Skip to content
AppSec PodcastThe Application Security Podcast — home
36 min

Charles Shirer -- The most positive person in security

With Charles Shirer

Careers in AppSec

Charles is a Senior Security Consultant for Red Siege. He has over 18 years of experience in IT.

Audio hosted by Buzzsprout. Nothing loads until you press play.

Episode chapters · 12 chapters
  1. 00:00Meet Charles Shirer: The most positive person in securityAudioVideo ↗
  2. 02:37Oh, very cool. Well, as you know, then, as a frequentAudioVideo ↗
  3. 03:47Year was thisAudioVideo ↗
  4. 10:52My C question, how did you get C to run inAudioVideo ↗
  5. 13:03Was the, uh, the use case thereAudioVideo ↗

About this episode

Charles is a Senior Security Consultant for Red Siege. He has over 18 years of experience in IT. In his spare time, Charles does retro gaming and works on the SECBSD open source project, a penetration testing distro. He currently works as Staff at several Security Conferences, podcasts (GrumpyHackers) (Positively Blue Team Cast), and is a part of the MentalHealthHackers DeadPixelSec NovaHackers and HackingisNotaCrime Family. Charles joins us to talk about positivity in InfoSec. If you’ve never seen Charle’s videos, you’re missing out. We’ll unpack what drives his positivity and how we as infosec / appsec people can embrace a more positive approach to our world.

The Application Security Podcast is brought to you by Security Journey.

About Security Journey
Charles Scherer is a senior security consultant for Red Siege.
Learn more about Security Journey

Connect with Charles Shirer:
Red Siege
SECBSD

Resources
Red Siege
SECBSD
Kali Linux
Rust

Actionable

From this conversation

  1. Work toward doing what you love

    If you're in a position where you're not doing what you love right now, work towards doing something that you love.

    16:51
  2. Approach problems with a positive mindset

    The key is how you approach it. Because again, you still got to face the problem, but do you want to face it in a negative attitude or do you want to keep it in a positive light? That's the choice that you control.

    23:07
  3. Take a 30-minute reset when burned out

    If you're feeling burned out, take a break. It could be your favorite television show. Take like 30 minutes if you need to, or if you want to go see something outside, take a walk outside, but fixate your mind on something that you enjoy for like, for like 30 minutes.

    24:28
  4. Keep building skills instead of comparing yourself

    I may not do— I may not be able to do what you can do right now, but I guarantee you, if I, if I stick around and keep working at it, I will get there.

    25:43
  5. Take the first step toward your security goal

    Even if it's taking the first step of asking the question. That's a step towards the right direction. Hey, how do I do this? I guarantee you, there's someone out there that's willing to help you.

    34:21
Transcript · 36 min conversation

0:00Chris RomeoCharles Scherer is a senior security consultant for Red Siege. He has over 18 years of experience in IT, and in his spare time, Charles does retro gaming and works on the SecBSD open source project, which is a pen testing distro. He currently works as staff at several security conferences, is a part of the Grumpy Hackers and Positively Blue Team podcast, and is a part of Mental Health Hackers, the Dead Pixel Sec, and Nova Hackers, as well as the Hacking Is Not a Crime family. Charles joins us to talk about positivity in information security. If you've never seen Charles' videos, you're missing out. We'll unpack what drives his positivity and how we as InfoSec and AppSec people can embrace a more positive approach to our world. We hope you enjoy this conversation with Charles Schurr. At Security Journey, we believe security is every developer's job. We work with our customers to help them build long-term sustainable security culture amongst all their developers. Our approach is to provide security education that's conversational, quick, hands-on, and fun. We don't do lectures. Instead, we let the experts talk about what's important. Modules are quick, 10 to 20 minutes in length. We believe in hands-on experiments, builder and breaker style, that allow your developers to put what they learned into action. And lastly, fun. Training doesn't have to be boring. We make it engaging and fun for the developers. Visit www.securityjourney.com to sign up for a free trial of the Security Dojo.

1:35Robert HurlbutHello folks, welcome to another episode of the Application Security Podcast. This is Robert Halver, Threat Modeling Architect. And I'm joined by my co-host, Chris Romeo. Hey, Chris.

2:00Chris RomeoHey, Robert. Chris Romeo, CEO of Security Journey and lover of all things application security. I'm trying to give myself a new tagline here. I don't know if it worked or not.

