OverTheWire Bandit Part 2

In my last post, I walked us through connecting to OverTheWire’s Bandit server, and completing level 0 and level 1. Following along with the previous article is a prerequisite to following this article, as you’ll need to get the password from the file in level 1 first.

You can view my last post about this by following this link.

Continue reading OverTheWire Bandit Part 2

OverTheWire Bandit Part 1

OverTheWire is a website with two games. One is “Wargames”, which is a level based game, the other game is “Warzone”, which is more of a free-for-all hacking game.

In this series of articles, I’m going to give a walkthrough of how to complete the “Bandit” series of levels on their website.

Continue reading OverTheWire Bandit Part 1

Hack The Box Intro

Hack The Box is a website that gives people a great place to test their penetration testing (hacking) skills. They have a selection of different machines available that are vulnerable to different types of attacks. This site uses the capture the flag scoring mechanism, where you hack machines, get a “flag” from them, and submit it to their site for points.

In this article, I’ll cover how to make an account on HTB.

Continue reading Hack The Box Intro

Demystifying Lossless File Compression

We all know the basic idea of file compression. We see ZIP files regularly, and know how to extract and compress them. Although most everyone knows how to use these compressed files, and understand that compressing files makes them smaller, most people have no idea how it works technically.

Though this may seem like magic, it’s a fairly straightforward concept. In this article, we are going to be demystifying file compression.

Continue reading Demystifying Lossless File Compression

Deep Learning Neural Networks

I keep seeing news about something awesome that a computer has been “trained” to do with “deep learning”. These news spiels refer to something called “Q Learning”, “Deep Learning Neural Networks”, or “Hierarchical Learning”.

Although these are huge terms, it’s a pretty simple idea as to how they work. In this article, we cover some of the basics of this genre of algorithm.

Continue reading Deep Learning Neural Networks

About Pseudo Random Number Generators

Pseudo Random Number Generators, or PRNGs, are extremely important, as randomness is needed by computers for many purposes. As computers are “deterministic” machines, meaning they follow a specific procedure for everything, they are terrible at making randomness. Because of this, there has been an enormous amount of studying on how to simulate randomness on computers. The algorithms that are developed to simulate randomness are called PRNGs.

Websites that use TLS/SSL (to get the lock symbol in the address bar) use randomness to establish a secure connection to someone visiting their website. If they didn’t use randomness, and used a non-random encryption key with someone who visited their website, then any malicious actor could visit the website, and get the same encryption and decryption key as you got. This would allow a hacker to decrypt your communications with the website. Imagine if this could occur with your banking website, and it becomes clear why this is important.

Continue reading About Pseudo Random Number Generators

All About Certificate Authorities

A “Certificate Authority” (CA), is a idea of “Public Key Infrastructure” (PKI), in which a special type of certificate is able to essentially co-sign other certificates to verify them as valid and trustworthy to certain levels.

Although CAs are generally trusted, there are non-trusted CAs. These CAs typically exist in corporate networks, in which their computers trust the CA, but others don’t. For example, a large company will have internal servers that need to be secured using SSL/TLS, but since nobody outside of the company ever accesses these systems, no computers outside of the company trusts this CA.

Continue reading All About Certificate Authorities