Episode: 4682
Title: Behind the Keyboard: A Cybersecurity Operator’s Real-World Workflow
Source: https://hub.hackerpublicradio.org/ccdn.php?filename=/eps/hpr4682/hpr4682.mp3
Transcribed: 2026-07-31 16:16:43 (official HPR transcript)

---

This is Hacker Public Radio Episode 4682, for 2026-07-14
Today's show is entitled, "Behind the Keyboard: A Cybersecurity Operator’s Real-World Workflow"
The host is operat0r and the duration is 01:23:16
The flag is Explicit, and the license is CC-BY-SA
The summary is "The presenter outlines a practical cybersecurity workflow, covering ergonomic setups, browser isolat"
Hello everyone, welcome to another episode of HectorPoke Radio.
It's going to be kind of another attempt at, I don't know if I've released the other one that I did or lost it,
but kind of what I'm doing at work and how what I'm not what my approach is.
So, today I have to check up on a test before I run it.
So, make sure connectivity works before I do it engagement.
I'm kind of going to start from the very beginning.
My feet are flat. My screen is actually too high. It's supposed to be at your eye level.
So, the top of the screen is supposed to be at your eye level. Mine's about the mid level.
So, my screen should actually be lower. Can I slam it down anymore?
No, so it's oddly too high. The reason it is too high is because my posture is so bad.
I have to put my elbows up almost shoulder length between my tip and my shoulder.
That's where my arms, my elbows are resting. So, I'm almost like a, my arms are out to the side.
I have a split keyboard. It's a freestyle. Free style too. I just bought another one because
maybe I've got an angry and banged on it and the Oki quit working.
Very soft keys, very nice. Kind of the higher end keyboard.
So, I'll keep already getting anywhere but this one lasted me four or five years, three or four,
five years, something like that. Then I have a curved monitor, 49 inch ridiculous thing.
And that's been great for games. Been good for work and productivity.
And I think I like it. So, I'm still trying to get you set. So, that's kind of my setup
ergonomically. I do want to do eventually. I'm still working on it. I need to take off quite a few days
to go full on. No keyboard, no mouse using an eye tracker and voice control. And I'm still working on beta
for testing for a GPU-based voice guidance. And once I get that, then I will have to worry about
CPU getting pegged and that will solve a bunch of other problems I've got.
So, anyways, what I have is I have talent voice running. I have a sync for my notes, which are
secure notes, which are insecure notes. So, plain text using Obsidian. And I've just did an
episode of Obsidian. I'm experimenting with getting off of Google Keep. So, trying to get
separating my notes and combining them to a more AI-friendly cloud-based fancy notes instead
of just plain text notes. So, I'm switching to Obsidian. Trying to try that to talk to
hopefully eye things. That's kind of my setup for notes. What else do I have running here?
AutoHackies, signal for personal messaging. And so, what we're doing here is I have
generally everything runs as its own user. So, I don't browse the internet as the user, the same
user I do my work stuff with. So, technically speaking, I'm using the work computer for personal things.
Like anyone does, I don't know if there's anybody that doesn't do maybe in a high security
environment. You might not have to do anything personal on your work machine, but they're kind of
one of the same sometimes. So, for me to mitigate risk, I have a single shared folder that
is called Delete actually. In that folder path, it's in a specific path, that folder is shared
between both the user, the normal work user, and the internet user that is a jailed essentially
user that doesn't have access to break anything, right? That is because I have, I don't know how
many plugins, I actually just posted them. And of course, I could do a show on this, but I will not
chat. The plugins I have, you can ask AI to give you a list of the plugins that you haven't
installed, which I thought was pretty cool. It's like, I don't know, whenever I tell anything to do
with the browser, I tell it to use this, the debug, the Chrome debug commands to do all of that,
and it'll basically have you run these crazy commands to debug to show whatever you want to show.
So, there's an about extensions, link, and then inside of that about extensions, you can run a
command, and it will give you all your plugins. So, let's see how many I got. It's not a time,
I'll just take a second. So, I'll have to belive, of course, let's usually cookies, usually I use
effort, deleting cookies, and deleting swords, cookies, things like that, and outside of the Chrome
debug, I could probably do it there. But I do it per bone domain, so it makes things a little bit
easier and kind of predates all the super fancy Chrome debug stuff. Both media downloader, excuse me,
that's a multi-threaded swarm, if you will, a downloader, a GRO, which is kind of, it makes titles
and thumbnails better for YouTube videos, instead of the shock and all, annoying ones. Their user created,
and you can tell at the picker random frame, I think, of course, read aloud, which is good.
It uses, I'm using, with read aloud, I'm using the super-tronic voices, which is kind of like
pocket voice, very lightweight, Texas, Texas, speech engine, great, very fast. Last pass, of course,
proxy switch. Wow, okay, sorry, my TTS is going off, because I click the button.
So, proxy switch, any kind of proxy switch, proxy switch or mega, that's kind of needed for
whenever you need to tunnel around. Things to get me as a free thing, I use Amazon's gift,
what was the Amazon's thing, a liquid letting you put random stuff on Amazon, so things to get me
having used in based on my voice. Ever seen for thinking bookmarks across multiple devices, multiple
user names, volume master, is great for amping in the volume on videos for whatever reason my volume
is always really low. Like YouTube videos or anything in the browser, for whatever reason,
global speed, video speed, controller, that one specifically is a very specific one, so
the plugin ID ends in I or end-to-go, no, I don't know what the phonetics are, well,
India, India, Fox, Fox, and I don't know what F is, Fox, try it. So anyways, global speed,
space, dash, space, video speed, control is phenomenal, because if you are doing corporate training,
or some kind of training that involves a video that you have to watch to the end,
about 80% of the time, I can click to make the speed like 16x, and I will get done with my training
16 times after. You can also download those, create a convert them to speech using whisper
and prioritization. I have a static binary on my site, it's under the scripts folder, it's called
like whisper diarization, if you want to try it out, it comes with all the, all the drivers,
bundled into it for Nvidia with CUDA Torch 12 in the support sector, so you can just run that zip
and extract it and you can do diarization and assign speaker names and stuff, and then you can convert
that to a summary and then you can do whatever testing you need to do.
