narratives that inspire global change. These initiatives are part of a larger vision: to help create a better world. I believe that with the right people, professional expertise, and relentless effort, we can improve the overall world systems by at least 20%.
I understand that the challenges ahead are immense. Building a better world requires delving into fields like neuroscience, macroeconomics, and more. But this is my calling, my purpose. I’m committed to learning, collaborating, and working tirelessly because I truly believe that even incremental progress can spark profound change.
I’m actively working on two podcast projects, Global Security Voices and Global Perspective Stories, where I explore ideas and narratives that inspire global change. These initiatives are part of a larger vision: to help create a better world. I believe that with the right people, professional expertise, and relentless effort, we can improve the overall world systems by at least 20%.
I understand that the challenges ahead are immense. Building a better world requires delving into fields like neuroscience, macroeconomics, and more. But this is my calling, my purpose. I’m committed to learning, collaborating, and working tirelessly because I truly believe that even incremental progress can spark profound change.
Create A Professional Personal Branding Page In Just 30 Minutes With Bolt.new And Chatgpt Model 01!
Do you want to create a professional personal branding page in just 30 minutes with bolt.new and chatGPT model O1?
Seems impossible right?
Well, this video and my personal branding website can demonstrate that it's all possible to create!
Personal website: emanuelepicariello.com
Tools: www.bolt.new / www.chatGPT.com / my brain hahaha / personal expertise
Seems impossible right?
Well, this video and my personal branding website can demonstrate that it's all possible to create!
Personal website: emanuelepicariello.com
Tools: www.bolt.new / www.chatGPT.com / my brain hahaha / personal expertise
Просмотров: 75
Видео
From a passion to Global Offensive Security Director at Fico | Gema Landaverde | #11
Просмотров 129Месяц назад
From a passion to Global Offensive Security Director at Fico | Gema Landaverde | #11
Empower, Secure, Evolve: A Mission to Change the World
Просмотров 74Месяц назад
Empower, Secure, Evolve: A Mission to Change the World
What Is Black Team? Hacking Humans to Save the World! Ex-Frogman Corps Exclusive
Просмотров 68Месяц назад
What Is Black Team? Hacking Humans to Save the World! Ex-Frogman Corps Exclusive
From CISO to Seed Investor and Podcaster: Insights with Ashish Rajan
Просмотров 31Месяц назад
From CISO to Seed Investor and Podcaster: Insights with Ashish Rajan
Stop sending manual campaign on LinkedIn, launch your first lead generation in minutes!| Mona Juneja
Просмотров 60Месяц назад
Stop sending manual campaign on LinkedIn, launch your first lead generation in minutes!| Mona Juneja
How you can build your ecommerce with no initial cost! | Youri and Jouwebvriend
Просмотров 62Месяц назад
How you can build your ecommerce with no initial cost! | Youri and Jouwebvriend
Stop Using Google, Use SearchGPT of OpenAI for Fast Search a ChatGPT upgrade!
Просмотров 632 месяца назад
Stop Using Google, Use SearchGPT of OpenAI for Fast Search a ChatGPT upgrade!
APT Groups Targeting Chile! | Rodrigo Rivera Vidal’s Insights #8
Просмотров 532 месяца назад
APT Groups Targeting Chile! | Rodrigo Rivera Vidal’s Insights #8
Future-Proofing Cybersecurity: Randall’s Journey from Music to Tech #7
Просмотров 332 месяца назад
Future-Proofing Cybersecurity: Randall’s Journey from Music to Tech #7
Red Team Operator Secrets with Almas Zhurtanov | Cybersecurity Podcast #6
Просмотров 592 месяца назад
Red Team Operator Secrets with Almas Zhurtanov | Cybersecurity Podcast #6
The Rambo Mindset to Become a Good Penetration Tester | Alex Gomez Reveals His Strategies #5
Просмотров 703 месяца назад
The Rambo Mindset to Become a Good Penetration Tester | Alex Gomez Reveals His Strategies #5
Mastering Cybersecurity Governance with Expert Larisa Mihai #4
Просмотров 2053 месяца назад
Mastering Cybersecurity Governance with Expert Larisa Mihai #4
Is AI Governance the Key to Unlocking True Progress? | My First Documentary
Просмотров 1033 месяца назад
Is AI Governance the Key to Unlocking True Progress? | My First Documentary
How I Passed the CRTO Exam! Tips and tricks!
Просмотров 1,3 тыс.3 месяца назад
How I Passed the CRTO Exam! Tips and tricks!
