Hack the Box – Haris Pylarinos, Hack the Box
Hack the Box has become a leading training company that teaches people about pentesting. Haris and his team have developed some unique methods to train people in this. Haris tells us about Hack the Box methods and discusses the general state of security
Transcript
This is texturing TV. Hey everyone. Welcome to Tech strong TV.
Thanks for joining us here for another interview. I'm really happy to have on as our interview guest in this segment all the way from Athens Greece beautiful city. Beautiful country.
Harris is the founder CEO of hack the Box. So I get that right Therese. Yeah, that was perfect.
Good. All right. So Harry hariz, let's start off.
You know, our audience is pretty Technical and there's a big cyber security audience. But let's let's assume not everyone knows hack the Box. So why don't we start off if you don't mind give us a little background on the company and maybe your own background.
It's awesome. Awesome. Yeah, I'll start with my own background.
So as a kid, I loved breaking things apart figuring out how they work. So I became a Colby's Target on my very early, let's say ages when I grew up to be employed. There was no cyber security profession, so I spent most of my career in Software engineering systems engineering Network.
So basically the entire it start. and towards the late their stages of my career when cyber security was becoming a Hot Topic primarily with gdpr in Europe back then. I found it a great opportunity to Pivot back to you know, what I loved as a kid.
Which I did I did trainings. I had it certifications. I was also teaching at some point certification called certified medical hacker.
Mm-hmm sure, which is from this councilm and I wasn't very satisfied with the way training was delivered in ethical hackers. So I decided to you know deliver it the way it would make more sense for me thus hack the box was created. where essentially what I've seen is that Cyber security is more about and ethical hiking is more about the mindset rather than you know.
Reading about all the tools remembering all the commands and you have Google why remember command when you have Google? What you need is the mindset the the we and the certainty that you will find a weak spot in the system. And be able to compromise it.
So in a natural hack the books started with the core product, which is adversarial Place labs. And what we do what we tell the user is here is an IP address. That's it.
No guidance. No hand holding go figure it out. And that forces the user, you know to fight or flight.
We only give the promise that this thing can be hacked. I guarantee that I've let purposely build hole on that system and that gives them the confidence they need on the early stages because when you are when you are losing at that at your first time, you know that someone designed that thing to keep you out. So your coffee days is right to the bottom.
You build that confidence. And as you progress, in fact the books you realize that practically everything is hackable. It's just a matter of time and persistence to make it happen.
Yes, so let me comment a little bit. So first of all Harry's like you You know, I've been in security 25 years. 25 plus years and when I first got in there was no Cyber security.
We didn't call it cybersecurity. We called it security or infosec and and there was no cybersecurity classes in college or Majors or stuff like this. Most of the people I knew in security were insecurity because they like to break things.
They like to see if they could break it and then fix it better. So it wouldn't be broken again, right that was exactual fact pattern and They weren't full-time security people most of the ones I knew were in network because I was more on the network security side of things. So most of the people I knew in security were former Network Engineers.
They were very good at routing tables and you know, and that's firewalls became I came on with like checkpoint, you know, the firewalls were first coming on and You know, but today of course very different world. You've got kids going to school. It's funny.
We have all these open jobs in security that are open because we can't find Qualified people. And then we have all of these people who graduated schools like University with cybersecurity. Classes, but they don't have any practical experience.
That qualified them to do the job. And so you ask yourself is the is the training is the education we're delivering in the schools. The right thing to help these people and to help the industry.
That's another question. In listening to what you're saying. So hack the box is really your take on how to teach people to be security people how to hack how to How to find vulnerabilities right because with you if you know, if you have the attitude of you know, we've called the hackers I view right if you have that sort of viewpoint that a hacker would have you better able a better able to defend it.
What a great concept. Congratulations on that before we get in a Trends and stuff that are out there right now. So when people take your courses, they're some sort of certification do they graduate?
Is it continuing tell us a little bit? It's a lifelong learning process because cyber security this progressing. Very fast.
So taking a training getting certified is one thing. But you have to you know, stay sharp with all the latest and greatest. I mean trans things 10 years ago.
You wouldn't hear about dokier escapes. For example, now it's all about them. Not everything is located right now.
So the trans things you have to keep up you have to stay sharp and it's better to do small iterations of new knowledge rather than multi courses that last for an intensive one week. Let's say per year. At least that's our view, of course.
That so it is that the offering then from hectorbox is you sign up and you you do almost what's called continuous education or continuous exactly exactly. Sure, please education leads to certifications but after being certified again you have things to do to stay sharp and stay let's say battle ready in that profession. I get it and for the kinds of people who are taking your exam or taking your offering not just the exam what certification but they're getting trained.
Are they pen testers absec folks network security or all over, you know, all of the above the majority spent tested or people wanting to become contesters and then we covered also the it space network engineering Etc. We don't really focus on the software engineering side yet. But everything else security is something that you can do in Hackler books.
Sure. Well, I would tell you what the with the shift left of security. It's a lot cheaper to test it on pre-deployed software dependence sort of pre-deployed out software then then after it's deployed right?
So I think it's only a matter of time until you start getting software developers here who are security and one of my the things that I strongly believe is that knowing how the attacker thinks. By becoming the hacker yourself when you called, you will have many aha moments. So that's that's another way.
Someone could have got in when you are building a system as a system administrator. Did you close anything that shouldn't be open? I mean all these hardening can be done three can be streamlined in the process of delivering the product itself instead of delivering having the pain test findings then fight a bit with a pen tester because the Developers Commonly fight with the pentatives no micro decide your own vice versa.