Not that I encourage blasting through training things, but let's all be honest, I don't know
anybody that actually does any training and pay attention. So with that, I can get notes and actually
query those notes if I actually, an inquestion about a process or a specific compliance thing
that's that I'm questioning. And oftentimes, that is there, and you can't enforce it because
nobody wants to use the band hammer and nobody cares about security. So anyways,
security theater, as we go on, turbo download managers, classic version, and then I have turbo
download managers or third edition, which I think I need to get rid of the classic, if I'm mistaken,
and I know I've deleted their on one, so I have both of them on there. Rango, RANGO, RANGO is what I'm
using for voice based, voice based, clicking a button. So each element on the site has a little
monitor above it, and I can say a bit underground or whatever the words are, I don't know the
fanatics for talent voice, but you can say the fanatics for those, and talent and voice will pick it up
and it will click the button for you. I don't even know a fox, it sit, yeah, I think talent voice has
to be running for for this to work, because my mic is on. So anyways, that goes in the browser,
and it clicks, it's easy way to click button. So instead of using the IR tracker to click buttons,
I can just move ahead around a sponsored block for YouTube, of course, down a minute, again,
privacy banner, and a scrap fly, anti-bot detector, which I've been using to, I'm trying to make
it, but scraper slash AI error, checker tool, thing to help with this and that stuff. So the idea is,
I can use scrap fly to scrap fly to easily identify what sites the protections this site has,
and try and work around to work around those. So I've boarded you with all my stupid chrome
plugins, the reason I went through those is because that's a lot of chrome plugins, and that's a lot
of a text surface to worry about. So instead of worrying about that with my work account,
I run a jailed a normal user account on the system, and that user account only runs as the
browser, it doesn't do anything else, but run a browser. Technically speaking, if you had like a
VM escape, and you could like do a key log through that, or whatever you could technically cross those
bridges, but you know, that's not something I'm necessarily concerned about, I just don't do work
stuff with this browser. The other browser has three plugins, it has last pass, and that's pretty much it.
Brain goes on there, which I need to actually remove, that's not really secure,
so we remove that, and then pretty much other of the retail out text speech. Now, I also have a
script that will nuke the update servers. It's under fu.txt, frelo 101 GitHub. So if you look for
fu, that's fox, I don't know, unicorn. fu.txt, and then frelo 101 frelo 101. That's our own search.
I'm also playing with my own search that uses Google search, essentially, with open web
but I won't bore you with that. So we're going to go frelo 101 fu.txt, and it should pop up
up in the search. Yeah, and in here, there is a thing that helps you to help protect against
water and collect x. It also prevents the app from being updated, so it for like a better term
freezes the app. So it looks for a file called manifest.jjson, and that manifests.json defines a
lot of things, mainly where the upload URL, the update URL is. For that particular plugin, right?
So if and when these plugins get compromised, it won't matter to me because I'm sending it to
a nowhere place. Interesting enough, the first time I came up with this idea, I had so many plugins
installed when I ran it. I noticed very quickly that Google, all of a sudden, had like meet singles
in your area, I'm like, what? So basically one of the plugins I had that was to rip way back,
I think it was maybe flash or video content, some kind of video content, before I learned how to
do stuff with FFMPIG and different kind of packet numbers for the browser. Download the download
watcher that I use is called. Interesting enough, I didn't hear it in that list that I was talking
about. Yeah, but we did a downloader. I use for most of the URL stuff. Anyways, before I did that,
I use that and that particular plugin or extension had like if I can't phone home for updates,
just turn the plugin to spam addware. I was like, okay, that's kind of gross. That's, you know,
an interesting text surface to think about. So not only could these things get taken over,
they might have code in them to serve up ads, which is a problem in itself because a lot of these
ad companies are basically sleazy, dark corners of the internet. So that's an attack surface.
You have to also think about not only updates, servers can compromise. If these things are configured
to throw ads up, if they can't talk at home, those ad providers can possibly be compromised also.
So I mean, we're talking about extensions for browsers. It's pretty terrifying. So the amount of
power these things have and Chrome has done a lot of work to minimize that threat, but I'm not
going to ramble any more on that. Let's do something fun. So I've got, I've tested my access
to the thing I'm trying to do through using Hypervia, use Hypervia and Windows. I'm pretty much
all Windows now and all all into WSL and Windows virtual V Hypervia. The reason I am is because
you can pretty much do everything you need to do in WSL. It's a, there's some lag there, of course,
and you don't want to do like GPU stuff necessarily inside of a WSL thing, but it is possible
installing like, what is your tools? So what I'm going to do is I've already checked my VPN
access to make sure I can get to connectivity to work. What I didn't know or understand
is that I was supposed to check access to a particular host that I'm supposed to be doing testing
from. So I'm not doing testing directly from the VPN host. I'm doing testing from a
virtual machine inside of their infrastructure. So I'm looking for my notes, hopefully,
or in here somewhere, and there should be like a pad here. I don't think there is. So we'll go this way.
At a lot of these VPN clients won't let you split them up. They also won't let you connect to
using enhanced sessions in Windows. So the problem with enhanced session with virtual, the VM,
VM, virtual machine stuff for Windows is that they all want to use, you create a shortcut here.
I use Tera Copy and Windows for shortcuts and stuff. So I've been pretty happy with it and I
actually paid for it. It's good for copying lots of files and ensuring you can pick up where you
left off and it's a lot better manager. So I've got, I've guessed actually without the client telling
me I've done passive recon to figure out their VPN hosts. And unfortunately, there's a sell
areas, which is not particularly great, but we're going to just make that a finding when we're
doing our testing. So we've got connected to what looks like a VPN and then it disconnects me because
I did not uncheck enhanced session. The enhanced session is basically a RDP session to the local host
of the guest machine and I can't type my password. So now I have to re-connect to the VPN
because I did not, I did before I used the VPN client. I did not disconnect the essentially RDP session
to myself. So it's like a local RDP session to the client host. Now once I've connected
what I'll notice is that now my split tunnel is gone. I don't have access to the local machine.
