Go offline with the Player FM app!
A Day in the Life of a Penetration Tester with Carson Sallis
Manage episode 484193488 series 3594482
In this episode, we chat with Carson Sallis, Senior Offensive Security Engineer and Vulnerability Researcher at NVIDIA. Carson walks us through a day in the life of a pentester and shares actionable advice for anyone looking to break into offensive security. He also gives a live demo of fuzzing with AFL (American Fuzzy Lop) and explains how tools like this are used in real-world vulnerability research.
Whether you're just starting out or looking to sharpen your red team skills, this episode is full of insights you won’t want to miss.
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Episode Resources:
GitHub: https://github.com/cybersecmentors/season_3_ep_6
Guest: Carson Sallis
Follow Carson and connect for updates, demos, and career insights.
LinkedIn: https://www.linkedin.com/in/carson-sallis/
Fuzzing Tools & Resources
· AFL (American Fuzzy Lop)
The fuzzing tool featured in Carson's demo.
Link: https://lcamtuf.coredump.cx/afl/
· AFL++
An advanced fork of AFL with modern features.
Link: https://github.com/AFLplusplus/AFLplusplus
· Fuzzing: Brute Force Vulnerability Discovery (Book)
A foundational guide for learning fuzzing.
Link: https://nostarch.com/fuzzing
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Connect with us and leave us feedback:
- Cybersecurity Mentors Podcast Swag: https://the-cybersecurity-mentors-pod.myspreadshop.com
- Mentorship - Sign up for a FREE session: https://www.cyberprofessionalservices.com/scheduling-free-consultation
- Sign up for our Newsletter: https://sendfox.com/lp/m2vx85
- Join us on Discord: https://discord.com/invite/g4yRKjnD78
- Follow our LinkedIn page: https://www.linkedin.com/company/cybersecurity-mentors-podcast
- Check out our YouTube channel for more content: https://www.youtube.com/@CybersecurityMentorsPodcast
- TCM Affiliate Link: https://certifications.tcm-sec.com/?ref=1
Chapters
1. Episode Introduction (00:00:00)
2. Offensive Security Engineering Explained (00:01:40)
3. From Pen Testing to Vulnerability Research (00:03:34)
4. The Art of Fuzzing (00:06:42)
5. Finding Real-World Vulnerabilities (00:12:42)
6. Vulnerability Research Demo with AFL (00:18:33)
7. Skills Needed for Vulnerability Research (00:38:39)
8. Breaking Into Offensive Security Careers (00:43:42)
9. Episode Wrap and Key Advice (00:46:19)
33 episodes
Manage episode 484193488 series 3594482
In this episode, we chat with Carson Sallis, Senior Offensive Security Engineer and Vulnerability Researcher at NVIDIA. Carson walks us through a day in the life of a pentester and shares actionable advice for anyone looking to break into offensive security. He also gives a live demo of fuzzing with AFL (American Fuzzy Lop) and explains how tools like this are used in real-world vulnerability research.
Whether you're just starting out or looking to sharpen your red team skills, this episode is full of insights you won’t want to miss.
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Episode Resources:
GitHub: https://github.com/cybersecmentors/season_3_ep_6
Guest: Carson Sallis
Follow Carson and connect for updates, demos, and career insights.
LinkedIn: https://www.linkedin.com/in/carson-sallis/
Fuzzing Tools & Resources
· AFL (American Fuzzy Lop)
The fuzzing tool featured in Carson's demo.
Link: https://lcamtuf.coredump.cx/afl/
· AFL++
An advanced fork of AFL with modern features.
Link: https://github.com/AFLplusplus/AFLplusplus
· Fuzzing: Brute Force Vulnerability Discovery (Book)
A foundational guide for learning fuzzing.
Link: https://nostarch.com/fuzzing
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Connect with us and leave us feedback:
- Cybersecurity Mentors Podcast Swag: https://the-cybersecurity-mentors-pod.myspreadshop.com
- Mentorship - Sign up for a FREE session: https://www.cyberprofessionalservices.com/scheduling-free-consultation
- Sign up for our Newsletter: https://sendfox.com/lp/m2vx85
- Join us on Discord: https://discord.com/invite/g4yRKjnD78
- Follow our LinkedIn page: https://www.linkedin.com/company/cybersecurity-mentors-podcast
- Check out our YouTube channel for more content: https://www.youtube.com/@CybersecurityMentorsPodcast
- TCM Affiliate Link: https://certifications.tcm-sec.com/?ref=1
Chapters
1. Episode Introduction (00:00:00)
2. Offensive Security Engineering Explained (00:01:40)
3. From Pen Testing to Vulnerability Research (00:03:34)
4. The Art of Fuzzing (00:06:42)
5. Finding Real-World Vulnerabilities (00:12:42)
6. Vulnerability Research Demo with AFL (00:18:33)
7. Skills Needed for Vulnerability Research (00:38:39)
8. Breaking Into Offensive Security Careers (00:43:42)
9. Episode Wrap and Key Advice (00:46:19)
33 episodes
All episodes
×Welcome to Player FM!
Player FM is scanning the web for high-quality podcasts for you to enjoy right now. It's the best podcast app and works on Android, iPhone, and the web. Signup to sync subscriptions across devices.