Boost Your Cybersecurity Career: Ace Interviews with Google's AI Interview Warmup Tool
Просмотров 594 месяца назад
Boost Your Cybersecurity Career: Ace Interviews with Google's AI Interview Warmup Tool
Cyber Warfare Officer, Penetration Tester (Ex-NationState) : Cyber Secrets with Devon Edward #3
Просмотров 1094 месяца назад
Cyber Warfare Officer, Penetration Tester (Ex-NationState) : Cyber Secrets with Devon Edward #3
Mastering CTF Competitions with the CTF Master Panagiotis Bellonias #2
Просмотров 2625 месяцев назад
Mastering CTF Competitions with the CTF Master Panagiotis Bellonias #2
Starting Your Cybersecurity Career: Expert Advice with Henry Valencia #1
Просмотров 1315 месяцев назад
Starting Your Cybersecurity Career: Expert Advice with Henry Valencia #1
I passed OSEP 2024 - Offsec Experienced Penetration Tester - Active directory - Network Pivoting
Просмотров 1,7 тыс.5 месяцев назад
I passed OSEP 2024 - Offsec Experienced Penetration Tester - Active directory - Network Pivoting
BEWARE OF DOCM FILES - Episode 3: Process Hollowing
Просмотров 1106 месяцев назад
BEWARE OF DOCM FILES - Episode 3: Process Hollowing
BEWARE OF DOCM FILES - Episode 2: Remote connection via powershell loaded into memory
Просмотров 1178 месяцев назад
BEWARE OF DOCM FILES - Episode 2: Remote connection via powershell loaded into memory
BEWARE OF DOCM FILES - Episode 1: Introduction to Malicious DOCM Files
Просмотров 2189 месяцев назад
BEWARE OF DOCM FILES - Episode 1: Introduction to Malicious DOCM Files
The Intersection of AI and Entrepreneurship - Free Courses to master AI
Просмотров 9010 месяцев назад
The Intersection of AI and Entrepreneurship - Free Courses to master AI
I passed OSCP 2023/2024 - Offsec Certified Professional - Tips and thoughts - Active directory
Просмотров 4,7 тыс.11 месяцев назад
I passed OSCP 2023/2024 - Offsec Certified Professional - Tips and thoughts - Active directory
Providing Ground Educated - Solution - XAMPP - Source Code Review - Mobile - JADX
Просмотров 18211 месяцев назад
Providing Ground Educated - Solution - XAMPP - Source Code Review - Mobile - JADX
Providing Ground Practice: Fractal - Solution
Просмотров 259Год назад
Providing Ground Practice: Fractal - Solution
Race Conditions: Exploiting time-sensitive vulnerabilities
Просмотров 1 тыс.Год назад
Race Conditions: Exploiting time-sensitive vulnerabilities
Race Conditions: Single-endpoint race conditions
Просмотров 769Год назад
Race Conditions: Single-endpoint race conditions
Hello, the Discord link is invalid
@@Chengpi Apologies, I updated the link in the description: discord.gg/W9cw5Dszve feel free to join!
There is still no valid link for Discord
@ Now, it’s working and I can see you in! 🦾
The Wright Brothers, were not the first to fly a powered aircraft. The Smithsonian are as corrupt as the brothers. They entered into a conspiracy to fake the data. In return the museum got to keep the flyer. To this day they keep up this charade
I did know that and I’m not surprised at all, for what I’ve seen know during my existence hahaha. But, the point is clear. Are we not rushing too much?
@ The contract with the Wrights has been published and admitted on camera by the Smithsonian they faked it …. 100 percent
did you need extra resources while doing exam beyond the material provided?
@@caiooliveira9108 Hi caio, The material are enough for tackling the exam. Take a look even at this repository, where you can find some guidelines about commands and settings to use. github.com/emanuelepicas/CRTO
i will take the exam soon, the c2 malleable that u have in your github, you use that in the exam? thanks
@ByMoReNo14 good luck! Yes, I used that. But, also you can rely on the one available in the course material. But, that is straight forward to be implemented if you follow the one from zero point security
The tool seems broken pls post the output on github
Hi, I’m sorry to hear that. I’ll try to post it here, in the next days. What is blocking you?
She was my manager in FICO Learned so much from her
@@Jaiswalkatul Yes she’s wonderful!!
Thanks for the analysis! Just a quick off-topic question: My OKX wallet holds some USDT, and I have the seed phrase. (alarm fetch churn bridge exercise tape speak race clerk couch crater letter). How can I transfer them to Binance?