I don't have access to anything. Now what you can do and I'll probably do this while I'm on the
form when I, I will use open connect. A lot of people don't block VPN access. So if you try to do
an SSH tunnel, it doesn't work. Try open VPN and that doesn't work. Try S tunnel. That doesn't work.
Try DNS tunnels. So there's a lot of, a lot of moving parts within these organizations and they
don't want to block third parties from being able to do their jobs. Nobody wants to do that guy.
So they might have the most secure system in the world but then they allow the
you to use open VPN to connect to any host. There's no whitelist thing. So there's like we
allow open VPN out and you'd be surprised at what types of places high security places allow you
to use open VPN to connect but basically negates the whole point of the whole thing.
So Windows and Cisco client does happen particular controls and it to force the client to do
specific things. But if you use a VPN and I'm getting a certificate error which is again,
okay. So now we have certificate from bubble block fail to trust this server in the future,
bubble block. Please complete authentication process in any connect login window,
no SSH tunnel or failed to complete authentication. Which I feel like means that they are enforcing
any connect stuff. So I'm going to take this and give it to AI and ask AI how I buy
it has it. So I say I get the Pintest prompt and I say how do I buy Pest? How do I buy this
this error? I want to make this a finding with the client. So the client gave me access to,
oh I can't. I'm just going to do a screenshot because the turn to copy and paste now I have to
do a bunch of stuff. So instead of doing that it's going to send it to a screenshot that is sanitized of
course because we do not want to be feeding the trolls. So I'm going to omit the the host name and
I am most of the key and I'm just going to give it that thing. So I say screenshot because I don't
feel like switching. How do I buy Pest? It's here. Miami, Miami do something in the background.
I also have local models I use if I'm going to do anything sensitive. I use local models because
my every time I start up my server the whole chat is wiped out. So basically anything that's
sensitive in my open web UI is going to get nuked every time I reboot. So there's no reason for
me to have any cash in there. I have no reason to go back and if I do want to keep notes I
you put them obviously and I'm sitting in. So I don't want chat history or any of that stuff
being in my thing. So here we go. It looks like it's going down the open connect rabbit hole
is which I want to do. I don't want to use any connect. It doesn't any connect to say what
it may be called fine. So VPN serves self-signed. Yeah that's fine. Whatever open is a
self-connect open. Love of a reveal it's first connect. Surfing a quick base since it's
before server hash. It says it only has an edge of the variety. No as a cell and saw open connect SSO.
Tell me to do like a pip install open connect SSO. So this is like a different thing. I wonder if
that's an app inside of here. Never heard of that. Open act SSO windows. Looks like a some open
source project. Installation. I don't really have pip necessarily. This is weird. Okay so
manual Sam, some will cookie injection works. P out protocol and you connect. Okay so open
connect V and then the host. So let's try to do that. Of course I can't copy and paste again.
Or so I have instances like this. I have a script that I can out of hockey.
Has a script if I do control Z. My controls my sorry. My control key is caps lock because
I basically have a couple at this point from doing control C control V control C control V for
18 hours a day. So now my control copy is control A, paste is control S or sorry. Copy is
caps lock A, paste is caps lock S. Some other hockey's are W and E and things like that. X I want
to use Z is to type what is in the clipboard physically right with a certain delay. So I press that
and I click and I hope that it happens. It does not happen which I've noticed with this. I killed the
I also have the same macro running on the virtual machine itself. So that's some of it on a test
of locally caps lock Z and we're going to see if it's typing what it's supposed to type.
Then it is it's typing it. So I would expect there's a delay after I so that I can click where I need to
click and it doesn't do it which is very odd. Usually that means you're not running as
administrator. You're not running auto hockey as administrator. So that might be it for this exercise at least.
I would say the easiest thing for me to do is I guess switch back to Enhanced Session.
Get the notes I need to put in there copied and pasted. So I switched back to Enhanced
mode so that I can copy and paste. So manual is cookie injection method combined one minor.
So I would bring all of this in and see if this works. Actually works with the host.
I take it back off of the problem with switching back and forth the Enhanced Enhanced Session
is that you have to, well again every time. Just kind of annoying. So I have my little command
that I might want to enable available off groups. Sure. Let's do what it says.
So I'm back on regular mode and I type things that is says the type or a copy and paste error
and handling command line, error and command line handling. I don't know if I click yes.
It might be just like a result of a result of the security enforcing of like this is
goes on something tells me that that might be problem. So I'm going to use dash protocol any
connect and dash server cert and use the hash that was given back to me. I don't want to hope
that works because this would be kind of a nice finding to have because when you can
that did not work at all. I got the ever popular when you put the command line in correctly.
It just dumps out the help. It doesn't tell you anything about the error message or what you screw
it up syntax. So I'm looking at no server specified. Well that's my fault because
I didn't put a server at the end. So that is my fault and actually gave me an error which is nice.
So copy and paste it again. I'm very anti type anything. I pretty much copy and paste every single thing
I can. So yeah it says no SSL handler which doesn't make any sense because there's no SSL built into
this just kind of strange. So once I'm, let me just keep going down this road. So jambri, jambri,
read or crazy.com. jambri is my little portable portable everything framework.
Wow really. jambri.com. It's a power cell script that gives you basically everything and one portable
thing and also it does not mess up your current environment. It resets all your current environment
variables mostly to just work. So I'm going to make a new folder for a client which is this guy
and I'm going to make a new folder for jambri. jambro, SSL because I'm trying to do this SSL something.
So from this power cell script I'm going to click it. I'm running the least one it checks
for the latest version. I'm going to click shell. Once the UI comes up it's a horrible UI that's just like
whatever. I'm going to click shell and it pulls down a number of things. It pulls down enter.
I can Android command line tools which you know you don't need that really. It pulls down java
and it pulls down hopefully the Python will come here in a second. The downloader I had to
fix here fairly recently because there's something weird with a specific website that was like
chunking weird. If you use the native downloader for Windows it's more for power cell. It's bad.
So I wrote or I had AI right one or I found one online and then I had AI right one when I had
problems with the downloader. So the downloader is pretty solid as it stands now. We got Python,
we got git, we got some extra libraries that we might not meet and we got we updated pip.