2:09Robert HurlbutI think it worked. I think I like that. I do. And today we have special guest Charles Scherer.

2:18Charles ShirerThere you go.

2:21Robert HurlbutMake sure I say it right. Make sure I say it right. Charles, thank you for joining us today.

2:26Charles ShirerOh my God, thank you for having me. Just want to start off by saying I'm a huge fan of the show. So I constantly listen to you guys all the time.

2:35Robert HurlbutExcellent.

2:35Charles ShirerI'm a podcast addict.

2:37Robert HurlbutOh, very cool. Well, as you know, then, as a frequent listener of our podcast, we like to first ask our guests, what's your security origin story? How did you get into this crazy world of security and application security in particular.

2:53Charles ShirerAll right, I'm gonna do a rewind. All right, so here's how I got into security. So I started out as just a, just a computer guy, just was just a huge fan of, and they kind of did it backwards, because most folks, they start out on Windows. I actually started out in the Linux world, and then kind of worked my way like backwards insanely. Right? So I started out with Mandrake, not Mandrivia, Mandrake.

3:23Chris RomeoThat's old school.

3:24Charles Shirer8.2. Yes, that was my first Linux, uh, Mandrake 8.2. It had 6 CDs, right? And it had an extra floppy so you can, I guess, kind of like the boot floppy. So just in case something goes wrong, you were good to go, right? And I actually bought that from Best Buy for $39. Yeah, they actually sold Linux in the store.

3:45Robert Hurlbut$35.

3:46Chris RomeoWhat year was this? Is this 1987 or something?

3:51Charles ShirerNo, no, this is actually year 2000. Yeah, the year 2000. So I bought it and I said, okay, cool, because I wanted to learn how, um, like dual booting worked and everything else because I had Windows XP Home and I was like, okay, um, and I was reading up From IRC, of course, how to do like dual booting. And I was like, hmm. And I downloaded Partition Magic 6.0 through dial-up. And yeah, so that took a couple of days. But once those couple days were up, I downloaded it. And I was like, hmm, why do I need this FAT partition? So I deleted it. And when I rebooted, all I had was a command line with Linux. So then I'm rushing back and forth to another computer. Hey, how do I do this in Linux. I'm in like the, the Ethernet channel. And it's like, oh, type startx. And they would help me get on the internet for starters. And then I learned a little bit of how Linux worked, needed a LIN modem instead of a WIN modem. And I got into it from there. And then of course, I moved on to Slackware. That was my next Linux. And of course, Red Hat 7.2, which is the last real Red Hat. I just want to plug that in there. Then I had an epiphany. I had my first firewall out of a garage. It was the old garage sale. So the lady, the lady just gave it away. It was an old 486 with the turbo button.

5:25Robert HurlbutOh, wow.

5:27Charles ShirerAnd I put OpenBSD 3.0 on it. Because that was the first time they were using PF, which we all know today as PF Sense, right? So with PF, I was like, oh, this is pretty cool. I was like, okay, I'm learning the the command line and everything. I'm like, oh, this is pretty cool. Then I found out about the da da da FreeBSD. So I started out with FreeBSD 4.8, and then I just started learning about different operating systems, and then. Course, my first, and this is all like during the college period. I didn't even have a job yet. All I cared about was just playing with computers, learning sed, learning awk, coding in, well, scripting in KornShell, which I still do to this day. I still use KornShell. From there, when I got my first job, I got into Novell NetWare. Novell NetWare 3.12, which was Bind, and then I moved on to For one. What was amazing, the way I got into that, because at the time I was a PC tech and I made cables and did all the network drops and everything. And what I wound up doing, well, the guy that was the email administrator, his, I guess, wife was in the military and they had to move. So, the boss comes to me with a Novell book in one hand, a GroupWise book in the other hand, puts it on my table, says, you are now the new email administrator. Don't screw up. So that was my intro into getting into, like, learning about the basics of, like, securing operating systems and actually securing, well, directory services at the time. It was eDirect— NDS at the time. They moved to eDirectory, and then of course, eventually Active Directory. But that was kind of like my intro into, like, security. Now I'm in charge of other people's data, and now I'm like, okay, how do I get in? How do I harden OSes? So that was kind of like the intro, even though it wasn't called InfoSec. And everything else. It was just me learning how to lock down the operating system from Windows to Novell. And then eventually I got moved over to Solaris. And that was my baby for a long time. And I came into— I became a Solaris engineer and everything else. And just been a huge Unix fan ever since. Even still to this day, my desktop is FreeBSD. I still use Ubuntu. I still use sed and awk. I'm a vi guy.