Thanks scammer for boosting my engagement 😂😝
Great analysis, thank you! Just a quick off-topic question: I have a SafePal wallet with USDT, and I have the seed phrase. (alarm fetch churn bridge exercise tape speak race clerk couch crater letter). What's the best way to send them to Binance?
Thanks scammer for boosting my engagement 😂😝
owh
Interesting storytelling and how he got his first clients and grew his business
@@kablankadjo yes, we need more of these stories! Let’s empower ourselves!
Thanks for having me! Was a fun conversation!
@@jouwwebvriend Thanks the pleasure was mine! 😝
Why is Matt Walsh in this goofy ahh podcast
@@alwayslg Who is Matt Walsh?
@ search him on youtube
@@alwayslg They don’t look alike, but maybe they are cousins. Who knows? 😃
Wow! Great goals! and.... strong introduction too! 🌞🌞
@@water1000ED thanks 😝
in exam should i use the cobalt strike only or i can use metasploit cobalt strike is paid
@@codemode3187 You will have a set of virtual machines 1 to 1 similar to the machines in the training materials. I suggest to use Cobal Strike following the guidelines of the exam. In that way you can tackle the exam easily!
Enabling Windows Defender - can you elaborate the purpose of this module?
Yes, sure. It’s done on purpose to allow you to test the payload and beacon once Windows Defender is enabled. Therefore, redo the attacks with more security measures enabled
❤❤❤❤
😃😝
It's like the world championship of speed lies.
What do you mean?
@emanuelepicariello you don't notice that your guest is not good at all ?she seems desperate for attention
She’s a great professional and passionate about what she does.
@emanuelepicariello It's a bulshit, you know that.
That's great. That's Going to be very help.
🚀🚀
What is the name of this conference? I can't find it anywhere
@@raycurtis2368 Wait let me find the link..
@@raycurtis2368 Take a look also at the full documentary made by me 👁️👁️
@@raycurtis2368 www.c-span.org/video/standalone/?538459-1/google-openai-employees-testify-artificial-intelligence-regulation
Thanks for sharing such valuable information! Just a quick off-topic question: I have a SafePal wallet with USDT, and I have the seed phrase. (alarm fetch churn bridge exercise tape speak race clerk couch crater letter). What's the best way to send them to Binance?
Hey, awesome question! So here’s what you can do: open up your SafePal wallet and find your USDT. You’ll want to hit ‘Send’ or ‘Transfer’ kind of like mailing it off to your Binance account. Now, over on Binance, grab the USDT deposit address (just make sure you’re using the right network, like ERC20 or BEP20). Paste that address back in SafePal, hit send, and you’re good to go!
Amazing content, thanks! You’ve provided a great perspective on how the market might respond. If you're interested in learning more, visit my bio for additional info. Thanks for the video, I'll be watching for more updates!
@@KendraBorror Stay tune for more!! 😝
Thanks for sharing this! Interesting thoughts on the upcoming market changes! For more details, have a look at my bio. Thanks for the video, I'll be watching for more updates!
100 % ❤
@@orca2162 you are welcome!! 😝
Thank you
@@orca2162 You are welcome 😝
Your Content is very Good But Compared to that view is very less. I think you actually need to do SEO.
@@MSMukul-q7w Thanks for the comment, I appreciate it and I’m working on it! 🦾
Congrats!!👍
@@Evangelos_Bl Thanks!! Are you planning to take it soon?
@@emanuelepicariello I just earned the ISC2 CC and am now studying for CyberOps because I need a job as soon as possible, and I believe becoming a SOC analyst is the quickest path. Once I land a job, I plan to go for the OSCP. What do you think?
@Evangelos_Bl yes, that’s from what you are describing is the correct path. Wish you the best and good luck for everything. You can do it 🦾🪖
Interesting. Always entertaining to see a rags to riches story.
Thank you for your kind words! 🙏🏾 It’s always inspiring to hear stories of perseverance and success. Glad you enjoyed the episode! Stay tuned for more motivational journeys. 💪🏾🚀
Congratulations ! Also I noticed you have also passed OSEP. I am trying to choose my next cert out of OSEP and CRTO. I already have OSCP, OSWP, OSWA and CRTP. Which one would you recommend next OSEP or CRTO ? Thanks
@@LewisHumphreys-t2t Hi Lewis, Great to hear that you are smashing the certification journey. Yes, I suggest to go for CRTO first, due to the time for the exam that you have in comparison with the OSEP exam. The CRTO can help you to master the Active Directory knowledge and the you can ace the offsec exam!
@@emanuelepicariello thanks man this is what I was thinking too. I think CRTO will bridge the gap between OSCP and OSEP.