We are downloading npm and now I have a shell with java, git, pip, npm, node and
does it java? I'm missing one. Anyways so now I'm ready to go. So I can do pip install whatever is talking
about. pip install this open SSL open connect SSL. So I'm going to copy this
paste, can I not copy and paste, pip install, did I not, did I not unenhanced anymore? I'm not unhanced anymore
has my problem. I don't want to be unenhanced actually. So pip install open connect
SSL. So this is some kind of shim for open connect to handle any connect
single sign up. I had a guess. So I'm going to look here while it's installing. We're going to
educate ourselves. In the course I got a builder because Windows is awful at doing anything with
wheel, good.google.com. I'm using Google, I use these, I use these coggy, like 300 bucks a year for
their thing and you get a healthy amount of wrapper script exactly, wrapper script for open connect
supporting Azure, Sample 2, Authentication 2, Cisco SSL VPNs. Oh that's actually exactly what
Microsoft Azure's vizor creator is more required for this C++ build. So when we're
coming past this, we're going to go here, we're going to go to com and we're going to say AI mode
and we're going to get our free AI answer without even signing in. Right works, use to the installer.
So I'm going to pause and not bore you with this part and get this working first and then we'll go
over there. So I wanted to jump in here because I'm doing a someone posted to do a report review.
A problem with doing a report review and my current flow is that the text is speech engine
that uses supertronic for whatever reason doesn't like to run as
the just browser user. You might need admin to do the text, it just takes a really long time
exceptionally long time to do the text's speech. I'm thinking because it doesn't have,
I don't know, something about it running as a different user for whatever reason,
it's slower, I don't know why. So I have to actually, unfortunately log in with my regular browser
to do a report review and then I click log out when I've done. So I'm going to do a review of some
of the report, hopefully it's just a few findings so we should be good there. But I'll bounce back
and then we'll catch back up here and I'll tell you about some of the stuff I saw or didn't see.
Okay, so to give you an update, I'm kind of gone down, I have a whole like, helped the other
coworker. I went down a rabbit hole about memory and forensics, stopping a thing, and that was
about an hour, 30 minutes and provided some tools. I have on my website, a MimprokFS version
under the downloads folder that's for basically mounting in real time the Windows memory. They got
rid of some of the features and older versions of Mimprok. So the version I have is a statically
compiled version with the hash in the zip file name that has some extra stuff with some more
sensitive information in there. So getting around EDR and then also a MimprokFS and then when
PEMM dump, which is like a memory dumping tool that doesn't get picked up by EDR and then
Jamboree, which is my GitHub project, also has a button called Valtility3, which will
statically compile Valtility3 with you with a fancy packer so that it's nice and small.
That was the first change that I went on. Now, I'm on this sort of tangent to get this open SSL
thing to work with the test to kind of show that I can use a different
yellow wing here, so I can use a different tool instead of the Cisco tool so that I can
do split tonning tunneling. I don't necessarily, you don't necessarily need to do that. It's
most of the time you can do routing shenanigans with with an almost Cisco client, but I like to
show with OpenBVN, you can pretty much do whatever you want. So I always prefer an OpenBVP
in connection. Already Cisco connection because I know there's not going to be as many shenanigans
going on. So that brought me down the rabbit hole of my Jamboree with different pit versions and
the different pit versions. I only support, I think, 112, something 12 right now, my current
Jamboree. So it's kind of a problem because, you know, Jamboree needs to probably be updated.
Check, I thought it currently downloads possibly the latest. I don't know, check Python.
I got to find the actual script. It looks like it downloads. I use a new get
and you G, E, T. It looks like it uses just whatever the latest. Oh yeah. So it uses new get.org
for it's API for it's SV2 for it's package for it's Python. And that will give you the latest and
greatest Python inside of new get. So new get will support, it looks like really 510 to 26. So
it pretty much downloads the latest. Well, I don't want that all the time and this specific Open
SSL Open VPN desk single sign-on script wants an older version of Python. With that said,
the problem with all of my new get versions, some of them have pit binary concluded in them
and some of them do not. And I do not understand how to tell the difference between which one has it
and which one doesn't. So I'm working with AI to help me find all the possible combinations of
all the possible downloads of whatever. So now I've got a list of like, I don't know, 100 or so
different Python versions and I want to narrow it down to just the release builds. So right now I
have like pre builds, whatever. So I don't want all of the, there's filters that you can apply
in the version numbers, pre releases, pre, PRE releases, just the normal ones.
I'm using Kuro. I've survived to me by work. So technically speaking, this will go into my
personal project, but this is for work. So it's sort of, you know, kosher. So we have all the way from 3.5x
to 3.14x. So I have a big menu of choices here. So what I want to do is I also want to crawl
each link and get the final download path for the, for the download. So there's a download package link.
So I can say, right, a script to go to that URL, then pull the URLs, then go to each URL and the
list and pull the link, pull the link, um, oh man, I just messed it up. I don't want to
rather, this is just the normal ones. Yep, I'm going to dust group up and press it up there. So I want
to pull all the, uh, I want to not pull, go to all of, of the URLs in the list and then pull the,
see, pull the URL, download the, I want to copy and paste this, make sure I copy and paste
the, download package URL, paste, download package, link, list and pull the download package link
for all of them. So basically said, go to this URL, pull you all the different versions and then
you got, you get Python and then give me a list of all of the actual download URLs for each for each
one, right. So it looks like we got a, it found a way to pull the version numbers.
Yeah, it's using package 4 slash Python 4 slash version in a for loop and then it's pulling
down, it's doing curl to pull down the index JSON for each one and then parsing in real time
with, uh, with Python each, uh, download URL and then it gives me a full list of all the download
URLs. Now, the problem with each URL is I don't know which ones have, um, pip in them and which ones don't.
So I'm going to make it do all the work for me. There's like 200 downloads here. Normally,
I would download these and analyze them manually, but with AI and tokens, we don't have to do that.
So the AI, okay, for each download URL, download, download and extract the, uh, compressed
file and check for the binary, pip.exe and give me a list a table for each one that does not have a pip.exe binary.
Go, I used to go what the end is to understand what versions have a pip.exe and what
versions do not and why. Um, so now it's going to pull down a lot. These are actually small
like 15 megs. So each one of these is 15 megs. I mean, I am, I gather, I don't know how many there are.
