Episode: 4682 Title: Behind the Keyboard: A Cybersecurity Operator’s Real-World Workflow Source: https://hub.hackerpublicradio.org/ccdn.php?filename=/eps/hpr4682/hpr4682.mp3 Transcribed: 2026-07-31 16:16:43 (official HPR transcript) --- This is Hacker Public Radio Episode 4682, for 2026-07-14 Today's show is entitled, "Behind the Keyboard: A Cybersecurity Operator’s Real-World Workflow" The host is operat0r and the duration is 01:23:16 The flag is Explicit, and the license is CC-BY-SA The summary is "The presenter outlines a practical cybersecurity workflow, covering ergonomic setups, browser isolat" Hello everyone, welcome to another episode of HectorPoke Radio. It's going to be kind of another attempt at, I don't know if I've released the other one that I did or lost it, but kind of what I'm doing at work and how what I'm not what my approach is. So, today I have to check up on a test before I run it. So, make sure connectivity works before I do it engagement. I'm kind of going to start from the very beginning. My feet are flat. My screen is actually too high. It's supposed to be at your eye level. So, the top of the screen is supposed to be at your eye level. Mine's about the mid level. So, my screen should actually be lower. Can I slam it down anymore? No, so it's oddly too high. The reason it is too high is because my posture is so bad. I have to put my elbows up almost shoulder length between my tip and my shoulder. That's where my arms, my elbows are resting. So, I'm almost like a, my arms are out to the side. I have a split keyboard. It's a freestyle. Free style too. I just bought another one because maybe I've got an angry and banged on it and the Oki quit working. Very soft keys, very nice. Kind of the higher end keyboard. So, I'll keep already getting anywhere but this one lasted me four or five years, three or four, five years, something like that. Then I have a curved monitor, 49 inch ridiculous thing. And that's been great for games. Been good for work and productivity. And I think I like it. So, I'm still trying to get you set. So, that's kind of my setup ergonomically. I do want to do eventually. I'm still working on it. I need to take off quite a few days to go full on. No keyboard, no mouse using an eye tracker and voice control. And I'm still working on beta for testing for a GPU-based voice guidance. And once I get that, then I will have to worry about CPU getting pegged and that will solve a bunch of other problems I've got. So, anyways, what I have is I have talent voice running. I have a sync for my notes, which are secure notes, which are insecure notes. So, plain text using Obsidian. And I've just did an episode of Obsidian. I'm experimenting with getting off of Google Keep. So, trying to get separating my notes and combining them to a more AI-friendly cloud-based fancy notes instead of just plain text notes. So, I'm switching to Obsidian. Trying to try that to talk to hopefully eye things. That's kind of my setup for notes. What else do I have running here? AutoHackies, signal for personal messaging. And so, what we're doing here is I have generally everything runs as its own user. So, I don't browse the internet as the user, the same user I do my work stuff with. So, technically speaking, I'm using the work computer for personal things. Like anyone does, I don't know if there's anybody that doesn't do maybe in a high security environment. You might not have to do anything personal on your work machine, but they're kind of one of the same sometimes. So, for me to mitigate risk, I have a single shared folder that is called Delete actually. In that folder path, it's in a specific path, that folder is shared between both the user, the normal work user, and the internet user that is a jailed essentially user that doesn't have access to break anything, right? That is because I have, I don't know how many plugins, I actually just posted them. And of course, I could do a show on this, but I will not chat. The plugins I have, you can ask AI to give you a list of the plugins that you haven't installed, which I thought was pretty cool. It's like, I don't know, whenever I tell anything to do with the browser, I tell it to use this, the debug, the Chrome debug commands to do all of that, and it'll basically have you run these crazy commands to debug to show whatever you want to show. So, there's an about extensions, link, and then inside of that about extensions, you can run a command, and it will give you all your plugins. So, let's see how many I got. It's not a time, I'll just take a second. So, I'll have to belive, of course, let's usually cookies, usually I use effort, deleting cookies, and deleting swords, cookies, things like that, and outside of the Chrome debug, I could probably do it there. But I do it per bone domain, so it makes things a little bit easier and kind of predates all the super fancy Chrome debug stuff. Both media downloader, excuse me, that's a multi-threaded swarm, if you will, a downloader, a GRO, which is kind of, it makes titles and thumbnails better for YouTube videos, instead of the shock and all, annoying ones. Their user created, and you can tell at the picker random frame, I think, of course, read aloud, which is good. It uses, I'm using, with read aloud, I'm using the super-tronic voices, which is kind of like pocket voice, very lightweight, Texas, Texas, speech engine, great, very fast. Last pass, of course, proxy switch. Wow, okay, sorry, my TTS is going off, because I click the button. So, proxy switch, any kind of proxy switch, proxy switch or mega, that's kind of needed for whenever you need to tunnel around. Things to get me as a free thing, I use Amazon's gift, what was the Amazon's thing, a liquid letting you put random stuff on Amazon, so things to get me having used in based on my voice. Ever seen for thinking bookmarks across multiple devices, multiple user names, volume master, is great for amping in the volume on videos for whatever reason my volume is always really low. Like YouTube videos or anything in the browser, for whatever reason, global speed, video speed, controller, that one specifically is a very specific one, so the plugin ID ends in I or end-to-go, no, I don't know what the phonetics are, well, India, India, Fox, Fox, and I don't know what F is, Fox, try it. So anyways, global speed, space, dash, space, video speed, control is phenomenal, because if you are doing corporate training, or some kind of training that involves a video that you have to watch to the end, about 80% of the time, I can click to make the speed like 16x, and I will get done with my training 16 times after. You can also download those, create a convert them to speech using whisper and prioritization. I have a static binary on my site, it's under the scripts folder, it's called like whisper diarization, if you want to try it out, it comes with all the, all the drivers, bundled into it for Nvidia with CUDA Torch 12 in the support sector, so you can just run that zip and extract it and you can do diarization and assign speaker names and stuff, and then you can convert that to a summary and then you can do whatever testing you need to do. Not that I encourage blasting through training things, but let's all be honest, I don't know anybody that actually does any training and pay attention. So with that, I can get notes and actually query those notes if I actually, an inquestion about a process or a specific compliance thing that's that I'm questioning. And oftentimes, that is there, and you can't enforce it because nobody wants to use the band hammer and nobody cares about security. So anyways, security theater, as we go on, turbo download managers, classic version, and then I have turbo download managers or third edition, which I think I need to get