WEBVTT

00:00.760 --> 00:07.960
Now there is one thing for certain when it comes to ethical hacking, and that is that we are really

00:07.960 --> 00:12.460
never going to be able to operate like a black cat.

00:12.730 --> 00:14.290
Yeah, it's unfortunate.

00:14.500 --> 00:21.190
Even though so many times we're going to be simulating the activities of a black cat.

00:21.400 --> 00:25.210
We can't just do whatever we want.

00:25.390 --> 00:27.340
This is extremely rare.

00:27.580 --> 00:34.420
I suppose one area where we do see this is when we set up a total like test environment.

00:34.720 --> 00:40.420
And this test environment is cut off from our organisation completely.

00:40.660 --> 00:46.060
And in that type of a sandbox we could go ahead and do whatever we wanted.

00:46.360 --> 00:53.560
But notice often times we're going to be working in the context of our organisation and we are going

00:53.560 --> 00:59.800
to be subject to definite limitations and scope.

01:00.550 --> 01:07.240
Before we get there though, I just wanted you to think about what it takes to be an excellent ethical

01:07.240 --> 01:12.400
hacker, and it's certainly going to take your technical skills.

01:12.640 --> 01:15.040
We're going to need to know networking.

01:15.040 --> 01:19.720
We're going to need to know systems, we're going to need to know protocols.

01:19.870 --> 01:22.570
We're going to need to know how to use tools.

01:22.720 --> 01:25.630
We're going to need to know how to interpret those tools.

01:25.900 --> 01:33.520
But remember, there is going to be non-technical skills that are going to prove critical for you as

01:33.520 --> 01:34.720
an ethical hacker.

01:35.260 --> 01:42.670
One of those non-technical skills is going to be your ability to communicate with other team members,

01:42.820 --> 01:49.480
your ability to communicate with superiors, your ability to communicate with end users.

01:49.630 --> 01:58.780
And notice this is often challenging since they to us will seem so technically inadequate.

01:59.140 --> 02:06.460
We all find it difficult to believe that they can be subject to social engineering attacks with such

02:06.460 --> 02:12.310
ease will you know they'll just dumb found us with their ignorance of things.

02:12.310 --> 02:13.600
Cybersecurity.

02:13.900 --> 02:20.740
We need to have incredible patience in that environment to work with them and give them the training

02:20.950 --> 02:22.600
they so desperately need.

02:23.500 --> 02:33.160
Now, once we have the skills that we need to be unethical hacker both those technical and non-technical

02:33.160 --> 02:40.540
skills, we have to know the scope of how we can work.

02:40.840 --> 02:51.760
We need to really, if the organization doesn't have documentation on how we cybersecurity analysts

02:51.760 --> 02:57.550
can conduct our business, we need to help them define that and document that.

02:58.030 --> 03:05.690
A great example might be if we have a bunch of resources inside of a RWC.

03:05.980 --> 03:13.270
Okay, let's say we have a whole bunch of our organization's resources inside of the cloud of IWC.

03:13.840 --> 03:22.480
We need to know that we can penetration test, we can pretend we are attackers, okay?

03:22.660 --> 03:27.730
And that is allowed by IWC against our own resources.

03:28.120 --> 03:36.880
But what IWC will not permit you to do is to penetration test their resources.

03:37.150 --> 03:45.790
So let's say we detect there's an AWB gateway that is giving access to our environment.

03:46.060 --> 03:53.590
They'll let us pass attack traffic through that gateway, but they won't let us attack to that gateway.

03:53.800 --> 03:55.540
Yeah, that's their property.

03:55.750 --> 04:03.010
If we down that gateway it could affect other, you know, tenants that they have that require access

04:03.190 --> 04:04.120
through that gateway.

04:04.300 --> 04:10.900
So we don't get to attack AWB only our own resources in AWB.

04:11.170 --> 04:14.920
Notice how important it is to know these limitations.

04:15.340 --> 04:18.970
And let me just tell you the example I gave of AWB.

04:19.300 --> 04:20.020
That's a.

04:21.030 --> 04:28.770
One I really wanted to give because that environment has changed several times over the years.

04:29.100 --> 04:36.870
It used to be that you could attack basically anything you wanted, but you had to obtain written permission

04:37.050 --> 04:39.900
and you had to give them all the details of the test.

04:40.290 --> 04:45.690
Then it became that you could attack your own stuff only with written permission.

04:45.900 --> 04:52.110
Then it became the current environment of You can attack your own stuff whenever you want.

04:52.290 --> 04:54.480
Don't touch any of the IWC stuff.

04:54.990 --> 05:03.550
You're going to be helping them to divine design and document the limitations and the scope.

05:03.570 --> 05:11.850
If your organisation hasn't already thought about this and have these plans in place, it's always important

05:11.850 --> 05:20.880
as an ethical hacker to make sure you are operating within the scope and limitations that have been

05:20.880 --> 05:21.510
defined.

05:21.780 --> 05:29.340
The last thing we would ever want to do is start engaging in illegal activity when, after all, we

05:29.340 --> 05:33.960
were trying to operate ethically and aboveboard the entire time.