There's a lot. So it's going to take it a minute to do this. Um, the reason I'm doing this is because
it wanted a specific version of Python. The problem with that is that you all know which versions of
Python are have pip in them already, statically compiled. The way these new get packages work is
there's um, Python you can get, which I haven't been able to trigger this out, but you can get
Python like embedded and that Python embedded has just Python in it, but doesn't have pip and I
don't know how to get pip working with just like the Python embedded that you get from like
Python.com. So I'm using these new get versions to get around it because they have pip already
built inside of them. So it's actually finding pip 3.exe instead of pip.exe. So that might be some
of why I can't find pip is because I'm looking for pip, pip.exe and that pip 3. So that might be one thing.
So we have it's dumping out to some trace logs. It looks like here.
It's using the API, which is what I should be doing. And when it's all said done, I'm going to tell
it give me a Python function to automatically bring up a menu and have the person select
versions of Python that we already know have the pip binary inside of them and exclude any of them
that don't have it that we know. And then then basically give me a list of all the Python's available
and exclude the ones that we know that we don't already have the pip binary inside of them. So that
way they can easily select whatever version of Python they want and know that pip is going to be
installed with it. So I have some weird, I have some weird shenanigans that I create a pip that
which basically calls Python and the pip binary inside of the scripts folder to get around
pip install whatever pip disk is. And seven have to do Python dash in module and call the pip module.
And then it's due in style that I just created a bad file and I put that in the same script folder.
So when you do call pip it just calls the command line which might actually break stuff because
if you just pass variables to pip. If you're a bad file you might lose extra parameters to
pip as you pass it. But it's in my knowledge I haven't found an issue with this. So we've got
so look at the table there for a second I saw something something knows something something
know. So it's still going to do it as thing. So I will put it on pause and then once this is
all done and I have the function ready then I will use that to figure out the closest version
I can find to the one that will this work for and then I'll go down the rabbit hole again
to try and get this Azure login working with open VPN which I probably don't even need to do
at this point. So I've complicated all situations. I'll probably just use the Cisco thing
and connect and then try to do my split tunnel stuff shenanigans to basically show clients that
hey you have essentially split tunnel disabled by default but all you have to do is do like some
routing commands and windows and as long as you have the network privileges user in windows which
is not normal usually most people just get the user or even more popular is the power user which
I think power user includes network operators but if you don't understand security the network
operators group is extremely powerful because that gives you the ability to manipulate
packets at the routing level and if you can do that then you can do a whole lot of scary things.
So just having a user that has regular user access but they have access to manipulate their own
packets essentially route their packets do whatever they want not whatever they want but certain
things you can change to redirect traffic route traffic you know potentially DNS I don't know the
extent of it but most of the work I've done with the network operators group is
changing my routing tables that I can do split tunnel or so that I can do weird shenanigans reverse tunnels
proxy things like that so it's all about that network layer so I'll shut up and then get back to you.
So before I forget I'm also adding my my power shell like steering file or skill file whatever
and I'm also telling it to use use add type assembly system when does system about windows.forms
as a menu to select the version to down do you know I'm asking it to do a lot here I wouldn't
normally do this in my local models this one is absolutely insane so I'm going to also include my
power shell power shell standardizer and it's a combination of of markdown files that I found on the
internet to do stuff correctly in power shell a lot of these things don't really do use my tricks
and a lot of them do like weird path stuff so it follows the rules of jambri essentially
and it also follows the rules of how to use power shell mostly correctly or at least the way
that I like to use it not so let's say also use the following guide to rate power shell
scripts and then I'm just paste this and hope 342 lines um at my current thing that would be
a line suddenly tokens that is but that would be a lot so I have an acknowledgement feedback
loops proper error analysts shaker file download using a dot net as a fallback batch processing
safe file division reading configuration files and about a bunch of things like don't use
all the cp and b r m cat p s grep curl would be get echo that those aren't power shell commands
I did hard code of user pests never use ckel and backslash users and b user program file
update so there's kind of a combination of my stuff in there and we'll see if it's doing
something um it looks like it added 221 lines and get python new get ps1
yeah it pays at a bunch of stuff sorry make this a function
for me
there make a function for me for me make this a power shell so a function
all right so we got some vip coded garbage here we're going to go to our jambory folder
which I don't even see here we go and gonna make copy back up my old before I mess with this
I have a standard build script that I run that basically I run on any windows image that
gives me like chocolaty in all kinds of stuff so chocolaty is a package manager
source in layer to actually jambory so we're going to make a new button here just for temporary
sake and I'm going to have it call the clicks whatever this function is
the function is get python new get I'm going to have it run this command
and hopefully it will work I actually have it running already so I want to call this pypoc
and the command is going to be run this and then I'm going to save it and then I'm going to run
jambory again um technically speaking you can run jambories many times as you want so you can
have a bunch of windows open the problem is that it gets pretty complicated once things get weird so
I have a python zip and a python zip and I'm going to delete both of those just in case there's
no convictions that I'm going to use my pypoc on the concept my menu came up so I like that
python version to download all of this versions include pippyxie pip3.exie so
which is weird because I don't even see 12 in here um so
that's not good um I only see 3.5 to 3.7 which is weird we're going to
download and extract and see how it goes um python extract it successfully
pulls pip are a bit 3 yep okay so we're going to go back to here
we're going to close this python minimize our window we're going to go back to the
we're not going to save this okay looks like you are missing
I'm going to save latest python which um I don't even know how this is going to work here
let me close this so I have my jambory open jambory window open I'm going to click shell again
because um I'm going to delete the python folder again click shell again and figure out what
version of python I get because I know this version the latest version has in fact it's own
pip so I can say pip and it gives me help it so no pip is there so I can say python such as version
I say hey looks like you're missing the lot so um notch i'm not sure
how you missed a lot of versions but you are missing people 1 4 5 that has a pip
I'll actually make sure I'm typing the right thing
pip 3.exe pip.exe one on the same that's kind of weird pip start out xe