7:57Chris RomeoI mean, so that means you have an editor, you have an editor open that you can't get out of is what you're saying.

8:04Charles ShirerUh-oh. Sounds like Emacs is in the room.

8:10Chris RomeoNo, no, that's my only vi joke. I only have one vi joke.

8:14Charles ShirerSo I went for that. But before, but even with all of that, And what really— my first job as a penetration tester, I got into wireless penetration testing. So I was a huge fan of learning about wireless and WEP, WPA2, ZigBee, Bluetooth. And I was literally trying to buy, like, every antenna I could get my hands on, you know? And shout out to Zero Chaos. He kind of pointed me in the right direction and looking at the OSWP, which was offered by Offensive Security. And once I took that, um, that kind of really like opened the door for like, you know, security-related, um, jobs or whatnot. So, um, that was kind of like my, my intro into everything. And of course I was still going to security conferences. I was still doing local talks. I was still like trying to mentor and help others who wanted to, even though I didn't have that much security experience. I did have a lot of experience as a sysadmin and a systems engineer. So I wanted to help others get into that realm. So it was just all about me being the computer guy. I never really looked at it as like cyber and all these different like titles and everything else. It was just me with my passion for computers in general. And that's how I got into security.

9:35Robert HurlbutVery cool. Very cool. So I have a question about C# here in a moment, kind of switching gears. But yeah, I want to say just before I get there, You mentioned FreeBSD. I can remember back in 2002, 2003 or so.

9:50Charles ShirerUh-huh.

9:52Robert HurlbutYou know, everybody talks about .NET Core. Hey, we can run it on Mac now. We can run it on Linux. Back then there was a, there was a project called Rotor. I don't know if you've ever heard of it.

10:01Charles ShirerI've heard of that.

10:03Robert HurlbutI got it and I installed it on FreeBSD and I ran .NET on FreeBSD back in the early 2000s. So I remember using that, learning. Yeah, yeah. And then of course they kind of scrapped it, and then years later it now sort of reappeared as .NET Core, more or less, running on Mac and Linux and so forth. Just kind of funny how it all sort of came around here.

10:26Charles ShirerOh, there was a, there was a lot of nostalgia in Charles's explanation here.

10:31Chris RomeoAll those things he was saying, I was like, yep, uh-huh, yep, yep, yep. He's from the same generation that I am in computing.

10:38Charles ShirerMaking cables. A lot of Twizzlers, Red Bull, and just sitting there and making crossover cables and cables for the network engineers. Yeah.

10:52Robert HurlbutSo my C# question, how did you get C# to run in the web browser?

10:58Charles ShirerOh my goodness. So a little backstory on that. So Again, I do a lot of web app pen testing as well.

11:06Robert HurlbutMm-hmm.

11:07Charles ShirerAnd I just made it up in my mind. I said, you know what, I really want to dig into these browsers. Browsers are popping up all over the place. Um, I think we're, you know, and this just in my mindset, I think I said as a community, I don't think we're digging deep enough into browser. Like we focus so much on the server side and everything else. And even with cloud and specific apps and, you know, now APIs. But nobody— it's like the browser was like forgotten, right? So I was like, you know what, let me start digging into that. And there's got to be a way where you can actually hide things inside the browser. So I was doing a lot of research and I ran across WebAssembly, right?

11:46Robert HurlbutMm-hmm.

11:47Charles ShirerSo I was like, oh man, this is pretty cool, WebAssembly. And, and I was doing a lot more research and I noticed that you can compile Rust, which is another language I use now to this day as well too. Um, Rust programming language, you can actually run Rust inside of the browser. So I was like, well, if it can run Rust, it's gotta be able to run some other languages too. And at the time I was getting into like, you know, hacking Active Directory, learning a little bit of red teaming and just, um, you know, C# was the way to go because a lot of folks were catching, of course, on PowerShell. So a lot of attackers were moving over to C#. So I said, I wonder if I could get C# to run in the browser. And lo and behold, I was able to get it to run in the browser using WebAssembly to compile the language and getting it to run. And I can show— I got my notes in Notepad because I kept that. I said, oh, this is huge. I got it to run. But that's how I was able to get it to run. You can you can run C# in your browser by compiling it through WebAssembly. So WebAssembly is a little bit faster than JavaScript, but, um, and just for certain instances, but, um, that's how I was able to actually get it run in a nutshell.

