Skip to content

Thought Behind Things · Jan 10, 2022 · 1:14:04

Pakistan's bug bounty culture is destroying our cyber youth

Cybersecurity researcher Etizaz Mohsin — the only Pakistani holding the OSWE certification — walks through how he taught himself the craft from a borrowed PC in 1997, what the OSCP/OSCE/OSEE certifications actually mean, how Pegasus really works, and why Pakistan's obsession with bug bounties is hollowing out the country's next generation of security researchers.

with Etizaz Mohsin

13 min read

A second cybersecurity conversation, prompted by a hacked embassy

The episode opens with Muzamil explaining why he has come back to cybersecurity so soon. He had done a podcast on the subject recently and, by his own admission, his appetite had not been satisfied. The audience had asked for more. And the day before recording, the Instagram account of the Pakistani embassy in Argentina had been hacked — the second major compromise of a state asset in roughly a month, after a similar incident in Eastern Europe.

“This is an alarming situation,” Muzamil says, and uses it as the launch pad to introduce his guest. Etizaz Mohsin is, at the time of recording, the only Pakistani to hold the OSWE certification — a credential Muzamil notes that fewer than a hundred people in the world possess. Etizaz has also spoken at more than twenty-five global cybersecurity conferences. The conversation is set up as the technical deep-dive the previous episode could not be.

A borrowed PC in 1997 and a self-taught hacker

Muzamil asks Etizaz to walk through his path from high school to the present, and the answer reframes the entire conversation: this is not a story about a curriculum. Etizaz did his FSc at Aslam Foundation College in Rawalpindi after schooling at Sir Syed, then took admission in software engineering at Riphah International University in February 2013. By that point, he had already been working in the field for years.

“I started my field at the end of 2009,” he says. “I knew what I had to do.” His first contact with a computer was 1997, at a friend’s house. He taught himself, without anyone guiding him, what the machine did. Later he tried to follow what was happening in the Pakistan Cyber Army and Indian Cyber Army communities of the time.

The contrast he draws is the most honest part of this section. He points to a seventeen-year-old American who, in 2003, produced an open-source reimplementation of the Windows operating system — reverse-engineering a closed-source product and trolling Microsoft with the result. “That kid had the privilege, the internet, the community,” Etizaz says. “How did he become capable? Because his community was like that.” His own environment offered none of that scaffolding. He had to build it himself.

He had originally gone into pre-medical, did well in the first year, and walked away in the second. “I told myself I wasn’t going to waste second year on studies,” he says. “I had no idea how, but FSc would clear.” It did. His marks were not strong enough for the universities he wanted. He ended up at Riphah by default.

The final-year project that exposed the curriculum

Later in the discussion, Etizaz describes the moment his self-taught capability collided with the formal degree. For his eighth-semester project, classmates were doing standard car-parking systems and similar exercises. He was building something far more ambitious — a tool that would automatically exploit weaknesses in Wi-Fi networks to keep a mobile device connected. He describes the energy of that moment with one line: “The josh was very high.”

Four days before the internal evaluation, the implementation was not where he wanted it. He pulled a commercial vulnerability scanner’s template, integrated two or three open-source scanners behind a clean front-end, presented it, and demonstrated an SQL injection that bypassed an admin portal live in front of his faculty. The room reacted as he expected — “everyone was like, wow.”

The undercurrent here is what Muzamil pulls out: the system did not know how to deal with a student who already worked at this level. The convocation, as Etizaz tells it, became its own act of pettiness. The computer-science batch graduated, and the department arranged for him to walk and be photographed with the electrical-engineering batch instead. “Because you weren’t sitting and coding computer-science assignments, you were the biggest failure in the world,” is how Muzamil paraphrases the message. Etizaz is generous about it: the faculty members who could not technically help him still encouraged him, and that was enough.

What OSCP, OSCE, OSWE, and OSEE actually mean

Muzamil asks Etizaz to break down the certifications, and this is where the conversation becomes a primer that does not exist cleanly elsewhere in Pakistani media. Offensive Security, the Israeli-founded company behind the OffSec series, broke a market previously dominated by EC-Council’s mostly theoretical Certified Ethical Hacker credential. OffSec built labs grounded in actual penetration testing experience, gave students sparse documentation, and famously answered most help requests with two words: “Try harder.”

Etizaz walks up the ladder. OSCP — Offensive Security Certified Professional — is the network penetration testing certification. Its core teaching, he says, is enumeration: not how to use ready-made exploits from a blog post, but the proper methodology for finding and chaining already-disclosed weaknesses at the network level. He registered for it after coming back to Pakistan, cleared it in a month, then registered for OSCE and cleared that within a month as well. He was the second Pakistani ever to hold OSCE.

OSCE moves down a layer — into low-level work, the kind of memory-corruption research that traces back to the Morris worm. “It was mostly related to what Morris did,” Etizaz says. The exam pushes you to identify mishandled inputs in old Windows-era software, the kind of test cases that bug-bounty hunters rarely touch because the modern bounty economy lives almost entirely on the web.

OSWE is the web-expert certification: not a generic OWASP Top 10 walkthrough, but training in chaining vulnerabilities together so that bugs which are individually un-exploitable can be combined into a working attack. And OSEE — Offensive Security Exploitation Expert — is, in Etizaz’s words, “close to impossible.” That is the certification associated with Pegasus-class research, where you are taught to build the kind of exploit chains used by state actors. He attended the Black Hat Singapore training to pursue it. “I asked them how many people have done that in the world,” he says. “Less than a hundred, as per the instructors. Usually twenty-five seats per year.”

The Morris worm and where the security industry actually comes from

When Muzamil asks the deceptively simple question — “What is this world, practically?” — Etizaz answers with history rather than buzzwords. The 1980s, he says, were a development era. Mainframes shrank into PCs, IT was a business, and security was not yet a concept. Then in 1988 the Morris worm appeared. A graduate from MIT (or possibly Stanford — Etizaz doesn’t remember which) wrote a program whose only function was to destroy the PCs of the era.

The conceptual leap matters. “Sochne wali baat hai — how is it even possible?” he says. You have given someone a machine whose maximum job is to add two and two. You have given them an email system whose job is to deliver a message. And then a person comes along, looks at the stack the machine was built on, finds weakness inside the memory and the operating system, and weaponises it. That is the moment, in his telling, when the psyche of “security is a thing” enters computing.

Morris specifically discovered the stack-based buffer overflow as an attack vector. Once disclosed, every other piece of C-language software written in that paradigm became a candidate for the same class of bug. Etizaz uses this to draw the line between “hacker” — the person who finds a new attack vector — and “black hat” — the person who turns it on a target for personal benefit.

How Pegasus actually works

The Pegasus section is the one general listeners will remember, and Etizaz gives the cleanest non-technical walkthrough of it. NSO Group, he explains, is in the spyware business — software that gets onto a target’s device and exfiltrates camera feeds, microphone audio, critical files, and decrypted messages. The hard part is getting on. Apple and Android are not in their initial stages anymore. Their defenses are strong.

So NSO does not build everything from scratch. There is a zero-day acquisition market — brokers worldwide who buy zero-days from researchers and resell them. Apple’s own bug bounty might pay a researcher a million dollars for a particular exploit; a broker might pay two. The broker then bundles the exploit into infrastructure and sells it onward, almost exclusively to governments. “Why only to governments?” Etizaz asks rhetorically. “Because the more they sell it, the higher the detection rate goes.”

He walks through the 2016 Pegasus sample as a worked example. The vector was an iMessage delivery: the user receives a message, opens it, and behind the scenes Safari renders embedded HTML, JavaScript and CSS. Safari, like any sufficiently complex browser, is prone to memory corruption bugs. The Trident exploit chain (he refers to it as “Kismet” — which is in fact the iOS 14 zero-click chain Project Zero later documented) used a Safari bug to break out of Apple’s per-app sandbox, then chained into a kernel exploit. “Combine it with a kernel exploit and your phone is gone.”