rid of the classic, if I'm mistaken, and I know I've deleted their on one, so I have both of them on there. Rango, RANGO, RANGO is what I'm using for voice based, voice based, clicking a button. So each element on the site has a little monitor above it, and I can say a bit underground or whatever the words are, I don't know the fanatics for talent voice, but you can say the fanatics for those, and talent and voice will pick it up and it will click the button for you. I don't even know a fox, it sit, yeah, I think talent voice has to be running for for this to work, because my mic is on. So anyways, that goes in the browser, and it clicks, it's easy way to click button. So instead of using the IR tracker to click buttons, I can just move ahead around a sponsored block for YouTube, of course, down a minute, again, privacy banner, and a scrap fly, anti-bot detector, which I've been using to, I'm trying to make it, but scraper slash AI error, checker tool, thing to help with this and that stuff. So the idea is, I can use scrap fly to scrap fly to easily identify what sites the protections this site has, and try and work around to work around those. So I've boarded you with all my stupid chrome plugins, the reason I went through those is because that's a lot of chrome plugins, and that's a lot of a text surface to worry about. So instead of worrying about that with my work account, I run a jailed a normal user account on the system, and that user account only runs as the browser, it doesn't do anything else, but run a browser. Technically speaking, if you had like a VM escape, and you could like do a key log through that, or whatever you could technically cross those bridges, but you know, that's not something I'm necessarily concerned about, I just don't do work stuff with this browser. The other browser has three plugins, it has last pass, and that's pretty much it. Brain goes on there, which I need to actually remove, that's not really secure, so we remove that, and then pretty much other of the retail out text speech. Now, I also have a script that will nuke the update servers. It's under fu.txt, frelo 101 GitHub. So if you look for fu, that's fox, I don't know, unicorn. fu.txt, and then frelo 101 frelo 101. That's our own search. I'm also playing with my own search that uses Google search, essentially, with open web but I won't bore you with that. So we're going to go frelo 101 fu.txt, and it should pop up up in the search. Yeah, and in here, there is a thing that helps you to help protect against water and collect x. It also prevents the app from being updated, so it for like a better term freezes the app. So it looks for a file called manifest.jjson, and that manifests.json defines a lot of things, mainly where the upload URL, the update URL is. For that particular plugin, right? So if and when these plugins get compromised, it won't matter to me because I'm sending it to a nowhere place. Interesting enough, the first time I came up with this idea, I had so many plugins installed when I ran it. I noticed very quickly that Google, all of a sudden, had like meet singles in your area, I'm like, what? So basically one of the plugins I had that was to rip way back, I think it was maybe flash or video content, some kind of video content, before I learned how to do stuff with FFMPIG and different kind of packet numbers for the browser. Download the download watcher that I use is called. Interesting enough, I didn't hear it in that list that I was talking about. Yeah, but we did a downloader. I use for most of the URL stuff. Anyways, before I did that, I use that and that particular plugin or extension had like if I can't phone home for updates, just turn the plugin to spam addware. I was like, okay, that's kind of gross. That's, you know, an interesting text surface to think about. So not only could these things get taken over, they might have code in them to serve up ads, which is a problem in itself because a lot of these ad companies are basically sleazy, dark corners of the internet. So that's an attack surface. You have to also think about not only updates, servers can compromise. If these things are configured to throw ads up, if they can't talk at home, those ad providers can possibly be compromised also. So I mean, we're talking about extensions for browsers. It's pretty terrifying. So the amount of power these things have and Chrome has done a lot of work to minimize that threat, but I'm not going to ramble any more on that. Let's do something fun. So I've got, I've tested my access to the thing I'm trying to do through using Hypervia, use Hypervia and Windows. I'm pretty much all Windows now and all all into WSL and Windows virtual V Hypervia. The reason I am is because you can pretty much do everything you need to do in WSL. It's a, there's some lag there, of course, and you don't want to do like GPU stuff necessarily inside of a WSL thing, but it is possible installing like, what is your tools? So what I'm going to do is I've already checked my VPN access to make sure I can get to connectivity to work. What I didn't know or understand is that I was supposed to check access to a particular host that I'm supposed to be doing testing from. So I'm not doing testing directly from the VPN host. I'm doing testing from a virtual machine inside of their infrastructure. So I'm looking for my notes, hopefully, or in here somewhere, and there should be like a pad here. I don't think there is. So we'll go this way. At a lot of these VPN clients won't let you split them up. They also won't let you connect to using enhanced sessions in Windows. So the problem with enhanced session with virtual, the VM, VM, virtual machine stuff for Windows is that they all want to use, you create a shortcut here. I use Tera Copy and Windows for shortcuts and stuff. So I've been pretty happy with it and I actually paid for it. It's good for copying lots of files and ensuring you can pick up where you left off and it's a lot better manager. So I've got, I've guessed actually without the client telling me I've done passive recon to figure out their VPN hosts. And unfortunately, there's a sell areas, which is not particularly great, but we're going to just make that a finding when we're doing our testing. So we've got connected to what looks like a VPN and then it disconnects me because I did not uncheck enhanced session. The enhanced session is basically a RDP session to the local host of the guest machine and I can't type my password. So now I have to re-connect to the VPN because I did not, I did before I used the VPN client. I did not disconnect the essentially RDP session to myself. So it's like a local RDP session to the client host. Now once I've connected what I'll notice is that now my split tunnel is gone. I don't have access to the local machine. I don't have access to anything. Now what you can do and I'll probably do this while I'm on the form when I, I will use open connect. A lot of people don't block VPN access. So if you try to do an SSH tunnel, it doesn't work. Try open VPN and that doesn't work. Try S tunnel. That doesn't work. Try DNS tunnels. So there's a lot of, a lot of moving parts within these organizations and they don't want to block third parties from being able to do their jobs. Nobody wants to do that guy. So they might have the most secure system in the world but then they allow the you to use open VPN to connect to any host. There's no whitelist thing. So there's like we allow open VPN out and you'd be surprised at what types of places high security places allow you to use open VPN to connect but basically negates the whole point of the whole thing. So Windows and Cisco client does happen particular controls and it to force the client to do specific things. But if you use a VPN and