yeah there's a pip pit 3.14 and pip other things there's like symbolic links or something I don't
even know actually let me go to the folder and let's prove it so this weird python has a bunch of
pips um yeah it's the same it's the same binary copy three different ways with three different names
you would normally do a symbolic link to that pip binary and not have three of the same
pips in one thing um so that's not really whatever um so let me go back to my prompt and say hey
this has pip.exe and pip 3.exe help me understand why you miss so many
other versions of their versions um so here we are you know like an hour later into this
I've already spent probably 30 minutes on it um threes and I am doing kind of a little bit
more bugged beyond is that this scope is very limited for this engagement so any what I like to say
color I can add to a existing thing um it's good because a lot of people will just do a test
they'll run a scan they'll do the thing um but if I a good tester will have a spidey sense right
and my arm my arm chair my arm handles are usually all the way down but the kids come in here and
mess with it um so if you have arm rest and you have back issues try and slam your arm rest all the
bit out I have a used which they normally sell these anymore because I got sued out of their pants
I have a used um fancy was it called arrow or whatever the fancy chair um um arrow
I don't know what the brand is um I've fixed a I've done after market seat that I had to replace
palm and miller their home and miller chair I have an after market seat that I've had no problems with
to replace the seat that I had it was the bolts for kind of oh wonky so anyways
I'm hesitant to never use python pit use python m dash pit okay so here here's the
squish was you're right call me out I was wrong and I really let me explain what happened point
actually contained in print has a pit python package but it does not have a
tail on pit of me sitting right at the older versions and then had a literal pit 3 and a little bit
however this is a key pit is still fully functional and 314 you can run a be a python dash in pit
or you can generate that video okay so my thing is I guess I figured out that pit runs
with new versions of pit so I guess I'm wrong I guess I forgot so pre-built pit is all the way to
three seven and then neither neither pit not bundled at all must run pit not proper to
putt insure pit first okay so python dash m insure pit I don't know what that does so let me let me ask
so what does
insure pit does that install pit if it's missing so yeah I'm asking it
insure pit I don't know what that does module that does do but module what it
oh well it's searching the internet for my dumb question yes exactly there's a bootstraps pit
from a bundled wheel that ships inside the python and stalk it itself it looks for a pre-packaged
video file so when we start talking about wheel that's when things get weird so I guess
so the lack of whatever okay just gives so far new get package already have wheel at
blah blah running python insure pit creates a little bit locally or you skip that step
insure entirely and just he's pit by that directly since pit packages are already unpacked
in site packages the easy to get to have check check pit bython and verify insure pit
wheels and scripts which suggest the insure pit module may be present with a bundled wheel but I
need to verify each one bottom line so for your script person is any version that has either
is that made is or effectively has pit so you just need to run one command okay just make sure
every download has pit has pit thanks um so I'm telling it to make sure every download has
pep where it's been extracted I don't know might be in the temple it's been dumping a lot of
they've been dumping a lot of stuff inside a pit template which is depending on how you have your
Linux structure up this your Linux structure is set up your temp file might not be enough storage
to extract copious amounts of data I've had to extract terabytes of data to the folders
and if I was running some kind of AI slot I would not want it extracting everything to force
temp because usually temp on some of these vpss or maybe you're given a weird excuse me a weird
setup to the home or the route going to have to be like you know 20 gigs and that's for your OS
and everything else you have to figure out and then these installers start dumping stuff everywhere
or Docker starts putting stuff in var which I've seen also it's always the same problem with
managing your managing your mounted paths if you have them mounted correctly
is an nightmare but it does prevent things like you're just filling up with wags or something like
that but a lot of times people don't split those up anymore I've never really seen it save anything
does a lot of times I'm running small services and it doesn't really matter if I can't write
and read a bunch of disks stuff so here we go it's saying use python and pip he's python on pit
so it's kind of doing a full evaluation of all of these now I've not talked about
I just clicked exit multi execution mode that's something horrible idea I've never used that before
so I use moba in on my website my just my get up I have a script called
um moba portable and it does the same thing as
planberry does but it's just for moba and moba is a windows terminal and I
co-worker from back for way back said something about moba because I was using portable
port of putty which is a portable putty version if you're a putty person I sorry you are wasting
your time um moba is fully featured it has built in x-server you can disable it by default
you can do tunneling it has an SCP server it has w self support it has automatic syntax highlighting
it has a support for different fonts it has you know multiple execution you can do tunneling
and that will say the killer feature for this thing is the tunneling there is no other app that I
have seen Linux or otherwise that does tunnels like this one so I can essentially copy a dynamic
and a static tunnel in the i and i file and basically go from you know something that would take
normally forever to do I can just copy a dynamic and copy a regular tunnel and copy a dynamic
basically for reverse channel it's whichcraft i'm only going to but basically for reverse tunnel
dynamic tunnel so you can basically set for reverse connection back to yourself and then set
a dynamic tunnel to that reverse connection to tunnel all of your traffic through that tunnel so that
way it's a reverse shell and then you reverse shell that shell through a proxy and then everything
on that proxy goes through that reverse shell so that's why things start to get kind of hairy when
you start talking about getting a reverse shell and you can proxy all your traffic through that
reverse shell you can and even with apps that don't support proxy you can use when does has a
couple of them pry boxy i think called you can force a TCP based applications to run through a
proxy that don't have proxy support so even where there's no support for proxy you can
use something like proxy chains and Linux to do that there's other ones that do manual proxy no
there's proxy chains and look couple of them i've always used proxy chains windows i use
privacy i've never had to really do that except for like third party apps that might have
some kind of weird thing and i want to tunnel the traffic to see it and they don't have a subscription
i will use five oxy to force that traffic through a barbsweet because the app doesn't have
proxy support but moba is awesome it's great i don't know if i have any videos on it
on there's probably tons of videos out there but just the way it manages you can have about a
reconnect so that way you're not accidentally doing traffic from a bad place it will automatically
reconnect so if you change if you move around change IPs if you're connected with different wifi
it will force that connection and it will nag you to death if you're not tunneling through that