The newer iMessage variant Project Zero documented later worked through a PDF carrier containing a GIF whose processing was handled by Apple’s graphics library — the bug lived there. “It is not that difficult,” he says. “You just have to invest some time.”

A hotel chain, a Wi-Fi network, and six hundred properties

In the most cinematic moment of the conversation, Etizaz describes his own research into the hospitality industry. He was staying at a hotel. He connected to the Wi-Fi. He noticed a weakness in the property-management system that ran reception, HR, room assignments, VIP flags, DNS, firewall configuration, IP allocation — every connected layer of guest experience and back-office operation.

He exploited it from his laptop. From that one access point, he could reach more than six hundred connected hotels worldwide — including, he notes, Emirates Palace, the world’s second seven-star property. UK, Germany, Saudi. He frames it carefully against a 2015 Silensec disclosure of a simpler bug in a similar device, which he describes as “stupid” — the kind of weakness no vendor should leave in a product that critical. His own finding, he argues, was more advanced.

The point, in context, is not the bragging right. It is that the surface area Pakistan and the wider region depend on is wider and softer than anyone admits.

K-Electric, the grid, and a country with no real defence

Muzamil pivots to the question the entire episode has been building toward: is Pakistan ready? He invokes the K-Electric incident some commentators had called a cyber attack and others had called a glitch, and asks whether the country’s companies and infrastructure are protected.

Etizaz is direct. Pakistani companies can buy foreign defence products — firewalls for web applications, endpoint solutions, antivirus for systems. There is a ceiling on how much that helps. The threat model that actually matters is the Advanced Persistent Threat: a sustained actor who builds a custom malware or spyware and gets one employee to bring it inside the perimeter. “Once one employee has brought a malware inside your network, all the systems you put up for blocking outside are irrelevant,” he says. The Log4j vulnerability, then making global headlines, was his example of how universally these defences could collapse.

He says there are genuinely talented Pakistanis in the field — friends of his he believes could represent the country internationally — but they have neither been given the opportunity nor do they want to be public figures. The state, in his read, has not built the channels that would let them contribute.

Why the bug bounty culture is destroying Pakistan’s youth

The sharpest claim in the conversation, and the one Muzamil lets land without interruption, is Etizaz’s view on bug bounties. “The bug bounty culture is destroying our country,” he says. “It is ruining the coming youth.”

His critique is precise. Bug bounties live on web applications. The economic incentive structures researchers’ careers around finding the same classes of bugs on the same kinds of targets — fast money, public leaderboards, repeat patterns. The result is that an entire generation that could be working on the low-level systems research a national cyber capability requires is instead optimising for web finds. He contrasts this with the model OffSec, ZDI’s Pwn2Own, and competitions like Tianfu Cup represent: vendors bring fully patched, up-to-date products to a stage, and researchers earn their reputation by producing original exploit chains against them. China responded to Tianfu Cup by banning Chinese researchers from Pwn2Own and forcing them to sell exploits domestically. That is what a state mobilising its talent pool looks like.

Muzamil and Etizaz agree on the comparison neither side wants to make. Pakistan runs a few annual events under banners like “Cyber Secure Pakistan” and considers the box ticked. Etizaz describes the Capture-the-Flag tournament he saw at a Black Hat event abroad — school children in line, organised, competing. “That is the Israeli policy,” he says. “Who was at our event? University students. Why aren’t school children there? Why aren’t college children there? If you want to build Pakistan’s cyber power, holding two or three events isn’t going to make your country secure.”

The cyber dimension of the next war

Muzamil closes by raising the stakes explicitly. “Cybersecurity’s requirement today is as important as the importance of the nuclear bomb was,” he says. He notes that Pakistan’s warfare equipment is integrating IT at a level he is not going to detail, and that every layer of integration adds vulnerability surface. The country needs the top talent capable of building a domestic internet with security baked into its foundations.

Etizaz agrees on the trajectory. Pakistan’s IT exports have grown. Digitalisation is moving. But the deciding variable is whether the government works on the youth in time. He is critical, without being dismissive, of the assumption that universities are nonsense — there is truth in the complaint, he concedes, but the answer is to rewire the system, not to write off the talent it produces.

Muzamil ends the conversation by acknowledging this was one of the most technically demanding episodes he has hosted. He estimates he could keep up with about eighty-five percent of it, despite his own computer-science background, and tells the audience that the listeners who can engage with the rest are the ones the country needs to keep an eye on. He plugs the launch of a sister show, the Pakistan Pavement, focused on conversations with policy makers, former ambassadors, and diplomats. Then he thanks Etizaz, and signs off.

Full transcript
Muzamil

धन्यवाद, welcome back to another episode of third band. Things are your my stomach, know, बहुत ही ख़ास ईमान. इनको बुलाने का मकसद primarily यह था कि you know we did a podcast on cyber security recently. मेरी personal appetite उससे पूरी नहीं हुई थी because I wanted to know more about this industry. उसी के साथ साथ a lot of you guys commented on it as well कि एक और इस तरह के experts को बुलाएं. But most importantly only yesterday पाकिस्तानी embassy in Argentina का जो Instagram account था वह hack हुआ है this is the second major hack of a state asset over the last one month. Last was I believe in Belarus or somewhere you know in Eastern Europe. तो यह बड़ी एक alarming सी situation है. But anyways for for our conversation today we have Etazaz Mosin Sab who's been kind enough for joining us sir. You so much for being part the show. बहुत शुक्रिया बुलाने के लिए. So Etazaz is a cybersecurity expert. He's the only पाक्षतानी who have gotten the OSWE certification. It's one of the probably the most prestigious certification in the world. I think only a 100 people have it. Isike SaaSat he's spoken to at over 25 different global conferences on cybersecurity as well, sir. I'm gonna start the conversation just trying to understand, you know, how so from high school till date,

Guest

what's your journey been like? मैंने अपना high school किया था सिलोरोग से, यह राल पिंडी में है. Mhmm. और उसी के साथ पढ़ता है असलम foundation college. वहां से मैंने अपना FSA किया

Muzamil

और उसके बाद मैंने admission लिया soft engineering में Rifle International University से. अच्छा मुझे यह थोड़ा सा बताइएगा. यह दो कौन सा साल चल रहा है? February

Guest

'13

Muzamil

और यह जब आपने किया था तो were you like यह आपने बड़ा by design किया था कि मैंने soft engineering करनी मैंने काफ़ी दवाई पहले से मैं यह काम करता रहा था. मैंने अपनी field 2009 के end में start की थी. अच्छा. हां तो मुझे पता था मुझे क्या करना है. Interesting interesting. So how did how did you get into computing and computer पहले दबाव आया what was that like? 1997.