So thinking like that. I get no matter which position you cover, you know in the it organization has a strong advantage. Actually, all right.
You're before we jump to the next thing too for people who are maybe interested in. Signing up with hacks the Box what what that's website for them to go to. com.
Easy h a c k t h e b o x Comm exactly the Box calm. All right. So, how are you?
Look you sit in a very a chair with a great vision of what's going on in the industry. What are the security challenges that today? You know we need to face.
What do you see is some of the biggest challenges is some of the biggest Trends out there in the security space today? Well, the biggest Trend still is around somewhere. Yeah, because you know, it's bulk many many organizations actually believe that especially in the S&P side that they will not Target me.
I mean they will Target the big ones. That's not the case. They will simply Target everyone.
It's a bulk process. So I and the primary Way by far is still through facing they start with the fishing nature. I have a hundred thousand email addresses from various companies.
I will send back to all and We see which one you know, right this what fish we get. So having you know such a broad landscape of targets it sure that you will find someone. And you will succeed as a cyber Criminal.
And then monetization part is also very easy now with you know, the cryptocurrencies. Yeah. and what I'm seeing also in most of the organizations that They tend to focus and spend a lot of money on software and tools.
Not so much money on educating the human element which for me is more important than the tool itself. So if we had an organization with open source tools, I don't like tables firewalls. Okay, and I don't know AVG Antivirus or anything free with extremely educated people on cyber security would have less chances of being attacked rather than an organization that deploy is massive capital and software and not so much capital on advancing the human element.
A good agreed. I I yeah, look, this is an old story and security the weakest link is still the person at the keyboard, right? And for all and and it's also been a long sailing thing in security always looking for a new Magic Bullet a new tool a new You know piece of software or Hardware that's gonna protect us.
A tool is not good as its operator. Exactly and the chain is as good as its weakest link, right? You could have the greatest tools and the greatest operators in the world.
But if someone clicks on something they shouldn't click on it's trouble right and and you know education and awareness, you know, it's not they're not just words. It's real it's real things there. You know, you spoke about the ransomware.
And SMB, you know medium sized smaller businesses. I think people need to realize that right we read about Colonial Pipeline and these large organizations and cities and governments, you know that they're being asked to pay millions of dollars in rent somewhere and there are there are deal, you know, but there's also the bread and butter of what these ransomware gangs make Come from the you know, 10,020,000. Yeah, it's a volume business now.
one of the things we're seeing is the rise of these like kind of ransomware insurance companies that will you know ensure you against ransomware and and have you know broad experience dealing with the different ransomware. Gangs and softwares out there that what are you seeing with that? Is that a help was it worth it?
You know, I mean, obviously it's a little after more you pay down somewhere the more you will find this and you will make it even bigger. so don't Yeah, My Views don't pay it's very difficult. And obviously you can say that but what if you're asses on fire, okay, you are losing Millions per day and you know that you can spend one million and everything will go back to normal.
So it's easy to say it's very hard to implement. yeah, I think one of the other interesting things around the whole ransomware thing hurries is Honor among Thieves right that that, you know, you're going to trust these people that you're gonna give them a million a hundred thousand whatever and they're gonna make it back to the way it was but of course no guarantee. They don't do it again, right you trust that and and I mean the whole premise of that is pretty When you think about it, right?
It's pretty ludicrous. Right? I'm gonna trust this person who I don't know who he is.
Or say where they are, right and I'm not gonna do it. It's crazy if you ask me crazy. So is that what your teaching the folks at hack who do hack the Box?
Not not to do the ransom. What did you do? If not pay the ransom?
You do very good backups. You do off-site backups. You do cold storage backups.
And you recover. Yeah. That's really I will tell you here.
I mean, you know, I I consider my company here where where we're not very big right where it's from medium business. 9% of our infrastructure. Is that that's based?
You know applications and that's providers are doing. Off-site backups and doing all that. So, you know in terms of being a Target.
Yeah, it would be You know a pain in the ass for a couple days maybe but at the end of the day. You know, I would providers have all of our backups. And let's a provider got told another story.
Anyway, it's a very much bigger problem much bigger problem than just me exactly how he's beyond ransomware. What else? What else do you see?
What about like Everybody's talking these days software supply chain security that's bombs. And and this guy like the like the solarwinds thing. Yeah.
Yeah. Okay, those are high-end very targeted attacks. They would not Target you or me or you know, they would go very specific.
and truth be told you can't avoid basically you can't avoid being hacked. That's a fact. The only thing that you can work on is.
How difficult we make it for the criminal and how soon you will find out about it because it's a totally different story. If you get hot and you find out about it within the first minute within the first hour the first week or the first year David damage multiplies. Yeah, so I don't defense is good and you know securing their organization as much as you can but monitoring is equal important figuring out any anomalies someone Lauren.
What did they take? What did they do? Did they manage to do what they wanted to be managed block them earlier?
Got it. Hurries were bad at a time. I want to thank you for coming on and telling us about hack the box.
It's great discussion. Again. It's hack the Box calm.
Yes, check it out. It sounds like a great program. for thank you very much for having me and thank you to see you in Athens.
You know what? I'm I'll let you know. Hopefully maybe maybe September if not next spring but be well or if not an athletes.
Maybe it's some security conference somewhere soon. All right. All righty.
How are you sticker? Arenas hacked the box here on techstroke TV. We're gonna take a break.
We'll be right back.