connection so that's some of why i've always used it since then okay so i'm gonna try this for a
bit more time i i'm actually at a time for today uh gotta get back to family stuff so down
great you python 3.13 or 3.12 safest worker so i have going to click my PIC POC
python thing i only have my whatever version so that's not great
um i go back and rerun take updates python pick yeah it's missing the list of URLs so
i'll go back to the AI and look at my function i'm pretty sure i copy and paste it in this function
um let's see um there's a brown context of it yeah so update the power shell to include all versions
versions sorry not to just ones with pip xe binary so i told it hey i messed up you know
it i told it to check everything i told it to update i told it to update because it did
say cat whatever um so i said you know all stable whatever it's okay me sure every download has
okay just make sure every download has pip thanks and then um said all of the
gen have pip i was completely wrong earlier there are zero versions without pip here are the actual
breakdown here's my earlier breakdown i said okay whatever so let's see let's just include all
versions version sorry not just ones with pip binary there's a two i just heard it does that
it would version two okay so maybe you had just missed it writing a different file name um that's what
will happen to my local who do the same thing all end up with like like 10 different versions to
Java and like multiple different versions of the same function it's really hard to follow when you're
vibe coding all that stuff so i will put this back in here i will leave this running because i do
have yeah i'm gonna close it actually so when i update that function one more time
i use no pet plus plus mainly for first stuff um
thought about switching to something more powerful like my portable vscode to do stuff because i do a lot
of stuff in power so so there's a lot of goodies and vscode that go work around power so i'm gonna
click my POC python POC i've got all the way to um 10 11 12 13 14 it's kind of in the non-logical
order so i'll have it fix that in the background um can the order is is um not human
read a bow make it sort proper the make it sort properly so they think it's see
the versions go up and down because right now it says 3.99 and then 3.8 7 6 5 4 and then 3.13
3.1 2 10 10 so like 3.12 like it's looking for using to read so i'm gonna go back to this
to say 3.3.1 2 so i'm gonna click 3.1 2 3.1 see if i can't do this 3.1 2 with no
anything 3.1 2 0 maybe 3.1 2 3.1 2 9 3.1 2 0
so maybe like if you want one 2 5 i don't know so we'll see you what happens there
uh extract successfully so i'll go to my shell and the five on version
five on is not installed so somehow oh i got the folder paths messed up so
this needs to go here so it extracted but it extracted the file name so there's a file called
Pythandesh 3125 blah blah blah so i need to also tell it to fix that so okay looks looks like you need to
extract to base um uh to remove the folder folder ex folder ex direction
i don't want a folder called five out of just Python p-y-ton so currently it installs to
currently it looks like Python looks like it's going back slash high-thon back slash
i want to want it all to go in the folder x-slash Python without the sub folder
minimize the code minimize the i's the in my eyes well and i'm i's the code and don't
uh provide comments um uh uh the jibbery is already 1.24 kilobytes
um it's pretty massive uh the problem with that is more code more problems we've got
2600 lines of code and that's after like a i got rid of half of it so um it used to be twice as big
and it's well a i minimize it and i ran through about 90% of the code base checking it
and make it sure that it's whatever so we have done blah blah blah there's no comments
actually directly to Python that was so fast like 21 seconds sit to that jesus um destroy
my local AI um these are front-to-ear models a cloud hope this 4.6 is absolutely insane so
of course that's temp we have our version two again we're gonna bring it up one more time
the uh there's also a default text editor inside of here you can tell it to use a different
default text editor um this is 143 lines it is following my paramed stuff that i told to do
it don't uh jibbery doesn't have a paramed uh basically doesn't have uh safe functions essentially
proper functions they're minimized so there's a lot of extra stuff in this function but you know
we're doing it live right now and i will add uh i will add it to the main repo what i'm
done here so i'm running paramed part running it again i'm gonna delete the Python folder
this is actually i think it cleans up itself pretty good let's see so Python concept
314 312 this is easier to read i'm gonna do 3.12.5 click extract and then we got a little
message it says whatever and we're gonna take my Pythat file and i need to add it into the repo
but i'll put it in the tools and the i guess put it in tools slash this folder because there's
no scripts folder at all so i'm breaking a few songs what's it is so Python and Python okay
yeah Python and so now we're back where we were several hours ago so Python install open connect
SSO the weird thing is i'm not sure what it's doing i'm not sure why it kind of froze out
when i finally did get the open connect dash this is a Python module to install it's said like
blah blah blah off into canny whatever and it's almost like it's supposed to bring up a browser
and never really did so i need to incorporate this new Python function with my Python
great function it upgrades it and then creates that Pythat file to make it say you can just type
Pyth and do something so anyways let's go down to the bottom here and i don't know what that is
somewhere here is my fancy stuff there's the basement you i don't need to bring up the
i want to bring up the UI for that at some point so that's why i kept seeing nothing when i
clicked things um so open connect open connect somewhere i have
somewhere i have the the open connect dash SSO server yep so we're gonna go here
i close our remote thing out i want to put notes back in my main notes here
so i have kind of two notes going now which is kind of annoying so level deep bug
so i'm going to try to call this open connect after installing it again
no novel no module named pkg resources so i'm going to just copy and paste this
um uh Python modules are weird because you can write you can try and guess the Python
module but at the time i get it wrong where there's like there's a dash and it it's a little annoying
to have to do that so i'm not sure what's going on here quick patch for Python now when you
just start all over with a new session because new thread um here's my ear i think some running
Python one two again again um so i'm going to do this command it's telling me to run
tell me to install set up tools then older version um is running from so maybe the tip the set
of tools version needs to match the Python version that you're running so it knows that set up tools
80.0.0 matches my version of Python maybe we'll see so okay now i've got looks like it did something
let's see what we ended up with um the weird thing about the console window it's like a better
turn i'm still on command line the cmd.exe a lot of people have moved to the straight
just power of shell the problem of power shells i can't do like the r4 such as like it's hard to search
for files there's a bunch of other stuff that's kind of annoying to do um uh check your official
company's ip documentation so there might be some stuff going on here that i don't quite understand
how to fix um that i caught i pasted the the errors at some point
python in the set of tools yep we did that i gave you the thing and then you said um certificate
because the mitch match yep yep um how do i bypass the i just want to bypass i just wants to
bypass the SSL errors um we'll work on this a little bit and i'll leave you alone for a second
all right so it's gonna go to Costco with my wife but she's i guess leaving it's now it's