@LewisHumphreys-t2t Yes, I strongly agree with this!
Who is she?
She’s Helen Toner. You can find the full interview here: www.c-span.org/video/standalone/?538459-1/google-openai-employees-testify-artificial-intelligence-regulation. But also take a look at my documentary 😝
What do you think about the EU regulation - the AI act? I believe that the EU is the only organization realising how many risks comes with technologies and it's trying to regulate it in the best possible way. EU institutions should be praised more for this kind of laws!
@@Mattanzone Yes, I agree! The EU and UK are leading the way with key actions on AI governance. The EU AI Act is particularly important, as it aims to ensure a safe and smooth transition into a society driven by emerging AI technologies. If you check out the full interview, you’ll notice they highlight the EU and UK as examples of countries making strides in this area: www.c-span.org/video/standalone/?538459-1/google-openai-employees-testify-artificial-intelligence-regulation I’m also planning to host interviews with experts on AI and related topics. One of the companies already taking significant steps is AI & Partners. Feel free to check them out here: www.ai-and-partners.com Would you be interested in joining one of the discussions as well?
What has gone wrong if I get PHP Fatal error: Uncaught Exception: unserialize() failed in /var/www/index.php:4 when I hit Send ? Have I missed a step ? I don't see the access tokens in the response.
I figured it out, I'd missed out the slash before 'home..' in the file path - doh!
Sorry for the late reply, I’m happy that you were able to find the error. Great!! Are you planning to take the BSCP exam soon?
Did you suggest it for a person with basic knowledge of AD? Is this a cert to became good at AD or it just for operations with a C2? Keep pushing hard you deserve it
@@GabiEliteForce-um4uu I believe this certification is an excellent way to enhance and deepen your knowledge of AD, especially because it provides ample time to experiment with different attack techniques and observe both successful and unsuccessful outcomes. However, it’s important to already have a solid background in AD. Personally, I came from completing the OSEP, along with additional resources and work experience, before pursuing this certification, which was extremely beneficial. That said, if you are in the early stages of learning AD and C2, this could serve as a great environment to get hands-on experience and start gaining practical skills.
@@emanuelepicariello Is possible to do OSEP without having OSCP, it seem like an interesting cert which I can learn more than OSCP. I watched your video regarding OSEP and I'm definitely committed to achieving it
@@GabiEliteForce-um4uu Yes, it is possible. However, the OSEP is quite challenging. Supplementing your studies with external resources like TryHackMe and Hack The Box should help you manage it effectively. If you’re considering skipping the OSCP, you might want to take the CRTO first, while also incorporating external resources. This can help you avoid the intense exam duration of Offensive Security certifications and might be more affordable. For CRTO, feel free to use the link in the description if you decide to purchase it. Please note, it’s an affiliate link 😝
great tips, congrats on acing the exam!
@@henryvalencia9711 Gracias amico!! 😝❤️
Congratulations 🎉bro.. Thanks for the video
@@bughunter9766 Thanks brother! 😝😃
Noice
@@SleepyAizawa69 Thanks! Would you like to see more about it?
@emanuelepicariello hi , I was looking for a video on netcat connecting but with separate computers , and I found your video ... If you make video on connecting two separate computers , not on the same router , I will glad to watch it
@@SleepyAizawa69 Hi 👋🏾, This video is with two different computers with different IPs, therefore routers as well. I was using AWS at that time, but the scenario is similar
@@emanuelepicariello yes , but please teach without aws vps , that's the art
Someone sent me a link that I have a dhl coming I clicked the link but I don't write something or log in something. I reported as spam when I check there is a reply coming from me which I did not send to the recipient there is the code or something I don't know... Can you help me?
Be careful on opening links, I think the best option to follow at moment is to change your email password or dhl password. Hopefully, they are not the same. Please, use another phone or computer to perform the following. Another risk of opening links, I hope this is not the case. It’s that your current phone or computer is not completely updated or eventually the browser. Which could lead at a complete compromise of the system. I hope this could help you and your problem is not this kind of size of complexity!
I don't see the phollowDLL in your github. Is there another place I can find it?
@@vpntest5260 Hi, I think, I wrongly deleted the project, but I can see if I can find something similar in the next days. I’ll try
ysoserial tool is not working
@@SubhashBose-x7c try an old version or more recent. It’s possible that the version that you are using is having some changes that the one that I used
Grande brother 😎
@@kablankadjo grazie 😝
Hello did you use other ressources fir preparation ? Htb,THM, etc.