I'm getting a certificate error which is again, okay. So now we have certificate from bubble block fail to trust this server in the future, bubble block. Please complete authentication process in any connect login window, no SSH tunnel or failed to complete authentication. Which I feel like means that they are enforcing any connect stuff. So I'm going to take this and give it to AI and ask AI how I buy it has it. So I say I get the Pintest prompt and I say how do I buy Pest? How do I buy this this error? I want to make this a finding with the client. So the client gave me access to, oh I can't. I'm just going to do a screenshot because the turn to copy and paste now I have to do a bunch of stuff. So instead of doing that it's going to send it to a screenshot that is sanitized of course because we do not want to be feeding the trolls. So I'm going to omit the the host name and I am most of the key and I'm just going to give it that thing. So I say screenshot because I don't feel like switching. How do I buy Pest? It's here. Miami, Miami do something in the background. I also have local models I use if I'm going to do anything sensitive. I use local models because my every time I start up my server the whole chat is wiped out. So basically anything that's sensitive in my open web UI is going to get nuked every time I reboot. So there's no reason for me to have any cash in there. I have no reason to go back and if I do want to keep notes I you put them obviously and I'm sitting in. So I don't want chat history or any of that stuff being in my thing. So here we go. It looks like it's going down the open connect rabbit hole is which I want to do. I don't want to use any connect. It doesn't any connect to say what it may be called fine. So VPN serves self-signed. Yeah that's fine. Whatever open is a self-connect open. Love of a reveal it's first connect. Surfing a quick base since it's before server hash. It says it only has an edge of the variety. No as a cell and saw open connect SSO. Tell me to do like a pip install open connect SSO. So this is like a different thing. I wonder if that's an app inside of here. Never heard of that. Open act SSO windows. Looks like a some open source project. Installation. I don't really have pip necessarily. This is weird. Okay so manual Sam, some will cookie injection works. P out protocol and you connect. Okay so open connect V and then the host. So let's try to do that. Of course I can't copy and paste again. Or so I have instances like this. I have a script that I can out of hockey. Has a script if I do control Z. My controls my sorry. My control key is caps lock because I basically have a couple at this point from doing control C control V control C control V for 18 hours a day. So now my control copy is control A, paste is control S or sorry. Copy is caps lock A, paste is caps lock S. Some other hockey's are W and E and things like that. X I want to use Z is to type what is in the clipboard physically right with a certain delay. So I press that and I click and I hope that it happens. It does not happen which I've noticed with this. I killed the I also have the same macro running on the virtual machine itself. So that's some of it on a test of locally caps lock Z and we're going to see if it's typing what it's supposed to type. Then it is it's typing it. So I would expect there's a delay after I so that I can click where I need to click and it doesn't do it which is very odd. Usually that means you're not running as administrator. You're not running auto hockey as administrator. So that might be it for this exercise at least. I would say the easiest thing for me to do is I guess switch back to Enhanced Session. Get the notes I need to put in there copied and pasted. So I switched back to Enhanced mode so that I can copy and paste. So manual is cookie injection method combined one minor. So I would bring all of this in and see if this works. Actually works with the host. I take it back off of the problem with switching back and forth the Enhanced Enhanced Session is that you have to, well again every time. Just kind of annoying. So I have my little command that I might want to enable available off groups. Sure. Let's do what it says. So I'm back on regular mode and I type things that is says the type or a copy and paste error and handling command line, error and command line handling. I don't know if I click yes. It might be just like a result of a result of the security enforcing of like this is goes on something tells me that that might be problem. So I'm going to use dash protocol any connect and dash server cert and use the hash that was given back to me. I don't want to hope that works because this would be kind of a nice finding to have because when you can that did not work at all. I got the ever popular when you put the command line in correctly. It just dumps out the help. It doesn't tell you anything about the error message or what you screw it up syntax. So I'm looking at no server specified. Well that's my fault because I didn't put a server at the end. So that is my fault and actually gave me an error which is nice. So copy and paste it again. I'm very anti type anything. I pretty much copy and paste every single thing I can. So yeah it says no SSL handler which doesn't make any sense because there's no SSL built into this just kind of strange. So once I'm, let me just keep going down this road. So jambri, jambri, read or crazy.com. jambri is my little portable portable everything framework. Wow really. jambri.com. It's a power cell script that gives you basically everything and one portable thing and also it does not mess up your current environment. It resets all your current environment variables mostly to just work. So I'm going to make a new folder for a client which is this guy and I'm going to make a new folder for jambri. jambro, SSL because I'm trying to do this SSL something. So from this power cell script I'm going to click it. I'm running the least one it checks for the latest version. I'm going to click shell. Once the UI comes up it's a horrible UI that's just like whatever. I'm going to click shell and it pulls down a number of things. It pulls down enter. I can Android command line tools which you know you don't need that really. It pulls down java and it pulls down hopefully the Python will come here in a second. The downloader I had to fix here fairly recently because there's something weird with a specific website that was like chunking weird. If you use the native downloader for Windows it's more for power cell. It's bad. So I wrote or I had AI right one or I found one online and then I had AI right one when I had problems with the downloader. So the downloader is pretty solid as it stands now. We got Python, we got git, we got some extra libraries that we might not meet and we got we updated pip. We are downloading npm and now I have a shell with java, git, pip, npm, node and does it java? I'm missing one. Anyways so now I'm ready to go. So I can do pip install whatever is talking about. pip install this open SSL open connect SSL. So I'm going to copy this paste, can I not copy and paste, pip install, did I not, did I not unenhanced anymore? I'm not unhanced anymore has my problem. I don't want to be unenhanced actually. So pip install open connect SSL. So this is some kind of shim for open connect to handle any connect single sign up. I had a guess. So I'm going to look here while it's installing. We're going to educate ourselves. In the course I got a builder because Windows is awful at doing anything with wheel, good.google.com. I'm using Google, I use these, I use these coggy, like 300 bucks a year for their thing and you get a healthy amount of wrapper script exactly, wrapper script for open connect supporting Azure, Sample 