24 minutes after five you know nine to five working i told her i'd have finished something
and instead of asking me it's going on uh she just gave up and left so you know that's the uh
disabled path link uh i give it up and then i actually installed python to the main environment
problem with jambree is it when you do calls like open browser or whatever with python they don't
work uh because you know it doesn't it's missing a bunch of stuff so i'm right now um
trying to see what version of python i have here are as i have uh three twelve five so i'll
save it to install um pippin stall whatever this thing is um do i go back one of these no no no no no
actually that was it um so let me let me let me try to get this work in nolsy let me go okay so
effectively given up now i managed to get uh open connect access is so working with the whole regular
normal windows environment um i hate installing anything on windows oh my you like to use jambree
but in this case it's a virtual machine i blow them up anyways after engagements so i installed uh
python the older version of python i told it to do whatever and it's doing the exact same thing
it's just sitting here at the authentication prompt so i'm not going to go crazy uh testing that
so i'm just going to use the regular VPN client so pretend how to say anything about open vpn
and open connect and doing routing exchange against we're not going to do that today because we were
only asked uh this is the problem being uh me we were i was only asked to test my credentials
and make sure they weren't not to go down the rabbit hole that i did so uh we're
going to put in the thing we're going to check enhanced session before we connect because if you
try to connect with the enhanced session again it will disconnect you because it's makes sense if you're
more on you don't know how a package worked you will get disconnected remotely and then you'll have
this session open on the other end and you'll be like oh every time i you know connect to the VPN
it just like disconnects me and then i don't know what's going on it's full of law so to make it
idiot proof Cisco's like all right we're just going to block anybody that's like doing an
RDP session or whatever uh to cave from stupid people saying like well i taught my arms off
because i connected to a you know no uh no whatever VPN so uh i taught my arms off because i connected
to a VPN that doesn't allow us with a toning which you're going to kick yourself offline unless
you have some kind of remote shell set up so my kit uh laughs about let me talk about
proxies and stuff all the time so uh mobile external portable power shell i run that it starts
power uh mobile with my portable settings so i can just kind of copy the files around there is a
master password that is encrypted with the uh encryption uh i don't know how it incorporates with
the tonaling aspect of it i think they're separate so if you take the tonnel i and i you're
basically screwed so it i think i don't know um it would i need to do some research to figure out hey
it all these credentials that i have uh for external sources are they part of they um
is that part of the whole certificate chain or is it you know is it a certificate store essentially
that's uh is in there and there's not any there's not any sensitive information is not protected by
my original password password thing so anyways what that said um you know keys keyless whatever
that's on on your own so if you have keyless this is a demeaning you can access agent to a computer
without any credentials at all you just provide a key um that's i don't know either way um you
want to have passwords no matter what so anyways i'm told to text this uh SSH on it tell on SSH
into this don't know the username i think i know the username and hopefully i copied and
pasted it somewhere there's host name i'm missing username so hopefully the i can find one of the
six places that my username could pass possibly be um oh cool the passwords completely different
for this uh machine so whatever um now i can't copy and paste since since i'm connected now
i can actually enable enhancement and i can um copy and paste stuff so i can actually remotely
mount my uh local system because that's how RDP works but i'm not going to do that because i need to
get going here so bureau it's a company work for the uh that's gonna be out of username
and i'm assuming the port is that and then we'll go and nothing of course not of course so we're
going to do um make sure we're on the VPN we're connected so we're going to do
and you know what and i i've found we're opting to not um i have issues with this so
and map and map and map out maybe it's not RDP maybe it's RDP or because i've turned so there's
client i'm going to put that IP address in there um because when they say remote access they don't
didn't know what people just assumed that you know what you're they know what you're talking
about so we're going to see what happens when i put in the IP for no either neither okay so
um a lot of times people give you VPN access you're not actually um a lot to hit any of you
can't hit anything sometimes so then you wonder what we're going to do reverse mode we're going
to do all ports so dash p dash sorry talking about in map is a port scanner so i'm doing in
map with dash p dash no spaces that does every port and then the IP address and then vvvvv which
is super verbose it'll basically tell me if there are any ports of been on this host so
it's doing DNS resolution which you can innate disable with dash d and this is not good um so we
don't have a connection we're going to show this in a uh in a screenshot i guess and show that you know
it's it's not it's not a thing so uh to connection refused and then we're going to show
we're going to wait for the 65,000 to pop out um same thing we're going to take a screenshot
and we're just going to paste it in the window here i'm not going to put the RDP up because that looks
that makes me look dumb um so something like that and i'll set this off to the client so we're
done for today um looks like it looks like i can can't reach but anyways i'll just go
that's kind of my my approach for today you know you go down rabbit holes sometimes you have
time for them sometimes you don't um anyways my wife didn't want to wait another 23 minutes but you
know these things take time anyways um i'll let me know in the comments if this is too long
if this is useless i don't know um it's a cool idea but when i'm doing work and it's not exciting
nobody wants to hear that but i don't know what percentage of this maybe what percentage of this
entire hour and basically 30 minutes of me hammering is actually useful um is it over your head
obviously maybe possibly and also you know not super useful i don't know but i i got the idea
from whatever his name is like hey this is my music me working i can't show you my screen but i can
talk about it and that's actually really powerful so anyways take it easy good luck um if you have any
questions about anything make a sure about it or maybe put in the comments if you're still
listening put in the comments if you want me to expand on any of these everybody but
janitors or whatever actual people uh each of our janitors um i'm not gonna a lot of time to make
shows out of all these but the idea is to as i'm working make a uh if i'm doing something
somewhat interesting make a uh episode about it because i'm here and i'm working so i might as well
be babbling babbling while i'm doing it anyways take it easy
You have been listening to the Hacker Public Radio podcast, at hackerpublicradio.org.
Today's show was contributed by a HPR listener like yourself.
If you ever thought of recording a podcast, then visit the HPR site to find out how easy it really is.
Hosting for HPR has been kindly provided by anhonesthost.com, the Internet Archive, rsync.net, and the HPR Community Content Delivery Network.
Unless otherwise stated, today's show is released under a Creative Commons Attribution-ShareAlike 4.0 International (CC BY-SA 4.0) license.