Guest

Really? It's 1997 में पहली बार मैंने देखा उसको. अच्छा. तो मेरा friend दूसरे घर में रहता था. मैंने बोला दो साल मैं वहां पर अपना हाथ पक्का कर लिया था क्या होता Without anyone telling me. ठीक है? तो उस time तो वह cancel हो गया. अच्छा, समझ नहीं आई. अब problem यहां पर मैं बताता हूं कि मेरे साथ क्या कि for example एक American बंदा है सत्रह साल की उम्र में 2,003 में Windows operating system की open source reimplementation करता है. Right. ठीक है? उसके बाद मैं बताऊंगा बंदा कौन है? मतलब उसके पास वह privilege था, internet था, लोग उसके बारे में बताते थे क्या है क्या नहीं है. तो एक बंदा जो closed source operating system है उसको reverse engineer करके internal structure समझकर अपना program लिख रहा है और Microsoft का नाम troll कर रहा है कि यार यह देखो तुमने बेशक clause tool बनाया होगा. यह उसकी जो open source implementation है. That means कि यार वह बंदा इस काबिल था. काबिल कैसे हुआ? उसकी community ऐसी थी. हां. वह privilege था उसके पास वह चीज़ें थी. थोड़ा time में समझ आ गई यार यह इससे कुछ नहीं होने वाला, यह अभी fake information है. मैंने कहा अच्छा आगे देखते हैं तो फिर वह Pakistan cyber army और Indian cyber army उन चीज़ों के बारे में पता चलना शुरू हो गया. तो मैं अभी इस line में चल पड़ा. Without programming language मेरे लिए पढ़ाई जो थी आप यह समझ लें कि medicine I was good. First year तक I was good. Second year में मैंने छोड़ दिया. मैंने कहा नहीं आ रही है, मेरी बस की बात नहीं है. ठीक है? तो उसके बाद मैंने मतलब कहा कि first year अच्छा था क्यों उसमें यह था कि मैंने first year में chemistry की अपनी लिए tuition भी रखाई थी मैंने किसको पढ़ लेते हैं क्योंकि मुश्किल server की जाती है. लेकिन हुआ यह है कि मेरे 49 marks आए थे chemistry में. अच्छा. Second year में मैंने कहा यार इतनी मेहनत करने के बाद भी इतने कम number कम नहीं थे. Three eighty थे उस वक़्त. 2,012 में I guess ठीक था. Mhmm. और तो उसके बाद मैंने कहा यार अब second year इतना waste नहीं करना पढ़ाई पर. कुछ फ़ायदा नहीं है इसका पता नहीं कैसे लेकिन FSE और यह clear होगी. अब यह था उसके बाद के admission लेना university के अंदर. Marks कम थे किसी university ने, I mean मैंने apply भी नहीं किया था. मुझे लगता है मैंने concerts के लिए apply किया था मैं अब car parking system बनाऊंगा. थोड़ा tidy. हमारे eighth semester में एक उसका चीता program हो जिसे कहा जाता है. वह थे senior काफ़ी मेरे regard करते थे. तो मैंने कहा मैं नहीं करने वाला अगर आप मेरी help कर दें. और उस वक़्त पैसे भी नहीं थे कि हम यह data ले सकें mobile के लिए तो usually में बाहर निकलता नहीं था, ग़ुम रहा होता था. तो वह mobile आपके हर एक second के बाद अगर आपका Wi Fi connected नहीं है तो वह जाकर उस चीज़ को exploit करके mobile connect कर देगा. मतलब जज़्बा बहुत high था, ठीक है? आज the जोश वाला scene था कि very high. लेकिन सातवां से mustard ग़ज़र गया. उसमें आपको document देना पड़ता है. उसमें कुछ ख़ास मेहनत करने की ज़रूरत नहीं पड़ेगी आपको. Net से मिलेगा सब कुछ. फिर आठवां से मुस्छर भी इसमें आपने अपनी implementation करनी होती उस चीज़ के लिए. चार दिन रह गए थे internal ले ली. Sorry, internal और external के लिए. मैंने फिर P को हाथ में ले लिया था. तो मैं बाकियों को देख रहा हूं हम सब अपनी वह final testing कर रहे हैं. सब ठीक है कि नहीं? अब मैं जिसने call अभी नहीं था अभी तो. तो मैंने क्या किया? मैंने देखा online इस तरह की services. कौन provide कर रहे हैं? उनका जो template था, उसको उठाया. दो तीन scanners जो open थे उनको integrate किया. ठीक है? और एक अच्छी सी शक्ल से FIP बनाकर मैंने present कर दिया और everyone was like wow. Obviously यहां तक याद पड़ता है कि जब मैं अपना internal दे रहा था अपनी faculty के इसको scan करके दिखाओ. मैंने उसी वक़्त scan पर लगा दिया उसको. First में SQL injection निकलाया जिसके through हमने admin portal bypass करके दिखाया और हर एक बंदा सोच रहा था यह क्या हो गया? So वहां पर कुछ teachers थे मतलब

Muzamil

Because तुम computer science का coding नहीं कर रहे बैठे हुए तो तुम तो सबसे बड़े failure हो इस दुनिया मैंने कहा था यार computer science is like I mean it's something that I would love to learn but maybe I don't wanna pursue it as a career but वह मेरी convocation होती है मैं computer science के batch का same day graduate करने के बावजूद उन्होंने मुझे electrical engineering के साथ graduate किया और मेरी तस्वीर भी उनका खिचवाई just to sort of spite पंद्रह बीस minute आगे करके और मतलब बंदा कहता है कि यार आप या तो आप मुझे exam दे दो ना. अगर तो मुझे नहीं समझ आ गई but just the idea कि ये हमारे निज़ाम में अगर attendance है तो attendance है, हमसे पढ़ेगा तो ये आ गया जाएगा. वो thinking थी और what you have said is I mean that's just empowerment on another level कि यार अगर लड़का खुद से कर सकता है तो क्यों उसको फ़ालतू में उसको रोकने की कोशिश कर रहे हो? That's

Guest

very fascinating. हां, मैं thankful to them. दो मेरी field बिल्कुल अलग थी अगर उनको समझ नहीं भी आती थी लेकिन वह हमेशा appreciate करते थे कि यार good job और आकर करते रहो. तो मैं समझता हूं अगर technical तौर पर उन्होंने कोई help नहीं की, तो कुछ किया तो है ना. तो मैंने कहा tension ना ले sir, इंशालाहब सब कुछ अच्छा होगा. तो सब कुछ अच्छा गया university ख़त्म होगी और यहां पर एक और चीज़ थी जो मैं mention करना चाहूंगा कि हमारे यहां ना बच्चों को बताया नहीं जाता even cybersecurity field जब मैं कर रहा था that was more like black hat thing, ठीक है? इसमें career का कोई option नहीं था हमारे पास क्योंकि हमने देखा था पढ़ा था कि हमसे पहले के जो लोग थे वह या तो arrest हुए थे तो तकरीबन अगले कुछ महीने या अकेले साल तक मैंने freelancing कर रहा था और आखिरी semester तक मुझे idea हो गया था यार this is good for example मैं hardly तीन चार दिन काम करता था. पचास हज़ार रुपए में ऐसे ही कमा लेता और मैं Israeli based company है offensive security, ठीक है? ठीक है. हमने पहले EC Council का नाम सुना था the Salute Theory. उसको आप यह कह लो कि यार वह EC Council क्या? EC Council एक body है, certification body है जो आपको cyber security की certifications करवाती हैं for example certified ethical lacking, ठीक है? यह उनकी तरफ़ से है और उसमें mostly theory है या फिर tools हैं. Right. वही अपने करने होते हैं, ठीक है? Offset अलग चीज़ है. उनका जो owner है वह अलग में एक बलात ही अपने time की. तो उन्होंने कहा ठीक है, business start करते हैं और offensive security के नाम से ना एक company launch की और सबसे पहला course जो उन्होंने launch किया था I guess that was OACP, offensive security certified professional, ठीक है? ठीक है. और यह एक कह लेंगे ना market में ऐसे आया कि सारी जो पीछे certification की bodies थी, companies थी वह side पर होगी. क्योंकि उन्हें practical experience के basis पर जब अपन test perform करते थे अपने career में, उसकी basis पर उन्होंने labs बनाई. उसी के according उन्होंने content generate किया जो top notch था बिल्कुल और आगे, ठीक है? मज़े की बात. आपको content देते हैं वह लोग. आप guide पढ़ लेते हो, videos देख लेते हो. तो आगे से कहते try harder. यह आपको जवाब मिलता है आगे से दुबंधा कहते मैं कहां जाऊं? ठीक है? तो मतलब painful. आपका दिमाग़ फटने लग जाता है ख़याद तक और यह सबसे आसान certification है offensive security certification series में. मैंने नहीं की थी. मुझे याद है Pakistan में नवेदन सारी. मैंने सुना था वह पहला बंदा जब मैंने उनसे पुछा था उन्होंने कहा नहीं मैं second हूं. मुझसे पहले भी एक बंदे ने OEC प्रयास किया था. मज़े की बात, OEC भी clear करना बहुत tough है. It's not easy. तो वापस Pakistan है और मैंने कहा चलिए ठीक है, let's give it a try. मैंने register किया उसी P के लिए और एक महीने के अंदर clear हो गया. दुबारा कुछ दिन बाद register किया CE के लिए. एक महीने के अंदर CE किया है. मैं वहां बंदा हूं Next एक call आया ना शुरू होगी जब उसकी. मैंने कहा यह क्या हो रहा है? ठीक है. So मैंने रियात में productivity करके यह भी मेरे ख़याल से business auditing firm है I guess. उनकी तरफ़ से मुझे offer आई और साथ में मुझे कचर से एक और जगह से offer आई and that was कचर national cert, ठीक है? It's not a company. यह पूरा अयधारा है जो पूरे मुल्क की security को देख रहा होता है. Right. ठीक है? और जिस age में लोग अपने internship ढूंढ रहे होते हैं, मुझे initially दस साल का jump मिल गया था अपने career के अंदर क्योंकि वहां पर पहुंचना usually आपको आठ, नौ, दस साल की experience चाहिए होता है. Right. और वहां से मैं सब कुछ पीछे छोड़कर इस field के अंदर अब आ कर पढ़ रहा हूं. Right, very interesting. So, or you move to Qatar from Pakistan से मैं Qatar चला गया. Pakistan काल चला कितन से आप बहा रहे हैं? मैं ढाई साल है वहां पर. मुझे वह काम पसंद भी नहीं है दूसरी बात. मुझे जगह नहीं पसंद आई. बहुत मतलब आप Middle East को अगर आप fast moving countries के साथ अगर आप compare करें ना तो जो यहां रह चुका है वह कहीं और नहीं रह सकता क्योंकि एक कतर में आपको यह होगा यार सन्नाटा है, सकून है. COVID था peak पर उस वक़्त ही मैं October last year बात बता रहा हूं. October 2020 की बात बता रहा आपको. तो Australia वाली चीज़ hold पर चलेगी कि नहीं अभी visas गहरा. मुझे रियात से offer आएगी Saudi Telecom company जो कि सऊदीया की दूसरी सबसे बड़ी company after सऊदी आराम को. Right. साल मैंने वहां गुज़ारा और अभी मैं गया नहीं था वहां पर. जैसे कि मैं बात remote चल रहा था. Remote नहीं था मैंने on-site ही थी लेकिन वह travel ban की वजह से मुझे तो नहीं गया. मैंने कहा नहीं यार घर से काम चल रहा है, कौन जाएगा UK? तो वह करने के बाद जनाब मैंने UK में मेरे उसी time जब मैंने जब उन्होंने बुला रहे थे मैंने कहा नहीं मुझे नहीं आना. Ok, that was over. मेरे UK में December 1 से भी