2, Authentication 2, Cisco SSL VPNs. Oh that's actually exactly what Microsoft Azure's vizor creator is more required for this C++ build. So when we're coming past this, we're going to go here, we're going to go to com and we're going to say AI mode and we're going to get our free AI answer without even signing in. Right works, use to the installer. So I'm going to pause and not bore you with this part and get this working first and then we'll go over there. So I wanted to jump in here because I'm doing a someone posted to do a report review. A problem with doing a report review and my current flow is that the text is speech engine that uses supertronic for whatever reason doesn't like to run as the just browser user. You might need admin to do the text, it just takes a really long time exceptionally long time to do the text's speech. I'm thinking because it doesn't have, I don't know, something about it running as a different user for whatever reason, it's slower, I don't know why. So I have to actually, unfortunately log in with my regular browser to do a report review and then I click log out when I've done. So I'm going to do a review of some of the report, hopefully it's just a few findings so we should be good there. But I'll bounce back and then we'll catch back up here and I'll tell you about some of the stuff I saw or didn't see. Okay, so to give you an update, I'm kind of gone down, I have a whole like, helped the other coworker. I went down a rabbit hole about memory and forensics, stopping a thing, and that was about an hour, 30 minutes and provided some tools. I have on my website, a MimprokFS version under the downloads folder that's for basically mounting in real time the Windows memory. They got rid of some of the features and older versions of Mimprok. So the version I have is a statically compiled version with the hash in the zip file name that has some extra stuff with some more sensitive information in there. So getting around EDR and then also a MimprokFS and then when PEMM dump, which is like a memory dumping tool that doesn't get picked up by EDR and then Jamboree, which is my GitHub project, also has a button called Valtility3, which will statically compile Valtility3 with you with a fancy packer so that it's nice and small. That was the first change that I went on. Now, I'm on this sort of tangent to get this open SSL thing to work with the test to kind of show that I can use a different yellow wing here, so I can use a different tool instead of the Cisco tool so that I can do split tonning tunneling. I don't necessarily, you don't necessarily need to do that. It's most of the time you can do routing shenanigans with with an almost Cisco client, but I like to show with OpenBVN, you can pretty much do whatever you want. So I always prefer an OpenBVP in connection. Already Cisco connection because I know there's not going to be as many shenanigans going on. So that brought me down the rabbit hole of my Jamboree with different pit versions and the different pit versions. I only support, I think, 112, something 12 right now, my current Jamboree. So it's kind of a problem because, you know, Jamboree needs to probably be updated. Check, I thought it currently downloads possibly the latest. I don't know, check Python. I got to find the actual script. It looks like it downloads. I use a new get and you G, E, T. It looks like it uses just whatever the latest. Oh yeah. So it uses new get.org for it's API for it's SV2 for it's package for it's Python. And that will give you the latest and greatest Python inside of new get. So new get will support, it looks like really 510 to 26. So it pretty much downloads the latest. Well, I don't want that all the time and this specific Open SSL Open VPN desk single sign-on script wants an older version of Python. With that said, the problem with all of my new get versions, some of them have pit binary concluded in them and some of them do not. And I do not understand how to tell the difference between which one has it and which one doesn't. So I'm working with AI to help me find all the possible combinations of all the possible downloads of whatever. So now I've got a list of like, I don't know, 100 or so different Python versions and I want to narrow it down to just the release builds. So right now I have like pre builds, whatever. So I don't want all of the, there's filters that you can apply in the version numbers, pre releases, pre, PRE releases, just the normal ones. I'm using Kuro. I've survived to me by work. So technically speaking, this will go into my personal project, but this is for work. So it's sort of, you know, kosher. So we have all the way from 3.5x to 3.14x. So I have a big menu of choices here. So what I want to do is I also want to crawl each link and get the final download path for the, for the download. So there's a download package link. So I can say, right, a script to go to that URL, then pull the URLs, then go to each URL and the list and pull the link, pull the link, um, oh man, I just messed it up. I don't want to rather, this is just the normal ones. Yep, I'm going to dust group up and press it up there. So I want to pull all the, uh, I want to not pull, go to all of, of the URLs in the list and then pull the, see, pull the URL, download the, I want to copy and paste this, make sure I copy and paste the, download package URL, paste, download package, link, list and pull the download package link for all of them. So basically said, go to this URL, pull you all the different versions and then you got, you get Python and then give me a list of all of the actual download URLs for each for each one, right. So it looks like we got a, it found a way to pull the version numbers. Yeah, it's using package 4 slash Python 4 slash version in a for loop and then it's pulling down, it's doing curl to pull down the index JSON for each one and then parsing in real time with, uh, with Python each, uh, download URL and then it gives me a full list of all the download URLs. Now, the problem with each URL is I don't know which ones have, um, pip in them and which ones don't. So I'm going to make it do all the work for me. There's like 200 downloads here. Normally, I would download these and analyze them manually, but with AI and tokens, we don't have to do that. So the AI, okay, for each download URL, download, download and extract the, uh, compressed file and check for the binary, pip.exe and give me a list a table for each one that does not have a pip.exe binary. Go, I used to go what the end is to understand what versions have a pip.exe and what versions do not and why. Um, so now it's going to pull down a lot. These are actually small like 15 megs. So each one of these is 15 megs. I mean, I am, I gather, I don't know how many there are. There's a lot. So it's going to take it a minute to do this. Um, the reason I'm doing this is because it wanted a specific version of Python. The problem with that is that you all know which versions of Python are have pip in them already, statically compiled. The way these new get packages work is there's um, Python you can get, which I haven't been able to trigger this out, but you can get Python like embedded and that Python embedded has just Python in it, but doesn't have pip and I don't know how to get pip working with just like the Python embedded that you get from like Python.com. So I'm using these new get versions to get around it because they have pip already built inside of them. So it's actually finding pip 3.exe instead of pip.exe. So that might be some of why I can't find pip is because I'm looking for pip, pip.exe and that pip 3. So that might be one thing. So we have it's dumping out to some trace logs. It looks like here. It's using the API, which is what I should be