13:03Chris RomeoAnd what was the, uh, the use case there? Was it like web shells, like dropping a web shell or something? That was the goal.

13:10Charles ShirerThat's still the goal, because what I wanted to do, because, you know, like with With the browser, it runs in a sandbox. My goal, and still is my goal, is actually because I've read through a lot of the Edge documentation, is actually being able to say, hey, let me run my C# code in here. If it's running on the Win— check to see if it's running a version of Windows, whatever version of Windows is actually running, and see if I can break out of the sandbox and maybe run OS-level commands from the browser. So that's, that's, that was the, that was my reason for thinking like, okay, how can I do different things within the browser that can, you know, that I can bypass certain things, you know? Because again, if you're, you know, nobody looks in the browser for anything. Well, I'm not saying now they don't, but at that time nobody was really paying attention to the browser like that.

14:02Robert HurlbutYeah.

14:02Charles ShirerBecause if you go back, think about it, um, 10, 15 years ago, it was all about the perimeter.

14:08Chris RomeoYeah.

14:08Charles ShirerWeb applications wasn't really getting that, you know, wasn't really getting that attention. Because if you had the best firewall, you had the best Cisco firewall and all your, like, the VLAN tagging and everything else in place, nobody cared about the web app. And that's how a lot of attackers were getting in was through the web app. If you were able to phish, I mean, the early stages of phishing, if you're able to get somebody to click on a JavaScript link, and whatever your JavaScript did, and you was able to do browser hooking and everything else, even before beef, you were in.

14:40Chris RomeoYeah.

14:40Charles ShirerAnd there was— and it was legitimate traffic according to the firewall because it's port 80 or port 443. Yep.

14:48Chris RomeoSo that's very cool. That's very cool. I want to— I want to transition now and kind of get to the, the story behind how we got to this interview. And so, okay, about— I don't know, it's probably 6 months or a year ago or so. You know, Robert and I are both— we're both huge Twitter people and, you know, we're probably on it too much. But that's— we could debate what too much actually accounts for.

15:12Charles ShirerHey, we are.

15:13Chris RomeoAnd I'm watching and I start to see these videos popping up. People are like— people that I follow are liking these videos. And I'm like, there's this guy on here and he's wearing a t-shirt and he's like, looks pretty happy. So I'm like, I play one of these videos and I'm like, This guy is just the most positive security person I've ever met in my life. He's encouraging me, and like he's encouraging our whole community. And so, before I even ask you about this, Charles, I'm gonna I'm gonna play one of these one of these for our audience.

15:44Charles ShirerOkay, yeah, definitely. Yeah, happy Fantastic Friday from the BSD Bandit.

15:49Robert HurlbutOw!

15:50Charles ShirerHope everyone is enjoying their morning. I definitely am. I'm super excited to live to see another day. But before I sit down and drink my morning coffee. Just want to stop by and say that I love you all. Let's live it up and enjoy the day and each other. Remember, help someone, digitally hug someone. And as you all know, my Follow Friday is the entire hacker community. Keep on doing great things, keep on spreading love, keep on just being awesome. Yeah. Well, that's my time. I love y'all all. And you know, I got to leave y'all with something. And this song was playing in my head like literally this morning. So this is going to be my Friday right here. Yes, yes, I love y'all. Have a good day. Later.

16:31Chris RomeoAll right, so now you've had a chance, audience, to hear what, what drew me to Charles. And so I reached out to him a few weeks ago and said, I gotta, I gotta ask this guy some questions. So the first thing is, when— how would you describe these videos that you do? Like, what is your motivation behind them?