Muzamil

मुझे थोड़ा सा यह बताइएगा जो यह OSCP and OSCE,

Guest

what do they stand for? OSCP stands for offensive security certified professional. It's like a very difficult baby certification. Right. इसके बाद आता है आपका offensive security certified expert. Mhmm. इसके बाद अगर आप difficulty wise देखना चाहते हैं तो उसके बाद आता है offensive security web expert. Right. और सबसे मुश्किल जिस industry के अंदर जो मानी जाती है certification की जिसको करना close to impossible है, मैं तो यह कहूंगा that's offensive security exploitation expert. अब बात यह आती है क्यों? इसमें आपको वह सिखाते हैं, वह RDX बनाना सिखाते हैं जो पे gases के अंदर use हुए हैं. हां, right. ठीक है. और उसको how many people have done that in the world? I guess less than 100 as per the instructors. जब मैं black hat Singapore गया था training लेने के लिए तो मैंने उनसे पुछा था. उस वक़्त उन्होंने मुझे बताया कि मतलब अगर for example usually 25 seats होती हैं per year

Muzamil

ये बातें तो सारी की सारी समझ आ गई but मैं cyber security expert तो बहुत दूर की बात है, बड़ा cyber security guy to begin with, right? आम alfas में अगर मैं आपसे पूछूं कि यार क्या है ये दुनिया? What is all of this? How would you explain it to me? The cyber security world? Yeah, like cyber security world, certifications. What exactly practically what's really happening here? Like what's going on? What are you doing? इस

Guest

चीज़ को समझने के लिए मेरे ख़्याल से हमें information technology को समझना चाहिए. Computing की दुनिया को समझना पड़ेगा. For example, मैं eighties की बात करूं तो यह computer का trend जो है ऊपर आने लगा था for example पहले mainframes थे, ठीक है? और बड़ी भी industries में user को उसका forward भी नहीं कर पाता था. फिर general जो PCs हैं for example users के लिए आने लग गए थे वह और उन्हीं चीज़ों पर acquire किया गया आगे यह जो आपकी जो different IT की companies बनना शुरू हो गई थी, ठीक है और काफ़ी businesses इनको inquire कर लिया था. उस वक़्त जो focus रहा था सारा ना वह development पर था. Right. क्या किया जाए? Computers का size छोटा किया जाए? मज़ी technologies बनाई जाए, ठीक है? ताकि पैसे कमाए जाए. So IT was business, ठीक है? Right. Time के साथ पता चला इनके अंदर loop holes हैं, ठीक है? कैसे पता चला? ठीक है? अगर ma'am Morris form का नाम सुनाओ कभी उसकी हम बात कर लेते हैं. Nineteen eighty eight के अंदर एक form निकला था virus जैसे कहा कहते हैं usually और आपके जो उस जमाने के PCs थे उनको destroy करता था, ठीक है? I don't remember he was he was the graduate from MIT or Stanford लेकिन वहीं के थे. मज़ा ही बात, एक program आपको दिया गया था इसका sole purpose यह है कि यार for example calculation करनी है. एक बंदा ऐसी चीज़ बनाकर देता है जो computer destroy करना है. सोचने वाली बात है how is it even possible? Maximum मैंने आपको computer सामने रखा है जिसका maximum काम ही है कि आप two plus two कर सकते हो. हां. ठीक है? मैंने आपको एक email का system दिया हुआ है जिसके अंदर आप email लिखो, आगे जाकर email पहुंच जाएगी. एक बंदा निकलता है जो computer का जो stack है ना जिसे बनाया गया था for example memory होगी, operating system उसके अंदर weakness निकालना शुरू हो जाता है. तो मैं समझता हूं वहां से एक psyche वन गई थी. ठीक है? एक train बनकर security भी कोई चीज़ है. ठीक है? उस वक़्त तो यह cyber का concept नहीं है. For example internet चल रहा था gas, internet का ज़माना ही नहीं था. तो उस वक़्त जो चीज़ें चल रही थी mostly virus based research होती थी कि ठीक है, लोग worms और viruses का नाम हम सुनते थे. Right और floppyयों पर इधर से उधर जाते थे. Floppyयों पर brain-brain-brain virus का हमने नाम सुना था. Right. यही चीज़ें चलती थी. Time के साथ जब internet आम हुआ, लोगों के घर में आने शुरू हो गया. Internet के basis के ऊपर ही business start होने लगे, websites बनने लगी. ठीक है. नहीं नहीं, technologies आने लगी for example, server side programming आपकी आने लगी, low level programming आने लगी. तो लोगों ने researchers ने basically ये techniques निकाली कि यार क्या क्या weakness हो सकती है? PhpA for example server side language किसकी संपती weakness हो सकती है इसके अंदर? Research थी. Morris was a hacker. इसने Morris form लिखा है. Mhmm. उसने for example एक attack vector निकाला था जिसका हम buffer of flow कहते हैं. ठीक है. ठीक है? तो अगर मैं यह कहूं ना कि Morris एक hacker था और hacker की general definition हमें यह सुनने का यह कि यार कैसा बंद है जो extreme programmer हो? Ins and out of computer system को समझता हो. Mhmm. वह hacker है, ठीक है? Black hat, white hat का concept आ जाता आगे से. अब Boris की जो चीज़ थी जो उसने attack vector आपको दिखा हर सी बात है जिस service के अंदर उसने bug निकाला था, वह बहुत service तो नहीं थी. और भी चीज़ें लिखी गई थी. For example, अगर मैं कहता हूं C language was used to develop that sand mail. जो भी email भेजने के लिए use होता था या finger d की service जो थी जिसमें memory corruption का exploit था. तो उसी C language को use करते हुए बाकी services भी तो लिखी गई थी बाकी I mean software बनाए गए थे. That means कि उसने attack factor निकाला, लोगों को बता दिया. Right. अब उस vector की basis पर वह हर एक software को लोग test करना शुरू हो जाते हैं. ठीक है? किसी भी for example मैं कहता हूं XP के अंदर वही vector निकाला है. कहीं ना कहीं भी किसी software की सी line के ऊपर वह बात था. ठीक है? तो अगर तो एक बंदा उसको अपनी जाती मफाद के लिए इस्तेमाल करता है तो वह कौन हो गया? Hacker. Black hat हो गया. Hacker नहीं, hacker Morris ही था. अच्छा. Hacker Morris ही था. जिसने attack vectors निकाले हैं, Memory में save होता है. Mhmm. लेकिन memory तो इतनी बड़ी है. Mhmm. कहां save होने वाला है? Operating system को क्या पता कि कौन से program का address space कहां पर होगा? Mhmm. उसमें भी पचास या पांच सौ for example functions हैं. हर एक functions की जगह कौन सी देनी है? Right. कहाँ रखा जाएगा stack के ऊपर? इसने find out कि यार there is a return pointer. Right. इसको override कर सकते हैं और अपनी उसके लिए आप इस्तेमाल कर सकते हैं. सुबह देख रहे जितना आप computer को बेहतर समझेंगे नई नई classes, old classes या research. पर most people they will