doing. And when it's all said done, I'm going to tell it give me a Python function to automatically bring up a menu and have the person select versions of Python that we already know have the pip binary inside of them and exclude any of them that don't have it that we know. And then then basically give me a list of all the Python's available and exclude the ones that we know that we don't already have the pip binary inside of them. So that way they can easily select whatever version of Python they want and know that pip is going to be installed with it. So I have some weird, I have some weird shenanigans that I create a pip that which basically calls Python and the pip binary inside of the scripts folder to get around pip install whatever pip disk is. And seven have to do Python dash in module and call the pip module. And then it's due in style that I just created a bad file and I put that in the same script folder. So when you do call pip it just calls the command line which might actually break stuff because if you just pass variables to pip. If you're a bad file you might lose extra parameters to pip as you pass it. But it's in my knowledge I haven't found an issue with this. So we've got so look at the table there for a second I saw something something knows something something know. So it's still going to do it as thing. So I will put it on pause and then once this is all done and I have the function ready then I will use that to figure out the closest version I can find to the one that will this work for and then I'll go down the rabbit hole again to try and get this Azure login working with open VPN which I probably don't even need to do at this point. So I've complicated all situations. I'll probably just use the Cisco thing and connect and then try to do my split tunnel stuff shenanigans to basically show clients that hey you have essentially split tunnel disabled by default but all you have to do is do like some routing commands and windows and as long as you have the network privileges user in windows which is not normal usually most people just get the user or even more popular is the power user which I think power user includes network operators but if you don't understand security the network operators group is extremely powerful because that gives you the ability to manipulate packets at the routing level and if you can do that then you can do a whole lot of scary things. So just having a user that has regular user access but they have access to manipulate their own packets essentially route their packets do whatever they want not whatever they want but certain things you can change to redirect traffic route traffic you know potentially DNS I don't know the extent of it but most of the work I've done with the network operators group is changing my routing tables that I can do split tunnel or so that I can do weird shenanigans reverse tunnels proxy things like that so it's all about that network layer so I'll shut up and then get back to you. So before I forget I'm also adding my my power shell like steering file or skill file whatever and I'm also telling it to use use add type assembly system when does system about windows.forms as a menu to select the version to down do you know I'm asking it to do a lot here I wouldn't normally do this in my local models this one is absolutely insane so I'm going to also include my power shell power shell standardizer and it's a combination of of markdown files that I found on the internet to do stuff correctly in power shell a lot of these things don't really do use my tricks and a lot of them do like weird path stuff so it follows the rules of jambri essentially and it also follows the rules of how to use power shell mostly correctly or at least the way that I like to use it not so let's say also use the following guide to rate power shell scripts and then I'm just paste this and hope 342 lines um at my current thing that would be a line suddenly tokens that is but that would be a lot so I have an acknowledgement feedback loops proper error analysts shaker file download using a dot net as a fallback batch processing safe file division reading configuration files and about a bunch of things like don't use all the cp and b r m cat p s grep curl would be get echo that those aren't power shell commands I did hard code of user pests never use ckel and backslash users and b user program file update so there's kind of a combination of my stuff in there and we'll see if it's doing something um it looks like it added 221 lines and get python new get ps1 yeah it pays at a bunch of stuff sorry make this a function for me there make a function for me for me make this a power shell so a function all right so we got some vip coded garbage here we're going to go to our jambory folder which I don't even see here we go and gonna make copy back up my old before I mess with this I have a standard build script that I run that basically I run on any windows image that gives me like chocolaty in all kinds of stuff so chocolaty is a package manager source in layer to actually jambory so we're going to make a new button here just for temporary sake and I'm going to have it call the clicks whatever this function is the function is get python new get I'm going to have it run this command and hopefully it will work I actually have it running already so I want to call this pypoc and the command is going to be run this and then I'm going to save it and then I'm going to run jambory again um technically speaking you can run jambories many times as you want so you can have a bunch of windows open the problem is that it gets pretty complicated once things get weird so I have a python zip and a python zip and I'm going to delete both of those just in case there's no convictions that I'm going to use my pypoc on the concept my menu came up so I like that python version to download all of this versions include pippyxie pip3.exie so which is weird because I don't even see 12 in here um so that's not good um I only see 3.5 to 3.7 which is weird we're going to download and extract and see how it goes um python extract it successfully pulls pip are a bit 3 yep okay so we're going to go back to here we're going to close this python minimize our window we're going to go back to the we're not going to save this okay looks like you are missing I'm going to save latest python which um I don't even know how this is going to work here let me close this so I have my jambory open jambory window open I'm going to click shell again because um I'm going to delete the python folder again click shell again and figure out what version of python I get because I know this version the latest version has in fact it's own pip so I can say pip and it gives me help it so no pip is there so I can say python such as version I say hey looks like you're missing the lot so um notch i'm not sure how you missed a lot of versions but you are missing people 1 4 5 that has a pip I'll actually make sure I'm typing the right thing pip 3.exe pip.exe one on the same that's kind of weird pip start out xe yeah there's a pip pit 3.14 and pip other things there's like symbolic links or something I don't even know actually let me go to the folder and let's prove it so this weird python has a bunch of pips um yeah it's the same it's the same binary copy three different ways with three different names you would normally do a symbolic link to that pip binary and not have three of the same pips in one thing um so that's not really whatever um so let me go back to my prompt and say hey this has pip.exe and pip 3.exe help me understand why you miss so many other versions of their versions um so here we are you know like an hour later into this I've already spent probably 30 minutes on it um threes and I am doing kind of