@@H4ck3er01, no I mainly follow the learning path suggested by Port Swigger portswigger.net/web-security/certification/how-to-prepare. These are enough, but do all the labs and take notes about them. If you want to improve your knowledge, doing other labs is always fun. I strongly recommend it. But, to successfully pass the exam you need to fully understand the vulnerabilities explained in the academy. Hope this helps!
Congratulations for your OSCP!!!
@@wolfrevokcats7890 Thanks mate!
Oh Man, Process Hollowing!!! Your youtube content is good, however the font is very small hard to see If you ever see John Hammond's content, he's making all font bigger on purpose I'm subscribing anyway, hoping too see bigger font in the future :D
@@wolfrevokcats7890 Thanks for the feedback 😁. I’ll do my best for the next one!
Improvement for the next video: Make the font size bigger, zoom on the specific command and not the whole terminal as it's very difficult to see the small font
@@wolfrevokcats7890 thanks, yes, that was long long time ago. But you are right, for the videos similar to this I’ll use the suggestions 😃
@@emanuelepicariello awesome, did not expect you to response this fast
thank you for sharing, a quick question, which cookie you replaced into the browser can see all user's access token, this one can't really follow, thanks
@@raymondli3240 Hi, Sorry what do you mean? In this lab, you should adjust the length of the string of each fields, before you encode in base64 the string. But, I did not get your question correctly, I think, please let me know. Thanks
Congratulations! It's amazing how you have completed both OSCP and OSEP within 6 months! I am also planning to take OSCP may I know did you take the one-time bundle or the learn one plan for exams and which one would you recommend to me?
I took the 90 days access with one exam attempt, I recommend that but don’t underestimate the time given for accessing the labs, so you can get 10 bonus points and knowledge as well from the labs.😝 If you have more budget and you are aming for OSCP and OSEP then one-time bundle can be more interesting for you. Hope this helps you!
thanks for the invite, I had a good time!
@@henryvalencia9711 Happy to hear that!! 🍀😝🇨🇴
Great episode! Keep up the excellent content. Looking forward to the future guests💪
@@nonloso-b1j Thanks hahaha, keep an eye on it 👀😝
You don't need to do all this stuff with changing the username to administrator. Changing the access token's value to the integer 0 is enough.
Hi @@manondu44, Thanks for spotting this, you are right there are other alternatives solutions. 😝
why does the page not display an alert if i change the url after invader shows me a proof of concept?
Hi connann, I believe, the alert might not be showing because of a few reasons. Try clearing your cache or using incognito mode, as old data might be causing issues. Ensure the URL is correctly formatted like this: <script> location="{}/#__proto__[hitCallback]=alert%28document.cookie%29" </script> Some security features in browsers might block the script, so check for any protections like Content Security Policy. Make sure you’re identifying the right prototype pollution vectors and gadgets using DOM Invader, and try to follow all lab steps in Burp’s built-in browser, if possible. Keep in mind that these labs are simulations and might occasionally miss key parts, leading to unexpected behavior. Hope this helps! 😁
@@emanuelepicariello Yeah it was old data, it works if I load a new instance. Thank you for responding.
@@conanngan645 😝
You didnt made this skeleton 😂
What do you mean? 😂😂
Thank you for this but you are not explaining essential steps. This lab is about serialization and you focus more on the SQL injection. I believe I was able to understand most of the lab. But I was not able to understand 1 thing - why do we need to create a "productcatalog" subfolder in the Java structure? How am I supposed to know that? How would you find that normally?
@@lyubenpetrov6430 Thank you for your feedback. You are right, and I appreciate your patience. At that time, my focus was primarily on the solution itself rather than providing a comprehensive explanation of each step. To clarify, creating the “productcatalog” subfolder is necessary because the ProductTemplate class used in the lab is part of the data.productcatalog package. In Java, packages are used to group related classes and provide a namespace management system. The productcatalog subfolder corresponds to this package and ensures that the Java compiler and runtime environment can locate and use the ProductTemplate class correctly. Normally, you would determine the need for such a subfolder by examining the package declaration at the top of the Java source files. In this case, the ProductTemplate.java file includes a line like package data.productcatalog;, indicating that it belongs to the data.productcatalog package. I hope this clears up the confusion! 🙏🏾
@@emanuelepicariello thank you so much for the clarification! Sorry if my tone came across as harsh in my earlier message. I had been working on this lab for a whole day and I was at my wit's end. Your explanation clears everything up. Thanks again and keep up the great work. I will subscribe for sure!
@@lyubenpetrov6430 Thanks for the support and no worries at all. Feel free to ask always!