Muzamil

अब जाहिर है कि उसमें फिर computing में essentially any any part of computing जो कि हमारा तो more and more दुनिया में उसका जो interaction होता जा रहा है. तो meta के अंदर तो हम काम भी essentially उसी पर ही कर रहे हैं. ज़ाहिर है कि digital उसपे digital पे services भी आ रही हैं, financial भी आ रहा है, सारा कुछ आ रहा because of that obviously security is an important aspect to it. जो आपकी

Guest

again मैं जरा certifications को breakdown करूंगा. जो OSCP है वह किस level पर है और क्या essentially आपको बताती है? OSCP basically आपको network pen testing सिखाती है जो usually consultancy companies जो services provide कर रही उसमें pen pen testing service है, ठीक है? और CP आपको वह अच्छे से कराने सिखाती है कि यार आपने कैसे करना है? For example कोई भी आप Google के blog post पढ़ लें. Already जो companies है वह blog post लिखे होते हैं या बने बने exploit पढ़े में आप इसको इस्तेमाल कर लेते हैं, ठीक है? लेकिन proper तरीका क्या है? कैसे होना चाहिए, ठीक है? OSCP का basically जो motto था या इस चीज़ के ऊपर उनका vision था कि यार लोगों को क्या बताना हुआ था enumeration. Right. ठीक है? I think like for example penetration का मतलब यह होता है कि services exposed हैं. ठीक है ठीक है. Penetration testings basically penetration testing. Essentially वह यह कह रहा कि यार आपने किस तरह के system अंदर घुसाया अभी weakness है find करो अंदर जाओ. Weakness कौन सी? Research वाली नहीं. Already जो disclose हो चुकी हैं उनको use करते हुए network level की. ठीक हो गया. फिर उसके बाद आपका OSCE.

Muzamil

उसने

Guest

क्या सिखाया? See, it was mostly related to what Morris did. Right. ठीक है? Low level stuff के बारे वह को पढ़ाते थे और यह पुराना ही था for example Windows XP के level का या Windows Vista पर जो आप कह लेंगे low level system हम मिसाल ले लेते for example Windows XP में कोई bug था internal, ठीक है? QA works. Exactly. मैं कहता क्यों यह करते कि software कैसे किस तरह के input दो जो mishandle करें और सही से काम नहीं करें तो मुझे वह find करने वह parameters. ठीक है? और वह test cases identify. Safe goes for bug bounty hunting, लेकिन mostly जो bug bounty hunting हो रही है वह web पर हो रही है. Right. ठीक है? और जो PICSS के level पर या फिर जो governments, law enforcement agencies वगैरह, ठीक है? Offensive companies वगैरह चीज़ की research करती है, वह mostly आपकी वह चीज़ें जो दिखाई भी नहीं देती. मिसाल के तौर पर आपका iPhone. Right. IMessaging application तो है. हां. ठीक है? मैंने आपको एक message भेजा. आंखों से नज़र आ रहा है आपको. हो सकता है आप यह भी detect कर लो कि malicious है. Mhmm. ठीक है? उन्होंने उस चीज़ पर research करना है कि ऐसे आपके mobile के साथ communicate करना है, ऐसी चीज़ भेजनी जो आपको नज़र भी नहीं है. Mhmm. ठीक है? That's a separate thing. उसको कुछ और कर दिया, उसको vulnerability research कहा जाता है.

Muzamil

Right उसके बाद आपकी O S E हो गई O S E में जब आप low level की बात कर रहे तो आप essentially क्या कह रहे कि assembly level के ऊपर assembly level पर exactly assembly level के ऊपर उसके बाद O S E हो गया O S E के बाद आपका आया OS W E

Guest

नहीं नहीं. W या web. Web बस. तो वह web वाला जो है वह generic जो आपने बोला कि web के अंदर नहीं और stop 10 तो पढ़ाते हैं आपको लेकिन यह आपको mostly इसे खाते हैं कि vulnerabilities का chain कैसे करना है? ठीक है. For example ज़रूरी नहीं कि हर एक vulnerability exploit ही होगी. Right. ठीक है? तो यह आपको कहते हैं कि ठीक है, कुछ test case studies आपके सामने लिए हैं, ठीक है? जो बड़े softwares थे और उनको आपने कैसे audit करना है, कितना weakness आपने find करनी है? वही होगा stop 10 ही है basically.

Muzamil

लेकिन हो सकता है कि कुछ ऐसी जगह जहां पर आप exploit ना कर सको उसको. Right. तो उनको exploit करने के लिए chain of vulnerabilities को कैसे combine करना है? और ताकि जाकर वह आप exploit हो सके. Right. तो यह एक plus point था उनका. और यह जब आप vulnerabilities की बात कर रहे हैं तो are they only exclusive to some sort of like a bug in a in the system या इसमें वह भी आते ना essentially अगर आप कहते हैं कि यार मैंने if I have to attack someone digitally तो मैं उसके अंदर वह system overload भी कर सकता हूं what's it called. वह आप जो है जी जाकर spam messages भेज भेज कीजिए. क्या है WhatsApp? हां, redoce वगैरह type की तो. तो वह भी इसमें आता है या वह अच्छा? हां, वह multi class है. अच्छा. Multi class है. Right? और फिर उसके बाद finally आता जो OS double E जिसमें आपने कहा कि जो पगैसे level है. पगैसे level है. For Windows platform. For Windows platform. What does that mean?