16:51Charles ShirerWell, okay. So, and this was literally right before the pandemic hit. So, um, I was just looking on Twitter one day and I just noticed that it was just a lot of just like negative stuff going on, you know, of course, everything that was going on out in the real world. And then I noticed a lot of the InfoSec community in general and developers as well too, tech in general. It was just all just like negative. Oh, why am I here? I'm going through stuff. And People were depressed, suicide. I mean, it was, it was pretty bad. And at first I started tweeting out just words and I was like, what am I doing? It's the age of video. So I wanted to encourage people. I have a passion for people and helping others. And I tied that into the, I call it the hacker lifestyle. And I truly Believe in the hacker lifestyle. So more so is like, you don't accept things just the way they are. You change them. So I saw there was a lot of negativity. So I said, you know what? I'm gonna reverse it. Let's get, let's, let's, you know, I'm excited. My, the reason for my excitement, I, it doesn't take much. Like I'm living my dream job. I get to do what I love to do for a living each day. It don't get no sweeter than that. You know, so I figured, you know what, if I can help someone else, even if it's just a little bit, like, hey, you can make it too. You can, you can get to that next level. Greatness awaits you. If it don't challenge you, it don't change you. You know, just keep people motivated to, to just make it through one more day, you know. And that's what— that was the reason behind, like, the videos. That's what motivated the videos. Now with the t-shirts, I'm a huge fan of retro. So I kind of combined everything and just said, you know what? I'm a huge fan of retro and I want to actually bring that into the fold because retro, when we look at a video game, we look at it, it takes us back to a time where it's like the simplest of times. So I said, you know what? Let's incorporate that as well too. So that's why I started wearing the different t-shirts. 'Cause it's symbolic to just say, you know, these are simpler times. Let's just get out there. Like, if you're up and you're breathing, you're winning. It's a bonus. Get out there and do what you love. Or if you're not, if you're in a position where you're not doing what you love right now, work towards doing something that you love.

19:23Chris RomeoYeah.

19:24Charles ShirerBut that's the end goal.

19:25Chris RomeoHow many shirts? 'Cause I swear I don't see the same shirt. And you may have snuck it in after a period of time, but how many t-shirts are in your your closet, your wardrobe, whatever.

19:38Charles ShirerAnd this is the first time I'm saying this live.

19:42Chris RomeoWe got a scoop here, folks.

19:43Robert HurlbutPay attention.

19:44Chris RomeoThere's a scoop coming up here.

19:46Robert HurlbutMark this out. Yeah.

19:48Charles ShirerI'm actually at 310 t-shirts.

19:52Chris RomeoThis is a look of surprise. This is a genuine look of surprise on my face.

19:55Robert HurlbutI've been to so many conferences and I don't have— and I have maybe a drawer full or two, but I don't have that many.

20:03Charles ShirerBecause I start— I've been doing the t-shirts for like a year or so now. So it's different t-shirts every day.

20:14Robert HurlbutYeah.

20:14Charles ShirerWow. So you are—

20:16Chris RomeoI was— I didn't know that you were— that you were actually doing a different t-shirt. I thought there were— there was a rotation somewhere and I was just missing it.

20:24Charles ShirerWow. Do you have a room? Yeah, the closet back there, that's full of t-shirts, that huge closet around the corner.

20:32Chris RomeoOh, that's, that is, that's so cool.

20:34Charles ShirerSo that's full of like t-shirts and my retro Mega Man stuff. I'm a huge Mega Man fan and Final Fantasy fan.

20:41Chris RomeoThat's so cool. It's encouraging just to see like a different t-shirt and stuff. But I want to, I want to unpack this even a little bit deeper because I've been in security for almost 25 years at this point. Robert's been, been around the world of security for a long time as well. And after hearing your origin story, you have as well. And we don't meet a lot of positive people in our business. And I'm not trying to be— I'm not trying to be, you know, insensitive or anything. It's just this business that we're in, we're always picking apart the negative.

21:18Robert HurlbutIt's just what—

21:18Chris Romeoit's what we get paid to do. And so I'm just like, how do you—

21:24Robert Hurlbuthow do you— where—

21:25Chris Romeohow do you get this positivity? Like, In a world where 10, if I asked 10 security people, if I said, hey, we got 10 security people here, I'd be like, hmm, we probably got 9.5 people are negative. And there's a half a person that's like once in a while, but you're bringing a different energy to it. And I'm just curious, like, how do you do that? And do you bring that into your work as well? Like as a pen tester, are you a positive pen tester?