a little bit more bugged beyond is that this scope is very limited for this engagement so any what I like to say color I can add to a existing thing um it's good because a lot of people will just do a test they'll run a scan they'll do the thing um but if I a good tester will have a spidey sense right and my arm my arm chair my arm handles are usually all the way down but the kids come in here and mess with it um so if you have arm rest and you have back issues try and slam your arm rest all the bit out I have a used which they normally sell these anymore because I got sued out of their pants I have a used um fancy was it called arrow or whatever the fancy chair um um arrow I don't know what the brand is um I've fixed a I've done after market seat that I had to replace palm and miller their home and miller chair I have an after market seat that I've had no problems with to replace the seat that I had it was the bolts for kind of oh wonky so anyways I'm hesitant to never use python pit use python m dash pit okay so here here's the squish was you're right call me out I was wrong and I really let me explain what happened point actually contained in print has a pit python package but it does not have a tail on pit of me sitting right at the older versions and then had a literal pit 3 and a little bit however this is a key pit is still fully functional and 314 you can run a be a python dash in pit or you can generate that video okay so my thing is I guess I figured out that pit runs with new versions of pit so I guess I'm wrong I guess I forgot so pre-built pit is all the way to three seven and then neither neither pit not bundled at all must run pit not proper to putt insure pit first okay so python dash m insure pit I don't know what that does so let me let me ask so what does insure pit does that install pit if it's missing so yeah I'm asking it insure pit I don't know what that does module that does do but module what it oh well it's searching the internet for my dumb question yes exactly there's a bootstraps pit from a bundled wheel that ships inside the python and stalk it itself it looks for a pre-packaged video file so when we start talking about wheel that's when things get weird so I guess so the lack of whatever okay just gives so far new get package already have wheel at blah blah running python insure pit creates a little bit locally or you skip that step insure entirely and just he's pit by that directly since pit packages are already unpacked in site packages the easy to get to have check check pit bython and verify insure pit wheels and scripts which suggest the insure pit module may be present with a bundled wheel but I need to verify each one bottom line so for your script person is any version that has either is that made is or effectively has pit so you just need to run one command okay just make sure every download has pit has pit thanks um so I'm telling it to make sure every download has pep where it's been extracted I don't know might be in the temple it's been dumping a lot of they've been dumping a lot of stuff inside a pit template which is depending on how you have your Linux structure up this your Linux structure is set up your temp file might not be enough storage to extract copious amounts of data I've had to extract terabytes of data to the folders and if I was running some kind of AI slot I would not want it extracting everything to force temp because usually temp on some of these vpss or maybe you're given a weird excuse me a weird setup to the home or the route going to have to be like you know 20 gigs and that's for your OS and everything else you have to figure out and then these installers start dumping stuff everywhere or Docker starts putting stuff in var which I've seen also it's always the same problem with managing your managing your mounted paths if you have them mounted correctly is an nightmare but it does prevent things like you're just filling up with wags or something like that but a lot of times people don't split those up anymore I've never really seen it save anything does a lot of times I'm running small services and it doesn't really matter if I can't write and read a bunch of disks stuff so here we go it's saying use python and pip he's python on pit so it's kind of doing a full evaluation of all of these now I've not talked about I just clicked exit multi execution mode that's something horrible idea I've never used that before so I use moba in on my website my just my get up I have a script called um moba portable and it does the same thing as planberry does but it's just for moba and moba is a windows terminal and I co-worker from back for way back said something about moba because I was using portable port of putty which is a portable putty version if you're a putty person I sorry you are wasting your time um moba is fully featured it has built in x-server you can disable it by default you can do tunneling it has an SCP server it has w self support it has automatic syntax highlighting it has a support for different fonts it has you know multiple execution you can do tunneling and that will say the killer feature for this thing is the tunneling there is no other app that I have seen Linux or otherwise that does tunnels like this one so I can essentially copy a dynamic and a static tunnel in the i and i file and basically go from you know something that would take normally forever to do I can just copy a dynamic and copy a regular tunnel and copy a dynamic basically for reverse channel it's whichcraft i'm only going to but basically for reverse tunnel dynamic tunnel so you can basically set for reverse connection back to yourself and then set a dynamic tunnel to that reverse connection to tunnel all of your traffic through that tunnel so that way it's a reverse shell and then you reverse shell that shell through a proxy and then everything on that proxy goes through that reverse shell so that's why things start to get kind of hairy when you start talking about getting a reverse shell and you can proxy all your traffic through that reverse shell you can and even with apps that don't support proxy you can use when does has a couple of them pry boxy i think called you can force a TCP based applications to run through a proxy that don't have proxy support so even where there's no support for proxy you can use something like proxy chains and Linux to do that there's other ones that do manual proxy no there's proxy chains and look couple of them i've always used proxy chains windows i use privacy i've never had to really do that except for like third party apps that might have some kind of weird thing and i want to tunnel the traffic to see it and they don't have a subscription i will use five oxy to force that traffic through a barbsweet because the app doesn't have proxy support but moba is awesome it's great i don't know if i have any videos on it on there's probably tons of videos out there but just the way it manages you can have about a reconnect so that way you're not accidentally doing traffic from a bad place it will automatically reconnect so if you change if you move around change IPs if you're connected with different wifi it will force that connection and it will nag you to death if you're not tunneling through that connection so that's some of why i've always used it since then okay so i'm gonna try this for a bit more time i i'm actually at a time for today uh gotta get back to family stuff so down great you python 3.13 or 3.12 safest worker so i have going to click my PIC POC python thing i only have my whatever version so that's not great um i go back and rerun take updates python pick yeah it's missing the list of URLs so i'll go back to the AI and look at my function i'm pretty sure i copy and paste it in this function um