Guest

Sir, यह समझने के जो research पगैसेस के अलावाल पर हो रही है या pontoon competition जिसको मैं discuss करता हूं फिर बाद में, उसमें जो research हो रही है वह usually ना तो आपको Google पर मिलने वाली है, ठीक है? ना आपको वह चीज़ किताबों मिलने वाली है, ठीक है? ना वह web से related उसका कोई तालुक होता है. Right. पढ़ाने वाला कोई नहीं है उस level की technique. So for example, किसी से पूछे ना Windows का kernel कैसे hack होता है? Windows का kernel itself है क्या? ठीक है? लोग तो user user space और kernels में differentiate नहीं कर पाते. उससे पहले इस तरह की चीज़ें black hat conference में पढ़ाई जाती हैं जो 2,010 के अंदर मैंने देखी थी और वह लोग भी वह थे कि जो ग़ायब हो गए अब कहीं और लगे हुए हैं, ठीक है? अच्छा. तो double e आपको basically यह पढ़ाता है कि modern जो software हैं, for example आपके browsers होंगे, इनके अंदर जो पुरानी vulnerability classes हैं, for example अगर Morris ने निकाला था buffer overflow, stack based buffer overflow, that's close to non existent. ठीक है? क्यों? क्योंकि वह इतना exploit हुआ है कि Microsoft को पता चल गया था यार मेरी coding में या क्या weakness आती थी या वह coding paradigm क्या था जिसको हमारे developers use करते थे जिसकी थोड़ी weakness आती उन्होंने उस चीज़ कोई change कर दिया या फिर example जिस बंदे ने c और mostly member cryption बग़ज़ाब के यह low level programming लग जैसे c, c plus plus में ही आता है. तो जो बनाने वाले थे c और c plus plus को उनको भी पता चल गया था ठीक है. तो अब नए version for example c इसको पढ़ाने वाला कोई नहीं है. Offset ने कहा चलो ठीक है, हम ऐसे researchers ढूंढते हैं जो इसके ऊपर काम कर रहे हैं. उनको बोलते हैं आकर हमारे साथ training दे, ठीक है? तो doubling basically मुझे जो पढ़ाया गया था उस वक़्त पर वह हमें Firefox exploit करना सिखाया था. बिल्कुल नया जो Firefox था Windows 10 के ऊपर. इसके अलावा हमें age exploit करने की case study थी जो अभी Google की Project Zero निकाला था वह बाक. यह यह कौन सा है? Google Project Zero. So दुनिया भर की जो big companies हैं उन्होंने cyber security की teams रखी हुई हैं. Right. और जो पूरी दुनिया में cream है ना वह निकालकर अलग hire करते हैं. अच्छा. तो आप यह कह सकते Google Project Zero एक team है Google की जो बहुत सारी security teams हैं लेकिन जो उनका बिल्कुल cream है ना operating system हो गया, mobile phone हो गया, Android ले लें. ठीक है, IoT की हो गयी, virtualization technology आपकी होगी. उनका काम यह है कि इसको exploit करना है, weakness निकालनी है, vendor को बताना है ताकि जो चल रहा है सारा कुछ दुनिया भर में exploitation हो रही है. ठीक है malware से wait कर रहे वह रुकी जा सकती है. Zero day से camera आता है आपका? Zero day का मतलब यह है कि ऐसी weakness किसी भी software के अंदर जिसके बारे में author के अलावा किसी को पता नहीं है. Right. मैं साल के तौर पर. हमारे सामने mic लगा हुआ है. ठीक है? मुझे कोई ऐसा method technique पता चल गई है, ठीक है? जिससे मैं इसको mute कर सकता हूं remotely. Right. किसी को और को नहीं पता. So this technique, this बाकी the zero day जब तक मैं आपको नहीं बताता. तो जब किसी और को पता चलेगी, उसको हम end day कहते हैं. Right. And so, यह है. ठीक हो गया. और

Muzamil

Pegasus का generally mode of वह था क्या अलग? Because it's very sort of, oh जी, Pegasus कोई software है. Oh जी, बस button दबाए और सब

Guest

फिर यह common होगी technology और आजकल मैं कह सकता हर country के पास drone technology लेकिन जैसी कोई technology, ठीक है? Public के पास जाती है, ठीक है? तो उसका फ़ायदा यह होगा दूसरी company वह defense system बना सकते हैं. Right. ठीक है? लेकिन beach में एक company पूरी दुनिया में आकर आपको कहती है कि मेरे पास ऐसी technology है. अगर आप अपने drone के साथ उसको integrate करते तो आपका पूरी दुनिया में पकड़ा नहीं जा सकता. Surveillance करते रहो. ठीक है? Mhmm. Gas is के case में क्या था? तो यह same चीज़ तो फिर जो spyware बनाने वाली companies है. Spyware basically एक software है जो आपके mobile पर या system के ऊपर जाएगा और उसमें भी surveillance करनी है. आपके camera की success करना है, critical files उठानी है. Microphone से बातें सुननी है, ठीक है? आपके messages जो encrypted पड़े होते हैं, ख़ैर decrypt हो जाते हैं. Messages वग़ैरह निकाल लें. Spyware का काम होता है. लेकिन वह spyware block के करेंगे क्या? Defense systems इतने strong हैं. Apple अब initial stages पर तो नहीं है ना? दो हज़ार इक्कीस चल रहा है. इतने strong defenses हैं Android के, Windows के अपने और इसके. तो अगर उन्होंने spyware बना दिया है NSO ने for example. NSO spyware बनाने वाली company है साफ़ सी बात है. Right. क्या करें? कैसा करूं मैं कि यार मुझसे यह चीज़ आगे government, eleventh, first and justice ख़रीद लें? NSO, यह भी 100% guarantee नहीं है कि वह यह जो, for example, यह जो exploits होते हैं, यह ख़ुद बनाते हैं. Zero day acquisition market है पूरी, ठीक है? For example ऐसे brokers हैं जो दुनिया भर के researcher से zero days खरीदते हैं. ठीक है? Zero day किसका हो सकता है? आप कह सकते हैं web का भी हो सकता है, web hack हो रही है जिससे zero day. IPhone के अंदर कोई component, इसके अंदर कोई weakness है उसको exploit किया जा सकता है. Exploit करने का मतलब यह Apple को नहीं पता. उसके against कोई defense ही नहीं तो वह क्या करेगा? Right. ठीक है? That means उसको utilize करो.

Muzamil

तो मैं iPhone hack कर सकता हूं. That's interesting. So essentially Pegasus ने यह किया है कि उन्होंने दमियान में एक वह, it was a lot of basically good networking,

Guest

good politics and a smart team that got together and were able to get these exploits first before it went to the market. यह पूरी market है. इसको zero day market कहते हैं. अच्छा. ठीक है? Underground है. दो लेकिन किसी बंदे में मिसाल लेता हूं. For example, Apple आपको देता है अगर आपने Pegasus level में Pegasus expiry, Pegasus ने exploits खरीदे या बनाए हैं. भी हो सकता है. Integrate की अपने spyware के उसको Pegasys का नाम दे दिए हैं और वह fire करते हैं. मज़े की बात. यह सिर्फ़ बेचते हैं government को. सोचने वाली बात है क्यों? कोई जितना ज़्यादा बेचेंगे detection rate ज़्यादा हो जाएगा. हां हां हां. एक for example एक researcher है उसने Apple को क्यों नहीं बेचना? इनको क्यों बेचता है? हां. ठीक है? Apple आपको exploit कर देता है $1,000,000. Brokers आपको दो million dollar दे रहे हैं तो फ़ायदा क्या हुआ? और यह broker जब NSO जैसी companies को यह चीज़ आगे बेच रहे हैं infrastructure खड़ा करके देती हैं. उसी में weakness डाल देती हैं. Government को बेचती हैं कि जाकर surveillance करो अपने लोगों पर. ऐसे भी चल रहा है. Interesting.