21:49Charles ShirerYes. Shout out to Red Siege. That's where I work. Tim Madeen. Yeah, so each day, like I said, I get excited to— like, this is something I've always wanted to do. Not even know it was going to be called InfoSec. I'm just into computers. And each day I get to, I get to do something new that I actually enjoy. And you get paid to do that. How sweet. It doesn't get any sweeter. And then the thing is, it's just like, I always look at it this way. True, be truly appreciative, because remember, it can all be gone in a second. So I truly appreciate every opportunity or every place that I've ever got an opportunity to work with or whoever, right?

22:39Robert HurlbutYeah.

22:39Charles ShirerBecause again, it can all be gone in a second. So I look at the simplicity. It's the simplicity because you don't have— like, in this industry, it's not a right that we're here. It's by— we have that privilege of being in security. We have the privilege of working with— whether if you're a coder, you have a privilege to work on a specific app or a specific project. These are all privileges. You get to wake up and breathe. Everything else is a bonus.

23:06Chris RomeoYep.

23:07Charles ShirerSo I always keep that mindset no matter what's going on, because again, everybody has problems. Yeah, you have problems, but The key is, is how you approach it. Because again, you still got to face the problem, but do you want to face it in a negative attitude or do you want to keep it in a positive light? That's the choice that you control. I just chose the positive side as opposed to just being negative. And that is inspired by— thank you for all— I grew up in New York. Thank you for all the Wall Street people that never smiled. When I was going to school, and then they had the same facial expression when I was coming home from school, and I never wanted to be that kind of adult.

23:47Robert HurlbutHmm. Wow.

23:50Chris RomeoNo, that's— it makes sense. I mean, I think we need more positivity in our industry. I think people burn out in InfoSec for a lot of different reasons, and that's a real thing because we, we were in jobs that are high stress. And we get— we work a lot of hours, and yeah, there's a lot of other things that are happening there, but some of it's got to be because of our general mindset, though. It's like, yeah, it's got to be— being more positive has got— it can't do anything but make us a little bit more resilient, a little bit less burning out, just because we're taking all that weight upon us, you know?

24:28Charles ShirerMm-hmm. Like, take a break, for example, right? If you're feeling burned out, take a break. It could be your favorite television show. Take like 30 minutes if you need to, or if you want to go see something outside, take a walk outside, but fixate your mind on something that, that you really enjoy for like, for like 30 minutes. And you'd be surprised. Just walk away from the problem, come back. You'd be surprised how refreshed you are and how you'd be able to tackle the problem, or if there's no problem, how you can actually make it through the rest of the day.

25:00Chris RomeoYeah, I've had that experience many times. Like, I'm not a, I'm not a great coder, but I do code it sometimes. And I've had that experience, or even trying to fix a problem, you know, you're like, right, it's— you sit there for 8 hours, and you're like, just ready to scream into the wall. You get up, you go, you go, and then you come back the next morning. And like 5 minutes later, you're like, oh, look at that.

25:21Charles ShirerIt's right in front. Right. And that's the beauty part of it. Again, like I said, with coding, let's use coding as an example, right? And, you know, I see a lot, uh, on Twitter where people say they have imposter syndrome, right? But here's the thing about that, right? It's just like, hey, you're not where you used to be. You're moving along in your career.

25:42Robert HurlbutYeah.

25:43Charles ShirerNo, you got to look at it as a mindset like, hey, hey, I may not do— I may not be able to do what you can do right now, but I guarantee you, if I, if I stick around and keep working at it, I will get there. Yeah, you know, none of us are born with a TCP/IP manual. We're just not.

26:03Chris RomeoLuckily, luckily we're not born.

26:04Charles ShirerI know, right?

26:06Chris RomeoThing weighs like ten pounds. We're not born like what?

26:08Charles ShirerRight? We're not born like what packets? We're not doing that.

26:14Chris RomeoYeah.

26:15Charles ShirerSo, you know, this is something that it and it's always going to be somebody that knows a little bit more. There's always going to be somebody that knows a little bit less. But that doesn't make them less. Yeah. Or the person more. And that's the mindset that I hope people get when they say, oh, I have imposter syndrome. No, you deserve to be there. You belong.

26:38Chris RomeoYep.