let's see um there's a brown context of it yeah so update the power shell to include all versions versions sorry not to just ones with pip xe binary so i told it hey i messed up you know it i told it to check everything i told it to update i told it to update because it did say cat whatever um so i said you know all stable whatever it's okay me sure every download has okay just make sure every download has pip thanks and then um said all of the gen have pip i was completely wrong earlier there are zero versions without pip here are the actual breakdown here's my earlier breakdown i said okay whatever so let's see let's just include all versions version sorry not just ones with pip binary there's a two i just heard it does that it would version two okay so maybe you had just missed it writing a different file name um that's what will happen to my local who do the same thing all end up with like like 10 different versions to Java and like multiple different versions of the same function it's really hard to follow when you're vibe coding all that stuff so i will put this back in here i will leave this running because i do have yeah i'm gonna close it actually so when i update that function one more time i use no pet plus plus mainly for first stuff um thought about switching to something more powerful like my portable vscode to do stuff because i do a lot of stuff in power so so there's a lot of goodies and vscode that go work around power so i'm gonna click my POC python POC i've got all the way to um 10 11 12 13 14 it's kind of in the non-logical order so i'll have it fix that in the background um can the order is is um not human read a bow make it sort proper the make it sort properly so they think it's see the versions go up and down because right now it says 3.99 and then 3.8 7 6 5 4 and then 3.13 3.1 2 10 10 so like 3.12 like it's looking for using to read so i'm gonna go back to this to say 3.3.1 2 so i'm gonna click 3.1 2 3.1 see if i can't do this 3.1 2 with no anything 3.1 2 0 maybe 3.1 2 3.1 2 9 3.1 2 0 so maybe like if you want one 2 5 i don't know so we'll see you what happens there uh extract successfully so i'll go to my shell and the five on version five on is not installed so somehow oh i got the folder paths messed up so this needs to go here so it extracted but it extracted the file name so there's a file called Pythandesh 3125 blah blah blah so i need to also tell it to fix that so okay looks looks like you need to extract to base um uh to remove the folder folder ex folder ex direction i don't want a folder called five out of just Python p-y-ton so currently it installs to currently it looks like Python looks like it's going back slash high-thon back slash i want to want it all to go in the folder x-slash Python without the sub folder minimize the code minimize the i's the in my eyes well and i'm i's the code and don't uh provide comments um uh uh the jibbery is already 1.24 kilobytes um it's pretty massive uh the problem with that is more code more problems we've got 2600 lines of code and that's after like a i got rid of half of it so um it used to be twice as big and it's well a i minimize it and i ran through about 90% of the code base checking it and make it sure that it's whatever so we have done blah blah blah there's no comments actually directly to Python that was so fast like 21 seconds sit to that jesus um destroy my local AI um these are front-to-ear models a cloud hope this 4.6 is absolutely insane so of course that's temp we have our version two again we're gonna bring it up one more time the uh there's also a default text editor inside of here you can tell it to use a different default text editor um this is 143 lines it is following my paramed stuff that i told to do it don't uh jibbery doesn't have a paramed uh basically doesn't have uh safe functions essentially proper functions they're minimized so there's a lot of extra stuff in this function but you know we're doing it live right now and i will add uh i will add it to the main repo what i'm done here so i'm running paramed part running it again i'm gonna delete the Python folder this is actually i think it cleans up itself pretty good let's see so Python concept 314 312 this is easier to read i'm gonna do 3.12.5 click extract and then we got a little message it says whatever and we're gonna take my Pythat file and i need to add it into the repo but i'll put it in the tools and the i guess put it in tools slash this folder because there's no scripts folder at all so i'm breaking a few songs what's it is so Python and Python okay yeah Python and so now we're back where we were several hours ago so Python install open connect SSO the weird thing is i'm not sure what it's doing i'm not sure why it kind of froze out when i finally did get the open connect dash this is a Python module to install it's said like blah blah blah off into canny whatever and it's almost like it's supposed to bring up a browser and never really did so i need to incorporate this new Python function with my Python great function it upgrades it and then creates that Pythat file to make it say you can just type Pyth and do something so anyways let's go down to the bottom here and i don't know what that is somewhere here is my fancy stuff there's the basement you i don't need to bring up the i want to bring up the UI for that at some point so that's why i kept seeing nothing when i clicked things um so open connect open connect somewhere i have somewhere i have the the open connect dash SSO server yep so we're gonna go here i close our remote thing out i want to put notes back in my main notes here so i have kind of two notes going now which is kind of annoying so level deep bug so i'm going to try to call this open connect after installing it again no novel no module named pkg resources so i'm going to just copy and paste this um uh Python modules are weird because you can write you can try and guess the Python module but at the time i get it wrong where there's like there's a dash and it it's a little annoying to have to do that so i'm not sure what's going on here quick patch for Python now when you just start all over with a new session because new thread um here's my ear i think some running Python one two again again um so i'm going to do this command it's telling me to run tell me to install set up tools then older version um is running from so maybe the tip the set of tools version needs to match the Python version that you're running so it knows that set up tools 80.0.0 matches my version of Python maybe we'll see so okay now i've got looks like it did something let's see what we ended up with um the weird thing about the console window it's like a better turn i'm still on command line the cmd.exe a lot of people have moved to the straight just power of shell the problem of power shells i can't do like the r4 such as like it's hard to search for files there's a bunch of other stuff that's kind of annoying to do um uh check your official company's ip documentation so there might be some stuff going on here that i don't quite understand how to fix um that i caught i pasted the the errors at some point python in the set of tools yep we did that i gave you the thing and then you said um certificate because the mitch match yep yep um how do i bypass the i just want to bypass i just wants to bypass the SSL errors um we'll work on this a little bit and i'll leave you alone for a second all right so it's gonna go to Costco with my wife but she's i guess leaving it's now it's 24 minutes after five you know nine to five working i told her i'd have finished something and instead of asking me it's going on uh she just gave up and left so you know that's the uh disabled path link uh i give it up and then i actually installed python to the