Muzamil

Interesting. जो NSA करी थी essentially. NSA

Guest

यही they had their own success. NSA का जो अभी तक model पता चला business का वह यह था कि वह already जो public applications हैं like for example IOS हो गया उसके अंदर जो internal applications चल रही हैं उनके ऊपर research करती थी उनके अंदर weakness निकाल लेती. दो हज़ार सोलह में जो PEGases का पकड़ा गया था sample, उसमें जो exploit इस्तेमाल हुआ था, basically आपको message आएगा. Mhmm. आपने उसको खोलना. जैसे ही उसको खोलोगे, basically है तो वह पीछे HTML, JavaScript, CSS चला कौन रहा उसको? Right. Safari. Right. Safari एक self software है. Mhmm. जो prone है memory corruption bugs के लिए. Mhmm. तो जिसने भी वह exploit बेचा, किस्मत के नाम से थाए गए. किस्मत कहते हैं, किस्मत कहते हैं. उसने Safari को exploit किया. ठीक है? Safari अभी अपने Apple का model को समझना है, ठीक है? Mhmm. Apple आपकी हर एक application को sandbox के अंदर चलाता है. Right. एक application दूसरे को communicate ही नहीं कर सकती. IPC के through करती है लेकिन यह नहीं है कि यार मैंने आपको अगर एक malware भी दे दिया है इसका, उसको चला दिया है. ज़रूरी नहीं है आप सारे iPhone की चीज़ों को access कर पाओगे. Basically उस app को आप exploit कर सकते Right. गया, WhatsApp compromise हुआ, colonel exploit हुआ, phone आपका combo हो गया. अभी जो packages पकड़ा गया iMessage का नाम उसके अंदर आता है. IMessage का basically application, ठीक है? Mhmm. अब भी उसमें जो Project Zero ने discovery की कि उसके अंदर क्या exploit हुआ? तो basically जब आप iMessage पर कोई PDF भेजते हैं तो उसके अंदर आप GIF GIF whatever. आप उसके अंदर embed कर रहे हो. Right. तो GIF की जो processing है ना Apple की graphics एक library है वह कर रही होती है. ठीक है. उसके अंदर भक्त है. Really interesting. PDF भेजो. IMessage पर. हां. अंदर जाएगा, exploit करेगा. Combine कर दो kernel exploits के साथ और phone आपका आओगे. Interesting. यही चीज़ है कि फिर यह काम करना मुश्किल नहीं और यह कोई इतना मुश्किल काम नहीं है just you have to invest some time, ठीक है? तो आप China, Russia, US वग़ैरह होगी, ठीक है? इनका कोई comparison नहीं कर सकते. हर बंदा किसी ना चीज़ में बेहतर है.

Muzamil

जिनको पता था यार computer काम कैसे करता उनको बताना कैसे तभी तो उनकी सबसे बड़ी army यहां पर. Do you think जो यह अभी Pakistan में भी I'm sure Pakistan India में भी है जो sort of underground armies चल रही हैं cyber security cyber security cyber attack

Guest

मैं समझ हूं. तो MLR analyst है. अब मैं उसके साथ बैठकर ना बातें कर रहा था कि मैं उसे दो हज़ार सौ, 2019 में black hat Singapore में मिला था वहां से. थोड़ी जान पहचान हो गई थी. उसके साथ बाकी Indians में बैठे हुए थे आप लोग कैसे यहां तक आते हो या क्या तरीका है जिसके साथ? मुझे simple कहते हैं यार कोई बड़ी science नहीं है इसमें. जैसे हमने क्या किया था हमने local meetup start किए थे कि जो researches अपने आप को कहते हैं या hackers थे उस time के, ठीक है? और जो हमने सीखा throughout the years उसका हमने content बनाकर वहां पर कर दिया. अब यह तो वह था कि आप कैसे for example लेकिन virtual Pakistan से भी कैसे जा सकता है? जहां तक बात आई यह दूसरे side की capabilities इन लोगों की क्या है? तो spivers तक capabilities ज़्यादा ज़्यादा virus बना सकते हैं, ठीक है? और दूसरी country तक भेज सकते हैं. और फिर कोई मनप्पा जैसा बंदा या Pakistan में मनप्पा जैसा बंदा उसके against कोई defense खड़ा कर देगा. Right. कम होगी. का नहीं है defense.

Muzamil

यह तो वह need सोनू है matter of time before आपके massive large scale आना शुरू जाएंगे और आपके जो यह do you think कि हमारी जो even companies काम कर रही हैं वह इतनी secure हैं कि उसके ऊपर जो है वह local या foreign organizations, terrorist organizations. I feel like the future of terrorism is not bomb lasts. बिल्कुल. I mean it's just like you know you wipe out the entire digital infrastructure and everything is over. So do you think they were ready? Do you think there is any protection for us then? देखिए,

Guest

ज़्यादा companies की बात है तो invest करें defense systems के अंदर, ठीक है? अलग आ रहे हैं cybersecurity वाले से जो भी होती है. लेकिन जहां तक पाक्षतानी companies का तालुक है तो foreign companies ऐसी मौजूद हैं जो आपको defense system बेच रही होती हैं. ठीक है? हर किस्म का क्या attack की हवाले से? Web applications हैं तो ठीक है वह आपको firewall भेजते हैं कि इस्तेमाल कर लो कोई बात नहीं attack आता है तुम्हारी e system है और उसको पकड़ लेगा. अगर आप endpoint की बात करते हैं, system जो वहां पर install हो रहे थे, वही होते हैं और जो इस्तेमाल हो रहे होते हैं, उसके हवाले से endpoint solutions आपके पास मौजूद हैं, ठीक है? Antiviruses आपके पास हैं. Mhmm. ज़्यादा से ज़्यादा आप इसके अंदर invest कर सकते हो. लेकिन तो फिर भी वह कहीं ना कहीं काम नहीं करेगा. ठीक है? दूसरी बात, जैसे मैंने आपको कहा कि आजकल bug bounty में तो हम यह देख रहे होते हैं और web applications पर attack कर रहे हैं और bounties ले रहे वह एक अलग बात है लेकिन जो आपके APTs हैं वह कभी भी काम नहीं करते हैं. Mostly viruses, spivers बनाते हैं, ठीक है? Valueers बनाते हैं और somehow किसी ना किसी employee को target करते हैं, ठीक है? अब एक employee ही अंदर ले आया आपके, ठीक है, network के अंदर एक malware. तो बाहर जो आपने blocking के लिए जितने systems लगाए थे वह तो Irrelevant. Irrelevant हो गए. या फिर for example अगर वह लगे हुए थे, उनके अंदर for example कोई weakness होगी तो क्या करें? Log four j चल रहा हर जगह पर internet के ऊपर, काफ़ी मेरे ऐसे दोस्त हैं जो मैं समझता हूं कि यार यह वह लोग हैं जो Pakistan को represent कर सकते हैं international लाल पर. Unfortunately, ना तो उनको मौका दिया गया, ना वह ख़ुद चाहते हैं public के सामने पाए रहे.

Muzamil

What about government?

Guest

यह event था black hat की तरफ से जो सुरेहात में हो रहा था. CTF हो रहा था वहां पर. इतनी लंबी line और इतना organized CTF है नैष्ठिनित का. School के बच्चे खेल रहे थे. वही Israel वाली policy. ठीक है? हमारे यहां कौन आया था? Universities के बच्चे से आए थे? School के बच्चे क्यों नहीं हैं? College के बच्चे क्यों नहीं हैं? आप Pakistan का cyber power बनाना चाहते हो? तो cyber secure Pakistan बोलने से दो तीन events कराने से आपका मुल्क secure नहीं होने वाला,

Muzamil

आज cyber security की requirement उतनी ही important है जितनी आपके nuclear bomb की important importance थी. Future of as a matter of fact Pakistan में I know for a fact कि जिस हद तक हमारी जो warfare के अंदर, हमारी जो equipment के अंदर जिस level पर IT की integration हो रही है, मैं उसमें ज़्यादा details में नहीं जाऊंगा but हो रही है और जितने ज़्यादा IT की integration होगी उतने ज़्यादा vulnerabilities भी आएंगी. उतना ज़्यादा जो है आपको you need the top talent that can come in and that can create the future of internet for your country and that internet is has some sort of a structure जिसके अंदर security का कोई कोई basis होगा जिसकी basis पर आप वह कर सकते हो. वह होता है ना कि आपका Pakistan का critical infrastructure पिछले दिनों I feel I I remember if I remember correctly I think यह भी hack हुआ था. Power grid भी hack हुआ था Pakistan.