26:39Charles ShirerSo, that's, that's, that's the mindset I try to impute in folks each day.

26:42Chris RomeoYeah, I love it. I love it. I'm someone who watches the videos. So, like, I love this idea. And when you think about, you know, imposter syndrome and stuff. Yeah. You know, one of the things that— it's crazy. I've gotten a chance to speak at a lot of different big conferences and things. And in the early days of speaking, I used to be deathly afraid. Like, one of my friends, when I worked back at Cisco, dragged me basically into a speaking engagement where I'm like, nope, nope, I don't want to do this. I don't want to do it. But, you know, the thing that— the thing that— where I'm— where I flipped the switch in my career, and I'm just going to share this. I don't know, maybe it'll help somebody somewhere. When I flipped the switch in my career, I realized I don't really care what the people in the room think about me, because 10% of the people in the room are going to think I'm the smartest person on earth, 10% are going to think I'm the dumbest person on earth, and the other 80% of people, they just— they're just going to listen and they're going to come along for the ride. And it was that moment where I just said, you know what, I'm not going to care anymore.

27:42Robert HurlbutI still—

27:42Chris RomeoI cared about what I— when I stand up to speak, it's very, you know, it's an honor, and I, I put a lot of preparation into it, but I'm like, The people in this room don't define me. They don't, they don't determine the value in what I am, what I'm doing or whatever. And when that happened, when I flipped that switch though, you look at that room and it's totally different. Because I'm not afraid anymore. I'm not afraid anymore. I'm like, go ahead, laugh at me, do it. I love it. I'll laugh with you. Like, you know, that's fine. I'm not— it's not going to— it's not going to change who I am as a person. And that's really for me and the point in my career, I was like, it's— I'm like, I can stand in front of 500 people now because Laugh. Maybe I'll fall and trip on the stage. We'll all laugh. It'll be a good day. You'll have a— someone will have a little bit of happiness because they'll be like, remember that guy tripped on that stage?

28:23Charles ShirerIt was hilarious. There you go.

28:25Chris RomeoBut that's just a little bit from my perspective and my background. Yeah. Thinking through how I process that. But we got to talk about this podcast you're doing now.

28:32Charles ShirerLet's do this.

28:33Chris RomeoThe Positively Blue Team. I didn't catch that until now. The Positively Blue Teamcast.

28:38Charles ShirerAll right.

28:39Chris RomeoSo tell us about this and we're going to put notes in the— there'll be stuff in the show notes, links so people can find it as well. But Tell us about this. Like, what would I experience if I, if I catch an episode of this podcast?

28:49Charles ShirerSo what you'll get, and we talk about various different topics from a positive perspective in the industry. Like last week, like last week, we talked about policy because I'm also a former threat hunter. Okay, so that's how I learned a lot about how, like, with defense and everything else. So which helps me as better as a red teamer and penetration tester. So with the Possibly Blue Team, my castmate, um, Understudy77, he actually does defense. He's 100% defensive. The positive comes from me, and that's how we got the name. He's blue team, I'm positive, and he's positive as well too. But, um, what you'll catch in this episode is 30 minutes of actual content that we talk about policies. We've talked about red teaming and blue teaming, but we always keep it at 30 minutes because we don't want to lose the audience just kind of like all over the place, right?

29:51Robert HurlbutYeah.

29:51Charles ShirerSo, we come in and we make it fun. It's like, hey, you got 2 minutes to introduce yourself.

29:56Chris RomeoGo!

29:56Charles ShirerAnd we just— and we make it fun and just interesting that way. And then, we talk about the different topics within a 30-minute span. And then, and that's how we wrap up our shows. But we, we do it from that standpoint. So it's not 100% red, it's not blue, it can be— the week before we had recruiters, how to work with recruiting when you're looking for a job on Positively Blue Team. So we talk about different aspects, we're going to talk about web apps, we're going to— and we're in episode— this is going to be the 4th episode coming up. But we're going to talk about web apps, we're going to talk about Hardware hackers. I mean, we're—I mean—we're just keeping with different topics all the time. So that's what makes it fun, and we keep it from a positive perspective.