main environment problem with jambree is it when you do calls like open browser or whatever with python they don't work uh because you know it doesn't it's missing a bunch of stuff so i'm right now um trying to see what version of python i have here are as i have uh three twelve five so i'll save it to install um pippin stall whatever this thing is um do i go back one of these no no no no no actually that was it um so let me let me let me try to get this work in nolsy let me go okay so effectively given up now i managed to get uh open connect access is so working with the whole regular normal windows environment um i hate installing anything on windows oh my you like to use jambree but in this case it's a virtual machine i blow them up anyways after engagements so i installed uh python the older version of python i told it to do whatever and it's doing the exact same thing it's just sitting here at the authentication prompt so i'm not going to go crazy uh testing that so i'm just going to use the regular VPN client so pretend how to say anything about open vpn and open connect and doing routing exchange against we're not going to do that today because we were only asked uh this is the problem being uh me we were i was only asked to test my credentials and make sure they weren't not to go down the rabbit hole that i did so uh we're going to put in the thing we're going to check enhanced session before we connect because if you try to connect with the enhanced session again it will disconnect you because it's makes sense if you're more on you don't know how a package worked you will get disconnected remotely and then you'll have this session open on the other end and you'll be like oh every time i you know connect to the VPN it just like disconnects me and then i don't know what's going on it's full of law so to make it idiot proof Cisco's like all right we're just going to block anybody that's like doing an RDP session or whatever uh to cave from stupid people saying like well i taught my arms off because i connected to a you know no uh no whatever VPN so uh i taught my arms off because i connected to a VPN that doesn't allow us with a toning which you're going to kick yourself offline unless you have some kind of remote shell set up so my kit uh laughs about let me talk about proxies and stuff all the time so uh mobile external portable power shell i run that it starts power uh mobile with my portable settings so i can just kind of copy the files around there is a master password that is encrypted with the uh encryption uh i don't know how it incorporates with the tonaling aspect of it i think they're separate so if you take the tonnel i and i you're basically screwed so it i think i don't know um it would i need to do some research to figure out hey it all these credentials that i have uh for external sources are they part of they um is that part of the whole certificate chain or is it you know is it a certificate store essentially that's uh is in there and there's not any there's not any sensitive information is not protected by my original password password thing so anyways what that said um you know keys keyless whatever that's on on your own so if you have keyless this is a demeaning you can access agent to a computer without any credentials at all you just provide a key um that's i don't know either way um you want to have passwords no matter what so anyways i'm told to text this uh SSH on it tell on SSH into this don't know the username i think i know the username and hopefully i copied and pasted it somewhere there's host name i'm missing username so hopefully the i can find one of the six places that my username could pass possibly be um oh cool the passwords completely different for this uh machine so whatever um now i can't copy and paste since since i'm connected now i can actually enable enhancement and i can um copy and paste stuff so i can actually remotely mount my uh local system because that's how RDP works but i'm not going to do that because i need to get going here so bureau it's a company work for the uh that's gonna be out of username and i'm assuming the port is that and then we'll go and nothing of course not of course so we're going to do um make sure we're on the VPN we're connected so we're going to do and you know what and i i've found we're opting to not um i have issues with this so and map and map and map out maybe it's not RDP maybe it's RDP or because i've turned so there's client i'm going to put that IP address in there um because when they say remote access they don't didn't know what people just assumed that you know what you're they know what you're talking about so we're going to see what happens when i put in the IP for no either neither okay so um a lot of times people give you VPN access you're not actually um a lot to hit any of you can't hit anything sometimes so then you wonder what we're going to do reverse mode we're going to do all ports so dash p dash sorry talking about in map is a port scanner so i'm doing in map with dash p dash no spaces that does every port and then the IP address and then vvvvv which is super verbose it'll basically tell me if there are any ports of been on this host so it's doing DNS resolution which you can innate disable with dash d and this is not good um so we don't have a connection we're going to show this in a uh in a screenshot i guess and show that you know it's it's not it's not a thing so uh to connection refused and then we're going to show we're going to wait for the 65,000 to pop out um same thing we're going to take a screenshot and we're just going to paste it in the window here i'm not going to put the RDP up because that looks that makes me look dumb um so something like that and i'll set this off to the client so we're done for today um looks like it looks like i can can't reach but anyways i'll just go that's kind of my my approach for today you know you go down rabbit holes sometimes you have time for them sometimes you don't um anyways my wife didn't want to wait another 23 minutes but you know these things take time anyways um i'll let me know in the comments if this is too long if this is useless i don't know um it's a cool idea but when i'm doing work and it's not exciting nobody wants to hear that but i don't know what percentage of this maybe what percentage of this entire hour and basically 30 minutes of me hammering is actually useful um is it over your head obviously maybe possibly and also you know not super useful i don't know but i i got the idea from whatever his name is like hey this is my music me working i can't show you my screen but i can talk about it and that's actually really powerful so anyways take it easy good luck um if you have any questions about anything make a sure about it or maybe put in the comments if you're still listening put in the comments if you want me to expand on any of these everybody but janitors or whatever actual people uh each of our janitors um i'm not gonna a lot of time to make shows out of all these but the idea is to as i'm working make a uh if i'm doing something somewhat interesting make a uh episode about it because i'm here and i'm working so i might as well be babbling babbling while i'm doing it anyways take it easy You have been listening to the Hacker Public Radio podcast, at hackerpublicradio.org. Today's show was contributed by a HPR listener like yourself. If you ever thought of recording a podcast, then visit the HPR site to find out how easy it really is. Hosting for HPR has been kindly provided by anhonesthost.com, the Internet Archive, rsync.net, and the HPR Community Content Delivery Network. Unless otherwise stated, today's show is released under a Creative Commons Attribution-ShareAlike 4.0 International (CC BY-SA 4.0) license.