Guest

हां हां. K electric हुआ था I think यहां. कुछ कह रहे हैं कि यह cyber attack था. कुछ कह रहे हैं नहीं. Glitch वगैरह था. Glitch वगैरह था. देखें companies ऐसा नहीं है कि है नहीं Pakistan में. अच्छी companies हैं. यह bricks बहुत अच्छी मिसाल है हमारे सामने. बाकी भी company है for example Tranchelets, Hertrillium है. यह भी अच्छा काम करें. Are they working for the government? या वह यही है कि वह run time पर अगर कुछ होगा तो तो मुझे जो लगता है जो मैं personally feel करता हूं I mean, friend नहीं करना चाहता किसी को. लेकिन जो bug bounty culture है यह हमारे मुल्क तबाह कर रहे हैं. मैं इसका समझ रहा हूं. आने वाली youth को बर्बाद कर रहे हैं. वह ऐसे अगर मुझसे कोई मुझे समझ नहीं आ रही थी इस वक़्त कि मैंने दस minute बोल तो लिए हैं उनको समझ नहीं है. Call मिलाकर दी एक एक ward है KPK में और वहां पर किसी hat से मेरी बात करी. उनको मैंने अपना सारा plan दाना मिलाकर sir अगर हम यह कर लेते हैं ना मैं Microsoft का owner, ठीक है? मैंने फिर dev team को बोला है, update करो. Windows होगी, update होगी बिलकर, ठीक है? Hacking team की मिसाल ले लेते हैं. वह भी काम करे zero days ख़रीदता था आगे से Adobe आपका हो गया, Microsoft हो गया, ठीक है? आपका Apple हो गया, Cisco हो गया, ठीक है? यह अपने products लेकर आते हैं, वहां पर रखते हैं. Up to date best. Researchers को बुलाते हैं यह पढ़े मैं इसको hack करके दिखाऊं चीज़ मिल गई. Competition का दिन आया. Up to date system उनके पास दिया जाएगा वह नहीं जिनके ऊपर आपने किया है company की तरफ़ से. अपने exploits इसके ऊपर run करेंगे. चल गया? That means कि एक latest चीज़ जिस तरह आपने recently सुना हो गया iPhone 13 अभी आया था Chinese ने hack करके दिखाया. Right. ठीक है? Tian Fu कब करके एक competition है वह इसलिए बनाया गया था. Chinese government ने ban कर दिए Chinese searches को कि pontoon में नहीं जाओगे. जो भी आपके exploits हैं government को बेचोगे. ठीक है? Interesting. तो यह है कि वहां भी चीज़ें हैं कौर्ति. अब pontoon competition की होता है. ठीक है? एक तो यह है कि for example वह ZDI, Trian Micro वह organize कराता है. तो Trian Micro को क्या ज़रूरत पड़ी कि यार उनको बुलाए ठीक है? और उससे पहले उनके अपने clients होते हैं जिनको अपने defense systems या जैसे system security solution भेजे होते हैं. उनको पहले से बता देते हैं यार यह भाग है, यह solution मैं आपको provide कर रहा हूं. तो client base उनका बढ़ता जाता है. Right. तो इस तरह की यह चीज़ है और pontoon है. इसका क्या है typhon कू tyan fu का पाया गया सिया. तो यह है. तो इनका producers का मकसद यह है कि researchers को बजाय इसके कि zero day और यहां black hat market में इन चीज़ों को बेचने से अच्छा है.

Muzamil

I know that you're you you you got into the hospitality industry once upon a time. थोड़ा सा उसके बारे में बताएंगे कि what that experience was? यह research है basically.

Guest

वाला वज़न कैत्र. जिस hotel में मैं रह रहा था. तो hospital industry में यह है कि या तो आपके property manager में system लगा हुआ था for example आप reception पर जा रहे होते हो. Mhmm. तो आपसे कहते कि ठीक है, कितने दिन के लिए कमरा चाहिए? ठीक है? फिर कहते हैं अच्छा payment by cash or card. Usually आप उसको card देते हो. ठीक है? तो वही point of sale system है. एक चीज़ सही होगी. या for example अगर आप आगे कहीं चले जाते हो जहां पर for example मैं कहता हूं HR का department है, employees बैठे हुए हैं. Mhmm. ठीक है? Hotel management कैसे यह देख रही होती है कि कौन सा कमरा है, कौन वहां बैठा हुआ है, ठीक है? HR के systems कौन से हैं मेरे पास? Systems के अंदर हर एक चीज़ मौजूद है. Room में कौन रह रहा ठीक है? कौन सा बंदा है, VIP है, नहीं है? Internet पर क्या देख रहा यहां तक वह लोग देख सकते हैं. ठीक है? IP कौन सी assigned हुई उनको? Firewall कैसे configure हुआ? DNS की settings हर एक चीज़ है उसके अंदर. That means कि हर एक चीज़ जो hotel के अंदर मौजूद है या buyer से guest अपने साथ लेकर आता है वह उस चीज़ के साथ connected है. Mhmm. अगर आपने उसको ही hack कर लिया तो क्या होगा? Mhmm. सब गया पीछे. Right. ठीक है?

Muzamil

तो मैंने somehow उसको compromise किया. Harold you get, manage to get into it. अपने Wi Fi से घुसकर.

Guest

Connect था उस वक़्त में उसके साथ और कुछ weakness मुझे नज़र आई. ठीक है? उसको exploit करते वहां पर चला गया. पता है यह चला गया यह तकरीबन छह सौ से ज़्यादा hotels ऐसे हैं जिनको internet से मैं access कर पा सकता हूं अपने laptop से. एक जगह से. एक जगह मैं बैठा हूं. Sir आप वहां से उठे उस hotel में, उस hotel से आप connected hotels में गए? छह सौ hotels थे जिसके अंदर आपका दुनिया का दूसरा seven star hotel Emirates Palace भी है. UK में ज़्यादा थे, Germany में थे, Saudi में थे. Right. तो यह थी मतलब it was kind of unique because 2015 के अंदर Silence company है. उन्होंने एक device के अंदर इस तरह का bug निकाला था लेकिन that was a very simple one. That was stupid मतलब यार कोई भी vendor इतनी की इतनी ऐसी चीज़ और इतनी critical चीज़ के ऊपर कैसे छोड़ सकता है? ठीक है? तो उन लोगों ने जो चीज़ निकाली थी वो असली America में use हो रही थी. मेरी जो चीज़ है उनसे kind of advance है. Vulnerabilities के हिसाब से मैं कहूंगा क्योंकि that was very easy to guess.

Muzamil

How do you see Pakistan? You know, आपका बड़ा मुख्तलिफ lens है, Pakistan को देखने का बड़ा digital क़िस्म का lens है. How do you see Pakistan in thirty years from now, in 2050?

Guest

मैं समझता हूं, अगर तो, जैसे मैंने पहले कहा था कि हमने अगर अपनी youth के ऊपर काम किया, ठीक है? और देखिए, digitalization की बात की जाए तो Pakistan already move कर रहे हैं और आगे जा रहे हैं. हमारी IT की export भी काफ़ी ज़्यादा हो गई है. और time के ऊपर decision ले सके. तो अगर तो government ने इनके ऊपर काम किया, ठीक है? इस तरह समझा जाता कि universities are nonsense, पैसे जाए करने वाली बात है और कई क़िसीयत तक यह बात true है, ठीक है? अगर इस प्रुजान को बदलना गया

Muzamil

That's 100%. One of the most difficult episodes to keep up with because बहुत technical उसमें आप थे और मैं मेरा computer science का background है मैं भी almost 85% तक आपको cover कर सका था. This time around I was like यार वो जो technical वाला आदमी है वो शायद देखे और वो देखे सीख सके और वो हो सके. Thank you so much for coming in for sharing all the insight and I wish you all the very best. You. For all of you guys thank you so much for watching. Support कर सकते हैं. If you would like, we accept anything from 1 rupee to as much as you like. It's a thought that counts. But हाँ, एक और हमने नई प्रकारिक्षा start किया It's called the Pakistan pavement जहा पर हम different policy makers, government officials और you know, former ambassadors, diplomats उनसे conversations करते Just to try to understand their policies and the thought behind it and what's going on in the world in a larger context. So you can check that out as well. The link is down below. But anyways, this was Sayyim Mazam elasun Zehdi. You were watching Thought Behind Things. Thank you so much for watching, and I'll see you in next one.