30:43Chris RomeoYeah, love to hear it. I'm gonna—I'm gonna check it out as well. I haven't heard any episodes yet, but I'm definitely gonna add that. So I wanted to just check in on one more thing in regards to this thing called SecBSD because I know you were telling me that that's something that you're a part of. Yes. I'm gonna be honest. I mean. honesty is an important thing. I had never heard of it, didn't know what it was. I'll say it on the air. I don't care. I'm not afraid. Now I want to know though. I want to learn. I want, I want you to teach me a little bit about SecBSD because I obviously, I know Kali Linux. Everybody kind of knows that. But even, um, now I can't remember what it was called before that. Backtrack, right? Backtrack. Yeah, Backtrack. Yes. Yeah. But I've never heard of SecBSD. So yeah, tell us a little bit about that project and kind of what, what it would be useful for.

31:25Charles ShirerSo with SecBSD, The idea came about in like November 2019, right? So, um, we had all these different distros out there that you had Pentoo, and of course Backtrack returned to the Kali Linux, and I think there was Arch Linux, right? Linux, Linux, Linux. And then for the BSD community, there was nothing. So we were looking at it from a standpoint like, hey, wouldn't it be cool to have like a BSD-based distro, pentest distro? So we were throwing names around and came up with SecBSD, right? So it's actually seven—it's actually nine of us now that are actually working on a project. It's 100% open source, and it's at secbsd.org if you want to check it out. It's 100% open source, is volunteer, and it's all—it's a pentest distro for like the BSD stop BSD community. So we're taking some of the tools like. Porting a lot of the tools that are in Kali over to the BSD side of the house as well too. Now we're probably not going to have as many tools as Kali because we just kind of, you know, pick a few because, I mean, Kali has a lot of tools. So, and you know, you have a certain amount that do kind of do the same thing. So we're kind of like pretty much just like doing this as we go. Um, if, if anybody wants to volunteer, they're perfectly free to do that. Um, again, it's just more so just wanting to have just that pentest distro for the BSD community. So it was kind of our way of like contributing, kind of like how the old way is, you know, you create a project, you contribute to the community, community works with it, or they'll tell you, hey, you could, you can make this better by doing this, or they actually fix bugs. So we're just trying to bring it back to that kind of retro way, if that makes sense. So that's where SecBSD actually comes from, is wanting to have a pentest distro in the BSD community.

33:18Robert HurlbutReally cool. Well, Charles, we really appreciate you coming and visiting with us today, and it's just a lot of fun just hearing about how positive you are. And I also, I want to check out your podcast as well and check out some of the videos. I haven't seen them. I don't think I've— I know I've at least seen one, but I want to see some more. I want to see the t-shirts. Yes, it's, uh, I'm thinking of all the t-shirts I have and they're nowhere near the numbers that you have. I keep thinking, why do I have all these t-shirts? But here's somebody who's taking advantage of it, so that's fantastic.

33:56Charles ShirerAnd just having fun with it. I'm, I'm, and again, once again, truly honored to be on the show today. This is, this is, this is awesome. Like I've been listening to you guys for a while. So this is— I'm really enjoying this.

34:09Robert HurlbutExcellent. Well, for our listeners, what would you say a call to action for our audience? What are some things that they could take away today from, from this podcast and help them? What do you think?

34:21Charles ShirerI would say, honestly, give it whatever it is that you want to do, whether it's web app security, whether it's network security, wireless, whatever, or even DevSecOps. Get out there and just go, just go do it. Even if it's just taking the first step of just asking the question. That's a step towards the right direction. Hey, how do I do this? I guarantee you, there's someone out there that's willing to help you. If you're trying to help yourself, there's going to be somebody out there that are going to point you in that direction and actually help you. So I want you to just, just take the first step. That's what I challenge you to do today. Take the first step towards your goals, your dreams, and greatness.

35:03Robert HurlbutExcellent. Excellent. Great advice. Well, again, Charles, thank you. Thank you for joining us today.

35:08Charles ShirerAll right. Well, thank you for having me.

35:12Chris RomeoThanks for listening to the Application Security Podcast. You'll find the show on Twitter @AppSecPodcast and on the web at www.securityjourney.com/resources/podcast. You can also find Chris on Twitter @edgeroute and Robert @roberthurlbut. Remember, with application security, there are many paths, but only one destination.

6,513 words · transcript by assemblyai

More on Careers in AppSec

View all episodes →

Get Reasonable AppSec: new episodes and useful picks from the archive.